This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] lsass.exe and permissions? Something weird... Please h

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

am running Vista x64. My hard drive has been thrashing even while idling and I looked into the problem. I tried to disable lsass.exe but I got an error that said "Windows has encountered a critical error and will shut down…" I tried to go into safe mode and work with it but I got all of these random security errors. Here is my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:13:49 AM, on 3/7/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

CODE
Running processes:
C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: *.line6.net
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - AppInit_DLLs: C:\Program,Files,(x86)\RelevantKnowledge\rlai.dll,C:\Program,Files,(x86)\RelevantKnowledge\rlai.dll,C:\Program,Files,(x86)\RelevantKnowledge\rlai.dll,C:\Program Files (x86)\RelevantKnowledge\rlai.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Cobian Backup 9 service (CobianBackupAmanita) - Luis Cobian - C:\Program Files (x86)\Cobian Backup 9\cbService.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: dkab_device - - C:\Windows\system32\DKabcoms.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RelevantKnowledge - Unknown owner - C:\Program Files (x86)\RelevantKnowledge\rlservice.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 7073 bytes



Any help is MUCH appreciated. I am worried something I downloaded may have had a virus.
Go to the top of the pageReport Post


Edit Post
Hi there,

Welcome to WTT.

Being a 64 bit windows system means that most of the tools I have available wont work, so we will need to do some searching with the tools that do. The good news is that most malware doesn't work on 64 bit systems either! :)

Now, tell me, what are you using for an anti virus, as I don't see one in your log.

Download OTListIt2.exe and save it to your desktop
  • Double click OTListIt2.exe to run the program
  • Put a checkmark into Scan All Users
  • In the Output box, make sure that Minimal Output is selected
  • In Extra Registry check Use SafeList
  • In the File Age drop down menu, select 30 Days
  • Click the Run Scan button
When the scan is complete, a log will open named OTListIt.Txt another log will also be produced but will be minimised, named Extras.Txt Both these logs will be saved to your desktop.

Please post the contents of both logs in your next reply.

Please make a separate post for each log.

Regards,
RatHat
I don't use antivirus (and I haven't for 17 years). I hit the occasional bump in the road, but for the most part it's been fine.

OTLIST

OTListIt logfile created on: 3/7/2009 10:58:59 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.3.4 Folder = C:\Users\Joe\Downloads
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.76 Gb Available Physical Memory | 69.01% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 139.73 Gb Total Space | 25.86 Gb Free Space | 18.51% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 232.76 Gb Total Space | 140.07 Gb Free Space | 60.18% Space Free | Partition Type: NTFS
Drive G: | 132.88 Gb Total Space | 34.81 Gb Free Space | 26.19% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive S: | 100.00 Gb Total Space | 83.90 Gb Free Space | 83.90% Space Free | Partition Type: NTFS

Computer Name: JOE-PC
Current User Name: Joe
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2005/07/15 16:48:33 | 00,479,232 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
PRC - [2008/11/07 14:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe
PRC - [2008/09/21 22:21:44 | 00,583,168 | —- | M] (Luis Cobian) – C:\Program Files (x86)\Cobian Backup 9\cbService.exe
PRC - [2009/03/01 20:59:47 | 00,070,968 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2009/03/07 08:33:01 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2008/01/19 02:33:18 | 00,151,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\NOTEPAD.EXE
PRC - [2009/03/07 10:58:38 | 00,498,176 | —- | M] (OldTimer Tools) – C:\Users\Joe\Downloads\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/11/07 14:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - File not found – – (aspnet_state [On_Demand | Stopped])
SRV - [2008/07/03 22:36:39 | 00,901,120 | —- | M] () – C:\Windows\sysnative\Ati2evxx.exe – (Ati External Event Utility [Auto | Running])
SRV - [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe – (Bonjour Service [Auto | Running])
SRV - [2008/07/27 13:03:13 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/27 13:01:49 | 00,093,184 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
SRV - [2008/09/21 22:21:44 | 00,583,168 | —- | M] (Luis Cobian) – C:\Program Files (x86)\Cobian Backup 9\cbService.exe – (CobianBackupAmanita [Auto | Running])
SRV - [2008/01/19 03:01:11 | 00,598,016 | —- | M] () – C:\Windows\sysnative\cscsvc.dll – (CscService [Auto | Running])
SRV - [2006/10/21 11:38:24 | 00,508,824 | —- | M] ( ) – C:\Windows\system32\DKabcoms.exe – (dkab_device [On_Demand | Stopped])
SRV - [2008/01/19 03:00:14 | 00,344,064 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehRecvr.exe – (ehRecvr [On_Demand | Stopped])
SRV - [2008/01/19 03:00:14 | 00,153,600 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehsched.exe – (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 10:03:44 | 00,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehstart.dll – (ehstart [Auto | Stopped])
SRV - [2008/01/19 03:00:17 | 00,689,152 | —- | M] () – C:\Windows\sysnative\fxssvc.exe – (Fax [On_Demand | Stopped])
SRV - [2008/11/16 18:59:27 | 00,655,624 | —- | M] (Acresso Software Inc.) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service [Disabled | Stopped])
SRV - [2008/11/16 18:59:32 | 01,038,088 | —- | M] (Acresso Software Inc.) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe – (FLEXnet Licensing Service 64 [On_Demand | Stopped])
SRV - [2008/06/19 20:17:12 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/06/19 20:16:53 | 00,859,648 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2008/11/20 13:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files (x86)\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Stopped])
SRV - [2007/10/19 12:17:04 | 00,255,000 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe – (LVCOMSer [Disabled | Stopped])
SRV - [2007/10/19 12:18:36 | 00,182,296 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcS64 [Disabled | Stopped])
SRV - [2007/10/19 12:20:42 | 00,171,032 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe – (LVSrvLauncher [Disabled | Stopped])
SRV - [2008/06/19 20:16:54 | 00,119,808 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/08/24 02:19:12 | 00,443,776 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 13:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2008/01/19 03:03:34 | 00,079,360 | —- | M] () – C:\Windows\sysnative\pcasvc.dll – (PcaSvc [Auto | Running])
SRV - [2008/01/19 02:33:19 | 00,019,968 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\perfhost.exe – (PerfHost [On_Demand | Stopped])
SRV - [2009/03/01 20:59:47 | 00,070,968 | —- | M] () – C:\Windows\system32\PnkBstrA.exe – (PnkBstrA [Auto | Running])
SRV - File not found – – (RelevantKnowledge [Auto | Stopped])
SRV - [2009/02/03 21:27:31 | 00,316,664 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service [On_Demand | Stopped])
SRV - [2008/01/19 03:04:21 | 00,252,928 | —- | M] () – C:\Windows\sysnative\umrdp.dll – (UmRdpService [On_Demand | Stopped])
SRV - [2008/01/19 03:00:43 | 01,147,904 | —- | M] () – C:\Windows\sysnative\wbengine.exe – (wbengine [On_Demand | Stopped])
SRV - [2008/01/19 03:00:47 | 01,216,000 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Running])

========== Driver Services (SafeList) ==========

DRV - [2008/06/27 07:51:10 | 00,088,632 | —- | M] () – C:\Windows\sysnative\drivers\adfs.sys – (adfs [Auto | Running])
DRV - [2008/07/04 01:36:02 | 04,598,272 | —- | M] () – C:\Windows\sysnative\DRIVERS\atikmdag.sys – (atikmdag [On_Demand | Running])
DRV - [2006/10/31 02:25:02 | 00,014,136 | R— | M] (BIOSTAR Group) – C:\Windows\system32\drivers\BIOS64.sys – (BIOS [System | Running])
DRV - [2008/01/19 00:55:40 | 00,460,800 | —- | M] () – C:\Windows\sysnative\drivers\csc.sys – (CSC [System | Running])
DRV - [2008/01/19 03:10:43 | 00,161,848 | —- | M] () – C:\Windows\sysnative\DRIVERS\fvevol.sys – (fvevol [Boot | Running])
DRV - [2008/04/17 12:12:54 | 00,019,304 | —- | M] () – C:\Windows\sysnative\Drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [2006/11/02 00:28:10 | 00,273,920 | —- | M] () – C:\Windows\sysnative\drivers\HdAudio.sys – (HdAudAddService [On_Demand | Running])
DRV - [2008/06/11 12:37:18 | 00,816,640 | —- | M] () – C:\Windows\sysnative\Drivers\L6POD64.sys – (L6POD [On_Demand | Stopped])
DRV - [2007/10/19 12:16:08 | 01,599,896 | —- | M] () – C:\Windows\sysnative\DRIVERS\LVcKap64.sys – (LVcKap64 [On_Demand | Stopped])
DRV - [2007/10/11 17:58:16 | 02,055,192 | —- | M] () – C:\Windows\sysnative\DRIVERS\LVMVDrv.sys – (LVMVDrv [On_Demand | Stopped])
DRV - [2007/10/11 20:58:26 | 01,381,528 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvpopf64.sys – (lvpopf64 [On_Demand | Stopped])
DRV - [2007/10/11 17:58:28 | 00,030,232 | —- | M] () – C:\Windows\sysnative\DRIVERS\LVPr2M64.sys – (LVPr2M64 [On_Demand | Stopped])
DRV - [2007/10/11 20:59:34 | 01,573,528 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvrs64.sys – (LVRS64 [On_Demand | Stopped])
DRV - [2007/10/11 20:59:46 | 00,067,864 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvsels64.sys – (lvsels64 [On_Demand | Stopped])
DRV - [2007/10/11 21:00:20 | 00,050,072 | —- | M] () – C:\Windows\sysnative\drivers\LVUSBS64.sys – (LVUSBS64 [On_Demand | Stopped])
DRV - [2007/10/11 21:00:32 | 03,875,736 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvuvc64.sys – (LVUVC64 [On_Demand | Stopped])
DRV - [2008/02/14 16:56:14 | 00,160,768 | —- | M] () – C:\Windows\sysnative\DRIVERS\Rtlh64.sys – (RTL8169 [On_Demand | Running])
DRV - [2007/08/06 19:21:32 | 00,057,776 | —- | M] () – C:\Windows\sysnative\drivers\scdemu.sys – (SCDEmu [System | Running])
DRV - [2008/09/24 20:44:14 | 00,868,848 | —- | M] () – C:\Windows\sysnative\Drivers\sptd.sys – (sptd [Boot | Running])
DRV - [2008/10/01 12:01:28 | 00,040,448 | —- | M] () – C:\Windows\sysnative\Drivers\usbaapl64.sys – (USBAAPL64 [On_Demand | Stopped])
DRV - [2008/01/19 01:33:58 | 00,098,816 | —- | M] () – C:\Windows\sysnative\drivers\usbaudio.sys – (usbaudio [On_Demand | Stopped])
DRV - [2008/01/19 01:47:12 | 00,046,080 | —- | M] () – C:\Windows\sysnative\DRIVERS\wpdusb.sys – (WpdUsb [On_Demand | Stopped])
DRV - [2008/01/19 01:30:09 | 00,903,168 | —- | M] () – C:\Windows\sysnative\DRIVERS\xnacc.sys – (xnacc [On_Demand | Stopped])
DRV - [2007/08/28 17:04:20 | 00,067,968 | —- | M] () – C:\Windows\sysnative\DRIVERS\xusb21.sys – (xusb21 [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2302334944-2735162308-3066632546-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-2302334944-2735162308-3066632546-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\S-1-5-21-2302334944-2735162308-3066632546-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKU\S-1-5-21-2302334944-2735162308-3066632546-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2302334944-2735162308-3066632546-1000\S-1-5-21-2302334944-2735162308-3066632546-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2302334944-2735162308-3066632546-1000\S-1-5-21-2302334944-2735162308-3066632546-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> %SystemRoot%\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/03/07 09:40:06 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS] -> [2009/03/07 08:33:09 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS] -> [2009/03/07 08:33:09 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Extensions [2008/07/24 09:39:17 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008/07/24 09:39:17 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Firefox\Profiles\vvcb3esk.default\extensions [2009/03/07 10:12:04 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Firefox\Profiles\vvcb3esk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2009/02/07 20:13:35 00,000,000 | —D | M]
FF - C:\Program Files (x86)\mozilla firefox\extensions [2009/03/07 10:12:04 00,000,000 | —D | M]
FF - C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/03/07 08:33:09 00,000,000 | —D | M]
FF - C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [2008/08/18 22:28:41 00,000,000 | —D | M]

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe" (Google Inc.)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)
O4 - HKU\S-1-5-21-2302334944-2735162308-3066632546-1000..\Run: [AdobeBridge] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2302334944-2735162308-3066632546-1000\..Trusted Sites: line6.net ([]* in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\Program) - File not found
O20 - AppInit_DLLs: (Files) - File not found
O20 - AppInit_DLLs: ((x86)\RelevantKnowledge\rlai.dll) - File not found
O20 - AppInit_DLLs: (C:\Program) - File not found
O20 - AppInit_DLLs: (Files) - File not found
O20 - AppInit_DLLs: ((x86)\RelevantKnowledge\rlai.dll) - File not found
O20 - AppInit_DLLs: (C:\Program) - File not found
O20 - AppInit_DLLs: (Files) - File not found
O20 - AppInit_DLLs: ((x86)\RelevantKnowledge\rlai.dll) - File not found
O20 - AppInit_DLLs: (C:\Program Files (x86)\RelevantKnowledge\rlai.dll) - C:\Program Files (x86)\RelevantKnowledge\rlai.dll File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\system32\explorer.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{fab4f970-6bf1-11dd-90bc-00e04d9293d1}\Shell - "" = AutoRun
O33 - MountPoints2\{fab4f970-6bf1-11dd-90bc-00e04d9293d1}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[2009/03/07 10:13:34 | 00,001,928 | —- | C] () – C:\Users\Joe\Desktop\HijackThis.lnk
[2009/03/07 10:13:33 | 00,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2009/03/07 10:11:04 | 42,941,64480 | -HS- | C] () – C:\hiberfil.sys
[2009/03/07 09:35:48 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/03/07 09:35:46 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/03/07 09:35:46 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/03/07 09:35:46 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/03/07 09:35:46 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/03/07 09:35:46 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/03/07 09:35:42 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/03/07 09:35:41 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/03/07 09:24:31 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/03/07 09:24:16 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/03/07 09:24:05 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/03/07 09:23:54 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/03/07 09:23:50 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/03/07 09:11:59 | 00,151,696 | —- | C] (Symantec Corporation) – C:\Users\Public\Documents\FxSasser.exe
[2009/03/05 21:07:39 | 00,000,000 | —D | C] – C:\Program Files (x86)\IrfanView
[2009/03/05 21:05:45 | 00,000,568 | —- | C] () – C:\Users\Joe\Desktop\Untitled-1.bmp
[2009/03/04 19:23:18 | 00,000,000 | —D | C] – C:\Users\Joe\Documents\FjChapman Current
[2009/03/03 23:07:32 | 02,021,903 | —- | C] () – C:\Users\Joe\Desktop\fat.mp3
[2009/03/03 21:32:18 | 01,081,852 | —- | C] () – C:\Users\Joe\Desktop\DIAB.psd
[2009/03/03 21:32:10 | 00,088,607 | —- | C] () – C:\Users\Joe\Desktop\DIAB.png
[2009/03/03 21:19:28 | 00,238,029 | —- | C] () – C:\Users\Joe\Desktop\diab.ai
[2009/03/03 14:30:31 | 00,879,378 | —- | C] () – C:\Users\Joe\Desktop\Untitled-5.jpg
[2009/03/03 14:25:26 | 00,113,347 | —- | C] () – C:\Users\Joe\Desktop\trans.png
[2009/03/03 08:35:05 | 00,000,000 | —D | C] – C:\Users\Joe\Desktop\auto
[2009/03/01 20:46:04 | 00,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\id Software
[2009/03/01 20:28:53 | 00,188,896 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2009/03/01 20:28:51 | 02,246,144 | —- | C] () – C:\Windows\System32\pbsvc.exe
[2009/03/01 20:28:51 | 00,070,968 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2009/03/01 20:28:51 | 00,000,000 | —D | C] – C:\ProgramData\id Software
[2009/03/01 12:07:58 | 00,000,000 | —D | C] – C:\$WINDOWS.~BT
[2009/02/15 01:29:14 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/02/15 01:29:14 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/02/15 01:29:13 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/02/15 01:29:13 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/02/15 01:29:13 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/02/12 22:44:55 | 00,471,624 | —- | C] () – C:\Users\Joe\Desktop\funkdrum.wav
[2009/02/11 21:48:18 | 07,686,144 | —- | C] () – C:\Users\Joe\Desktop\stressed.mp3
[2009/02/11 14:10:04 | 06,069,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/02/11 14:10:04 | 03,580,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/02/11 14:10:03 | 01,166,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/02/11 14:10:03 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/02/11 14:10:03 | 00,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/02/11 14:10:02 | 01,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/02/11 14:10:02 | 00,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/02/11 14:10:02 | 00,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/02/11 14:10:02 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/02/10 20:51:48 | 03,107,582 | —- | C] () – C:\Users\Joe\Desktop\pc.mp3
[2009/02/05 18:15:02 | 00,946,776 | —- | C] () – C:\Users\Joe\Desktop\Yagmi.mp3

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[2009/03/07 10:13:34 | 00,001,928 | —- | M] () – C:\Users\Joe\Desktop\HijackThis.lnk
[2009/03/07 10:11:13 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/03/07 10:11:09 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/03/07 10:11:04 | 42,941,64480 | -HS- | M] () – C:\hiberfil.sys
[2009/03/07 09:55:14 | 00,743,720 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/03/07 09:10:20 | 00,151,696 | —- | M] (Symantec Corporation) – C:\Users\Public\Documents\FxSasser.exe
[2009/03/06 17:03:16 | 00,000,465 | —- | M] () – C:\Windows\BRWMARK.INI
[2009/03/05 21:05:49 | 00,000,568 | —- | M] () – C:\Users\Joe\Desktop\Untitled-1.bmp
[2009/03/03 23:07:38 | 02,021,903 | —- | M] () – C:\Users\Joe\Desktop\fat.mp3
[2009/03/03 21:32:18 | 01,081,852 | —- | M] () – C:\Users\Joe\Desktop\DIAB.psd
[2009/03/03 21:32:12 | 00,088,607 | —- | M] () – C:\Users\Joe\Desktop\DIAB.png
[2009/03/03 21:19:32 | 00,238,029 | —- | M] () – C:\Users\Joe\Desktop\diab.ai
[2009/03/03 14:30:32 | 00,879,378 | —- | M] () – C:\Users\Joe\Desktop\Untitled-5.jpg
[2009/03/03 14:25:27 | 00,113,347 | —- | M] () – C:\Users\Joe\Desktop\trans.png
[2009/03/02 11:21:14 | 07,686,144 | —- | M] () – C:\Users\Joe\Desktop\stressed.mp3
[2009/03/01 20:59:47 | 00,070,968 | —- | M] () – C:\Windows\System32\PnkBstrA.exe
[2009/03/01 20:59:37 | 00,188,896 | —- | M] () – C:\Windows\System32\PnkBstrB.exe
[2009/03/01 20:32:15 | 02,246,144 | —- | M] () – C:\Windows\System32\pbsvc.exe
[2009/03/01 12:08:16 | 00,001,905 | —- | M] () – C:\Windows\diagwrn.xml
[2009/03/01 12:08:16 | 00,001,905 | —- | M] () – C:\Windows\diagerr.xml
[2009/02/17 14:58:18 | 00,044,032 | —- | M] () – C:\Users\Joe\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/12 22:45:28 | 00,471,624 | —- | M] () – C:\Users\Joe\Desktop\funkdrum.wav
[2009/02/10 20:52:13 | 03,107,582 | —- | M] () – C:\Users\Joe\Desktop\pc.mp3
[2009/02/08 14:09:04 | 00,946,776 | —- | M] () – C:\Users\Joe\Desktop\Yagmi.mp3
< End of report >
Extras

OTListIt Extras logfile created on: 3/7/2009 10:58:59 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.3.4 Folder = C:\Users\Joe\Downloads
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.76 Gb Available Physical Memory | 69.01% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 139.73 Gb Total Space | 25.86 Gb Free Space | 18.51% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 232.76 Gb Total Space | 140.07 Gb Free Space | 60.18% Space Free | Partition Type: NTFS
Drive G: | 132.88 Gb Total Space | 34.81 Gb Free Space | 26.19% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive S: | 100.00 Gb Total Space | 83.90 Gb Free Space | 83.90% Space Free | Partition Type: NTFS

Computer Name: JOE-PC
Current User Name: Joe
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\Windows\system32\regedit.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_USERS\S-1-5-21-2302334944-2735162308-3066632546-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{02EBDBB9-4600-41D3-B566-40CB861511D2}" = World of Warcraft FREE Trial
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0B533F34-22BA-4301-BAF8-EA1CEDB06F9E}" = Quake Live Mozilla Plugin
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{102BBD3F-807B-EAA8-BCDA-4776CE151C88}" = Catalyst Control Center HydraVision Full
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2EC9C5F0-FE63-F7EF-309F-4F84A65DEF9F}" = CCC Help English
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{37E1C1F7-D70C-62C6-E76B-9339F172B7CC}" = Catalyst Control Center Graphics Full New
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{3EE51BAD-9916-49C7-90BA-3D500B031E0C}_is1" = VSO Image Resizer [removed]
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4AB03689-77FF-EEC5-0EC8-333E90D1C5DF}" = Catalyst Control Center Graphics Light
"{4F3E17F8-F1C8-4A4B-9EB8-1EE2D190CDA9}" = Adobe Setup
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{600DFD83-DD58-25D6-E8F5-EB52E79AEC5A}" = Catalyst Control Center Graphics Full Existing
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}" = Power Tab Editor 1.7
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77C6259A-4B53-402C-BE95-DE3C43E3655C}" = Brother HL-4040CN
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{784E6B0F-00EC-4950-95A2-BBA64F44EC48}" = Camtasia Studio 5
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{00C5525B-3CB3-467D-8100-2E6FB306CD86}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{9A9487A0-A716-40B2-AF7D-8902E0DC85AF}" = TouchCopy
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A7BA4B8D-0349-9387-0F35-E0AC7985D4B8}" = ccc-core-static
"{A98BEA7A-5F50-45C9-AB8C-751BBBC661C6}" = Quake Live Internet Explorer Plugin
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AE9F08F6-9CBC-AC76-73E7-FB4F7E7023BE}" = Catalyst Control Center Graphics Previews Common
"{AF22BF45-2451-F683-C1FA-025D62D536A5}" = Catalyst Control Center Graphics Previews Vista
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B6C3EBA1-5A68-1881-4DF1-E594C4BD4A2B}" = Skins
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C8616041-2802-4DE2-B3BD-6285AAD65C2A}" = NEF Codec
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{E33EAB77-A36A-4FBF-BB15-2BBF74C7A796}" = iPhoneBrowser
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E87162FD-1821-C742-5D9E-F83E6D69851B}" = Catalyst Control Center Core Implementation
"{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
"{FA3A247D-437A-455E-A88F-7EB6E5F9E799}" = Catalyst Control Center - Branding
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_a04a925a57548091300ada368235fc6" = Adobe Illustrator CS3
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"All ATI Software" = ATI - Software Uninstall Utility
"ASIO4ALL" = ASIO4ALL
"Audacity_is1" = Audacity 1.2.6
"AviSynth" = AviSynth 2.5
"CobBackup9" = Cobian Backup 9
"Drum Machine" = Drum Machine 1.34 BETA
"DVD Decrypter" = DVD Decrypter (Remove Only)
"FileZilla Client" = FileZilla Client 3.1.6
"FL Studio 8" = FL Studio 8
"FLV Player" = FLV Player 2.0, build 24
"GoldWave v5.23" = GoldWave v5.23
"Guitar Pro 5_is1" = Guitar Pro 5.2
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IL Download Manager" = IL Download Manager
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty® 4 - Modern Warfare™ 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty® 4 - Modern Warfare™ 1.7 Patch
"IrfanView" = IrfanView (remove only)
"Line 6 Uninstaller" = Line 6 Uninstaller
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.7)" = Mozilla Firefox (3.0.7)
"PoiZone" = PoiZone
"PowerISO" = PowerISO
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 6.0" = RealPlayer
"Steam App 240" = Counter-Strike: Source
"Steam App 440" = Team Fortress 2
"Toxic Biohazard" = Toxic Biohazard
"Trillian" = Trillian
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 0.9.6
"Winamp" = Winamp
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2302334944-2735162308-3066632546-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/7/2009 10:02:12 AM | Computer Name = Joe-PC | Source = Wininit | ID = 1015
Description = A critical system process, C:\Windows\system32\lsass.exe, failed with
status code 1. The machine must now be restarted.

Error - 3/7/2009 10:57:55 AM | Computer Name = Joe-PC | Source = Wininit | ID = 1015
Description = A critical system process, C:\Windows\system32\lsass.exe, failed with
status code 1. The machine must now be restarted.

Error - 3/7/2009 10:57:56 AM | Computer Name = Joe-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 3/7/2009 10:58:00 AM | Computer Name = Joe-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 3/7/2009 10:58:11 AM | Computer Name = Joe-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 3/7/2009 10:58:11 AM | Computer Name = Joe-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 3/7/2009 10:58:15 AM | Computer Name = Joe-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 3/7/2009 10:58:20 AM | Computer Name = Joe-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 3/7/2009 10:58:20 AM | Computer Name = Joe-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 3/7/2009 11:00:29 AM | Computer Name = Joe-PC | Source = EventSystem | ID = 4609
Description =

[ System Events ]
Error - 3/7/2009 10:02:26 AM | Computer Name = Joe-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 3/7/2009 10:02:26 AM | Computer Name = Joe-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 3/7/2009 10:02:26 AM | Computer Name = Joe-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 3/7/2009 10:02:26 AM | Computer Name = Joe-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 3/7/2009 10:02:26 AM | Computer Name = Joe-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 3/7/2009 10:02:26 AM | Computer Name = Joe-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 3/7/2009 10:02:26 AM | Computer Name = Joe-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 3/7/2009 10:02:26 AM | Computer Name = Joe-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 3/7/2009 7:13:25 AM | Computer Name = Joe-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 9:03:08 AM on 3/7/2009 was unexpected.

Error - 3/7/2009 7:13:28 AM | Computer Name = Joe-PC | Source = HTTP | ID = 15016
Description =


< End of report >
There are a few things we can fix with OTListIt2
  • Double click OTListIt2.exe to run the program
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :processes
    explorer.exe
    
    :otli
    SRV - File not found – – (RelevantKnowledge [Auto | Stopped])
    O20 - AppInit_DLLs: (C:\Program) - File not found
    O20 - AppInit_DLLs: (Files) - File not found
    O20 - AppInit_DLLs: ((x86)\RelevantKnowledge\rlai.dll) - File not found
    O20 - AppInit_DLLs: (C:\Program) - File not found
    O20 - AppInit_DLLs: (Files) - File not found
    O20 - AppInit_DLLs: ((x86)\RelevantKnowledge\rlai.dll) - File not found
    O20 - AppInit_DLLs: (C:\Program) - File not found
    O20 - AppInit_DLLs: (Files) - File not found
    O20 - AppInit_DLLs: ((x86)\RelevantKnowledge\rlai.dll) - File not found
    O20 - AppInit_DLLs: (C:\Program Files (x86)\RelevantKnowledge\rlai.dll) - C:\Program Files (x86)\RelevantKnowledge\rlai.dll File not found
    
    :commands
    [start explorer]
    [emptytemp]
    [purity]
  • Return to OTListIt2, right click in the "Custom Scans/Fixes" window (under the light blue bar) and choose Paste.
  • Click the red Run Fix button.
  • When complete it will give you a dialog telling you it has finished and will open a log file, click OK to open the log
  • Save the log to your desktop, and post the contents in your next reply.
Now Reboot your computer.


I don't use antivirus (and I haven't for 17 years). I hit the occasional bump in the road, but for the most part it's been fine.


Well it is time to get one now, as that is one of the only means of protection that you are going to have with this operating system. Other than that, in todays internet world, not having one is suicidal for your computer.

Have a look at this page for some 64 bit compatible AntiVirus programs. I would recommend that you use Avast home edition, and run a boot scan once it has been installed.

Post me a fresh OTListIt log when you have completed the scan, and let me know how the machine is performing.
Post Run Fix: ========== PROCESSES ========== No active process named explorer.exe was found! ========== OTLISTIT ========== Service\Driver RelevantKnowledge deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\Program deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:Files deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:(x86 deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\Program deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:Files deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:(x86 deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\Program deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:Files deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:(x86 deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\Program Files (x86 deleted successfully. ========== COMMANDS ========== Explorer started successfully File delete failed. C:\Users\Joe\AppData\Local\Temp\etilqs_q5apSfRpfqD3hgee38Vv scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. File delete failed. C:\Windows\temp\TMP00000034348552045BB93438 scheduled to be deleted on reboot. Windows Temp folder emptied. File delete failed. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. OTListIt2 by OldTimer - Version 2.0.3.4 log created on 03072009_122127 Files moved on Reboot… File C:\Users\Joe\AppData\Local\Temp\etilqs_q5apSfRpfqD3hgee38Vv not found! C:\Users\Joe\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File C:\Windows\temp\TMP00000034348552045BB93438 not found! C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_001_ moved successfully. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_002_ moved successfully. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_003_ moved successfully. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_MAP_ moved successfully. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\urlclassifier3.sqlite moved successfully. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\XUL.mfl moved successfully. Registry entries deleted on Reboot…
Fresh OTList:

OTListIt logfile created on: 3/7/2009 4:50:12 PM - Run 4
OTListIt2 by OldTimer - Version 2.0.3.4 Folder = C:\Users\Joe\Downloads
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.62 Gb Available Physical Memory | 65.49% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 139.73 Gb Total Space | 28.16 Gb Free Space | 20.15% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 232.76 Gb Total Space | 140.11 Gb Free Space | 60.20% Space Free | Partition Type: NTFS
Drive G: | 132.88 Gb Total Space | 34.81 Gb Free Space | 26.19% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive S: | 100.00 Gb Total Space | 83.90 Gb Free Space | 83.90% Space Free | Partition Type: NTFS

Computer Name: JOE-PC
Current User Name: Joe
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2009/02/05 16:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 16:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2005/07/15 16:48:33 | 00,479,232 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
PRC - [2009/02/05 16:08:45 | 00,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2008/11/07 14:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe
PRC - [2008/09/21 22:21:44 | 00,583,168 | —- | M] (Luis Cobian) – C:\Program Files (x86)\Cobian Backup 9\cbService.exe
PRC - [2009/03/01 20:59:47 | 00,070,968 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2009/03/07 08:33:01 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2008/11/20 13:20:48 | 14,294,824 | —- | M] (Apple Inc.) – C:\Program Files (x86)\iTunes\iTunes.exe
PRC - [2008/11/20 13:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files (x86)\iPod\bin\iPodService.exe
PRC - [2008/11/26 00:00:00 | 01,873,280 | —- | M] (Cerulean Studios) – C:\Program Files (x86)\Trillian\trillian.exe
PRC - [2009/03/07 10:58:38 | 00,498,176 | —- | M] (OldTimer Tools) – C:\Users\Joe\Downloads\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/11/07 14:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - File not found – – (aspnet_state [On_Demand | Stopped])
SRV - [2009/02/05 16:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv [Auto | Running])
SRV - [2008/07/03 22:36:39 | 00,901,120 | —- | M] () – C:\Windows\sysnative\Ati2evxx.exe – (Ati External Event Utility [Auto | Running])
SRV - [2009/02/05 16:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus [Auto | Running])
SRV - [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe – (Bonjour Service [Auto | Running])
SRV - [2008/07/27 13:03:13 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/27 13:01:49 | 00,093,184 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
SRV - [2008/09/21 22:21:44 | 00,583,168 | —- | M] (Luis Cobian) – C:\Program Files (x86)\Cobian Backup 9\cbService.exe – (CobianBackupAmanita [Auto | Running])
SRV - [2008/01/19 03:01:11 | 00,598,016 | —- | M] () – C:\Windows\sysnative\cscsvc.dll – (CscService [Auto | Running])
SRV - [2006/10/21 11:38:24 | 00,508,824 | —- | M] ( ) – C:\Windows\system32\DKabcoms.exe – (dkab_device [On_Demand | Stopped])
SRV - [2008/01/19 03:00:14 | 00,344,064 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehRecvr.exe – (ehRecvr [On_Demand | Stopped])
SRV - [2008/01/19 03:00:14 | 00,153,600 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehsched.exe – (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 10:03:44 | 00,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehstart.dll – (ehstart [Auto | Stopped])
SRV - [2008/01/19 03:00:17 | 00,689,152 | —- | M] () – C:\Windows\sysnative\fxssvc.exe – (Fax [On_Demand | Stopped])
SRV - [2008/11/16 18:59:27 | 00,655,624 | —- | M] (Acresso Software Inc.) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service [Disabled | Stopped])
SRV - [2008/11/16 18:59:32 | 01,038,088 | —- | M] (Acresso Software Inc.) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe – (FLEXnet Licensing Service 64 [On_Demand | Stopped])
SRV - [2008/06/19 20:17:12 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/06/19 20:16:53 | 00,859,648 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2008/11/20 13:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files (x86)\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
SRV - [2007/10/19 12:17:04 | 00,255,000 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe – (LVCOMSer [Disabled | Stopped])
SRV - [2007/10/19 12:18:36 | 00,182,296 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcS64 [Disabled | Stopped])
SRV - [2007/10/19 12:20:42 | 00,171,032 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe – (LVSrvLauncher [Disabled | Stopped])
SRV - [2008/06/19 20:16:54 | 00,119,808 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/08/24 02:19:12 | 00,443,776 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 13:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2008/01/19 03:03:34 | 00,079,360 | —- | M] () – C:\Windows\sysnative\pcasvc.dll – (PcaSvc [Auto | Running])
SRV - [2008/01/19 02:33:19 | 00,019,968 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\perfhost.exe – (PerfHost [On_Demand | Stopped])
SRV - [2009/03/01 20:59:47 | 00,070,968 | —- | M] () – C:\Windows\system32\PnkBstrA.exe – (PnkBstrA [Auto | Running])
SRV - [2009/02/03 21:27:31 | 00,316,664 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service [On_Demand | Stopped])
SRV - [2008/01/19 03:04:21 | 00,252,928 | —- | M] () – C:\Windows\sysnative\umrdp.dll – (UmRdpService [On_Demand | Stopped])
SRV - [2008/01/19 03:00:43 | 01,147,904 | —- | M] () – C:\Windows\sysnative\wbengine.exe – (wbengine [On_Demand | Stopped])
SRV - [2008/01/19 03:00:47 | 01,216,000 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2008/06/27 07:51:10 | 00,088,632 | —- | M] () – C:\Windows\sysnative\drivers\adfs.sys – (adfs [Auto | Running])
DRV - [2009/02/05 16:07:17 | 00,022,096 | —- | M] () – C:\Windows\sysnative\DRIVERS\aswFsBlk.sys – (aswFsBlk [Auto | Running])
DRV - [2009/02/05 16:07:07 | 00,064,592 | —- | M] () – C:\Windows\sysnative\DRIVERS\aswMonFlt.sys – (aswMonFlt [Auto | Running])
DRV - [2009/02/05 16:07:36 | 00,089,680 | —- | M] () – C:\Windows\sysnative\drivers\aswSP.sys – (aswSP [System | Running])
DRV - [2008/07/04 01:36:02 | 04,598,272 | —- | M] () – C:\Windows\sysnative\DRIVERS\atikmdag.sys – (atikmdag [On_Demand | Running])
DRV - [2006/10/31 02:25:02 | 00,014,136 | R— | M] (BIOSTAR Group) – C:\Windows\system32\drivers\BIOS64.sys – (BIOS [System | Running])
DRV - [2008/01/19 00:55:40 | 00,460,800 | —- | M] () – C:\Windows\sysnative\drivers\csc.sys – (CSC [System | Running])
DRV - [2008/01/19 03:10:43 | 00,161,848 | —- | M] () – C:\Windows\sysnative\DRIVERS\fvevol.sys – (fvevol [Boot | Running])
DRV - [2008/04/17 12:12:54 | 00,019,304 | —- | M] () – C:\Windows\sysnative\Drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [2006/11/02 00:28:10 | 00,273,920 | —- | M] () – C:\Windows\sysnative\drivers\HdAudio.sys – (HdAudAddService [On_Demand | Running])
DRV - [2008/06/11 12:37:18 | 00,816,640 | —- | M] () – C:\Windows\sysnative\Drivers\L6POD64.sys – (L6POD [On_Demand | Stopped])
DRV - [2007/10/19 12:16:08 | 01,599,896 | —- | M] () – C:\Windows\sysnative\DRIVERS\LVcKap64.sys – (LVcKap64 [On_Demand | Stopped])
DRV - [2007/10/11 17:58:16 | 02,055,192 | —- | M] () – C:\Windows\sysnative\DRIVERS\LVMVDrv.sys – (LVMVDrv [On_Demand | Stopped])
DRV - [2007/10/11 20:58:26 | 01,381,528 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvpopf64.sys – (lvpopf64 [On_Demand | Stopped])
DRV - [2007/10/11 17:58:28 | 00,030,232 | —- | M] () – C:\Windows\sysnative\DRIVERS\LVPr2M64.sys – (LVPr2M64 [On_Demand | Stopped])
DRV - [2007/10/11 20:59:34 | 01,573,528 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvrs64.sys – (LVRS64 [On_Demand | Stopped])
DRV - [2007/10/11 20:59:46 | 00,067,864 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvsels64.sys – (lvsels64 [On_Demand | Stopped])
DRV - [2007/10/11 21:00:20 | 00,050,072 | —- | M] () – C:\Windows\sysnative\drivers\LVUSBS64.sys – (LVUSBS64 [On_Demand | Stopped])
DRV - [2007/10/11 21:00:32 | 03,875,736 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvuvc64.sys – (LVUVC64 [On_Demand | Stopped])
DRV - [2008/02/14 16:56:14 | 00,160,768 | —- | M] () – C:\Windows\sysnative\DRIVERS\Rtlh64.sys – (RTL8169 [On_Demand | Running])
DRV - [2007/08/06 19:21:32 | 00,057,776 | —- | M] () – C:\Windows\sysnative\drivers\scdemu.sys – (SCDEmu [System | Running])
DRV - [2008/09/24 20:44:14 | 00,868,848 | —- | M] () – C:\Windows\sysnative\Drivers\sptd.sys – (sptd [Boot | Running])
DRV - [2008/10/01 12:01:28 | 00,040,448 | —- | M] () – C:\Windows\sysnative\Drivers\usbaapl64.sys – (USBAAPL64 [On_Demand | Stopped])
DRV - [2008/01/19 01:33:58 | 00,098,816 | —- | M] () – C:\Windows\sysnative\drivers\usbaudio.sys – (usbaudio [On_Demand | Stopped])
DRV - [2008/01/19 01:47:12 | 00,046,080 | —- | M] () – C:\Windows\sysnative\DRIVERS\wpdusb.sys – (WpdUsb [On_Demand | Stopped])
DRV - [2008/01/19 01:30:09 | 00,903,168 | —- | M] () – C:\Windows\sysnative\DRIVERS\xnacc.sys – (xnacc [On_Demand | Stopped])
DRV - [2007/08/28 17:04:20 | 00,067,968 | —- | M] () – C:\Windows\sysnative\DRIVERS\xusb21.sys – (xusb21 [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> %SystemRoot%\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/03/07 09:40:06 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS] -> [2009/03/07 08:33:09 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS] -> [2009/03/07 08:33:09 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Extensions [2008/07/24 09:39:17 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008/07/24 09:39:17 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Firefox\Profiles\vvcb3esk.default\extensions [2009/03/07 10:12:04 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Firefox\Profiles\vvcb3esk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2009/02/07 20:13:35 00,000,000 | —D | M]
FF - C:\Program Files (x86)\mozilla firefox\extensions [2009/03/07 10:12:04 00,000,000 | —D | M]
FF - C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/03/07 08:33:09 00,000,000 | —D | M]
FF - C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [2008/08/18 22:28:41 00,000,000 | —D | M]

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe" (Google Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Sites: line6.net ([]* in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: ()\relevantknowledge\rlai.dll) - File not found
O20 - AppInit_DLLs: ()\relevantknowledge\rlai.dll) - File not found
O20 - AppInit_DLLs: ()\relevantknowledge\rlai.dll) - File not found
O20 - AppInit_DLLs: ()\relevantknowledge\rlai.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\system32\explorer.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{fab4f970-6bf1-11dd-90bc-00e04d9293d1}\Shell - "" = AutoRun
O33 - MountPoints2\{fab4f970-6bf1-11dd-90bc-00e04d9293d1}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[2009/03/07 12:30:43 | 02,340,848 | -H– | C] () – C:\Users\Joe\AppData\Local\IconCache.db
[2009/03/07 12:28:16 | 00,001,805 | —- | C] () – C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/03/07 12:28:14 | 00,000,000 | —- | C] () – C:\Windows\System32\config.nt
[2009/03/07 12:28:02 | 01,256,296 | —- | C] (ALWIL Software) – C:\Windows\System32\aswBoot.exe
[2009/03/07 12:28:02 | 00,380,928 | —- | C] () – C:\Windows\System32\actskin4.ocx
[2009/03/07 12:21:27 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/03/07 10:13:34 | 00,001,928 | —- | C] () – C:\Users\Joe\Desktop\HijackThis.lnk
[2009/03/07 10:13:33 | 00,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2009/03/07 10:11:04 | 42,941,64480 | -HS- | C] () – C:\hiberfil.sys
[2009/03/07 09:35:48 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/03/07 09:35:46 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/03/07 09:35:46 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/03/07 09:35:46 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/03/07 09:35:46 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/03/07 09:35:46 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/03/07 09:35:42 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/03/07 09:35:41 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/03/07 09:24:31 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/03/07 09:24:16 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/03/07 09:24:05 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/03/07 09:23:54 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/03/07 09:23:50 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/03/07 09:11:59 | 00,151,696 | —- | C] (Symantec Corporation) – C:\Users\Public\Documents\FxSasser.exe
[2009/03/05 21:07:39 | 00,000,000 | —D | C] – C:\Program Files (x86)\IrfanView
[2009/03/05 21:05:45 | 00,000,568 | —- | C] () – C:\Users\Joe\Desktop\Untitled-1.bmp
[2009/03/04 19:23:18 | 00,000,000 | —D | C] – C:\Users\Joe\Documents\FjChapman Current
[2009/03/03 23:07:32 | 02,021,903 | —- | C] () – C:\Users\Joe\Desktop\fat.mp3
[2009/03/03 21:32:18 | 01,081,852 | —- | C] () – C:\Users\Joe\Desktop\DIAB.psd
[2009/03/03 21:32:10 | 00,088,607 | —- | C] () – C:\Users\Joe\Desktop\DIAB.png
[2009/03/03 21:19:28 | 00,238,029 | —- | C] () – C:\Users\Joe\Desktop\diab.ai
[2009/03/03 14:30:31 | 00,879,378 | —- | C] () – C:\Users\Joe\Desktop\Untitled-5.jpg
[2009/03/03 14:25:26 | 00,113,347 | —- | C] () – C:\Users\Joe\Desktop\trans.png
[2009/03/03 08:35:05 | 00,000,000 | —D | C] – C:\Users\Joe\Desktop\auto
[2009/03/01 20:46:04 | 00,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\id Software
[2009/03/01 20:28:53 | 00,188,896 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2009/03/01 20:28:51 | 02,246,144 | —- | C] () – C:\Windows\System32\pbsvc.exe
[2009/03/01 20:28:51 | 00,070,968 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2009/03/01 20:28:51 | 00,000,000 | —D | C] – C:\ProgramData\id Software
[2009/03/01 12:07:58 | 00,000,000 | —D | C] – C:\$WINDOWS.~BT
[2009/02/15 01:29:14 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/02/15 01:29:14 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/02/15 01:29:13 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/02/15 01:29:13 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/02/15 01:29:13 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/02/12 22:44:55 | 00,471,624 | —- | C] () – C:\Users\Joe\Desktop\funkdrum.wav
[2009/02/11 21:48:18 | 07,686,144 | —- | C] () – C:\Users\Joe\Desktop\stressed.mp3
[2009/02/11 14:10:04 | 06,069,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/02/11 14:10:04 | 03,580,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/02/11 14:10:03 | 01,166,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/02/11 14:10:03 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/02/11 14:10:03 | 00,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/02/11 14:10:02 | 01,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/02/11 14:10:02 | 00,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/02/11 14:10:02 | 00,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/02/11 14:10:02 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/02/10 20:51:48 | 03,107,582 | —- | C] () – C:\Users\Joe\Desktop\pc.mp3
[2009/02/05 18:15:02 | 00,946,776 | —- | C] () – C:\Users\Joe\Desktop\Yagmi.mp3

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[2009/03/07 12:31:49 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/03/07 12:31:39 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/03/07 12:31:35 | 42,941,64480 | -HS- | M] () – C:\hiberfil.sys
[2009/03/07 12:30:43 | 02,340,848 | -H– | M] () – C:\Users\Joe\AppData\Local\IconCache.db
[2009/03/07 12:28:16 | 00,001,805 | —- | M] () – C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/03/07 12:28:14 | 00,000,000 | —- | M] () – C:\Windows\System32\config.nt
[2009/03/07 10:13:34 | 00,001,928 | —- | M] () – C:\Users\Joe\Desktop\HijackThis.lnk
[2009/03/07 09:55:14 | 00,743,720 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/03/07 09:10:20 | 00,151,696 | —- | M] (Symantec Corporation) – C:\Users\Public\Documents\FxSasser.exe
[2009/03/06 17:03:16 | 00,000,465 | —- | M] () – C:\Windows\BRWMARK.INI
[2009/03/05 21:05:49 | 00,000,568 | —- | M] () – C:\Users\Joe\Desktop\Untitled-1.bmp
[2009/03/03 23:07:38 | 02,021,903 | —- | M] () – C:\Users\Joe\Desktop\fat.mp3
[2009/03/03 21:32:18 | 01,081,852 | —- | M] () – C:\Users\Joe\Desktop\DIAB.psd
[2009/03/03 21:32:12 | 00,088,607 | —- | M] () – C:\Users\Joe\Desktop\DIAB.png
[2009/03/03 21:19:32 | 00,238,029 | —- | M] () – C:\Users\Joe\Desktop\diab.ai
[2009/03/03 14:30:32 | 00,879,378 | —- | M] () – C:\Users\Joe\Desktop\Untitled-5.jpg
[2009/03/03 14:25:27 | 00,113,347 | —- | M] () – C:\Users\Joe\Desktop\trans.png
[2009/03/02 11:21:14 | 07,686,144 | —- | M] () – C:\Users\Joe\Desktop\stressed.mp3
[2009/03/01 20:59:47 | 00,070,968 | —- | M] () – C:\Windows\System32\PnkBstrA.exe
[2009/03/01 20:59:37 | 00,188,896 | —- | M] () – C:\Windows\System32\PnkBstrB.exe
[2009/03/01 20:32:15 | 02,246,144 | —- | M] () – C:\Windows\System32\pbsvc.exe
[2009/03/01 12:08:16 | 00,001,905 | —- | M] () – C:\Windows\diagwrn.xml
[2009/03/01 12:08:16 | 00,001,905 | —- | M] () – C:\Windows\diagerr.xml
[2009/02/17 14:58:18 | 00,044,032 | —- | M] () – C:\Users\Joe\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/12 22:45:28 | 00,471,624 | —- | M] () – C:\Users\Joe\Desktop\funkdrum.wav
[2009/02/10 20:52:13 | 03,107,582 | —- | M] () – C:\Users\Joe\Desktop\pc.mp3
[2009/02/08 14:09:04 | 00,946,776 | —- | M] () – C:\Users\Joe\Desktop\Yagmi.mp3
< End of report >



Everything seems to be running fine now. Any thing else I should be weary of? Thanks so much for the help!
I am glad to see you got the AV. Please keep it, you never know when it will save all your info. :thumbup:

It looks better, but there are still some bad entries left over in your registry.
  • Double click OTListIt2.exe to run the program
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :otli
    O20 - AppInit_DLLs: ()\relevantknowledge\rlai.dll) - File not found
    O20 - AppInit_DLLs: ()\relevantknowledge\rlai.dll) - File not found
    O20 - AppInit_DLLs: ()\relevantknowledge\rlai.dll) - File not found
    O20 - AppInit_DLLs: ()\relevantknowledge\rlai.dll) - File not found
    
    :commands
    [emptytemp]
    [purity]
  • Return to OTListIt2, right click in the "Custom Scans/Fixes" window (under the light blue bar) and choose Paste.
  • Click the red Run Fix button.
  • When complete it will give you a dialog telling you it has finished and will open a log file, click OK to open the log
  • Save the log to your desktop, and post the contents in your next reply.
Now Reboot your computer, and run an OTListIt scan again. Post me the scan results.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Please run an online scan with Kaspersky WebScanner.
Note: You must disable your Anti Virus program during the scan. If you are unsure of how to disable these programs, please refer to this page for details.
  • Click the Accept button to agree to the disclaimer.

    You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded and updated click on My Computer in the Scan settings
    • This will start the scan of your system.
    • The scan will take a while so be patient and let it run until it is complete.
    • Now click on the View scan report link:
  • Click the Save report as button
  • Under Save as type, choose Text file (*.txt)
  • Save the file to your desktop as Kaspersky.txt
  • Copy and paste that information in your next post.
========== OTLISTIT ========== Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls not found. ========== COMMANDS ========== File delete failed. C:\Users\Joe\AppData\Local\Temp\etilqs_c3djkz6fXKPjbLZWaeaQ scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Temp\etilqs_c3djkz6fXKPjbLZWaeaQ-journal scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Temp\etilqs_pBu5aKJufM2hUWiytrTl scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. File delete failed. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\C0D8ABD3d01 scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. OTListIt2 by OldTimer - Version 2.0.3.4 log created on 03072009_183846 Files moved on Reboot… File C:\Users\Joe\AppData\Local\Temp\etilqs_c3djkz6fXKPjbLZWaeaQ not found! File C:\Users\Joe\AppData\Local\Temp\etilqs_c3djkz6fXKPjbLZWaeaQ-journal not found! File C:\Users\Joe\AppData\Local\Temp\etilqs_pBu5aKJufM2hUWiytrTl not found! C:\Users\Joe\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\C0D8ABD3d01 moved successfully. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_001_ moved successfully. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_002_ moved successfully. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_003_ moved successfully. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\Cache\_CACHE_MAP_ moved successfully. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\urlclassifier3.sqlite moved successfully. C:\Users\Joe\AppData\Local\Mozilla\Firefox\Profiles\vvcb3esk.default\XUL.mfl moved successfully. Registry entries deleted on Reboot…
OTListIt logfile created on: 3/7/2009 6:44:53 PM - Run 7
OTListIt2 by OldTimer - Version 2.0.3.4 Folder = C:\Users\Joe\Downloads
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.82 Gb Available Physical Memory | 70.55% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 139.73 Gb Total Space | 27.99 Gb Free Space | 20.03% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 232.76 Gb Total Space | 140.11 Gb Free Space | 60.20% Space Free | Partition Type: NTFS
Drive G: | 132.88 Gb Total Space | 34.81 Gb Free Space | 26.19% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive S: | 100.00 Gb Total Space | 83.90 Gb Free Space | 83.90% Space Free | Partition Type: NTFS

Computer Name: JOE-PC
Current User Name: Joe
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2009/02/05 16:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 16:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2005/07/15 16:48:33 | 00,479,232 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
PRC - [2009/02/05 16:08:45 | 00,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2008/11/07 14:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe
PRC - [2008/09/21 22:21:44 | 00,583,168 | —- | M] (Luis Cobian) – C:\Program Files (x86)\Cobian Backup 9\cbService.exe
PRC - [2009/03/01 20:59:47 | 00,070,968 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2009/03/07 08:33:01 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2008/11/20 13:20:48 | 14,294,824 | —- | M] (Apple Inc.) – C:\Program Files (x86)\iTunes\iTunes.exe
PRC - [2008/11/20 13:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files (x86)\iPod\bin\iPodService.exe
PRC - [2009/03/07 10:58:38 | 00,498,176 | —- | M] (OldTimer Tools) – C:\Users\Joe\Downloads\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/11/07 14:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - File not found – – (aspnet_state [On_Demand | Stopped])
SRV - [2009/02/05 16:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv [Auto | Running])
SRV - [2008/07/03 22:36:39 | 00,901,120 | —- | M] () – C:\Windows\sysnative\Ati2evxx.exe – (Ati External Event Utility [Auto | Running])
SRV - [2009/02/05 16:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus [Auto | Running])
SRV - [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe – (Bonjour Service [Auto | Running])
SRV - [2008/07/27 13:03:13 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/27 13:01:49 | 00,093,184 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
SRV - [2008/09/21 22:21:44 | 00,583,168 | —- | M] (Luis Cobian) – C:\Program Files (x86)\Cobian Backup 9\cbService.exe – (CobianBackupAmanita [Auto | Running])
SRV - [2008/01/19 03:01:11 | 00,598,016 | —- | M] () – C:\Windows\sysnative\cscsvc.dll – (CscService [Auto | Running])
SRV - [2006/10/21 11:38:24 | 00,508,824 | —- | M] ( ) – C:\Windows\system32\DKabcoms.exe – (dkab_device [On_Demand | Stopped])
SRV - [2008/01/19 03:00:14 | 00,344,064 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehRecvr.exe – (ehRecvr [On_Demand | Stopped])
SRV - [2008/01/19 03:00:14 | 00,153,600 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehsched.exe – (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 10:03:44 | 00,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehstart.dll – (ehstart [Auto | Stopped])
SRV - [2008/01/19 03:00:17 | 00,689,152 | —- | M] () – C:\Windows\sysnative\fxssvc.exe – (Fax [On_Demand | Stopped])
SRV - [2008/11/16 18:59:27 | 00,655,624 | —- | M] (Acresso Software Inc.) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service [Disabled | Stopped])
SRV - [2008/11/16 18:59:32 | 01,038,088 | —- | M] (Acresso Software Inc.) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe – (FLEXnet Licensing Service 64 [On_Demand | Stopped])
SRV - [2008/06/19 20:17:12 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/06/19 20:16:53 | 00,859,648 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2008/11/20 13:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files (x86)\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
SRV - [2007/10/19 12:17:04 | 00,255,000 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe – (LVCOMSer [Disabled | Stopped])
SRV - [2007/10/19 12:18:36 | 00,182,296 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcS64 [Disabled | Stopped])
SRV - [2007/10/19 12:20:42 | 00,171,032 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe – (LVSrvLauncher [Disabled | Stopped])
SRV - [2008/06/19 20:16:54 | 00,119,808 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/08/24 02:19:12 | 00,443,776 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 13:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2008/01/19 03:03:34 | 00,079,360 | —- | M] () – C:\Windows\sysnative\pcasvc.dll – (PcaSvc [Auto | Running])
SRV - [2008/01/19 02:33:19 | 00,019,968 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\perfhost.exe – (PerfHost [On_Demand | Stopped])
SRV - [2009/03/01 20:59:47 | 00,070,968 | —- | M] () – C:\Windows\system32\PnkBstrA.exe – (PnkBstrA [Auto | Running])
SRV - [2009/02/03 21:27:31 | 00,316,664 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service [On_Demand | Stopped])
SRV - [2008/01/19 03:04:21 | 00,252,928 | —- | M] () – C:\Windows\sysnative\umrdp.dll – (UmRdpService [On_Demand | Stopped])
SRV - [2008/01/19 03:00:43 | 01,147,904 | —- | M] () – C:\Windows\sysnative\wbengine.exe – (wbengine [On_Demand | Stopped])
SRV - [2008/01/19 03:00:47 | 01,216,000 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2008/06/27 07:51:10 | 00,088,632 | —- | M] () – C:\Windows\sysnative\drivers\adfs.sys – (adfs [Auto | Running])
DRV - [2009/02/05 16:07:17 | 00,022,096 | —- | M] () – C:\Windows\sysnative\DRIVERS\aswFsBlk.sys – (aswFsBlk [Auto | Running])
DRV - [2009/02/05 16:07:07 | 00,064,592 | —- | M] () – C:\Windows\sysnative\DRIVERS\aswMonFlt.sys – (aswMonFlt [Auto | Running])
DRV - [2009/02/05 16:07:36 | 00,089,680 | —- | M] () – C:\Windows\sysnative\drivers\aswSP.sys – (aswSP [System | Running])
DRV - [2008/07/04 01:36:02 | 04,598,272 | —- | M] () – C:\Windows\sysnative\DRIVERS\atikmdag.sys – (atikmdag [On_Demand | Running])
DRV - [2006/10/31 02:25:02 | 00,014,136 | R— | M] (BIOSTAR Group) – C:\Windows\system32\drivers\BIOS64.sys – (BIOS [System | Running])
DRV - [2008/01/19 00:55:40 | 00,460,800 | —- | M] () – C:\Windows\sysnative\drivers\csc.sys – (CSC [System | Running])
DRV - [2008/01/19 03:10:43 | 00,161,848 | —- | M] () – C:\Windows\sysnative\DRIVERS\fvevol.sys – (fvevol [Boot | Running])
DRV - [2008/04/17 12:12:54 | 00,019,304 | —- | M] () – C:\Windows\sysnative\Drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [2006/11/02 00:28:10 | 00,273,920 | —- | M] () – C:\Windows\sysnative\drivers\HdAudio.sys – (HdAudAddService [On_Demand | Running])
DRV - [2008/06/11 12:37:18 | 00,816,640 | —- | M] () – C:\Windows\sysnative\Drivers\L6POD64.sys – (L6POD [On_Demand | Stopped])
DRV - [2007/10/19 12:16:08 | 01,599,896 | —- | M] () – C:\Windows\sysnative\DRIVERS\LVcKap64.sys – (LVcKap64 [On_Demand | Stopped])
DRV - [2007/10/11 17:58:16 | 02,055,192 | —- | M] () – C:\Windows\sysnative\DRIVERS\LVMVDrv.sys – (LVMVDrv [On_Demand | Stopped])
DRV - [2007/10/11 20:58:26 | 01,381,528 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvpopf64.sys – (lvpopf64 [On_Demand | Stopped])
DRV - [2007/10/11 17:58:28 | 00,030,232 | —- | M] () – C:\Windows\sysnative\DRIVERS\LVPr2M64.sys – (LVPr2M64 [On_Demand | Stopped])
DRV - [2007/10/11 20:59:34 | 01,573,528 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvrs64.sys – (LVRS64 [On_Demand | Stopped])
DRV - [2007/10/11 20:59:46 | 00,067,864 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvsels64.sys – (lvsels64 [On_Demand | Stopped])
DRV - [2007/10/11 21:00:20 | 00,050,072 | —- | M] () – C:\Windows\sysnative\drivers\LVUSBS64.sys – (LVUSBS64 [On_Demand | Stopped])
DRV - [2007/10/11 21:00:32 | 03,875,736 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvuvc64.sys – (LVUVC64 [On_Demand | Stopped])
DRV - [2008/02/14 16:56:14 | 00,160,768 | —- | M] () – C:\Windows\sysnative\DRIVERS\Rtlh64.sys – (RTL8169 [On_Demand | Running])
DRV - [2007/08/06 19:21:32 | 00,057,776 | —- | M] () – C:\Windows\sysnative\drivers\scdemu.sys – (SCDEmu [System | Running])
DRV - [2008/09/24 20:44:14 | 00,868,848 | —- | M] () – C:\Windows\sysnative\Drivers\sptd.sys – (sptd [Boot | Running])
DRV - [2008/10/01 12:01:28 | 00,040,448 | —- | M] () – C:\Windows\sysnative\Drivers\usbaapl64.sys – (USBAAPL64 [On_Demand | Stopped])
DRV - [2008/01/19 01:33:58 | 00,098,816 | —- | M] () – C:\Windows\sysnative\drivers\usbaudio.sys – (usbaudio [On_Demand | Stopped])
DRV - [2008/01/19 01:47:12 | 00,046,080 | —- | M] () – C:\Windows\sysnative\DRIVERS\wpdusb.sys – (WpdUsb [On_Demand | Stopped])
DRV - [2008/01/19 01:30:09 | 00,903,168 | —- | M] () – C:\Windows\sysnative\DRIVERS\xnacc.sys – (xnacc [On_Demand | Stopped])
DRV - [2007/08/28 17:04:20 | 00,067,968 | —- | M] () – C:\Windows\sysnative\DRIVERS\xusb21.sys – (xusb21 [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> %SystemRoot%\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/03/07 09:40:06 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS] -> [2009/03/07 08:33:09 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS] -> [2009/03/07 08:33:09 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Extensions [2008/07/24 09:39:17 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008/07/24 09:39:17 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Firefox\Profiles\vvcb3esk.default\extensions [2009/03/07 10:12:04 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Firefox\Profiles\vvcb3esk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2009/02/07 20:13:35 00,000,000 | —D | M]
FF - C:\Program Files (x86)\mozilla firefox\extensions [2009/03/07 10:12:04 00,000,000 | —D | M]
FF - C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/03/07 08:33:09 00,000,000 | —D | M]
FF - C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [2008/08/18 22:28:41 00,000,000 | —D | M]

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe" (Google Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Sites: line6.net ([]* in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\system32\explorer.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{fab4f970-6bf1-11dd-90bc-00e04d9293d1}\Shell - "" = AutoRun
O33 - MountPoints2\{fab4f970-6bf1-11dd-90bc-00e04d9293d1}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[2009/03/07 12:30:43 | 02,378,942 | -H– | C] () – C:\Users\Joe\AppData\Local\IconCache.db
[2009/03/07 12:28:16 | 00,001,805 | —- | C] () – C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/03/07 12:28:14 | 00,000,000 | —- | C] () – C:\Windows\System32\config.nt
[2009/03/07 12:28:02 | 01,256,296 | —- | C] (ALWIL Software) – C:\Windows\System32\aswBoot.exe
[2009/03/07 12:28:02 | 00,380,928 | —- | C] () – C:\Windows\System32\actskin4.ocx
[2009/03/07 12:21:27 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/03/07 10:13:34 | 00,001,928 | —- | C] () – C:\Users\Joe\Desktop\HijackThis.lnk
[2009/03/07 10:13:33 | 00,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2009/03/07 10:11:04 | 42,941,64480 | -HS- | C] () – C:\hiberfil.sys
[2009/03/07 09:35:48 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/03/07 09:35:46 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/03/07 09:35:46 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/03/07 09:35:46 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/03/07 09:35:46 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/03/07 09:35:46 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/03/07 09:35:42 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/03/07 09:35:41 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/03/07 09:24:31 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/03/07 09:24:16 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/03/07 09:24:05 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/03/07 09:23:54 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/03/07 09:23:50 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/03/07 09:11:59 | 00,151,696 | —- | C] (Symantec Corporation) – C:\Users\Public\Documents\FxSasser.exe
[2009/03/05 21:07:39 | 00,000,000 | —D | C] – C:\Program Files (x86)\IrfanView
[2009/03/05 21:05:45 | 00,000,568 | —- | C] () – C:\Users\Joe\Desktop\Untitled-1.bmp
[2009/03/04 19:23:18 | 00,000,000 | —D | C] – C:\Users\Joe\Documents\FjChapman Current
[2009/03/03 23:07:32 | 02,021,903 | —- | C] () – C:\Users\Joe\Desktop\fat.mp3
[2009/03/03 21:32:18 | 01,081,852 | —- | C] () – C:\Users\Joe\Desktop\DIAB.psd
[2009/03/03 21:32:10 | 00,088,607 | —- | C] () – C:\Users\Joe\Desktop\DIAB.png
[2009/03/03 21:19:28 | 00,238,029 | —- | C] () – C:\Users\Joe\Desktop\diab.ai
[2009/03/03 14:30:31 | 00,879,378 | —- | C] () – C:\Users\Joe\Desktop\Untitled-5.jpg
[2009/03/03 14:25:26 | 00,113,347 | —- | C] () – C:\Users\Joe\Desktop\trans.png
[2009/03/03 08:35:05 | 00,000,000 | —D | C] – C:\Users\Joe\Desktop\auto
[2009/03/01 20:46:04 | 00,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\id Software
[2009/03/01 20:28:53 | 00,188,896 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2009/03/01 20:28:51 | 02,246,144 | —- | C] () – C:\Windows\System32\pbsvc.exe
[2009/03/01 20:28:51 | 00,070,968 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2009/03/01 20:28:51 | 00,000,000 | —D | C] – C:\ProgramData\id Software
[2009/03/01 12:07:58 | 00,000,000 | —D | C] – C:\$WINDOWS.~BT
[2009/02/15 01:29:14 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/02/15 01:29:14 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/02/15 01:29:13 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/02/15 01:29:13 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/02/15 01:29:13 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/02/12 22:44:55 | 00,471,624 | —- | C] () – C:\Users\Joe\Desktop\funkdrum.wav
[2009/02/11 21:48:18 | 07,686,144 | —- | C] () – C:\Users\Joe\Desktop\stressed.mp3
[2009/02/11 14:10:04 | 06,069,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/02/11 14:10:04 | 03,580,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/02/11 14:10:03 | 01,166,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/02/11 14:10:03 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/02/11 14:10:03 | 00,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/02/11 14:10:02 | 01,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/02/11 14:10:02 | 00,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/02/11 14:10:02 | 00,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/02/11 14:10:02 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/02/10 20:51:48 | 03,107,582 | —- | C] () – C:\Users\Joe\Desktop\pc.mp3

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[2009/03/07 18:40:41 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/03/07 18:40:34 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/03/07 18:40:29 | 42,941,64480 | -HS- | M] () – C:\hiberfil.sys
[2009/03/07 18:39:37 | 02,378,942 | -H– | M] () – C:\Users\Joe\AppData\Local\IconCache.db
[2009/03/07 12:28:16 | 00,001,805 | —- | M] () – C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/03/07 12:28:14 | 00,000,000 | —- | M] () – C:\Windows\System32\config.nt
[2009/03/07 10:13:34 | 00,001,928 | —- | M] () – C:\Users\Joe\Desktop\HijackThis.lnk
[2009/03/07 09:55:14 | 00,743,720 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/03/07 09:10:20 | 00,151,696 | —- | M] (Symantec Corporation) – C:\Users\Public\Documents\FxSasser.exe
[2009/03/06 17:03:16 | 00,000,465 | —- | M] () – C:\Windows\BRWMARK.INI
[2009/03/05 21:05:49 | 00,000,568 | —- | M] () – C:\Users\Joe\Desktop\Untitled-1.bmp
[2009/03/03 23:07:38 | 02,021,903 | —- | M] () – C:\Users\Joe\Desktop\fat.mp3
[2009/03/03 21:32:18 | 01,081,852 | —- | M] () – C:\Users\Joe\Desktop\DIAB.psd
[2009/03/03 21:32:12 | 00,088,607 | —- | M] () – C:\Users\Joe\Desktop\DIAB.png
[2009/03/03 21:19:32 | 00,238,029 | —- | M] () – C:\Users\Joe\Desktop\diab.ai
[2009/03/03 14:30:32 | 00,879,378 | —- | M] () – C:\Users\Joe\Desktop\Untitled-5.jpg
[2009/03/03 14:25:27 | 00,113,347 | —- | M] () – C:\Users\Joe\Desktop\trans.png
[2009/03/02 11:21:14 | 07,686,144 | —- | M] () – C:\Users\Joe\Desktop\stressed.mp3
[2009/03/01 20:59:47 | 00,070,968 | —- | M] () – C:\Windows\System32\PnkBstrA.exe
[2009/03/01 20:59:37 | 00,188,896 | —- | M] () – C:\Windows\System32\PnkBstrB.exe
[2009/03/01 20:32:15 | 02,246,144 | —- | M] () – C:\Windows\System32\pbsvc.exe
[2009/03/01 12:08:16 | 00,001,905 | —- | M] () – C:\Windows\diagwrn.xml
[2009/03/01 12:08:16 | 00,001,905 | —- | M] () – C:\Windows\diagerr.xml
[2009/02/17 14:58:18 | 00,044,032 | —- | M] () – C:\Users\Joe\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/12 22:45:28 | 00,471,624 | —- | M] () – C:\Users\Joe\Desktop\funkdrum.wav
[2009/02/10 20:52:13 | 03,107,582 | —- | M] () – C:\Users\Joe\Desktop\pc.mp3
[2009/02/08 14:09:04 | 00,946,776 | —- | M] () – C:\Users\Joe\Desktop\Yagmi.mp3
< End of report >
Good. Those O20 - AppInit_DLLs: ()\relevantknowledge\rlai.dll) - File not found entries are lo longer there. :)

Let's see the results of the Kaspersky scan, and see if it turns anything up.
I did the Kaspersky scan and it found nothing. A good sign! (Avast was disabled) Anything else I need to do? Thanks again for all this help.
No, it looks like you are good to go! :thumbup:

Now, we can uninstall OTListIt:
  • Doublle click OTListIt2.exe to start the program
  • Click the CleanUp button at the top right
  • When it prompts, agree to the reboot

Next delete any logs that you have left over on your desktop.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

What to do next, along with some useful tips on staying clean,and links to some freeware to help, have a look at this page (make sure that anything you download is 64 bit compatible).

I will keep this log open for the next couple of days, so if you have any further problems post another reply here.

OK, all the best, and stay safe!

Best regards,
RatHat
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI