This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Multiple Security Warning Popups and self creating .exe&

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Have a vrius that creates letter/number named exe files and also have a security warning popup that says my computer is infected! It is recommended to start spyware cleaner tool. It also set all policies in gpedit to 'Not Configured'.
Here is my log file

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:14:45 PM, on 2/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Applicure\dotDefender for IIS\bin\aclogsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\SplineTech JavaScript HTML Debugger\mdm.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINDOWS\system32\srvany.exe
C:\pvsw\bin\w3dbsmgr.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
C:\WINDOWS\system32\locator.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\HP\HP WebInspect\WIScheduler.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\winlognn.exe
C:\WINDOWS\system32\frmwrk32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\ntdll64.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Tools AntiVirus\PCTAV.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Justin Ward\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\iPhoneRingToneMaker\iPhoneRingToneMaker.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 80.95.132.35 www.expekt.com 80.95.132.35 expekt.com
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: C:\WINDOWS\system32\hs78344kjkfd.dll - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\hs78344kjkfd.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Visual IP Trace - {E70C26AE-DFF1-40A8-8D37-19180F56F0AA} - C:\Program Files\Visual IP Trace 2007\VisualIPTraceIE.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: Delicious Toolbar - {61D1C847-DF80-423A-8C6D-DC03B97E6EBE} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [HPLJ Config] C:\Program Files\Hewlett-Packard\hp LaserJet 1150_1300\SetConfig.exe -c Direct -p \\RICH\Printer2 -pn "hp LaserJet 1300 PCL 6" -n 0 -l 1033 -sl 120000
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3Tray.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Vcomohaqiteji] rundll32.exe "C:\WINDOWS\Tyadabadeb.dll",e
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\winlognn.exe
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\Run: [NvSvc] C:\WINDOWS\system32\nvsvc32.exe
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\Run: [Hkovorukemo] rundll32.exe "C:\WINDOWS\ucitevih.dll",e
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\200921911740_mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\200921911734_mcinfo.exe /insfin
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Justin Ward\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [Tristana] "C:\Program Files\eRSS Reader\Reader.exe"
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\winlognn.exe
O4 - HKCU\..\Run: [ztr8nm77q5xuv6nz81ycb6dt] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\fd117itww.exe
O4 - HKCU\..\Run: [t5k8fcekpw13] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\powlndyn6j5a.exe
O4 - HKCU\..\Run: [uw6ejwixxs4ek38sedtcrc39cleube3c0zm] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\esq9op661fqei.exe
O4 - HKCU\..\Run: [pru7o969axu3ffk2] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\lv14smnscue8.exe
O4 - HKCU\..\Run: [zcggpb06yy4yrykoxha9hs3dwfv6rto51] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\u6tdgyij40fr.exe
O4 - HKCU\..\Run: [w5qsj9cf2o4j] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\kn25c79pey5x.exe
O4 - HKCU\..\Run: [ktb0t1dldnuk0z8s52f082mws8i0yx8xob6t7gu] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\s6e6b63hesw.exe
O4 - HKCU\..\Run: [qkpe4bm37mdamlbh9w3vposohnmsgqcnmzx9f0xkwu] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ueohl3osop.exe
O4 - HKCU\..\Run: [rulm8siujym5hfhg8ofyjcnexh] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\cujf6c.exe
O4 - HKCU\..\Run: [sfjjzm3pxvl5stwiklfz7kd] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\qnx1124x99v.exe
O4 - HKCU\..\Run: [jz2wqwc2jh2v7n87stsmgtmiw1p2blqxr] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xo8110q8ch3y.exe
O4 - HKCU\..\Run: [c5aje7761df246gnxtibusumghp4nmsvo6n6zo] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\e40ouqdkjjwxp.exe
O4 - HKCU\..\Run: [vxqb37qz39p3e2yxhb456e8dbtv08ctjpjgugpx7vn] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\wj2pr25g.exe
O4 - HKCU\..\Run: [dfvemqqi7uy] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\q100rnvl.exe
O4 - HKCU\..\Run: [a9iap34n2y8] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\t4d23ml19qp.exe
O4 - HKCU\..\Run: [ixlg10f6tz27xs22p1kfgpielzzwdxyw9lpi] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hlr8ot9.exe
O4 - HKCU\..\Run: [tcmcqp3pbi1g2k80ey9s20hhl7cqyjobm7vjycc8] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\oizv35he3bp.exe
O4 - HKCU\..\Run: [hs8oy8fprxahhpcer] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xcvkb8v3v7h.exe
O4 - HKCU\..\Run: [bnnqdds8f4h1] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\qndogi64u.exe
O4 - HKCU\..\Run: [fnwd0e3x6xp0otnyuzf74xm278] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\okstgo1.exe
O4 - HKCU\..\Run: [a191x79n6j19j27woypg8akyfre] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f4ch1c5vqa8c.exe
O4 - HKCU\..\Run: [uqfes7bu2dt5pme4s] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ndo0boji7vc.exe
O4 - HKCU\..\Run: [d2l9flclm2n6ovkgkdyp95fz88zjgelw39kloycq97nbc] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\enk5je.exe
O4 - HKCU\..\Run: [bqhsnkw2najvltz1r43i8xoivpy8ic0ozre9561mva88ak04] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\vlst73.exe
O4 - HKCU\..\Run: [c2c58klinb0l7wqz7oaalhise0apjqw9h4hklhdqh7ni] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\oxm0bvolai06.exe
O4 - HKCU\..\Run: [wbgt0286sn] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xfvryaeq.exe
O4 - HKCU\..\Run: [z22svugzj] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\n8m9tm.exe
O4 - HKCU\..\Run: [vzisn8y2cidi3l88as8vm] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\orvkc5x.exe
O4 - HKCU\..\Run: [gpm9hup22jndklp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xs3khwse5gua.exe
O4 - HKCU\..\Run: [xrcv1k3z8frp22l9mg4bsn26nbqie] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ikqgjyhmo955w.exe
O4 - HKCU\..\Run: [azqq4ymzxe6p2oesy2mkhnelkln1h6m372] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xpi3zhl54hy.exe
O4 - HKCU\..\Run: [skob19httrc33w0ffcnja] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f2ywbe32gqh.exe
O4 - HKCU\..\Run: [j4i5nlypax50nvlmh0c97kbhmz5k91legryexcamk] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\nms9t5n.exe
O4 - HKCU\..\Run: [fhdvrisxij1ov28p6ok6kom1cv4m1] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\t4mqusyucwq.exe
O4 - HKCU\..\Run: [rmnd6l94rxvba5qsomy2shbl98uq] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\miwltw3i0spc6.exe
O4 - HKCU\..\Run: [rwmqut43mk5jpgs8sq9u1ktqwxskf7snns1u] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\gohvjkq.exe
O4 - HKCU\..\Run: [pz4yzjca7dvrz7w4qdnimka6tt0] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f954x9u3b93.exe
O4 - HKCU\..\Run: [e4d9xq0gxozh5yqy8inoektvucc3g] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\kjjd797d8j775.exe
O4 - HKCU\..\Run: [uqfy1tlq9h6ili6fc3t4kax4a9x8z08so85hddyxz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\vv2v50k5piz5.exe
O4 - HKCU\..\Run: [zkrs056v9myzx2a6p8x0mvza4y3k77m] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hxupqk.exe
O4 - HKCU\..\Run: [wntdutq77eb2c6rkigfmbyfj3rcvdue3k3uhf9k8fx66us] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xdi7h0h.exe
O4 - HKCU\..\Run: [krib7o62a09isefvebmqkn1mtyhgezw5] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\rj3hqoljz.exe
O4 - HKCU\..\Run: [pa4cw283qemmltec615w9] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\lvv683wy8c1lw.exe
O4 - HKCU\..\Run: [gnrtxl3j0l1lmvt9cnvav5tc] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\i1gzynal.exe
O4 - HKCU\..\Run: [ahg6gk9ojwxgvi7hhdy1dgvcgyi15ylw0gwp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\zs61x3l.exe
O4 - HKCU\..\Run: [a1hq5xdcwe6m5h3gp8ebavquguc6pb1fkg2mdmj3] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\tyrury3hgr.exe
O4 - HKCU\..\Run: [adp9e72vwkav81jegtpzww2fuzrsgu39em9rm] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\yamddtdads.exe
O4 - HKCU\..\Run: [k0kmjvval49fl0p9eji3mx2fsxcvts] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hx74x7fiqen.exe
O4 - HKCU\..\Run: [v7v4sl9jvtvs0hgo] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\qxntld0z7.exe
O4 - HKCU\..\Run: [w4f3t4cvqw1otq1r98dp3zh62ayxt4kw54t3ez3] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\z183or27k2.exe
O4 - HKCU\..\Run: [laikfcprvs1vz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\r7w3bn9p.exe
O4 - HKCU\..\Run: [z0wwdsleti] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\s2cex7qlghel.exe
O4 - HKCU\..\Run: [lea5z886l7qk6h0tpcj8r6y9dml23195v] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\uo2c7mr9ts9.exe
O4 - HKCU\..\Run: [f97jpjtuzj0kgky06] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\vounq538ppzj.exe
O4 - HKCU\..\Run: [ryk2gtiwnenihzr8376gwcmyvz0oihe0hk5o2vzt97ix8lybc6] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\t38k3bis3p7al.exe
O4 - HKCU\..\Run: [ongyaka9nocq2yn3j262u7sfk] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f50vs4d.exe
O4 - HKCU\..\Run: [x20jt7q69l3966yqq17t3bidyy0lims8z6vu4kqogugam7n35] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xhjxpckmt1pgm.exe
O4 - HKCU\..\Run: [yglkyqg7f1rdwa] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\c1bqownrr28.exe
O4 - HKCU\..\Run: [ow0owf3y44qq2otx1hzi5grkdrd7cm3w687k] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\cwx90b8u38wg.exe
O4 - HKCU\..\Run: [omuzfata5ddwer2eajbp3msf9n6gpwzrmafssgn0455] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\k9k5mq.exe
O4 - HKCU\..\Run: [l8dtlntzivepyu9u] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\jqhbuob240e.exe
O4 - HKCU\..\Run: [v3577xcujgetocj7se7q1l39g1kc495119oe] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\mhhy2mho.exe
O4 - HKCU\..\Run: [oakusxy7f0v98jmlv43eocpsthk7cyzyzv5e8] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\dw2l3tf3k4bcz.exe
O4 - HKCU\..\Run: [szdw4xv7s3p9iqvcgeiy4r] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\i7lj8mhcgumf.exe
O4 - HKCU\..\Run: [zl19v132mdys] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xdppb5ib4lqy.exe
O4 - HKCU\..\Run: [alpc4dhchszxzm7smzc17s65elksgh] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\nrjcyjw2.exe
O4 - HKCU\..\Run: [eqkc1y97ju8aivsxkvolxref] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f99gn5s.exe
O4 - HKCU\..\Run: [hrhrhxh5w8b42d0i36su] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\pws1mzymt8.exe
O4 - HKCU\..\Run: [h2jqoxb6d2nmzqwuz3cvp4] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\itz3z19.exe
O4 - HKCU\..\Run: [af1g1vbdtnxqieq4ys5f2bx8v113kn394uh6wuf3oaanzs9v] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hodph1uro8bfi.exe
O4 - HKCU\..\Run: [i9jhe68max] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\px88ru8e5emz.exe
O4 - HKCU\..\Run: [jwo8cxrtvkkucqdq5d4f9sfqeudy] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\zkrtqoe.exe
O4 - HKCU\..\Run: [ino7oolzf64ub8chxc3c2edf69fsonm3bo6x28z3wkyacmfim] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\alrbnlflrfsk.exe
O4 - HKCU\..\Run: [bi6cco8o3ad3xa] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ox5ezshvn.exe
O4 - HKCU\..\Run: [huhmu0w3jd5k] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\y1ozymnawl3r.exe
O4 - HKCU\..\Run: [awabe62wi5dh5x] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\rhv1uofts.exe
O4 - HKCU\..\Run: [fwgg2fr3ib6lxm2ifg8yjaz6v5jk580949h] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\blemtilr1x25.exe
O4 - HKCU\..\Run: [hr2d2769x2u2n8lgv3y4kjlgs7xjr2yau3a43r01fptx] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\njlngqv9593ee.exe
O4 - HKCU\..\Run: [jag7wjp5id0mv9r69t] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\mmmy70j4eoid.exe
O4 - HKCU\..\Run: [iuto7v28tfh4tw8omr1] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\i3q78glw3oy.exe
O4 - HKCU\..\Run: [a91ywwtuwf6cfz18v5y8qyaqi8rmj482sif6] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\uihp9jr1z.exe
O4 - HKCU\..\Run: [uwoxucafhylikcqglmkqs0i16bkyvbe53gb0cqwhfc] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\not7go23jv.exe
O4 - HKCU\..\Run: [w65gyv42br6qjwgg0f7l6tvngg455ykujkts] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\x27clfpil.exe
O4 - HKCU\..\Run: [ob5hyz8pdsuwmv1iiepnc2f64q3ru5x414ltnpgv] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\k01oek56iw.exe
O4 - HKCU\..\Run: [ojgyghzsnb0l8wwpkhgyl0rnpb0ohp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\rdpp7fu4y.exe
O4 - HKCU\..\Run: [jvu2euku5favq55oz5y0h0mo6z6623h98ijyzpd0o8cyp9] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\la6m516yjqc.exe
O4 - HKCU\..\Run: [ewlc74dtb] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ok1pbh6.exe
O4 - HKCU\..\Run: [lqe58li4fa73jsoehltre1ntgvkp394lwzdwqt5xkz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\gg8qamx.exe
O4 - HKCU\..\Run: [venv3pi7q5z5c8v13soxi] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\v73rascdle.exe
O4 - HKCU\..\Run: [cfn0xtg48sp49ohrh3ehm6tj5j4xjv2fx16ldrkf3qcs8] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\nkrb9x3448.exe
O4 - HKCU\..\Run: [bg3r4q04nkwmp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\cynb9ym.exe
O4 - HKCU\..\Run: [qvyktn7ly9x6xryayo5diadsgqj2kt8zigxalc7xcam4v] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\fe7mhlz.exe
O4 - HKCU\..\Run: [tvh8t8p5tfah] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ra565o2lm.exe
O4 - HKCU\..\Run: [k7y0o1b4sd0pkhr1cj7kd44rrhirdvg63gyx] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\dcx0uygdlhq.exe
O4 - HKCU\..\Run: [rhrxvuv0c9lllacmj61cnxhvceshq] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\uzwu52sjjq.exe
O4 - HKCU\..\Run: [ig1ps46pbghr84ybbt2nkni1onp9h4prn89vm8xro646oyh] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\kdqh9z.exe
O4 - HKCU\..\Run: [fv3jqdbxgzn9omrxktokgyuj46n79h55fv1w] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\dbar89ziio.exe
O4 - HKCU\..\Run: [d5miwxgyxrg2ecmr61oqe09ahwlsbzs1icqkymde3uavkgc] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\o109iydb0q.exe
O4 - HKCU\..\Run: [ic7xn1yvr44mw4o] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\qpddnh7.exe
O4 - HKCU\..\Run: [k9d3beq9yuohug4qmcn9fboyottb5o] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\agdawn6si.exe
O4 - HKCU\..\Run: [ktud582s0aqruo26vhi0qsbukyrfxt28ck8u5s] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\y0kyj38mz.exe
O4 - HKCU\..\Run: [lirkja3p68n4nyf0qllswr4yi4qcu4wrwc6cyowcr2igovchz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\y5lyq2m5njn5.exe
O4 - HKCU\..\Run: [zby8h7axpd34j32] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hhqde6bt.exe
O4 - HKCU\..\Run: [urt8z7oqkc2qvrnovw75otxx9nf] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\m6ppxzuudt.exe
O4 - HKCU\..\Run: [d49s4ltc2da7l8rrh7gwfu1820] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\gcaznnyvax8m.exe
O4 - HKCU\..\Run: [tvfsj3fg4wzmeb6zl4obykfkrycpdvsbmvv1lloo6dt7fymw1u] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ngj4fggl9.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Alienware Dock.lnk = C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe
O4 - Startup: iPhoneRingToneMaker.lnk = C:\Program Files\iPhoneRingToneMaker\iPhoneRingToneMaker.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: UltraMon.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Delicious - {2C887991-08F0-11DC-A9B2-0012F0B227DD} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll
O9 - Extra button: Bookmarks - {2C887992-08F0-11DC-A9B2-0012F0B227DD} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll
O9 - Extra button: Tag - {2C887993-08F0-11DC-A9B2-0012F0B227DD} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll (file missing)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - http://w4s2.work4sure.com/c/ge/w4sgeen9.exe
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} - http://www.photodex.com/pxplay.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: acaptuser32.dll,wbsys.dll
O20 - Winlogon Notify: tuVnMFvW - tuVnMFvW.dll (file missing)
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\hs78344kjkfd.dll
O23 - Service: dotDefender Log Service (aclogsvc) - Unknown owner - C:\Program Files\Applicure\dotDefender for IIS\bin\aclogsvc.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: AMP 3.0 Sensor for WebInspect (AmpSensor3.0-WebInspect) - Hewlett-Packard Company - C:\Program Files\HP\HP WebInspect\AmpSensorWI.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Pervasive.SQL Workgroup Engine - Unknown owner - C:\WINDOWS\system32\srvany.exe
O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\system32\HPZipm12.exe (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WebInspect Scheduler Service - Hewlett-Packard Company - C:\Program Files\HP\HP WebInspect\WIScheduler.exe

–
End of file - 24684 bytes
hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scans box at the bottom copy and paste this into it

    net services
    msconfig
    safeboot minimal
    safeboot network


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
I can only get the OTListIt file to get created. The program freezes when it gets to helpsvc…

OTListIt logfile created on: 2/19/2009 12:34:53 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.18 Folder = C:\Documents and Settings\Justin Ward\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 3.81 Gb Available in Paging File | 95.23% Paging File free
Paging file location(s): C:\pagefile.sys 2000 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.80 Gb Total Space | 22.36 Gb Free Space | 32.03% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 68.36 Gb Total Space | 42.92 Gb Free Space | 62.79% Space Free | Partition Type: NTFS
Drive F: | 121.55 Gb Total Space | 0.28 Gb Free Space | 0.23% Space Free | Partition Type: NTFS
Drive G: | 510.35 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JDOUBLEYA
Current User Name: Justin Ward
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Applicure\dotDefender for IIS\bin\aclogsvc.exe ()
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE (C-Dilla Ltd)
PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\SplineTech JavaScript HTML Debugger\mdm.exe (Microsoft Corporation)
PRC - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe (PC Tools Research Pty Ltd)
PRC - C:\WINDOWS\system32\srvany.exe ()
PRC - C:\pvsw\bin\w3dbsmgr.exe ()
PRC - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe ()
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\HP\HP WebInspect\WIScheduler.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\AlienGUIse\wbload.exe (Stardock Systems, Inc)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\userinit.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Documents and Settings\Justin Ward\Local Settings\Temp\winlognn.exe ()
PRC - C:\WINDOWS\system32\frmwrk32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\system32\ntdll64.exe ()
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\AIM6\aim6.exe (AOL LLC)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Documents and Settings\Justin Ward\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe (YourWare Solutions ™)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\UltraMon\UltraMon.exe (Realtime Soft Ltd)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\UltraMon\UltraMonTaskbar.exe (Realtime Soft Ltd)
PRC - C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe (Stardock)
PRC - C:\Program Files\AIM6\aolsoftware.exe (AOL LLC)
PRC - C:\Program Files\iPhoneRingToneMaker\iPhoneRingToneMaker.exe ()
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe (Lavasoft)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\system32\ntdll64.exe ()
PRC - C:\Documents and Settings\Justin Ward\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (6to4 [Auto | Running]) – C:\WINDOWS\System32\6to4svc.dll (Microsoft Corporation)
SRV - (aclogsvc [Auto | Running]) – C:\Program Files\Applicure\dotDefender for IIS\bin\aclogsvc.exe ()
SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Adobe Version Cue CS3 [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)
SRV - (AmpSensor3.0-WebInspect [Auto | Stopped]) – C:\Program Files\HP\HP WebInspect\AmpSensorWI.exe (Hewlett-Packard Company)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (C-DillaSrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE (C-Dilla Ltd)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (ehRecvr [Auto | Running]) – C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) – C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IISADMIN [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (McrdSvc [Auto | Stopped]) – C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (MDM [Auto | Running]) – C:\Program Files\SplineTech JavaScript HTML Debugger\mdm.exe (Microsoft Corporation)
SRV - (MHN [On_Demand | Stopped]) – C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service [On_Demand | Stopped]) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (NetSvc [On_Demand | Stopped]) – C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PCTAVSvc [Auto | Running]) – C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe (PC Tools Research Pty Ltd)
SRV - (Pervasive.SQL Workgroup Engine [Auto | Running]) – C:\WINDOWS\system32\srvany.exe ()
SRV - (Pml Driver HPZ12 [On_Demand | Stopped]) – File not found
SRV - (ProtexisLicensing [Auto | Running]) – C:\Program Files\Common Files\Protexis\License Service\PSIService.exe ()
SRV - (SMTPSVC [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Running]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (W3SVC [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (WebInspect Scheduler Service [Auto | Running]) – C:\Program Files\HP\HP WebInspect\WIScheduler.exe (Hewlett-Packard Company)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (AN983 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\AN983.sys (ADMtek Incorporated.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ASCTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ATIAVPCI [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinavxx.sys (ATI Technologies Inc.)
DRV - (AVFilter [Auto | Running]) – C:\WINDOWS\system32\drivers\AVFilter.sys (PC Tools Research Pty Ltd)
DRV - (AVHook [On_Demand | Running]) – C:\WINDOWS\system32\drivers\AVHook.sys (PC Tools Research Pty Ltd.)
DRV - (AVRec [On_Demand | Running]) – C:\WINDOWS\system32\drivers\AVRec.sys (PC Tools Research Pty Ltd )
DRV - (C-Dilla [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\CDANT.SYS (Macrovision)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DLABOIOM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLACDBHM [System | Running]) – C:\WINDOWS\System32\Drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLADResN [Auto | Running]) – C:\WINDOWS\System32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLAIFS_M [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLAOPIOM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLARTL_N [System | Running]) – C:\WINDOWS\System32\Drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (DLAUDFAM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DRVMCDB [Boot | Running]) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DRVNDDM [Auto | Running]) – C:\WINDOWS\System32\Drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWBS2 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (MODEMCSA [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (MPE [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\MPE.sys (Microsoft Corporation)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RivaTuner32 [On_Demand | Stopped]) – C:\Program Files\RivaTuner v2.0 Final Release\RivaTuner32.sys ()
DRV - (SCDEmu [System | Running]) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sptd [Boot | Running]) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (StarPortLite [System | Running]) – C:\WINDOWS\system32\DRIVERS\StarPortLite.sys (Rocket Division Software)
DRV - (STHDA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (Tcpip6 [System | Running]) – C:\WINDOWS\system32\DRIVERS\tcpip6.sys (Microsoft Corporation)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (UltraMonMirror [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\UltraMonMirror.sys (Realtime Soft)
DRV - (UltraMonUtility [Auto | Running]) – C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys (Realtime Soft)
DRV - (USBAAPL [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (winachsf [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (XUIF [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Invalid data type.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Invalid data type.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com/ig/dell?hl=en&cl…&channel=us

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = Reg Error: Invalid data type.
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = Reg Error: Invalid data type.
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

O1 HOSTS File: (57 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 80.95.132.35 www.expekt.com 80.95.132.35 expekt.com
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (C:\WINDOWS\system32\hs78344kjkfd.dll) - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\hs78344kjkfd.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (StumbleUpon Toolbar) - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll (stumbleupon.com)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe [2008/12/17 15:14:03 00,000,000 | —D | M]
O3 - HKLM\..\Toolbar: (Delicious Toolbar) - {61D1C847-DF80-423A-8C6D-DC03B97E6EBE} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll (Yahoo!)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Visual IP Trace) - {E70C26AE-DFF1-40A8-8D37-19180F56F0AA} - C:\Program Files\Visual IP Trace 2007\VisualIPTraceIE.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {61D1C847-DF80-423A-8C6D-DC03B97E6EBE} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll (Yahoo!)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" (ATI Technologies, Inc.)
O4 - HKLM..\Run: [Cleanup] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\200921911740_mcappins.exe /v=3 /cleanup File not found
O4 - HKLM..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [Framework Windows] frmwrk32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [Hkovorukemo] rundll32.exe "C:\WINDOWS\ucitevih.dll",e (Mozilla Foundation)
O4 - HKLM..\Run: [HPLJ Config] C:\Program Files\Hewlett-Packard\hp LaserJet 1150_1300\SetConfig.exe -c Direct -p \\RICH\Printer2 -pn "hp LaserJet 1300 PCL 6" -n 0 -l 1033 -sl 120000 File not found
O4 - HKLM..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup (InstallShield Software Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\winlognn.exe ()
O4 - HKLM..\Run: [msci] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\200921911734_mcinfo.exe /insfin File not found
O4 - HKLM..\Run: [NvSvc] C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN (PC Tools Research Pty Ltd)
O4 - HKLM..\Run: [POEngine] File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Vcomohaqiteji] rundll32.exe "C:\WINDOWS\Tyadabadeb.dll",e ()
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [a191x79n6j19j27woypg8akyfre] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f4ch1c5vqa8c.exe File not found
O4 - HKCU..\Run: [a1hq5xdcwe6m5h3gp8ebavquguc6pb1fkg2mdmj3] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\tyrury3hgr.exe File not found
O4 - HKCU..\Run: [a91ywwtuwf6cfz18v5y8qyaqi8rmj482sif6] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\uihp9jr1z.exe File not found
O4 - HKCU..\Run: [a9iap34n2y8] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\t4d23ml19qp.exe File not found
O4 - HKCU..\Run: [adp9e72vwkav81jegtpzww2fuzrsgu39em9rm] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\yamddtdads.exe File not found
O4 - HKCU..\Run: [af1g1vbdtnxqieq4ys5f2bx8v113kn394uh6wuf3oaanzs9v] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hodph1uro8bfi.exe File not found
O4 - HKCU..\Run: [ahg6gk9ojwxgvi7hhdy1dgvcgyi15ylw0gwp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\zs61x3l.exe File not found
O4 - HKCU..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (AOL LLC)
O4 - HKCU..\Run: [alpc4dhchszxzm7smzc17s65elksgh] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\nrjcyjw2.exe File not found
O4 - HKCU..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h File not found
O4 - HKCU..\Run: [awabe62wi5dh5x] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\rhv1uofts.exe File not found
O4 - HKCU..\Run: [azqq4ymzxe6p2oesy2mkhnelkln1h6m372] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xpi3zhl54hy.exe File not found
O4 - HKCU..\Run: [bg3r4q04nkwmp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\cynb9ym.exe File not found
O4 - HKCU..\Run: [bi6cco8o3ad3xa] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ox5ezshvn.exe File not found
O4 - HKCU..\Run: [bnnqdds8f4h1] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\qndogi64u.exe File not found
O4 - HKCU..\Run: [bqhsnkw2najvltz1r43i8xoivpy8ic0ozre9561mva88ak04] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\vlst73.exe File not found
O4 - HKCU..\Run: [c2c58klinb0l7wqz7oaalhise0apjqw9h4hklhdqh7ni] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\oxm0bvolai06.exe File not found
O4 - HKCU..\Run: [c5aje7761df246gnxtibusumghp4nmsvo6n6zo] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\e40ouqdkjjwxp.exe File not found
O4 - HKCU..\Run: [cfn0xtg48sp49ohrh3ehm6tj5j4xjv2fx16ldrkf3qcs8] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\nkrb9x3448.exe File not found
O4 - HKCU..\Run: [d2l9flclm2n6ovkgkdyp95fz88zjgelw39kloycq97nbc] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\enk5je.exe File not found
O4 - HKCU..\Run: [d49s4ltc2da7l8rrh7gwfu1820] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\gcaznnyvax8m.exe File not found
O4 - HKCU..\Run: [d5miwxgyxrg2ecmr61oqe09ahwlsbzs1icqkymde3uavkgc] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\o109iydb0q.exe File not found
O4 - HKCU..\Run: [dfvemqqi7uy] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\q100rnvl.exe File not found
O4 - HKCU..\Run: [e4d9xq0gxozh5yqy8inoektvucc3g] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\kjjd797d8j775.exe File not found
O4 - HKCU..\Run: [eqkc1y97ju8aivsxkvolxref] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f99gn5s.exe File not found
O4 - HKCU..\Run: [ewlc74dtb] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ok1pbh6.exe File not found
O4 - HKCU..\Run: [f97jpjtuzj0kgky06] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\vounq538ppzj.exe File not found
O4 - HKCU..\Run: [fhdvrisxij1ov28p6ok6kom1cv4m1] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\t4mqusyucwq.exe File not found
O4 - HKCU..\Run: [fnwd0e3x6xp0otnyuzf74xm278] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\okstgo1.exe File not found
O4 - HKCU..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win (YourWare Solutions ™)
O4 - HKCU..\Run: [fv3jqdbxgzn9omrxktokgyuj46n79h55fv1w] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\dbar89ziio.exe File not found
O4 - HKCU..\Run: [fwgg2fr3ib6lxm2ifg8yjaz6v5jk580949h] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\blemtilr1x25.exe File not found
O4 - HKCU..\Run: [gnrtxl3j0l1lmvt9cnvav5tc] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\i1gzynal.exe File not found
O4 - HKCU..\Run: [Google Update] "C:\Documents and Settings\Justin Ward\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKCU..\Run: [gpm9hup22jndklp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xs3khwse5gua.exe File not found
O4 - HKCU..\Run: [h2jqoxb6d2nmzqwuz3cvp4] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\itz3z19.exe File not found
O4 - HKCU..\Run: [hr2d2769x2u2n8lgv3y4kjlgs7xjr2yau3a43r01fptx] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\njlngqv9593ee.exe File not found
O4 - HKCU..\Run: [hrhrhxh5w8b42d0i36su] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\pws1mzymt8.exe File not found
O4 - HKCU..\Run: [hs8oy8fprxahhpcer] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xcvkb8v3v7h.exe File not found
O4 - HKCU..\Run: [huhmu0w3jd5k] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\y1ozymnawl3r.exe File not found
O4 - HKCU..\Run: [i9jhe68max] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\px88ru8e5emz.exe File not found
O4 - HKCU..\Run: [ic7xn1yvr44mw4o] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\qpddnh7.exe File not found
O4 - HKCU..\Run: [ig1ps46pbghr84ybbt2nkni1onp9h4prn89vm8xro646oyh] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\kdqh9z.exe File not found
O4 - HKCU..\Run: [ino7oolzf64ub8chxc3c2edf69fsonm3bo6x28z3wkyacmfim] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\alrbnlflrfsk.exe File not found
O4 - HKCU..\Run: [iuto7v28tfh4tw8omr1] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\i3q78glw3oy.exe File not found
O4 - HKCU..\Run: [ixlg10f6tz27xs22p1kfgpielzzwdxyw9lpi] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hlr8ot9.exe File not found
O4 - HKCU..\Run: [j4i5nlypax50nvlmh0c97kbhmz5k91legryexcamk] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\nms9t5n.exe File not found
O4 - HKCU..\Run: [jag7wjp5id0mv9r69t] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\mmmy70j4eoid.exe File not found
O4 - HKCU..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\winlognn.exe ()
O4 - HKCU..\Run: [jvu2euku5favq55oz5y0h0mo6z6623h98ijyzpd0o8cyp9] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\la6m516yjqc.exe File not found
O4 - HKCU..\Run: [jwo8cxrtvkkucqdq5d4f9sfqeudy] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\zkrtqoe.exe File not found
O4 - HKCU..\Run: [jz2wqwc2jh2v7n87stsmgtmiw1p2blqxr] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xo8110q8ch3y.exe File not found
O4 - HKCU..\Run: [k0kmjvval49fl0p9eji3mx2fsxcvts] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hx74x7fiqen.exe File not found
O4 - HKCU..\Run: [k7y0o1b4sd0pkhr1cj7kd44rrhirdvg63gyx] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\dcx0uygdlhq.exe File not found
O4 - HKCU..\Run: [k9d3beq9yuohug4qmcn9fboyottb5o] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\agdawn6si.exe File not found
O4 - HKCU..\Run: [krib7o62a09isefvebmqkn1mtyhgezw5] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\rj3hqoljz.exe File not found
O4 - HKCU..\Run: [ktb0t1dldnuk0z8s52f082mws8i0yx8xob6t7gu] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\s6e6b63hesw.exe File not found
O4 - HKCU..\Run: [ktud582s0aqruo26vhi0qsbukyrfxt28ck8u5s] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\y0kyj38mz.exe ()
O4 - HKCU..\Run: [l8dtlntzivepyu9u] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\jqhbuob240e.exe File not found
O4 - HKCU..\Run: [laikfcprvs1vz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\r7w3bn9p.exe File not found
O4 - HKCU..\Run: [lea5z886l7qk6h0tpcj8r6y9dml23195v] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\uo2c7mr9ts9.exe File not found
O4 - HKCU..\Run: [lirkja3p68n4nyf0qllswr4yi4qcu4wrwc6cyowcr2igovchz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\y5lyq2m5njn5.exe File not found
O4 - HKCU..\Run: [lqe58li4fa73jsoehltre1ntgvkp394lwzdwqt5xkz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\gg8qamx.exe File not found
O4 - HKCU..\Run: [oakusxy7f0v98jmlv43eocpsthk7cyzyzv5e8] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\dw2l3tf3k4bcz.exe File not found
O4 - HKCU..\Run: [ob5hyz8pdsuwmv1iiepnc2f64q3ru5x414ltnpgv] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\k01oek56iw.exe File not found
O4 - HKCU..\Run: [ojgyghzsnb0l8wwpkhgyl0rnpb0ohp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\rdpp7fu4y.exe File not found
O4 - HKCU..\Run: [omuzfata5ddwer2eajbp3msf9n6gpwzrmafssgn0455] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\k9k5mq.exe File not found
O4 - HKCU..\Run: [ongyaka9nocq2yn3j262u7sfk] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f50vs4d.exe File not found
O4 - HKCU..\Run: [ow0owf3y44qq2otx1hzi5grkdrd7cm3w687k] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\cwx90b8u38wg.exe File not found
O4 - HKCU..\Run: [pa4cw283qemmltec615w9] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\lvv683wy8c1lw.exe File not found
O4 - HKCU..\Run: [pru7o969axu3ffk2] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\lv14smnscue8.exe File not found
O4 - HKCU..\Run: [pz4yzjca7dvrz7w4qdnimka6tt0] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f954x9u3b93.exe File not found
O4 - HKCU..\Run: [qkpe4bm37mdamlbh9w3vposohnmsgqcnmzx9f0xkwu] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ueohl3osop.exe File not found
O4 - HKCU..\Run: [qvyktn7ly9x6xryayo5diadsgqj2kt8zigxalc7xcam4v] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\fe7mhlz.exe File not found
O4 - HKCU..\Run: [rhrxvuv0c9lllacmj61cnxhvceshq] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\uzwu52sjjq.exe File not found
O4 - HKCU..\Run: [rmnd6l94rxvba5qsomy2shbl98uq] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\miwltw3i0spc6.exe File not found
O4 - HKCU..\Run: [rulm8siujym5hfhg8ofyjcnexh] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\cujf6c.exe File not found
O4 - HKCU..\Run: [rwmqut43mk5jpgs8sq9u1ktqwxskf7snns1u] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\gohvjkq.exe File not found
O4 - HKCU..\Run: [ryk2gtiwnenihzr8376gwcmyvz0oihe0hk5o2vzt97ix8lybc6] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\t38k3bis3p7al.exe File not found
O4 - HKCU..\Run: [sfjjzm3pxvl5stwiklfz7kd] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\qnx1124x99v.exe File not found
O4 - HKCU..\Run: [skob19httrc33w0ffcnja] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f2ywbe32gqh.exe File not found
O4 - HKCU..\Run: [szdw4xv7s3p9iqvcgeiy4r] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\i7lj8mhcgumf.exe File not found
O4 - HKCU..\Run: [t5k8fcekpw13] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\powlndyn6j5a.exe File not found
O4 - HKCU..\Run: [tcmcqp3pbi1g2k80ey9s20hhl7cqyjobm7vjycc8] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\oizv35he3bp.exe File not found
O4 - HKCU..\Run: [Tristana] "C:\Program Files\eRSS Reader\Reader.exe" File not found
O4 - HKCU..\Run: [tvfsj3fg4wzmeb6zl4obykfkrycpdvsbmvv1lloo6dt7fymw1u] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ngj4fggl9.exe File not found
O4 - HKCU..\Run: [tvh8t8p5tfah] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ra565o2lm.exe File not found
O4 - HKCU..\Run: [uqfes7bu2dt5pme4s] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ndo0boji7vc.exe File not found
O4 - HKCU..\Run: [uqfy1tlq9h6ili6fc3t4kax4a9x8z08so85hddyxz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\vv2v50k5piz5.exe File not found
O4 - HKCU..\Run: [urt8z7oqkc2qvrnovw75otxx9nf] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\m6ppxzuudt.exe File not found
O4 - HKCU..\Run: [uw6ejwixxs4ek38sedtcrc39cleube3c0zm] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\esq9op661fqei.exe File not found
O4 - HKCU..\Run: [uwoxucafhylikcqglmkqs0i16bkyvbe53gb0cqwhfc] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\not7go23jv.exe File not found
O4 - HKCU..\Run: [v3577xcujgetocj7se7q1l39g1kc495119oe] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\mhhy2mho.exe File not found
O4 - HKCU..\Run: [v7v4sl9jvtvs0hgo] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\qxntld0z7.exe File not found
O4 - HKCU..\Run: [venv3pi7q5z5c8v13soxi] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\v73rascdle.exe File not found
O4 - HKCU..\Run: [vxqb37qz39p3e2yxhb456e8dbtv08ctjpjgugpx7vn] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\wj2pr25g.exe File not found
O4 - HKCU..\Run: [vzisn8y2cidi3l88as8vm] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\orvkc5x.exe File not found
O4 - HKCU..\Run: [w4f3t4cvqw1otq1r98dp3zh62ayxt4kw54t3ez3] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\z183or27k2.exe File not found
O4 - HKCU..\Run: [w5qsj9cf2o4j] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\kn25c79pey5x.exe File not found
O4 - HKCU..\Run: [w65gyv42br6qjwgg0f7l6tvngg455ykujkts] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\x27clfpil.exe File not found
O4 - HKCU..\Run: [wbgt0286sn] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xfvryaeq.exe File not found
O4 - HKCU..\Run: [wntdutq77eb2c6rkigfmbyfj3rcvdue3k3uhf9k8fx66us] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xdi7h0h.exe File not found
O4 - HKCU..\Run: [x20jt7q69l3966yqq17t3bidyy0lims8z6vu4kqogugam7n35] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xhjxpckmt1pgm.exe File not found
O4 - HKCU..\Run: [xrcv1k3z8frp22l9mg4bsn26nbqie] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ikqgjyhmo955w.exe File not found
O4 - HKCU..\Run: [yglkyqg7f1rdwa] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\c1bqownrr28.exe File not found
O4 - HKCU..\Run: [z0wwdsleti] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\s2cex7qlghel.exe File not found
O4 - HKCU..\Run: [z22svugzj] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\n8m9tm.exe File not found
O4 - HKCU..\Run: [zby8h7axpd34j32] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hhqde6bt.exe File not found
O4 - HKCU..\Run: [zcggpb06yy4yrykoxha9hs3dwfv6rto51] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\u6tdgyij40fr.exe File not found
O4 - HKCU..\Run: [zkrs056v9myzx2a6p8x0mvza4y3k77m] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hxupqk.exe File not found
O4 - HKCU..\Run: [zl19v132mdys] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xdppb5ib4lqy.exe File not found
O4 - HKCU..\Run: [ztr8nm77q5xuv6nz81ycb6dt] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\fd117itww.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UltraMon.lnk = C:\WINDOWS\Installer\{AF0FA6D7-96F3-468A-ABB7-28BE006EA8E9}\IcoUltraMon.ico ()
O4 - Startup: C:\Documents and Settings\Justin Ward\Start Menu\Programs\Startup\Alienware Dock.lnk = C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe (Stardock)
O4 - Startup: C:\Documents and Settings\Justin Ward\Start Menu\Programs\Startup\iPhoneRingToneMaker.lnk = C:\Program Files\iPhoneRingToneMaker\iPhoneRingToneMaker.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMyMusic = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInstrumentation = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSimpleStartMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Activities present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogOff = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: GreyMSIAds = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuEjectPC = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThemesTab = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: Shell = sdcsdc
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoColorChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSizeChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVisualStyleChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Delicious - {2C887991-08F0-11DC-A9B2-0012F0B227DD} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll (Yahoo!)
O9 - Extra Button: Bookmarks - {2C887992-08F0-11DC-A9B2-0012F0B227DD} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll (Yahoo!)
O9 - Extra Button: Tag - {2C887993-08F0-11DC-A9B2-0012F0B227DD} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll (Yahoo!)
O9 - Extra Button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll File not found
O9 - Extra 'Tools' menuitem : Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 8 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} http://w4s2.work4sure.com/c/ge/w4sgeen9.exe (Reg Error: Key error.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} http://download.microsoft.com/download/7/1…20/pmupd806.exe (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} http://www.photodex.com/pxplay.cab (Reg Error: Key error.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (acaptuser32.dll) - File not found
O20 - AppInit_DLLs: (wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe ()
O20 - Winlogon\Notify\tuVnMFvW: DllName - tuVnMFvW.dll - File not found
O20 - Winlogon\Notify\WB: DllName - C:\Program Files\AlienGUIse\fastload.dll - C:\Program Files\AlienGUIse\fastload.dll (Stardock)
O22 - SharedTaskScheduler: {C5BF49A2-94F3-42BD-F434-3604812C8955} - jgzfkj9w38rksndfi7r4 - C:\WINDOWS\system32\hs78344kjkfd.dll ()
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {88485281-8b4b-4f8d-9ede-82e29a064277} - C:\Program Files\MarkAny\ContentSAFER\MACSMANAGER.dll (MarkAny Cooperation.)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[10 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/02/19 12:33:48 | 00,494,592 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Justin Ward\Desktop\OTListIt2.exe
[2009/02/19 12:14:02 | 00,001,740 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\HijackThis.lnk
[2009/02/19 12:14:02 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/19 12:12:46 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Justin Ward\Desktop\HJTInstall.exe
[2009/02/19 12:02:27 | 00,000,200 | -H– | C] () – C:\aaw7boot.cmd
[2009/02/19 11:55:37 | 00,104,960 | —- | C] () – C:\WINDOWS\System32\ntdll64.exe
[2009/02/19 11:49:46 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/02/19 11:43:10 | 00,001,347 | —- | C] () – C:\WINDOWS\System32\ahtn.htm
[2009/02/19 11:43:09 | 00,004,785 | —- | C] () – C:\WINDOWS\System32\warning.gif
[2009/02/19 11:43:06 | 00,104,960 | —- | C] () – C:\WINDOWS\System32\dllcache\userinit.exe
[2009/02/19 11:43:06 | 00,000,439 | —- | C] () – C:\WINDOWS\System32\win32hlp.cnf
[2009/02/19 11:22:41 | 00,108,032 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\ResetSecuritySettingsBackToTheDefaults(2).msi
[2009/02/19 11:08:49 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/02/19 11:08:40 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/02/19 11:06:57 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/02/19 11:06:56 | 00,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/02/19 11:06:22 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2009/02/19 11:06:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/02/19 10:52:15 | 00,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2009/02/19 10:42:33 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\Desktop\smitRem
[2009/02/19 10:41:58 | 34,543,112 | —- | C] (Lavasoft ) – C:\Documents and Settings\Justin Ward\Desktop\Ad-AwareAE.exe
[2009/02/19 10:40:46 | 00,000,000 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\avg_avwt_stf_en_8_237a1428.exe
[2009/02/19 10:40:44 | 14,813,076 | —- | C] (AVG Technologies) – C:\Documents and Settings\Justin Ward\Desktop\avg_avwt_stf_en_8_237a1428.exe.part
[2009/02/19 10:40:15 | 00,383,836 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\smitRem.exe
[2009/02/19 10:30:08 | 03,153,920 | —- | C] () – C:\WINDOWS\System32\secsetup.sdb
[2009/02/19 10:29:29 | 00,108,032 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\ResetSecuritySettingsBackToTheDefaults.msi
[2009/02/18 16:12:46 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\{096DF24C-78B9-4FE5-ABAD-74E000BCD27D}
[2009/02/18 16:12:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\Application Data\PC Tools
[2009/02/18 16:12:28 | 00,134,144 | —- | C] (Mozilla Foundation) – C:\WINDOWS\ucitevih.dll
[2009/02/18 16:11:05 | 00,000,671 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PC Tools AntiVirus.lnk
[2009/02/18 16:11:05 | 00,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2009/02/18 16:11:04 | 00,028,568 | —- | C] (PC Tools Research Pty Ltd.) – C:\WINDOWS\System32\drivers\AVHook.sys
[2009/02/18 16:11:04 | 00,021,912 | —- | C] (PC Tools Research Pty Ltd ) – C:\WINDOWS\System32\drivers\AVRec.sys
[2009/02/18 16:11:04 | 00,021,904 | —- | C] (PC Tools Research Pty Ltd) – C:\WINDOWS\System32\drivers\AVFilter.sys
[2009/02/18 16:10:54 | 00,000,000 | —D | C] – C:\Program Files\PC Tools AntiVirus
[2009/02/18 16:10:54 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2009/02/18 16:07:41 | 29,688,176 | —- | C] (PC Tools ) – C:\Documents and Settings\Justin Ward\Desktop\avinstall.exe
[2009/02/18 15:27:17 | 00,000,328 | —- | C] () – C:\WINDOWS\tasks\hrtgmihd.job
[2009/02/18 15:26:49 | 00,000,000 | —- | C] () – C:\pbjrtsau.exe
[2009/02/18 15:26:49 | 00,000,000 | —- | C] () – C:\mlafhs.exe
[2009/02/18 15:26:48 | 00,000,000 | —- | C] () – C:\qmbkgm.exe
[2009/02/18 15:26:48 | 00,000,000 | —- | C] () – C:\epri.exe
[2009/02/18 15:26:33 | 00,000,001 | —- | C] () – C:\WINDOWS\System32\uniq.tll
[2009/02/18 15:26:13 | 00,000,000 | —- | C] () – C:\-1463359964
[2009/02/18 15:26:12 | 00,008,704 | —- | C] () – C:\emvwk.exe
[2009/02/18 15:26:11 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\frmwrk32.exe
[2009/02/18 15:26:08 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\kjqgqk.exe
[2009/02/18 15:26:04 | 00,064,000 | —- | C] () – C:\joehug.exe
[2009/02/18 15:26:03 | 00,015,000 | —- | C] () – C:\WINDOWS\System32\hs78344kjkfd.dll
[2009/02/18 15:26:00 | 00,039,936 | —- | C] () – C:\WINDOWS\Tyadabadeb.dll
[2009/02/18 15:25:58 | 00,039,936 | —- | C] (MainConcept AG) – C:\ouqhk.exe
[2009/02/18 15:25:41 | 00,000,000 | —D | C] – C:\WINDOWS\System32\tov15
[2009/02/18 15:25:41 | 00,000,000 | —D | C] – C:\Temp
[2009/02/18 14:56:36 | 00,032,712 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\livehelp.jpg
[2009/02/18 14:29:24 | 00,095,256 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\part240.zip
[2009/02/18 12:37:10 | 01,378,482 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\Advertising Layout Mautofied.pdf
[2009/02/18 10:54:45 | 00,000,000 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\panel.justin.xls
[2009/02/17 16:57:00 | 00,007,959 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_product.htm
[2009/02/17 16:57:00 | 00,006,612 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_saleproduct.htm
[2009/02/17 15:19:34 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\Desktop\Steam Showers, Steam Rooms, Whirlpool Bathtubs for your Steam Shower Enclosure_files
[2009/02/17 15:19:33 | 00,055,163 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\Steam Showers, Steam Rooms, Whirlpool Bathtubs for your Steam Shower Enclosure.htm
[2009/02/17 12:51:33 | 00,361,597 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\VolusionThumbnailGeneratorSetup.zip
[2009/02/17 12:47:36 | 00,000,000 | —D | C] – C:\Program Files\Volusion Inc
[2009/02/13 16:02:08 | 24,165,313 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\mfd_uc.psd
[2009/02/13 16:00:18 | 00,267,228 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\mfd_uc.jpg
[2009/02/13 15:24:15 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\Application Data\FileZilla
[2009/02/13 15:23:49 | 00,000,000 | —D | C] – C:\Program Files\FileZilla FTP Client
[2009/02/13 15:22:08 | 01,362,713 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\SubsitesFinal.jpg
[2009/02/13 14:57:11 | 00,047,001 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\Products_WTMYTNW4SR.csv
[2009/02/13 13:20:46 | 01,094,447 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\Untitled-8.psd
[2009/02/13 13:20:20 | 02,124,412 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\Untitled-9.psd
[2009/02/13 13:19:56 | 03,912,675 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\Untitled-7.psd
[2009/02/13 12:28:57 | 01,289,291 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\Is Goin In Your Moms Lockness Beaver.psd
[2009/02/13 12:28:46 | 01,277,061 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\This Foot.psd
[2009/02/12 15:08:53 | 04,559,648 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\splashlogos.psd
[2009/02/12 11:34:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\Boldchat
[2009/02/12 11:34:16 | 00,000,000 | —D | C] – C:\Program Files\Boldchat
[2009/02/12 10:36:01 | 00,000,000 | —D | C] – C:\Program Files\Foxit Software
[2009/02/11 17:29:00 | 00,007,933 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_default.htm
[2009/02/11 15:24:00 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\WMTools Downloaded Files
[2009/02/11 15:10:01 | 40,288,200 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\B505 MANUFACTURES MANUAL.pdf
[2009/02/10 14:20:00 | 00,002,435 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_saleproductformat.htm
[2009/02/05 16:19:59 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\My Documents\Adobe
[2009/02/05 15:36:00 | 00,002,215 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_saleformat.htm
[2009/02/02 09:55:47 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/02/02 09:51:52 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/30 14:58:42 | 00,518,064 | —- | C] (Codejock Software) – C:\WINDOWS\System32\Codejock.SkinFramework.Unicode.v11.2.0.ocx
[2009/01/30 14:58:41 | 01,746,864 | —- | C] (Codejock Software) – C:\WINDOWS\System32\Codejock.CommandBars.Unicode.v11.2.0.ocx
[2009/01/27 14:27:52 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\My Documents\BGroomSaved Files
[2009/01/22 11:51:00 | 00,000,000 | —D | C] – C:\Program Files\YourWare Solutions

========== Files - Modified Within 30 Days ==========

[10 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/02/19 12:33:51 | 00,494,592 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Justin Ward\Desktop\OTListIt2.exe
[2009/02/19 12:26:50 | 00,001,347 | —- | M] () – C:\WINDOWS\System32\ahtn.htm
[2009/02/19 12:26:49 | 00,004,785 | —- | M] () – C:\WINDOWS\System32\warning.gif
[2009/02/19 12:14:02 | 00,001,740 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\HijackThis.lnk
[2009/02/19 12:12:49 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Justin Ward\Desktop\HJTInstall.exe
[2009/02/19 12:12:04 | 00,000,266 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2009/02/19 12:02:27 | 00,000,200 | -H– | M] () – C:\aaw7boot.cmd
[2009/02/19 12:00:00 | 00,000,328 | —- | M] () – C:\WINDOWS\tasks\hrtgmihd.job
[2009/02/19 11:56:34 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/02/19 11:56:33 | 00,002,299 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UltraMon.lnk
[2009/02/19 11:55:41 | 00,104,960 | —- | M] () – C:\WINDOWS\System32\ntdll64.exe
[2009/02/19 11:54:01 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/19 11:53:28 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/19 11:53:25 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/19 11:51:19 | 07,440,016 | -H– | M] () – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\IconCache.db
[2009/02/19 11:43:06 | 00,000,439 | —- | M] () – C:\WINDOWS\System32\win32hlp.cnf
[2009/02/19 11:43:01 | 00,104,960 | —- | M] () – C:\WINDOWS\System32\userinit.exe
[2009/02/19 11:43:01 | 00,104,960 | —- | M] () – C:\WINDOWS\System32\dllcache\userinit.exe
[2009/02/19 11:42:47 | 00,442,576 | —- | M] () – C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT
[2009/02/19 11:41:10 | 03,075,408 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/19 11:23:19 | 03,153,920 | —- | M] () – C:\WINDOWS\System32\secsetup.sdb
[2009/02/19 11:22:42 | 00,108,032 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\ResetSecuritySettingsBackToTheDefaults(2).msi
[2009/02/19 11:08:49 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/02/19 11:08:37 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/02/19 11:08:24 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/02/19 11:06:56 | 00,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/02/19 11:05:38 | 00,566,912 | —- | M] () – C:\WINDOWS\System32\Status.MPF
[2009/02/19 10:47:06 | 00,000,950 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2252052014-1732420521-1256393475-1005.job
[2009/02/19 10:47:00 | 14,813,076 | —- | M] (AVG Technologies) – C:\Documents and Settings\Justin Ward\Desktop\avg_avwt_stf_en_8_237a1428.exe.part
[2009/02/19 10:46:30 | 34,543,112 | —- | M] (Lavasoft ) – C:\Documents and Settings\Justin Ward\Desktop\Ad-AwareAE.exe
[2009/02/19 10:40:46 | 00,000,000 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\avg_avwt_stf_en_8_237a1428.exe
[2009/02/19 10:40:17 | 00,383,836 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\smitRem.exe
[2009/02/19 10:29:30 | 00,108,032 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\ResetSecuritySettingsBackToTheDefaults.msi
[2009/02/19 06:12:14 | 00,000,434 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{7043F3C0-C09E-4408-B96A-28E1B96FE699}.job
[2009/02/18 17:20:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/02/18 16:12:40 | 00,134,144 | —- | M] (Mozilla Foundation) – C:\WINDOWS\ucitevih.dll
[2009/02/18 16:11:05 | 00,000,671 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PC Tools AntiVirus.lnk
[2009/02/18 16:10:22 | 29,688,176 | —- | M] (PC Tools ) – C:\Documents and Settings\Justin Ward\Desktop\avinstall.exe
[2009/02/18 15:26:49 | 00,000,000 | —- | M] () – C:\pbjrtsau.exe
[2009/02/18 15:26:49 | 00,000,000 | —- | M] () – C:\mlafhs.exe
[2009/02/18 15:26:48 | 00,000,000 | —- | M] () – C:\qmbkgm.exe
[2009/02/18 15:26:48 | 00,000,000 | —- | M] () – C:\epri.exe
[2009/02/18 15:26:33 | 00,000,001 | —- | M] () – C:\WINDOWS\System32\uniq.tll
[2009/02/18 15:26:13 | 00,008,704 | —- | M] () – C:\emvwk.exe
[2009/02/18 15:26:13 | 00,000,000 | —- | M] () – C:\-1463359964
[2009/02/18 15:26:10 | 00,026,624 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\frmwrk32.exe
[2009/02/18 15:26:10 | 00,026,624 | —- | M] (Microsoft Corporation) – C:\kjqgqk.exe
[2009/02/18 15:26:08 | 00,064,000 | —- | M] () – C:\joehug.exe
[2009/02/18 15:26:03 | 00,015,000 | —- | M] () – C:\WINDOWS\System32\hs78344kjkfd.dll
[2009/02/18 15:26:00 | 00,039,936 | —- | M] (MainConcept AG) – C:\ouqhk.exe
[2009/02/18 15:26:00 | 00,039,936 | —- | M] () – C:\WINDOWS\Tyadabadeb.dll
[2009/02/18 14:56:38 | 00,032,712 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\livehelp.jpg
[2009/02/18 14:29:25 | 00,095,256 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\part240.zip
[2009/02/18 11:36:48 | 00,001,930 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_productformat.htm
[2009/02/18 11:36:42 | 00,002,215 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_saleformat.htm
[2009/02/18 11:36:33 | 00,002,435 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_saleproductformat.htm
[2009/02/18 11:36:26 | 00,006,612 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_saleproduct.htm
[2009/02/18 11:20:41 | 00,007,959 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_product.htm
[2009/02/18 11:20:26 | 00,001,021 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_categorytemplate2.htm
[2009/02/18 10:58:00 | 00,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/02/18 10:55:03 | 00,000,000 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\panel.justin.xls
[2009/02/18 09:59:38 | 00,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/02/17 16:38:54 | 00,007,933 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_default.htm
[2009/02/17 15:19:36 | 00,055,163 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\Steam Showers, Steam Rooms, Whirlpool Bathtubs for your Steam Shower Enclosure.htm
[2009/02/17 13:24:55 | 00,047,001 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\Products_WTMYTNW4SR.csv
[2009/02/17 12:51:34 | 00,361,597 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\VolusionThumbnailGeneratorSetup.zip
[2009/02/13 22:20:57 | 00,000,362 | —- | M] () – C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (DELLBOX-Justin Ward).job
[2009/02/13 16:27:00 | 40,288,200 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\B505 MANUFACTURES MANUAL.pdf
[2009/02/13 16:02:11 | 24,165,313 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\mfd_uc.psd
[2009/02/13 16:00:18 | 00,267,228 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\mfd_uc.jpg
[2009/02/13 15:22:10 | 01,362,713 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\SubsitesFinal.jpg
[2009/02/13 14:01:06 | 04,920,320 | -HS- | M] () – C:\Documents and Settings\Justin Ward\Desktop\Thumbs.db
[2009/02/13 13:54:40 | 01,277,061 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\This Foot.psd
[2009/02/13 13:20:46 | 01,094,447 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\Untitled-8.psd
[2009/02/13 13:20:23 | 02,124,412 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\Untitled-9.psd
[2009/02/13 13:20:05 | 03,912,675 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\Untitled-7.psd
[2009/02/13 12:35:09 | 01,289,291 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\Is Goin In Your Moms Lockness Beaver.psd
[2009/02/12 15:08:54 | 04,559,648 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\splashlogos.psd
[2009/02/12 10:53:01 | 00,019,456 | —- | M] () – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/06 13:35:16 | 00,001,908 | -H– | M] () – C:\Documents and Settings\Justin Ward\My Documents\Default.rdp
[2009/02/03 15:21:12 | 21,244,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/02/02 10:01:37 | 00,000,082 | -HS- | M] () – C:\Documents and Settings\Justin Ward\My Documents\desktop.ini
[2009/02/02 09:58:41 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/01/29 11:04:26 | 00,001,824 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk

========== LOP Check ==========

[2009/02/19 11:06:57 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/11/24 14:22:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/02/19 11:06:58 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2008/11/13 14:59:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/12/15 10:52:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/12/15 11:09:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2008/09/22 14:33:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ALM
[2006/06/28 18:56:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2000/02/08 16:10:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2006/12/15 10:22:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2007/07/16 08:10:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/09/13 18:20:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/07/15 11:52:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Auslogics
[2008/12/12 11:24:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avanquest
[2007/03/06 14:56:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Corel
[2008/12/15 10:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FLEXnet
[2006/03/21 05:36:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2007/01/04 15:21:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2006/03/21 05:39:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2007/03/02 10:45:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2008/07/15 11:23:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2009/02/19 11:08:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2006/03/31 23:25:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Macromedia
[2009/02/19 11:07:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/09/16 22:16:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
[2008/04/21 16:43:43 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/02/19 11:09:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
[2006/03/28 22:16:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Games
[2009/01/14 11:18:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2008/04/30 16:19:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2008/10/01 15:11:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2007/08/15 11:37:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/02/19 10:50:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2007/05/01 09:45:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Protexis
[2006/03/31 17:42:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2008/07/07 09:33:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Radar Website Monitor
[2008/05/12 13:23:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Realtime Soft
[2007/11/20 11:06:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2006/03/21 05:31:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonic
[2008/06/11 14:18:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SPI Dynamics
[2006/12/15 10:52:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2006/12/15 10:52:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2007/10/19 11:14:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/02/19 11:01:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/10/16 09:15:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vale Software
[2008/11/13 14:59:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/03/28 21:52:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/09/18 09:49:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\XemiComputers
[2007/01/16 09:50:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2009/02/18 16:12:30 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Justin Ward\Application Data
[2008/09/09 14:08:15 | 00,000,000 | -HSD | M] – C:\Documents and Settings\Justin Ward\Application Data\.#
[2007/05/01 08:14:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\acccore
[2009/02/12 14:15:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Adobe
[2008/01/31 15:10:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\AdobeUM
[2008/03/26 13:25:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Apple Computer
[2007/01/04 16:21:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Arcsoft
[2008/12/12 11:15:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Avanquest
[2008/08/12 12:10:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Canon
[2008/09/24 14:04:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\cmw
[2007/03/06 14:59:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Corel
[2006/04/30 18:05:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Corel Photo Album
[2008/12/01 15:32:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Delicious IE Extension
[2008/10/24 11:59:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\DivX
[2007/10/19 11:04:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Download Manager
[2009/02/17 15:57:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\FileZilla
[2006/11/18 16:59:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\GlobalSCAPE
[2006/03/21 05:42:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Google
[2007/04/12 11:05:12 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Justin Ward\Application Data\Gtek
[2007/02/19 13:02:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Help
[2007/01/04 15:20:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\HotSync
[2009/02/18 12:57:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\IBP
[2005/08/16 02:50:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Identities
[2007/08/15 12:42:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\InstallShield
[2007/03/02 10:46:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Intuit
[2008/07/15 11:25:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\iolo
[2009/02/19 11:57:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\iPhoneRingToneMaker
[2006/04/06 18:25:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Leadertech
[2007/04/30 10:08:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\LimeWire
[2006/12/10 23:00:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Macromedia
[2009/01/05 14:24:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Mc & RENOX
[2007/04/02 15:16:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\McAfee.com Personal Firewall
[2008/08/18 08:39:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Microgaming
[2008/10/01 15:35:33 | 00,000,000 | –SD | M] – C:\Documents and Settings\Justin Ward\Application Data\Microsoft
[2006/03/28 22:16:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Microsoft Games
[2009/01/13 12:03:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Move Networks
[2009/01/29 10:02:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Mozilla
[2007/09/07 14:06:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Netscape
[2008/10/01 15:13:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Nitro PDF
[2007/01/26 10:40:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Opera
[2009/02/18 16:12:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\PC Tools
[2007/01/10 15:51:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Peachtree
[2008/02/08 16:44:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\QQ Games Plugin
[2007/02/04 16:12:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Real
[2008/01/11 10:22:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Realtime Soft
[2007/03/22 16:24:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Roxio
[2006/12/15 10:52:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\ScanSoft
[2008/09/04 09:59:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\SmartFTP
[2007/08/15 12:44:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Software602
[2006/12/15 10:47:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Sonic
[2008/08/05 08:36:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\StumbleUpon
[2006/03/21 05:25:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Sun
[2007/02/28 16:05:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Symantec
[2007/08/16 14:43:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Thinstall
[2009/01/05 14:18:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\TickerCast
[2009/02/18 15:29:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\uTorrent
[2007/04/12 09:40:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\UVU
[2007/02/01 09:06:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Vale Software
[2008/07/15 11:24:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\VersionTracker Pro
[2007/01/11 11:13:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Viewpoint
[2008/02/25 13:45:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Winamp
[2008/04/02 16:38:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Windows Desktop Search
[2007/09/18 09:49:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\XemiComputers
[2007/01/16 09:50:30 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Justin Ward\Application Data\yahoo!
[2009/02/19 11:08:49 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/02/18 17:20:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/02/19 12:12:04 | 00,000,266 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
[2004/08/10 03:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/19 10:47:06 | 00,000,950 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2252052014-1732420521-1256393475-1005.job
[2009/02/19 12:00:00 | 00,000,328 | —- | M] () – C:\WINDOWS\Tasks\hrtgmihd.job
[2009/02/13 22:20:57 | 00,000,362 | —- | M] () – C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (DELLBOX-Justin Ward).job
[2009/02/19 11:56:34 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/02/19 11:53:28 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/02/19 06:12:14 | 00,000,434 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{7043F3C0-C09E-4408-B96A-28E1B96FE699}.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:933B2316
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:54272E15
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A8E2C33
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\System32\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Justin Ward\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Justin Ward\Desktop\Thumbs.db:encryptable
< End of report >
hello

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
    PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
    PRC - C:\Documents and Settings\Justin Ward\Local Settings\Temp\winlognn.exe ()
    PRC - C:\WINDOWS\system32\ntdll64.exe ()
    PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
    PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
    PRC - C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe (Lavasoft)
    PRC - C:\WINDOWS\system32\ntdll64.exe ()
    O2 - BHO: (C:\WINDOWS\system32\hs78344kjkfd.dll) - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\hs78344kjkfd.dll ()
    O4 - HKLM..\Run: [Hkovorukemo] rundll32.exe "C:\WINDOWS\ucitevih.dll",e (Mozilla Foundation)
    O4 - HKLM..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\winlognn.exe ()
    O4 - HKLM..\Run: [msci] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\200921911734_mcinfo.exe /insfin File not found
    O4 - HKLM..\Run: [Vcomohaqiteji] rundll32.exe "C:\WINDOWS\Tyadabadeb.dll",e ()
    O4 - HKCU..\Run: [a191x79n6j19j27woypg8akyfre] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f4ch1c5vqa8c.exe File not found
    O4 - HKCU..\Run: [a1hq5xdcwe6m5h3gp8ebavquguc6pb1fkg2mdmj3] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\tyrury3hgr.exe File not found
    O4 - HKCU..\Run: [a91ywwtuwf6cfz18v5y8qyaqi8rmj482sif6] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\uihp9jr1z.exe File not found
    O4 - HKCU..\Run: [a9iap34n2y8] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\t4d23ml19qp.exe File not found
    O4 - HKCU..\Run: [adp9e72vwkav81jegtpzww2fuzrsgu39em9rm] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\yamddtdads.exe File not found
    O4 - HKCU..\Run: [af1g1vbdtnxqieq4ys5f2bx8v113kn394uh6wuf3oaanzs9v] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hodph1uro8bfi.exe File not found
    O4 - HKCU..\Run: [ahg6gk9ojwxgvi7hhdy1dgvcgyi15ylw0gwp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\zs61x3l.exe File not found
    O4 - HKCU..\Run: [alpc4dhchszxzm7smzc17s65elksgh] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\nrjcyjw2.exe File not found
    O4 - HKCU..\Run: [awabe62wi5dh5x] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\rhv1uofts.exe File not found
    O4 - HKCU..\Run: [azqq4ymzxe6p2oesy2mkhnelkln1h6m372] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xpi3zhl54hy.exe File not found
    O4 - HKCU..\Run: [bg3r4q04nkwmp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\cynb9ym.exe File not found
    O4 - HKCU..\Run: [bi6cco8o3ad3xa] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ox5ezshvn.exe File not found
    O4 - HKCU..\Run: [bnnqdds8f4h1] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\qndogi64u.exe File not found
    O4 - HKCU..\Run: [bqhsnkw2najvltz1r43i8xoivpy8ic0ozre9561mva88ak04] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\vlst73.exe File not found
    O4 - HKCU..\Run: [c2c58klinb0l7wqz7oaalhise0apjqw9h4hklhdqh7ni] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\oxm0bvolai06.exe File not found
    O4 - HKCU..\Run: [c5aje7761df246gnxtibusumghp4nmsvo6n6zo] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\e40ouqdkjjwxp.exe File not found
    O4 - HKCU..\Run: [cfn0xtg48sp49ohrh3ehm6tj5j4xjv2fx16ldrkf3qcs8] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\nkrb9x3448.exe File not found
    O4 - HKCU..\Run: [d2l9flclm2n6ovkgkdyp95fz88zjgelw39kloycq97nbc] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\enk5je.exe File not found
    O4 - HKCU..\Run: [d49s4ltc2da7l8rrh7gwfu1820] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\gcaznnyvax8m.exe File not found
    O4 - HKCU..\Run: [d5miwxgyxrg2ecmr61oqe09ahwlsbzs1icqkymde3uavkgc] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\o109iydb0q.exe File not found
    O4 - HKCU..\Run: [dfvemqqi7uy] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\q100rnvl.exe File not found
    O4 - HKCU..\Run: [e4d9xq0gxozh5yqy8inoektvucc3g] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\kjjd797d8j775.exe File not found
    O4 - HKCU..\Run: [eqkc1y97ju8aivsxkvolxref] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f99gn5s.exe File not found
    O4 - HKCU..\Run: [ewlc74dtb] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ok1pbh6.exe File not found
    O4 - HKCU..\Run: [f97jpjtuzj0kgky06] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\vounq538ppzj.exe File not found
    O4 - HKCU..\Run: [fhdvrisxij1ov28p6ok6kom1cv4m1] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\t4mqusyucwq.exe File not found
    O4 - HKCU..\Run: [fnwd0e3x6xp0otnyuzf74xm278] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\okstgo1.exe File not found
    O4 - HKCU..\Run: [fv3jqdbxgzn9omrxktokgyuj46n79h55fv1w] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\dbar89ziio.exe File not found
    O4 - HKCU..\Run: [fwgg2fr3ib6lxm2ifg8yjaz6v5jk580949h] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\blemtilr1x25.exe File not found
    O4 - HKCU..\Run: [gnrtxl3j0l1lmvt9cnvav5tc] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\i1gzynal.exe File not found
    O4 - HKCU..\Run: [gpm9hup22jndklp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xs3khwse5gua.exe File not found
    O4 - HKCU..\Run: [h2jqoxb6d2nmzqwuz3cvp4] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\itz3z19.exe File not found
    O4 - HKCU..\Run: [hr2d2769x2u2n8lgv3y4kjlgs7xjr2yau3a43r01fptx] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\njlngqv9593ee.exe File not found
    O4 - HKCU..\Run: [hrhrhxh5w8b42d0i36su] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\pws1mzymt8.exe File not found
    O4 - HKCU..\Run: [hs8oy8fprxahhpcer] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xcvkb8v3v7h.exe File not found
    O4 - HKCU..\Run: [huhmu0w3jd5k] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\y1ozymnawl3r.exe File not found
    O4 - HKCU..\Run: [i9jhe68max] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\px88ru8e5emz.exe File not found
    O4 - HKCU..\Run: [ic7xn1yvr44mw4o] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\qpddnh7.exe File not found
    O4 - HKCU..\Run: [ig1ps46pbghr84ybbt2nkni1onp9h4prn89vm8xro646oyh] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\kdqh9z.exe File not found
    O4 - HKCU..\Run: [ino7oolzf64ub8chxc3c2edf69fsonm3bo6x28z3wkyacmfim] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\alrbnlflrfsk.exe File not found
    O4 - HKCU..\Run: [iuto7v28tfh4tw8omr1] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\i3q78glw3oy.exe File not found
    O4 - HKCU..\Run: [ixlg10f6tz27xs22p1kfgpielzzwdxyw9lpi] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hlr8ot9.exe File not found
    O4 - HKCU..\Run: [j4i5nlypax50nvlmh0c97kbhmz5k91legryexcamk] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\nms9t5n.exe File not found
    O4 - HKCU..\Run: [jag7wjp5id0mv9r69t] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\mmmy70j4eoid.exe File not found
    O4 - HKCU..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\winlognn.exe ()
    O4 - HKCU..\Run: [jvu2euku5favq55oz5y0h0mo6z6623h98ijyzpd0o8cyp9] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\la6m516yjqc.exe File not found
    O4 - HKCU..\Run: [jwo8cxrtvkkucqdq5d4f9sfqeudy] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\zkrtqoe.exe File not found
    O4 - HKCU..\Run: [jz2wqwc2jh2v7n87stsmgtmiw1p2blqxr] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xo8110q8ch3y.exe File not found
    O4 - HKCU..\Run: [k0kmjvval49fl0p9eji3mx2fsxcvts] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hx74x7fiqen.exe File not found
    O4 - HKCU..\Run: [k7y0o1b4sd0pkhr1cj7kd44rrhirdvg63gyx] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\dcx0uygdlhq.exe File not found
    O4 - HKCU..\Run: [k9d3beq9yuohug4qmcn9fboyottb5o] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\agdawn6si.exe File not found
    O4 - HKCU..\Run: [krib7o62a09isefvebmqkn1mtyhgezw5] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\rj3hqoljz.exe File not found
    O4 - HKCU..\Run: [ktb0t1dldnuk0z8s52f082mws8i0yx8xob6t7gu] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\s6e6b63hesw.exe File not found
    O4 - HKCU..\Run: [ktud582s0aqruo26vhi0qsbukyrfxt28ck8u5s] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\y0kyj38mz.exe ()
    O4 - HKCU..\Run: [l8dtlntzivepyu9u] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\jqhbuob240e.exe File not found
    O4 - HKCU..\Run: [laikfcprvs1vz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\r7w3bn9p.exe File not found
    O4 - HKCU..\Run: [lea5z886l7qk6h0tpcj8r6y9dml23195v] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\uo2c7mr9ts9.exe File not found
    O4 - HKCU..\Run: [lirkja3p68n4nyf0qllswr4yi4qcu4wrwc6cyowcr2igovchz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\y5lyq2m5njn5.exe File not found
    O4 - HKCU..\Run: [lqe58li4fa73jsoehltre1ntgvkp394lwzdwqt5xkz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\gg8qamx.exe File not found
    O4 - HKCU..\Run: [oakusxy7f0v98jmlv43eocpsthk7cyzyzv5e8] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\dw2l3tf3k4bcz.exe File not found
    O4 - HKCU..\Run: [ob5hyz8pdsuwmv1iiepnc2f64q3ru5x414ltnpgv] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\k01oek56iw.exe File not found
    O4 - HKCU..\Run: [ojgyghzsnb0l8wwpkhgyl0rnpb0ohp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\rdpp7fu4y.exe File not found
    O4 - HKCU..\Run: [omuzfata5ddwer2eajbp3msf9n6gpwzrmafssgn0455] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\k9k5mq.exe File not found
    O4 - HKCU..\Run: [ongyaka9nocq2yn3j262u7sfk] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f50vs4d.exe File not found
    O4 - HKCU..\Run: [ow0owf3y44qq2otx1hzi5grkdrd7cm3w687k] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\cwx90b8u38wg.exe File not found
    O4 - HKCU..\Run: [pa4cw283qemmltec615w9] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\lvv683wy8c1lw.exe File not found
    O4 - HKCU..\Run: [pru7o969axu3ffk2] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\lv14smnscue8.exe File not found
    O4 - HKCU..\Run: [pz4yzjca7dvrz7w4qdnimka6tt0] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f954x9u3b93.exe File not found
    O4 - HKCU..\Run: [qkpe4bm37mdamlbh9w3vposohnmsgqcnmzx9f0xkwu] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ueohl3osop.exe File not found
    O4 - HKCU..\Run: [qvyktn7ly9x6xryayo5diadsgqj2kt8zigxalc7xcam4v] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\fe7mhlz.exe File not found
    O4 - HKCU..\Run: [rhrxvuv0c9lllacmj61cnxhvceshq] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\uzwu52sjjq.exe File not found
    O4 - HKCU..\Run: [rmnd6l94rxvba5qsomy2shbl98uq] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\miwltw3i0spc6.exe File not found
    O4 - HKCU..\Run: [rulm8siujym5hfhg8ofyjcnexh] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\cujf6c.exe File not found
    O4 - HKCU..\Run: [rwmqut43mk5jpgs8sq9u1ktqwxskf7snns1u] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\gohvjkq.exe File not found
    O4 - HKCU..\Run: [ryk2gtiwnenihzr8376gwcmyvz0oihe0hk5o2vzt97ix8lybc6] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\t38k3bis3p7al.exe File not found
    O4 - HKCU..\Run: [sfjjzm3pxvl5stwiklfz7kd] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\qnx1124x99v.exe File not found
    O4 - HKCU..\Run: [skob19httrc33w0ffcnja] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\f2ywbe32gqh.exe File not found
    O4 - HKCU..\Run: [szdw4xv7s3p9iqvcgeiy4r] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\i7lj8mhcgumf.exe File not found
    O4 - HKCU..\Run: [t5k8fcekpw13] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\powlndyn6j5a.exe File not found
    O4 - HKCU..\Run: [tcmcqp3pbi1g2k80ey9s20hhl7cqyjobm7vjycc8] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\oizv35he3bp.exe File not found
    O4 - HKCU..\Run: [tvfsj3fg4wzmeb6zl4obykfkrycpdvsbmvv1lloo6dt7fymw1u] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ngj4fggl9.exe File not found
    O4 - HKCU..\Run: [tvh8t8p5tfah] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ra565o2lm.exe File not found
    O4 - HKCU..\Run: [uqfes7bu2dt5pme4s] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ndo0boji7vc.exe File not found
    O4 - HKCU..\Run: [uqfy1tlq9h6ili6fc3t4kax4a9x8z08so85hddyxz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\vv2v50k5piz5.exe File not found
    O4 - HKCU..\Run: [urt8z7oqkc2qvrnovw75otxx9nf] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\m6ppxzuudt.exe File not found
    O4 - HKCU..\Run: [uw6ejwixxs4ek38sedtcrc39cleube3c0zm] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\esq9op661fqei.exe File not found
    O4 - HKCU..\Run: [uwoxucafhylikcqglmkqs0i16bkyvbe53gb0cqwhfc] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\not7go23jv.exe File not found
    O4 - HKCU..\Run: [v3577xcujgetocj7se7q1l39g1kc495119oe] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\mhhy2mho.exe File not found
    O4 - HKCU..\Run: [v7v4sl9jvtvs0hgo] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\qxntld0z7.exe File not found
    O4 - HKCU..\Run: [venv3pi7q5z5c8v13soxi] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\v73rascdle.exe File not found
    O4 - HKCU..\Run: [vxqb37qz39p3e2yxhb456e8dbtv08ctjpjgugpx7vn] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\wj2pr25g.exe File not found
    O4 - HKCU..\Run: [vzisn8y2cidi3l88as8vm] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\orvkc5x.exe File not found
    O4 - HKCU..\Run: [w4f3t4cvqw1otq1r98dp3zh62ayxt4kw54t3ez3] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\z183or27k2.exe File not found
    O4 - HKCU..\Run: [w5qsj9cf2o4j] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\kn25c79pey5x.exe File not found
    O4 - HKCU..\Run: [w65gyv42br6qjwgg0f7l6tvngg455ykujkts] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\x27clfpil.exe File not found
    O4 - HKCU..\Run: [wbgt0286sn] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xfvryaeq.exe File not found
    O4 - HKCU..\Run: [wntdutq77eb2c6rkigfmbyfj3rcvdue3k3uhf9k8fx66us] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xdi7h0h.exe File not found
    O4 - HKCU..\Run: [x20jt7q69l3966yqq17t3bidyy0lims8z6vu4kqogugam7n35] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xhjxpckmt1pgm.exe File not found
    O4 - HKCU..\Run: [xrcv1k3z8frp22l9mg4bsn26nbqie] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ikqgjyhmo955w.exe File not found
    O4 - HKCU..\Run: [yglkyqg7f1rdwa] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\c1bqownrr28.exe File not found
    O4 - HKCU..\Run: [z0wwdsleti] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\s2cex7qlghel.exe File not found
    O4 - HKCU..\Run: [z22svugzj] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\n8m9tm.exe File not found
    O4 - HKCU..\Run: [zby8h7axpd34j32] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hhqde6bt.exe File not found
    O4 - HKCU..\Run: [zcggpb06yy4yrykoxha9hs3dwfv6rto51] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\u6tdgyij40fr.exe File not found
    O4 - HKCU..\Run: [zkrs056v9myzx2a6p8x0mvza4y3k77m] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\hxupqk.exe File not found
    O4 - HKCU..\Run: [zl19v132mdys] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xdppb5ib4lqy.exe File not found
    O4 - HKCU..\Run: [ztr8nm77q5xuv6nz81ycb6dt] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\fd117itww.exe File not found
    O20 - AppInit_DLLs: (acaptuser32.dll) - File not found
    O20 - Winlogon\Notify\tuVnMFvW: DllName - tuVnMFvW.dll - File not found
    O22 - SharedTaskScheduler: {C5BF49A2-94F3-42BD-F434-3604812C8955} - jgzfkj9w38rksndfi7r4 - C:\WINDOWS\system32\hs78344kjkfd.dll ()
    O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
    O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe – File not found
    [2009/02/19 11:55:37 | 00,104,960 | —- | C] () – C:\WINDOWS\System32\ntdll64.exe
    [2009/02/19 11:43:10 | 00,001,347 | —- | C] () – C:\WINDOWS\System32\ahtn.htm
    [2009/02/19 11:43:09 | 00,004,785 | —- | C] () – C:\WINDOWS\System32\warning.gif
    [2009/02/19 11:43:06 | 00,000,439 | —- | C] () – C:\WINDOWS\System32\win32hlp.cnf
    [2009/02/18 15:27:17 | 00,000,328 | —- | C] () – C:\WINDOWS\tasks\hrtgmihd.job
    [2009/02/18 15:26:49 | 00,000,000 | —- | C] () – C:\pbjrtsau.exe
    [2009/02/18 15:26:49 | 00,000,000 | —- | C] () – C:\mlafhs.exe
    [2009/02/18 15:26:48 | 00,000,000 | —- | C] () – C:\qmbkgm.exe
    [2009/02/18 15:26:48 | 00,000,000 | —- | C] () – C:\epri.exe
    [2009/02/18 15:26:33 | 00,000,001 | —- | C] () – C:\WINDOWS\System32\uniq.tll
    [2009/02/18 15:26:13 | 00,000,000 | —- | C] () – C:\-1463359964
    [2009/02/18 15:26:12 | 00,008,704 | —- | C] () – C:\emvwk.exe
    [2009/02/18 15:26:11 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\frmwrk32.exe
    [2009/02/18 15:26:08 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\kjqgqk.exe
    [2009/02/18 15:26:04 | 00,064,000 | —- | C] () – C:\joehug.exe
    [2009/02/18 15:26:03 | 00,015,000 | —- | C] () – C:\WINDOWS\System32\hs78344kjkfd.dll
    [2009/02/18 15:26:00 | 00,039,936 | —- | C] () – C:\WINDOWS\Tyadabadeb.dll
    [2009/02/18 15:25:58 | 00,039,936 | —- | C] (MainConcept AG) – C:\ouqhk.exe
    [2009/02/18 15:25:41 | 00,000,000 | —D | C] – C:\WINDOWS\System32\tov15
    [2008/09/09 14:08:15 | 00,000,000 | -HSD | M] – C:\Documents and Settings\Justin Ward\Application Data\.#
    [2009/02/19 12:00:00 | 00,000,328 | —- | M] () – C:\WINDOWS\Tasks\hrtgmihd.job
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
========== OTLISTIT ========== Process explorer.exe killed successfully! No active process named MsMpEng.exe was found! Process MSASCui.exe killed successfully! Process winlognn.exe killed successfully! Process ntdll64.exe killed successfully! No active process named AAWService.exe was found! No active process named AAWTray.exe was found! No active process named Ad-Aware.exe was found! No active process named ntdll64.exe was found! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C5BF49A2-94F3-42BD-F434-3604812C8955}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BF49A2-94F3-42BD-F434-3604812C8955}\ deleted successfully. C:\WINDOWS\system32\hs78344kjkfd.dll NOT unregistered. C:\WINDOWS\system32\hs78344kjkfd.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Hkovorukemo deleted successfully. C:\WINDOWS\ucitevih.DLL NOT unregistered. C:\WINDOWS\ucitevih.DLL moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\jsf8uiw3jnjgffght deleted successfully. C:\Documents and Settings\Justin Ward\Local Settings\Temp\winlognn.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\msci deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Vcomohaqiteji deleted successfully. DllUnregisterServer procedure not found in C:\WINDOWS\Tyadabadeb.DLL C:\WINDOWS\Tyadabadeb.DLL NOT unregistered. C:\WINDOWS\Tyadabadeb.DLL moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\a191x79n6j19j27woypg8akyfre deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\a1hq5xdcwe6m5h3gp8ebavquguc6pb1fkg2mdmj3 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\a91ywwtuwf6cfz18v5y8qyaqi8rmj482sif6 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\a9iap34n2y8 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\adp9e72vwkav81jegtpzww2fuzrsgu39em9rm deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\af1g1vbdtnxqieq4ys5f2bx8v113kn394uh6wuf3oaanzs9v deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ahg6gk9ojwxgvi7hhdy1dgvcgyi15ylw0gwp deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\alpc4dhchszxzm7smzc17s65elksgh deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\awabe62wi5dh5x deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\azqq4ymzxe6p2oesy2mkhnelkln1h6m372 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\bg3r4q04nkwmp deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\bi6cco8o3ad3xa deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\bnnqdds8f4h1 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\bqhsnkw2najvltz1r43i8xoivpy8ic0ozre9561mva88ak04 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\c2c58klinb0l7wqz7oaalhise0apjqw9h4hklhdqh7ni deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\c5aje7761df246gnxtibusumghp4nmsvo6n6zo deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\cfn0xtg48sp49ohrh3ehm6tj5j4xjv2fx16ldrkf3qcs8 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\d2l9flclm2n6ovkgkdyp95fz88zjgelw39kloycq97nbc deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\d49s4ltc2da7l8rrh7gwfu1820 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\d5miwxgyxrg2ecmr61oqe09ahwlsbzs1icqkymde3uavkgc deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\dfvemqqi7uy deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\e4d9xq0gxozh5yqy8inoektvucc3g deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\eqkc1y97ju8aivsxkvolxref deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ewlc74dtb deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\f97jpjtuzj0kgky06 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\fhdvrisxij1ov28p6ok6kom1cv4m1 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\fnwd0e3x6xp0otnyuzf74xm278 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\fv3jqdbxgzn9omrxktokgyuj46n79h55fv1w deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\fwgg2fr3ib6lxm2ifg8yjaz6v5jk580949h deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\gnrtxl3j0l1lmvt9cnvav5tc deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\gpm9hup22jndklp deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\h2jqoxb6d2nmzqwuz3cvp4 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\hr2d2769x2u2n8lgv3y4kjlgs7xjr2yau3a43r01fptx deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\hrhrhxh5w8b42d0i36su deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\hs8oy8fprxahhpcer deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\huhmu0w3jd5k deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\i9jhe68max deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ic7xn1yvr44mw4o deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ig1ps46pbghr84ybbt2nkni1onp9h4prn89vm8xro646oyh deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ino7oolzf64ub8chxc3c2edf69fsonm3bo6x28z3wkyacmfim deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\iuto7v28tfh4tw8omr1 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ixlg10f6tz27xs22p1kfgpielzzwdxyw9lpi deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\j4i5nlypax50nvlmh0c97kbhmz5k91legryexcamk deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\jag7wjp5id0mv9r69t deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\jsf8uiw3jnjgffght deleted successfully. File C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\winlognn.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\jvu2euku5favq55oz5y0h0mo6z6623h98ijyzpd0o8cyp9 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\jwo8cxrtvkkucqdq5d4f9sfqeudy deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\jz2wqwc2jh2v7n87stsmgtmiw1p2blqxr deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\k0kmjvval49fl0p9eji3mx2fsxcvts deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\k7y0o1b4sd0pkhr1cj7kd44rrhirdvg63gyx deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\k9d3beq9yuohug4qmcn9fboyottb5o deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\krib7o62a09isefvebmqkn1mtyhgezw5 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ktb0t1dldnuk0z8s52f082mws8i0yx8xob6t7gu deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ktud582s0aqruo26vhi0qsbukyrfxt28ck8u5s deleted successfully. File C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\y0kyj38mz.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\l8dtlntzivepyu9u deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\laikfcprvs1vz deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\lea5z886l7qk6h0tpcj8r6y9dml23195v deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\lirkja3p68n4nyf0qllswr4yi4qcu4wrwc6cyowcr2igovchz deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\lqe58li4fa73jsoehltre1ntgvkp394lwzdwqt5xkz deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\oakusxy7f0v98jmlv43eocpsthk7cyzyzv5e8 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ob5hyz8pdsuwmv1iiepnc2f64q3ru5x414ltnpgv deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ojgyghzsnb0l8wwpkhgyl0rnpb0ohp deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\omuzfata5ddwer2eajbp3msf9n6gpwzrmafssgn0455 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ongyaka9nocq2yn3j262u7sfk deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ow0owf3y44qq2otx1hzi5grkdrd7cm3w687k deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\pa4cw283qemmltec615w9 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\pru7o969axu3ffk2 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\pz4yzjca7dvrz7w4qdnimka6tt0 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\qkpe4bm37mdamlbh9w3vposohnmsgqcnmzx9f0xkwu deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\qvyktn7ly9x6xryayo5diadsgqj2kt8zigxalc7xcam4v deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\rhrxvuv0c9lllacmj61cnxhvceshq deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\rmnd6l94rxvba5qsomy2shbl98uq deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\rulm8siujym5hfhg8ofyjcnexh deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\rwmqut43mk5jpgs8sq9u1ktqwxskf7snns1u deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ryk2gtiwnenihzr8376gwcmyvz0oihe0hk5o2vzt97ix8lybc6 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\sfjjzm3pxvl5stwiklfz7kd deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\skob19httrc33w0ffcnja deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\szdw4xv7s3p9iqvcgeiy4r deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\t5k8fcekpw13 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\tcmcqp3pbi1g2k80ey9s20hhl7cqyjobm7vjycc8 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\tvfsj3fg4wzmeb6zl4obykfkrycpdvsbmvv1lloo6dt7fymw1u deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\tvh8t8p5tfah deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uqfes7bu2dt5pme4s deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uqfy1tlq9h6ili6fc3t4kax4a9x8z08so85hddyxz deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\urt8z7oqkc2qvrnovw75otxx9nf deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uw6ejwixxs4ek38sedtcrc39cleube3c0zm deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uwoxucafhylikcqglmkqs0i16bkyvbe53gb0cqwhfc deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\v3577xcujgetocj7se7q1l39g1kc495119oe deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\v7v4sl9jvtvs0hgo deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\venv3pi7q5z5c8v13soxi deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\vxqb37qz39p3e2yxhb456e8dbtv08ctjpjgugpx7vn deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\vzisn8y2cidi3l88as8vm deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\w4f3t4cvqw1otq1r98dp3zh62ayxt4kw54t3ez3 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\w5qsj9cf2o4j deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\w65gyv42br6qjwgg0f7l6tvngg455ykujkts deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\wbgt0286sn deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\wntdutq77eb2c6rkigfmbyfj3rcvdue3k3uhf9k8fx66us deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\x20jt7q69l3966yqq17t3bidyy0lims8z6vu4kqogugam7n35 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\xrcv1k3z8frp22l9mg4bsn26nbqie deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\yglkyqg7f1rdwa deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\z0wwdsleti deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\z22svugzj deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\zby8h7axpd34j32 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\zcggpb06yy4yrykoxha9hs3dwfv6rto51 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\zkrs056v9myzx2a6p8x0mvza4y3k77m deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\zl19v132mdys deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ztr8nm77q5xuv6nz81ycb6dt deleted successfully. Registry value \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:acaptuser32.dll deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuVnMFvW\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{C5BF49A2-94F3-42BD-F434-3604812C8955} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BF49A2-94F3-42BD-F434-3604812C8955}\ not found. File C:\WINDOWS\system32\hs78344kjkfd.dll not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found. File E:\setup.exe not found. C:\WINDOWS\System32\ntdll64.exe moved successfully. C:\WINDOWS\System32\ahtn.htm moved successfully. C:\WINDOWS\System32\warning.gif moved successfully. C:\WINDOWS\System32\win32hlp.cnf moved successfully. C:\WINDOWS\tasks\hrtgmihd.job moved successfully. C:\pbjrtsau.exe moved successfully. C:\mlafhs.exe moved successfully. C:\qmbkgm.exe moved successfully. C:\epri.exe moved successfully. C:\WINDOWS\System32\uniq.tll moved successfully. C:\-1463359964 moved successfully. C:\emvwk.exe moved successfully. C:\WINDOWS\System32\frmwrk32.exe moved successfully. C:\kjqgqk.exe moved successfully. C:\joehug.exe moved successfully. File C:\WINDOWS\System32\hs78344kjkfd.dll not found. File C:\WINDOWS\Tyadabadeb.dll not found. C:\ouqhk.exe moved successfully. Folder C:\WINDOWS\System32\tov15 not found. Folder C:\Documents and Settings\Justin Ward\Application Data\.# not found. File C:\WINDOWS\Tasks\hrtgmihd.job not found. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\Documents and Settings\Justin Ward\Local Settings\Temp\dmc1uy0w.exe scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Justin Ward\Local Settings\Temp\gy4z7ig1sic2w.exe scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Justin Ward\Local Settings\Temp\mousehook.dll scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_19c.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.0.18 log created on 02192009_152243 Files moved on Reboot… C:\Documents and Settings\Justin Ward\Local Settings\Temp\dmc1uy0w.exe moved successfully. C:\Documents and Settings\Justin Ward\Local Settings\Temp\gy4z7ig1sic2w.exe moved successfully. DllUnregisterServer procedure not found in C:\Documents and Settings\Justin Ward\Local Settings\Temp\mousehook.dll C:\Documents and Settings\Justin Ward\Local Settings\Temp\mousehook.dll NOT unregistered. C:\Documents and Settings\Justin Ward\Local Settings\Temp\mousehook.dll moved successfully. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_19c.dat not found! Registry entries deleted on Reboot…
OTListIt logfile created on: 2/19/2009 3:41:49 PM - Run 17
OTListIt2 by OldTimer - Version 2.0.0.18 Folder = C:\Documents and Settings\Justin Ward\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.80 Gb Total Space | 17.68 Gb Free Space | 25.32% Space Free | Partition Type: NTFS
Drive D: | 385.86 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 7.52 Gb Total Space | 0.97 Gb Free Space | 12.84% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
Drive G: | 510.35 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JDOUBLEYA
Current User Name: Justin Ward
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Applicure\dotDefender for IIS\bin\aclogsvc.exe ()
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE (C-Dilla Ltd)
PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\SplineTech JavaScript HTML Debugger\mdm.exe (Microsoft Corporation)
PRC - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe (PC Tools Research Pty Ltd)
PRC - C:\WINDOWS\system32\srvany.exe ()
PRC - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe ()
PRC - C:\pvsw\bin\w3dbsmgr.exe ()
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\AlienGUIse\wbload.exe (Stardock Systems, Inc)
PRC - C:\Program Files\HP\HP WebInspect\WIScheduler.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\UltraMon\UltraMon.exe (Realtime Soft Ltd)
PRC - C:\Program Files\UltraMon\UltraMonTaskbar.exe (Realtime Soft Ltd)
PRC - C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe (Stardock)
PRC - C:\Program Files\iPhoneRingToneMaker\iPhoneRingToneMaker.exe ()
PRC - C:\Program Files\AIM6\aim6.exe (AOL LLC)
PRC - C:\Program Files\AIM6\aolsoftware.exe (AOL LLC)
PRC - C:\Documents and Settings\Justin Ward\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (6to4 [Auto | Running]) – C:\WINDOWS\System32\6to4svc.dll (Microsoft Corporation)
SRV - (aclogsvc [Auto | Running]) – C:\Program Files\Applicure\dotDefender for IIS\bin\aclogsvc.exe ()
SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Adobe Version Cue CS3 [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)
SRV - (AmpSensor3.0-WebInspect [Auto | Stopped]) – C:\Program Files\HP\HP WebInspect\AmpSensorWI.exe (Hewlett-Packard Company)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (C-DillaSrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE (C-Dilla Ltd)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (ehRecvr [Auto | Running]) – C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) – C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IISADMIN [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Stopped]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (McrdSvc [Auto | Stopped]) – C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (MDM [Auto | Running]) – C:\Program Files\SplineTech JavaScript HTML Debugger\mdm.exe (Microsoft Corporation)
SRV - (MHN [On_Demand | Stopped]) – C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service [On_Demand | Stopped]) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (NetSvc [On_Demand | Stopped]) – C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PCTAVSvc [Auto | Running]) – C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe (PC Tools Research Pty Ltd)
SRV - (Pervasive.SQL Workgroup Engine [Auto | Running]) – C:\WINDOWS\system32\srvany.exe ()
SRV - (Pml Driver HPZ12 [On_Demand | Stopped]) – File not found
SRV - (ProtexisLicensing [Auto | Running]) – C:\Program Files\Common Files\Protexis\License Service\PSIService.exe ()
SRV - (SMTPSVC [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Running]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (W3SVC [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (WebInspect Scheduler Service [Auto | Running]) – C:\Program Files\HP\HP WebInspect\WIScheduler.exe (Hewlett-Packard Company)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (AN983 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\AN983.sys (ADMtek Incorporated.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ASCTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ATIAVPCI [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinavxx.sys (ATI Technologies Inc.)
DRV - (AVFilter [Auto | Running]) – C:\WINDOWS\system32\drivers\AVFilter.sys (PC Tools Research Pty Ltd)
DRV - (AVHook [On_Demand | Running]) – C:\WINDOWS\system32\drivers\AVHook.sys (PC Tools Research Pty Ltd.)
DRV - (AVRec [On_Demand | Running]) – C:\WINDOWS\system32\drivers\AVRec.sys (PC Tools Research Pty Ltd )
DRV - (C-Dilla [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\CDANT.SYS (Macrovision)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DLABOIOM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLACDBHM [System | Running]) – C:\WINDOWS\System32\Drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLADResN [Auto | Running]) – C:\WINDOWS\System32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLAIFS_M [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLAOPIOM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLARTL_N [System | Running]) – C:\WINDOWS\System32\Drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (DLAUDFAM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DRVMCDB [Boot | Running]) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DRVNDDM [Auto | Running]) – C:\WINDOWS\System32\Drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWBS2 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (MODEMCSA [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (MPE [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\MPE.sys (Microsoft Corporation)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RivaTuner32 [On_Demand | Stopped]) – C:\Program Files\RivaTuner v2.0 Final Release\RivaTuner32.sys ()
DRV - (SCDEmu [System | Running]) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sptd [Boot | Running]) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (StarPortLite [System | Running]) – C:\WINDOWS\system32\DRIVERS\StarPortLite.sys (Rocket Division Software)
DRV - (STHDA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (Tcpip6 [System | Running]) – C:\WINDOWS\system32\DRIVERS\tcpip6.sys (Microsoft Corporation)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (UltraMonMirror [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\UltraMonMirror.sys (Realtime Soft)
DRV - (UltraMonUtility [Auto | Running]) – C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys (Realtime Soft)
DRV - (USBAAPL [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (winachsf [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (XUIF [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Invalid data type.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Invalid data type.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com/ig/dell?hl=en&cl…&channel=us

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = Reg Error: Invalid data type.
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = Reg Error: Invalid data type.
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

O1 HOSTS File: (57 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 80.95.132.35 www.expekt.com 80.95.132.35 expekt.com
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (StumbleUpon Toolbar) - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll (stumbleupon.com)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe [2008/12/17 15:14:03 00,000,000 | —D | M]
O3 - HKLM\..\Toolbar: (Delicious Toolbar) - {61D1C847-DF80-423A-8C6D-DC03B97E6EBE} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll (Yahoo!)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Visual IP Trace) - {E70C26AE-DFF1-40A8-8D37-19180F56F0AA} - C:\Program Files\Visual IP Trace 2007\VisualIPTraceIE.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {61D1C847-DF80-423A-8C6D-DC03B97E6EBE} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll (Yahoo!)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3Tray.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" (ATI Technologies, Inc.)
O4 - HKLM..\Run: [Cleanup] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\200921911740_mcappins.exe /v=3 /cleanup File not found
O4 - HKLM..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [Framework Windows] frmwrk32.exe File not found
O4 - HKLM..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [HPLJ Config] C:\Program Files\Hewlett-Packard\hp LaserJet 1150_1300\SetConfig.exe -c Direct -p \\RICH\Printer2 -pn "hp LaserJet 1300 PCL 6" -n 0 -l 1033 -sl 120000 File not found
O4 - HKLM..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup (InstallShield Software Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [NvSvc] C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN (PC Tools Research Pty Ltd)
O4 - HKLM..\Run: [POEngine] File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Vcomohaqiteji] rundll32.exe "C:\WINDOWS\Tyadabadeb.dll",e File not found
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (AOL LLC)
O4 - HKCU..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h File not found
O4 - HKCU..\Run: [buxrn1pz7w] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\m94skxhh23w.exe File not found
O4 - HKCU..\Run: [ddbvvbffgcugslzluzvuzapozhq4ky3wtngfimalwo] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\mk6f6erbw5o.exe File not found
O4 - HKCU..\Run: [epouhezrh8m2febmukgj0lz4min1w0ja01q60o] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\jxlv8ubf6k7nk.exe File not found
O4 - HKCU..\Run: [eunwiivzf1qq4b6k8oy4hlejx1e] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ej674mgg2mqy9.exe File not found
O4 - HKCU..\Run: [f8oe3zmrk6qxdne30n] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ryo6abq.exe File not found
O4 - HKCU..\Run: [fd65ohld27xru3v3xnlpu8mnahwl] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\s4wqxhxm.exe File not found
O4 - HKCU..\Run: [fkvygza7dulzvx7] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\t7knpv.exe File not found
O4 - HKCU..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win (YourWare Solutions ™)
O4 - HKCU..\Run: [fufiavwt66uhm02kmd6z6m9sa9e1ye9yrgz90n2qlk] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\oq80yv6aex4xr.exe File not found
O4 - HKCU..\Run: [fz11zmfxxti0tm0fyea8cspi5ju7hed06v549h18rtjlmk17r] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\mppnb2l.exe File not found
O4 - HKCU..\Run: [g5bnfmyad5] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\q7g79u.exe File not found
O4 - HKCU..\Run: [gblwalhj50u050wowfub19crkywmz0ox5iuxkgsvyy] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\z4uiu7zr87.exe File not found
O4 - HKCU..\Run: [gefy7bvx0g356l3fof9vam72xcfvoynymzgkt6zpw41bdz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\k279qdq.exe File not found
O4 - HKCU..\Run: [Google Update] "C:\Documents and Settings\Justin Ward\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKCU..\Run: [hih6n8huzuwfo54bs9aztp9342a1k2v74q5hda7] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\omjmy1ta0us6b.exe File not found
O4 - HKCU..\Run: [hnvwypqz4wktrijiptavkw3] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\bp8017utvg6.exe File not found
O4 - HKCU..\Run: [hvfhh59loyl9fxbobxzq5zwta3q7q7klrgz6leec] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\gy4z7ig1sic2w.exe File not found
O4 - HKCU..\Run: [ih1lla2ugxyup8c5vjprp0xh5ifn] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\zdpw76q.exe File not found
O4 - HKCU..\Run: [ij0x3dqp8n2eanuuc35g276xv3m0cwuc92uk0m4yu0pwv1] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\kxd6rd.exe File not found
O4 - HKCU..\Run: [inq199t3um35gr95uqi99tizmmtixlgwuq6s28ml] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\cpvchcko3a9.exe File not found
O4 - HKCU..\Run: [j0bcgbrssfv7u8ki211xah3h] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\jbxrkfx644bml.exe File not found
O4 - HKCU..\Run: [j2kttcxbeyc8uu7xd0y3qo] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\vdpl98s.exe File not found
O4 - HKCU..\Run: [j6yeokh35p8lrrou38ndqpjkcq0w2hujjroz4ifvmdjp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\s1hlom17yoin5.exe File not found
O4 - HKCU..\Run: [ki70iwt539anjyex8yqwwzl842oyrbpu4m4bzp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\mamj5o.exe File not found
O4 - HKCU..\Run: [kj9amvvgra] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\q1yv1xtvqqeay.exe File not found
O4 - HKCU..\Run: [l15xjruer15j3] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\umqlnbkd9h.exe File not found
O4 - HKCU..\Run: [lb7zfzu9wmyryfuxedm53a151h6xzvyrjrxkgw6m6ajoun01] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\wyb9bsl9lb51.exe File not found
O4 - HKCU..\Run: [lik3apn6ns8pu3tgax2x4zz4uvpgwk] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\gcogol2a.exe File not found
O4 - HKCU..\Run: [mt45oumu76t2vs3v78aoneyo1nxnp3tj9yystt71] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\dtv02t9cuo.exe File not found
O4 - HKCU..\Run: [muzccvxccj0jrj27vygqsai4f4m5v57am9h20lb] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\rs5emz.exe File not found
O4 - HKCU..\Run: [nji71nhrq009qdnpk98trgftei7o6lbo2yh4castuh7] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\k1vf2y2.exe File not found
O4 - HKCU..\Run: [o5ag05ltdnt5weu1] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\s1boaa9pay.exe File not found
O4 - HKCU..\Run: [oefoafquonf0h82ca1igff6tqsw1h6] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\lgsu6c1t.exe File not found
O4 - HKCU..\Run: [ogmn3oex3nx4hunslx1nt73sb4lyzo4hi] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\v4a59bxqy8r72.exe File not found
O4 - HKCU..\Run: [psmrrboujpwq0ca0wzp4eu1wy9iz1byml0j] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\iu3f7g.exe File not found
O4 - HKCU..\Run: [q08dy0b3hvdj6zgkbu7c0xd84b26p6] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\tmha4s8ew.exe File not found
O4 - HKCU..\Run: [q5kz5rxk46yz6je] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\jecwtatp7.exe File not found
O4 - HKCU..\Run: [qxosansa18t6zsn4bp] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\ys67t8do.exe File not found
O4 - HKCU..\Run: [sk8fa8ccu6zaoce49v73l1l8tjm5frphj1r] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\rw6qwmku285u.exe File not found
O4 - HKCU..\Run: [sq9337epwvqh80k7c43] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\vkliiqxopv.exe File not found
O4 - HKCU..\Run: [tfqx8t7vsicg] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\s8g15z.exe File not found
O4 - HKCU..\Run: [Tristana] "C:\Program Files\eRSS Reader\Reader.exe" File not found
O4 - HKCU..\Run: [ur03apkgwhh62sd627o7m30] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\mqew4f.exe File not found
O4 - HKCU..\Run: [v6e8uu4wvm6tfboaoq4v3tgf4qulbqc5rze6r0lum] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\iwn5icjz64r.exe File not found
O4 - HKCU..\Run: [vhs5jutn7sa944h] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\q85alz.exe File not found
O4 - HKCU..\Run: [wbg6eywymqykmg92zz] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\flde355ncu.exe File not found
O4 - HKCU..\Run: [wmwpyccdavbrl6xr3sndqvz9a] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\kxz5da.exe File not found
O4 - HKCU..\Run: [wwvxjjq2fvap5wbu8dntyxjqcrx25vxpps90s1w71w2a7us] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\pvsw8ce742s.exe File not found
O4 - HKCU..\Run: [wxfywvapfqj5mqcu8ywwvypqptbvfxkgibk4ajqwuxbyb4] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\t0iqpwfukxbc8.exe File not found
O4 - HKCU..\Run: [xvgqph5xwsll] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\dmc1uy0w.exe File not found
O4 - HKCU..\Run: [ygew1wve0i8xw1m7wuegggozvi457s0tdrmqxhap9r] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\vxj8zv3.exe File not found
O4 - HKCU..\Run: [yjmg0bjxt4yvth2lux8nf] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\w048f0po.exe File not found
O4 - HKCU..\Run: [z0ulprkareo8mxzpyzp7owq6da7whkkz4q9q3fozdfit] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\tpcd6fcfulkei.exe File not found
O4 - HKCU..\Run: [zt45u3cu5bw03qns2qacys3lcmqmag4kwihh1onzhg8] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\xyj32d8duxg.exe File not found
O4 - HKCU..\Run: [zwptro0kcpym31arx40w4] C:\DOCUME~1\JUSTIN~1\LOCALS~1\Temp\sa7yca.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UltraMon.lnk = C:\WINDOWS\Installer\{AF0FA6D7-96F3-468A-ABB7-28BE006EA8E9}\IcoUltraMon.ico ()
O4 - Startup: C:\Documents and Settings\Justin Ward\Start Menu\Programs\Startup\Alienware Dock.lnk = C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe (Stardock)
O4 - Startup: C:\Documents and Settings\Justin Ward\Start Menu\Programs\Startup\iPhoneRingToneMaker.lnk = C:\Program Files\iPhoneRingToneMaker\iPhoneRingToneMaker.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMyMusic = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInstrumentation = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSimpleStartMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Activities present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThemesTab = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogOff = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: GreyMSIAds = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuEjectPC = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoColorChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSizeChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVisualStyleChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: Wallpaper = dcsdcs
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: Shell = sdcsdc
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Delicious - {2C887991-08F0-11DC-A9B2-0012F0B227DD} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll (Yahoo!)
O9 - Extra Button: Bookmarks - {2C887992-08F0-11DC-A9B2-0012F0B227DD} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll (Yahoo!)
O9 - Extra Button: Tag - {2C887993-08F0-11DC-A9B2-0012F0B227DD} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll (Yahoo!)
O9 - Extra Button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll File not found
O9 - Extra 'Tools' menuitem : Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 8 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} http://w4s2.work4sure.com/c/ge/w4sgeen9.exe (Reg Error: Key error.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} http://download.microsoft.com/download/7/1…20/pmupd806.exe (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} http://www.photodex.com/pxplay.cab (Reg Error: Key error.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe ()
O20 - Winlogon\Notify\WB: DllName - C:\Program Files\AlienGUIse\fastload.dll - C:\Program Files\AlienGUIse\fastload.dll (Stardock)
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {88485281-8b4b-4f8d-9ede-82e29a064277} - C:\Program Files\MarkAny\ContentSAFER\MACSMANAGER.dll (MarkAny Cooperation.)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[10 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/02/19 15:22:43 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/19 14:51:57 | 00,000,838 | —- | C] () – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\FASTWiz.html
[2009/02/19 14:50:11 | 00,000,760 | —- | C] () – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\FASTApp.html
[2009/02/19 14:45:39 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Dell
[2009/02/19 13:49:24 | 00,001,816 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\Default.rdp
[2009/02/19 13:43:17 | 00,009,320 | —- | C] () – C:\Documents and Settings\Justin Ward\Application Data\Tab Separated Values (Windows).EML
[2009/02/19 13:31:51 | 73,830,0927 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\Backup.bkf
[2009/02/19 12:33:48 | 00,494,592 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Justin Ward\Desktop\OTListIt2.exe
[2009/02/19 12:14:02 | 00,001,740 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\HijackThis.lnk
[2009/02/19 12:14:02 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/19 12:12:46 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Justin Ward\Desktop\HJTInstall.exe
[2009/02/19 11:49:46 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/02/19 11:43:06 | 00,104,960 | —- | C] () – C:\WINDOWS\System32\dllcache\userinit.exe
[2009/02/19 11:08:49 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/02/19 11:08:40 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/02/19 11:06:57 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/02/19 11:06:56 | 00,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/02/19 11:06:22 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2009/02/19 11:06:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/02/19 10:52:15 | 00,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2009/02/19 10:42:33 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\Desktop\smitRem
[2009/02/19 10:41:58 | 34,543,112 | —- | C] (Lavasoft ) – C:\Documents and Settings\Justin Ward\Desktop\Ad-AwareAE.exe
[2009/02/19 10:40:46 | 00,000,000 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\avg_avwt_stf_en_8_237a1428.exe
[2009/02/19 10:40:44 | 14,813,076 | —- | C] (AVG Technologies) – C:\Documents and Settings\Justin Ward\Desktop\avg_avwt_stf_en_8_237a1428.exe.part
[2009/02/19 10:40:15 | 00,383,836 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\smitRem.exe
[2009/02/19 10:30:08 | 03,153,920 | —- | C] () – C:\WINDOWS\System32\secsetup.sdb
[2009/02/18 16:12:46 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\{096DF24C-78B9-4FE5-ABAD-74E000BCD27D}
[2009/02/18 16:12:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\Application Data\PC Tools
[2009/02/18 16:11:05 | 00,000,671 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PC Tools AntiVirus.lnk
[2009/02/18 16:11:05 | 00,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2009/02/18 16:11:04 | 00,028,568 | —- | C] (PC Tools Research Pty Ltd.) – C:\WINDOWS\System32\drivers\AVHook.sys
[2009/02/18 16:11:04 | 00,021,912 | —- | C] (PC Tools Research Pty Ltd ) – C:\WINDOWS\System32\drivers\AVRec.sys
[2009/02/18 16:11:04 | 00,021,904 | —- | C] (PC Tools Research Pty Ltd) – C:\WINDOWS\System32\drivers\AVFilter.sys
[2009/02/18 16:10:54 | 00,000,000 | —D | C] – C:\Program Files\PC Tools AntiVirus
[2009/02/18 16:10:54 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2009/02/18 16:07:41 | 29,688,176 | —- | C] (PC Tools ) – C:\Documents and Settings\Justin Ward\Desktop\avinstall.exe
[2009/02/18 15:25:41 | 00,000,000 | —D | C] – C:\WINDOWS\System32\tov15
[2009/02/18 15:25:41 | 00,000,000 | —D | C] – C:\Temp
[2009/02/18 14:36:00 | 00,007,926 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_product.htm
[2009/02/18 14:36:00 | 00,006,577 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_saleproduct.htm
[2009/02/18 14:36:00 | 00,002,435 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_saleproductformat.htm
[2009/02/18 14:36:00 | 00,002,215 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_saleformat.htm
[2009/02/18 14:36:00 | 00,001,930 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_productformat.htm
[2009/02/18 14:29:24 | 00,095,256 | —- | C] () – C:\Documents and Settings\Justin Ward\Desktop\part240.zip
[2009/02/17 12:47:36 | 00,000,000 | —D | C] – C:\Program Files\Volusion Inc
[2009/02/13 15:24:15 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\Application Data\FileZilla
[2009/02/13 15:23:49 | 00,000,000 | —D | C] – C:\Program Files\FileZilla FTP Client
[2009/02/12 11:34:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\Boldchat
[2009/02/12 11:34:16 | 00,000,000 | —D | C] – C:\Program Files\Boldchat
[2009/02/12 10:36:01 | 00,000,000 | —D | C] – C:\Program Files\Foxit Software
[2009/02/11 15:24:00 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\WMTools Downloaded Files
[2009/02/05 16:19:59 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\My Documents\Adobe
[2009/02/02 09:55:47 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/02/02 09:51:52 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/30 14:58:42 | 00,518,064 | —- | C] (Codejock Software) – C:\WINDOWS\System32\Codejock.SkinFramework.Unicode.v11.2.0.ocx
[2009/01/30 14:58:41 | 01,746,864 | —- | C] (Codejock Software) – C:\WINDOWS\System32\Codejock.CommandBars.Unicode.v11.2.0.ocx
[2009/01/27 14:27:52 | 00,000,000 | —D | C] – C:\Documents and Settings\Justin Ward\My Documents\BGroomSaved Files
[2009/01/22 11:51:00 | 00,000,000 | —D | C] – C:\Program Files\YourWare Solutions

========== Files - Modified Within 30 Days ==========

[10 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/02/19 15:41:56 | 00,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/02/19 15:30:14 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/02/19 15:29:24 | 00,002,299 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UltraMon.lnk
[2009/02/19 15:27:30 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/19 15:27:08 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/19 15:27:06 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/19 15:17:59 | 00,006,577 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_saleproduct.htm
[2009/02/19 15:17:45 | 00,007,926 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_product.htm
[2009/02/19 15:12:00 | 00,000,266 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2009/02/19 15:00:34 | 08,566,836 | -H– | M] () – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\IconCache.db
[2009/02/19 14:51:58 | 00,000,838 | —- | M] () – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\FASTWiz.html
[2009/02/19 14:51:58 | 00,000,760 | —- | M] () – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\FASTApp.html
[2009/02/19 14:14:22 | 73,830,0927 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\Backup.bkf
[2009/02/19 13:49:25 | 00,001,816 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\Default.rdp
[2009/02/19 13:43:43 | 00,009,320 | —- | M] () – C:\Documents and Settings\Justin Ward\Application Data\Tab Separated Values (Windows).EML
[2009/02/19 12:33:51 | 00,494,592 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Justin Ward\Desktop\OTListIt2.exe
[2009/02/19 12:14:02 | 00,001,740 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\HijackThis.lnk
[2009/02/19 12:12:49 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Justin Ward\Desktop\HJTInstall.exe
[2009/02/19 11:43:01 | 00,104,960 | —- | M] () – C:\WINDOWS\System32\userinit.exe
[2009/02/19 11:43:01 | 00,104,960 | —- | M] () – C:\WINDOWS\System32\dllcache\userinit.exe
[2009/02/19 11:42:47 | 00,442,576 | —- | M] () – C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT
[2009/02/19 11:41:10 | 03,075,408 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/19 11:23:19 | 03,153,920 | —- | M] () – C:\WINDOWS\System32\secsetup.sdb
[2009/02/19 11:08:49 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/02/19 11:08:37 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/02/19 11:08:24 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/02/19 11:06:56 | 00,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/02/19 11:05:38 | 00,566,912 | —- | M] () – C:\WINDOWS\System32\Status.MPF
[2009/02/19 10:47:06 | 00,000,950 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2252052014-1732420521-1256393475-1005.job
[2009/02/19 10:47:00 | 14,813,076 | —- | M] (AVG Technologies) – C:\Documents and Settings\Justin Ward\Desktop\avg_avwt_stf_en_8_237a1428.exe.part
[2009/02/19 10:46:30 | 34,543,112 | —- | M] (Lavasoft ) – C:\Documents and Settings\Justin Ward\Desktop\Ad-AwareAE.exe
[2009/02/19 10:40:46 | 00,000,000 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\avg_avwt_stf_en_8_237a1428.exe
[2009/02/19 10:40:17 | 00,383,836 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\smitRem.exe
[2009/02/19 06:12:14 | 00,000,434 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{7043F3C0-C09E-4408-B96A-28E1B96FE699}.job
[2009/02/18 17:20:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/02/18 16:11:05 | 00,000,671 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PC Tools AntiVirus.lnk
[2009/02/18 16:10:22 | 29,688,176 | —- | M] (PC Tools ) – C:\Documents and Settings\Justin Ward\Desktop\avinstall.exe
[2009/02/18 14:36:00 | 00,002,435 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_saleproductformat.htm
[2009/02/18 14:36:00 | 00,002,215 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_saleformat.htm
[2009/02/18 14:36:00 | 00,001,930 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\tmp_productformat.htm
[2009/02/18 14:29:25 | 00,095,256 | —- | M] () – C:\Documents and Settings\Justin Ward\Desktop\part240.zip
[2009/02/18 09:59:38 | 00,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/02/13 22:20:57 | 00,000,362 | —- | M] () – C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (DELLBOX-Justin Ward).job
[2009/02/12 10:53:01 | 00,019,456 | —- | M] () – C:\Documents and Settings\Justin Ward\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/06 13:35:16 | 00,001,908 | -H– | M] () – C:\Documents and Settings\Justin Ward\My Documents\Default.rdp
[2009/02/03 15:21:12 | 21,244,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/02/02 10:01:37 | 00,000,082 | -HS- | M] () – C:\Documents and Settings\Justin Ward\My Documents\desktop.ini
[2009/02/02 09:58:41 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/01/29 11:04:26 | 00,001,824 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk

========== LOP Check ==========

[2009/02/19 14:45:39 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/11/24 14:22:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/02/19 11:06:58 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2008/11/13 14:59:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/12/15 10:52:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/12/15 11:09:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2008/09/22 14:33:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ALM
[2006/06/28 18:56:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2000/02/08 16:10:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2006/12/15 10:22:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2007/07/16 08:10:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/09/13 18:20:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/07/15 11:52:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Auslogics
[2008/12/12 11:24:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avanquest
[2007/03/06 14:56:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Corel
[2009/02/19 14:45:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2008/12/15 10:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FLEXnet
[2006/03/21 05:36:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2007/01/04 15:21:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2006/03/21 05:39:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2007/03/02 10:45:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2008/07/15 11:23:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2009/02/19 11:08:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2006/03/31 23:25:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Macromedia
[2009/02/19 11:07:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/09/16 22:16:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
[2008/04/21 16:43:43 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/02/19 11:09:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
[2006/03/28 22:16:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Games
[2009/01/14 11:18:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2008/04/30 16:19:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2008/10/01 15:11:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2007/08/15 11:37:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/02/19 10:50:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2007/05/01 09:45:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Protexis
[2006/03/31 17:42:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2008/07/07 09:33:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Radar Website Monitor
[2008/05/12 13:23:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Realtime Soft
[2007/11/20 11:06:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2006/03/21 05:31:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonic
[2008/06/11 14:18:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SPI Dynamics
[2006/12/15 10:52:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2006/12/15 10:52:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2007/10/19 11:14:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/02/19 15:30:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/10/16 09:15:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vale Software
[2008/11/13 14:59:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/03/28 21:52:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/09/18 09:49:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\XemiComputers
[2007/01/16 09:50:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2009/02/19 13:43:43 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Justin Ward\Application Data
[2008/09/09 14:08:15 | 00,000,000 | -HSD | M] – C:\Documents and Settings\Justin Ward\Application Data\.#
[2007/05/01 08:14:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\acccore
[2009/02/12 14:15:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Adobe
[2008/01/31 15:10:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\AdobeUM
[2008/03/26 13:25:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Apple Computer
[2007/01/04 16:21:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Arcsoft
[2008/12/12 11:15:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Avanquest
[2008/08/12 12:10:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Canon
[2008/09/24 14:04:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\cmw
[2007/03/06 14:59:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Corel
[2006/04/30 18:05:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Corel Photo Album
[2008/12/01 15:32:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Delicious IE Extension
[2008/10/24 11:59:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\DivX
[2007/10/19 11:04:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Download Manager
[2009/02/17 15:57:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\FileZilla
[2006/11/18 16:59:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\GlobalSCAPE
[2006/03/21 05:42:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Google
[2007/04/12 11:05:12 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Justin Ward\Application Data\Gtek
[2007/02/19 13:02:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Help
[2007/01/04 15:20:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\HotSync
[2009/02/18 12:57:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\IBP
[2005/08/16 02:50:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Identities
[2007/08/15 12:42:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\InstallShield
[2007/03/02 10:46:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Intuit
[2008/07/15 11:25:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\iolo
[2009/02/19 15:30:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\iPhoneRingToneMaker
[2006/04/06 18:25:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Leadertech
[2007/04/30 10:08:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\LimeWire
[2006/12/10 23:00:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Macromedia
[2009/01/05 14:24:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Mc & RENOX
[2007/04/02 15:16:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\McAfee.com Personal Firewall
[2008/08/18 08:39:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Microgaming
[2008/10/01 15:35:33 | 00,000,000 | –SD | M] – C:\Documents and Settings\Justin Ward\Application Data\Microsoft
[2006/03/28 22:16:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Microsoft Games
[2009/01/13 12:03:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Move Networks
[2009/01/29 10:02:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Mozilla
[2007/09/07 14:06:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Netscape
[2008/10/01 15:13:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Nitro PDF
[2007/01/26 10:40:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Opera
[2009/02/18 16:12:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\PC Tools
[2007/01/10 15:51:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Peachtree
[2008/02/08 16:44:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\QQ Games Plugin
[2007/02/04 16:12:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Real
[2008/01/11 10:22:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Realtime Soft
[2007/03/22 16:24:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Roxio
[2006/12/15 10:52:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\ScanSoft
[2008/09/04 09:59:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\SmartFTP
[2007/08/15 12:44:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Software602
[2006/12/15 10:47:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Sonic
[2008/08/05 08:36:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\StumbleUpon
[2006/03/21 05:25:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Sun
[2007/02/28 16:05:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Symantec
[2007/08/16 14:43:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Thinstall
[2009/01/05 14:18:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\TickerCast
[2009/02/19 15:24:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\uTorrent
[2007/04/12 09:40:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\UVU
[2007/02/01 09:06:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Vale Software
[2008/07/15 11:24:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\VersionTracker Pro
[2007/01/11 11:13:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Viewpoint
[2008/02/25 13:45:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Winamp
[2008/04/02 16:38:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\Windows Desktop Search
[2007/09/18 09:49:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Justin Ward\Application Data\XemiComputers
[2007/01/16 09:50:30 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Justin Ward\Application Data\yahoo!
[2009/02/19 11:08:49 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/02/18 17:20:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/02/19 15:12:00 | 00,000,266 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
[2004/08/10 03:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/19 10:47:06 | 00,000,950 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2252052014-1732420521-1256393475-1005.job
[2009/02/13 22:20:57 | 00,000,362 | —- | M] () – C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (DELLBOX-Justin Ward).job
[2009/02/19 15:30:14 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/02/19 15:27:08 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/02/19 06:12:14 | 00,000,434 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{7043F3C0-C09E-4408-B96A-28E1B96FE699}.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:933B2316
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:54272E15
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A8E2C33
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\System32\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Justin Ward\My Documents\Thumbs.db:encryptable
< End of report >
hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Heres the MBAM Log File Malwarebytes' Anti-Malware 1.34 Database version: 1780 Windows 5.1.2600 Service Pack 3 2/19/2009 4:01:14 PM mbam-log-2009-02-19 (16-01-14).txt Scan type: Quick Scan Objects scanned: 83173 Time elapsed: 10 minute(s), 5 second(s) Memory Processes Infected: 1 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 3 Registry Data Items Infected: 9 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: C:\WINDOWS\system32\nvsvc32.exe (Spyware.Agent) -> Failed to unload process. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7a23a1e8-b2ab-4c50-ad12-9e19b747e17c} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5bf49a2-94f3-42bd-f434-3604812c8955} (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nvsvc (Spyware.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vcomohaqiteji (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Framework Windows (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\userinit.exe -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceActiveDesktopOn (Hijack.Desktop) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\nvsvc32.exe (Spyware.Agent) -> Delete on reboot. C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully. C:\Documents and Settings\Justin Ward\MediaTubeCodec_ver1.1502.0.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. ——————————————————————————————————————————————————————————————————————– ——————————————————————————————————————————————————————————————————————– ——————————————————————————————————————————————————————————————————————– ——————————————————————————————————————————————————————————————————————– ——————————————————————————————————————————————————————————————————————– And the Kaspersky Log File ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Friday, February 20, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Thursday, February 19, 2009 22:49:01 Records in database: 1818144 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ G:\ Scan statistics: Files scanned: 282158 Threat name: 7 Infected objects: 9 Suspicious objects: 0 Duration of the scan: 04:31:58 File name / Threat name / Threats count C:\Documents and Settings\Justin Ward\My Documents\Downloads\SmartFTP 3.0.1019.8 Incl Crack [Working]\sftpmsi.exe Infected: Trojan-Downloader.Win32.Agent.aeog 1 C:\Documents and Settings\Justin Ward\My Documents\Downloads\SmartFTP 3.0.1019.8 Incl Crack [Working].rar Infected: Trojan-Downloader.Win32.Agent.aeog 1 C:\Program Files\XemiComputers\Active Desktop Calendar\ADC World Clock.scr Infected: not-a-virus:Monitor.Win32.KeyPressHooker.f 1 C:\WINDOWS\system32\tov15\tov151080.exe Infected: Trojan-Downloader.Win32.VB.hvw 1 C:\_OTListIt\MovedFiles\02192009_152243\joehug.exe Infected: Trojan-Downloader.Win32.Agent.bgxu 1 C:\_OTListIt\MovedFiles\02192009_152243\kjqgqk.exe Infected: Trojan.Win32.Monder.bdnr 1 C:\_OTListIt\MovedFiles\02192009_152243\ouqhk.exe Infected: Trojan-Downloader.Win32.Agent.biai 1 C:\_OTListIt\MovedFiles\02192009_152243\WINDOWS\system32\frmwrk32.exe Infected: Trojan.Win32.Monder.bdnr 1 C:\_OTListIt\MovedFiles\02192009_152243\WINDOWS\system32\ntdll64.exe Infected: Trojan.Win32.Monder.bdnp 1 The selected area was scanned.
Heres the MBAM Log File Malwarebytes' Anti-Malware 1.34 Database version: 1780 Windows 5.1.2600 Service Pack 3 2/19/2009 4:01:14 PM mbam-log-2009-02-19 (16-01-14).txt Scan type: Quick Scan Objects scanned: 83173 Time elapsed: 10 minute(s), 5 second(s) Memory Processes Infected: 1 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 3 Registry Data Items Infected: 9 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: C:\WINDOWS\system32\nvsvc32.exe (Spyware.Agent) -> Failed to unload process. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7a23a1e8-b2ab-4c50-ad12-9e19b747e17c} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5bf49a2-94f3-42bd-f434-3604812c8955} (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nvsvc (Spyware.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vcomohaqiteji (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Framework Windows (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\userinit.exe -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceActiveDesktopOn (Hijack.Desktop) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\nvsvc32.exe (Spyware.Agent) -> Delete on reboot. C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully. C:\Documents and Settings\Justin Ward\MediaTubeCodec_ver1.1502.0.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. ——————————————————————————————————————————————————————————————————————– ——————————————————————————————————————————————————————————————————————– ——————————————————————————————————————————————————————————————————————– ——————————————————————————————————————————————————————————————————————– ——————————————————————————————————————————————————————————————————————– And the Kaspersky Log File ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Friday, February 20, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Thursday, February 19, 2009 22:49:01 Records in database: 1818144 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ G:\ Scan statistics: Files scanned: 282158 Threat name: 7 Infected objects: 9 Suspicious objects: 0 Duration of the scan: 04:31:58 File name / Threat name / Threats count C:\Documents and Settings\Justin Ward\My Documents\Downloads\SmartFTP 3.0.1019.8 Incl Crack [Working]\sftpmsi.exe Infected: Trojan-Downloader.Win32.Agent.aeog 1 C:\Documents and Settings\Justin Ward\My Documents\Downloads\SmartFTP 3.0.1019.8 Incl Crack [Working].rar Infected: Trojan-Downloader.Win32.Agent.aeog 1 C:\Program Files\XemiComputers\Active Desktop Calendar\ADC World Clock.scr Infected: not-a-virus:Monitor.Win32.KeyPressHooker.f 1 C:\WINDOWS\system32\tov15\tov151080.exe Infected: Trojan-Downloader.Win32.VB.hvw 1 C:\_OTListIt\MovedFiles\02192009_152243\joehug.exe Infected: Trojan-Downloader.Win32.Agent.bgxu 1 C:\_OTListIt\MovedFiles\02192009_152243\kjqgqk.exe Infected: Trojan.Win32.Monder.bdnr 1 C:\_OTListIt\MovedFiles\02192009_152243\ouqhk.exe Infected: Trojan-Downloader.Win32.Agent.biai 1 C:\_OTListIt\MovedFiles\02192009_152243\WINDOWS\system32\frmwrk32.exe Infected: Trojan.Win32.Monder.bdnr 1 C:\_OTListIt\MovedFiles\02192009_152243\WINDOWS\system32\ntdll64.exe Infected: Trojan.Win32.Monder.bdnp 1 The selected area was scanned.
Don't bump your topic Its been less than a day since you got a reply. I am a volunteer, I do this in my free time. It's also the weekend, that means I have a life If you want instant service, please feel free to bring it to a repair shop and pay $200 for it. Is that clear ?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI