when ever on the computer or even when computer is just on, A message will keep repeatedly popping up saying RunDLL error loading. And say this specified module could not be found. Do know how to fix this from popping up all the time?

hijackthis log:

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 1:19:33 AM, on 3/25/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
c:\PROGRA~2\mcafee.com\agent\mcagent.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Hp\QuickPlay\QPService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\SSDK04.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
c:\PROGRA~2\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\PROGRA~2\McAfee\MSC\mcshell.exe
C:\Program Files (x86)\TrendMicro\HiJackThis\HiJackThis.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: QvodExtend - {53AC8551-0DE0-4606-8A1E-A51AF20ADD60} - C:\Program Files (x86)\Common Files\System\Extend.dll
O2 - BHO: (no name) - {7B434A2A-9E4C-48F2-8373-5801F316A4D5} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~2\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\New Folder\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\windows sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
O4 - HKCU\..\Run: [PPAP] C:\ProgramData\PPLiveVA\Application\PPAP.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jenny\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: 百度hi.lnk = C:\Program Files (x86)\baidu\Baidu Hi\BaiduHi.exe.vbs
O8 - Extra context menu item: &U使用米人下载并收藏 - C:\Program Files (x86)\NamiRobot\Data\du.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {09E90109-A9AA-4980-BCEF-76F8D924E902} - (no file)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {09E90109-A9AA-4980-BCEF-76F8D924E902} - (no file) (HKCU)
O13 - Gopher Prefix:
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter hijack: text/xml - (no CLSID) - (no file)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MacroISer - Unknown owner - C:\Windows\SysWOW64\a22d.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~2\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~2\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~2\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files (x86)\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 12470 bytes

Thanks for the help...

Recommended Answers

All 27 Replies

Your log shows signs of definite infections. You need to do the following:
Please download Malwarebytes' Anti-Malware (MBA-M) to your Desktop.

* DoubleClick mbam-setup.exe and follow the prompts to install MBA-M.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When MBA-M finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt.

Reboot the Computer

Please Run the ESET Online Scanner and post the ScanLog with your post for assistance.

* You will need to use Internet Explorer to to complete this scan.
* You will need to temporarily Disable your current Anti-virus program.

* Be sure the option to Remove found threats is checked and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.
Reboot the system.
Run a new HJT scan, save the log and post back with the MBA-M log, the ESET log and the new HJT log.
Judy

I can't access my ESET log but here is my MBA-M log and new HJT log

MBA-M log:

Malwarebytes' Anti-Malware 1.44
Database version: 3913
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18882

3/25/2010 4:48:07 PM
mbam-log-2010-03-25 (16-48-07).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 326823
Time elapsed: 1 hour(s), 42 minute(s), 45 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 13
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 32
Files Infected: 631

Memory Processes Infected:
C:\Windows\SysWOW64\a22d.exe (Trojan.Agent) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\macroiser (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\yodaotoolbar.stockbar (Adware.Toolbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7b434a2a-9e4c-48f2-8373-5801f316a4d5} (Adware.Toolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7b434a2a-9e4c-48f2-8373-5801f316a4d5} (Adware.Toolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{7b434a2a-9e4c-48f2-8373-5801f316a4d5} (Adware.Toolbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7b434a2a-9e4c-48f2-8373-5801f316a4d5} (Adware.Toolbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{7b3ef01d-b7c5-4905-82ef-258f6c02a21d} (Adware.Baidu) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{40a846d3-a52a-49a5-a2c8-8a200d01396b} (Adware.Baidu) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{23f67c64-0b79-4ae3-9fc9-4289f8a03c6b} (Adware.Baidu) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{23f67c64-0b79-4ae3-9fc9-4289f8a03c6b} (Adware.Baidu) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bbd7098e-c5ce-4d42-ab0b-54fda7c8c87c} (Adware.Baidu) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.pox (Rogue.FixTool) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\pofile (Rogue.FixTool) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files (x86)\Perfect Optimizer (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Application (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Registry (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Registry\FirstBackup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Registry\FullBackup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Service (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Temp (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\Download (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\Download\BaiduHi (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\Download\updater (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baidubi (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baifubao (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baike (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\CRM (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\news (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\star (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\subaccount (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\tieba (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\zhidao (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\skin (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\syshead (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysimage (Adware.Baidu) -> Quarantined and deleted successfully.

Files Infected:
C:\Windows\SysWOW64\a22d.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Jenny\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DFL7P31F\36a[1].exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Users\Jenny\AppData\Local\Mozilla\Firefox\Profiles\2zgbeljt.default\Cache\F4FEFF22d01 (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Windows\212d.flv (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\a22d.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\PerfectOptimizer.ini (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\apputil.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\atl80.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\baiduhi.exe (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\BaiduHi.exe.vbs (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\baiduhiproperty.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\baike.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\basement.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\bdsns.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\bugreport.exe (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\bull80u.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\bvelib.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\dbghelp.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\fmmgr.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\gipsvideodll.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\groupclass.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\historyexplorer.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\imengine.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\improtocol.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\imstorage.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\licence.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\locallog.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\mediaengine.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\memo.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\microsoft.vc80.atl.manifest (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\netservice.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\pengine.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\resource.db (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\riched20.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\rudplib.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\serverconfig.dat (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\skindll.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\space.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\speexcodec.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\syscustomstatus.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\uninst.exe (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\urlprotocol.exe (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\versioninfo (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\wealthapp.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\webdetect3.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\youa.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\zhidao.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\zlib1.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\atl80.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\AutoInstall.exe (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\AutoUpdateUtil.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\BaiduHiUpdate.exe (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\config.ini (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\Microsoft.VC80.ATL.manifest (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\VersionInfo.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\Download\AutoUpdate.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\Download\PackageInfo.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\02ae27f41042ab70f961302d73dfb503.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\0f5c6443c3e8e74ad496d24ed6f8bd36.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\10c61e4d3b4cea255ef9e4acc44ad6a3.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\35848DB0EE394D63997C2E231DBCC167.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\41f354b0a403c7175fd88a64f71b9f43.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\45a50e49741972f3b2a59bb7dd882a2d.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\4991ff8a7690bc8f872d639125c8d4de.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\50c6429b08cf686179a60dd4ac2e7d9a.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\72C9A0EFBDE7506B9AD08DA9DB79FFE5.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\75DAF25C1D78733C16EB484B206B5BA5.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\8ad2a3ae47773d3fb32a2d7949b5830b.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\90df14a1839f9f726bc8927cf7c87ea8.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\a093ac06695f6176894e2ae6065cc89f.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\A530D16E25E826634DF7898044D5252F.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\a8f4bc3305b9c104801e516bf75e92fb.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\a91c81316d66cbdf9d3d7b90a51bfd8c.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\ABD4981D0A9D2AE634C0F6E44483824E.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\be00a34ce98d956358594dbd8a3ddc63.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\F3CA1F95AF31C5E7BF1054E75953D2F6.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\f409717a7d1f294c65cf65f7f8057ca0.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\fc56c50cead3ceab2727533a1beb7354.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\fdc274eddb0c06742decd86f4c4ac246.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\sortguide.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baidubi\baidubi.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baidubi\baidubi.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baidubi\baidubi.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baidubi\baidubi_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baidubi\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baifubao\baifubao.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baifubao\baifubao.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baifubao\baifubao.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baifubao\baifubao_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baifubao\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baike\baike.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baike\baike.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baike\baike.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baike\baike_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baike\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\CRM\crm.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\CRM\crm.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\CRM\crm.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\CRM\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\CRM\tabbtn.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\news\news.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\news\news.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\news\news.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\news\news_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\news\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\star\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\star\star.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\star\star.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\star\star.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\star\star_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\subaccount\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\subaccount\subaccount.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\subaccount\subaccount.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\tieba\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\tieba\tieba.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\tieba\tieba.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\tieba\tieba.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\tieba\tieba_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\chatframeentrance.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\resource.db (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\vvgame.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\vvgame.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\vvgame.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\vvgameconfig.dat (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\vvgame_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\waitrequesticon.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\zhidao\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\zhidao\zhidao.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\zhidao\zhidao.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\zhidao\zhidao.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\zhidao\zhidao_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\skin\default.db (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound\msg.wav (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound\online.wav (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound\phone.wav (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound\snapshot.wav (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound\system.wav (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound\winks.wav (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\0A6E06BBCB9501857BAFA74719D928F8.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\0ed289287d89a9c69a5d3a3736503680.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\0FBDFEB9BBC01F849D34D44C8BFEAE55.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\2698C2F9931AAB9B5F305B7CE6D6A950.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\63AF498CE8B260BF854EF2BCD59CAED7.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\6EBE180202B59EA6F59C9A433099C14F.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\defaultfrg.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b01.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b01_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b02.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b02_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b03.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b03_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b04.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b04_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b05.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b05_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b06.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b06_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b07.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b07_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b08.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b08_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b09.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b09_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b10.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b10_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b11.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b11_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b12.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b12_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b13.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b13_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b14.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b14_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b15.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b15_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b16_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b17.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b17_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b18.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b18_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b19.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b19_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b20.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b20_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b21.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b21_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b22.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b22_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b23.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b23_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b24.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b24_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b25.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b25_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b26.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b26_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b27.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b27_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b28.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b28_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b29.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b29_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b30.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b30_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b31.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b31_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b32.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b32_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b33.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b33_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b34.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b34_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b35.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b35_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b36.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b36_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b37.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b37_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b38.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b38_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b39.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b39_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b40.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b40_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b41.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b41_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b42.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b42_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b43.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b43_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b44.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b44_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b45.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b45_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b46.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b46_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b47.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b47_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b48.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b48_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b49.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b49_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b50.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b50_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b51.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b51_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b52.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b52_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b53.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b53_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b54.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b54_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b55.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b55_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b56.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b56_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b57.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b57_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b58.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b58_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b59.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b59_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b60.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b60_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b61.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b61_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b62.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b62_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d01.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d01_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d02.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d02_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d03.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d03_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d04.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d04_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d05.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d05_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d06.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d06_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d07.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d07_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d08.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d08_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d09.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d09_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d10.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d10_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d11.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d11_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d12.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d12_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d13.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d13_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d14.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d14_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d15.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d15_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d16_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d17.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d17_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d18.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d18_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d19.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d19_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d20.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d20_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d21.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d21_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d22.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d22_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d23.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d23_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d24.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d24_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d25.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d25_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d26.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d26_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d27.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d27_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d28.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d28_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d29.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d29_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d30.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d30_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d31.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d31_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d32.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d32_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d33.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d33_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d34.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d34_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d35.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d35_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d36.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d36_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d37.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d37_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d38.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d38_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d39.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d39_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d40.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d40_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d41.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d41_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d42.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d42_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d43.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d43_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d44.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d44_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d45.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d45_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d46.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d46_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d47.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d47_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d48.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d48_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d49.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d49_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d50.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d50_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d51.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d51_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d52.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d52_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d53.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d53_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d54.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d54_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d55.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d55_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d56.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d56_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d57.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d57_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d58.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d58_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d59.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d59_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d60.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d60_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\face.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y01.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y01_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y02.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y02_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y03.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y03_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y04.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y04_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y05.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y05_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y06.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y06_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y07.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y07_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y08.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y08_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y09.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y09_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y10.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y10_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y11.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y11_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y12.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y12_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y13.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y13_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y14.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y14_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y15.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y15_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y16_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y17.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y17_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y18.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y18_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y19.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y19_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y20.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y20_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y21.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y21_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y22.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y22_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y23.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y23_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y24.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y24_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y25.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y25_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y26.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y26_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y27.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y27_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y28.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y28_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y29.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y29_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y30.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y30_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y31.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y31_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y32.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y32_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y33.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y33_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y34.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y34_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y35.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y35_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y36.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y36_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y37.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y37_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y38.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y38_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y39.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y39_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y40.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y40_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y41.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y41_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y42.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y42_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y43.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baid

I can't access my ESET log but here is my MBA-M log and new HJT log

MBA-M log:

Malwarebytes' Anti-Malware 1.44
Database version: 3913
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18882

3/25/2010 4:48:07 PM
mbam-log-2010-03-25 (16-48-07).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 326823
Time elapsed: 1 hour(s), 42 minute(s), 45 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 13
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 32
Files Infected: 631

Memory Processes Infected:
C:\Windows\SysWOW64\a22d.exe (Trojan.Agent) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\macroiser (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\yodaotoolbar.stockbar (Adware.Toolbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7b434a2a-9e4c-48f2-8373-5801f316a4d5} (Adware.Toolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7b434a2a-9e4c-48f2-8373-5801f316a4d5} (Adware.Toolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{7b434a2a-9e4c-48f2-8373-5801f316a4d5} (Adware.Toolbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7b434a2a-9e4c-48f2-8373-5801f316a4d5} (Adware.Toolbar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{7b3ef01d-b7c5-4905-82ef-258f6c02a21d} (Adware.Baidu) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{40a846d3-a52a-49a5-a2c8-8a200d01396b} (Adware.Baidu) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{23f67c64-0b79-4ae3-9fc9-4289f8a03c6b} (Adware.Baidu) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{23f67c64-0b79-4ae3-9fc9-4289f8a03c6b} (Adware.Baidu) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bbd7098e-c5ce-4d42-ab0b-54fda7c8c87c} (Adware.Baidu) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.pox (Rogue.FixTool) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\pofile (Rogue.FixTool) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files (x86)\Perfect Optimizer (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Application (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Registry (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Registry\FirstBackup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Registry\FullBackup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Service (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Temp (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\Download (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\Download\BaiduHi (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\Download\updater (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baidubi (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baifubao (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baike (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\CRM (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\news (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\star (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\subaccount (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\tieba (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\zhidao (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\skin (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\syshead (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysimage (Adware.Baidu) -> Quarantined and deleted successfully.

Files Infected:
C:\Windows\SysWOW64\a22d.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Jenny\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DFL7P31F\36a[1].exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Users\Jenny\AppData\Local\Mozilla\Firefox\Profiles\2zgbeljt.default\Cache\F4FEFF22d01 (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Windows\212d.flv (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\a22d.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\PerfectOptimizer.ini (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\apputil.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\atl80.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\baiduhi.exe (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\BaiduHi.exe.vbs (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\baiduhiproperty.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\baike.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\basement.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\bdsns.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\bugreport.exe (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\bull80u.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\bvelib.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\dbghelp.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\fmmgr.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\gipsvideodll.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\groupclass.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\historyexplorer.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\imengine.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\improtocol.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\imstorage.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\licence.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\locallog.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\mediaengine.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\memo.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\microsoft.vc80.atl.manifest (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\netservice.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\pengine.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\resource.db (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\riched20.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\rudplib.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\serverconfig.dat (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\skindll.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\space.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\speexcodec.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\syscustomstatus.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\uninst.exe (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\urlprotocol.exe (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\versioninfo (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\wealthapp.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\webdetect3.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\youa.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\zhidao.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\zlib1.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\atl80.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\AutoInstall.exe (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\AutoUpdateUtil.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\BaiduHiUpdate.exe (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\config.ini (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\Microsoft.VC80.ATL.manifest (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\VersionInfo.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\Download\AutoUpdate.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\AutoUpdate\Download\PackageInfo.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\02ae27f41042ab70f961302d73dfb503.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\0f5c6443c3e8e74ad496d24ed6f8bd36.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\10c61e4d3b4cea255ef9e4acc44ad6a3.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\35848DB0EE394D63997C2E231DBCC167.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\41f354b0a403c7175fd88a64f71b9f43.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\45a50e49741972f3b2a59bb7dd882a2d.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\4991ff8a7690bc8f872d639125c8d4de.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\50c6429b08cf686179a60dd4ac2e7d9a.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\72C9A0EFBDE7506B9AD08DA9DB79FFE5.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\75DAF25C1D78733C16EB484B206B5BA5.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\8ad2a3ae47773d3fb32a2d7949b5830b.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\90df14a1839f9f726bc8927cf7c87ea8.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\a093ac06695f6176894e2ae6065cc89f.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\A530D16E25E826634DF7898044D5252F.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\a8f4bc3305b9c104801e516bf75e92fb.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\a91c81316d66cbdf9d3d7b90a51bfd8c.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\ABD4981D0A9D2AE634C0F6E44483824E.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\be00a34ce98d956358594dbd8a3ddc63.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\F3CA1F95AF31C5E7BF1054E75953D2F6.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\f409717a7d1f294c65cf65f7f8057ca0.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\fc56c50cead3ceab2727533a1beb7354.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\campaign\fdc274eddb0c06742decd86f4c4ac246.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\sortguide.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baidubi\baidubi.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baidubi\baidubi.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baidubi\baidubi.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baidubi\baidubi_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baidubi\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baifubao\baifubao.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baifubao\baifubao.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baifubao\baifubao.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baifubao\baifubao_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baifubao\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baike\baike.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baike\baike.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baike\baike.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baike\baike_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\baike\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\CRM\crm.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\CRM\crm.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\CRM\crm.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\CRM\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\CRM\tabbtn.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\news\news.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\news\news.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\news\news.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\news\news_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\news\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\star\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\star\star.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\star\star.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\star\star.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\star\star_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\subaccount\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\subaccount\subaccount.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\subaccount\subaccount.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\tieba\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\tieba\tieba.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\tieba\tieba.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\tieba\tieba.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\tieba\tieba_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\chatframeentrance.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\resource.db (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\vvgame.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\vvgame.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\vvgame.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\vvgameconfig.dat (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\vvgame_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\vvgame\waitrequesticon.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\zhidao\sign.txt (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\zhidao\zhidao.dll (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\zhidao\zhidao.hpd (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\zhidao\zhidao.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\Plugins\zhidao\zhidao_plugin.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\skin\default.db (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound\msg.wav (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound\online.wav (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound\phone.wav (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound\snapshot.wav (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound\system.wav (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sound\winks.wav (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\0A6E06BBCB9501857BAFA74719D928F8.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\0ed289287d89a9c69a5d3a3736503680.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\0FBDFEB9BBC01F849D34D44C8BFEAE55.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\2698C2F9931AAB9B5F305B7CE6D6A950.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\63AF498CE8B260BF854EF2BCD59CAED7.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\6EBE180202B59EA6F59C9A433099C14F.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\SysBanner\defaultfrg.png (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b01.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b01_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b02.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b02_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b03.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b03_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b04.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b04_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b05.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b05_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b06.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b06_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b07.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b07_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b08.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b08_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b09.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b09_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b10.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b10_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b11.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b11_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b12.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b12_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b13.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b13_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b14.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b14_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b15.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b15_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b16_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b17.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b17_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b18.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b18_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b19.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b19_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b20.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b20_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b21.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b21_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b22.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b22_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b23.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b23_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b24.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b24_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b25.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b25_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b26.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b26_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b27.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b27_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b28.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b28_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b29.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b29_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b30.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b30_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b31.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b31_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b32.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b32_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b33.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b33_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b34.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b34_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b35.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b35_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b36.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b36_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b37.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b37_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b38.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b38_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b39.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b39_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b40.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b40_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b41.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b41_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b42.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b42_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b43.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b43_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b44.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b44_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b45.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b45_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b46.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b46_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b47.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b47_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b48.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b48_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b49.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b49_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b50.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b50_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b51.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b51_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b52.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b52_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b53.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b53_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b54.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b54_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b55.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b55_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b56.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b56_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b57.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b57_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b58.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b58_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b59.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b59_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b60.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b60_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b61.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b61_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b62.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\b62_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d01.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d01_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d02.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d02_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d03.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d03_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d04.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d04_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d05.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d05_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d06.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d06_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d07.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d07_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d08.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d08_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d09.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d09_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d10.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d10_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d11.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d11_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d12.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d12_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d13.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d13_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d14.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d14_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d15.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d15_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d16_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d17.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d17_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d18.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d18_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d19.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d19_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d20.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d20_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d21.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d21_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d22.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d22_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d23.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d23_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d24.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d24_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d25.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d25_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d26.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d26_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d27.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d27_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d28.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d28_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d29.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d29_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d30.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d30_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d31.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d31_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d32.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d32_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d33.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d33_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d34.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d34_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d35.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d35_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d36.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d36_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d37.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d37_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d38.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d38_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d39.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d39_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d40.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d40_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d41.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d41_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d42.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d42_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d43.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d43_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d44.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d44_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d45.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d45_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d46.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d46_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d47.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d47_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d48.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d48_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d49.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d49_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d50.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d50_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d51.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d51_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d52.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d52_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d53.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d53_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d54.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d54_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d55.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d55_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d56.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d56_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d57.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d57_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d58.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d58_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d59.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d59_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d60.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\d60_16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\face.xml (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y01.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y01_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y02.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y02_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y03.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y03_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y04.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y04_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y05.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y05_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y06.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y06_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y07.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y07_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y08.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y08_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y09.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y09_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y10.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y10_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y11.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y11_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y12.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y12_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y13.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y13_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y14.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y14_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y15.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y15_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y16.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y16_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y17.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y17_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y18.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y18_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y19.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y19_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y20.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y20_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y21.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y21_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y22.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y22_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y23.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y23_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y24.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y24_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y25.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y25_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y26.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y26_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y27.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y27_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y28.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y28_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y29.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y29_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y30.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y30_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y31.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y31_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y32.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y32_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y33.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y33_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y34.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y34_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y35.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y35_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y36.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y36_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y37.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y37_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y38.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y38_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y39.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y39_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y40.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y40_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y41.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y41_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y42.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y42_s.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baidu\Baidu Hi\sysface\y43.gif (Adware.Baidu) -> Quarantined and deleted successfully.
C:\Program Files (x86)\baid

Why can't you access the ESET log? It should be located at
C:\Program Files\EsetOnlineScanner\log.txt

Well, it is because some my notepad, workpad and microsoft are all not working on me and every time when I try to open the file it just says "Windows cannot find 'C:/Program'. Make sure you typed the name correctly, and try again. But I swear I put this exact thing in "C:\Program Files\EsetOnlineScanner\log.txt"

Did it find infections and remove them? Were you actually able to find the file by going into C:\Program Files\ ?

I don't understand when you say that my notepad, workpad and microsoft are all not working because you have been able to post all the other logs and they all would have first been in Notepad.

Yes, the program did find the infections and remove them and I used internet explorer as instructed. But when I go try to go into C:\Program Files\ it wasn't there.

Also I said my notepad, workpad and microsoft are all not working because they seem to be removed by the infection.

Yes, the program did find the infections and remove them and I used internet explorer as instructed. But when I go try to go into C:\Program Files\ it wasn't there.

Also I said my notepad, workpad and microsoft are all not working because they seem to be removed by the infection.

Ok, sometimes it doesn't save the log. If the above items were removed then how did you post the logs? In other words, how were they displayed to you as they are displayed in Notepad.

Which Microsoft program do you mean was removed?

Well, for the documents and files that was already created and saved, then I open it fine with the notepad, word-pad and Microsoft office word (Just like the two logs). But if I want to open notepad, word-pad and Microsoft office word, from the accessories, then it won't work. First when I try to open notepad it just gave me a pop up saying "Do you want to open or save this file", asking me to save some file. Secondly when I try yo open both the word-pad and the Microsoft office word, it will just say "Windows cannot access the specific device, path, or file. You may not have the appropriate permissions to access the item". But I am the administrator on the computer (vista).

Thanks, it wasn't that I didn't believe you I needed to know exactly what was happening.
I would like you to follow the following instructions exactly as given. Read them all very carefully before you proceed:

Please download ComboFix by sUBs from HERE or HERE
· You must download it to and run it from your Desktop
· Physically disconnect from the internet.
· Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
· Double click combofix.exe & follow the prompts. Sometimes if you are using Windows Vista you may receive UAC prompt asking if you would like to continue running the program, you should press the Continue button.
· When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
· Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Run Combofix ONCE only!!

Once it is complete run a new HJT scan and save the log. Post back here first with the Combofix log and then the HJT log.
Judy

The ComboFix by sUBs won't work with my computer which is windows vista 64-bits

Lordy, glad you caught that...it just totally slipped my mind! Glad you were paying attention!
Let's back up here...do you know what these two programs are?
Baidu Hi
NamiRobot

Most of the infected files were located in Baidu Hi and can find no info on the NamiRobot

Baidu Hi is just sort of like a yahoo messenger type of software where one can have a conversation with others user on there. And as for NamiRobot, it is a software for downloading large files like concerts, cds, etc...But I remove the application from the compute some time ago cause I find no use for it. Both of these are Chinese programs.

They BOTH need to go ASAP. Even though that NamiRobot was supposedly removed it is still listed in your HJT logs, so there are some remnants. The other one is most definitely malware and also must go.
Uninstall both, do a file search for any remaining parts and then update MBA-M again and do another Full Scan with it. Have it remove everything it finds.
Also clear all your temp files, cookies, etc. before you do the scan. Reboot following that MBA-M scan and do another HJT scan and post both logs.
Judy

MBA-M log:

Malwarebytes' Anti-Malware 1.44
Database version: 3919
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18882

3/26/2010 5:34:51 PM
mbam-log-2010-03-26 (17-34-51).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 326025
Time elapsed: 1 hour(s), 26 minute(s), 46 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

HJT log:

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 5:41:57 PM, on 3/26/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hp\QuickPlay\QPService.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe
C:\Windows\SysWOW64\conime.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\PROGRA~2\MICROS~1\wkcalrem.exe
C:\Program Files (x86)\TrendMicro\HiJackThis\HiJackThis.exe

R3 - Default URLSearchHook is missing
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: QvodExtend - {53AC8551-0DE0-4606-8A1E-A51AF20ADD60} - C:\Program Files (x86)\Common Files\System\Extend.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [QlbCtrl.exe] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /Start
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~2\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\New Folder\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\windows sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
O4 - HKCU\..\Run: [PPAP] C:\ProgramData\PPLiveVA\Application\PPAP.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jenny\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: &U使用米人下载并收藏 - C:\Program Files (x86)\NamiRobot\Data\du.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {09E90109-A9AA-4980-BCEF-76F8D924E902} - (no file)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {09E90109-A9AA-4980-BCEF-76F8D924E902} - (no file) (HKCU)
O13 - Gopher Prefix:
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter hijack: text/xml - (no CLSID) - (no file)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~2\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~2\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~2\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files (x86)\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 11888 bytes

You still have infection on there. Let me get one of the other Mods to take a look and one of us will get back with you.
Judy

Ok, thanks to crunchie, here you go:

Download OTL to your Desktop.

* Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
* Under the Custom Scan box paste this in:


netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\System32\config\*.sav
CREATERESTOREPOINT


* Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

* When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
* Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.

OTL logfile created on: 3/26/2010 9:51:03 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\Jenny\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 35.00% Memory free
8.00 Gb Paging File | 5.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 220.65 Gb Total Space | 125.35 Gb Free Space | 56.81% Space Free | Partition Type: NTFS
Drive D: | 12.23 Gb Total Space | 0.96 Gb Free Space | 7.85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JENNY-PC
Current User Name: Jenny
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/03/26 21:50:35 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Users\Jenny\Downloads\OTL.exe
PRC - [2010/03/23 17:59:24 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2010/03/09 09:17:17 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/10/29 07:54:44 | 001,218,008 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe
PRC - [2009/10/27 12:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\MPF\MpfSrv.exe
PRC - [2009/09/16 09:28:38 | 000,606,736 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/07/10 00:26:20 | 000,865,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe
PRC - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009/07/07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/10/06 12:54:52 | 000,365,952 | ---- | M] () -- C:\Program Files (x86)\SMINST\BLService.exe
PRC - [2008/01/20 21:49:12 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\conime.exe
PRC - [2007/06/21 00:04:52 | 000,046,432 | ---- | M] (Microsoft® Corporation) -- C:\Program Files (x86)\Microsoft Works\WkCalRem.exe


========== Modules (SafeList) ==========

MOD - [2010/03/26 21:50:35 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Users\Jenny\Downloads\OTL.exe
MOD - [2009/12/08 14:12:24 | 000,014,544 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\McAfee\SiteAdvisor\sahook.dll
MOD - [2008/01/20 21:50:03 | 000,450,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll
MOD - [2008/01/20 21:48:06 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/09/16 11:23:32 | 000,696,848 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV:64bit: - [2009/09/16 10:15:32 | 000,155,456 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
SRV:64bit: - [2008/01/20 21:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2007/10/17 18:37:22 | 000,412,672 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\DRIVERS\xaudio64.exe -- (XAudioService)
SRV - [2009/12/08 15:25:28 | 000,110,312 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2009/10/27 12:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - [2009/09/16 09:28:38 | 000,606,736 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
SRV - [2009/08/24 07:16:12 | 000,378,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2009/07/10 00:26:20 | 000,865,832 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
SRV - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
SRV - [2009/07/07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)
SRV - [2009/04/02 12:47:04 | 000,234,888 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe -- (ASKUpgrade)
SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/10/06 12:54:52 | 000,365,952 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\SMINST\BLService.exe -- (Recovery Service for Windows)
SRV - [2008/01/20 21:50:38 | 000,093,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
SRV - [2006/11/02 08:34:14 | 000,000,000 | ---D | M] [Unknown | Stopped] -- C:\Windows\SysWOW64\Msdtc -- (MSDTC)
SRV - [2006/11/02 01:35:15 | 000,060,994 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\vds.mof -- (vds)
SRV - [2006/11/02 01:35:15 | 000,055,846 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\vss.mof -- (VSS)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.9281.net/?cmd
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://hk.news.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = http://localhost:9000/application.pac

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://hk.news.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: txftn@tencent.com:1.0.0.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655


FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2010/02/26 18:48:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/09 09:20:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/03/23 17:59:27 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/03/23 17:59:27 | 000,000,000 | ---D | M]

[2009/02/20 10:33:47 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Mozilla\Extensions
[2010/03/26 15:44:55 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Mozilla\Firefox\Profiles\2zgbeljt.default\extensions
[2009/09/20 13:14:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenny\AppData\Roaming\Mozilla\Firefox\Profiles\2zgbeljt.default\extensions\{1B33E42F-EF14-4cd3-B6DC-174571C4349C}
[2009/12/27 18:37:48 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Jenny\AppData\Roaming\Mozilla\Firefox\Profiles\2zgbeljt.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/12/10 22:56:25 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Mozilla\Firefox\Profiles\2zgbeljt.default\extensions\txftn@tencent.com
[2010/03/11 14:46:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2009/09/24 05:04:52 | 000,075,568 | ---- | M] (ShenZhen Xunlei Networking Technologies,LTD) -- C:\Program Files (x86)\Mozilla Firefox\components\ThunderComponent.dll
[2009/03/30 17:13:54 | 000,098,304 | ---- | M] (RealNetworks) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npraclient.dll

O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (QvodExtend) - {53AC8551-0DE0-4606-8A1E-A51AF20ADD60} - C:\Program Files (x86)\Common Files\System\Extend.dll (Shenzhen QVOD Technology Co.,Ltd)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4064EA35-578D-4073-A834-C96D82CBCF40} - No CLSID value found.
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL ()
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL ()
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\New Folder\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files (x86)\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [PPAP] C:\ProgramData\PPLiveVA\Application\PPAP.exe File not found
O4 - Startup: C:\Users\Jenny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Jenny\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Jenny\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2008/01/20 22:06:38 | 000,000,000 | ---D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll ()
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll ()
NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008/01/20 22:08:35 | 000,000,000 | ---D | M]
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)
OTL cannot create restorepoints on Vista OSs!

========== Files/Folders - Created Within 14 Days ==========

[2010/03/26 15:50:28 | 000,000,000 | ---D | C] -- C:\Users\Jenny\Documents\Baidu
[2010/03/26 14:51:52 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2010/03/25 15:26:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TrendMicro
[2010/03/25 15:01:47 | 000,000,000 | ---D | C] -- C:\Users\Jenny\AppData\Roaming\Malwarebytes
[2010/03/25 15:01:39 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/03/25 15:01:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/03/25 15:01:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/03/25 00:28:44 | 000,000,000 | ---D | C] -- C:\Program Files\Registry Easy
[2010/03/24 22:52:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\iso
[2010/03/24 22:52:17 | 000,000,000 | ---D | C] -- C:\Users\Jenny\AppData\Roaming\JjlDownLoader
[2010/03/24 22:52:13 | 000,412,565 | -HS- | C] ( ) -- C:\Program Files (x86)\Common Files\360Safe.exe
[2010/03/24 22:51:34 | 000,000,000 | ---D | C] -- C:\Program Files\winrar
[2010/03/24 22:51:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Microsoft
[2010/03/24 22:51:22 | 000,000,000 | ---D | C] -- C:\Program Files\Kingsoft
[2010/03/18 23:22:16 | 000,000,000 | ---D | C] -- C:\Users\Jenny\AppData\Roaming\Nero
[2010/03/18 22:27:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Nero
[2010/03/18 22:27:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nero

========== Files - Modified Within 14 Days ==========

[2010/03/26 21:57:16 | 004,718,592 | -HS- | M] () -- C:\Users\Jenny\ntuser.dat
[2010/03/26 21:12:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-660015699-3099172772-2367458381-1000UA.job
[2010/03/26 20:53:32 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/26 20:53:32 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/26 20:10:28 | 000,046,905 | ---- | M] () -- C:\Windows\SysNative\Config.MPF
[2010/03/26 20:03:34 | 000,000,188 | ---- | M] () -- C:\Windows\tasks\ms.job
[2010/03/26 19:59:12 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{8B2AACFE-262C-469C-97D5-58A5FA70C8E6}.job
[2010/03/26 17:40:42 | 000,002,553 | ---- | M] () -- C:\Users\Jenny\Desktop\HiJackThis.lnk
[2010/03/26 13:01:23 | 000,690,960 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010/03/26 13:01:23 | 000,587,178 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010/03/26 13:01:23 | 000,101,250 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010/03/26 12:54:07 | 000,067,627 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/03/26 12:53:59 | 000,000,252 | ---- | M] () -- C:\ProgramData\hpqp.ini
[2010/03/26 12:53:44 | 000,000,386 | ---- | M] () -- C:\Windows\tasks\Reg Tool Startup.job
[2010/03/26 12:53:29 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/03/26 12:53:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/03/26 12:53:21 | 4024,881,152 | -HS- | M] () -- C:\hiberfil.sys
[2010/03/26 00:39:14 | 000,524,288 | -HS- | M] () -- C:\Users\Jenny\ntuser.dat{17c09dfa-5a0c-11de-bcb7-001f16663652}.TMContainer00000000000000000001.regtrans-ms
[2010/03/26 00:39:14 | 000,065,536 | -HS- | M] () -- C:\Users\Jenny\ntuser.dat{17c09dfa-5a0c-11de-bcb7-001f16663652}.TM.blf
[2010/03/26 00:38:38 | 004,200,269 | -H-- | M] () -- C:\Users\Jenny\AppData\Local\IconCache.db
[2010/03/25 16:50:52 | 000,007,592 | ---- | M] () -- C:\Users\Jenny\AppData\Local\d3d9caps.dat
[2010/03/25 15:01:43 | 000,000,848 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/25 12:00:15 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\PerfectOptimizer_home.job
[2010/03/25 12:00:00 | 000,000,446 | ---- | M] () -- C:\Windows\tasks\Reg Tool Scan.job
[2010/03/25 00:46:45 | 000,000,042 | ---- | M] () -- C:\Windows\SysWow64\RegistryEasy.lie
[2010/03/24 23:32:37 | 000,001,905 | ---- | M] () -- C:\Windows\diagwrn.xml
[2010/03/24 23:32:37 | 000,001,905 | ---- | M] () -- C:\Windows\diagerr.xml
[2010/03/24 22:52:25 | 000,000,011 | ---- | M] () -- C:\Windows\SysWow64\-1347-2419
[2010/03/24 22:52:10 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\notepad.exe.vbs
[2010/03/24 22:52:10 | 000,000,288 | ---- | M] () -- C:\Windows\SysWow64\cmd.exe.vbs
[2010/03/24 22:52:10 | 000,000,284 | ---- | M] () -- C:\Windows\explorer.exe.vbs
[2010/03/24 22:52:08 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\msiexec.exe.vbs
[2010/03/24 22:51:57 | 000,000,289 | ---- | M] () -- C:\Windows\SysWow64\msra.exe.vbs
[2010/03/24 22:51:54 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\control.exe.vbs
[2010/03/24 22:51:40 | 000,000,306 | ---- | M] () -- C:\Windows\SysWow64\WindowsAnytimeUpgrade.exe.vbs
[2010/03/24 22:51:36 | 000,000,293 | ---- | M] () -- C:\Windows\SysWow64\msconfig.exe.vbs
[2010/03/24 22:51:35 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\MdSched.exe.vbs
[2010/03/24 22:51:34 | 000,000,293 | ---- | M] () -- C:\Windows\SysWow64\iscsicpl.exe.vbs
[2010/03/24 22:51:30 | 000,000,293 | ---- | M] () -- C:\Windows\SysWow64\odbcad32.exe.vbs
[2010/03/24 22:51:28 | 000,000,298 | ---- | M] () -- C:\Windows\SysWow64\SoundRecorder.exe.vbs
[2010/03/24 22:51:28 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\mobsync.exe.vbs
[2010/03/24 22:51:28 | 000,000,290 | ---- | M] () -- C:\Windows\SysWow64\mstsc.exe.vbs
[2010/03/24 22:51:27 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\NetProj.exe.vbs
[2010/03/24 22:51:27 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\mspaint.exe.vbs
[2010/03/24 22:51:27 | 000,000,291 | ---- | M] () -- C:\Windows\SysWow64\mblctr.exe.vbs
[2010/03/24 22:51:27 | 000,000,289 | ---- | M] () -- C:\Windows\SysWow64\calc.exe.vbs
[2010/03/24 22:51:23 | 000,001,866 | R--- | M] () -- C:\Users\Public\Desktop\mozilla firefox.lnk
[2010/03/24 22:51:23 | 000,001,791 | R--- | M] () -- C:\Users\Public\Desktop\mcafee security center.lnk
[2010/03/24 22:51:22 | 000,001,782 | R--- | M] () -- C:\Users\Public\Desktop\mcafee easynetwork.lnk
[2010/03/24 22:51:20 | 000,064,981 | -HS- | M] () -- C:\Program Files (x86)\CCE51.exe
[2010/03/24 22:51:16 | 000,412,565 | -HS- | M] ( ) -- C:\Program Files (x86)\Common Files\360Safe.exe
[2010/03/19 16:09:09 | 000,027,136 | ---- | M] () -- C:\Users\Jenny\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/19 09:11:03 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-660015699-3099172772-2367458381-1000Core.job
[2010/03/19 09:09:51 | 000,015,797 | ---- | M] () -- C:\Users\Jenny\Documents\Proposal.docx
[2010/03/15 01:11:30 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\McDefragTask.job

========== Files Created - No Company Name ==========

[2010/03/25 15:26:07 | 000,002,553 | ---- | C] () -- C:\Users\Jenny\Desktop\HiJackThis.lnk
[2010/03/25 15:01:43 | 000,000,848 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/25 15:01:37 | 000,022,104 | ---- | C] () -- C:\Windows\SysNative\drivers\mbam.sys
[2010/03/25 12:22:14 | 000,212,864 | ---- | C] () -- C:\Windows\SysNative\MpSigStub.exe
[2010/03/25 00:46:45 | 000,000,042 | ---- | C] () -- C:\Windows\SysWow64\RegistryEasy.lie
[2010/03/24 23:51:38 | 000,422,780 | ---- | C] () -- C:\Users\Jenny\AppData\Local\dd_vcredistMSI474C.txt
[2010/03/24 23:51:35 | 000,010,666 | ---- | C] () -- C:\Users\Jenny\AppData\Local\dd_vcredistUI474F.txt
[2010/03/24 23:51:34 | 000,011,478 | ---- | C] () -- C:\Users\Jenny\AppData\Local\dd_vcredistUI474C.txt
[2010/03/24 23:25:38 | 000,001,905 | ---- | C] () -- C:\Windows\diagwrn.xml
[2010/03/24 23:25:38 | 000,001,905 | ---- | C] () -- C:\Windows\diagerr.xml
[2010/03/24 23:14:51 | 4024,881,152 | -HS- | C] () -- C:\hiberfil.sys
[2010/03/24 22:58:22 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\PerfectOptimizer_home.job
[2010/03/24 22:52:48 | 000,000,188 | ---- | C] () -- C:\Windows\tasks\ms.job
[2010/03/24 22:52:25 | 000,000,011 | ---- | C] () -- C:\Windows\SysWow64\-1347-2419
[2010/03/24 22:52:10 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\notepad.exe.vbs
[2010/03/24 22:52:10 | 000,000,288 | ---- | C] () -- C:\Windows\SysWow64\cmd.exe.vbs
[2010/03/24 22:52:10 | 000,000,284 | ---- | C] () -- C:\Windows\explorer.exe.vbs
[2010/03/24 22:52:08 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\msiexec.exe.vbs
[2010/03/24 22:51:57 | 000,000,289 | ---- | C] () -- C:\Windows\SysWow64\msra.exe.vbs
[2010/03/24 22:51:40 | 000,000,306 | ---- | C] () -- C:\Windows\SysWow64\WindowsAnytimeUpgrade.exe.vbs
[2010/03/24 22:51:36 | 000,000,293 | ---- | C] () -- C:\Windows\SysWow64\msconfig.exe.vbs
[2010/03/24 22:51:35 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\MdSched.exe.vbs
[2010/03/24 22:51:34 | 000,000,293 | ---- | C] () -- C:\Windows\SysWow64\iscsicpl.exe.vbs
[2010/03/24 22:51:30 | 000,000,293 | ---- | C] () -- C:\Windows\SysWow64\odbcad32.exe.vbs
[2010/03/24 22:51:28 | 000,000,298 | ---- | C] () -- C:\Windows\SysWow64\SoundRecorder.exe.vbs
[2010/03/24 22:51:28 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\mobsync.exe.vbs
[2010/03/24 22:51:28 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\control.exe.vbs
[2010/03/24 22:51:28 | 000,000,290 | ---- | C] () -- C:\Windows\SysWow64\mstsc.exe.vbs
[2010/03/24 22:51:27 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\NetProj.exe.vbs
[2010/03/24 22:51:27 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\mspaint.exe.vbs
[2010/03/24 22:51:27 | 000,000,291 | ---- | C] () -- C:\Windows\SysWow64\mblctr.exe.vbs
[2010/03/24 22:51:27 | 000,000,289 | ---- | C] () -- C:\Windows\SysWow64\calc.exe.vbs
[2010/03/24 22:51:21 | 000,064,981 | -HS- | C] () -- C:\Program Files (x86)\CCE51.exe
[2010/03/17 01:05:11 | 000,015,797 | ---- | C] () -- C:\Users\Jenny\Documents\Proposal.docx
[2010/03/13 00:01:06 | 000,000,908 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-660015699-3099172772-2367458381-1000UA.job
[2010/03/13 00:01:05 | 000,000,856 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-660015699-3099172772-2367458381-1000Core.job
[2009/12/31 15:14:36 | 000,000,552 | ---- | C] () -- C:\Users\Jenny\AppData\Local\d3d8caps.dat
[2009/09/25 00:06:40 | 000,000,000 | ---- | C] () -- C:\Users\Jenny\AppData\Roaming\FileStore.dll
[2009/09/16 23:17:54 | 000,237,568 | ---- | C] () -- C:\Windows\SysWow64\rmc_rtspdl.dll
[2009/07/30 06:06:08 | 000,000,294 | ---- | C] () -- C:\Users\Jenny\AppData\Roaming\wklnhst.dat
[2009/05/25 09:14:53 | 000,007,592 | ---- | C] () -- C:\Users\Jenny\AppData\Local\d3d9caps.dat
[2009/03/02 00:29:33 | 000,027,136 | ---- | C] () -- C:\Users\Jenny\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/20 12:01:19 | 000,000,021 | ---- | C] () -- C:\ProgramData\hpqp.txt
[2009/02/18 19:40:40 | 000,067,627 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/02/18 19:40:35 | 000,067,627 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/02/17 22:12:38 | 000,000,000 | ---- | C] () -- C:\Users\Jenny\AppData\Local\QSwitch.txt
[2009/02/17 22:12:38 | 000,000,000 | ---- | C] () -- C:\Users\Jenny\AppData\Local\DSwitch.txt
[2009/02/17 22:12:38 | 000,000,000 | ---- | C] () -- C:\Users\Jenny\AppData\Local\AtStart.txt
[2009/01/22 04:50:48 | 000,000,105 | ---- | C] () -- C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2009/01/22 04:50:38 | 000,000,032 | ---- | C] () -- C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2009/01/22 04:50:10 | 000,000,032 | ---- | C] () -- C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2009/01/22 04:49:33 | 000,000,032 | ---- | C] () -- C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2009/01/22 04:47:10 | 000,000,032 | ---- | C] () -- C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2009/01/22 04:46:45 | 000,000,252 | ---- | C] () -- C:\ProgramData\hpqp.ini
[2008/11/08 21:26:41 | 000,000,109 | ---- | C] () -- C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2008/11/08 21:19:08 | 000,000,110 | ---- | C] () -- C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2008/11/08 21:16:32 | 000,000,105 | ---- | C] () -- C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2008/11/08 21:14:46 | 000,000,107 | ---- | C] () -- C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2008/01/20 21:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 21:49:49 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2007/12/27 00:45:40 | 000,000,680 | ---- | C] () -- C:\Users\Jenny\AppData\Roaming\coreavc.ini
[2002/03/16 19:00:00 | 000,007,420 | ---- | C] () -- C:\Windows\UA000106.DLL

========== LOP Check ==========

[2009/09/25 00:02:56 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Any Video Converter
[2009/09/24 19:15:34 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Any Video Converter Professional
[2009/11/02 16:02:02 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/09/18 21:09:33 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\DMCache
[2009/08/15 00:10:09 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\FMZilla
[2009/11/19 22:24:35 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Geniesoft
[2009/09/18 21:02:29 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\GetRightToGo
[2009/09/18 21:09:34 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\IDM
[2009/06/18 18:32:57 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\iWin
[2010/03/24 22:53:20 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\JjlDownLoader
[2010/02/05 17:15:46 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Leadertech
[2009/09/24 19:54:30 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Opera
[2009/09/13 21:47:12 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\PlayFirst
[2009/11/26 16:36:58 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\PPLiveVA
[2009/12/18 12:31:32 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\PrimoPDF
[2009/02/20 10:46:45 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\SystemRequirementsLab
[2009/07/30 06:06:10 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Template
[2009/09/24 19:54:17 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\tencent
[2009/09/21 22:44:55 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Ulead Systems
[2009/09/18 20:44:01 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\uTorrent
[2009/09/19 23:00:22 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Watermark Master
[2009/03/02 13:46:32 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\WildTangent
[2010/03/15 01:11:30 | 000,000,340 | ---- | M] () -- C:\Windows\Tasks\McDefragTask.job
[2010/03/01 02:00:07 | 000,000,332 | ---- | M] () -- C:\Windows\Tasks\McQcTask.job
[2010/03/26 20:03:34 | 000,000,188 | ---- | M] () -- C:\Windows\Tasks\ms.job
[2010/03/25 12:00:15 | 000,000,374 | ---- | M] () -- C:\Windows\Tasks\PerfectOptimizer_home.job
[2010/03/25 12:00:00 | 000,000,446 | ---- | M] () -- C:\Windows\Tasks\Reg Tool Scan.job
[2010/03/26 12:53:44 | 000,000,386 | ---- | M] () -- C:\Windows\Tasks\Reg Tool Startup.job
[2010/03/26 12:53:29 | 000,032,562 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010/03/26 19:59:12 | 000,000,418 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{8B2AACFE-262C-469C-97D5-58A5FA70C8E6}.job

========== Purity Check ==========

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/01/20 21:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008/01/20 21:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/01/20 21:46:50 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2008/11/08 21:21:00 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=35137384FFB6FB4B4C3063CEB5DB34BE -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.20847_none_37d5e5fef5f86cf7\atapi.sys
[2008/11/08 21:21:00 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=B388797CAAB36D523840347CC6A39B96 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.22193_none_398211faf34b271a\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 06:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006/11/02 04:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 04:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 04:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2007/05/18 00:34:04 | 000,007,216 | ---- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 -- C:\Program Files (x86)\CyberLink\PowerDirector\EventLog.dll

< MD5 for: IASTORV.SYS >
[2008/01/20 21:46:59 | 000,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2008/01/20 21:51:03 | 000,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2008/01/20 21:48:28 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\SysWOW64\netlogon.dll
[2008/01/20 21:48:28 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\SysWOW64\netlogon.dll
[2008/01/20 21:48:28 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2008/01/20 21:46:54 | 000,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/20 21:50:28 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\SysWOW64\scecli.dll
[2008/01/20 21:50:28 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\SysWOW64\scecli.dll
[2008/01/20 21:50:28 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008/01/20 21:49:49 | 000,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\System32\config\*.sav >

========== Alternate Data Streams ==========

@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:8C35AEA7
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:661DFA1C
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:6152D44C
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:D1B5B4F1
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:A8ADE5D8
< End of report >

OTL Extras logfile created on: 3/26/2010 9:51:03 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\Jenny\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 35.00% Memory free
8.00 Gb Paging File | 5.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 220.65 Gb Total Space | 125.35 Gb Free Space | 56.81% Space Free | Partition Type: NTFS
Drive D: | 12.23 Gb Total Space | 0.96 Gb Free Space | 7.85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JENNY-PC
Current User Name: Jenny
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.hlp[@ = hlpfile] -- C:\Windows\SysWow64\winhlp32.exe File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\SysWow64\winhlp32.exe File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\SysWow64\winhlp32.exe %1 File not found
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" ()
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l ()
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] -- cmd.exe /s /k pushd "%V" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\SysWow64\winhlp32.exe %1 File not found
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0624C415-4607-4960-8447-F954827FFE31}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{14C42428-55AC-40AA-AF76-500151C3D069}" = rport=138 | protocol=17 | dir=out | app=system |
"{1E97106C-DA4C-4261-A08C-80EBA7E2EC10}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4A5273F2-736E-471A-9C38-A6F064CC70E4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{540D7B32-B440-4D64-89B9-BFE30DB474A8}" = rport=139 | protocol=6 | dir=out | app=system |
"{584ACAE1-32BF-4C1E-BD72-09653473F210}" = rport=137 | protocol=17 | dir=out | app=system |
"{5ECDF85A-61B5-4E10-A30C-C3A0B23339CD}" = lport=139 | protocol=6 | dir=in | app=system |
"{683A6361-B298-4C1B-A419-183A8CD2118C}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{70F550AF-D744-47E9-8588-08A5C4A4F4D5}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{72B16C33-5469-4A0C-ACA1-5EB56F88FC13}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{7BEAEEBE-912C-4C4E-B3FC-4563AD45C666}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{94026388-E8DE-4E04-A979-C97C95FCEB42}" = lport=138 | protocol=17 | dir=in | app=system |
"{969A6BCB-7C3B-4FC6-8EE6-F3CB7334E003}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{98F73437-77CF-43B1-9248-A9142DE1B31D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{AFCD84FC-54F9-4137-A5F6-988E2A7F6CFA}" = lport=137 | protocol=17 | dir=in | app=system |
"{B0F7499A-E43F-430A-93BC-6B5F23EC2428}" = lport=445 | protocol=6 | dir=in | app=system |
"{DD6A9A1D-C670-44E5-A637-7E2C99C538A6}" = rport=445 | protocol=6 | dir=out | app=system |
"{EDDBDF95-8D57-4BCD-9F8A-DADD4F3C59F2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03B112A3-543A-4F56-A9AF-C4E7F5A411CC}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{048BD47F-A9EF-4FD2-800E-D89BBAD1569B}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\xlbugreport.exe |
"{07C42EB0-47F2-4B16-BA52-DD9068088AB3}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderservice.exe |
"{0C9D174D-608B-45F5-B722-653B5717FB24}" = protocol=6 | dir=in | app=c:\program files (x86)\thunder network\thunder\program\filelink\xlfilelink.exe |
"{13903593-00C3-4C8C-ACC5-A9475EF3425D}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderliveud.exe |
"{17FA50B7-F92E-47AF-BFAB-A9F1B3F04C00}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderliveud.exe |
"{1815A7B2-0B3E-495D-BEF9-91297CD84E40}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderservice.exe |
"{18470DDA-9566-44E6-BAA2-E8ABBED594CB}" = protocol=6 | dir=in | app=c:\program files (x86)\ppliveva\flvpick.exe |
"{186581D0-AF0F-453C-B7F1-231F21FEE83A}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\xlbugreport.exe |
"{1D11F5B8-3688-482C-98AC-8A1D362F4B37}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\xlbugreport.exe |
"{1E11A06A-5BA4-4D5F-B57E-A2CE8D3E1E9F}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderliveud.exe |
"{214853C8-E65D-4B21-91CC-F5D59FFD5A4D}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderservice.exe |
"{22F3BF2B-6151-4283-A038-310AC1951FD2}" = protocol=6 | dir=in | app=c:\program files (x86)\ppliveva\download.exe |
"{233C61C4-D4BB-4D84-94F7-BE3CD38B57C5}" = protocol=6 | dir=in | app=c:\program files (x86)\pplive\ppliveu.exe |
"{264D04F0-23A5-427B-A544-9DBF3B220D05}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{2C0DC766-AD73-41AC-B0BA-E4D26759C818}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\xlbugreport.exe |
"{2DF73800-821F-4D70-938F-9A5A3AA862A2}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderliveud.exe |
"{2F8A57F8-1538-464A-803D-0C153768299B}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderliveud.exe |
"{314D4322-0F59-4150-96CC-2C599146653E}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderliveud.exe |
"{35C879E8-D437-46E4-A269-F4BEEAAE60FA}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\xlbugreport.exe |
"{39975BC0-EC1A-477B-8EEC-656C8F77EE45}" = protocol=17 | dir=in | app=c:\program files (x86)\ppliveva\download.exe |
"{3A99D011-1C64-4D82-B2E8-19E1567E413E}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderservice.exe |
"{3D63C661-99BF-48E6-A300-93AF0B6AECA4}" = protocol=17 | dir=in | app=c:\program files (x86)\ppliveva\crashupload.exe |
"{3DA9E2B9-683E-4226-A152-142F5246BA5A}" = protocol=6 | dir=in | app=c:\programdata\ppliveva\application\ppap.exe |
"{3FE3D185-7284-43FA-81A9-6549378C2B31}" = protocol=17 | dir=in | app=c:\program files (x86)\ppliveva\flvpick.exe |
"{42977B21-6E35-47FA-89B5-4A851A3DD54B}" = protocol=6 | dir=in | app=c:\program files (x86)\ppliveva\downloadprogress.exe |
"{43EFF98D-7D20-4593-9A02-710F11AEB542}" = dir=in | app=c:\program files (x86)\hp\quickplay\qp.exe |
"{4690638E-5783-45F9-B2A3-EDD4A193A810}" = protocol=17 | dir=in | app=c:\program files (x86)\thunder network\thunder\program\filelink\xlfilelink.exe |
"{46C4B36A-5A7C-4C11-85F2-B2DD2511F757}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{470D5734-13B1-439C-97F3-37ADF7AEBF13}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\xlbugreport.exe |
"{4C64AB6F-CEEB-42A9-AF53-12B629C352ED}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderservice.exe |
"{62B7D8DD-48FB-4C29-BB03-840B68380F69}" = protocol=17 | dir=in | app=c:\program files (x86)\thunder network\thunder\program\filelink\xlfilelink.exe |
"{64A4F66A-43A9-430B-B5BC-B9A8383445B9}" = dir=in | app=c:\program files (x86)\common files\mcafee\mna\mcnasvc.exe |
"{64E17656-3750-4F05-9834-9B0C12E1266D}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderservice.exe |
"{673AB00A-E16B-45F2-8435-7D58AC53331C}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderliveud.exe |
"{6827F5FA-0E3B-4BFF-9525-38E28B2DDE49}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{6AD9123A-18F8-4499-96AA-3CB1F732C456}" = protocol=6 | dir=in | app=c:\users\jenny\appdata\local\temp\~nsu.tmp\bu_.exe |
"{6B57C876-00D8-4A4E-9E84-572AD9F7DB3B}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\xlbugreport.exe |
"{7229587D-66AB-442A-A03D-C1179F9A4B66}" = protocol=17 | dir=in | app=c:\program files (x86)\thunder network\thunder\program\filelink\xlfilelink.exe |
"{770B2F2A-6507-48F9-B40C-21923B20D3FE}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderliveud.exe |
"{7F968096-3709-442E-8179-2B30E0FA1F70}" = protocol=17 | dir=in | app=c:\program files (x86)\ppliveva\ppliveva.exe |
"{813F6E8F-1867-4886-9E81-3DC1561E376C}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderservice.exe |
"{8649F3E1-EBC9-4573-B0B4-7BA167BCA5BD}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderservice.exe |
"{8C0493EE-91D4-4990-B6A7-EBAFDDDC2C8D}" = protocol=6 | dir=in | app=c:\program files (x86)\ppliveva\crashupload.exe |
"{8C89AFC2-8910-455F-89B3-F27B8517B06A}" = protocol=6 | dir=in | app=c:\program files (x86)\thunder network\thunder\program\filelink\xlfilelink.exe |
"{8DE8B646-6606-4F5B-8BC1-44DE0F1B9BCB}" = protocol=6 | dir=in | app=c:\program files (x86)\thunder network\thunder\program\filelink\xlfilelink.exe |
"{9216AD78-54FD-45D8-BA23-C5AE5DB31EE4}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\xlbugreport.exe |
"{960E29A1-3FB6-432C-88DC-A343FF0CF5FA}" = protocol=17 | dir=in | app=c:\program files (x86)\ppliveva\downloadprogress.exe |
"{9DDC1CAA-F8F3-418F-9BE3-8ABCD09B414E}" = dir=in | app=c:\program files (x86)\hp\quickplay\qpservice.exe |
"{9E540B1B-9C50-42AC-AE3C-BD6E17311749}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{9F233040-D5D1-42DF-83F7-60EFDF3057E4}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderservice.exe |
"{9F709083-A78C-48D7-8E04-D1B412A0A18F}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{9F8B460B-74DF-4DBA-A493-39E4BF7E73FA}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderliveud.exe |
"{A05B8CD8-4390-4F8D-9615-EF09D1884E19}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderservice.exe |
"{A3F062DD-86CB-4A87-9981-0C765FF7AD4D}" = protocol=6 | dir=in | app=c:\program files (x86)\thunder network\thunder\program\filelink\xlfilelink.exe |
"{A8834924-318C-40E5-B90B-E5CA46EE773F}" = protocol=17 | dir=in | app=c:\program files (x86)\thunder network\thunder\program\filelink\xlfilelink.exe |
"{ABE692D5-8063-4FA7-A35B-ECD9999ADC98}" = protocol=17 | dir=in | app=c:\programdata\ppliveva\application\ppap.exe |
"{AD98B452-2CCC-4630-8426-A58E9E16D69D}" = protocol=17 | dir=in | app=c:\program files (x86)\thunder network\thunder\program\filelink\xlfilelink.exe |
"{AE5FFD9C-D541-4D64-8029-2C53B2D537A3}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{B26E1578-F096-4434-87DB-974A47BA4127}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{B8DB815E-3345-435B-B1CF-C0DBB73B063A}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{BE5B9D95-4CF0-4046-93F1-AABEEF429420}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderservice.exe |
"{BF6DEC55-61A4-42C3-9E37-7F5BB36B1362}" = protocol=6 | dir=in | app=c:\program files (x86)\thunder network\thunder\program\filelink\xlfilelink.exe |
"{C5C1CCF3-E8E4-40F8-AEF3-65A61C549B04}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{CA441A2D-8304-4DEB-B010-4B6ADEC9327E}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{CD375CD0-AEA5-48C3-B60D-1ED76CFE7C7E}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderliveud.exe |
"{CF2BA034-79A4-4FCB-94EF-9B4B28F45669}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{D38C4BA4-4759-40D4-BBB3-4636F6D6F8EC}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderservice.exe |
"{D53EBFB4-B454-429F-AE61-32EABEA404C7}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderliveud.exe |
"{D736EAA3-E974-485A-886F-0DD1C1927C11}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\xlbugreport.exe |
"{DA36CCF4-D177-4C2B-B75A-FD1A19B4270B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{DD20AAE3-FB92-4ED9-9AA2-0620784EF87D}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\xlbugreport.exe |
"{DD29247D-28E8-4903-BF7F-F93F29B3BCB5}" = protocol=17 | dir=in | app=c:\program files (x86)\pplive\ppliveu.exe |
"{DDFAB6A4-7CBE-4E07-ACEE-16CF70421D77}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\xlbugreport.exe |
"{E124AE0E-8150-4BAA-B3AC-0BACF56EE1A8}" = protocol=6 | dir=in | app=c:\program files (x86)\ppliveva\ppliveva.exe |
"{E1DBA3BA-CE0F-4C11-B2BE-92CD14CE37F9}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{E9C9AE17-2FCE-468F-B1C7-64953317F829}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\xlbugreport.exe |
"{FBE048E0-3772-4037-9D9E-3DF7308AB4F8}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\thunder network\ds\ver1\1.0.2.35\thunderliveud.exe |
"TCP Query User{3E392000-DD5C-4580-9414-25C5F9F0F530}C:\program files (x86)\gridservice\peer.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gridservice\peer.exe |
"TCP Query User{59393505-2E57-4176-9052-CB8FB411A6F0}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"TCP Query User{617D5FE1-733D-4EF9-8F43-216995F34684}C:\program files (x86)\baidu\baidu hi\baiduhi.exe" = protocol=6 | dir=in | app=c:\program files (x86)\baidu\baidu hi\baiduhi.exe |
"TCP Query User{8385EC14-18AB-4016-8352-49D92A81DEF9}C:\program files (x86)\pplive\pplive.exe" = protocol=6 | dir=in | app=c:\program files (x86)\pplive\pplive.exe |
"UDP Query User{028D081C-08EE-47B5-AEC5-340358B568C8}C:\program files (x86)\gridservice\peer.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gridservice\peer.exe |
"UDP Query User{4A30E89F-FC12-4948-AFB8-D5E885A4E42D}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{839205C0-6816-4AE7-A76D-1E93835DE1FB}C:\program files (x86)\baidu\baidu hi\baiduhi.exe" = protocol=17 | dir=in | app=c:\program files (x86)\baidu\baidu hi\baiduhi.exe |
"UDP Query User{BEA93171-7CB9-4DD1-8453-8B41376A09AF}C:\program files (x86)\pplive\pplive.exe" = protocol=17 | dir=in | app=c:\program files (x86)\pplive\pplive.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9EFC40E3-5F31-4F75-8445-286273F74D8E}" = Apple Mobile Device Support
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{B812FCC0-6192-4BFA-A9C6-1E8578F255DA}" = iTunes
"{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"NVIDIA Drivers" = NVIDIA Drivers
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}" = HiJackThis
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 18
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{6423EF83-6E1D-4D22-A36F-689CD19FD4D2}" = Juno Preloader
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{846DDADA-0239-4B67-A6B1-33658863793B}" = HPTCSSetup
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96384578-C6A2-4EC6-92CD-B62A60713040}" = Microsoft Live Search Toolbar
"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B6D0B141-B2BE-4DD0-B08F-B9186F3E36B3}" = HP User Guides 0118
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}" = muvee Reveal
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Ask Toolbar_is1" = Ask Toolbar
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.6.2)" = Mozilla Firefox (3.6.2)
"MSC" = McAfee SecurityCenter
"RealPlayer 12.0" = RealPlayer
"SystemRequirementsLab" = System Requirements Lab
"WildTangent hp Master Uninstall" = My HP Games
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/25/2010 12:53:47 PM | Computer Name = Jenny-PC | Source = ESENT | ID = 447
Description = Catalog Database (1128) Catalog Database: A bad page link (error -327)
has been detected in a B-Tree (ObjectId: 8, PgnoRoot: 35) of database C:\Windows\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
(1305 => 130, 2301).

Error - 3/25/2010 12:55:07 PM | Computer Name = Jenny-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18882, time stamp
0x4b3ed243, faulting module msxml6.dll_unloaded, version 0.0.0.0, time stamp 0x4ba2d44f,
exception code 0xc0000005, fault offset 0x02b12e1d, process id 0xb84, application
start time 0x01cacc3bca85c51c.

Error - 3/25/2010 12:56:11 PM | Computer Name = Jenny-PC | Source = ESENT | ID = 447
Description = Catalog Database (1128) Catalog Database: A bad page link (error -327)
has been detected in a B-Tree (ObjectId: 8, PgnoRoot: 35) of database C:\Windows\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
(880 => 2303, 680).

Error - 3/25/2010 12:56:38 PM | Computer Name = Jenny-PC | Source = ESENT | ID = 447
Description = Catalog Database (1128) Catalog Database: A bad page link (error -327)
has been detected in a B-Tree (ObjectId: 8, PgnoRoot: 35) of database C:\Windows\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
(397 => 2299, 1235).

Error - 3/25/2010 12:57:38 PM | Computer Name = Jenny-PC | Source = ESENT | ID = 447
Description = Catalog Database (1128) Catalog Database: A bad page link (error -327)
has been detected in a B-Tree (ObjectId: 8, PgnoRoot: 35) of database C:\Windows\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
(397 => 2299, 1235).

Error - 3/25/2010 12:58:11 PM | Computer Name = Jenny-PC | Source = ESENT | ID = 447
Description = Catalog Database (1128) Catalog Database: A bad page link (error -327)
has been detected in a B-Tree (ObjectId: 8, PgnoRoot: 35) of database C:\Windows\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
(1305 => 130, 2301).

Error - 3/25/2010 12:58:29 PM | Computer Name = Jenny-PC | Source = ESENT | ID = 447
Description = Catalog Database (1128) Catalog Database: A bad page link (error -327)
has been detected in a B-Tree (ObjectId: 8, PgnoRoot: 35) of database C:\Windows\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
(1305 => 130, 2301).

Error - 3/25/2010 12:59:02 PM | Computer Name = Jenny-PC | Source = ESENT | ID = 447
Description = Catalog Database (1128) Catalog Database: A bad page link (error -327)
has been detected in a B-Tree (ObjectId: 8, PgnoRoot: 35) of database C:\Windows\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
(1305 => 130, 2301).

Error - 3/25/2010 12:59:36 PM | Computer Name = Jenny-PC | Source = ESENT | ID = 447
Description = Catalog Database (1128) Catalog Database: A bad page link (error -327)
has been detected in a B-Tree (ObjectId: 8, PgnoRoot: 35) of database C:\Windows\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
(397 => 2299, 1235).

Error - 3/25/2010 12:59:51 PM | Computer Name = Jenny-PC | Source = ESENT | ID = 447
Description = Catalog Database (1128) Catalog Database: A bad page link (error -327)
has been detected in a B-Tree (ObjectId: 8, PgnoRoot: 35) of database C:\Windows\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
(880 => 2303, 680).

[ System Events ]
Error - 3/26/2010 2:12:28 PM | Computer Name = Jenny-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 3/26/2010 2:12:28 PM | Computer Name = Jenny-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 3/26/2010 2:12:28 PM | Computer Name = Jenny-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 3/26/2010 2:12:28 PM | Computer Name = Jenny-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 3/26/2010 2:12:28 PM | Computer Name = Jenny-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 3/26/2010 2:12:28 PM | Computer Name = Jenny-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 3/26/2010 2:15:31 PM | Computer Name = Jenny-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 3/26/2010 2:15:31 PM | Computer Name = Jenny-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 3/26/2010 7:00:15 PM | Computer Name = Jenny-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 3/26/2010 8:16:04 PM | Computer Name = Jenny-PC | Source = bowser | ID = 8003
Description =


< End of report >

Thanks so much for your time.

Now we have to wait for either crunchie or PhilliePhan to take a look at this log because this is a tool I don't work with. One of them will get back with you on this as soon as they can go through the log, which as you can see, is quite extensive. So hang in there.
Judy

Ok, now this is going to take several steps. You need to do the following first: Do a search for each one of these files and when you find each one then copy it to the "C" drive. Once you have all copied to the "C" drive then report back here and I will give you the next step.
Here are the files you need to look for:
notepad.exe
cmd.exe
explorer.exe
msiexec.exe
msra.exe
control.exe
WindowsAnytimeUpgrade.exe
msconfig.exe
MdSched.exe
iscsicpl.exe
odbcad32.exe
SoundRecorder.exe
mobsync.exe
mstsc.exe
NetProj.exe
mspaint.exe
mblctr.exe
calc.exe

There are 18 files you will need to find and then copy to the "C" drive. Please make note of any you cannot find and note them here. Note they ALL end with .exe those are the good files. The ones we will need to replace with those in the next step are ones with the same name but the infection has created files with the same name BUT with .vbs as the file extension AFTER the .exe so we DON'T want those copied.
Do the search, save to "C" drive and then report back here for the next step.
Judy

OK. I have found all 18 of them and copied to the "C" drive.

Run OTL

* Under the Custom Scans/Fixes box at the bottom, paste in the following;

:files
C:\Windows\SysWow64\notepad.exe.vbs|c:\notepad.exe/replace
C:\Windows\SysWow64\cmd.exe.vbs|c:\cmd.exe/replace
C:\Windows\explorer.exe.vbs|c:\explorer.exe/replace
C:\Windows\SysWow64\msiexec.exe.vbs|c:\msiexec.exe/replace
C:\Windows\SysWow64\msra.exe.vbs|c:\msra.exe/replace
C:\Windows\SysWow64\control.exe.vbs|c:\control.exe /replace
C:\Windows\SysWow64\WindowsAnytimeUpgrade.exe.vbs|c:\WindowsAnytimeUpgrade.exe /replace
C:\Windows\SysWow64\msconfig.exe.vbs|c:\msconfig.exe /replace
C:\Windows\SysWow64\MdSched.exe.vbs|c:\MdSched.exe/replace
C:\Windows\SysWow64\iscsicpl.exe.vbs|c:\iscsicpl.exe /replace
C:\Windows\SysWow64\odbcad32.exe.vbs|c:\odbcad32.exe /replace
C:\Windows\SysWow64\SoundRecorder.exe.vbs|c:\SoundRecorder.exe/replace
C:\Windows\SysWow64\mobsync.exe.vbs|c:\mobsync.exe/replace
C:\Windows\SysWow64\mstsc.exe.vbs|c:\mstsc.exe/replace
C:\Windows\SysWow64\NetProj.exe.vbs|c:\NetProj.exe/replace
C:\Windows\SysWow64\mspaint.exe.vbs|c:\mspaint.exe/replace
C:\Windows\SysWow64\mblctr.exe.vbs|c:\mblctr.exe/replace
C:\Windows\SysWow64\calc.exe.vbs|c:\calc.exe/replace


:Commands
[emptytemp]
[resethosts]
[Reboot]

Then click the Run Fix button at the top

Let the program run unhindered, reboot the PC when it is done

Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Here is the log:

OTL logfile created on: 3/27/2010 12:47:02 PM - Run 2
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\Jenny\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 55.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 220.65 Gb Total Space | 126.75 Gb Free Space | 57.44% Space Free | Partition Type: NTFS
Drive D: | 12.23 Gb Total Space | 0.96 Gb Free Space | 7.85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JENNY-PC
Current User Name: Jenny
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/03/26 21:50:35 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Users\Jenny\Downloads\OTL.exe
PRC - [2010/03/23 17:59:24 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2010/03/09 09:17:17 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/10/29 07:54:44 | 001,218,008 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe
PRC - [2009/10/27 12:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\MPF\MpfSrv.exe
PRC - [2009/09/16 09:28:38 | 000,606,736 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/07/10 00:26:20 | 000,865,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe
PRC - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009/07/07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/10/06 12:54:52 | 000,365,952 | ---- | M] () -- C:\Program Files (x86)\SMINST\BLService.exe
PRC - [2008/01/20 21:49:12 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\conime.exe


========== Modules (SafeList) ==========

MOD - [2010/03/26 21:50:35 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Users\Jenny\Downloads\OTL.exe
MOD - [2009/12/08 14:12:24 | 000,014,544 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\McAfee\SiteAdvisor\sahook.dll
MOD - [2008/01/20 21:50:03 | 000,450,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll
MOD - [2008/01/20 21:48:06 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/09/16 11:23:32 | 000,696,848 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV:64bit: - [2009/09/16 10:15:32 | 000,155,456 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
SRV:64bit: - [2008/01/20 21:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2007/10/17 18:37:22 | 000,412,672 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\DRIVERS\xaudio64.exe -- (XAudioService)
SRV - [2009/12/08 15:25:28 | 000,110,312 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2009/10/27 12:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - [2009/09/16 09:28:38 | 000,606,736 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
SRV - [2009/07/10 00:26:20 | 000,865,832 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
SRV - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
SRV - [2009/07/07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)
SRV - [2009/04/02 12:47:04 | 000,234,888 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe -- (ASKUpgrade)
SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/10/06 12:54:52 | 000,365,952 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\SMINST\BLService.exe -- (Recovery Service for Windows)
SRV - [2008/01/20 21:50:38 | 000,093,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
SRV - [2006/11/02 08:34:14 | 000,000,000 | ---D | M] [Unknown | Stopped] -- C:\Windows\SysWOW64\Msdtc -- (MSDTC)
SRV - [2006/11/02 01:35:15 | 000,060,994 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\vds.mof -- (vds)
SRV - [2006/11/02 01:35:15 | 000,055,846 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\vss.mof -- (VSS)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.9281.net/?cmd
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://hk.news.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = http://localhost:9000/application.pac

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://hk.news.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: txftn@tencent.com:1.0.0.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655


FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2010/02/26 18:48:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/09 09:20:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/03/23 17:59:27 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/03/23 17:59:27 | 000,000,000 | ---D | M]

[2009/02/20 10:33:47 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Mozilla\Extensions
[2010/03/26 15:44:55 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Mozilla\Firefox\Profiles\2zgbeljt.default\extensions
[2009/09/20 13:14:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Jenny\AppData\Roaming\Mozilla\Firefox\Profiles\2zgbeljt.default\extensions\{1B33E42F-EF14-4cd3-B6DC-174571C4349C}
[2009/12/27 18:37:48 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Jenny\AppData\Roaming\Mozilla\Firefox\Profiles\2zgbeljt.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/12/10 22:56:25 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Mozilla\Firefox\Profiles\2zgbeljt.default\extensions\txftn@tencent.com
[2010/03/11 14:46:55 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2009/09/24 05:04:52 | 000,075,568 | ---- | M] (ShenZhen Xunlei Networking Technologies,LTD) -- C:\Program Files (x86)\Mozilla Firefox\components\ThunderComponent.dll
[2009/03/30 17:13:54 | 000,098,304 | ---- | M] (RealNetworks) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npraclient.dll

O1 HOSTS File: ([2010/03/27 12:40:57 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (QvodExtend) - {53AC8551-0DE0-4606-8A1E-A51AF20ADD60} - C:\Program Files (x86)\Common Files\System\Extend.dll (Shenzhen QVOD Technology Co.,Ltd)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4064EA35-578D-4073-A834-C96D82CBCF40} - No CLSID value found.
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL ()
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL ()
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\New Folder\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files (x86)\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [PPAP] C:\ProgramData\PPLiveVA\Application\PPAP.exe File not found
O4 - Startup: C:\Users\Jenny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O18 - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Jenny\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Jenny\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 14 Days ==========

[2010/03/27 12:38:53 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/03/26 15:50:28 | 000,000,000 | ---D | C] -- C:\Users\Jenny\Documents\Baidu
[2010/03/26 14:51:52 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2010/03/25 15:26:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TrendMicro
[2010/03/25 15:01:47 | 000,000,000 | ---D | C] -- C:\Users\Jenny\AppData\Roaming\Malwarebytes
[2010/03/25 15:01:39 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/03/25 15:01:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/03/25 15:01:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/03/25 00:28:44 | 000,000,000 | ---D | C] -- C:\Program Files\Registry Easy
[2010/03/24 22:52:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\iso
[2010/03/24 22:52:17 | 000,000,000 | ---D | C] -- C:\Users\Jenny\AppData\Roaming\JjlDownLoader
[2010/03/24 22:52:13 | 000,412,565 | -HS- | C] ( ) -- C:\Program Files (x86)\Common Files\360Safe.exe
[2010/03/24 22:51:34 | 000,000,000 | ---D | C] -- C:\Program Files\winrar
[2010/03/24 22:51:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Microsoft
[2010/03/24 22:51:22 | 000,000,000 | ---D | C] -- C:\Program Files\Kingsoft
[2010/03/18 23:22:16 | 000,000,000 | ---D | C] -- C:\Users\Jenny\AppData\Roaming\Nero
[2010/03/18 22:27:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Nero
[2010/03/18 22:27:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nero

========== Files - Modified Within 14 Days ==========

[2010/03/27 12:51:07 | 004,718,592 | -HS- | M] () -- C:\Users\Jenny\ntuser.dat
[2010/03/27 12:50:33 | 000,690,960 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010/03/27 12:50:33 | 000,587,178 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010/03/27 12:50:33 | 000,101,250 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010/03/27 12:43:44 | 000,046,905 | ---- | M] () -- C:\Windows\SysNative\Config.MPF
[2010/03/27 12:43:41 | 000,067,627 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/03/27 12:43:40 | 000,000,252 | ---- | M] () -- C:\ProgramData\hpqp.ini
[2010/03/27 12:43:22 | 000,000,386 | ---- | M] () -- C:\Windows\tasks\Reg Tool Startup.job
[2010/03/27 12:43:18 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/27 12:43:18 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/27 12:43:13 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/03/27 12:43:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/03/27 12:42:47 | 4024,881,152 | -HS- | M] () -- C:\hiberfil.sys
[2010/03/27 12:41:42 | 000,524,288 | -HS- | M] () -- C:\Users\Jenny\ntuser.dat{17c09dfa-5a0c-11de-bcb7-001f16663652}.TMContainer00000000000000000001.regtrans-ms
[2010/03/27 12:41:42 | 000,065,536 | -HS- | M] () -- C:\Users\Jenny\ntuser.dat{17c09dfa-5a0c-11de-bcb7-001f16663652}.TM.blf
[2010/03/27 12:41:16 | 004,294,087 | -H-- | M] () -- C:\Users\Jenny\AppData\Local\IconCache.db
[2010/03/27 12:12:08 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-660015699-3099172772-2367458381-1000UA.job
[2010/03/27 00:00:03 | 000,000,188 | ---- | M] () -- C:\Windows\tasks\ms.job
[2010/03/26 19:59:12 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{8B2AACFE-262C-469C-97D5-58A5FA70C8E6}.job
[2010/03/26 17:40:42 | 000,002,553 | ---- | M] () -- C:\Users\Jenny\Desktop\HiJackThis.lnk
[2010/03/25 16:50:52 | 000,007,592 | ---- | M] () -- C:\Users\Jenny\AppData\Local\d3d9caps.dat
[2010/03/25 15:01:43 | 000,000,848 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/25 12:00:15 | 000,000,374 | ---- | M] () -- C:\Windows\tasks\PerfectOptimizer_home.job
[2010/03/25 12:00:00 | 000,000,446 | ---- | M] () -- C:\Windows\tasks\Reg Tool Scan.job
[2010/03/25 00:46:45 | 000,000,042 | ---- | M] () -- C:\Windows\SysWow64\RegistryEasy.lie
[2010/03/24 23:32:37 | 000,001,905 | ---- | M] () -- C:\Windows\diagwrn.xml
[2010/03/24 23:32:37 | 000,001,905 | ---- | M] () -- C:\Windows\diagerr.xml
[2010/03/24 22:52:25 | 000,000,011 | ---- | M] () -- C:\Windows\SysWow64\-1347-2419
[2010/03/24 22:52:10 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\notepad.exe.vbs
[2010/03/24 22:52:10 | 000,000,288 | ---- | M] () -- C:\Windows\SysWow64\cmd.exe.vbs
[2010/03/24 22:52:10 | 000,000,284 | ---- | M] () -- C:\Windows\explorer.exe.vbs
[2010/03/24 22:52:08 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\msiexec.exe.vbs
[2010/03/24 22:51:57 | 000,000,289 | ---- | M] () -- C:\Windows\SysWow64\msra.exe.vbs
[2010/03/24 22:51:35 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\MdSched.exe.vbs
[2010/03/24 22:51:28 | 000,000,298 | ---- | M] () -- C:\Windows\SysWow64\SoundRecorder.exe.vbs
[2010/03/24 22:51:28 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\mobsync.exe.vbs
[2010/03/24 22:51:28 | 000,000,290 | ---- | M] () -- C:\Windows\SysWow64\mstsc.exe.vbs
[2010/03/24 22:51:27 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\NetProj.exe.vbs
[2010/03/24 22:51:27 | 000,000,292 | ---- | M] () -- C:\Windows\SysWow64\mspaint.exe.vbs
[2010/03/24 22:51:27 | 000,000,291 | ---- | M] () -- C:\Windows\SysWow64\mblctr.exe.vbs
[2010/03/24 22:51:27 | 000,000,289 | ---- | M] () -- C:\Windows\SysWow64\calc.exe.vbs
[2010/03/24 22:51:23 | 000,001,866 | R--- | M] () -- C:\Users\Public\Desktop\mozilla firefox.lnk
[2010/03/24 22:51:23 | 000,001,791 | R--- | M] () -- C:\Users\Public\Desktop\mcafee security center.lnk
[2010/03/24 22:51:22 | 000,001,782 | R--- | M] () -- C:\Users\Public\Desktop\mcafee easynetwork.lnk
[2010/03/24 22:51:20 | 000,064,981 | -HS- | M] () -- C:\Program Files (x86)\CCE51.exe
[2010/03/24 22:51:16 | 000,412,565 | -HS- | M] ( ) -- C:\Program Files (x86)\Common Files\360Safe.exe
[2010/03/19 16:09:09 | 000,027,136 | ---- | M] () -- C:\Users\Jenny\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/19 09:11:03 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-660015699-3099172772-2367458381-1000Core.job
[2010/03/19 09:09:51 | 000,015,797 | ---- | M] () -- C:\Users\Jenny\Documents\Proposal.docx
[2010/03/15 01:11:30 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\McDefragTask.job

========== Files Created - No Company Name ==========

[2010/03/25 15:26:07 | 000,002,553 | ---- | C] () -- C:\Users\Jenny\Desktop\HiJackThis.lnk
[2010/03/25 15:01:43 | 000,000,848 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/25 15:01:37 | 000,022,104 | ---- | C] () -- C:\Windows\SysNative\drivers\mbam.sys
[2010/03/25 12:22:14 | 000,212,864 | ---- | C] () -- C:\Windows\SysNative\MpSigStub.exe
[2010/03/25 00:46:45 | 000,000,042 | ---- | C] () -- C:\Windows\SysWow64\RegistryEasy.lie
[2010/03/24 23:51:38 | 000,422,780 | ---- | C] () -- C:\Users\Jenny\AppData\Local\dd_vcredistMSI474C.txt
[2010/03/24 23:51:35 | 000,010,666 | ---- | C] () -- C:\Users\Jenny\AppData\Local\dd_vcredistUI474F.txt
[2010/03/24 23:51:34 | 000,011,478 | ---- | C] () -- C:\Users\Jenny\AppData\Local\dd_vcredistUI474C.txt
[2010/03/24 23:25:38 | 000,001,905 | ---- | C] () -- C:\Windows\diagwrn.xml
[2010/03/24 23:25:38 | 000,001,905 | ---- | C] () -- C:\Windows\diagerr.xml
[2010/03/24 23:14:51 | 4024,881,152 | -HS- | C] () -- C:\hiberfil.sys
[2010/03/24 22:58:22 | 000,000,374 | ---- | C] () -- C:\Windows\tasks\PerfectOptimizer_home.job
[2010/03/24 22:52:48 | 000,000,188 | ---- | C] () -- C:\Windows\tasks\ms.job
[2010/03/24 22:52:25 | 000,000,011 | ---- | C] () -- C:\Windows\SysWow64\-1347-2419
[2010/03/24 22:52:10 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\notepad.exe.vbs
[2010/03/24 22:52:10 | 000,000,288 | ---- | C] () -- C:\Windows\SysWow64\cmd.exe.vbs
[2010/03/24 22:52:10 | 000,000,284 | ---- | C] () -- C:\Windows\explorer.exe.vbs
[2010/03/24 22:52:08 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\msiexec.exe.vbs
[2010/03/24 22:51:57 | 000,000,289 | ---- | C] () -- C:\Windows\SysWow64\msra.exe.vbs
[2010/03/24 22:51:35 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\MdSched.exe.vbs
[2010/03/24 22:51:28 | 000,000,298 | ---- | C] () -- C:\Windows\SysWow64\SoundRecorder.exe.vbs
[2010/03/24 22:51:28 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\mobsync.exe.vbs
[2010/03/24 22:51:28 | 000,000,290 | ---- | C] () -- C:\Windows\SysWow64\mstsc.exe.vbs
[2010/03/24 22:51:27 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\NetProj.exe.vbs
[2010/03/24 22:51:27 | 000,000,292 | ---- | C] () -- C:\Windows\SysWow64\mspaint.exe.vbs
[2010/03/24 22:51:27 | 000,000,291 | ---- | C] () -- C:\Windows\SysWow64\mblctr.exe.vbs
[2010/03/24 22:51:27 | 000,000,289 | ---- | C] () -- C:\Windows\SysWow64\calc.exe.vbs
[2010/03/24 22:51:21 | 000,064,981 | -HS- | C] () -- C:\Program Files (x86)\CCE51.exe
[2010/03/17 01:05:11 | 000,015,797 | ---- | C] () -- C:\Users\Jenny\Documents\Proposal.docx
[2009/12/31 15:14:36 | 000,000,552 | ---- | C] () -- C:\Users\Jenny\AppData\Local\d3d8caps.dat
[2009/09/25 00:06:40 | 000,000,000 | ---- | C] () -- C:\Users\Jenny\AppData\Roaming\FileStore.dll
[2009/09/16 23:17:54 | 000,237,568 | ---- | C] () -- C:\Windows\SysWow64\rmc_rtspdl.dll
[2009/07/30 06:06:08 | 000,000,294 | ---- | C] () -- C:\Users\Jenny\AppData\Roaming\wklnhst.dat
[2009/05/25 09:14:53 | 000,007,592 | ---- | C] () -- C:\Users\Jenny\AppData\Local\d3d9caps.dat
[2009/03/02 00:29:33 | 000,027,136 | ---- | C] () -- C:\Users\Jenny\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/20 12:01:19 | 000,000,021 | ---- | C] () -- C:\ProgramData\hpqp.txt
[2009/02/18 19:40:40 | 000,067,627 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/02/18 19:40:35 | 000,067,627 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/02/17 22:12:38 | 000,000,000 | ---- | C] () -- C:\Users\Jenny\AppData\Local\QSwitch.txt
[2009/02/17 22:12:38 | 000,000,000 | ---- | C] () -- C:\Users\Jenny\AppData\Local\DSwitch.txt
[2009/02/17 22:12:38 | 000,000,000 | ---- | C] () -- C:\Users\Jenny\AppData\Local\AtStart.txt
[2009/01/22 04:50:48 | 000,000,105 | ---- | C] () -- C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2009/01/22 04:50:38 | 000,000,032 | ---- | C] () -- C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2009/01/22 04:50:10 | 000,000,032 | ---- | C] () -- C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2009/01/22 04:49:33 | 000,000,032 | ---- | C] () -- C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2009/01/22 04:47:10 | 000,000,032 | ---- | C] () -- C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2009/01/22 04:46:45 | 000,000,252 | ---- | C] () -- C:\ProgramData\hpqp.ini
[2008/11/08 21:26:41 | 000,000,109 | ---- | C] () -- C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2008/11/08 21:19:08 | 000,000,110 | ---- | C] () -- C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2008/11/08 21:16:32 | 000,000,105 | ---- | C] () -- C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2008/11/08 21:14:46 | 000,000,107 | ---- | C] () -- C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2008/01/20 21:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 21:49:49 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2007/12/27 00:45:40 | 000,000,680 | ---- | C] () -- C:\Users\Jenny\AppData\Roaming\coreavc.ini
[2002/03/16 19:00:00 | 000,007,420 | ---- | C] () -- C:\Windows\UA000106.DLL

========== LOP Check ==========

[2009/09/25 00:02:56 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Any Video Converter
[2009/09/24 19:15:34 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Any Video Converter Professional
[2009/11/02 16:02:02 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/09/18 21:09:33 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\DMCache
[2009/08/15 00:10:09 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\FMZilla
[2009/11/19 22:24:35 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Geniesoft
[2009/09/18 21:02:29 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\GetRightToGo
[2009/09/18 21:09:34 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\IDM
[2009/06/18 18:32:57 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\iWin
[2010/03/24 22:53:20 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\JjlDownLoader
[2010/02/05 17:15:46 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Leadertech
[2009/09/24 19:54:30 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Opera
[2009/09/13 21:47:12 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\PlayFirst
[2009/11/26 16:36:58 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\PPLiveVA
[2009/12/18 12:31:32 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\PrimoPDF
[2009/02/20 10:46:45 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\SystemRequirementsLab
[2009/07/30 06:06:10 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Template
[2009/09/24 19:54:17 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\tencent
[2009/09/21 22:44:55 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Ulead Systems
[2009/09/18 20:44:01 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\uTorrent
[2009/09/19 23:00:22 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\Watermark Master
[2009/03/02 13:46:32 | 000,000,000 | ---D | M] -- C:\Users\Jenny\AppData\Roaming\WildTangent
[2010/03/15 01:11:30 | 000,000,340 | ---- | M] () -- C:\Windows\Tasks\McDefragTask.job
[2010/03/01 02:00:07 | 000,000,332 | ---- | M] () -- C:\Windows\Tasks\McQcTask.job
[2010/03/27 00:00:03 | 000,000,188 | ---- | M] () -- C:\Windows\Tasks\ms.job
[2010/03/25 12:00:15 | 000,000,374 | ---- | M] () -- C:\Windows\Tasks\PerfectOptimizer_home.job
[2010/03/25 12:00:00 | 000,000,446 | ---- | M] () -- C:\Windows\Tasks\Reg Tool Scan.job
[2010/03/27 12:43:22 | 000,000,386 | ---- | M] () -- C:\Windows\Tasks\Reg Tool Startup.job
[2010/03/27 12:41:20 | 000,032,562 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010/03/26 19:59:12 | 000,000,418 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{8B2AACFE-262C-469C-97D5-58A5FA70C8E6}.job

========== Purity Check ==========

========== Alternate Data Streams ==========

@Alternate Data Stream - 145 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:8C35AEA7
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:661DFA1C
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:6152D44C
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:D1B5B4F1
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:A8ADE5D8
< End of report >

Ok got to have PP or Crunchie take a look. Thanks for being patient.
Judy

Hi Karen,

The problem that we are running into is that 64-bit Vista is a difficult animal with which to deal in a forum setting. Most of the tools we use are just not compatible....

-- Did you download this ---> 360Safe ?
-- How are things running after Judy's last set of instructions?
-- What about the programs that were giving you trouble? Are they working now?

PP:)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.