OTListIt logfile created on: 4/24/2009 12:40:37 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Users\Jim\Documents\My Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18762)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1177.27 Gb Total Space | 981.52 Gb Free Space | 83.37% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 8.92 Gb Free Space | 59.44% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JIM-PC
Current User Name: Jim
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE ()
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Digital Line Detect\DLG.exe (Avanquest Software )
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Firefly Media Server\FireflyShell.exe (Roku LLC)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files (x86)\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Internet Explorer\IELowutil.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\MSN\MSNCoreFiles\msn.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - C:\Users\Jim\Documents\My Downloads\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati External Event Utility [Auto | Running]) – C:\Windows\sysnative\Ati2evxx.exe ()
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GameConsoleService [On_Demand | Stopped]) – C:\Program Files (x86)\Dell Games\Dell Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (IAANTMON [Auto | Running]) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IJPLMSVC [Auto | Running]) – C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE ()
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files (x86)\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (MyWebSearchService [Auto | Stopped]) – File not found
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (PcaSvc [Auto | Running]) – C:\Windows\sysnative\pcasvc.dll ()
SRV - (PerfHost [On_Demand | Stopped]) – C:\Windows\SysWow64\perfhost.exe (Microsoft Corporation)
SRV - (stllssvr [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (usnjsvc [On_Demand | Running]) – C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) – C:\Program Files (x86)\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (XAudioService [Auto | Running]) – C:\Windows\sysnative\DRIVERS\xaudio64.exe ()
========== Driver Services (SafeList) ==========
DRV - (ASPI32 [System | Stopped]) – C:\Windows\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (aswFsBlk [Auto | Running]) – C:\Windows\sysnative\DRIVERS\aswFsBlk.sys ()
DRV - (aswMonFlt [Auto | Running]) – C:\Windows\sysnative\DRIVERS\aswMonFlt.sys ()
DRV - (aswRdr [System | Running]) – C:\Windows\sysnative\drivers\aswRdr.sys ()
DRV - (aswSP [System | Running]) – C:\Windows\sysnative\drivers\aswSP.sys ()
DRV - (aswTdi [System | Running]) – C:\Windows\sysnative\drivers\aswTdi.sys ()
DRV - (AtiHdmiService [On_Demand | Running]) – C:\Windows\sysnative\drivers\AtiHdmi.sys ()
DRV - (atikmdag [On_Demand | Running]) – C:\Windows\sysnative\DRIVERS\atikmdag.sys ()
DRV - (CAXHWBS2 [On_Demand | Running]) – C:\Windows\sysnative\DRIVERS\CAXHWBS2.sys ()
DRV - (e1express [On_Demand | Stopped]) – C:\Windows\sysnative\DRIVERS\e1e6032e.sys ()
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\Windows\sysnative\DRIVERS\GEARAspiWDM.sys ()
DRV - (HdAudAddService [On_Demand | Running]) – C:\Windows\sysnative\drivers\HdAudio.sys ()
DRV - (HSF_DPV [On_Demand | Running]) – C:\Windows\sysnative\DRIVERS\CAX_DPV.sys ()
DRV - (iaStor [Boot | Running]) – C:\Windows\sysnative\drivers\iastor.sys ()
DRV - (Lbd [Boot | Running]) – C:\Windows\sysnative\DRIVERS\Lbd.sys ()
DRV - (mdmxsdk [Auto | Running]) – C:\Windows\sysnative\DRIVERS\mdmxsdk.sys ()
DRV - (pcouffin [On_Demand | Running]) – C:\Windows\sysnative\Drivers\pcouffin.sys ()
DRV - (PxHlpa64 [Boot | Running]) – C:\Windows\sysnative\Drivers\PxHlpa64.sys ()
DRV - (R300 [On_Demand | Stopped]) – C:\Windows\sysnative\DRIVERS\atikmdag.sys ()
DRV - (RTL8169 [On_Demand | Running]) – C:\Windows\sysnative\DRIVERS\Rtlh64.sys ()
DRV - (RtNdPt60 [Auto | Running]) – C:\Windows\sysnative\DRIVERS\RtNdPt60.sys ()
DRV - (tmcomm [Auto | Stopped]) – C:\Windows\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\Windows\sysnative\DRIVERS\CAX_CNXT.sys ()
DRV - (WpdUsb [On_Demand | Stopped]) – C:\Windows\sysnative\DRIVERS\wpdusb.sys ()
DRV - (XAudio [Auto | Running]) – C:\Windows\sysnative\DRIVERS\xaudio64.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.live.com;
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.live.com/;
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.9
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/03/12 12:14:40 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Minefield 3.1b2pre\extensions\\Components: C:\PROGRAM FILES (X86)\MINEFIELD\COMPONENTS [2009/03/26 17:28:51 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Minefield 3.1b2pre\extensions\\Plugins: C:\PROGRAM FILES (X86)\MINEFIELD\PLUGINS [2009/03/26 17:28:51 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.9\extensions\\Components: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS [2009/04/23 20:23:20 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.9\extensions\\Plugins: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS [2009/04/23 20:23:20 | 00,000,000 | —D | M]
[2008/10/31 12:55:45 | 00,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\mozilla\Extensions
[2008/10/31 12:55:45 | 00,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/23 18:42:07 | 00,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\mozilla\Firefox\Profiles\9kvd9dtd.default\extensions
[2009/03/25 12:39:51 | 00,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\mozilla\Firefox\Profiles\9kvd9dtd.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/03/25 02:18:29 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions
[2009/04/23 20:23:20 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/23 07:46:24 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/03/25 02:18:29 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/23 20:23:18 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2009/04/23 20:23:19 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2009/03/11 11:53:37 | 00,001,394 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
[2009/03/11 11:53:37 | 00,002,193 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml
[2009/03/11 11:53:37 | 00,001,534 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml
[2009/03/11 11:53:37 | 00,002,343 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
[2009/03/11 11:53:37 | 00,001,706 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2009/03/11 11:53:37 | 00,001,178 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2009/03/11 11:53:37 | 00,000,792 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files (x86)\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files (x86)\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] "C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe" (Lavasoft)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [FireflyShell] "C:\Program Files (x86)\Firefly Media Server\FireflyShell.exe" -q (Roku LLC)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe 1 File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/…?p=ZUxdm486YYUS File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Sites: //@mail.mar@/ ([]msn in Local intranet)
O15 - HKCU\..Trusted Sites: //@signup.mar@/ ([]msn in Computer)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED}
https://ra.qwest.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A}
http://tky09.celartem.com/en/download/data…ntrol_en_US.cab (DjVuCtl Class)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab (Reg Error: Key error.)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo2.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6}
http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\system32\explorer.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{de80d469-a825-11dd-bf77-0021703ced2b}\Shell\AutoRun\command - "" = J:\Autorun.exe – File not found
O33 - MountPoints2\{de80d469-a825-11dd-bf77-0021703ced2b}\Shell\Shell00\Command - "" = J:\Autorun.exe – File not found
O33 - MountPoints2\{de80d469-a825-11dd-bf77-0021703ced2b}\Shell\Shell01\Command - "" = J:\Autorun.exe – File not found
O33 - MountPoints2\{de80d469-a825-11dd-bf77-0021703ced2b}\Shell\Shell02\Command - "" = J:\Autorun.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\Windows\*.tmp files]
[2009/04/24 08:23:07 | 00,001,890 | —- | C] () – C:\Users\Jim\Desktop\HijackThis.lnk
[2009/04/24 08:23:07 | 00,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2009/04/24 08:19:29 | 00,000,000 | —D | C] – C:\Program Files (x86)\Windows Live Safety Center
[2009/04/22 08:27:11 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Boomzap
[2009/04/22 07:30:20 | 00,000,000 | —D | C] – C:\Users\Jim\Documents\BarnyardInvasionSaveData
[2009/04/22 07:21:00 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\PlayFirst
[2009/04/22 07:21:00 | 00,000,000 | —D | C] – C:\ProgramData\PlayFirst
[2009/04/21 18:22:40 | 00,000,000 | —D | C] – C:\ProgramData\SugarGames
[2009/04/21 18:18:40 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Local\JollyBear
[2009/04/21 18:18:40 | 00,000,000 | —D | C] – C:\ProgramData\JollyBear
[2009/04/19 13:25:20 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Divo Games
[2009/04/19 13:11:17 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\blg
[2009/04/19 13:11:17 | 00,000,000 | —D | C] – C:\ProgramData\blg
[2009/04/19 13:06:01 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Meridian93
[2009/04/17 17:31:03 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\WildTangentv1002
[2009/04/17 16:18:51 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Fuzzy Games
[2009/04/16 17:25:33 | 00,000,000 | —D | C] – C:\ProgramData\Arcade Lab
[2009/04/15 17:14:21 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\The Flying Trapeezees
[2009/04/15 17:05:41 | 00,000,000 | —D | C] – C:\ProgramData\GameXzone
[2009/04/15 12:56:39 | 00,000,000 | —D | C] – C:\ProgramData\Farm Frenzy
[2009/04/15 12:28:40 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\VisualShape
[2009/04/15 12:28:40 | 00,000,000 | —D | C] – C:\ProgramData\VisualShape
[2009/04/15 07:20:19 | 00,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winhttp.dll
[2009/04/15 07:20:16 | 00,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kernel32.dll
[2009/04/15 07:20:16 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secur32.dll
[2009/04/15 07:20:16 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amxread.dll
[2009/04/15 07:20:16 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apilogen.dll
[2009/04/15 07:20:11 | 00,183,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2009/04/15 07:20:11 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2009/04/15 07:20:11 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2009/04/15 07:20:11 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2009/04/15 07:20:11 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashost.exe
[2009/04/15 07:20:09 | 00,562,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2009/04/15 07:20:09 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xolehlp.dll
[2009/04/13 17:15:06 | 00,000,000 | —D | C] – C:\Users\Public\Documents\WildGames
[2009/04/12 08:43:51 | 00,000,000 | —D | C] – C:\Users\Public\Documents\iwin
[2009/04/12 08:13:54 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Boolat Games
[2009/04/12 08:00:50 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Pogo Games
[2009/04/11 14:37:59 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\My Games
[2009/04/11 14:13:14 | 00,000,000 | —D | C] – C:\ProgramData\Rumbic Studio
[2009/04/11 13:48:03 | 00,000,000 | —D | C] – C:\Users\Jim\Documents\Alawar
[2009/04/11 13:36:10 | 00,000,000 | —D | C] – C:\Users\Jim\Documents\Flock
[2009/04/11 13:35:23 | 03,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_39.dll
[2009/04/11 13:35:23 | 01,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_39.dll
[2009/04/11 13:35:23 | 00,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_2.dll
[2009/04/11 13:35:23 | 00,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_39.dll
[2009/04/11 13:35:23 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_2.dll
[2009/04/11 13:35:23 | 00,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_1.dll
[2009/04/11 13:35:22 | 03,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_38.dll
[2009/04/11 13:35:22 | 01,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_38.dll
[2009/04/11 13:35:22 | 00,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_1.dll
[2009/04/11 13:35:22 | 00,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_38.dll
[2009/04/11 13:35:22 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_1.dll
[2009/04/11 13:35:22 | 00,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_0.dll
[2009/04/11 13:35:22 | 00,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_4.dll
[2009/04/11 13:35:21 | 03,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_37.dll
[2009/04/11 13:35:21 | 01,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_37.dll
[2009/04/11 13:35:21 | 01,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_36.dll
[2009/04/11 13:35:21 | 00,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_0.dll
[2009/04/11 13:35:21 | 00,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_37.dll
[2009/04/11 13:35:21 | 00,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_36.dll
[2009/04/11 13:35:21 | 00,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_10.dll
[2009/04/11 13:35:21 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_0.dll
[2009/04/11 13:35:21 | 00,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_3.dll
[2009/04/11 13:35:20 | 03,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_36.dll
[2009/04/11 13:35:20 | 03,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_35.dll
[2009/04/11 13:35:20 | 01,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_35.dll
[2009/04/11 13:35:20 | 00,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_35.dll
[2009/04/11 13:35:20 | 00,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_9.dll
[2009/04/11 13:35:19 | 03,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_34.dll
[2009/04/11 13:35:19 | 01,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_34.dll
[2009/04/11 13:35:19 | 01,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_33.dll
[2009/04/11 13:35:19 | 00,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_34.dll
[2009/04/11 13:35:19 | 00,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_33.dll
[2009/04/11 13:35:19 | 00,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_8.dll
[2009/04/11 13:35:19 | 00,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_7.dll
[2009/04/11 13:35:19 | 00,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_3.dll
[2009/04/11 13:35:19 | 00,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_2.dll
[2009/04/11 13:35:18 | 03,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_33.dll
[2009/04/11 13:35:18 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_32.dll
[2009/04/11 13:35:18 | 00,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10.dll
[2009/04/11 13:35:18 | 00,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_6.dll
[2009/04/11 13:35:18 | 00,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_5.dll
[2009/04/11 13:35:17 | 02,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_31.dll
[2009/04/11 13:35:17 | 00,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_4.dll
[2009/04/11 13:35:17 | 00,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_3.dll
[2009/04/11 13:35:17 | 00,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_2.dll
[2009/04/11 13:35:17 | 00,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_1.dll
[2009/04/11 13:35:17 | 00,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_2.dll
[2009/04/11 13:35:17 | 00,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_1.dll
[2009/04/11 13:35:17 | 00,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\x3daudio1_1.dll
[2009/04/11 13:35:11 | 02,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_29.dll
[2009/04/11 13:35:11 | 02,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_28.dll
[2009/04/11 13:35:11 | 02,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_27.dll
[2009/04/11 13:35:11 | 00,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_0.dll
[2009/04/11 13:35:11 | 00,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\x3daudio1_0.dll
[2009/04/11 13:35:10 | 02,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_25.dll
[2009/04/11 13:35:10 | 02,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_26.dll
[2009/04/11 13:35:10 | 02,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_24.dll
[2009/04/11 08:35:14 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Alawar
[2009/04/10 20:46:33 | 00,000,000 | —D | C] – C:\ProgramData\MonteCristo
[2009/04/10 13:03:38 | 00,001,804 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2009/04/10 13:03:31 | 00,000,000 | —D | C] – C:\Program Files (x86)\iPod
[2009/04/10 13:03:30 | 00,000,000 | —D | C] – C:\ProgramData\{35733029-9859-49C7-8475-1E78E2AAE413}
[2009/04/10 13:03:30 | 00,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2009/04/10 13:02:53 | 00,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2009/04/10 13:00:33 | 00,001,866 | —- | C] () – C:\Users\Public\Desktop\Safari.lnk
[2009/04/10 13:00:29 | 00,000,000 | —D | C] – C:\Program Files (x86)\Safari
[2009/04/09 19:14:18 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Skip-Bo
[2009/04/09 17:42:05 | 00,000,000 | —D | C] – C:\Users\Jim\Documents\My Games
[2009/04/09 17:41:31 | 00,000,000 | —D | C] – C:\Program Files (x86)\WildTangent
[2009/04/07 23:29:43 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\WildTangent
[2009/04/07 23:29:39 | 00,002,100 | —- | C] () – C:\Users\Public\Desktop\Play Games.lnk
[2009/04/07 23:29:28 | 00,000,000 | —D | C] – C:\Program Files (x86)\Dell Games
[2009/04/06 16:02:20 | 00,031,570 | —- | C] () – C:\Users\Jim\Documents\heinz gf list.email
[2009/04/05 09:46:13 | 00,000,000 | —D | C] – C:\Users\Jim\Desktop\printer files
[2009/04/04 11:59:43 | 00,038,400 | —- | C] () – C:\Users\Jim\Documents\April 2,09 meeting notes.doc
[2009/04/03 17:05:07 | 00,000,000 | -H-D | C] – C:\ProgramData\CanonIJEGV
[2009/04/03 17:04:12 | 00,204,701 | —- | C] () – C:\Users\Jim\Documents\IMG.pdf
[2009/04/03 16:59:31 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Local\Canon Easy-PhotoPrint EX
[2009/04/03 16:59:29 | 00,000,000 | -H-D | C] – C:\ProgramData\CanonIJEPPEX
[2009/04/03 16:57:13 | 00,000,000 | —D | C] – C:\ProgramData\CanonIJ
[2009/04/03 16:52:47 | 00,000,000 | -H-D | C] – C:\ProgramData\CanonIJSolutionMenu
[2009/04/03 16:51:18 | 00,000,000 | -H-D | C] – C:\ProgramData\CanonIJScan
[2009/04/03 16:50:24 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Canon
[2009/04/03 16:50:13 | 00,000,000 | -H-D | C] – C:\ProgramData\CanonIJMyPrinter
[2009/04/03 16:50:07 | 00,000,000 | —D | C] – C:\ProgramData\CanonIJPLM
[2009/04/03 16:43:04 | 00,000,000 | —D | C] – C:\Program Files (x86)\Canon
[2009/04/01 14:03:41 | 00,000,430 | -H– | C] () – C:\Windows\tasks\User_Feed_Synchronization-{2A20B9E8-2391-4130-A1C9-486621E1B587}.job
[2009/04/01 13:59:07 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/04/01 13:59:07 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/04/01 13:59:07 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/04/01 13:56:48 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/04/01 13:56:48 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advpack.dll
[2009/04/01 13:56:48 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2009/04/01 13:56:48 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2009/04/01 13:56:48 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardie.dll
[2009/04/01 13:56:48 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/04/01 13:56:48 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2009/04/01 13:56:47 | 00,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2009/04/01 13:56:47 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2009/04/01 13:56:47 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tdc.ocx
[2009/04/01 13:56:47 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/04/01 13:56:47 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/04/01 13:56:46 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/04/01 13:56:46 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/04/01 13:56:46 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2009/04/01 13:56:46 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2009/04/01 13:56:46 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2009/04/01 13:56:46 | 00,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2009/04/01 13:56:46 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2009/04/01 13:56:46 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2009/04/01 13:56:45 | 00,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/04/01 13:56:45 | 00,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webcheck.dll
[2009/04/01 13:56:45 | 00,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/04/01 13:56:45 | 00,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/04/01 13:56:45 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/04/01 13:56:45 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2009/04/01 13:56:45 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmled.dll
[2009/04/01 13:56:45 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2009/04/01 13:56:44 | 00,914,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/04/01 13:56:44 | 00,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2009/04/01 13:56:44 | 00,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2009/04/01 13:56:44 | 00,391,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/04/01 13:56:44 | 00,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2009/04/01 13:56:44 | 00,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2009/04/01 13:56:44 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2009/04/01 13:56:43 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/04/01 13:56:43 | 00,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2009/04/01 13:56:43 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2009/04/01 13:56:43 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2009/04/01 13:56:43 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshta.exe
[2009/04/01 13:56:42 | 03,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2009/04/01 13:56:42 | 01,985,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/04/01 13:56:42 | 01,206,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/04/01 13:56:42 | 00,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/04/01 13:56:42 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2009/04/01 13:56:42 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/04/01 13:56:42 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2009/04/01 13:56:42 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2009/04/01 13:56:42 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2009/04/01 13:56:41 | 11,063,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/04/01 13:56:41 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/04/01 13:56:40 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/04/01 13:55:23 | 00,000,000 | -H-D | C] – C:\Windows\msdownld.tmp
[2009/03/26 17:36:34 | 00,000,000 | —D | C] – C:\ProgramData\{CD649BED-8A0E-48BE-B3B6-0F5055BED534}
[2009/03/26 17:28:40 | 00,001,718 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2009/03/26 17:28:32 | 00,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2009/03/25 14:29:39 | 00,000,000 | —D | C] – C:\Recovered Files
[2008/11/06 11:37:32 | 03,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/11/06 11:34:00 | 00,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/11/06 11:34:00 | 00,000,416 | —- | C] () – C:\Windows\System32\dpl100.dll.manifest
[2008/11/06 11:33:02 | 00,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2006/11/02 07:34:27 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 07:34:27 | 00,000,144 | —- | C] () – C:\Windows\win.ini
========== Files - Modified Within 30 Days ==========
[1 C:\Windows\*.tmp files]
[2009/04/24 12:28:22 | 00,000,430 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{2A20B9E8-2391-4130-A1C9-486621E1B587}.job
[2009/04/24 10:43:11 | 00,000,288 | —- | M] () – C:\Windows\tasks\RtlNICDiagVistaStart.job
[2009/04/24 10:41:55 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/04/24 10:41:52 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/04/24 09:58:52 | 03,652,488 | -H– | M] () – C:\Users\Jim\AppData\Local\IconCache.db
[2009/04/24 08:23:07 | 00,001,890 | —- | M] () – C:\Users\Jim\Desktop\HijackThis.lnk
[2009/04/20 11:48:23 | 00,000,496 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/04/19 18:41:27 | 00,002,475 | —- | M] () – C:\Users\Jim\Desktop\Plan3D.lnk
[2009/04/19 18:29:44 | 00,007,728 | —- | M] () – C:\Users\Jim\AppData\Local\d3d9caps.dat
[2009/04/19 12:45:22 | 00,005,912 | —- | M] () – C:\Users\Jim\AppData\Roaming\wklnhst.dat
[2009/04/10 13:03:38 | 00,001,804 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2009/04/10 13:00:33 | 00,001,866 | —- | M] () – C:\Users\Public\Desktop\Safari.lnk
[2009/04/08 16:09:21 | 00,000,732 | —- | M] () – C:\Users\Jim\Desktop\DVDFab 5.lnk
[2009/04/07 23:29:39 | 00,002,100 | —- | M] () – C:\Users\Public\Desktop\Play Games.lnk
[2009/04/06 16:02:20 | 00,031,570 | —- | M] () – C:\Users\Jim\Documents\heinz gf list.email
[2009/04/05 12:16:14 | 00,065,536 | —- | M] () – C:\Users\Jim\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/04 11:59:43 | 00,038,400 | —- | M] () – C:\Users\Jim\Documents\April 2,09 meeting notes.doc
[2009/04/03 17:04:12 | 00,204,701 | —- | M] () – C:\Users\Jim\Documents\IMG.pdf
[2009/03/26 17:28:40 | 00,001,718 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
========== LOP Check ==========
[2009/04/20 11:48:23 | 00,000,496 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/04/24 10:43:11 | 00,000,288 | —- | M] () – C:\Windows\Tasks\RtlNICDiagVistaStart.job
[2009/04/24 10:41:55 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/04/24 09:58:56 | 00,032,644 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2009/04/24 12:28:22 | 00,000,430 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{2A20B9E8-2391-4130-A1C9-486621E1B587}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 24 bytes -> C:\Windows:C9EEA6B31347C544
< End of report >
———————————————————————————————
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:23:31 AM, on 4/24/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Digital Line Detect\DLG.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Firefly Media Server\FireflyShell.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files (x86)\Dell\BAE\BAE.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files (x86)\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [FireflyShell] "C:\Program Files (x86)\Firefly Media Server\FireflyShell.exe" -q
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Ad-Watch] "C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files (x86)\Digital Line Detect\DLG.exe
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/…?p=ZUxdm486YYUS
O13 - Gopher Prefix:
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
https://ra.qwest.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) -
http://tky09.celartem.com/en/download/data…ntrol_en_US.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo2.walgreens.com/WalgreensActivia.cab
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) -
http://support.dell.com/systemprofiler/SysProExe.CAB
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\Dell Games\Dell Game Console\GameConsoleService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)
–
End of file - 10674 bytes