This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] hijackthis lov

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:24:37 PM, on 2/15/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Lala.com\Lala Music Mover\LalaMover.exe
E:\Program Files (x86)\RocketDock\RocketDock.exe
E:\Program Files (x86)\johnsadventures.com\John's Background Switcher\BackgroundSwitcher.exe
C:\Users\Jason\AppData\Local\Google\Update\GoogleUpdate.exe
E:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe
E:\Program Files (x86)\Dropbox\Dropbox.exe
E:\Program Files (x86)\AVG\AVG8\avgtray.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
C:\Users\Jason\AppData\Local\Microsoft\Live Mesh\GacBase\Moe.exe
C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
E:\Program Files (x86)\Mozilla Firefox\firefox.exe
e:\Program Files (x86)\AVG\AVG8\avgcsrvx.exe
C:\Windows\sysWow64\SearchProtocolHost.exe
C:\Program Files (x86)\Lala.com\Lala Music Mover\lalaTranscoder.exe
E:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AVG8_TRAY] e:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [Lala Music Mover] "C:\Program Files (x86)\Lala.com\Lala Music Mover\LalaMover.exe" /minimized
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [RocketDock] "E:\Program Files (x86)\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [BackgroundSwitcher] "E:\Program Files (x86)\johnsadventures.com\John's Background Switcher\BackgroundSwitcher.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Jason\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [MoeMonitor.exe] "C:\Users\Jason\AppData\Local\Microsoft\Live Mesh\Bin\Servicing\0.9.3424.14\MoeMonitor.exe"
O4 - Startup: Dropbox.lnk = E:\Program Files (x86)\Dropbox\Dropbox.exe
O4 - Global Startup: Audible Download Manager.lnk = E:\Program Files (x86)\Audible\Bin\AudibleDownloadHelper.exe
O4 - Global Startup: Google Calendar Sync.lnk = E:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe
O4 - Global Startup: Mozy Status.lnk = C:\Program Files\Mozy\mozystat.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files (x86)\Linksys\Bluetooth Utility\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: acaptuser32.dll C:\PROGRA~2\Google\GO333C~1\GOEC62~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - E:\Program Files (x86)\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - e:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c964b3dc08f00) (gupdate1c964b3dc08f00) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MozyHome Backup Service (mozybackup) - Unknown owner - C:\Program Files\Mozy\mozybackup.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - e:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 10946 bytes

I keep getting popups while using firefox, I was wondering if anything in here could be the issue.
Hi, and Welcome to WhatTheTech :)

Apologies in the delay in a response. We are overwhelmed with logs at the moment and there aren't enough helpers to go around. If you still require help, please do the following:

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.

Thanks.
Hi,

It does work on Vista, but it might stumble with the 64 bit version. Let's run this one instead, I'm pretty sure this runs on 64bit Vista.

Please download OTViewIt and save it to your Desktop.
  • Double-click OTViewIt to run it.
  • Click Run Scan to beginning scanning.
  • OTViewIt will now scan your system. When it finishes, two logs will open in notepad windows.
  • Please post the contents of OTViewIt.txt in your next reply.
  • Please attach the Extras.txt report to your next reply.
Thanks.
OTViewIt logfile created on: 2/24/2009 6:01:44 AM - Run
OTViewIt by OldTimer - Version 1.0.21.0 Folder = D:\Downloads
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.70 Gb Available Physical Memory | 35.09% Memory free
4.00 Gb Paging File | 2.74 Gb Available in Paging File | 68.61% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = e:\Program Files (x86)
Drive C: | 37.28 Gb Total Space | 3.04 Gb Free Space | 8.15% Space Free | Partition Type: NTFS
Drive D: | 279.46 Gb Total Space | 146.68 Gb Free Space | 52.49% Space Free | Partition Type: NTFS
Drive E: | 139.78 Gb Total Space | 129.57 Gb Free Space | 92.70% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
Drive G: | 464.85 Gb Total Space | 231.63 Gb Free Space | 49.83% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
Drive I: | 139.68 Gb Total Space | 137.37 Gb Free Space | 98.35% Space Free | Partition Type: NTFS

Computer Name: GOFER
Current User Name: Jason
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days

========== Processes ==========

[2009/02/15 14:15:31 | 00,950,096 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
[2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe
[2009/02/22 19:32:44 | 00,266,240 | —- | M] () – C:\Windows\SysWOW64\CSHelper.exe
[2008/11/23 09:54:37 | 00,168,432 | —- | M] (Google) – C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
[2008/12/22 21:00:43 | 00,133,104 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
[2008/10/17 17:58:22 | 02,221,360 | —- | M] (Lala Media) – C:\Program Files (x86)\Lala.com\Lala Music Mover\LalaMover.exe
[2007/09/02 13:58:52 | 00,495,616 | —- | M] () – E:\Program Files (x86)\RocketDock\RocketDock.exe
[2008/12/08 06:11:00 | 01,095,568 | —- | M] (johnsadventures.com) – E:\Program Files (x86)\johnsadventures.com\John's Background Switcher\BackgroundSwitcher.exe
[2008/11/02 14:10:06 | 00,133,104 | —- | M] (Google Inc.) – C:\Users\Jason\AppData\Local\Google\Update\GoogleUpdate.exe
[2006/11/02 02:45:37 | 00,044,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\rundll32.exe
[2009/01/30 00:20:18 | 00,030,192 | —- | M] (Google) – C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
[2008/10/02 09:23:16 | 00,546,288 | —- | M] (Google) – E:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe
[2009/02/15 14:15:32 | 00,509,784 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
[2009/02/13 21:58:38 | 24,576,823 | —- | M] () – E:\Program Files (x86)\Dropbox\Dropbox.exe
[2008/05/21 04:37:24 | 12,844,576 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
[2009/02/02 00:15:08 | 00,207,696 | —- | M] (Microsoft Corporation) – C:\Users\Jason\AppData\Local\Microsoft\Live Mesh\GacBase\Moe.exe
[2008/01/19 00:33:39 | 00,245,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
[2009/02/04 09:01:32 | 00,307,704 | —- | M] (Mozilla Corporation) – E:\Program Files (x86)\Mozilla Firefox\firefox.exe
[2008/05/26 22:18:16 | 00,184,832 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\SearchProtocolHost.exe
[2009/02/24 06:01:11 | 00,422,912 | —- | M] (OldTimer Tools) – D:\Downloads\OTViewIt.exe

========== (O23) Win32 Services ==========

[2008/11/07 14:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Disabled | Stopped])
File not found – – (Ati External Event Utility [Auto | Running])
[2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe – (Bonjour Service [Auto | Running])
File not found – – (CertPropSvc [Unknown | Running])
[2008/01/05 04:26:41 | 00,070,144 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2008/01/05 04:25:45 | 00,093,696 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
[2008/10/08 17:09:47 | 00,079,360 | —- | M] (Creative Labs) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe – (Creative ALchemy AL6 Licensing Service [On_Demand | Stopped])
[2009/02/22 19:32:44 | 00,266,240 | —- | M] () – C:\Windows\SysWOW64\CSHelper.exe – (CSHelper [Auto | Running])
File not found – – (DcomLaunch [Unknown | Running])
File not found – – (DPS [Unknown | Running])
[2008/01/19 01:00:14 | 00,344,064 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehrecvr.exe – (ehRecvr [On_Demand | Stopped])
[2008/01/19 01:00:14 | 00,153,600 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehsched.exe – (ehSched [On_Demand | Stopped])
[2008/11/10 17:14:06 | 00,651,720 | —- | M] (Macrovision Europe Ltd.) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service [On_Demand | Stopped])
[2008/01/05 04:23:12 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
[2009/01/30 00:20:18 | 00,030,192 | —- | M] (Google) – C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe – (GoogleDesktopManager-092308-165331 [On_Demand | Stopped])
[2008/12/22 21:00:43 | 00,133,104 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Update\GoogleUpdate.exe – (gupdate1c964b3dc08f00 [Auto | Stopped])
[2008/11/23 09:54:37 | 00,168,432 | —- | M] (Google) – C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [Auto | Running])
[2005/04/04 00:41:10 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
[2008/11/20 13:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files (x86)\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Stopped])
[2006/11/02 02:46:05 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\Windows\System32\keyiso.dll – (KeyIso [On_Demand | Running])
[2009/02/15 14:15:31 | 00,950,096 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service [Auto | Running])
[2008/10/28 22:02:51 | 01,715,200 | —- | M] (MediaMall Technologies, Inc.) – C:\Program Files (x86)\MediaMall\MediaMallServer.exe – (MediaMall Server [Disabled | Stopped])
[2008/10/06 13:45:50 | 00,084,784 | —- | M] () – C:\Program Files\Mozy\mozybackup.exe – (mozybackup [Auto | Running])
[2006/11/02 06:34:14 | 00,000,000 | —D | M] – C:\Windows\System32\Msdtc – (MSDTC [Unknown | Stopped])
[2008/01/19 00:35:36 | 00,592,384 | —- | M] (Microsoft Corporation) – C:\Windows\System32\netlogon.dll – (Netlogon [On_Demand | Stopped])
[2008/01/05 04:23:05 | 00,122,880 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
[2007/08/24 03:19:12 | 00,443,776 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
[2006/10/26 14:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
[2008/01/19 00:33:19 | 00,019,968 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\perfhost.exe – (PerfHost [On_Demand | Stopped])
File not found – – (RpcSs [Unknown | Running])
[2008/01/19 00:36:19 | 00,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SCardSvr.dll – (SCardSvr [Unknown | Stopped])
File not found – – (Schedule [Unknown | Running])
File not found – – (SCPolicySvc [Unknown | Stopped])
[2006/11/01 23:35:15 | 00,060,994 | —- | M] () – C:\Windows\System32\wbem\vds.mof – (vds [On_Demand | Stopped])
[2006/11/01 23:35:15 | 00,055,846 | —- | M] () – C:\Windows\System32\wbem\vss.mof – (VSS [On_Demand | Running])
File not found – – (WdiServiceHost [Unknown | Stopped])
File not found – – (WdiSystemHost [Unknown | Running])
File not found – – (WinDefend [Unknown | Stopped])
[2009/02/02 00:17:51 | 00,050,496 | —- | M] (Microsoft Corporation) – e:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe – (wlcrasvc [Auto | Running])
[2008/05/26 22:18:43 | 00,439,808 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SearchIndexer.exe – (WSearch [Auto | Running])

========== Driver Services ==========

[2008/01/19 01:12:01 | 00,486,456 | —- | M] (Adaptec, Inc.) – C:\Windows\WinSxS\amd64_adp94xx.inf_31bf3856ad364e35_6.0.6001.18000_none_5e0fcb9b69814f7b\adp94xx.sys – (adp94xx [Disabled | Stopped])
[2008/01/19 01:11:40 | 00,342,584 | —- | M] (Adaptec, Inc.) – C:\Windows\WinSxS\amd64_adpahci.inf_31bf3856ad364e35_6.0.6001.18000_none_c05c13aa3dfbc961\adpahci.sys – (adpahci [Disabled | Stopped])
[2008/01/19 01:10:01 | 00,126,520 | —- | M] (Adaptec, Inc.) – C:\Windows\WinSxS\amd64_adpu160m.inf_31bf3856ad364e35_6.0.6001.18000_none_f2feed0b63bf261d\adpu160m.sys – (adpu160m [Disabled | Stopped])
[2008/01/19 01:11:12 | 00,185,912 | —- | M] (Adaptec, Inc.) – C:\Windows\WinSxS\amd64_adpu320.inf_31bf3856ad364e35_6.0.6001.18000_none_f4cbbad1148c6b4a\adpu320.sys – (adpu320 [Disabled | Stopped])
[2008/03/22 13:22:54 | 00,018,488 | —- | M] (Acer Laboratories Inc.) – C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\aliide.sys – (aliide [Disabled | Stopped])
File not found – – (Amfilter [System | Running])
File not found – – (Amusbprt [On_Demand | Running])
[2008/01/19 01:09:34 | 00,090,680 | —- | M] (Adaptec, Inc.) – C:\Windows\WinSxS\amd64_arc.inf_31bf3856ad364e35_6.0.6001.18000_none_7bfed8c7803713cf\arc.sys – (arc [Disabled | Stopped])
[2008/01/19 01:09:37 | 00,091,192 | —- | M] (Adaptec, Inc.) – C:\Windows\WinSxS\amd64_arcsas.inf_31bf3856ad364e35_6.0.6001.18000_none_771684264153c2d4\arcsas.sys – (arcsas [Disabled | Stopped])
File not found – – (atikmdag [On_Demand | Running])
[2006/09/18 14:30:15 | 00,018,432 | —- | M] (Brother Industries, Ltd.) – C:\Windows\WinSxS\amd64_brmfcsto.inf_31bf3856ad364e35_6.0.6001.18000_none_800ff95700142785\BrFiltLo.sys – (BrFiltLo [On_Demand | Stopped])
[2006/09/18 14:30:15 | 00,008,704 | —- | M] (Brother Industries, Ltd.) – C:\Windows\WinSxS\amd64_brmfcsto.inf_31bf3856ad364e35_6.0.6001.18000_none_800ff95700142785\BrFiltUp.sys – (BrFiltUp [On_Demand | Stopped])
[2008/03/22 13:22:54 | 00,020,536 | —- | M] (CMD Technology, Inc.) – C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\cmdide.sys – (cmdide [Disabled | Stopped])
[2007/01/30 15:27:09 | 00,000,000 | —D | M] – C:\Windows\CSC – (CSC [System | Running])
[2008/01/05 04:22:48 | 00,317,952 | —- | M] (Intel Corporation) – C:\Windows\WinSxS\amd64_nete1e3e.inf_31bf3856ad364e35_6.0.6001.18000_none_be74415a049dfa61\e1e6032e.sys – (e1express [On_Demand | Running])
[2008/01/05 04:22:47 | 00,146,176 | —- | M] (Intel Corporation) – C:\Windows\WinSxS\amd64_nete1g3e.inf_31bf3856ad364e35_6.0.6001.18000_none_04b0c96be9c034d3\E1G6032E.sys – (E1G60 [On_Demand | Stopped])
[2008/01/19 01:11:53 | 00,397,368 | —- | M] (Emulex) – C:\Windows\WinSxS\amd64_elxstor.inf_31bf3856ad364e35_6.0.6001.18000_none_08ac13ff69b034ee\elxstor.sys – (elxstor [Disabled | Stopped])
[2006/09/19 15:44:04 | 00,015,664 | —- | M] (GEAR Software Inc.) – C:\Windows\System32\drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
File not found – – (HdAudAddService [On_Demand | Running])
[2008/01/19 01:08:42 | 00,047,672 | —- | M] (Hewlett-Packard Company) – C:\Windows\WinSxS\amd64_hpcisss.inf_31bf3856ad364e35_6.0.6001.18000_none_d59c6600292b9522\HpCISSs.sys – (HpCISSs [Disabled | Stopped])
[2008/01/19 01:11:31 | 00,290,872 | —- | M] (Intel Corporation) – C:\Windows\WinSxS\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys – (iaStorV [Disabled | Stopped])
File not found – – (Lbd [Boot | Running])
[2008/01/19 01:09:57 | 00,113,720 | —- | M] (LSI Logic) – C:\Windows\WinSxS\amd64_lsi_fc.inf_31bf3856ad364e35_6.0.6001.18000_none_c59b4ac1fa719137\lsi_fc.sys – (LSI_FC [Disabled | Stopped])
[2008/01/19 01:09:48 | 00,105,016 | —- | M] (LSI Logic) – C:\Windows\WinSxS\amd64_lsi_sas.inf_31bf3856ad364e35_6.0.6001.18000_none_5b86b7f9e8ff0dc5\lsi_sas.sys – (LSI_SAS [Disabled | Stopped])
[2008/01/19 01:09:56 | 00,113,720 | —- | M] (LSI Logic) – C:\Windows\WinSxS\amd64_lsi_scsi.inf_31bf3856ad364e35_6.0.6001.18000_none_f883c787da42af0c\lsi_scsi.sys – (LSI_SCSI [Disabled | Stopped])
[2008/01/19 01:08:18 | 00,035,896 | —- | M] (LSI Corporation) – C:\Windows\WinSxS\amd64_megasas.inf_31bf3856ad364e35_6.0.6001.18000_none_8c5ef0c0070fb814\megasas.sys – (megasas [Disabled | Stopped])
File not found – – (mozyFilter [System | Running])
[2007/07/11 11:50:10 | 00,001,088 | —- | M] () – C:\Windows\System32\wbem\mpsdrv.mof – (mpsdrv [On_Demand | Running])
[2008/01/19 01:10:12 | 00,128,056 | —- | M] (NVIDIA Corporation) – C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvraid.sys – (nvraid [Disabled | Stopped])
[2008/01/19 01:08:50 | 00,054,328 | —- | M] (NVIDIA Corporation) – C:\Windows\WinSxS\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys – (nvstor [Disabled | Stopped])
File not found – – (P17 [On_Demand | Running])
[2008/01/19 01:12:10 | 01,221,176 | —- | M] (QLogic Corporation) – C:\Windows\WinSxS\amd64_ql2300.inf_31bf3856ad364e35_6.0.6001.18000_none_90b29e0f5eb4b0a1\ql2300.sys – (ql2300 [Disabled | Stopped])
File not found – – (RDPDISPM [On_Demand | Running])
File not found – – (rt70x64 [On_Demand | Running])
File not found – – (RTL8169 [On_Demand | Running])
[2006/09/29 16:51:44 | 00,023,040 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\Windows\WinSxS\amd64_macrovision-protection-safedisc_31bf3856ad364e35_6.0.6000.16386_none_b794b0d578b7ec2e\secdrv.sys – (secdrv [Auto | Running])
File not found – – (Si3132r5 [Boot | Running])
File not found – – (SiFilter [Boot | Running])
File not found – – (SiRemFil [Boot | Running])
[2008/01/19 01:09:28 | 00,078,392 | —- | M] (Silicon Integrated Systems) – C:\Windows\WinSxS\amd64_sisraid4.inf_31bf3856ad364e35_6.0.6001.18000_none_8460e59f708bb476\sisraid4.sys – (SiSRaid4 [Disabled | Stopped])
File not found – – (SSPORT [Auto | Running])
[2006/09/18 14:36:40 | 00,003,066 | —- | M] () – C:\Windows\System32\wbem\tcpip.mof – (Tcpip [Boot | Running])
[2008/01/19 01:11:28 | 00,284,728 | —- | M] (ULi Electronics Inc.) – C:\Windows\WinSxS\amd64_uliahci.inf_31bf3856ad364e35_6.0.6001.18000_none_a21b1cbb80e47096\uliahci.sys – (uliahci [Disabled | Stopped])
[2006/11/02 04:51:19 | 00,174,696 | —- | M] (Promise Technology, Inc.) – C:\Windows\WinSxS\amd64_ulsata2.inf_31bf3856ad364e35_6.0.6001.18000_none_9ce1027f4768b389\ulsata2.sys – (ulsata2 [Disabled | Stopped])
[2008/03/22 13:22:54 | 00,020,536 | —- | M] (VIA Technologies, Inc.) – C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\viaide.sys – (viaide [Disabled | Stopped])
[2008/01/19 01:10:22 | 00,149,048 | —- | M] (VIA Technologies Inc.,Ltd) – C:\Windows\WinSxS\amd64_vsmraid.inf_31bf3856ad364e35_6.0.6001.18000_none_508698a452d25e17\vsmraid.sys – (vsmraid [Disabled | Stopped])
[2008/01/19 00:36:56 | 00,016,384 | —- | M] (Microsoft Corporation) – C:\Windows\System32\winusb.dll – (winusb [On_Demand | Stopped])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=C:\Windows\SysWOW64\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Search_URL"=http://www.google.com/ie
"Local Page"=C:\Windows\system32\blank.htm
"Search Page"=http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
"Start Page"=http://www.google.com/
"StartPageCache"=

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search]
"AutoSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/saautosearch.aspx
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"Default_Search_URL"=http://www.google.com/ie
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
""=http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

========== (O1) Hosts File ==========

HOSTS File = (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
First 25 entries…
127.0.0.1 localhost
::1 localhost

========== (O2) BHO's ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (HKLM) – C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) – C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
{9030D464-4C02-4ABF-8ECC-5164760863C6} (HKLM) – C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
{AE7CD045-E861-484f-8273-0445EE161910} (HKLM) – C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (HKLM) – C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) – C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} (HKLM) – C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll (Google Inc.)
{F4971EE7-DAA0-4053-9964-665D8EE6A077} (HKLM) – C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)

========== (O3) Toolbars ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) – C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) – C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
""= File not found
"Ad-Watch"="C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe" (Lavasoft)
"Google Desktop Search"="C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
"P17RunE"=RunDll32 P17RunE.dll,RunDLLEntry (Creative Technology Ltd.)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
""= File not found
"BackgroundSwitcher"="E:\Program Files (x86)\johnsadventures.com\John's Background Switcher\BackgroundSwitcher.exe" (johnsadventures.com)
"ehTray.exe"=C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
"Google Update"="C:\Users\Jason\AppData\Local\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
"Lala Music Mover"="C:\Program Files (x86)\Lala.com\Lala Music Mover\LalaMover.exe" /minimized (Lala Media)
"MoeMonitor.exe"="C:\Users\Jason\AppData\Local\Microsoft\Live Mesh\Bin\Servicing\0.9.3424.14\MoeMonitor.exe" (Microsoft Corporation)
"RocketDock"="E:\Program Files (x86)\RocketDock\RocketDock.exe" ()
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()

========== (O6 & O7) Current Version Policies ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"ConsentPromptBehaviorAdmin"=2
"ConsentPromptBehaviorUser"=1
"EnableInstallerDetection"=1
"EnableLUA"=1
"EnableSecureUIAPaths"=1
"EnableVirtualization"=1
"PromptOnSecureDesktop"=1
"ValidateAdminCodeSignatures"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"scforceoption"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"FilterAdministratorToken"=0
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=1
"CF_BITMAP"=2
"CF_OEMTEXT"=7
"CF_DIB"=8
"CF_PALETTE"=9
"CF_UNICODETEXT"=13
"CF_DIBV5"=17

========== (O8) IE Context Menu Extensions ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
Add to Google Photos Screensa&ver: C:\Windows\System32\GPhotos.scr [2009/01/05 15:33:03 | 03,751,995 | —- | M] (Google Inc.)
Append Link Target to Existing PDF: C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008/06/11 22:42:44 | 00,345,480 | —- | M] (Adobe Systems Incorporated)
Append to Existing PDF: C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008/06/11 22:42:44 | 00,345,480 | —- | M] (Adobe Systems Incorporated)
Convert Link Target to Adobe PDF: C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008/06/11 22:42:44 | 00,345,480 | —- | M] (Adobe Systems Incorporated)
Convert to Adobe PDF: C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008/06/11 22:42:44 | 00,345,480 | —- | M] (Adobe Systems Incorporated)
E&xport to Microsoft Excel: C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE [2008/10/18 18:30:22 | 17,931,616 | —- | M] (Microsoft Corporation)
Send To &Bluetooth: C:\Program Files (x86)\Linksys\Bluetooth Utility\btsendto_ie_ctx.htm File not found

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5}: Menu: &Gears Settings – %SystemDrive%\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll [2008/11/29 16:27:46 | 01,667,072 | —- | M] (Google Inc.)
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Button: Send to OneNote – %SystemDrive%\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll [2007/12/13 02:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}: Menu: S&end to OneNote – %SystemDrive%\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll [2007/12/13 02:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research – %SystemDrive%\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL [2006/10/26 20:12:22 | 00,040,424 | —- | M] (Microsoft Corporation)

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O15) Trusted Sites ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
GD: ":Range"=127.0.0.1 – http in Local intranet |

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}: http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab – QuickTime Object
{0DB074F0-617E-4EE9-912C-2965CF2AA5A4}: http://download.microsoft.com/download/0/f…tualEarth3D.cab – Reg Error: Key does not exist or could not be opened.
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_10
{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_10
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_10

========== (O17) DNS Name Servers ==========

{11E059DB-F5FD-4A94-BB26-A5D0DDD96F27} (Servers: | Description: )
{2B4D0983-86C7-43A5-91D6-24E04ADE7E71} (Servers: | Description: RT2500 USB Wireless LAN Card)
{46DCED24-BB53-4772-9BD5-392EF2500501} (Servers: | Description: RT2500 USB Wireless LAN Card)
{B077BBD2-E4BB-4A77-BB67-7CF29076C726} (Servers: | Description: Intel® PRO/1000 PM Network Connection)
{D3AD5B72-975E-4A38-A8D7-298325122AE0} (Servers: | Description: RT2500 USB Wireless LAN Card)
{DD6186C8-0E7B-4086-B5E7-C128755B0435} (Servers: | Description: Realtek RTL8169/8110 Family PCI GBE NIC)
{E152DFE2-5893-457C-85F5-7D8B0CAF0170} (Servers: | Description: RT2500 USB Wireless LAN Card)

========== (O20) HKLM Winlogon Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"=explorer.exe
>[2008/10/28 23:29:41 | 02,927,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\explorer.exe


========== (O21) SSODL Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"={E6FB5E20-DE35-11CF-9C87-00AA005127ED} (HKLM) – C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)

========== HKLM *SecurityProviders* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders"=credssp.dll
>[2008/01/19 00:33:59 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\credssp.dll

========== LSA *Security Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages"=kerberos,msv1_0,schannel,wdigest,tspkg,
>[2008/01/19 00:36:42 | 00,062,464 | —- | M] (Microsoft Corporation) – C:\Windows\System32\TSpkg.dll

========== Safeboot Options ==========

"AlternateShell"=cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a5fac2b6-b0b0-11db-acdc-806e6f6e6963}\Shell]
""=AutoRun


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a5fac2b6-b0b0-11db-acdc-806e6f6e6963}\Shell\AutoRun\command]
""=F:\Install.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/02/24 05:59:15 | 00,001,037 | —- | C] () – C:\Users\Jason\AppData\Local\Account.atomsvc
[2009/02/22 19:32:44 | 00,266,240 | —- | C] () – C:\Windows\System32\CSHelper.exe
[2009/02/22 19:32:44 | 00,225,280 | —- | C] (Art Dept (nsw) Pty Ltd) – C:\Windows\System32\CSInstru.DLL
[2009/02/22 19:32:43 | 00,000,000 | —D | C] – C:\Windows\ArtistScope Plugin FX 42
[2009/02/15 16:03:37 | 00,000,681 | —- | C] () – C:\Users\Jason\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2009/02/15 14:16:09 | 00,000,496 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/02/15 14:14:15 | 00,000,000 | -H-D | C] – C:\ProgramData\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/02/15 14:02:22 | 00,000,000 | —D | C] – C:\Users\Jason\AppData\Roaming\vlc
[2009/02/15 10:45:35 | 00,001,743 | —- | C] () – C:\Users\Jason\Desktop\HijackThis.lnk
[2009/02/15 10:45:34 | 00,000,000 | —D | C] – e:\Program Files (x86)\Trend Micro
[2009/02/15 10:20:50 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/02/15 10:20:49 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/02/15 10:20:42 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/02/15 10:20:42 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/02/15 10:20:41 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/02/14 13:15:25 | 00,000,000 | —D | C] – C:\Users\Jason\AppData\Roaming\Skype
[2009/02/14 13:13:58 | 00,000,000 | R–D | C] – e:\Program Files (x86)\Skype
[2009/02/13 14:58:31 | 00,043,070 | —- | C] () – d:\cc_20090213_145827.reg
[2009/02/10 23:39:42 | 00,000,000 | —D | C] – C:\Users\Jason\AppData\Roaming\PCF-VLC
[2009/02/10 23:36:00 | 00,000,000 | —D | C] – C:\Users\Jason\AppData\Roaming\Participatory Culture Foundation
[2009/02/10 23:35:44 | 00,000,000 | —D | C] – e:\Program Files (x86)\Participatory Culture Foundation
[2009/02/09 10:22:21 | 00,000,000 | —D | C] – C:\Users\Jason\Desktop\mahara-1.0.9
[2009/02/08 12:57:11 | 00,000,000 | —D | C] – C:\Users\Jason\Desktop\tng
[2009/02/08 12:21:15 | 00,000,000 | —D | C] – C:\Users\Jason\Desktop\wordpress
[2009/02/08 01:43:44 | 00,000,000 | —D | C] – C:\Users\Jason\AppData\Roaming\gtk-2.0
[2009/02/07 23:52:54 | 00,000,000 | —D | C] – e:\Program Files (x86)\gs
[2009/02/07 22:02:09 | 00,000,000 | —D | C] – e:\Program Files (x86)\Scribus 1.3.3.12
[2009/02/07 21:44:37 | 00,000,000 | —D | C] – e:\Program Files (x86)\GIMP-2.0
[2009/02/06 12:38:53 | 00,010,775 | —- | C] () – d:\cease and disist 262009.docx
[2009/02/05 11:43:17 | 00,000,000 | —D | C] – C:\Users\Jason\AppData\Roaming\Gizmo5
[2009/02/04 22:29:15 | 00,000,000 | —D | C] – e:\Program Files (x86)\GMATPrep
[2009/02/04 19:05:09 | 00,001,643 | —- | C] () – C:\Users\Jason\Desktop\Flickr Uploadr.lnk
[2009/02/04 17:41:29 | 00,000,000 | —D | C] – C:\Users\Jason\AppData\Local\DiskAnalyzer
[2009/02/04 17:40:55 | 00,000,000 | —D | C] – C:\ProgramData\DiskAnalyzer
[2009/02/04 08:48:23 | 00,000,000 | —D | C] – C:\Windows\System32\drivers\avg
[2009/02/02 22:32:53 | 00,000,000 | —D | C] – e:\Program Files (x86)\Internet Explorer
[2009/02/02 22:32:53 | 00,000,000 | —D | C] – e:\Program Files (x86)\Common Files\Microsoft Shared
[2009/02/02 22:03:14 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/02/02 22:03:14 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advpack.dll
[2009/02/02 22:03:14 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2009/02/02 22:03:14 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmled.dll
[2009/02/02 22:03:14 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardie.dll
[2009/02/02 22:03:13 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2009/02/02 22:03:13 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/02/02 22:03:13 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2009/02/02 22:03:12 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tdc.ocx
[2009/02/02 22:03:12 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2009/02/02 22:03:11 | 00,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2009/02/02 22:03:11 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2009/02/02 22:03:11 | 00,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/02/02 22:03:11 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/02/02 22:03:10 | 00,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/02/02 22:03:10 | 00,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2009/02/02 22:03:10 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2009/02/02 22:03:09 | 01,639,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/02/02 22:03:09 | 00,445,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2009/02/02 22:03:09 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/02/02 22:03:08 | 00,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/02/02 22:03:08 | 00,593,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/02/02 22:03:07 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2009/02/02 22:03:07 | 00,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webcheck.dll
[2009/02/02 22:03:07 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2009/02/02 22:03:07 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/02/02 22:03:07 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2009/02/02 22:03:07 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2009/02/02 22:03:07 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2009/02/02 22:03:06 | 00,228,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/02/02 22:03:06 | 00,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2009/02/02 22:03:06 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2009/02/02 22:03:05 | 00,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2009/02/02 22:03:05 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/02/02 22:03:04 | 00,911,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/02/02 22:03:04 | 00,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2009/02/02 22:03:03 | 00,724,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2009/02/02 22:03:03 | 00,392,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/02/02 22:03:03 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2009/02/02 22:03:01 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/02/02 22:03:01 | 00,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2009/02/02 22:03:01 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshta.exe
[2009/02/02 22:03:00 | 03,698,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2009/02/02 22:03:00 | 00,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/02/02 22:03:00 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2009/02/02 22:03:00 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/02/02 22:03:00 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2009/02/02 22:03:00 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2009/02/02 22:03:00 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2009/02/02 22:02:59 | 01,975,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/02/02 22:02:59 | 01,182,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/02/02 22:02:59 | 00,172,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/02/02 22:02:58 | 01,467,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/02/02 22:02:57 | 10,963,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/02/02 22:02:54 | 05,888,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/02/02 01:59:56 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\davclnt.dll
[2009/01/29 22:35:20 | 00,000,000 | —D | C] – C:\Users\Jason\AppData\Local\Cooliris
[2009/01/25 10:19:07 | 00,000,418 | RHS- | C] () – C:\ProgramData\ntuser.pol

========== Files - Modified Within 30 Days ==========

[1 C:\Windows\System32\*.tmp files]
[2009/02/24 06:15:03 | 00,000,412 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{59DD276D-D758-4291-B195-29FACB776E5E}.job
[2009/02/24 05:59:15 | 00,001,037 | —- | M] () – C:\Users\Jason\AppData\Local\Account.atomsvc
[2009/02/24 05:51:20 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/02/24 05:50:17 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/02/23 21:47:16 | 00,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2009/02/23 21:46:55 | 01,551,537 | -H– | M] () – C:\Users\Jason\AppData\Local\IconCache.db
[2009/02/23 19:05:17 | 00,004,362 | —- | M] () – C:\Windows\mozy.blk
[2009/02/23 19:05:11 | 00,000,724 | —- | M] () – C:\Windows\mozy.flt
[2009/02/22 19:32:44 | 00,266,240 | —- | M] () – C:\Windows\System32\CSHelper.exe
[2009/02/22 19:32:44 | 00,225,280 | —- | M] (Art Dept (nsw) Pty Ltd) – C:\Windows\System32\CSInstru.DLL
[2009/02/22 14:17:02 | 00,000,496 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/02/15 16:03:37 | 00,000,681 | —- | M] () – C:\Users\Jason\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2009/02/15 10:45:35 | 00,001,743 | —- | M] () – C:\Users\Jason\Desktop\HijackThis.lnk
[2009/02/13 14:58:36 | 00,043,070 | —- | M] () – d:\cc_20090213_145827.reg
[2009/02/08 22:01:07 | 00,088,064 | —- | M] () – C:\Users\Jason\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/06 12:38:59 | 00,010,775 | —- | M] () – d:\cease and disist 262009.docx
[2009/02/04 22:39:02 | 00,083,992 | —- | M] () – C:\Users\Jason\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/02/04 19:05:09 | 00,001,643 | —- | M] () – C:\Users\Jason\Desktop\Flickr Uploadr.lnk
[2009/01/25 10:19:07 | 00,000,418 | RHS- | M] () – C:\ProgramData\ntuser.pol
< End of report >

Attachments:

Hi,

What kind of popups are you getting?

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.
Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI