This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] HJT file included. Computer just not right

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have include the HJT log. Something about my computer is just not right. Its slow, constantly freezes, and keeps losing my printer. I am sure there is things running that shouldn't be. Please help! Thank you!!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:28:04 PM, on 18/04/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\HiYo\Bin\HiYo.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\Pete&Adie\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Windows\system32\conime.exe
C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe
C:\hp\kbd\kbd.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: IEPlugin Class - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\PROGRA~1\ArcSoft\VIDEOD~1\ARCURL~1.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Pete&Adie\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SmartRAM] "C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe" /m
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: IE Theme Search Bar - {323AF0A7-690A-47D9-819B-348831CC7DC5} - C:\Program Files\IECustomizer.com\IEButtons\SearchIECThemes.htm
O9 - Extra 'Tools' menuitem: Free Themes for Internet Explorer - {323AF0A7-690A-47D9-819B-348831CC7DC5} - C:\Program Files\IECustomizer.com\IEButtons\SearchIECThemes.htm
O9 - Extra button: (no name) - {472A296E-D7C1-4A70-8511-5039B09EBDDB} - java script:document.location='http://www.iecustomizer.com/iethemes' (file missing)
O9 - Extra 'Tools' menuitem: Online Themes Gallery - {472A296E-D7C1-4A70-8511-5039B09EBDDB} - java script:document.location='http://www.iecustomizer.com/iethemes' (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Themes - {B9844E33-6201-47AA-B30A-BCA3363C2BFA} - C:\Program Files\IECustomizer.com\Tools\IETheme.exe
O9 - Extra 'Tools' menuitem: Themes - {B9844E33-6201-47AA-B30A-BCA3363C2BFA} - C:\Program Files\IECustomizer.com\Tools\IETheme.exe
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\Windows\system32\CSHelper.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 15420 bytes
Hi Adrienne,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hi Tom and Thank you for your time! :D

My computer has good and bad days. Its having a good day right now. NOt freezing as often as it can. My printer, which often disappears, has miraculously reappeared again. (It tends to go missing or be unrecognizable one and a while). It still loads really slowly, and can take a while to respond to requests.

MalBytes Antimalware logfile

Malwarebytes' Anti-Malware 1.36
Database version: 2036
Windows 6.0.6001 Service Pack 1

24/04/2009 1:48:37 PM
mbam-log-2009-04-24 (13-48-19).txt

Scan type: Quick Scan
Objects scanned: 77748
Time elapsed: 6 minute(s), 22 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 26
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\Program Files\Windows Live\Messenger\riched20.dll (Adware.MyWebSearch) -> No action taken.

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> No action taken.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> No action taken.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\Windows Live\Messenger\riched20.dll (Adware.MyWebSearch) -> No action taken.



New HJT log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:03:07 PM, on 24/04/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\HiYo\Bin\HiYo.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Users\Pete&Adie\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\hp\kbd\kbd.exe
C:\Windows\system32\conime.exe
C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: IEPlugin Class - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\PROGRA~1\ArcSoft\VIDEOD~1\ARCURL~1.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Pete&Adie\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SmartRAM] "C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe" /m
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: IE Theme Search Bar - {323AF0A7-690A-47D9-819B-348831CC7DC5} - C:\Program Files\IECustomizer.com\IEButtons\SearchIECThemes.htm
O9 - Extra 'Tools' menuitem: Free Themes for Internet Explorer - {323AF0A7-690A-47D9-819B-348831CC7DC5} - C:\Program Files\IECustomizer.com\IEButtons\SearchIECThemes.htm
O9 - Extra button: (no name) - {472A296E-D7C1-4A70-8511-5039B09EBDDB} - java script:document.location='http://www.iecustomizer.com/iethemes' (file missing)
O9 - Extra 'Tools' menuitem: Online Themes Gallery - {472A296E-D7C1-4A70-8511-5039B09EBDDB} - java script:document.location='http://www.iecustomizer.com/iethemes' (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Themes - {B9844E33-6201-47AA-B30A-BCA3363C2BFA} - C:\Program Files\IECustomizer.com\Tools\IETheme.exe
O9 - Extra 'Tools' menuitem: Themes - {B9844E33-6201-47AA-B30A-BCA3363C2BFA} - C:\Program Files\IECustomizer.com\Tools\IETheme.exe
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/webgames/popcaploader_v10.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\Windows\system32\CSHelper.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 15571 bytes
Adrienne,

I need you to re-run Malwarebytes' but, this time,:

# When the scan is complete, click OK, then Show Results to view the results.
# Be sure that everything is checked, and click Remove Selected.

There are a bunch of items in quarantine in Malwarebytes. Should I be erasing them? Malwarebytes' Anti-Malware 1.36 Database version: 2043 Windows 6.0.6001 Service Pack 1 25/04/2009 7:19:24 PM mbam-log-2009-04-25 (19-19-24).txt Scan type: Quick Scan Objects scanned: 78285 Time elapsed: 3 minute(s), 38 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Adrienne,

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
OTListIt Extras logfile created on: 26/04/2009 6:14:02 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Users\Pete&Adie\Desktop
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.13 Gb Available Physical Memory | 56.98% Memory free
4.00 Gb Paging File | 2.67 Gb Available in Paging File | 66.65% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 141.96 Gb Total Space | 78.12 Gb Free Space | 55.03% Space Free | Partition Type: NTFS
Drive D: | 7.09 Gb Total Space | 0.88 Gb Free Space | 12.41% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 76.32 Gb Total Space | 58.00 Gb Free Space | 76.00% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PETEANDADIE-PC
Current User Name: Pete&Adie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

[HKEY_USERS\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" =
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"EnableFirewall" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2006/08/30 06:35:12 | 00,952,088 | —- | M] (EarthLink, Inc.) – C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
[2008/12/16 14:16:10 | 00,637,232 | —- | M] (BitTorrent, Inc.) – C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{01A1A019-E1D8-482A-BE17-5E118D17C0A0}" = ArcSoft Print Creations - Brochures & Flyers
"{034E061B-B3A3-4123-842E-10C1B6B3C8C7}" = BlackBerry Desktop Software 4.7
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{10CE1EA2-12E9-11D3-825E-00C04F6843FE}" = Microsoft Office Sounds
"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp
"{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
"{17BC8909-234D-4C4B-9FD7-C909D3B8560A}" = BlackBerry Device Software v4.5.0 for the BlackBerry 8100 smartphone
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1A0F7DFF-6F13-458C-8EC3-5386E8C251C6}" = BlackBerry Device Software Updater
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{22466889-7642-488d-AA0E-F619704CF7AB}" = DeviceDiscovery
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24557DC0-0839-496f-82F9-C4EB72EFE4FA}" = HP Deskjet All-In-One Software 8.0
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 13
"{271C6608-69FD-4D6E-933C-4C08742AA33C}" = ArcSoft Print Creations
"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg
"{2A5C6AD0-F7B3-40A1-B140-23B085B1B8CE}" = UFile 2008
"{2C464EC1-2B0C-4490-9CAC-D4562DD8377A}" = Soap 3.0 Toolkit
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{2E376AD9-5C49-4F7D-A0BA-6A44E8FA5A3B}" = Next Generation Visualisations
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{3347F0DF-4396-4DAB-9DDA-81D38B08FF63}_is1" = Internet Explorer Theme Manager (1.1.3)
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{37D74171-3131-498A-BE5D-7E3DA6AC0DBE}" = UFile 2007
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CCB26F5-E2A7-4C91-8340-9149D7B7C2BE}" = Virtual Earth 3D (Beta)
"{3CE47E6B-AE27-4E40-AC54-329EED96B933}" = ArcSoft Print Creations - Funhouse II
"{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend
"{451BB54C-8B23-4455-8BDC-14FC7D43E056}" = MSXML4SP2
"{4532168B-140A-48D1-91F3-4F52EEE3DBA3}" = ArcSoft Collage Creator
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = DVD Play
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{5023B3E9-6B73-471E-8BD9-DA4442AE357C}" = ArcSoft Print Creations - Quick Photo Book
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{5D1C82E7-7EC0-4404-A8AD-36C3B444BC34}" = ArcSoft Print Creations - Poster Creator
"{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{63E949F6-03BC-5C40-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT.Policy (x86) WinSXS MSM
"{657F8B33-CBBB-45F4-9087-274F22C89400}" = DJ_AIO_ProductContext
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{68B7C6D9-1DF2-54C1-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 MFC.Policy (x86) WinSXS MSM
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}" = HP Active Support Library 32 bit components
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75E71ADD-042C-4F30-BFAC-A9EC42351313}" = Python 2.4.3
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{7DDEABFB-0621-4321-B385-CB86D3A6F90F}" = F4100
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8F3A13FC-DFDA-4001-A6C3-030495A1E66E}" = HiYo
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{913D0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Standard for Students and Teachers
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}" = Logitech QuickCam
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{95F875CC-1B85-43E6-B3E0-13EA04F3D995}" = ArcSoft Print Creations - Photo Prints
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{99A40651-0BC2-4095-8F9A-A40FAB224FEF}" = PC Connectivity Solution
"{9BAE13A2-E7AF-D6C3-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 MFC (x86) WinSXS MSM
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{9ECB4705-B9CB-405A-B6D4-33BDF707308E}" = DJ_AIO_Software
"{A2A60894-E3ED-46FE-9A6A-7CF7A87572A0}" = Opera 9.64
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1
"{A9DC9256-709F-4BEA-B39D-4F11D90585AA}" = HP Smart Web Printing
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{ACE22C48-49D7-4531-BE20-5C3D03393AB6}" = F4100_Help
"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4F35A00-24FD-4fb3-BF5E-413D5423434D}" = DJ_AIO_Software_min
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{BAF0296B-77EA-425B-934E-671B4DBAED6E}" = UFile Updater 2007
"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C7EEC93A-2A61-4B1E-B696-A264680A889D}" = MobileMe Control Panel
"{C867F57B-39C1-4341-A164-F569839BCCBF}" = Cards
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{C9967B5A-6E08-4E79-BFBD-BBB07DB0CA04}" = UFile Updater 2008
"{CA50045C-5119-48e7-9BA7-6B317379857A}" = DJ_AIO_Software
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CBFEEA43-2B94-44AF-8325-B413E62D2A5D}" = HP Total Care Advisor
"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{D90AFDE3-3E67-407A-ACA8-F0BAAD012F08}" = Safari
"{DB909A1C-B447-428F-8103-E8975BCB99F0}" = ArcSoft RAW Thumbnail Viewer
"{DC83F417-8068-4074-BA2F-C4F8AB872556}" = DJ_AIO_Software_min
"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{EA01B804-60DA-41ED-80D3-4C7EBB62774A}" = ArcSoft Video Downloader
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F2EC3CA2-1136-45C1-B5AE-AB03DED6E98C}" = Logitech QuickCapture Gadget
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F94234DB-FD06-42C3-B88D-6FC4DC9F988C}" = HP Easy Setup - Core
"{FA8A44D7-3E8A-4034-9C4F-088FA6B72BC4}" = HP Deskjet All-In-One Software 9.0
"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"0C5EDC3653FED5B121F464339EAC12534D253B25" = Windows Driver Package - Nokia Modem (02/15/2007 3.1)
"24894EA20BE8E62AA4FC3DD3AA85785356B52BF5" = Windows Driver Package - Nokia Modem (08/08/2007 3.3)
"4077F884D1BB007055BDB83B621D87220A73F30F" = Windows Driver Package - Nokia (WUDFRd) WPD (06/01/2007 6.84.33.0)
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"aignesamdeadlink" = AM-DeadLink 3.3
"Arthur's Wilderness Rescue" = Arthur's Wilderness Rescue
"ArtistScope Plugin FX4.2.0.3" = ArtistScope Plugin FX
"avast!" = avast! Antivirus
"B726756F5B5A5AA9D798B399386FC6205A45F19E" = Windows Driver Package - Nokia Modem (02/15/2007 3.1)
"BlackBerry_{034E061B-B3A3-4123-842E-10C1B6B3C8C7}" = BlackBerry Desktop Software 4.7
"CD8424B9400BFF7D34AA18F816C71322AC4BDAA7" = Windows Driver Package - Nokia Modem (05/24/2007 6.84.0.1)
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"Color Correction Wizard_is1" = Color Correction Wizard 1.1
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Concord Telephony Translation" = Concord Telephony Translation
"CTIAPI32" = CTIAPI32 (remove only)
"CtiLogC" = CtiLogC (remove only)
"ERUNT_is1" = ERUNT 1.1j
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"Google Updater" = Google Updater
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 9.0
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0
"HPExtendedCapabilities" = HP Customer Participation Program 9.0
"IncrediMail" = IncrediMail
"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"iPhoneRingToneMaker" = iPhoneRingToneMaker 2.5.1
"Jpeg Enhancer_is1" = Jpeg Enhancer 1.8
"JumpStart Advanced 1st Grade" = JumpStart Advanced 1st Grade
"legacyqcam_10.51" = Logitech Legacy USB Camera Driver Package
"Light Artist_is1" = Light Artist 1.5
"LimeWire" = LimeWire 5.0.3
"lvdrivers_11.50" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Movies" = Movies
"Mozilla Firefox (3.0.7)" = Mozilla Firefox (3.0.7)
"Mr. Potato Head's Activity Pack" = Mr. Potato Head Uninstaller
"Ogg Codecs" = Ogg Codecs 0.81.15562
"OsdMaestro" = HP On-Screen Caps/Num/Scroll Lock Indicator
"PhotoFiltre" = PhotoFiltre
"PhotoToolkit_is1" = Photo! Editor 1.0 Beta
"Plazmic CDK 4.7 for BlackBerry" = Plazmic CDK 4.7 for BlackBerry
"RealPlayer 6.0" = RealPlayer
"Red Eye Remover Pro_is1" = Red Eye Remover Pro 1.2
"Rhapsody" = Rhapsody
"Shop for HP Supplies" = Shop for HP Supplies
"Skin Creator" = Skin Creator
"The Game Of Life" = The Game Of Life
"ToneThis" = ToneThis
"VCW VicMan's Photo Editor_is1" = VCW VicMan's Photo Editor 8.1
"WhiteCap" = WhiteCap
"WinLiveSuite_Wave3" = Windows Live Essentials
"Xvid_is1" = Xvid 1.1.3 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar for Internet Explorer
"Yahoo! Toolbar" = Yahoo! Toolbar
"Yahtzeev1" = Yahtzee

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"DNA" = DNA
"Google Chrome" = Google Chrome

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"DNA" = DNA
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 25/05/2008 12:04:31 PM | Computer Name = PeteandAdie-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\100SSCAM\DOLPHIN STATUE BEHIND HOTEL.JPG failed, 00000015.

Error - 25/05/2008 12:10:35 PM | Computer Name = PeteandAdie-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Topaz.JPG failed, 00000015.

Error - 02/10/2008 11:46:29 AM | Computer Name = PeteandAdie-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\Pete&Adie\AppData\Roaming\Mozilla\Firefox\Profiles\4f2g3bpa.default\places.sqlite
failed, 00000005.

Error - 19/10/2008 5:38:44 PM | Computer Name = PeteandAdie-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\Pete&Adie\AppData\Roaming\Mozilla\Firefox\Profiles\4f2g3bpa.default\cookies.sqlite
failed, 00000005.

Error - 20/10/2008 4:05:06 PM | Computer Name = PeteandAdie-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\Pete&Adie\AppData\Roaming\Mozilla\Firefox\Profiles\4f2g3bpa.default\places.sqlite
failed, 00000005.

Error - 09/11/2008 12:30:18 AM | Computer Name = PeteandAdie-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\Pete&Adie\AppData\Roaming\Mozilla\Firefox\Profiles\4f2g3bpa.default\places.sqlite
failed, 00000005.

Error - 09/11/2008 9:22:23 PM | Computer Name = PeteandAdie-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Users\Pete&Adie\AppData\Roaming\Mozilla\Firefox\Profiles\4f2g3bpa.default\places.sqlite
failed, 00000005.

Error - 13/12/2008 9:05:42 AM | Computer Name = PeteandAdie-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\System32\conime.exe failed, 00000005.

Error - 30/12/2008 12:14:01 AM | Computer Name = PeteandAdie-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91\msvcp90.dll
failed, 00000005.

Error - 26/04/2009 1:24:54 PM | Computer Name = PeteandAdie-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\Program Files\Windows Live\Messenger\uxcontacts.dll failed, 00000005.

[ Application Events ]
Error - 05/03/2009 6:56:37 PM | Computer Name = PeteandAdie-PC | Source = Sound Recorder | ID = 65535
Description =

Error - 05/03/2009 6:56:37 PM | Computer Name = PeteandAdie-PC | Source = Sound Recorder | ID = 65535
Description =

Error - 05/03/2009 6:56:37 PM | Computer Name = PeteandAdie-PC | Source = Sound Recorder | ID = 65535
Description =

Error - 05/03/2009 6:56:37 PM | Computer Name = PeteandAdie-PC | Source = Sound Recorder | ID = 65535
Description =

Error - 05/03/2009 6:56:37 PM | Computer Name = PeteandAdie-PC | Source = Sound Recorder | ID = 65535
Description =

Error - 05/03/2009 6:56:37 PM | Computer Name = PeteandAdie-PC | Source = Sound Recorder | ID = 65535
Description =

Error - 05/03/2009 6:56:37 PM | Computer Name = PeteandAdie-PC | Source = Sound Recorder | ID = 65535
Description =

Error - 05/03/2009 6:56:38 PM | Computer Name = PeteandAdie-PC | Source = Sound Recorder | ID = 65535
Description =

Error - 05/03/2009 6:56:38 PM | Computer Name = PeteandAdie-PC | Source = Sound Recorder | ID = 65535
Description =

Error - 05/03/2009 6:56:38 PM | Computer Name = PeteandAdie-PC | Source = Sound Recorder | ID = 65535
Description =

[ OSession Events ]
Error - 24/05/2008 4:11:16 PM | Computer Name = PeteandAdie-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6300.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1055077
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 24/04/2009 3:26:38 PM | Computer Name = PeteandAdie-PC | Source = DCOM | ID = 10010
Description =

Error - 24/04/2009 3:51:34 PM | Computer Name = PeteandAdie-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 24/04/2009 3:51:40 PM | Computer Name = PeteandAdie-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 24/04/2009 3:52:05 PM | Computer Name = PeteandAdie-PC | Source = HTTP | ID = 15016
Description =

Error - 26/04/2009 1:18:08 AM | Computer Name = PeteandAdie-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 26/04/2009 1:18:14 AM | Computer Name = PeteandAdie-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 26/04/2009 1:18:34 AM | Computer Name = PeteandAdie-PC | Source = HTTP | ID = 15016
Description =

Error - 26/04/2009 12:51:58 PM | Computer Name = PeteandAdie-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 26/04/2009 12:52:06 PM | Computer Name = PeteandAdie-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 26/04/2009 12:52:19 PM | Computer Name = PeteandAdie-PC | Source = HTTP | ID = 15016
Description =


< End of report >
OTListIt logfile created on: 26/04/2009 6:14:02 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Users\Pete&Adie\Desktop
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 1.13 Gb Available Physical Memory | 56.98% Memory free
4.00 Gb Paging File | 2.67 Gb Available in Paging File | 66.65% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 141.96 Gb Total Space | 78.12 Gb Free Space | 55.03% Space Free | Partition Type: NTFS
Drive D: | 7.09 Gb Total Space | 0.88 Gb Free Space | 12.41% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 76.32 Gb Total Space | 58.00 Gb Free Space | 76.00% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PETEANDADIE-PC
Current User Name: Pete&Adie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2007/10/19 14:19:22 | 00,141,848 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009/02/05 14:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 14:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2008/11/19 10:47:24 | 00,109,056 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009/03/06 00:04:30 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/12/12 12:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2009/03/20 13:26:16 | 00,266,240 | —- | M] () – C:\Windows\system32\CSHelper.exe
PRC - [2006/12/14 19:49:10 | 00,061,440 | —- | M] (Hewlett-Packard Company) – c:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2007/10/19 14:17:28 | 00,186,904 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2009/01/14 17:53:02 | 00,226,656 | —- | M] (Microsoft Corp.) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2007/10/18 07:37:04 | 00,386,560 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\xaudio.exe
PRC - [2009/02/05 14:08:26 | 00,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/02/05 14:06:04 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2008/10/09 07:56:48 | 00,094,208 | —- | M] (Hewlett-Packard) – c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
PRC - [2007/10/19 14:17:28 | 00,186,904 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2009/02/22 14:45:54 | 02,272,592 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
PRC - [2008/10/29 00:29:41 | 02,927,104 | —- | M] (Microsoft Corporation) – C:\Windows\Explorer.EXE
PRC - [2008/01/19 01:38:38 | 01,008,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2006/09/28 07:42:24 | 00,065,536 | —- | M] (Hewlett-Packard Company) – C:\hp\support\hpsysdrv.exe
PRC - [2006/11/20 05:34:52 | 00,155,648 | —- | M] (OsdMaestro) – C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
PRC - [2008/01/15 12:26:18 | 04,874,240 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
PRC - [2007/05/08 16:24:20 | 00,054,840 | —- | M] (Hewlett-Packard) – C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
PRC - [2006/11/02 06:34:44 | 00,176,128 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wpcumi.exe
PRC - [2007/10/25 17:37:32 | 02,178,832 | —- | M] () – C:\Program Files\Logitech\QuickCam\Quickcam.exe
PRC - [2009/03/02 20:16:04 | 00,247,296 | —- | M] (Microsoft Corporation) – C:\Windows\system32\wbem\wmiprvse.exe
PRC - [2007/10/25 17:33:22 | 00,563,984 | —- | M] () – C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2008/05/21 12:19:24 | 00,143,360 | —- | M] () – C:\Program Files\HiYo\Bin\HiYo.exe
PRC - [2008/04/01 14:41:10 | 00,166,424 | —- | M] (Intel Corporation) – C:\Windows\System32\hkcmd.exe
PRC - [2008/04/01 14:41:26 | 00,133,656 | —- | M] (Intel Corporation) – C:\Windows\System32\igfxpers.exe
PRC - [2008/11/20 11:06:14 | 00,178,688 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2008/04/01 14:41:30 | 00,256,536 | —- | M] (Intel Corporation) – C:\Windows\system32\igfxsrvc.exe
PRC - [2008/11/04 13:09:58 | 00,615,696 | —- | M] (Research In Motion Limited) – C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
PRC - [2009/02/05 14:08:45 | 00,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2008/01/19 01:33:39 | 00,202,240 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2009/04/02 16:11:02 | 00,342,312 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/03/09 05:19:17 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008/01/19 01:33:39 | 00,896,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe
PRC - [2008/01/19 01:33:30 | 01,233,920 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Sidebar\sidebar.exe
PRC - [2006/11/23 18:53:24 | 01,480,296 | —- | M] (Hewlett-Packard) – C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
PRC - [2008/01/19 01:33:33 | 00,037,888 | —- | M] (Microsoft Corporation) – C:\Windows\system32\wbem\unsecapp.exe
PRC - [2008/09/08 18:43:11 | 00,133,104 | —- | M] (Google Inc.) – C:\Users\Pete&Adie\AppData\Local\Google\Update\GoogleUpdate.exe
PRC - [2008/03/06 13:42:51 | 00,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/02/19 14:23:24 | 00,202,064 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe
PRC - [2007/03/11 21:26:24 | 00,210,520 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
PRC - [2008/01/09 13:32:08 | 00,789,008 | —- | M] (Logitech, Inc.) – C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2009/02/06 18:51:28 | 03,885,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Messenger\msnmsgr.exe
PRC - [2008/01/19 01:33:30 | 01,233,920 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Sidebar\sidebar.exe
PRC - [2009/02/02 13:45:56 | 00,189,824 | —- | M] (IncrediMail, Ltd.) – C:\Program Files\IncrediMail\bin\IMApp.exe
PRC - [2007/10/25 17:32:58 | 00,407,824 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
PRC - [2007/03/11 21:32:42 | 00,151,552 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
PRC - [2009/04/02 16:10:56 | 00,656,168 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe
PRC - [2008/06/19 19:14:44 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
PRC - [2008/01/19 01:33:04 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\system32\conime.exe
PRC - [2009/03/02 20:16:04 | 00,247,296 | —- | M] (Microsoft Corporation) – C:\Windows\system32\wbem\wmiprvse.exe
PRC - [2006/10/30 20:59:14 | 00,505,520 | —- | M] (Symantec Corporation) – C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe
PRC - [2005/02/02 09:44:24 | 00,061,440 | —- | M] (Hewlett-Packard Company) – C:\hp\kbd\kbd.exe
PRC - [2009/04/26 18:11:19 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Users\Pete&Adie\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/11/19 10:47:24 | 00,109,056 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon [Auto | Running])
SRV - [2008/01/19 01:33:43 | 00,052,224 | —- | M] (Microsoft Corporation) – C:\Windows\system32\inetsrv\apphostsvc.dll – (AppHostSvc [Auto | Running])
SRV - [2009/03/06 00:04:30 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - [2009/02/05 14:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv [Auto | Running])
SRV - [2009/02/05 14:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus [Auto | Running])
SRV - [2009/02/05 14:08:26 | 00,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/02/05 14:06:04 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner [On_Demand | Running])
SRV - [2008/12/12 12:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe – (Bonjour Service [Auto | Running])
SRV - [2008/07/27 12:03:13 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - File not found – – (CLTNetCnService [Auto | Stopped])
SRV - [2009/03/20 13:26:16 | 00,266,240 | —- | M] () – C:\Windows\system32\CSHelper.exe – (CSHelper [Auto | Running])
SRV - [2008/06/19 19:14:44 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Running])
SRV - [2009/03/25 15:28:42 | 00,183,280 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [Auto | Stopped])
SRV - [2008/10/09 07:56:48 | 00,094,208 | —- | M] (Hewlett-Packard) – c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe – (HP Health Check Service [Auto | Running])
SRV - [2007/06/04 22:14:50 | 00,217,088 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcxs08.dll – (hpqcxs08 [On_Demand | Running])
SRV - [2007/06/04 22:14:50 | 00,131,072 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqddsvc.dll – (hpqddsvc [Auto | Running])
SRV - [2004/10/22 05:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/06/19 19:14:31 | 00,881,664 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2009/04/02 16:10:56 | 00,656,168 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
SRV - [2006/11/02 03:46:05 | 00,017,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\irmon.dll – (Irmon [Auto | Running])
SRV - [2008/01/09 13:30:08 | 00,121,360 | —- | M] (Logitech, Inc.) – C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe – (LBTServ [On_Demand | Stopped])
SRV - [2006/12/14 19:49:10 | 00,061,440 | —- | M] (Hewlett-Packard Company) – c:\Program Files\Common Files\LightScribe\LSSrvc.exe – (LightScribeService [Auto | Running])
SRV - [2008/01/19 01:34:43 | 00,035,328 | —- | M] (Microsoft Corporation) – C:\Windows\system32\lpdsvc.dll – (LPDSVC [Auto | Running])
SRV - [2007/10/19 14:17:28 | 00,186,904 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe – (LVCOMSer [Auto | Running])
SRV - [2007/10/19 14:19:22 | 00,141,848 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv [Auto | Running])
SRV - [2007/10/19 14:21:16 | 00,141,848 | —- | M] (Logitech Inc.) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe – (LVSrvLauncher [Auto | Stopped])
SRV - [2006/12/14 02:21:20 | 00,045,056 | —- | M] (Sony Corporation) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe – (MSCSPTISRV [On_Demand | Stopped])
SRV - [2006/11/08 16:35:36 | 00,043,520 | —- | M] (Hewlett-Packard) – C:\Windows\system32\HPZinw12.dll – (Net Driver HPZ12 [Auto | Running])
SRV - [2008/06/19 19:14:31 | 00,132,096 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/08/24 04:19:12 | 00,443,776 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 16:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2006/12/14 01:46:16 | 00,057,344 | —- | M] () – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe – (PACSPTISVR [On_Demand | Stopped])
SRV - [2006/11/08 16:35:38 | 00,053,248 | —- | M] (Hewlett-Packard) – C:\Windows\system32\HPZipm12.dll – (Pml Driver HPZ12 [Auto | Running])
SRV - [2009/01/14 17:53:02 | 00,226,656 | —- | M] (Microsoft Corp.) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort [Auto | Running])
SRV - [2007/06/15 16:55:00 | 00,300,544 | —- | M] (Nokia.) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe – (ServiceLayer [On_Demand | Stopped])
SRV - [2006/12/14 02:02:08 | 00,069,632 | —- | M] (Sony Corporation) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe – (SPTISRV [On_Demand | Stopped])
SRV - [2006/11/01 13:58:02 | 00,078,752 | R— | M] (MicroVision Development, Inc.) – c:\Program Files\Common Files\SureThing Shared\stllssvr.exe – (stllssvr [On_Demand | Stopped])
SRV - [2008/01/19 01:34:32 | 00,371,200 | —- | M] (Microsoft Corporation) – C:\Windows\system32\inetsrv\iisw3adm.dll – (W3SVC [Auto | Running])
SRV - [2008/01/19 01:34:32 | 00,371,200 | —- | M] (Microsoft Corporation) – C:\Windows\system32\inetsrv\iisw3adm.dll – (WAS [On_Demand | Running])
SRV - [2008/01/19 01:38:24 | 00,272,952 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\mpsvc.dll – (WinDefend [Auto | Running])
SRV - [2008/01/19 01:33:39 | 00,896,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Running])
SRV - [2007/10/18 07:37:04 | 00,386,560 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\xaudio.exe – (XAudioService [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2006/11/02 03:51:38 | 00,420,968 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx [Disabled | Stopped])
DRV - [2006/11/02 03:51:32 | 00,297,576 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adpahci.sys – (adpahci [Disabled | Stopped])
DRV - [2006/11/02 03:50:35 | 00,098,408 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m [Disabled | Stopped])
DRV - [2006/11/02 03:51:00 | 00,147,048 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adpu320.sys – (adpu320 [Disabled | Stopped])
DRV - [2006/11/02 03:50:11 | 00,071,272 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\djsvs.sys – (aic78xx [Disabled | Stopped])
DRV - [2006/11/02 03:49:20 | 00,014,952 | —- | M] (Acer Laboratories Inc.) – C:\Windows\system32\drivers\aliide.sys – (aliide [Disabled | Stopped])
DRV - [2006/11/02 03:50:09 | 00,067,688 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\arc.sys – (arc [Disabled | Stopped])
DRV - [2006/11/02 03:50:10 | 00,067,688 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\arcsas.sys – (arcsas [Disabled | Stopped])
DRV - [2009/02/05 14:07:12 | 00,020,560 | —- | M] (ALWIL Software) – C:\Windows\system32\DRIVERS\aswFsBlk.sys – (aswFsBlk [Auto | Running])
DRV - [2009/02/05 14:06:59 | 00,051,792 | —- | M] (ALWIL Software) – C:\Windows\system32\DRIVERS\aswMonFlt.sys – (aswMonFlt [Auto | Running])
DRV - [2009/02/05 14:06:10 | 00,023,152 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys – (aswRdr [System | Running])
DRV - [2009/02/05 14:07:23 | 00,114,768 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys – (aswSP [System | Running])
DRV - [2009/02/05 14:06:20 | 00,051,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys – (aswTdi [System | Running])
DRV - [2006/11/02 02:24:45 | 00,013,568 | —- | M] (Brother Industries, Ltd.) – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo [On_Demand | Stopped])
DRV - [2006/11/02 02:24:46 | 00,005,248 | —- | M] (Brother Industries, Ltd.) – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp [On_Demand | Stopped])
DRV - [2006/11/02 02:25:24 | 00,071,808 | —- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brserid.sys – (Brserid [Disabled | Stopped])
DRV - [2006/11/02 02:24:44 | 00,062,336 | —- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm [Disabled | Stopped])
DRV - [2006/11/02 02:24:44 | 00,012,160 | —- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm [Disabled | Stopped])
DRV - [2006/11/02 02:24:47 | 00,011,904 | —- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer [On_Demand | Stopped])
DRV - [2006/11/02 03:49:28 | 00,016,488 | —- | M] (CMD Technology, Inc.) – C:\Windows\system32\drivers\cmdide.sys – (cmdide [Disabled | Stopped])
DRV - [2006/11/02 01:30:54 | 00,117,760 | —- | M] (Intel Corporation) – C:\Windows\system32\DRIVERS\E1G60I32.sys – (E1G60 [On_Demand | Stopped])
DRV - [2006/11/02 03:51:34 | 00,316,520 | —- | M] (Emulex) – C:\Windows\system32\drivers\elxstor.sys – (elxstor [Disabled | Stopped])
DRV - [2009/03/19 16:32:48 | 00,023,400 | —- | M] (GEAR Software Inc.) – C:\Windows\system32\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [2006/11/02 03:50:10 | 00,037,480 | —- | M] (Hewlett-Packard Company) – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs [Disabled | Stopped])
DRV - [2008/05/08 05:03:18 | 00,980,992 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\HSX_DP.sys – (HSF_DP [On_Demand | Running])
DRV - [2008/05/08 05:05:18 | 00,266,752 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\HSXHWBS2.sys – (HSXHWBS2 [On_Demand | Running])
DRV - [2006/11/02 03:51:25 | 00,232,040 | —- | M] (Intel Corporation) – C:\Windows\system32\drivers\iastorv.sys – (iaStorV [Disabled | Stopped])
DRV - [2008/03/25 09:44:24 | 02,307,072 | —- | M] (Intel Corporation) – C:\Windows\system32\DRIVERS\igdkmd32.sys – (igfx [On_Demand | Running])
DRV - [2006/11/02 03:50:17 | 00,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) – C:\Windows\system32\drivers\iirsp.sys – (iirsp [Disabled | Stopped])
DRV - [2008/01/15 20:19:04 | 02,047,576 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\system32\drivers\RTKVHDA.sys – (IntcAzAudAddService [On_Demand | Running])
DRV - [2008/01/18 23:55:21 | 00,020,992 | —- | M] (Microsoft Corporation) – C:\Windows\system32\DRIVERS\irsir.sys – (irsir [On_Demand | Stopped])
DRV - [2006/11/02 03:50:07 | 00,035,944 | —- | M] (Integrated Technology Express, Inc.) – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi [Disabled | Stopped])
DRV - [2006/11/02 03:50:09 | 00,035,944 | —- | M] (Integrated Technology Express, Inc.) – C:\Windows\system32\drivers\iteraid.sys – (iteraid [Disabled | Stopped])
DRV - [2007/04/11 15:32:30 | 00,020,496 | —- | M] (Logitech Inc.) – C:\Windows\system32\DRIVERS\L8042Kbd.sys – (L8042Kbd [On_Demand | Stopped])
DRV - [2007/11/29 03:17:34 | 00,063,120 | —- | M] (Logitech, Inc.) – C:\Windows\system32\DRIVERS\L8042mou.Sys – (L8042mou [On_Demand | Stopped])
DRV - [2007/11/29 03:17:48 | 00,035,088 | —- | M] (Logitech, Inc.) – C:\Windows\system32\DRIVERS\LHidFilt.Sys – (LHidFilt [On_Demand | Running])
DRV - [2007/11/29 03:17:56 | 00,036,368 | —- | M] (Logitech, Inc.) – C:\Windows\system32\DRIVERS\LMouFilt.Sys – (LMouFilt [On_Demand | Running])
DRV - [2007/11/29 03:18:04 | 00,078,992 | —- | M] (Logitech, Inc.) – C:\Windows\system32\DRIVERS\LMouKE.Sys – (LMouKE [On_Demand | Stopped])
DRV - [2006/11/02 03:50:04 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC [Disabled | Stopped])
DRV - [2006/11/02 03:50:05 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS [Disabled | Stopped])
DRV - [2006/11/02 03:50:10 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI [Disabled | Stopped])
DRV - [2007/04/11 15:33:14 | 00,028,688 | —- | M] (Logitech, Inc.) – C:\Windows\System32\Drivers\LUsbFilt.Sys – (LUsbFilt [On_Demand | Stopped])
DRV - [2007/10/19 14:16:30 | 02,109,976 | —- | M] (Logitech Inc.) – C:\Windows\system32\DRIVERS\LVcKap.sys – (LVcKap [On_Demand | Stopped])
DRV - [2007/10/11 19:59:02 | 02,142,488 | —- | M] (Logitech Inc.) – C:\Windows\system32\DRIVERS\LVMVDrv.sys – (LVMVDrv [On_Demand | Stopped])
DRV - [2007/10/11 19:59:24 | 00,025,624 | —- | M] () – C:\Windows\system32\DRIVERS\LVPr2Mon.sys – (LVPr2Mon [On_Demand | Running])
DRV - [2007/10/11 20:00:42 | 00,041,752 | —- | M] (Logitech Inc.) – C:\Windows\system32\drivers\LVUSBSta.sys – (LVUSBSta [On_Demand | Running])
DRV - [2006/06/19 08:26:58 | 00,012,672 | —- | M] (Conexant) – C:\Windows\system32\DRIVERS\mdmxsdk.sys – (mdmxsdk [Auto | Running])
DRV - [2006/11/02 03:49:53 | 00,028,776 | —- | M] (LSI Logic Corporation) – C:\Windows\system32\drivers\megasas.sys – (megasas [Disabled | Stopped])
DRV - [2007/06/18 20:18:26 | 00,023,680 | —- | M] (Motorola) – C:\Windows\system32\DRIVERS\motmodem.sys – (motmodem [On_Demand | Stopped])
DRV - [2006/11/02 03:49:59 | 00,033,384 | —- | M] (LSI Logic Corporation) – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x [Disabled | Stopped])
DRV - [2006/11/02 03:50:19 | 00,045,160 | —- | M] (IBM Corporation) – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960 [Disabled | Stopped])
DRV - [2006/11/02 01:36:50 | 00,020,608 | —- | M] (N-trig Innovative Technologies) – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi [Disabled | Stopped])
DRV - [2006/11/02 03:50:24 | 00,088,680 | —- | M] (NVIDIA Corporation) – C:\Windows\system32\drivers\nvraid.sys – (nvraid [Disabled | Stopped])
DRV - [2006/11/02 03:50:13 | 00,040,040 | —- | M] (NVIDIA Corporation) – C:\Windows\system32\drivers\nvstor.sys – (nvstor [Disabled | Stopped])
DRV - [2007/10/11 19:56:20 | 00,490,776 | —- | M] (Logitech Inc.) – C:\Windows\system32\DRIVERS\LV561AV.SYS – (PID_0928 [On_Demand | Running])
DRV - [2005/12/12 10:27:00 | 00,019,072 | —- | M] (Hewlett-Packard Company) – C:\Windows\system32\DRIVERS\PS2.sys – (Ps2 [On_Demand | Running])
DRV - [2006/07/24 05:00:00 | 00,036,528 | —- | M] (Sonic Solutions) – C:\Windows\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2006/11/02 03:51:45 | 00,900,712 | —- | M] (QLogic Corporation) – C:\Windows\system32\drivers\ql2300.sys – (ql2300 [Disabled | Stopped])
DRV - [2006/11/02 03:50:35 | 00,106,088 | —- | M] (QLogic Corporation) – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx [Disabled | Stopped])
DRV - [2008/09/10 18:47:24 | 00,031,104 | —- | M] (Research In Motion Limited) – C:\Windows\System32\Drivers\BlackBerrySCRDriver.sys – (Rim [On_Demand | Stopped])
DRV - [2008/05/20 20:33:50 | 00,022,784 | —- | M] (Research In Motion Limited) – C:\Windows\System32\Drivers\RimUsb.sys – (RimUsb [On_Demand | Stopped])
DRV - [2007/01/18 10:24:58 | 00,026,496 | —- | M] (Research in Motion Ltd) – C:\Windows\system32\DRIVERS\RimSerial.sys – (RimVSerPort [On_Demand | Running])
DRV - [2008/01/18 23:57:15 | 00,008,192 | —- | M] (Microsoft Corporation) – C:\Windows\System32\Drivers\RootMdm.sys – (ROOTMODEM [On_Demand | Running])
DRV - [2008/12/23 04:47:52 | 00,138,240 | —- | M] (Realtek Corporation ) – C:\Windows\system32\DRIVERS\Rtlh86.sys – (RTL8169 [On_Demand | Running])
DRV - [2006/11/02 00:37:21 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\Windows\System32\drivers\secdrv.sys – (secdrv [Auto | Running])
DRV - [2006/11/02 03:50:10 | 00,038,504 | —- | M] (Silicon Integrated Systems Corp.) – C:\Windows\system32\drivers\sisraid2.sys – (SiSRaid2 [Disabled | Stopped])
DRV - [2006/11/02 03:50:16 | 00,071,784 | —- | M] (Silicon Integrated Systems) – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4 [Disabled | Stopped])
DRV - [2006/11/02 03:50:05 | 00,035,944 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx [Disabled | Stopped])
DRV - [2006/11/02 03:49:56 | 00,031,848 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi [Disabled | Stopped])
DRV - [2006/11/02 03:50:03 | 00,034,920 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3 [Disabled | Stopped])
DRV - [2006/11/02 03:51:25 | 00,235,112 | —- | M] (ULi Electronics Inc.) – C:\Windows\system32\drivers\uliahci.sys – (uliahci [Disabled | Stopped])
DRV - [2006/11/02 03:50:35 | 00,098,408 | —- | M] (Promise Technology, Inc.) – C:\Windows\system32\drivers\ulsata.sys – (UlSata [Disabled | Stopped])
DRV - [2006/11/02 03:50:45 | 00,115,816 | —- | M] (Promise Technology, Inc.) – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2 [Disabled | Stopped])
DRV - [2008/11/07 15:23:30 | 00,032,000 | —- | M] (Apple, Inc.) – C:\Windows\System32\Drivers\usbaapl.sys – (USBAAPL [On_Demand | Stopped])
DRV - [2006/11/02 03:49:30 | 00,017,512 | —- | M] (VIA Technologies, Inc.) – C:\Windows\system32\drivers\viaide.sys – (viaide [Disabled | Stopped])
DRV - [2006/11/02 03:50:41 | 00,112,232 | —- | M] (VIA Technologies Inc.,Ltd) – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid [Disabled | Stopped])
DRV - [2006/11/02 01:41:53 | 00,251,904 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\VSTBS23.SYS – (VSTHWBS2 [On_Demand | Stopped])
DRV - [2006/11/02 01:41:50 | 00,987,648 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\VSTDPV3.SYS – (VST_DPV [On_Demand | Stopped])
DRV - [2008/05/08 05:04:16 | 00,661,504 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\HSX_CNXT.sys – (winachsf [On_Demand | Running])
DRV - [2007/10/18 07:36:54 | 00,008,704 | —- | M] (Conexant Systems, Inc.) – C:\Windows\system32\DRIVERS\xaudio.sys – (XAudio [Auto | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop


IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://sympatico.msn.ca/?lang=en-CA&OCID=FW69157
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 68 A8 12 1E 2D C6 C9 01 [binary data]
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\S-1-5-21-961656175-201489447-2584037788-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-961656175-201489447-2584037788-1000\S-1-5-21-961656175-201489447-2584037788-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Live Search"
FF - prefs.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=IEFM1&q="
FF - prefs.js..browser.search.selectedEngine: "Yahoo Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.ca/ig?hl=en"
FF - prefs.js..extensions.enabledItems: {f02289b7-b23a-49b1-a7da-b60880e69629}:1.300.199
FF - prefs.js..extensions.enabledItems: [removed]:0.8.1
FF - prefs.js..extensions.enabledItems: {47624dda-b77e-4feb-820a-e4f077d5d4ca}:9.3.2
FF - prefs.js..extensions.enabledItems: [removed]:1.1.1
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:3.9.1
FF - prefs.js..extensions.enabledItems: [removed]:1.10
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:2.7.4
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.2
FF - prefs.js..extensions.enabledItems: {249df6a2-e336-47d1-b6c3-ec711ad140ca}:0.4.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.2.1
FF - prefs.js..extensions.enabledItems: {62760FD6-B943-48C9-AB09-F99C6FE96088}:1.6.11
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:0.9.9
FF - prefs.js..extensions.enabledItems: {463F6CA5-EE3C-4be1-B7E6-7FEE11953374}:3.0.4
FF - prefs.js..extensions.enabledItems: {469CEB59-8266-438b-91D9-82F56D595E15}:2.3
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.7
FF - prefs.js..extensions.enabledItems: [removed]:2.0.2
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.29
FF - prefs.js..extensions.enabledItems: [removed]:3.6.0
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:2.1.5
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.9
FF - prefs.js..extensions.enabledItems: {BB359C50-BFC9-4f40-8302-3FE5A499A859}:3.2
FF - prefs.js..extensions.enabledItems: {55c25c30-73c7-11dd-ad8b-0800200c9a66}:2.9.1
FF - prefs.js..extensions.enabledItems: {66871bd1-5ba2-4739-b485-2a15f5969bd8}:2.081108
FF - prefs.js..extensions.enabledItems: {BF32D2C8-9C75-404b-ACF4-880DB4679236}:1.1
FF - prefs.js..extensions.enabledItems: [removed]:0.6.20090322
FF - prefs.js..extensions.enabledItems: {a02c0c70-605c-11da-8cd6-0800200c9a66}:4.08
FF - prefs.js..extensions.enabledItems: {5f0a19e0-2921-11dd-bd0b-0800200c9a66}:1.00.49
FF - prefs.js..extensions.enabledItems: {ff356687-aa08-463d-a46c-11c451824939}:[removed]
FF - prefs.js..extensions.enabledItems: {F587B2D4-7C09-4a23-AC4A-8D6E3CE8C7DA}:3.2
FF - prefs.js..extensions.enabledItems: {33A8946C-B859-4f7d-8382-ADAB29623DEE}:3.2
FF - prefs.js..extensions.enabledItems: [removed]:1.5.1
FF - prefs.js..extensions.enabledItems: {285da7e0-729d-11db-9fe1-0800200c9a66}:2.121408
FF - prefs.js..extensions.enabledItems: {C288E3D6-3588-4b60-BD4A-7413899D269B}:1.1
FF - prefs.js..keyword.URL: "http://search.freecause.com/search?fr=freecause&ourmark=3&type=56939&ei=utf-8&yahoo_domain=search.yahoo.com&p="

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON2 [2008/09/10 21:28:16 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD [2008/10/04 15:21:05 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/03/14 15:21:57 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/23 08:52:34 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/23 08:52:34 | 00,000,000 | —D | M]

[2008/12/25 11:49:18 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Extensions
[2008/08/26 09:06:59 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008/12/25 11:49:18 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Extensions\[removed]
[2009/04/26 16:38:51 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions
[2009/04/17 10:27:37 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2009/03/27 12:58:50 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2009/04/10 22:39:36 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{249df6a2-e336-47d1-b6c3-ec711ad140ca}
[2008/12/21 13:07:43 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{285da7e0-729d-11db-9fe1-0800200c9a66}
[2009/01/06 22:31:51 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/03/24 12:56:58 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{33A8946C-B859-4f7d-8382-ADAB29623DEE}
[2008/07/30 20:46:08 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2009/03/19 22:19:28 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{469CEB59-8266-438b-91D9-82F56D595E15}
[2009/03/19 22:19:25 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{47624dda-b77e-4feb-820a-e4f077d5d4ca}
[2008/10/15 19:31:10 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{55c25c30-73c7-11dd-ad8b-0800200c9a66}
[2008/09/19 09:50:34 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{5f0a19e0-2921-11dd-bd0b-0800200c9a66}
[2009/04/24 13:12:19 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}
[2008/09/15 18:15:54 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}(300)
[2008/08/26 09:10:06 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{66871bd1-5ba2-4739-b485-2a15f5969bd8}
[2008/10/20 10:30:06 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}
[2009/04/24 13:12:16 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2009/03/22 11:08:43 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{BB359C50-BFC9-4f40-8302-3FE5A499A859}
[2008/03/07 08:42:34 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{BB359C50-BFC9-4f40-8302-3FE5A499A859}(139)
[2009/02/17 19:43:33 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{BF32D2C8-9C75-404b-ACF4-880DB4679236}
[2008/12/09 15:01:58 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{C288E3D6-3588-4b60-BD4A-7413899D269B}
[2009/04/21 17:31:35 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2009/03/24 14:25:25 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/03/20 13:27:32 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{f02289b7-b23a-49b1-a7da-b60880e69629}
[2009/03/24 12:56:40 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{F587B2D4-7C09-4a23-AC4A-8D6E3CE8C7DA}
[2008/03/07 08:42:38 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{F587B2D4-7C09-4a23-AC4A-8D6E3CE8C7DA}(140)
[2008/09/16 13:33:54 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb}(301)
[2009/03/26 08:51:04 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{ff356687-aa08-463d-a46c-11c451824939}
[2009/01/29 10:13:55 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/11/10 23:35:59 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2009/04/24 13:12:19 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/09/12 10:06:15 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/12/23 10:46:55 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2009/03/16 21:22:32 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/11/18 19:32:57 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/10/15 19:32:47 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2009/03/27 12:57:32 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/09/10 20:06:57 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2009/04/17 10:27:31 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2009/04/17 10:27:31 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]-trash
[2008/09/16 11:32:03 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\pink-bee@loic(299).com
[2009/02/14 22:39:52 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/10/15 19:30:27 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/11/18 19:32:57 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]
[2008/11/18 19:32:56 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\[removed]\chrome
[2009/03/24 12:57:07 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{33A8946C-B859-4f7d-8382-ADAB29623DEE}\chrome\mozapps\extensions
[2009/03/23 19:06:43 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}\chrome\mozapps\extensions
[2009/03/22 11:08:48 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{BB359C50-BFC9-4f40-8302-3FE5A499A859}\chrome\mozapps\extensions
[2009/03/24 12:56:45 | 00,000,000 | —D | M] – C:\Users\Pete&Adie\AppData\Roaming\mozilla\Firefox\Profiles\4f2g3bpa.default\extensions\{F587B2D4-7C09-4a23-AC4A-8D6E3CE8C7DA}\chrome\mozapps\extensions
[2008/12/23 20:19:23 | 00,001,632 | —- | M] () – C:\Users\Pete&Adie\AppData\Roaming\Mozilla\FireFox\Profiles\4f2g3bpa.default\searchplugins\live-search.xml
[2008/09/21 18:18:20 | 00,002,137 | —- | M] () – C:\Users\Pete&Adie\AppData\Roaming\Mozilla\FireFox\Profiles\4f2g3bpa.default\searchplugins\MyStart Search.xml
[2009/03/20 20:09:04 | 00,000,872 | —- | M] () – C:\Users\Pete&Adie\AppData\Roaming\Mozilla\FireFox\Profiles\4f2g3bpa.default\searchplugins\yahoo.gif
[2009/03/20 20:09:04 | 00,000,466 | —- | M] () – C:\Users\Pete&Adie\AppData\Roaming\Mozilla\FireFox\Profiles\4f2g3bpa.default\searchplugins\yahoo.src
[2009/03/20 20:09:04 | 00,001,767 | —- | M] () – C:\Users\Pete&Adie\AppData\Roaming\Mozilla\FireFox\Profiles\4f2g3bpa.default\searchplugins\yahoo.xml
[2009/04/10 11:00:51 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/23 08:52:34 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/03/14 11:59:33 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/07/14 11:03:55 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2008/11/01 22:01:42 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2009/03/05 23:49:46 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/04/10 11:00:51 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/23 08:52:30 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/23 08:52:30 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/02/19 13:33:08 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/02/19 13:33:08 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/02/19 13:33:08 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/02/19 13:33:08 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/02/19 13:33:08 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/02/19 13:33:08 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/02/19 13:33:08 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\Program Files\ArcSoft\Video Downloader\ArcURLRecord.dll (ArcSoft, Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Click-to-Call BHO) - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll (Microsoft Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background (Research In Motion Limited)
O4 - HKLM..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup ()
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [KBD] C:\HP\KBD\KbdStub.EXE ()
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE (Logitech, Inc.)
O4 - HKLM..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide ()
O4 - HKLM..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" (OsdMaestro)
O4 - HKLM..\Run: [Persistence] C:\Windows\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RtHDVCpl] RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-18..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Microsoft Corporation)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [Google Update] "C:\Users\Pete&Adie\AppData\Local\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Hewlett-Packard)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c (IncrediMail, Ltd.)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe ()
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [SmartRAM] "C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe" /m (IObit)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-961656175-201489447-2584037788-1000..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe (soft thinks)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: IE Theme Search Bar - {323AF0A7-690A-47D9-819B-348831CC7DC5} - C:\Program Files\IECustomizer.com\IEButtons\SearchIECThemes.htm ()
O9 - Extra 'Tools' menuitem : Free Themes for Internet Explorer - {323AF0A7-690A-47D9-819B-348831CC7DC5} - C:\Program Files\IECustomizer.com\IEButtons\SearchIECThemes.htm ()
O9 - Extra 'Tools' menuitem : Online Themes Gallery - {472A296E-D7C1-4A70-8511-5039B09EBDDB} - File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Themes - {B9844E33-6201-47AA-B30A-BCA3363C2BFA} - C:\Program Files\IECustomizer.com\Tools\IETheme.exe (Eye Can Publishing)
O9 - Extra 'Tools' menuitem : Themes - {B9844E33-6201-47AA-B30A-BCA3363C2BFA} - C:\Program Files\IECustomizer.com\Tools\IETheme.exe (Eye Can Publishing)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Windows\system32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-961656175-201489447-2584037788-1000\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Reg Error: Value error.)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/webgames/popcaploader_v10.cab (PopCapLoader Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\SYSTEM32\igfxdev.dll (Intel Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 00,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{d0380e54-b893-11dc-88ea-001921f5f9ba}\Shell - "" = AutoRun
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\Windows\*.tmp files]
[2009/04/26 18:11:06 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Users\Pete&Adie\Desktop\OTListIt2.exe
[2009/04/25 23:20:44 | 00,000,000 | —D | C] – C:\Users\Pete&Adie\AppData\Local\Apple Computer
[2009/04/24 15:23:20 | 00,000,000 | —D | C] – C:\Users\Pete&Adie\AppData\Roaming\Composer
[2009/04/21 11:11:40 | 00,000,000 | —D | C] – C:\Users\Pete&Adie\AppData\Roaming\Malwarebytes
[2009/04/21 11:11:34 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/04/21 11:11:30 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/04/21 11:11:27 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/04/21 11:11:26 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/18 12:26:41 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/18 12:24:49 | 00,000,000 | —D | C] – C:\Windows\ERDNT
[2009/04/18 12:24:28 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/04/18 10:29:08 | 00,026,624 | —- | C] () – C:\Users\Pete&Adie\Documents\Adriennes cleaning schedule.xls
[2009/04/14 20:05:49 | 00,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winhttp.dll
[2009/04/14 20:05:46 | 00,562,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2009/04/14 20:05:46 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xolehlp.dll
[2009/04/14 20:05:33 | 00,551,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpcss.dll
[2009/04/14 20:05:32 | 03,599,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2009/04/14 20:05:31 | 03,547,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2009/04/14 20:05:29 | 00,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2009/04/14 20:05:28 | 00,183,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2009/04/14 20:05:28 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2009/04/14 20:05:28 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2009/04/14 20:05:27 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2009/04/14 20:05:27 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2009/04/14 20:05:27 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashost.exe
[2009/04/14 20:05:16 | 01,255,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2009/04/14 20:05:15 | 00,888,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kernel32.dll
[2009/04/14 20:05:13 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secur32.dll
[2009/04/14 20:05:13 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amxread.dll
[2009/04/14 20:05:13 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apilogen.dll
[2009/04/11 10:32:43 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmled.dll
[2009/04/11 10:32:42 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/04/11 10:32:42 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2009/04/11 10:32:42 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardie.dll
[2009/04/11 10:32:42 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2009/04/11 10:32:40 | 00,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2009/04/11 10:32:40 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/04/11 10:32:40 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2009/04/11 10:32:39 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2009/04/11 10:32:39 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tdc.ocx
[2009/04/11 10:32:39 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/04/11 10:32:38 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/04/11 10:32:38 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2009/04/11 10:32:38 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2009/04/11 10:32:38 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2009/04/11 10:32:37 | 00,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/04/11 10:32:37 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/04/11 10:32:36 | 00,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/04/11 10:32:36 | 00,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2009/04/11 10:32:36 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/04/11 10:32:36 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2009/04/11 10:32:36 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2009/04/11 10:32:35 | 00,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webcheck.dll
[2009/04/11 10:32:35 | 00,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2009/04/11 10:32:35 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2009/04/11 10:32:35 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/04/11 10:32:35 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2009/04/11 10:32:35 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/04/11 10:32:34 | 00,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/04/11 10:32:34 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/04/11 10:32:34 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advpack.dll
[2009/04/11 10:32:33 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2009/04/11 10:32:32 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2009/04/11 10:32:32 | 00,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2009/04/11 10:32:31 | 00,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2009/04/11 10:32:31 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2009/04/11 10:32:30 | 00,391,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/04/11 10:32:28 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/04/11 10:32:28 | 00,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2009/04/11 10:32:28 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshta.exe
[2009/04/11 10:32:27 | 03,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2009/04/11 10:32:27 | 00,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/04/11 10:32:27 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2009/04/11 10:32:27 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/04/11 10:32:27 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2009/04/11 10:32:27 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2009/04/11 10:32:27 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2009/04/11 10:32:26 | 01,985,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/04/11 10:32:26 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/04/11 10:32:25 | 00,914,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/04/11 10:32:24 | 01,206,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/04/11 10:32:23 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/04/11 10:32:22 | 11,063,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/04/11 10:32:21 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/04/07 16:41:38 | 00,001,804 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2009/04/07 16:40:30 | 00,000,000 | —D | C] – C:\Program Files\iPod
[2009/04/07 16:40:20 | 00,000,000 | —D | C] – C:\ProgramData\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/04/07 16:40:20 | 00,000,000 | —D | C] – C:\Program Files\iTunes
[2009/04/07 16:33:57 | 00,000,227 | —- | C] () – C:\Users\Pete&Adie\Desktop\Sound - Shortcut.lnk
[2009/04/07 11:26:42 | 00,001,893 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2009/03/31 14:42:53 | 00,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
[2009/03/30 18:01:12 | 00,225,280 | —- | C] () – C:\Windows\System32\net_rim_plazmic_flint_dialog.dll
[2009/03/30 18:01:08 | 00,000,000 | —D | C] – C:\Users\Pete&Adie\AppData\Roaming\Plazmic
[2009/03/30 17:58:55 | 00,000,000 | —D | C] – C:\Program Files\Plazmic CDK 4.7
[2009/03/30 17:58:40 | 00,000,000 | -H-D | C] – C:\Program Files\Zero G Registry
[2009/03/13 18:07:13 | 00,000,227 | —- | C] () – C:\Windows\AvDetected.ini
[2009/01/17 14:49:36 | 00,000,087 | —- | C] () – C:\Windows\ka.ini
[2009/01/15 14:10:02 | 00,001,554 | —- | C] () – C:\Windows\yahtzee.ini
[2008/12/21 15:42:38 | 00,000,119 | —- | C] () – C:\Windows\mrpotato.ini
[2008/07/23 10:50:52 | 03,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/07/23 10:47:34 | 00,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/07/23 10:47:34 | 00,000,416 | —- | C] () – C:\Windows\System32\dpl100.dll.manifest
[2008/07/23 10:46:38 | 00,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2008/05/26 16:42:08 | 00,000,000 | —- | C] () – C:\Windows\setup32.INI
[2008/04/02 21:06:53 | 00,012,288 | —- | C] () – C:\Windows\impborl.dll
[2008/03/25 09:56:08 | 00,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1461.dll
[2008/03/24 22:18:04 | 00,000,252 | —- | C] () – C:\Windows\phedit.ini
[2008/03/24 22:03:50 | 00,210,944 | —- | C] () – C:\Windows\System32\msvcrt10.dll
[2008/03/24 22:03:50 | 00,005,515 | —- | C] () – C:\Windows\fmachine.ini
[2008/02/25 16:34:49 | 00,059,500 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2008/01/02 17:57:36 | 00,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1409.dll
[2007/10/22 09:44:38 | 00,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2007/10/11 19:59:24 | 00,025,624 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2007/09/04 13:48:13 | 00,765,952 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2007/09/04 13:48:13 | 00,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2007/08/24 12:46:48 | 00,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1322.dll
[2007/08/01 20:48:55 | 00,000,039 | —- | C] () – C:\Windows\WININIT.INI
[2007/03/10 03:02:56 | 00,102,400 | —- | C] () – C:\Windows\System32\pywintypes24.dll
[2007/03/10 03:02:55 | 00,327,680 | —- | C] () – C:\Windows\System32\pythoncom24.dll
[2007/03/10 02:55:09 | 00,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1132.dll
[2007/03/06 12:49:42 | 00,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1227.dll
[2007/03/05 13:34:28 | 00,676,224 | —- | C] () – C:\Windows\System32\OGACheckControl.DLL
[2007/01/10 05:56:34 | 00,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 04:23:31 | 00,000,436 | —- | C] () – C:\Windows\win.ini
[2006/11/02 04:23:31 | 00,000,235 | —- | C] () – C:\Windows\system.ini
[2006/11/02 01:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/08/11 01:00:40 | 00,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/08/11 01:00:40 | 00,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll

========== Files - Modified Within 30 Days ==========

[1 C:\Windows\*.tmp files]
[2009/04/26 18:15:00 | 00,000,422 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{017B901C-58CB-49BD-A4C4-916A2BA03B41}.job
[2009/04/26 18:11:19 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Users\Pete&Adie\Desktop\OTListIt2.exe
[2009/04/26 16:52:15 | 00,003,680 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/04/26 16:52:15 | 00,003,680 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/04/26 12:50:13 | 00,000,430 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{F40F8D07-D9D7-4C72-83BB-10C4B4A44DDF}.job
[2009/04/26 12:39:10 | 00,000,868 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2009/04/26 11:24:28 | 00,000,378 | —- | M] () – C:\Windows\tasks\AWC Startup.job
[2009/04/26 10:52:19 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/04/26 10:52:09 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/04/26 10:50:57 | 06,291,456 | -H– | M] () – C:\Users\Pete&Adie\AppData\Local\IconCache.db
[2009/04/19 21:20:25 | 00,000,436 | —- | M] () – C:\Windows\win.ini
[2009/04/18 11:21:49 | 00,026,624 | —- | M] () – C:\Users\Pete&Adie\Documents\Adriennes cleaning schedule.xls
[2009/04/15 08:21:19 | 00,000,872 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-961656175-201489447-2584037788-1000.job
[2009/04/11 10:33:28 | 00,652,874 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/04/11 10:33:27 | 00,764,022 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/04/11 10:33:27 | 00,123,742 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/04/08 20:15:43 | 00,168,448 | —- | M] () – C:\Users\Pete&Adie\Desktop\Superintendent Diary.xls
[2009/04/07 16:41:38 | 00,001,804 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2009/04/07 16:33:57 | 00,000,227 | —- | M] () – C:\Users\Pete&Adie\Desktop\Sound - Shortcut.lnk
[2009/04/07 11:26:42 | 00,001,893 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2009/04/06 18:33:36 | 00,030,720 | —- | M] () – C:\Users\Pete&Adie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/04/06 08:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mrt.exe
[2009/03/31 20:29:03 | 00,089,160 | —- | M] () – C:\Users\Pete&Adie\AppData\Roaming\GDIPFONTCACHEV1.DAT
[2009/03/31 14:42:53 | 00,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
[2009/03/30 18:06:30 | 00,089,160 | —- | M] () – C:\Users\Pete&Adie\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/03/30 18:04:25 | 00,352,480 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/03/29 18:28:05 | 00,000,256 | —- | M] () – C:\Windows\System32\pool.bin
[2009/03/28 22:12:02 | 00,002,595 | —- | M] () – C:\Users\Pete&Adie\Desktop\Microsoft Word.lnk

========== LOP Check ==========

[2009/04/26 11:24:28 | 00,000,378 | —- | M] () – C:\Windows\Tasks\AWC Startup.job
[2009/04/26 12:39:10 | 00,000,868 | —- | M] () – C:\Windows\Tasks\Google Software Updater.job
[2009/04/15 08:21:19 | 00,000,872 | —- | M] () – C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-961656175-201489447-2584037788-1000.job
[2009/04/26 10:52:19 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/04/26 10:51:08 | 00,032,636 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2009/04/26 18:15:00 | 00,000,422 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{017B901C-58CB-49BD-A4C4-916A2BA03B41}.job
[2009/04/26 12:50:13 | 00,000,430 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{F40F8D07-D9D7-4C72-83BB-10C4B4A44DDF}.job

========== Purity Check ==========

< End of report >
Adrienne,

You can erase the Malwarebytes quarantine.

BitTorrent
You have BitTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm


I would recommend that you uninstall BitTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

  • Click Start, then Settings, then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, Remove Java™ SE Runtime Environment 6 Update 1
  • Do the same for: Java™ 6 Update 2
    Java™ 6 Update 3
    Java™ 6 Update 5
    Java™ 6 Update 7

Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are two options in the window to clear the cache - Leave both Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
explorer.exe

:OTLI

:Services

:Reg

:Files
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/webgames/popcaploader_v10.cab (PopCapLoader Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL2 log and a new HJT log.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Hi Tom. I attempted to run the OST as you directed. (copied and pasted) I got this error: Invalid time flag [popcaploader_v10.cab (PopCaploader Object)] Must be numerical Adrienne
Adrienne,

Oops. I messed up the script. Please replace instructions as follows:

Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
explorer.exe

:OTLI
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/webgames/popcaploader_v10.cab (PopCapLoader Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL2 log and a new HJT log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI