Thank you so much for the help!
OTListIt Extras logfile created on: 4/5/2009 9:53:05 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Users\Adam\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.41 Mb Total Physical Memory | 479.81 Mb Available Physical Memory | 47.35% Memory free
2.23 Gb Paging File | 1.43 Gb Available in Paging File | 64.06% Paging File free
Paging file location(s): ?:\pagefile.sys;
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.06 Gb Total Space | 90.61 Gb Free Space | 40.62% Space Free | Partition Type: NTFS
Drive D: | 9.82 Gb Total Space | 4.47 Gb Free Space | 45.53% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ADAM-PC
Current User Name: Adam
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
"UpdatesDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-1503100673-2415758853-3373541529-1001]
"EnableNotificationsRef" = 2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-1503100673-2415758853-3373541529-500]
"EnableNotificationsRef" = 2
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"EnableFirewall" = 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent (BitTorrent, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0C2AF762-0565-4C91-9F55-B8B53BB82A38}" = Microsoft Office Accounting 2008 Equifax Addin
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{26C610BF-761B-4209-BD6A-A0F1B73D6DDE}" = Intel® Viiv™ Software
"{270940EA-C235-40D9-B2AE-2D450356DF8E}" = Microsoft Office Accounting 2008
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 5.0
"{44C05309-60F4-410B-BC32-31733CFF1A41}" = Microsoft Digital Image Starter Edition 2006 Editor
"{4FE542EB-FF0B-4739-94DD-25C8AE0AB251}" = Microsoft Digital Image Starter Edition 2006 Library
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{5FA793A6-0071-42C1-9355-8F69A428C44F}" = Microsoft Office Accounting ADP Payroll Addin
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F3BCF8A-8E02-4659-AF25-F9AB66BD6718}" = Gateway Recovery Center Installer
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A5FB086B-B602-4452-8FE9-DF6BFBCE3D09}" = Cubase Studio 4
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B391EECE-DFEA-4FC5-9D40-47FA43E2DBE6}" = Microsoft Office Accounting 2008 PayPal Addin
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BE2CC4A5-2128-4EA2-941D-14F7A6A1AB61}" = Digital Media Reader
"{CF1D7323-8A0A-49C7-83B0-088DB90721E2}" = AmpegSVX
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E3DF6916-2472-43D9-8B3C-9F2F0AAB01B5}" = Microsoft Office Accounting 2008 Fixed Asset Manager
"{E9F44C98-B8B6-480F-AF7B-E42A0A46F4E3}" = Microsoft SQL Server VSS Writer
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F9B3DD02-B0B3-42E9-8650-030DFF0D133D}" = Microsoft SQL Server Native Client
"{FF262740-C85A-11D5-BBEC-00D0B740900A}" = PS2 Multimedia Keyboard Driver
"Ableton Live v5.0.3" = Ableton Live v5.0.3
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Agere Systems Soft Modem" = Agere Systems PCI-SV92PP Soft Modem
"Antares AVOX Vocal Kit Bundle VST v1.02" = Antares AVOX Vocal Kit Bundle VST v1.02
"ArtsAcoustic Reverb VST v1.1.0.1" = ArtsAcoustic Reverb VST v1.1.0.1
"Audio Damage 907A VST v1.0.0.7" = Audio Damage 907A VST v1.0.0.7
"Audio Damage DeVerb VST v1.0" = Audio Damage DeVerb VST v1.0
"Audio Damage DubStation VST v1.0.2.0" = Audio Damage DubStation VST v1.0.2.0
"Audio.Damage.Ronin.v1.0.VST-DAC" = Audio.Damage.Ronin.v1.0.VST-DAC
"BigSeq VST plug-in" = BigSeq VST plug-in
"Camel Audio Camel Space VST v1.15" = Camel Audio Camel Space VST v1.15
"DiscoDSP FX Bundle v1.0a" = DiscoDSP FX Bundle v1.0a
"Echo24 PCI" = Echo24 PCI
"Focusrite Saffire Bundle VST v2.0" = Focusrite Saffire Bundle VST v2.0
"Haihaisoft Universal Player" = Haihaisoft Universal Player
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"InstallShield_{BE2CC4A5-2128-4EA2-941D-14F7A6A1AB61}" = Digital Media Reader
"Intel® Configuration Center" = Intel® Viiv™ Software
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 3.7.5
"Live 6.0.9" = Live 6.0.9
"Microsoft Office Accounting 2008" = Microsoft Office Accounting 2008
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Money2006b" = Microsoft Money 2006
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"MP3Suite" = MP3Suite
"Native Instruments - Rig Kontrol 2 Driver" = Native Instruments - Rig Kontrol 2 Driver
"Native Instruments GuitarRig2 RTAS VSTi DXi" = Native Instruments GuitarRig2 RTAS VSTi DXi
"OrangeVocoder v2.0-OxYGeN" = OrangeVocoder v2.0-OxYGeN
"PCSI" = Prevx CSI
"PhaseTwo VST plug-in" = PhaseTwo VST plug-in
"PictureItSuiteTrial_v12" = Microsoft Digital Image Starter Edition 2006
"PROR" = Microsoft Office Professional 2007 Trial
"PROSet" = Intel® PRO Network Connections Drivers
"QuickTime" = QuickTime
"Reverence VST plug-in" = Reverence VST plug-in
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SSL LMC-1" = SSL LMC-1 v1.0
"Steinberg Cubase SX v2.2.0.35" = Steinberg Cubase SX v2.2.0.35
"Switch" = Switch
"Syncrosoft License Control" = Syncrosoft License Control
"Trillian" = Trillian
"Vienna" = Vienna SoundFont Studio
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6c
"Voxengo Soniformer VST v2.3" = Voxengo Soniformer VST v2.3
"Voxengo_Polysquasher_1.0" = Polysquasher VST 1.0
"Waves Diamond Bundle v5.0" = Waves Diamond Bundle v5.0
"Waves SSL Collection v1.2" = Waves SSL Collection v1.2
"Waves Vocal Bundle v1.1" = Waves Vocal Bundle v1.1
"Winamp" = Winamp (remove only)
"WinRAR archiver" = WinRAR archiver
"WT014954" = Polar Bowler
"WT014956" = Polar Golfer
"WT014962" = SCRABBLE
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/31/2009 7:05:23 PM | Computer Name = Adam-PC | Source = EventSystem | ID = 4609
Description =
Error - 4/2/2009 8:11:22 PM | Computer Name = Adam-PC | Source = EventSystem | ID = 4609
Description =
Error - 4/2/2009 9:52:59 PM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0xffff7085, process id 0x17e0, application start time 0x01c9b3fb1a56b673.
Error - 4/3/2009 7:53:55 AM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module xul.dll, version 1.9.0.3334, time stamp 0x499db2f3, exception code
0xc0000409, fault offset 0x0057d996, process id 0x1080, application start time 0x01c9b45278286e93.
Error - 4/3/2009 8:04:35 AM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x00610077, process id 0x1568, application start time 0x01c9b452e14aa5a3.
Error - 4/3/2009 6:52:07 PM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module xul.dll, version 1.9.0.3334, time stamp 0x499db2f3, exception code
0xc0000005, fault offset 0x00115797, process id 0xc18, application start time 0x01c9b4ad6a6128c0.
Error - 4/4/2009 12:00:37 AM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0xb5ff0f74, process id 0x1d8, application start time 0x01c9b4aed745aa50.
Error - 4/4/2009 8:53:38 AM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module hareyiyi.dll, version 0.0.0.0, time stamp 0x499ecba7, exception
code 0xc0000005, fault offset 0x00001c60, process id 0x1d8, application start time
0x01c9b4aed745aa50.
Error - 4/4/2009 12:53:42 PM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3372, time stamp 0x49cbcea4,
faulting module xul.dll, version 1.9.0.3372, time stamp 0x49cbcf01, exception code
0xc0000005, fault offset 0x00042dd7, process id 0x1444, application start time 0x01c9b5247cc679d0.
Error - 4/5/2009 8:12:30 AM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3372, time stamp 0x49cbcea4,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x54c08304, process id 0x36c, application start time 0x01c9b545ec7fff00.
[ System Events ]
Error - 4/5/2009 9:22:06 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =
Error - 4/5/2009 9:22:09 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =
Error - 4/5/2009 9:22:09 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =
Error - 4/5/2009 9:22:09 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =
Error - 4/5/2009 9:28:14 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =
Error - 4/5/2009 9:28:18 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =
Error - 4/5/2009 9:28:23 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =
Error - 4/5/2009 9:33:47 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =
Error - 4/5/2009 9:33:55 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =
Error - 4/5/2009 9:34:09 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =
< End of report >
================================================================================
==============
OTListIt logfile created on: 4/5/2009 9:53:04 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Users\Adam\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.41 Mb Total Physical Memory | 479.81 Mb Available Physical Memory | 47.35% Memory free
2.23 Gb Paging File | 1.43 Gb Available in Paging File | 64.06% Paging File free
Paging file location(s): ?:\pagefile.sys;
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.06 Gb Total Space | 90.61 Gb Free Space | 40.62% Space Free | Partition Type: NTFS
Drive D: | 9.82 Gb Total Space | 4.47 Gb Free Space | 45.53% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ADAM-PC
Current User Name: Adam
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Windows\system32\AUDIODG.EXE (Microsoft Corporation)
PRC - C:\Windows\system32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe (SigmaTel, Inc.)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe (Intel® Corporation)
PRC - C:\Windows\zHotkey.exe ()
PRC - C:\Windows\ModPS2Key.exe (Chicony)
PRC - C:\Windows\sttray.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\System32\hkcmd.exe (Intel Corporation)
PRC - C:\Windows\System32\igfxpers.exe (Intel Corporation)
PRC - C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
PRC - C:\Program Files\Internet Explorer\ieuser.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wermgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Windows\system32\WUDFHost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\mobsync.exe (Microsoft Corporation)
PRC - C:\Program Files\Prevx\prevx.exe (Prevx)
PRC - C:\Program Files\Prevx\prevx.exe (Prevx)
PRC - C:\Users\Adam\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (AgereModemAudio [Auto | Running]) – C:\Windows\system32\agrsmsvc.exe (Agere Systems)
SRV - (AlertService [On_Demand | Running]) – C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
SRV - (Automatic LiveUpdate Scheduler [Auto | Stopped]) – File not found
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DQLWinService [Auto | Running]) – C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (IAANTMON [Auto | Running]) – C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (ISSM [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe (Intel® Corporation)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LiveUpdate [Disabled | Stopped]) – File not found
SRV - (M1 Server [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe ()
SRV - (McciCMService [Auto | Running]) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (MCLServiceATL [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe (Intel® Corporation)
SRV - (MSSQL$MSSMLBIZ [Auto | Running]) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper [Disabled | Stopped]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PrismXL [Auto | Running]) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (Remote UI Service [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe (Intel® Corporation)
SRV - (SQLBrowser [Disabled | Stopped]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (SQLWriter [Auto | Running]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (STacSV [Auto | Running]) – C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe (SigmaTel, Inc.)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (CSIScanner [Auto | Running]) – C:\Program Files\Prevx\prevx.exe (Prevx)
========== Driver Services (SafeList) ==========
DRV - (ac97intc [On_Demand | Stopped]) – C:\Windows\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (adp94xx [Disabled | Stopped]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (AgereSoftModem [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (aic78xx [Disabled | Stopped]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (arc [Disabled | Stopped]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (bcm4sbxp [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (Cdr4_xp [System | Running]) – C:\Windows\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (Cdralw2k [System | Running]) – C:\Windows\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (cmdide [Disabled | Stopped]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (E100B [On_Demand | Running]) – C:\Windows\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (echo24 [On_Demand | Running]) – C:\Windows\system32\drivers\echo24.sys (Echo Digital Audio Corp.)
DRV - (elxstor [Disabled | Stopped]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (FVNETusb [On_Demand | Running]) – C:\Windows\system32\DRIVERS\vnet558x.sys (ATMEL)
DRV - (HpCISSs [Disabled | Stopped]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (ialm [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation)
DRV - (iaStor [Boot | Running]) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (iaStorV [Boot | Running]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (igfx [On_Demand | Running]) – C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (IntelDH [On_Demand | Running]) – C:\Windows\System32\Drivers\IntelDH.sys (Intel Corporation)
DRV - (iteatapi [Disabled | Stopped]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (Lbd [Boot | Running]) – C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (LSI_FC [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (megasas [Disabled | Stopped]) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NETw2v32 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\NETw2v32.sys (Intel® Corporation)
DRV - (nfrd960 [Disabled | Stopped]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (nmsgopro [Auto | Running]) – C:\Windows\system32\DRIVERS\nmsgopro.sys (Gteko Ltd.)
DRV - (nmsunidr [Auto | Running]) – C:\Windows\system32\DRIVERS\nmsunidr.sys (Gteko Ltd.)
DRV - (ntrigdigi [Disabled | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvraid [Disabled | Stopped]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (PxHelp20 [Boot | Running]) – C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql2300 [Disabled | Stopped]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (secdrv [Auto | Running]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (STHDA [On_Demand | Running]) – C:\Windows\system32\drivers\stwrt.sys (SigmaTel, Inc.)
DRV - (Symc8xx [Disabled | Stopped]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (SynasUSB [On_Demand | Stopped]) – C:\Windows\system32\drivers\SynasUSB.sys (SIA Syncrosoft)
DRV - (TSHWMDTCP [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys ()
DRV - (uliahci [Disabled | Stopped]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\Windows\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (viaide [Disabled | Stopped]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (pxscan [Boot | Running]) – C:\Windows\System32\drivers\pxscan.sys (Prevx)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.gateway.com/g/startpage.html?Ch…TP&M;=GT5404
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.gateway.com/g/startpage.html?Ch…TP&M;=GT5404
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.gateway.com/g/sidepanel.html?Ch…TP&M;=GT5404
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.gateway.com/g/startpage.html?Ch…TP&M;=GT5404
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.84
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.0.0
FF - prefs.js..extensions.enabledItems: {2e61e246-e640-4c56-b1ed-f146dbed48cd}:0.7.6
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/04 07:54:18 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/04 07:54:18 | 00,000,000 | —D | M]
[2009/03/07 10:55:27 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Extensions
[2009/03/07 10:55:27 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/04 19:53:47 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions
[2009/03/07 10:56:03 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions\{2e61e246-e640-4c56-b1ed-f146dbed48cd}
[2009/03/07 10:56:03 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2008/07/29 03:40:17 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2009/02/08 18:44:12 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions\[removed]
[2009/03/07 10:55:28 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/04 07:54:18 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/04 07:54:02 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/04 07:54:02 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/04 07:54:12 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/04 07:54:12 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/04 07:54:12 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/04 07:54:12 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/04 07:54:12 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/04 07:54:12 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/04 07:54:13 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (728 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {a84e6d05-9fad-4976-af9e-24b9c775dffd} - C:\Windows\system32\lakofote.dll ()
O4 - HKLM..\Run: [a2a56c9a] rundll32.exe "C:\Windows\system32\kegorafa.dll",b (ICQ)
O4 - HKLM..\Run: [BigFix] c:\program files\Bigfix\bigfix.exe /atstartup File not found
O4 - HKLM..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe (Intel® Corporation)
O4 - HKLM..\Run: [CHotkey] zHotkey.exe ()
O4 - HKLM..\Run: [CPMa1965f06] Rundll32.exe "c:\windows\system32\jinohila.dll",a ()
O4 - HKLM..\Run: [fumogogiha] Rundll32.exe "C:\Windows\system32\jebihote.dll",s ()
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ModPS2] ModPS2Key.exe (Chicony)
O4 - HKLM..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup (Intel Corporation)
O4 - HKLM..\Run: [Persistence] C:\Windows\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] sttray.exe (SigmaTel, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\windows\system32\jinohila.dll) - c:\windows\system32\jinohila.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\wijariwo.dll) - C:\Windows\system32\wijariwo.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\system32\igfxdev.dll (Intel Corporation)
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\jinohila.dll ()
O22 - SharedTaskScheduler: {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - STS - c:\windows\system32\jinohila.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\autoexec.bat () - [ NTFS ]
O32 - Autorun File - D:\autorun.inf () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[2 C:\Windows\System32\*.tmp files]
[2009/04/05 09:50:05 | 00,499,200 | —- | C] (OldTimer Tools) – C:\Users\Adam\Desktop\OTListIt2.exe
[2009/04/05 09:23:54 | 00,022,024 | —- | C] (Prevx) – C:\Windows\System32\drivers\pxscan.sys
[2009/04/05 09:23:54 | 00,000,000 | —D | C] – C:\Program Files\Prevx
[2009/04/05 09:23:50 | 00,000,000 | —D | C] – C:\ProgramData\PrevxCSI
[2009/04/05 09:23:49 | 00,000,065 | —- | C] () – C:\Windows\wininit.ini
[2009/04/05 07:23:11 | 01,422,825 | -HS- | C] () – C:\Windows\System32\afarogek.ini
[2009/04/04 19:22:49 | 01,422,803 | -HS- | C] () – C:\Windows\System32\ibigutik.ini
[2009/04/04 07:22:45 | 01,422,834 | -HS- | C] () – C:\Windows\System32\iyakimer.ini
[2009/04/03 21:10:29 | 00,054,156 | -H– | C] () – C:\Windows\QTFont.qfn
[2009/04/03 21:10:29 | 00,001,409 | —- | C] () – C:\Windows\QTFont.for
[2009/04/03 19:22:35 | 01,422,825 | -HS- | C] () – C:\Windows\System32\enilowes.ini
[2009/04/03 17:41:58 | 00,000,060 | -H– | C] () – C:\aaw7boot.cmd
[2009/04/03 07:22:24 | 01,422,825 | -HS- | C] () – C:\Windows\System32\asivefeh.ini
[2009/04/02 19:22:13 | 01,418,378 | -HS- | C] () – C:\Windows\System32\arovofuh.ini
[2009/04/02 19:21:05 | 10,632,19200 | -HS- | C] () – C:\hiberfil.sys
[2009/04/01 07:08:17 | 00,000,680 | —- | C] () – C:\Users\Adam\AppData\Local\d3d9caps.dat
[2009/03/31 18:10:21 | 00,000,552 | —- | C] () – C:\Users\Adam\AppData\Local\d3d8caps.dat
[2009/03/31 14:08:05 | 00,000,002 | —- | C] () – C:\-1566217163
[2009/03/26 00:10:41 | 00,037,355 | —- | C] () – C:\Users\Adam\Desktop\n1063746744_166822_6363615.jpg
[2009/03/24 21:42:28 | 00,142,336 | -HS- | C] (ICQ) – C:\Windows\System32\ksougj.dll
[2009/03/24 21:42:27 | 01,418,387 | -HS- | C] () – C:\Windows\System32\ogajodig.ini
[2009/03/24 09:42:22 | 00,141,824 | -HS- | C] (ICQ) – C:\Windows\System32\dlzynh.dll
[2009/03/24 09:42:20 | 01,420,795 | -HS- | C] () – C:\Windows\System32\ebabales.ini
[2009/03/23 22:59:00 | 00,129,664 | —- | C] () – C:\Users\Adam\Desktop\artofbookcover.jpg
[2009/03/23 21:42:19 | 00,141,312 | -HS- | C] (ICQ) – C:\Windows\System32\aknvvd.dll
[2009/03/23 21:42:17 | 01,420,795 | -HS- | C] () – C:\Windows\System32\ivoreroj.ini
[2009/03/23 09:42:12 | 00,140,800 | -HS- | C] (ICQ) – C:\Windows\System32\grsziv.dll
[2009/03/23 09:42:07 | 01,802,266 | -HS- | C] () – C:\Windows\System32\avigehem.ini
[2009/03/22 21:41:59 | 00,140,800 | -HS- | C] (ICQ) – C:\Windows\System32\rhnvxs.dll
[2009/03/22 21:41:57 | 01,801,911 | -HS- | C] () – C:\Windows\System32\uwuwudun.ini
[2009/03/22 21:09:00 | 00,436,629 | —- | C] () – C:\Users\Adam\Desktop\Backroom Boom Boom Rendered.wav.asd
[2009/03/22 21:05:46 | 37,895,472 | —- | C] () – C:\Users\Adam\Desktop\Backroom Boom Boom Rendered.wav
[2009/03/22 09:41:48 | 00,140,800 | -HS- | C] (ICQ) – C:\Windows\System32\nyytqc.dll
[2009/03/22 09:41:45 | 01,801,920 | -HS- | C] () – C:\Windows\System32\idiwalur.ini
[2009/03/21 21:41:40 | 00,141,824 | -HS- | C] (ICQ) – C:\Windows\System32\cvhxxw.dll
[2009/03/21 21:41:37 | 01,801,911 | -HS- | C] () – C:\Windows\System32\oyijejer.ini
[2009/03/21 19:21:32 | 01,524,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2009/03/21 19:21:32 | 00,051,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuauclt.exe
[2009/03/21 19:21:32 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2009/03/21 19:21:31 | 01,809,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuaueng.dll
[2009/03/21 19:18:35 | 00,162,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2009/03/21 19:18:35 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2009/03/21 09:41:28 | 00,142,848 | -HS- | C] (ICQ) – C:\Windows\System32\ipiiko.dll
[2009/03/21 09:41:25 | 01,801,920 | -HS- | C] () – C:\Windows\System32\osaradeh.ini
[2009/03/20 21:41:21 | 01,801,911 | -HS- | C] () – C:\Windows\System32\ofuhesek.ini
[2009/03/20 21:41:18 | 00,142,848 | -HS- | C] (ICQ) – C:\Windows\System32\xfpwaf.dll
[2009/03/20 09:41:12 | 01,799,769 | -HS- | C] () – C:\Windows\System32\ebadegez.ini
[2009/03/19 21:41:07 | 01,799,218 | -HS- | C] () – C:\Windows\System32\ujekunot.ini
[2009/03/19 09:41:01 | 01,795,884 | -HS- | C] () – C:\Windows\System32\obuzokit.ini
[2009/03/18 21:40:59 | 01,795,884 | -HS- | C] () – C:\Windows\System32\ufosonev.ini
[2009/03/17 21:40:29 | 01,957,494 | -HS- | C] () – C:\Windows\System32\ifirewur.ini
[2009/03/17 09:40:21 | 01,933,175 | -HS- | C] () – C:\Windows\System32\ihawureg.ini
[2009/03/16 21:39:53 | 01,932,881 | -HS- | C] () – C:\Windows\System32\efaheyol.ini
[2009/03/16 20:54:24 | 00,000,000 | R–D | C] – C:\Users\Adam\Desktop\Backroom Boom Boom Project
[2009/03/16 19:22:09 | 00,000,000 | —D | C] – C:\VundoFix Backups
[2009/03/16 09:39:39 | 01,912,660 | -HS- | C] () – C:\Windows\System32\uzetobav.ini
[2009/03/15 21:39:31 | 01,912,660 | -HS- | C] () – C:\Windows\System32\utopunip.ini
[2009/03/15 09:39:20 | 01,912,660 | -HS- | C] () – C:\Windows\System32\urelowid.ini
[2009/03/14 21:39:11 | 01,912,660 | -HS- | C] () – C:\Windows\System32\irelefog.ini
[2009/03/14 10:02:35 | 00,001,874 | —- | C] () – C:\Users\Adam\Desktop\HijackThis.lnk
[2009/03/14 10:02:35 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/14 09:39:03 | 01,912,660 | -HS- | C] () – C:\Windows\System32\ubuvikes.ini
[2009/03/14 07:55:31 | 00,064,160 | —- | C] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2009/03/13 21:38:52 | 01,912,660 | -HS- | C] () – C:\Windows\System32\utoveton.ini
[2009/03/13 09:38:26 | 01,912,680 | -HS- | C] () – C:\Windows\System32\arirayew.ini
[2009/03/12 21:38:10 | 01,808,081 | -HS- | C] () – C:\Windows\System32\ajedafet.ini
[2009/03/12 21:38:07 | 00,142,336 | -HS- | C] () – C:\Windows\System32\noxnkk.dll
[2009/03/12 12:02:27 | 01,808,081 | -HS- | C] () – C:\Windows\System32\eyanofef.ini
[2009/03/12 09:37:52 | 00,143,360 | -HS- | C] () – C:\Windows\System32\zmvxeu.dll
[2009/03/07 09:08:13 | 00,015,688 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2009/03/07 08:51:01 | 00,000,472 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/03/07 08:50:46 | 00,000,000 | —D | C] – C:\Windows\System32\DRVSTORE
[2009/03/07 08:50:02 | 00,000,000 | -H-D | C] – C:\ProgramData\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/03/07 08:50:00 | 00,001,007 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2009/03/07 08:49:47 | 00,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2009/03/07 08:49:47 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2009/03/07 08:44:39 | 34,543,112 | —- | C] (Lavasoft ) – C:\Users\Adam\Desktop\Ad-AwareAE.exe
[2009/01/08 00:39:26 | 00,000,016 | —- | C] () – C:\Windows\System32\msvcsv60.dll
[2009/01/05 07:23:04 | 00,104,960 | -HS- | C] () – C:\Windows\System32\jinohila.dll
[2008/07/22 18:51:01 | 00,000,092 | —- | C] () – C:\Windows\mp3wavcon.ini
[2008/07/22 18:26:58 | 00,237,568 | —- | C] () – C:\Windows\System32\lame_enc.dll
[2008/01/10 07:16:20 | 00,159,839 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/01/10 07:15:30 | 00,755,027 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2007/09/25 16:59:58 | 00,007,168 | —- | C] () – C:\Windows\System32\Echo24Wrap.dll
[2007/09/04 11:56:10 | 00,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2007/05/07 09:11:09 | 00,000,061 | —- | C] () – C:\Windows\SBWIN.INI
[2007/03/27 02:55:48 | 03,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2007/01/25 14:53:19 | 00,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1114.dll
[2007/01/25 14:53:16 | 00,077,824 | —- | C] () – C:\Windows\System32\hccutils.dll
[2007/01/25 14:20:32 | 00,532,544 | —- | C] () – C:\Windows\PIC.dll
[2007/01/25 14:20:32 | 00,024,576 | —- | C] () – C:\Windows\HKNTDLL.dll
[2006/12/12 11:24:42 | 00,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2006/12/12 11:13:50 | 00,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1147.dll
[2006/12/12 10:02:50 | 00,053,248 | —- | C] () – C:\Windows\System32\oemdspif.dll
[2006/11/22 17:16:18 | 00,003,612 | —- | C] () – C:\Windows\ReaderString.ini
[2006/11/21 13:50:06 | 00,000,037 | —- | C] () – C:\Windows\sunkist.ini
[2006/11/02 07:56:07 | 00,000,082 | -HS- | C] () – C:\Windows\System32\desktop.ini
[2006/11/02 07:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 00,786,636 | —- | C] () – C:\Windows\System32\PerfStringBackup.INI
[2006/11/02 05:25:21 | 00,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 05:24:31 | 00,001,405 | —- | C] () – C:\Windows\msdfmap.ini
[2006/11/02 05:23:31 | 00,000,244 | —- | C] () – C:\Windows\win.ini
[2006/11/02 05:23:31 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 03:23:38 | 00,055,858 | —- | C] () – C:\Windows\System32\tcpmon.ini
[2006/11/02 02:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 02:09:45 | 00,027,097 | —- | C] () – C:\Windows\System32\country.sys
[2006/11/02 02:09:44 | 00,042,809 | —- | C] () – C:\Windows\System32\KEY01.SYS
[2006/11/02 02:09:44 | 00,042,537 | —- | C] () – C:\Windows\System32\KEYBOARD.SYS
[2006/11/02 02:09:42 | 00,009,029 | —- | C] () – C:\Windows\System32\ANSI.SYS
[2006/11/02 02:09:41 | 00,004,768 | —- | C] () – C:\Windows\System32\HIMEM.SYS
[2006/11/02 02:09:40 | 00,029,274 | —- | C] () – C:\Windows\System32\NTDOS412.SYS
[2006/11/02 02:09:38 | 00,029,370 | —- | C] () – C:\Windows\System32\NTDOS411.SYS
[2006/11/02 02:09:35 | 00,029,146 | —- | C] () – C:\Windows\System32\NTDOS404.SYS
[2006/11/02 02:09:31 | 00,029,146 | —- | C] () – C:\Windows\System32\NTDOS804.SYS
[2006/11/02 02:09:29 | 00,027,866 | —- | C] () – C:\Windows\System32\NTDOS.SYS
[2006/11/02 02:09:26 | 00,035,536 | —- | C] () – C:\Windows\System32\NTIO412.SYS
[2006/11/02 02:09:24 | 00,035,776 | —- | C] () – C:\Windows\System32\NTIO411.SYS
[2006/11/02 02:09:23 | 00,034,672 | —- | C] () – C:\Windows\System32\NTIO404.SYS
[2006/11/02 02:09:22 | 00,034,672 | —- | C] () – C:\Windows\System32\NTIO804.SYS
[2006/11/02 02:09:20 | 00,033,952 | —- | C] () – C:\Windows\System32\NTIO.SYS
[2006/11/02 01:47:51 | 00,364,544 | —- | C] () – C:\Windows\System32\msjetoledb40.dll
[2006/11/02 01:25:08 | 00,013,312 | —- | C] () – C:\Windows\System32\win87em.dll
[2006/10/03 10:53:03 | 00,069,632 | —- | C] () – C:\Windows\System32\com.fxpansion.fxshared.dll
[2006/06/23 12:09:34 | 00,019,968 | R— | C] () – C:\Windows\System32\cpuinf32.dll
[2006/05/26 08:29:14 | 00,005,120 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2006/04/03 07:26:36 | 00,000,547 | —- | C] () – C:\Windows\System32\ff_vfw.dll.manifest
[1900/01/01 12:00:00 | 00,143,360 | -HS- | C] () – C:\Windows\System32\ramemori.dll
[1900/01/01 12:00:00 | 00,142,336 | -HS- | C] () – C:\Windows\System32\talopoja.dll
[1900/01/01 12:00:00 | 00,108,032 | -HS- | C] () – C:\Windows\System32\remizalu.dll
[1900/01/01 12:00:00 | 00,108,032 | -HS- | C] () – C:\Windows\System32\nemulopi.dll
[1900/01/01 12:00:00 | 00,108,032 | -HS- | C] () – C:\Windows\System32\jeruwuke.dll
[1900/01/01 12:00:00 | 00,108,032 | -HS- | C] () – C:\Windows\System32\davewodu.dll
[1900/01/01 12:00:00 | 00,107,520 | -HS- | C] () – C:\Windows\System32\setegabo.dll
[1900/01/01 12:00:00 | 00,107,520 | -HS- | C] () – C:\Windows\System32\howewufu.dll
[1900/01/01 12:00:00 | 00,107,520 | -HS- | C] () – C:\Windows\System32\gidalepu.dll
[1900/01/01 12:00:00 | 00,107,008 | -HS- | C] () – C:\Windows\System32\zovadejo.dll
[1900/01/01 12:00:00 | 00,105,984 | -HS- | C] () – C:\Windows\System32\tutogupo.dll
[1900/01/01 12:00:00 | 00,105,984 | -HS- | C] () – C:\Windows\System32\hitoremi.dll
[1900/01/01 12:00:00 | 00,105,984 | -HS- | C] () – C:\Windows\System32\gijudefu.dll
[1900/01/01 12:00:00 | 00,069,120 | -HS- | C] () – C:\Windows\System32\wijariwo.dll
[1900/01/01 12:00:00 | 00,069,120 | -HS- | C] () – C:\Windows\System32\lakofote.dll
[1900/01/01 12:00:00 | 00,069,120 | -HS- | C] () – C:\Windows\System32\jebihote.dll
[1900/01/01 12:00:00 | 00,002,713 | -HS- | C] () – C:\Windows\System32\wegayalu.dll
[1900/01/01 12:00:00 | 00,002,713 | -HS- | C] () – C:\Windows\System32\tuyotete.dll
[1900/01/01 12:00:00 | 00,002,713 | -HS- | C] () – C:\Windows\System32\rafinuno.dll
[1900/01/01 12:00:00 | 00,002,713 | -HS- | C] () – C:\Windows\System32\hajifobu.dll
========== Files - Modified Within 30 Days ==========
[2 C:\Windows\System32\*.tmp files]
[1 C:\Windows\*.tmp files]
[2009/04/05 09:58:51 | 00,011,168 | -H– | M] () – C:\Windows\System32\kujadebo
[2009/04/05 09:50:07 | 00,499,200 | —- | M] (OldTimer Tools) – C:\Users\Adam\Desktop\OTListIt2.exe
[2009/04/05 09:24:09 | 00,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/04/05 09:24:09 | 00,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/04/05 09:23:54 | 00,022,024 | —- | M] (Prevx) – C:\Windows\System32\drivers\pxscan.sys
[2009/04/05 09:23:49 | 00,000,065 | —- | M] () – C:\Windows\wininit.ini
[2009/04/05 08:47:36 | 01,422,825 | -HS- | M] () – C:\Windows\System32\afarogek.ini
[2009/04/05 07:27:19 | 00,000,728 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2009/04/05 07:23:08 | 00,104,960 | -HS- | M] () – C:\Windows\System32\jinohila.dll
[2009/04/05 07:23:06 | 00,100,352 | -HS- | M] (ICQ) – C:\Windows\System32\kegorafa.dll
[2009/04/05 07:23:05 | 00,061,440 | -HS- | M] () – C:\Windows\System32\juhonemo.exe
[2009/04/04 19:45:02 | 01,422,803 | -HS- | M] () – C:\Windows\System32\ibigutik.ini
[2009/04/04 19:22:45 | 00,099,840 | —- | M] (ICQ) – C:\Windows\System32\kitugibi.dll
[2009/04/04 19:22:44 | 00,061,440 | -HS- | M] () – C:\Windows\System32\bubesomu.exe
[2009/04/04 19:22:43 | 00,106,496 | -HS- | M] (ICQ) – C:\Windows\System32\zayiwomo.dll
[2009/04/04 12:19:26 | 01,422,834 | -HS- | M] () – C:\Windows\System32\iyakimer.ini
[2009/04/04 07:50:55 | 00,000,472 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/04/04 07:22:39 | 00,104,960 | -HS- | M] (ICQ) – C:\Windows\System32\hareyiyi.dll
[2009/04/04 07:22:39 | 00,100,352 | —- | M] (ICQ) – C:\Windows\System32\remikayi.dll
[2009/04/04 07:22:38 | 00,061,440 | -HS- | M] () – C:\Windows\System32\pibosine.exe
[2009/04/03 22:54:42 | 01,422,825 | -HS- | M] () – C:\Windows\System32\enilowes.ini
[2009/04/03 21:10:29 | 00,054,156 | -H– | M] () – C:\Windows\QTFont.qfn
[2009/04/03 21:10:29 | 00,001,409 | —- | M] () – C:\Windows\QTFont.for
[2009/04/03 19:22:31 | 00,099,328 | —- | M] (ICQ) – C:\Windows\System32\sewoline.dll
[2009/04/03 19:22:30 | 00,061,440 | -HS- | M] () – C:\Windows\System32\jepeyumu.exe
[2009/04/03 19:22:29 | 00,104,960 | -HS- | M] (ICQ) – C:\Windows\System32\mawisega.dll
[2009/04/03 17:52:01 | 01,422,825 | -HS- | M] () – C:\Windows\System32\asivefeh.ini
[2009/04/03 17:41:58 | 00,000,060 | -H– | M] () – C:\aaw7boot.cmd
[2009/04/03 07:30:21 | 00,786,636 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/04/03 07:30:21 | 00,668,022 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/04/03 07:30:21 | 00,122,184 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/04/03 07:24:06 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/04/03 07:24:01 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/04/03 07:23:53 | 10,632,19200 | -HS- | M] () – C:\hiberfil.sys
[2009/04/03 07:22:24 | 00,061,440 | -HS- | M] () – C:\Windows\System32\zekazide.exe
[2009/04/03 07:22:23 | 00,103,936 | -HS- | M] (ICQ) – C:\Windows\System32\fofajivo.dll
[2009/04/03 07:22:23 | 00,100,352 | —- | M] (ICQ) – C:\Windows\System32\hefevisa.dll
[2009/04/03 06:53:53 | 01,418,387 | -HS- | M] () – C:\Windows\System32\ogajodig.ini
[2009/04/02 19:24:47 | 01,418,378 | -HS- | M] () – C:\Windows\System32\arovofuh.ini
[2009/04/02 19:22:03 | 00,105,472 | -HS- | M] (ICQ) – C:\Windows\System32\norupeze.dll
[2009/04/02 19:22:00 | 00,061,440 | -HS- | M] () – C:\Windows\System32\davagadu.exe
[2009/04/01 07:08:57 | 00,000,680 | —- | M] () – C:\Users\Adam\AppData\Local\d3d9caps.dat
[2009/03/31 18:10:21 | 00,000,552 | —- | M] () – C:\Users\Adam\AppData\Local\d3d8caps.dat
[2009/03/31 14:08:05 | 00,000,002 | —- | M] () – C:\-1566217163
[2009/03/26 00:10:46 | 00,037,355 | —- | M] () – C:\Users\Adam\Desktop\n1063746744_166822_6363615.jpg
[2009/03/25 07:19:37 | 00,224,256 | —- | M] () – C:\Users\Adam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/24 21:42:28 | 00,142,336 | -HS- | M] (ICQ) – C:\Windows\System32\pazesomu.dll
[2009/03/24 21:42:28 | 00,142,336 | -HS- | M] (ICQ) – C:\Windows\System32\ksougj.dll
[2009/03/24 21:42:26 | 00,107,520 | -HS- | M] (ICQ) – C:\Windows\System32\yikelido.dll
[2009/03/24 10:03:43 | 01,420,795 | -HS- | M] () – C:\Windows\System32\ebabales.ini
[2009/03/24 09:42:22 | 00,141,824 | -HS- | M] (ICQ) – C:\Windows\System32\pevowuhi.dll
[2009/03/24 09:42:22 | 00,141,824 | -HS- | M] (ICQ) – C:\Windows\System32\dlzynh.dll
[2009/03/24 09:42:22 | 00,108,544 | -HS- | M] (ICQ) – C:\Windows\System32\kigirefu.dll
[2009/03/24 09:42:20 | 00,100,352 | —- | M] (ICQ) – C:\Windows\System32\selababe.dll
[2009/03/23 22:59:02 | 00,129,664 | —- | M] () – C:\Users\Adam\Desktop\artofbookcover.jpg
[2009/03/23 22:04:36 | 01,420,795 | -HS- | M] () – C:\Windows\System32\ivoreroj.ini
[2009/03/23 21:42:20 | 00,108,032 | -HS- | M] (ICQ) – C:\Windows\System32\zatidege.dll
[2009/03/23 21:42:19 | 00,141,312 | -HS- | M] (ICQ) – C:\Windows\System32\jahitipa.dll
[2009/03/23 21:42:19 | 00,141,312 | -HS- | M] (ICQ) – C:\Windows\System32\aknvvd.dll
[2009/03/23 21:42:17 | 00,102,400 | —- | M] (ICQ) – C:\Windows\System32\jorerovi.dll
[2009/03/23 10:03:31 | 01,802,266 | -HS- | M] () – C:\Windows\System32\avigehem.ini
[2009/03/23 09:42:12 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\lurujako.dll
[2009/03/23 09:42:12 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\grsziv.dll
[2009/03/23 09:42:07 | 00,106,496 | -HS- | M] (ICQ) – C:\Windows\System32\jikodiwa.dll
[2009/03/23 09:42:07 | 00,102,912 | —- | M] (ICQ) – C:\Windows\System32\mehegiva.dll
[2009/03/22 22:03:22 | 01,801,911 | -HS- | M] () – C:\Windows\System32\uwuwudun.ini
[2009/03/22 21:41:59 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\sebiluza.dll
[2009/03/22 21:41:59 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\rhnvxs.dll
[2009/03/22 21:41:56 | 00,101,376 | —- | M] (ICQ) – C:\Windows\System32\nuduwuwu.dll
[2009/03/22 21:41:55 | 00,105,472 | -HS- | M] (ICQ) – C:\Windows\System32\yupujeba.dll
[2009/03/22 21:09:00 | 00,436,629 | —- | M] () – C:\Users\Adam\Desktop\Backroom Boom Boom Rendered.wav.asd
[2009/03/22 21:05:47 | 37,895,472 | —- | M] () – C:\Users\Adam\Desktop\Backroom Boom Boom Rendered.wav
[2009/03/22 16:22:22 | 01,801,920 | -HS- | M] () – C:\Windows\System32\idiwalur.ini
[2009/03/22 09:41:49 | 00,104,960 | -HS- | M] (ICQ) – C:\Windows\System32\gomewihe.dll
[2009/03/22 09:41:47 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\nyytqc.dll
[2009/03/22 09:41:47 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\lopisedu.dll
[2009/03/22 09:41:45 | 00,101,888 | —- | M] (ICQ) – C:\Windows\System32\rulawidi.dll
[2009/03/21 22:03:01 | 01,801,911 | -HS- | M] () – C:\Windows\System32\oyijejer.ini
[2009/03/21 21:41:39 | 00,141,824 | -HS- | M] (ICQ) – C:\Windows\System32\nopefine.dll
[2009/03/21 21:41:39 | 00,141,824 | -HS- | M] (ICQ) – C:\Windows\System32\cvhxxw.dll
[2009/03/21 21:41:36 | 00,101,888 | —- | M] (ICQ) – C:\Windows\System32\rejejiyo.dll
[2009/03/21 21:41:35 | 00,104,448 | -HS- | M] (ICQ) – C:\Windows\System32\zutedizo.dll
[2009/03/21 19:21:32 | 01,524,736 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2009/03/21 19:21:32 | 00,051,224 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuauclt.exe
[2009/03/21 19:21:32 | 00,043,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2009/03/21 19:21:31 | 01,809,944 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuaueng.dll
[2009/03/21 19:18:35 | 00,162,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2009/03/21 19:18:35 | 00,031,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2009/03/21 19:14:40 | 01,801,920 | -HS- | M] () – C:\Windows\System32\osaradeh.ini
[2009/03/21 09:41:27 | 00,142,848 | -HS- | M] (ICQ) – C:\Windows\System32\tekigobe.dll
[2009/03/21 09:41:27 | 00,142,848 | -HS- | M] (ICQ) – C:\Windows\System32\ipiiko.dll
[2009/03/21 09:41:26 | 00,107,520 | -HS- | M] (ICQ) – C:\Windows\System32\fuyozafe.dll
[2009/03/21 09:41:25 | 00,098,816 | —- | M] (ICQ) – C:\Windows\System32\hedaraso.dll
[2009/03/20 22:02:43 | 01,801,911 | -HS- | M] () – C:\Windows\System32\ofuhesek.ini
[2009/03/20 21:41:20 | 00,106,496 | -HS- | M] (ICQ) – C:\Windows\System32\lokabuki.dll
[2009/03/20 21:41:20 | 00,101,888 | —- | M] (ICQ) – C:\Windows\System32\kesehufo.dll
[2009/03/20 21:41:18 | 00,142,848 | -HS- | M] (ICQ) – C:\Windows\System32\xfpwaf.dll
[2009/03/20 21:41:18 | 00,142,848 | -HS- | M] (ICQ) – C:\Windows\System32\kewakiti.dll
[2009/03/20 18:35:39 | 01,799,769 | -HS- | M] () – C:\Windows\System32\ebadegez.ini
[2009/03/19 23:54:52 | 01,799,218 | -HS- | M] () – C:\Windows\System32\ujekunot.ini
[2009/03/19 18:28:27 | 01,795,884 | -HS- | M] () – C:\Windows\System32\obuzokit.ini
[2009/03/19 07:05:03 | 01,795,884 | -HS- | M] () – C:\Windows\System32\ufosonev.ini
[2009/03/18 17:42:59 | 01,957,494 | -HS- | M] () – C:\Windows\System32\ifirewur.ini
[2009/03/17 17:01:22 | 01,933,175 | -HS- | M] () – C:\Windows\System32\ihawureg.ini
[2009/03/17 03:07:00 | 01,932,881 | -HS- | M] () – C:\Windows\System32\efaheyol.ini
[2009/03/16 10:01:02 | 01,912,660 | -HS- | M] () – C:\Windows\System32\uzetobav.ini
[2009/03/15 22:00:53 | 01,912,660 | -HS- | M] () – C:\Windows\System32\utopunip.ini
[2009/03/15 10:00:42 | 01,912,660 | -HS- | M] () – C:\Windows\System32\urelowid.ini
[2009/03/14 22:00:33 | 01,912,660 | -HS- | M] () – C:\Windows\System32\irelefog.ini
[2009/03/14 10:02:35 | 00,001,874 | —- | M] () – C:\Users\Adam\Desktop\HijackThis.lnk
[2009/03/14 10:00:26 | 01,912,660 | -HS- | M] () – C:\Windows\System32\ubuvikes.ini
[2009/03/14 07:54:48 | 00,015,688 | —- | M] () – C:\Windows\System32\lsdelete.exe
[2009/03/14 07:54:19 | 00,064,160 | —- | M] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2009/03/13 22:00:16 | 01,912,660 | -HS- | M] () – C:\Windows\System32\utoveton.ini
[2009/03/13 10:00:38 | 01,912,680 | -HS- | M] () – C:\Windows\System32\arirayew.ini
[2009/03/12 23:20:33 | 01,808,081 | -HS- | M] () – C:\Windows\System32\ajedafet.ini
[2009/03/12 21:38:07 | 00,142,336 | -HS- | M] () – C:\Windows\System32\talopoja.dll
[2009/03/12 21:38:07 | 00,142,336 | -HS- | M] () – C:\Windows\System32\noxnkk.dll
[2009/03/12 21:38:04 | 00,108,032 | -HS- | M] () – C:\Windows\System32\remizalu.dll
[2009/03/12 12:23:37 | 01,808,081 | -HS- | M] () – C:\Windows\System32\eyanofef.ini
[2009/03/12 09:37:52 | 00,143,360 | -HS- | M] () – C:\Windows\System32\zmvxeu.dll
[2009/03/12 09:37:52 | 00,143,360 | -HS- | M] () – C:\Windows\System32\ramemori.dll
[2009/03/12 09:37:50 | 00,105,984 | -HS- | M] () – C:\Windows\System32\hitoremi.dll
[2009/03/11 21:37:47 | 00,108,032 | -HS- | M] () – C:\Windows\System32\nemulopi.dll
[2009/03/11 09:37:35 | 00,107,008 | -HS- | M] () – C:\Windows\System32\zovadejo.dll
[2009/03/10 21:37:18 | 00,108,032 | -HS- | M] () – C:\Windows\System32\davewodu.dll
[2009/03/09 21:36:59 | 00,107,520 | -HS- | M] () – C:\Windows\System32\howewufu.dll
[2009/03/09 09:36:36 | 00,105,984 | -HS- | M] () – C:\Windows\System32\tutogupo.dll
[2009/03/08 20:36:23 | 00,107,520 | -HS- | M] () – C:\Windows\System32\setegabo.dll
[2009/03/08 08:36:19 | 00,107,520 | -HS- | M] () – C:\Windows\System32\gidalepu.dll
[2009/03/07 20:36:16 | 00,108,032 | -HS- | M] () – C:\Windows\System32\jeruwuke.dll
[2009/03/07 08:50:00 | 00,001,007 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2009/03/07 08:47:22 | 34,543,112 | —- | M] (Lavasoft ) – C:\Users\Adam\Desktop\Ad-AwareAE.exe
[2009/03/07 08:36:37 | 00,105,984 | -HS- | M] () – C:\Windows\System32\gijudefu.dll
========== LOP Check ==========
[2009/04/04 07:50:55 | 00,000,472 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/04/03 07:24:06 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/03/13 16:30:07 | 00,032,638 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 43520 bytes -> C:\Windows\System32:nskrnl32.exe
@Alternate Data Stream - 1073 bytes -> C:\Windows\System32:nskrnl32
< End of report >