Fresh OTList:
OTListIt logfile created on: 3/7/2009 4:50:12 PM - Run 4
OTListIt2 by OldTimer - Version 2.0.3.4 Folder = C:\Users\Joe\Downloads
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 2.62 Gb Available Physical Memory | 65.49% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 139.73 Gb Total Space | 28.16 Gb Free Space | 20.15% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 232.76 Gb Total Space | 140.11 Gb Free Space | 60.20% Space Free | Partition Type: NTFS
Drive G: | 132.88 Gb Total Space | 34.81 Gb Free Space | 26.19% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive S: | 100.00 Gb Total Space | 83.90 Gb Free Space | 83.90% Space Free | Partition Type: NTFS
Computer Name: JOE-PC
Current User Name: Joe
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2009/02/05 16:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 16:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2005/07/15 16:48:33 | 00,479,232 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
PRC - [2009/02/05 16:08:45 | 00,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2008/11/07 14:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe
PRC - [2008/09/21 22:21:44 | 00,583,168 | —- | M] (Luis Cobian) – C:\Program Files (x86)\Cobian Backup 9\cbService.exe
PRC - [2009/03/01 20:59:47 | 00,070,968 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2009/03/07 08:33:01 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2008/11/20 13:20:48 | 14,294,824 | —- | M] (Apple Inc.) – C:\Program Files (x86)\iTunes\iTunes.exe
PRC - [2008/11/20 13:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files (x86)\iPod\bin\iPodService.exe
PRC - [2008/11/26 00:00:00 | 01,873,280 | —- | M] (Cerulean Studios) – C:\Program Files (x86)\Trillian\trillian.exe
PRC - [2009/03/07 10:58:38 | 00,498,176 | —- | M] (OldTimer Tools) – C:\Users\Joe\Downloads\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2008/11/07 14:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - File not found – – (aspnet_state [On_Demand | Stopped])
SRV - [2009/02/05 16:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv [Auto | Running])
SRV - [2008/07/03 22:36:39 | 00,901,120 | —- | M] () – C:\Windows\sysnative\Ati2evxx.exe – (Ati External Event Utility [Auto | Running])
SRV - [2009/02/05 16:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus [Auto | Running])
SRV - [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe – (Bonjour Service [Auto | Running])
SRV - [2008/07/27 13:03:13 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/27 13:01:49 | 00,093,184 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
SRV - [2008/09/21 22:21:44 | 00,583,168 | —- | M] (Luis Cobian) – C:\Program Files (x86)\Cobian Backup 9\cbService.exe – (CobianBackupAmanita [Auto | Running])
SRV - [2008/01/19 03:01:11 | 00,598,016 | —- | M] () – C:\Windows\sysnative\cscsvc.dll – (CscService [Auto | Running])
SRV - [2006/10/21 11:38:24 | 00,508,824 | —- | M] ( ) – C:\Windows\system32\DKabcoms.exe – (dkab_device [On_Demand | Stopped])
SRV - [2008/01/19 03:00:14 | 00,344,064 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehRecvr.exe – (ehRecvr [On_Demand | Stopped])
SRV - [2008/01/19 03:00:14 | 00,153,600 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehsched.exe – (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 10:03:44 | 00,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehstart.dll – (ehstart [Auto | Stopped])
SRV - [2008/01/19 03:00:17 | 00,689,152 | —- | M] () – C:\Windows\sysnative\fxssvc.exe – (Fax [On_Demand | Stopped])
SRV - [2008/11/16 18:59:27 | 00,655,624 | —- | M] (Acresso Software Inc.) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service [Disabled | Stopped])
SRV - [2008/11/16 18:59:32 | 01,038,088 | —- | M] (Acresso Software Inc.) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe – (FLEXnet Licensing Service 64 [On_Demand | Stopped])
SRV - [2008/06/19 20:17:12 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/06/19 20:16:53 | 00,859,648 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2008/11/20 13:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files (x86)\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
SRV - [2007/10/19 12:17:04 | 00,255,000 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe – (LVCOMSer [Disabled | Stopped])
SRV - [2007/10/19 12:18:36 | 00,182,296 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcS64 [Disabled | Stopped])
SRV - [2007/10/19 12:20:42 | 00,171,032 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe – (LVSrvLauncher [Disabled | Stopped])
SRV - [2008/06/19 20:16:54 | 00,119,808 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/08/24 02:19:12 | 00,443,776 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 13:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2008/01/19 03:03:34 | 00,079,360 | —- | M] () – C:\Windows\sysnative\pcasvc.dll – (PcaSvc [Auto | Running])
SRV - [2008/01/19 02:33:19 | 00,019,968 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\perfhost.exe – (PerfHost [On_Demand | Stopped])
SRV - [2009/03/01 20:59:47 | 00,070,968 | —- | M] () – C:\Windows\system32\PnkBstrA.exe – (PnkBstrA [Auto | Running])
SRV - [2009/02/03 21:27:31 | 00,316,664 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service [On_Demand | Stopped])
SRV - [2008/01/19 03:04:21 | 00,252,928 | —- | M] () – C:\Windows\sysnative\umrdp.dll – (UmRdpService [On_Demand | Stopped])
SRV - [2008/01/19 03:00:43 | 01,147,904 | —- | M] () – C:\Windows\sysnative\wbengine.exe – (wbengine [On_Demand | Stopped])
SRV - [2008/01/19 03:00:47 | 01,216,000 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2008/06/27 07:51:10 | 00,088,632 | —- | M] () – C:\Windows\sysnative\drivers\adfs.sys – (adfs [Auto | Running])
DRV - [2009/02/05 16:07:17 | 00,022,096 | —- | M] () – C:\Windows\sysnative\DRIVERS\aswFsBlk.sys – (aswFsBlk [Auto | Running])
DRV - [2009/02/05 16:07:07 | 00,064,592 | —- | M] () – C:\Windows\sysnative\DRIVERS\aswMonFlt.sys – (aswMonFlt [Auto | Running])
DRV - [2009/02/05 16:07:36 | 00,089,680 | —- | M] () – C:\Windows\sysnative\drivers\aswSP.sys – (aswSP [System | Running])
DRV - [2008/07/04 01:36:02 | 04,598,272 | —- | M] () – C:\Windows\sysnative\DRIVERS\atikmdag.sys – (atikmdag [On_Demand | Running])
DRV - [2006/10/31 02:25:02 | 00,014,136 | R— | M] (BIOSTAR Group) – C:\Windows\system32\drivers\BIOS64.sys – (BIOS [System | Running])
DRV - [2008/01/19 00:55:40 | 00,460,800 | —- | M] () – C:\Windows\sysnative\drivers\csc.sys – (CSC [System | Running])
DRV - [2008/01/19 03:10:43 | 00,161,848 | —- | M] () – C:\Windows\sysnative\DRIVERS\fvevol.sys – (fvevol [Boot | Running])
DRV - [2008/04/17 12:12:54 | 00,019,304 | —- | M] () – C:\Windows\sysnative\Drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [2006/11/02 00:28:10 | 00,273,920 | —- | M] () – C:\Windows\sysnative\drivers\HdAudio.sys – (HdAudAddService [On_Demand | Running])
DRV - [2008/06/11 12:37:18 | 00,816,640 | —- | M] () – C:\Windows\sysnative\Drivers\L6POD64.sys – (L6POD [On_Demand | Stopped])
DRV - [2007/10/19 12:16:08 | 01,599,896 | —- | M] () – C:\Windows\sysnative\DRIVERS\LVcKap64.sys – (LVcKap64 [On_Demand | Stopped])
DRV - [2007/10/11 17:58:16 | 02,055,192 | —- | M] () – C:\Windows\sysnative\DRIVERS\LVMVDrv.sys – (LVMVDrv [On_Demand | Stopped])
DRV - [2007/10/11 20:58:26 | 01,381,528 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvpopf64.sys – (lvpopf64 [On_Demand | Stopped])
DRV - [2007/10/11 17:58:28 | 00,030,232 | —- | M] () – C:\Windows\sysnative\DRIVERS\LVPr2M64.sys – (LVPr2M64 [On_Demand | Stopped])
DRV - [2007/10/11 20:59:34 | 01,573,528 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvrs64.sys – (LVRS64 [On_Demand | Stopped])
DRV - [2007/10/11 20:59:46 | 00,067,864 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvsels64.sys – (lvsels64 [On_Demand | Stopped])
DRV - [2007/10/11 21:00:20 | 00,050,072 | —- | M] () – C:\Windows\sysnative\drivers\LVUSBS64.sys – (LVUSBS64 [On_Demand | Stopped])
DRV - [2007/10/11 21:00:32 | 03,875,736 | —- | M] () – C:\Windows\sysnative\DRIVERS\lvuvc64.sys – (LVUVC64 [On_Demand | Stopped])
DRV - [2008/02/14 16:56:14 | 00,160,768 | —- | M] () – C:\Windows\sysnative\DRIVERS\Rtlh64.sys – (RTL8169 [On_Demand | Running])
DRV - [2007/08/06 19:21:32 | 00,057,776 | —- | M] () – C:\Windows\sysnative\drivers\scdemu.sys – (SCDEmu [System | Running])
DRV - [2008/09/24 20:44:14 | 00,868,848 | —- | M] () – C:\Windows\sysnative\Drivers\sptd.sys – (sptd [Boot | Running])
DRV - [2008/10/01 12:01:28 | 00,040,448 | —- | M] () – C:\Windows\sysnative\Drivers\usbaapl64.sys – (USBAAPL64 [On_Demand | Stopped])
DRV - [2008/01/19 01:33:58 | 00,098,816 | —- | M] () – C:\Windows\sysnative\drivers\usbaudio.sys – (usbaudio [On_Demand | Stopped])
DRV - [2008/01/19 01:47:12 | 00,046,080 | —- | M] () – C:\Windows\sysnative\DRIVERS\wpdusb.sys – (WpdUsb [On_Demand | Stopped])
DRV - [2008/01/19 01:30:09 | 00,903,168 | —- | M] () – C:\Windows\sysnative\DRIVERS\xnacc.sys – (xnacc [On_Demand | Stopped])
DRV - [2007/08/28 17:04:20 | 00,067,968 | —- | M] () – C:\Windows\sysnative\DRIVERS\xusb21.sys – (xusb21 [On_Demand | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> %SystemRoot%\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/03/07 09:40:06 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS] -> [2009/03/07 08:33:09 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS] -> [2009/03/07 08:33:09 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Extensions [2008/07/24 09:39:17 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008/07/24 09:39:17 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Firefox\Profiles\vvcb3esk.default\extensions [2009/03/07 10:12:04 00,000,000 | —D | M]
FF - C:\Users\Joe\AppData\Roaming\mozilla\Firefox\Profiles\vvcb3esk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2009/02/07 20:13:35 00,000,000 | —D | M]
FF - C:\Program Files (x86)\mozilla firefox\extensions [2009/03/07 10:12:04 00,000,000 | —D | M]
FF - C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/03/07 08:33:09 00,000,000 | —D | M]
FF - C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [2008/08/18 22:28:41 00,000,000 | —D | M]
O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe" (Google Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Sites: line6.net ([]* in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: ()\relevantknowledge\rlai.dll) - File not found
O20 - AppInit_DLLs: ()\relevantknowledge\rlai.dll) - File not found
O20 - AppInit_DLLs: ()\relevantknowledge\rlai.dll) - File not found
O20 - AppInit_DLLs: ()\relevantknowledge\rlai.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\system32\explorer.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{fab4f970-6bf1-11dd-90bc-00e04d9293d1}\Shell - "" = AutoRun
O33 - MountPoints2\{fab4f970-6bf1-11dd-90bc-00e04d9293d1}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\*.tmp files]
[2009/03/07 12:30:43 | 02,340,848 | -H– | C] () – C:\Users\Joe\AppData\Local\IconCache.db
[2009/03/07 12:28:16 | 00,001,805 | —- | C] () – C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/03/07 12:28:14 | 00,000,000 | —- | C] () – C:\Windows\System32\config.nt
[2009/03/07 12:28:02 | 01,256,296 | —- | C] (ALWIL Software) – C:\Windows\System32\aswBoot.exe
[2009/03/07 12:28:02 | 00,380,928 | —- | C] () – C:\Windows\System32\actskin4.ocx
[2009/03/07 12:21:27 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/03/07 10:13:34 | 00,001,928 | —- | C] () – C:\Users\Joe\Desktop\HijackThis.lnk
[2009/03/07 10:13:33 | 00,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2009/03/07 10:11:04 | 42,941,64480 | -HS- | C] () – C:\hiberfil.sys
[2009/03/07 09:35:48 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/03/07 09:35:46 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/03/07 09:35:46 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/03/07 09:35:46 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/03/07 09:35:46 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/03/07 09:35:46 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/03/07 09:35:42 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/03/07 09:35:41 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/03/07 09:24:31 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/03/07 09:24:16 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/03/07 09:24:05 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/03/07 09:23:54 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/03/07 09:23:50 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/03/07 09:11:59 | 00,151,696 | —- | C] (Symantec Corporation) – C:\Users\Public\Documents\FxSasser.exe
[2009/03/05 21:07:39 | 00,000,000 | —D | C] – C:\Program Files (x86)\IrfanView
[2009/03/05 21:05:45 | 00,000,568 | —- | C] () – C:\Users\Joe\Desktop\Untitled-1.bmp
[2009/03/04 19:23:18 | 00,000,000 | —D | C] – C:\Users\Joe\Documents\FjChapman Current
[2009/03/03 23:07:32 | 02,021,903 | —- | C] () – C:\Users\Joe\Desktop\fat.mp3
[2009/03/03 21:32:18 | 01,081,852 | —- | C] () – C:\Users\Joe\Desktop\DIAB.psd
[2009/03/03 21:32:10 | 00,088,607 | —- | C] () – C:\Users\Joe\Desktop\DIAB.png
[2009/03/03 21:19:28 | 00,238,029 | —- | C] () – C:\Users\Joe\Desktop\diab.ai
[2009/03/03 14:30:31 | 00,879,378 | —- | C] () – C:\Users\Joe\Desktop\Untitled-5.jpg
[2009/03/03 14:25:26 | 00,113,347 | —- | C] () – C:\Users\Joe\Desktop\trans.png
[2009/03/03 08:35:05 | 00,000,000 | —D | C] – C:\Users\Joe\Desktop\auto
[2009/03/01 20:46:04 | 00,000,000 | —D | C] – C:\Users\Joe\AppData\Roaming\id Software
[2009/03/01 20:28:53 | 00,188,896 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2009/03/01 20:28:51 | 02,246,144 | —- | C] () – C:\Windows\System32\pbsvc.exe
[2009/03/01 20:28:51 | 00,070,968 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2009/03/01 20:28:51 | 00,000,000 | —D | C] – C:\ProgramData\id Software
[2009/03/01 12:07:58 | 00,000,000 | —D | C] – C:\$WINDOWS.~BT
[2009/02/15 01:29:14 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/02/15 01:29:14 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/02/15 01:29:13 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/02/15 01:29:13 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/02/15 01:29:13 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/02/12 22:44:55 | 00,471,624 | —- | C] () – C:\Users\Joe\Desktop\funkdrum.wav
[2009/02/11 21:48:18 | 07,686,144 | —- | C] () – C:\Users\Joe\Desktop\stressed.mp3
[2009/02/11 14:10:04 | 06,069,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/02/11 14:10:04 | 03,580,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/02/11 14:10:03 | 01,166,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/02/11 14:10:03 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/02/11 14:10:03 | 00,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/02/11 14:10:02 | 01,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/02/11 14:10:02 | 00,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/02/11 14:10:02 | 00,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/02/11 14:10:02 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/02/10 20:51:48 | 03,107,582 | —- | C] () – C:\Users\Joe\Desktop\pc.mp3
[2009/02/05 18:15:02 | 00,946,776 | —- | C] () – C:\Users\Joe\Desktop\Yagmi.mp3
========== Files - Modified Within 30 Days ==========
[1 C:\*.tmp files]
[2009/03/07 12:31:49 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/03/07 12:31:39 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/03/07 12:31:35 | 42,941,64480 | -HS- | M] () – C:\hiberfil.sys
[2009/03/07 12:30:43 | 02,340,848 | -H– | M] () – C:\Users\Joe\AppData\Local\IconCache.db
[2009/03/07 12:28:16 | 00,001,805 | —- | M] () – C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/03/07 12:28:14 | 00,000,000 | —- | M] () – C:\Windows\System32\config.nt
[2009/03/07 10:13:34 | 00,001,928 | —- | M] () – C:\Users\Joe\Desktop\HijackThis.lnk
[2009/03/07 09:55:14 | 00,743,720 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/03/07 09:10:20 | 00,151,696 | —- | M] (Symantec Corporation) – C:\Users\Public\Documents\FxSasser.exe
[2009/03/06 17:03:16 | 00,000,465 | —- | M] () – C:\Windows\BRWMARK.INI
[2009/03/05 21:05:49 | 00,000,568 | —- | M] () – C:\Users\Joe\Desktop\Untitled-1.bmp
[2009/03/03 23:07:38 | 02,021,903 | —- | M] () – C:\Users\Joe\Desktop\fat.mp3
[2009/03/03 21:32:18 | 01,081,852 | —- | M] () – C:\Users\Joe\Desktop\DIAB.psd
[2009/03/03 21:32:12 | 00,088,607 | —- | M] () – C:\Users\Joe\Desktop\DIAB.png
[2009/03/03 21:19:32 | 00,238,029 | —- | M] () – C:\Users\Joe\Desktop\diab.ai
[2009/03/03 14:30:32 | 00,879,378 | —- | M] () – C:\Users\Joe\Desktop\Untitled-5.jpg
[2009/03/03 14:25:27 | 00,113,347 | —- | M] () – C:\Users\Joe\Desktop\trans.png
[2009/03/02 11:21:14 | 07,686,144 | —- | M] () – C:\Users\Joe\Desktop\stressed.mp3
[2009/03/01 20:59:47 | 00,070,968 | —- | M] () – C:\Windows\System32\PnkBstrA.exe
[2009/03/01 20:59:37 | 00,188,896 | —- | M] () – C:\Windows\System32\PnkBstrB.exe
[2009/03/01 20:32:15 | 02,246,144 | —- | M] () – C:\Windows\System32\pbsvc.exe
[2009/03/01 12:08:16 | 00,001,905 | —- | M] () – C:\Windows\diagwrn.xml
[2009/03/01 12:08:16 | 00,001,905 | —- | M] () – C:\Windows\diagerr.xml
[2009/02/17 14:58:18 | 00,044,032 | —- | M] () – C:\Users\Joe\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/12 22:45:28 | 00,471,624 | —- | M] () – C:\Users\Joe\Desktop\funkdrum.wav
[2009/02/10 20:52:13 | 03,107,582 | —- | M] () – C:\Users\Joe\Desktop\pc.mp3
[2009/02/08 14:09:04 | 00,946,776 | —- | M] () – C:\Users\Joe\Desktop\Yagmi.mp3
< End of report >
Everything seems to be running fine now. Any thing else I should be weary of? Thanks so much for the help!