This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] virus still on my pc?

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I bought a new pc around december 2008. I am running vista premium 64 bit. I had a virus pop up on my microtrend software. I ran a scan and it found nothing. I downloaded avast free homeedition. It restarted pc and ran a scan. Saying it got a trogen virus. It said to move to chest I tried and it said it was too big. I have over a terabite of harddrive space? Avast seemed to eventually remove trojan? I uninstalled mico trend trial version as I heard more then one virus program can conflict. I also use ad-ware. All scans by both programs come up without virus detected. pc runs fine now, but I have heard the vius could still be there. Ran high jack this today on advice from a friend looked confusing so I saved log and closed program until I could get someone who knows what the highjack this log means. Other question is that My other old pc still in use had a virus on windows xp home edition upgrade previous M.E.. I wiped the harddrive and reinstalled xp clean install. Wondering if that always gets rid of a virus? I still use that pc for my kids? It runs fairly slow not sure if it is just because cause it is old or still infected. Kids have been limited to neflicks and pbs kids.com all other sites are password protected. Wife does download games on occasion to play with them. Main concern is new pc. thanks, Jim
Hi Jim, :welcome:

My name is SpySentinel and I will be helping you.


Other question is that My other old pc still in use had a virus on windows xp home edition upgrade previous M.E.. I wiped the harddrive and reinstalled xp clean install. Wondering if that always gets rid of a virus?


To answer your question, yes a Clean Install/reformat will remove all malware, except a few nasty infections, but I doubt you had them. To be sure, I would like to run a few scans.


  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.



Also go ahead and post the HijackThis Log.
OTListIt Extras logfile created on: 4/24/2009 12:40:37 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Users\Jim\Documents\My Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18762)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1177.27 Gb Total Space | 981.52 Gb Free Space | 83.37% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 8.92 Gb Free Space | 59.44% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JIM-PC
Current User Name: Jim
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – C:\Windows\SysWOW64\ieframe.DLL (Microsoft Corporation)
.js [@ = JSFile] – C:\Windows\SysWOW64\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\Windows\SysWOW64\WScript.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\Windows\system32\regedit.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== HKEY_LOCAL_MACHINE Uninstall List ==========
OTListIt logfile created on: 4/24/2009 12:40:37 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Users\Jim\Documents\My Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18762)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1177.27 Gb Total Space | 981.52 Gb Free Space | 83.37% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 8.92 Gb Free Space | 59.44% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JIM-PC
Current User Name: Jim
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE ()
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Digital Line Detect\DLG.exe (Avanquest Software )
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Firefly Media Server\FireflyShell.exe (Roku LLC)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files (x86)\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Internet Explorer\IELowutil.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\MSN\MSNCoreFiles\msn.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - C:\Users\Jim\Documents\My Downloads\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati External Event Utility [Auto | Running]) – C:\Windows\sysnative\Ati2evxx.exe ()
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GameConsoleService [On_Demand | Stopped]) – C:\Program Files (x86)\Dell Games\Dell Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (IAANTMON [Auto | Running]) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IJPLMSVC [Auto | Running]) – C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE ()
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files (x86)\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (MyWebSearchService [Auto | Stopped]) – File not found
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (PcaSvc [Auto | Running]) – C:\Windows\sysnative\pcasvc.dll ()
SRV - (PerfHost [On_Demand | Stopped]) – C:\Windows\SysWow64\perfhost.exe (Microsoft Corporation)
SRV - (stllssvr [On_Demand | Stopped]) – C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (usnjsvc [On_Demand | Running]) – C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) – C:\Program Files (x86)\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (XAudioService [Auto | Running]) – C:\Windows\sysnative\DRIVERS\xaudio64.exe ()

========== Driver Services (SafeList) ==========

DRV - (ASPI32 [System | Stopped]) – C:\Windows\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (aswFsBlk [Auto | Running]) – C:\Windows\sysnative\DRIVERS\aswFsBlk.sys ()
DRV - (aswMonFlt [Auto | Running]) – C:\Windows\sysnative\DRIVERS\aswMonFlt.sys ()
DRV - (aswRdr [System | Running]) – C:\Windows\sysnative\drivers\aswRdr.sys ()
DRV - (aswSP [System | Running]) – C:\Windows\sysnative\drivers\aswSP.sys ()
DRV - (aswTdi [System | Running]) – C:\Windows\sysnative\drivers\aswTdi.sys ()
DRV - (AtiHdmiService [On_Demand | Running]) – C:\Windows\sysnative\drivers\AtiHdmi.sys ()
DRV - (atikmdag [On_Demand | Running]) – C:\Windows\sysnative\DRIVERS\atikmdag.sys ()
DRV - (CAXHWBS2 [On_Demand | Running]) – C:\Windows\sysnative\DRIVERS\CAXHWBS2.sys ()
DRV - (e1express [On_Demand | Stopped]) – C:\Windows\sysnative\DRIVERS\e1e6032e.sys ()
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\Windows\sysnative\DRIVERS\GEARAspiWDM.sys ()
DRV - (HdAudAddService [On_Demand | Running]) – C:\Windows\sysnative\drivers\HdAudio.sys ()
DRV - (HSF_DPV [On_Demand | Running]) – C:\Windows\sysnative\DRIVERS\CAX_DPV.sys ()
DRV - (iaStor [Boot | Running]) – C:\Windows\sysnative\drivers\iastor.sys ()
DRV - (Lbd [Boot | Running]) – C:\Windows\sysnative\DRIVERS\Lbd.sys ()
DRV - (mdmxsdk [Auto | Running]) – C:\Windows\sysnative\DRIVERS\mdmxsdk.sys ()
DRV - (pcouffin [On_Demand | Running]) – C:\Windows\sysnative\Drivers\pcouffin.sys ()
DRV - (PxHlpa64 [Boot | Running]) – C:\Windows\sysnative\Drivers\PxHlpa64.sys ()
DRV - (R300 [On_Demand | Stopped]) – C:\Windows\sysnative\DRIVERS\atikmdag.sys ()
DRV - (RTL8169 [On_Demand | Running]) – C:\Windows\sysnative\DRIVERS\Rtlh64.sys ()
DRV - (RtNdPt60 [Auto | Running]) – C:\Windows\sysnative\DRIVERS\RtNdPt60.sys ()
DRV - (tmcomm [Auto | Stopped]) – C:\Windows\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\Windows\sysnative\DRIVERS\CAX_CNXT.sys ()
DRV - (WpdUsb [On_Demand | Stopped]) – C:\Windows\sysnative\DRIVERS\wpdusb.sys ()
DRV - (XAudio [Auto | Running]) – C:\Windows\sysnative\DRIVERS\xaudio64.sys ()

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.live.com;
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.live.com/;
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.9


FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/03/12 12:14:40 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Minefield 3.1b2pre\extensions\\Components: C:\PROGRAM FILES (X86)\MINEFIELD\COMPONENTS [2009/03/26 17:28:51 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Minefield 3.1b2pre\extensions\\Plugins: C:\PROGRAM FILES (X86)\MINEFIELD\PLUGINS [2009/03/26 17:28:51 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.9\extensions\\Components: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS [2009/04/23 20:23:20 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.9\extensions\\Plugins: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS [2009/04/23 20:23:20 | 00,000,000 | —D | M]

[2008/10/31 12:55:45 | 00,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\mozilla\Extensions
[2008/10/31 12:55:45 | 00,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/23 18:42:07 | 00,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\mozilla\Firefox\Profiles\9kvd9dtd.default\extensions
[2009/03/25 12:39:51 | 00,000,000 | —D | M] – C:\Users\Jim\AppData\Roaming\mozilla\Firefox\Profiles\9kvd9dtd.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/03/25 02:18:29 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions
[2009/04/23 20:23:20 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/23 07:46:24 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/03/25 02:18:29 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/23 20:23:18 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2009/04/23 20:23:19 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2009/03/11 11:53:37 | 00,001,394 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
[2009/03/11 11:53:37 | 00,002,193 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml
[2009/03/11 11:53:37 | 00,001,534 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml
[2009/03/11 11:53:37 | 00,002,343 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
[2009/03/11 11:53:37 | 00,001,706 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2009/03/11 11:53:37 | 00,001,178 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2009/03/11 11:53:37 | 00,000,792 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files (x86)\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files (x86)\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] "C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe" (Lavasoft)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [FireflyShell] "C:\Program Files (x86)\Firefly Media Server\FireflyShell.exe" -q (Roku LLC)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe 1 File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZUxdm486YYUS File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Sites: //@mail.mar@/ ([]msn in Local intranet)
O15 - HKCU\..Trusted Sites: //@signup.mar@/ ([]msn in Computer)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://ra.qwest.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://tky09.celartem.com/en/download/data…ntrol_en_US.cab (DjVuCtl Class)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab (Reg Error: Key error.)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo2.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\system32\explorer.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{de80d469-a825-11dd-bf77-0021703ced2b}\Shell\AutoRun\command - "" = J:\Autorun.exe – File not found
O33 - MountPoints2\{de80d469-a825-11dd-bf77-0021703ced2b}\Shell\Shell00\Command - "" = J:\Autorun.exe – File not found
O33 - MountPoints2\{de80d469-a825-11dd-bf77-0021703ced2b}\Shell\Shell01\Command - "" = J:\Autorun.exe – File not found
O33 - MountPoints2\{de80d469-a825-11dd-bf77-0021703ced2b}\Shell\Shell02\Command - "" = J:\Autorun.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\Windows\*.tmp files]
[2009/04/24 08:23:07 | 00,001,890 | —- | C] () – C:\Users\Jim\Desktop\HijackThis.lnk
[2009/04/24 08:23:07 | 00,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2009/04/24 08:19:29 | 00,000,000 | —D | C] – C:\Program Files (x86)\Windows Live Safety Center
[2009/04/22 08:27:11 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Boomzap
[2009/04/22 07:30:20 | 00,000,000 | —D | C] – C:\Users\Jim\Documents\BarnyardInvasionSaveData
[2009/04/22 07:21:00 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\PlayFirst
[2009/04/22 07:21:00 | 00,000,000 | —D | C] – C:\ProgramData\PlayFirst
[2009/04/21 18:22:40 | 00,000,000 | —D | C] – C:\ProgramData\SugarGames
[2009/04/21 18:18:40 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Local\JollyBear
[2009/04/21 18:18:40 | 00,000,000 | —D | C] – C:\ProgramData\JollyBear
[2009/04/19 13:25:20 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Divo Games
[2009/04/19 13:11:17 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\blg
[2009/04/19 13:11:17 | 00,000,000 | —D | C] – C:\ProgramData\blg
[2009/04/19 13:06:01 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Meridian93
[2009/04/17 17:31:03 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\WildTangentv1002
[2009/04/17 16:18:51 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Fuzzy Games
[2009/04/16 17:25:33 | 00,000,000 | —D | C] – C:\ProgramData\Arcade Lab
[2009/04/15 17:14:21 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\The Flying Trapeezees
[2009/04/15 17:05:41 | 00,000,000 | —D | C] – C:\ProgramData\GameXzone
[2009/04/15 12:56:39 | 00,000,000 | —D | C] – C:\ProgramData\Farm Frenzy
[2009/04/15 12:28:40 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\VisualShape
[2009/04/15 12:28:40 | 00,000,000 | —D | C] – C:\ProgramData\VisualShape
[2009/04/15 07:20:19 | 00,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winhttp.dll
[2009/04/15 07:20:16 | 00,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kernel32.dll
[2009/04/15 07:20:16 | 00,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secur32.dll
[2009/04/15 07:20:16 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amxread.dll
[2009/04/15 07:20:16 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apilogen.dll
[2009/04/15 07:20:11 | 00,183,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2009/04/15 07:20:11 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2009/04/15 07:20:11 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2009/04/15 07:20:11 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2009/04/15 07:20:11 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashost.exe
[2009/04/15 07:20:09 | 00,562,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2009/04/15 07:20:09 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xolehlp.dll
[2009/04/13 17:15:06 | 00,000,000 | —D | C] – C:\Users\Public\Documents\WildGames
[2009/04/12 08:43:51 | 00,000,000 | —D | C] – C:\Users\Public\Documents\iwin
[2009/04/12 08:13:54 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Boolat Games
[2009/04/12 08:00:50 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Pogo Games
[2009/04/11 14:37:59 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\My Games
[2009/04/11 14:13:14 | 00,000,000 | —D | C] – C:\ProgramData\Rumbic Studio
[2009/04/11 13:48:03 | 00,000,000 | —D | C] – C:\Users\Jim\Documents\Alawar
[2009/04/11 13:36:10 | 00,000,000 | —D | C] – C:\Users\Jim\Documents\Flock
[2009/04/11 13:35:23 | 03,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_39.dll
[2009/04/11 13:35:23 | 01,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_39.dll
[2009/04/11 13:35:23 | 00,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_2.dll
[2009/04/11 13:35:23 | 00,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_39.dll
[2009/04/11 13:35:23 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_2.dll
[2009/04/11 13:35:23 | 00,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_1.dll
[2009/04/11 13:35:22 | 03,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_38.dll
[2009/04/11 13:35:22 | 01,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_38.dll
[2009/04/11 13:35:22 | 00,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_1.dll
[2009/04/11 13:35:22 | 00,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_38.dll
[2009/04/11 13:35:22 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_1.dll
[2009/04/11 13:35:22 | 00,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_0.dll
[2009/04/11 13:35:22 | 00,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_4.dll
[2009/04/11 13:35:21 | 03,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_37.dll
[2009/04/11 13:35:21 | 01,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_37.dll
[2009/04/11 13:35:21 | 01,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_36.dll
[2009/04/11 13:35:21 | 00,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_0.dll
[2009/04/11 13:35:21 | 00,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_37.dll
[2009/04/11 13:35:21 | 00,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_36.dll
[2009/04/11 13:35:21 | 00,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_10.dll
[2009/04/11 13:35:21 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_0.dll
[2009/04/11 13:35:21 | 00,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_3.dll
[2009/04/11 13:35:20 | 03,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_36.dll
[2009/04/11 13:35:20 | 03,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_35.dll
[2009/04/11 13:35:20 | 01,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_35.dll
[2009/04/11 13:35:20 | 00,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_35.dll
[2009/04/11 13:35:20 | 00,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_9.dll
[2009/04/11 13:35:19 | 03,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_34.dll
[2009/04/11 13:35:19 | 01,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_34.dll
[2009/04/11 13:35:19 | 01,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_33.dll
[2009/04/11 13:35:19 | 00,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_34.dll
[2009/04/11 13:35:19 | 00,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_33.dll
[2009/04/11 13:35:19 | 00,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_8.dll
[2009/04/11 13:35:19 | 00,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_7.dll
[2009/04/11 13:35:19 | 00,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_3.dll
[2009/04/11 13:35:19 | 00,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_2.dll
[2009/04/11 13:35:18 | 03,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_33.dll
[2009/04/11 13:35:18 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_32.dll
[2009/04/11 13:35:18 | 00,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10.dll
[2009/04/11 13:35:18 | 00,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_6.dll
[2009/04/11 13:35:18 | 00,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_5.dll
[2009/04/11 13:35:17 | 02,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_31.dll
[2009/04/11 13:35:17 | 00,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_4.dll
[2009/04/11 13:35:17 | 00,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_3.dll
[2009/04/11 13:35:17 | 00,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_2.dll
[2009/04/11 13:35:17 | 00,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_1.dll
[2009/04/11 13:35:17 | 00,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_2.dll
[2009/04/11 13:35:17 | 00,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_1.dll
[2009/04/11 13:35:17 | 00,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\x3daudio1_1.dll
[2009/04/11 13:35:11 | 02,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_29.dll
[2009/04/11 13:35:11 | 02,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_28.dll
[2009/04/11 13:35:11 | 02,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_27.dll
[2009/04/11 13:35:11 | 00,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_0.dll
[2009/04/11 13:35:11 | 00,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\x3daudio1_0.dll
[2009/04/11 13:35:10 | 02,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_25.dll
[2009/04/11 13:35:10 | 02,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_26.dll
[2009/04/11 13:35:10 | 02,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_24.dll
[2009/04/11 08:35:14 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Alawar
[2009/04/10 20:46:33 | 00,000,000 | —D | C] – C:\ProgramData\MonteCristo
[2009/04/10 13:03:38 | 00,001,804 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2009/04/10 13:03:31 | 00,000,000 | —D | C] – C:\Program Files (x86)\iPod
[2009/04/10 13:03:30 | 00,000,000 | —D | C] – C:\ProgramData\{35733029-9859-49C7-8475-1E78E2AAE413}
[2009/04/10 13:03:30 | 00,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2009/04/10 13:02:53 | 00,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2009/04/10 13:00:33 | 00,001,866 | —- | C] () – C:\Users\Public\Desktop\Safari.lnk
[2009/04/10 13:00:29 | 00,000,000 | —D | C] – C:\Program Files (x86)\Safari
[2009/04/09 19:14:18 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Skip-Bo
[2009/04/09 17:42:05 | 00,000,000 | —D | C] – C:\Users\Jim\Documents\My Games
[2009/04/09 17:41:31 | 00,000,000 | —D | C] – C:\Program Files (x86)\WildTangent
[2009/04/07 23:29:43 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\WildTangent
[2009/04/07 23:29:39 | 00,002,100 | —- | C] () – C:\Users\Public\Desktop\Play Games.lnk
[2009/04/07 23:29:28 | 00,000,000 | —D | C] – C:\Program Files (x86)\Dell Games
[2009/04/06 16:02:20 | 00,031,570 | —- | C] () – C:\Users\Jim\Documents\heinz gf list.email
[2009/04/05 09:46:13 | 00,000,000 | —D | C] – C:\Users\Jim\Desktop\printer files
[2009/04/04 11:59:43 | 00,038,400 | —- | C] () – C:\Users\Jim\Documents\April 2,09 meeting notes.doc
[2009/04/03 17:05:07 | 00,000,000 | -H-D | C] – C:\ProgramData\CanonIJEGV
[2009/04/03 17:04:12 | 00,204,701 | —- | C] () – C:\Users\Jim\Documents\IMG.pdf
[2009/04/03 16:59:31 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Local\Canon Easy-PhotoPrint EX
[2009/04/03 16:59:29 | 00,000,000 | -H-D | C] – C:\ProgramData\CanonIJEPPEX
[2009/04/03 16:57:13 | 00,000,000 | —D | C] – C:\ProgramData\CanonIJ
[2009/04/03 16:52:47 | 00,000,000 | -H-D | C] – C:\ProgramData\CanonIJSolutionMenu
[2009/04/03 16:51:18 | 00,000,000 | -H-D | C] – C:\ProgramData\CanonIJScan
[2009/04/03 16:50:24 | 00,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\Canon
[2009/04/03 16:50:13 | 00,000,000 | -H-D | C] – C:\ProgramData\CanonIJMyPrinter
[2009/04/03 16:50:07 | 00,000,000 | —D | C] – C:\ProgramData\CanonIJPLM
[2009/04/03 16:43:04 | 00,000,000 | —D | C] – C:\Program Files (x86)\Canon
[2009/04/01 14:03:41 | 00,000,430 | -H– | C] () – C:\Windows\tasks\User_Feed_Synchronization-{2A20B9E8-2391-4130-A1C9-486621E1B587}.job
[2009/04/01 13:59:07 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/04/01 13:59:07 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/04/01 13:59:07 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/04/01 13:56:48 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/04/01 13:56:48 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advpack.dll
[2009/04/01 13:56:48 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2009/04/01 13:56:48 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2009/04/01 13:56:48 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardie.dll
[2009/04/01 13:56:48 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/04/01 13:56:48 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2009/04/01 13:56:47 | 00,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2009/04/01 13:56:47 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2009/04/01 13:56:47 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tdc.ocx
[2009/04/01 13:56:47 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/04/01 13:56:47 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/04/01 13:56:46 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/04/01 13:56:46 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/04/01 13:56:46 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2009/04/01 13:56:46 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2009/04/01 13:56:46 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2009/04/01 13:56:46 | 00,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2009/04/01 13:56:46 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2009/04/01 13:56:46 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2009/04/01 13:56:45 | 00,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/04/01 13:56:45 | 00,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webcheck.dll
[2009/04/01 13:56:45 | 00,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/04/01 13:56:45 | 00,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/04/01 13:56:45 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/04/01 13:56:45 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2009/04/01 13:56:45 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmled.dll
[2009/04/01 13:56:45 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2009/04/01 13:56:44 | 00,914,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/04/01 13:56:44 | 00,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2009/04/01 13:56:44 | 00,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2009/04/01 13:56:44 | 00,391,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/04/01 13:56:44 | 00,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2009/04/01 13:56:44 | 00,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2009/04/01 13:56:44 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2009/04/01 13:56:43 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/04/01 13:56:43 | 00,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2009/04/01 13:56:43 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2009/04/01 13:56:43 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2009/04/01 13:56:43 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshta.exe
[2009/04/01 13:56:42 | 03,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2009/04/01 13:56:42 | 01,985,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/04/01 13:56:42 | 01,206,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/04/01 13:56:42 | 00,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/04/01 13:56:42 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2009/04/01 13:56:42 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/04/01 13:56:42 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2009/04/01 13:56:42 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2009/04/01 13:56:42 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2009/04/01 13:56:41 | 11,063,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/04/01 13:56:41 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/04/01 13:56:40 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/04/01 13:55:23 | 00,000,000 | -H-D | C] – C:\Windows\msdownld.tmp
[2009/03/26 17:36:34 | 00,000,000 | —D | C] – C:\ProgramData\{CD649BED-8A0E-48BE-B3B6-0F5055BED534}
[2009/03/26 17:28:40 | 00,001,718 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2009/03/26 17:28:32 | 00,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2009/03/25 14:29:39 | 00,000,000 | —D | C] – C:\Recovered Files
[2008/11/06 11:37:32 | 03,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/11/06 11:34:00 | 00,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/11/06 11:34:00 | 00,000,416 | —- | C] () – C:\Windows\System32\dpl100.dll.manifest
[2008/11/06 11:33:02 | 00,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2006/11/02 07:34:27 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 07:34:27 | 00,000,144 | —- | C] () – C:\Windows\win.ini

========== Files - Modified Within 30 Days ==========

[1 C:\Windows\*.tmp files]
[2009/04/24 12:28:22 | 00,000,430 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{2A20B9E8-2391-4130-A1C9-486621E1B587}.job
[2009/04/24 10:43:11 | 00,000,288 | —- | M] () – C:\Windows\tasks\RtlNICDiagVistaStart.job
[2009/04/24 10:41:55 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/04/24 10:41:52 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/04/24 09:58:52 | 03,652,488 | -H– | M] () – C:\Users\Jim\AppData\Local\IconCache.db
[2009/04/24 08:23:07 | 00,001,890 | —- | M] () – C:\Users\Jim\Desktop\HijackThis.lnk
[2009/04/20 11:48:23 | 00,000,496 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/04/19 18:41:27 | 00,002,475 | —- | M] () – C:\Users\Jim\Desktop\Plan3D.lnk
[2009/04/19 18:29:44 | 00,007,728 | —- | M] () – C:\Users\Jim\AppData\Local\d3d9caps.dat
[2009/04/19 12:45:22 | 00,005,912 | —- | M] () – C:\Users\Jim\AppData\Roaming\wklnhst.dat
[2009/04/10 13:03:38 | 00,001,804 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2009/04/10 13:00:33 | 00,001,866 | —- | M] () – C:\Users\Public\Desktop\Safari.lnk
[2009/04/08 16:09:21 | 00,000,732 | —- | M] () – C:\Users\Jim\Desktop\DVDFab 5.lnk
[2009/04/07 23:29:39 | 00,002,100 | —- | M] () – C:\Users\Public\Desktop\Play Games.lnk
[2009/04/06 16:02:20 | 00,031,570 | —- | M] () – C:\Users\Jim\Documents\heinz gf list.email
[2009/04/05 12:16:14 | 00,065,536 | —- | M] () – C:\Users\Jim\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/04 11:59:43 | 00,038,400 | —- | M] () – C:\Users\Jim\Documents\April 2,09 meeting notes.doc
[2009/04/03 17:04:12 | 00,204,701 | —- | M] () – C:\Users\Jim\Documents\IMG.pdf
[2009/03/26 17:28:40 | 00,001,718 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk

========== LOP Check ==========

[2009/04/20 11:48:23 | 00,000,496 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/04/24 10:43:11 | 00,000,288 | —- | M] () – C:\Windows\Tasks\RtlNICDiagVistaStart.job
[2009/04/24 10:41:55 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/04/24 09:58:56 | 00,032,644 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2009/04/24 12:28:22 | 00,000,430 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{2A20B9E8-2391-4130-A1C9-486621E1B587}.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 24 bytes -> C:\Windows:C9EEA6B31347C544
< End of report >

———————————————————————————————

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:23:31 AM, on 4/24/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Digital Line Detect\DLG.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Firefly Media Server\FireflyShell.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files (x86)\Dell\BAE\BAE.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files (x86)\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [FireflyShell] "C:\Program Files (x86)\Firefly Media Server\FireflyShell.exe" -q
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Ad-Watch] "C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files (x86)\Digital Line Detect\DLG.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZUxdm486YYUS
O13 - Gopher Prefix:
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://ra.qwest.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://tky09.celartem.com/en/download/data…ntrol_en_US.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo2.walgreens.com/WalgreensActivia.cab
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - http://support.dell.com/systemprofiler/SysProExe.CAB
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\Dell Games\Dell Game Console\GameConsoleService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

–
End of file - 10674 bytes
Please download Malwarebytes' Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Malewarebites antimaleware is 32 bit only I am running 64 bits on this machine. I screwed up and misread first email you sent-I thought you were reponding to new pc question. Would you like me to start over with old pc that I did clean install xp after virus? The logs above are from new pc-sorry

The logs above are from new pc-sorry


No problem, sorry about the mix up. Lets deal with this first, the new pc, then we can check the old.

Run the Kaspersky scan and then post the log back when its finished.
I ran kasperssky and it came up with no problems. I tried to view scan report it said turn off pop up blocker, but that part of msn was not on the top menu? I went into security settings and clicked allow popups from this Kasperssky and ran kasperssky scan and same problem allow pop ups? my avast and ad-aware were shut off at the time of scan? How do I proceed?
My pc appears to be running fine other then an error message that comes on every time I start the pc. It says cannot find mom implementation… etc. This started coming up after my failed attempt to update my ati card driver. I tried to undo it. I was updating driver because I am running one regular mointor and another lcd tv moinitor from my pc. I stumbled across an update while setting up the sound and display settings. No idea how to fix error, but it doesn't seem to effect anything? Anyway the ati card on my pc attaches to my lcd tv thru an hdmi cable. It seemed logical at the time to update the driver. Wish I hadn't now.
If you want, I can send you over to the Techs after we are done, and they can help you with the error.


  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
info.txt logfile of random's system information tool 1.06 2009-04-26 15:55:47 ======Uninstall list====== –>"C:\Program Files (x86)\Dell Games\4 Elements\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\7 Wonders - Treasures of Seven\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Alice Greenfingers\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Barnyard Invasion\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Big City Adventure - Sydney\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Bookworm Adventures\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Chicken Invaders 2 - The Next Wave\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Crystal Maze\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Dell Game Console\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Diner Dash Hometown Hero\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Dragon Ball\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Farm Frenzy\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Final Drive Fury\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Fish Tycoon\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Garden Defense\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Penguins' Journey\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Polar Tubing\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Shrek 2 Ogre Bowler\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Super Granny\Uninstall.exe" –>"C:\Program Files (x86)\Dell Games\Turtle Odyssey\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Amelie's Cafe\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Big Island Blends\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Cannon Blast\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Continental Cafe\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\County Fair\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Diner Dash\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Emerald City Confidential\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Escape Rosecliff Island\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Fab Fashion\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Fishing Craze\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Flock Demo\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Gourmania\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Hidden World of Art\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Jenny's Fish Shop\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Jewel Match 2\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Jewel Quest Solitaire 3\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Juice Mania\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Little Shop - City Lights\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Little Shop - Road Trip\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Lost in Reefs\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Orchard\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Penguins!\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Polar Bowler\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Polar Golfer\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Posh Boutique\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Sally's Salon\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Satisfashion\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Sea Journey\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Skip-Bo - Castaway Caper\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Sunshine Acres\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\The Count of Monte Cristo\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\The Enchanting Islands\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\The Flying Trapeezees\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Tibet Quest\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Way to Go! Bowling\Uninstall.exe" –>"C:\Program Files (x86)\WildTangent\Dell Games\Wendy's Wellness\Uninstall.exe" Acrobat.com–>C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07} Ad-Aware–>"C:\ProgramData\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE Ad-Aware–>C:\ProgramData\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe Adobe AIR–>C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F} Adobe Flash Player 10 ActiveX–>C:\Windows\SysWOW64\Macromed\Flash\uninstall_activeX.exe Adobe Flash Player 10 Plugin–>C:\Windows\SysWOW64\Macromed\Flash\uninstall_plugin.exe Adobe Reader 9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001} Adobe Shockwave Player–>C:\Windows\System32\Macromed\SHOCKW~1\UNWISE.EXE C:\Windows\System32\Macromed\SHOCKW~1\Install.log Apple Software Update–>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033} ATI Catalyst Control Center–>RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x9 avast! Antivirus–>C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup Browser Address Error Redirector–>MsiExec.exe /I{62230596-37E5-4618-A329-0D21F529A86F} Browser Address Error Redirector–>regsvr32 /u /s "C:\Program Files (x86)\Dell\BAE\BAE.dll" Canon MP Navigator EX 2.0–>"C:\Program Files (x86)\Canon\MP Navigator EX 2.0\Maint.exe" /UninstallRemove C:\Program Files (x86)\Canon\MP Navigator EX 2.0\uninst.ini Canon MP240 series User Registration–>C:\Program Files (x86)\Canon\IJEREG\MP240 series\UNINST.EXE Canon Utilities Easy-PhotoPrint EX–>C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\uninst.exe uninst.ini Canon Utilities My Printer–>C:\Program Files\Canon\MyPrinter\uninst.exe uninst.ini Canon Utilities Solution Menu–>C:\Program Files (x86)\Canon\SolutionMenu\uninst.exe uninst.ini Catalyst Control Center - Branding–>MsiExec.exe /I{D3B1C799-CB73-42DE-BA0F-2344793A095C} Compatibility Pack for the 2007 Office system–>MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE} Dell Getting Started Guide–>MsiExec.exe /I{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045} Dell Video Chat (remove only)–>C:\Program Files (x86)\Dell Video Chat\uninst.exe Dell-eBay–>MsiExec.exe /I{B935C985-A17F-484B-8470-09E4FC27DC26} Digital Line Detect–>C:\Program Files (x86)\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly DivX Codec–>C:\Program Files (x86)\DivX\DivXCodecUninstall.exe /CODEC DivX Plus DirectShow Filters–>C:\Program Files (x86)\DivX\DivXDSFiltersUninstall.exe /DSFILTERS DivX Web Player–>C:\Program Files (x86)\DivX\DivXWebPlayerUninstall.exe /PLUGIN DVD Shrink 3.2–>"C:\Program Files (x86)\DVD Shrink\unins000.exe" DVDFab (Platinum/Gold/HD Decrypter) (Non-CSS Version) 5.2.3.0–>"C:\Program Files (x86)\DVDFab 5\unins001.exe" DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.2.3.2–>"C:\Program Files (x86)\DVDFab 5\unins002.exe" Easy DVD Shrink–>C:\PROGRA~2\EASYDV~1\UNWISE.EXE C:\PROGRA~2\EASYDV~1\INSTALL.LOG EDocs–>RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{6B7B6D4D-8F9B-4CB3-8CA4-BCA9CC4C1A22}\setup.exe" Google Toolbar for Internet Explorer–>"C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall Google Toolbar for Internet Explorer–>MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C} HijackThis 2.0.2–>"C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe" /uninstall Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)–>c:\Windows\SysWOW64\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT="" Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)–>c:\Windows\SysWOW64\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {08155812-0202-4D5F-A7FF-12A2782DC548} /qb+ REBOOTPROMPT="" Inkjet Printer/Scanner Extended Survey Program–>C:\Program Files (x86)\Canon\IJPLM\SETUP.EXE -R Java™ 6 Update 13–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF} Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070} Lizardtech DjVu Control (autoinstall)–>RunDll32 advpack.dll,LaunchINFSection C:\Windows\INF\DjVuLite.us.inf,DefaultUninstall,5 Microsoft Office PowerPoint Viewer 2007 (English)–>MsiExec.exe /X{95120000-00AF-0409-0000-0000000FF1CE} Microsoft Silverlight–>MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} Microsoft Works–>MsiExec.exe /I{15BC8CD0-A65B-47D0-A2DD-90A824590FA8} Minefield (3.1b2pre)–>C:\Program Files (x86)\Minefield\uninstall\helper.exe Mozilla Firefox (3.0.9)–>C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe MSN Toolbar–>MsiExec.exe /I{3560CE5A-C4EF-4DB0-9ECC-BA035FE309C5} MSN–>C:\Program Files (x86)\MSN\MsnInstaller\msniadm.exe /Action:ARP MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} MSXML 4.0 SP2 (KB941833)–>MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF} MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71} NeroVision Express 2–>C:\Windows\UNNeroVision.exe /UNINSTALL neroxml–>MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B} NetWaiting–>C:\Program Files (x86)\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly Plan3D–>MsiExec.exe /I{4613D63D-52C3-4BC5-BB65-622A801997E2} PowerDVD–>RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -l0x9 -cluninstall QuickTime–>MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F} Realtek Ethernet Network Card Diagnostic tool for Windows Vista–>C:\Program Files (x86)\InstallShield Installation Information\{1FECF5F8-8E75-432C-9FF7-1C04F1956B54}\setup.exe -runfromtemp -l0x0009 -removeonly Roxio Creator Audio–>MsiExec.exe /I{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83} Roxio Creator Copy–>MsiExec.exe /I{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD} Roxio Creator Data–>MsiExec.exe /I{08E81ABD-79F7-49C2-881F-FD6CB0975693} Roxio Creator DE–>C:\ProgramData\Uninstall\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}\setup.exe /x {09760D42-E223-42AD-8C3E-55B47D0DDAC3} Roxio Creator DE–>MsiExec.exe /I{ED439A64-F018-4DD4-8BA5-328D85AB09AB} Roxio Creator Tools–>MsiExec.exe /I{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4} Roxio Express Labeler 3–>MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA} Roxio Update Manager–>MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E} Safari–>MsiExec.exe /I{D90AFDE3-3E67-407A-ACA8-F0BAAD012F08} Spelling Dictionaries Support For Adobe Reader 9–>MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004} VideoFab Converter 1.0.1.0–>"C:\Program Files (x86)\VideoFab\unins000.exe" Visual C++ 2008 x86 Runtime - (v9.0.30729)–>MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27} Visual C++ 2008 x86 Runtime - v9.0.30729.01–>C:\Windows\SysWOW64\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT="" WildTangent Games–>"C:\Program Files (x86)\WildTangent\Dell Games\Uninstall.exe" Windows Live installer–>MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320} Windows Live Messenger–>MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0} Windows Live OneCare safety scanner–>%ProgramFiles(x86)%\Windows Live Safety Center\wlschost.exe -Uninstall World of Warcraft FREE Trial–>MsiExec.exe /X{02EBDBB9-4600-41D3-B566-40CB861511D2} ======Security center information====== AS: Lavasoft Ad-Watch Live! AS: Windows Defender ======System event log====== Computer Name: Jim-PC Event Code: 7000 Message: The tmcomm service failed to start due to the following error: This driver has been blocked from loading Record Number: 112036 Source Name: Service Control Manager Time Written: 20090426184433.000000-000 Event Type: Error User: Computer Name: Jim-PC Event Code: 7026 Message: The following boot-start or system-start driver(s) failed to load: ASPI32 Record Number: 112054 Source Name: Service Control Manager Time Written: 20090426184433.000000-000 Event Type: Error User: Computer Name: Jim-PC Event Code: 1060 Message: \??\C:\Windows\SysWow64\drivers\tmcomm.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Record Number: 112061 Source Name: Application Popup Time Written: 20090426184432.432544-000 Event Type: Error User: Computer Name: Jim-PC Event Code: 4226 Message: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts. Record Number: 112100 Source Name: Tcpip Time Written: 20090426200958.086200-000 Event Type: Warning User: Computer Name: Jim-PC Event Code: 4226 Message: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts. Record Number: 112103 Source Name: Tcpip Time Written: 20090426205257.983200-000 Event Type: Warning User: =====Application event log===== Computer Name: Jim-PC Event Code: 10 Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Record Number: 44993 Source Name: Microsoft-Windows-WMI Time Written: 20090426005051.000000-000 Event Type: Error User: Computer Name: Jim-PC Event Code: 1530 Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-3208434245-2966178592-688181538-1000: Process 900 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3208434245-2966178592-688181538-1000 Record Number: 45007 Source Name: Microsoft-Windows-User Profiles Service Time Written: 20090426013920.000000-000 Event Type: Warning User: NT AUTHORITY\SYSTEM Computer Name: Jim-PC Event Code: 1530 Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-3208434245-2966178592-688181538-1000_Classes: Process 900 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3208434245-2966178592-688181538-1000_CLASSES Record Number: 45008 Source Name: Microsoft-Windows-User Profiles Service Time Written: 20090426013920.000000-000 Event Type: Warning User: NT AUTHORITY\SYSTEM Computer Name: Jim-PC Event Code: 10 Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Record Number: 45028 Source Name: Microsoft-Windows-WMI Time Written: 20090426120912.000000-000 Event Type: Error User: Computer Name: Jim-PC Event Code: 10 Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Record Number: 45082 Source Name: Microsoft-Windows-WMI Time Written: 20090426184433.000000-000 Event Type: Error User: =====Security event log===== Computer Name: Jim-PC Event Code: 4616 Message: The system time was changed. Subject: Security ID: S-1-5-19 Account Name: LOCAL SERVICE Account Domain: NT AUTHORITY Logon ID: 0x3e5 Process Information: Process ID: 0x32c Name: C:\Windows\System32\svchost.exe Previous Time: 1:45:10 PM 4/26/2009 New Time: 1:45:10 PM 4/26/2009 This event is generated when the system time is changed. It is normal for the Windows Time Service, which runs with System privilege, to change the system time on a regular basis. Other system time changes may be indicative of attempts to tamper with the computer. Record Number: 35814 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090426184510.046600-000 Event Type: Audit Success User: Computer Name: Jim-PC Event Code: 4648 Message: A logon was attempted using explicit credentials. Subject: Security ID: S-1-5-18 Account Name: JIM-PC$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: Jim Account Domain: Jim-PC Logon GUID: {00000000-0000-0000-0000-000000000000} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x438 Process Name: C:\Windows\System32\winlogon.exe Network Information: Network Address: 127.0.0.1 Port: 0 This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command. Record Number: 35815 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090426184937.840200-000 Event Type: Audit Success User: Computer Name: Jim-PC Event Code: 4624 Message: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: JIM-PC$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 New Logon: Security ID: S-1-5-21-3208434245-2966178592-688181538-1000 Account Name: Jim Account Domain: Jim-PC Logon ID: 0x797e3 Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x438 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: JIM-PC Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested. Record Number: 35816 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090426184937.840200-000 Event Type: Audit Success User: Computer Name: Jim-PC Event Code: 4624 Message: An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: JIM-PC$ Account Domain: WORKGROUP Logon ID: 0x3e7 Logon Type: 2 New Logon: Security ID: S-1-5-21-3208434245-2966178592-688181538-1000 Account Name: Jim Account Domain: Jim-PC Logon ID: 0x7980c Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x438 Process Name: C:\Windows\System32\winlogon.exe Network Information: Workstation Name: JIM-PC Source Network Address: 127.0.0.1 Source Port: 0 Detailed Authentication Information: Logon Process: User32 Authentication Package: Negotiate Transited Services: - Package Name (NTLM only): - Key Length: 0 This event is generated when a logon session is created. It is generated on the computer that was accessed. The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network). The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on. The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases. The authentication information fields provide detailed information about this specific logon request. - Logon GUID is a unique identifier that can be used to correlate this event with a KDC event. - Transited services indicate which intermediate services have participated in this logon request. - Package name indicates which sub-protocol was used among the NTLM protocols. - Key length indicates the length of the generated session key. This will be 0 if no session key was requested. Record Number: 35817 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090426184937.840200-000 Event Type: Audit Success User: Computer Name: Jim-PC Event Code: 4672 Message: Special privileges assigned to new logon. Subject: Security ID: S-1-5-21-3208434245-2966178592-688181538-1000 Account Name: Jim Account Domain: Jim-PC Logon ID: 0x797e3 Privileges: SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege Record Number: 35818 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090426184937.840200-000 Event Type: Audit Success User: ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "FP_NO_HOST_CHECK"=NO "OS"=Windows_NT "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files (x86)\QuickTime\QTSystem\ "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC "PROCESSOR_ARCHITECTURE"=AMD64 "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "USERNAME"=SYSTEM "windir"=%SystemRoot% "PROCESSOR_LEVEL"=6 "PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 23 Stepping 7, GenuineIntel "PROCESSOR_REVISION"=1707 "NUMBER_OF_PROCESSORS"=4 "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\34FB5F65-FFEB-4B61-BF0E-A6A76C450FAA\TraceFormat "DFSTRACINGON"=FALSE "RoxioCentral"=C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\ "CLASSPATH"=.;C:\Program Files (x86)\Java\jre6\lib\ext\QTJava.zip "QTJAVA"=C:\Program Files (x86)\Java\jre6\lib\ext\QTJava.zip —————–EOF—————–
Logfile of random's system information tool 1.06 (written by random/random)
Run by [removed] at 2009-04-26 15:55:45
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 1004 GB (83%) free of 1206 GB
Total RAM: 8190 MB (76% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:55:46 PM, on 4/26/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Digital Line Detect\DLG.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Firefly Media Server\FireflyShell.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Program Files (x86)\MSN\MSNCoreFiles\msn.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Users\Jim\Documents\My Downloads\RSIT.exe
C:\Program Files (x86)\Trend Micro\HijackThis\Jim.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files (x86)\Dell\BAE\BAE.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files (x86)\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [FireflyShell] "C:\Program Files (x86)\Firefly Media Server\FireflyShell.exe" -q
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Ad-Watch] "C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files (x86)\Digital Line Detect\DLG.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZUxdm486YYUS
O13 - Gopher Prefix:
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://ra.qwest.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://tky09.celartem.com/en/download/data…ntrol_en_US.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo2.walgreens.com/WalgreensActivia.cab
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - http://support.dell.com/systemprofiler/SysProExe.CAB
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\Dell Games\Dell Game Console\GameConsoleService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

–
End of file - 10602 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Ad-Aware Update (Weekly).job
C:\Windows\tasks\RtlNICDiagVistaStart.job
C:\Windows\tasks\User_Feed_Synchronization-{2A20B9E8-2391-4130-A1C9-486621E1B587}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll [2009-04-22 259696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-04-22 668656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [2009-04-22 470512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - C:\Program Files (x86)\Dell\BAE\BAE.dll [2006-11-09 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
MSN Toolbar Helper - C:\Program Files (x86)\MSN\Toolbar\3.0.1203.0\msneshellx.dll [2009-03-13 82768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{07B18EA9-A523-4961-B6BB-170DE4475CCA}
{1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - MSN Toolbar - C:\Program Files (x86)\MSN\Toolbar\3.0.1203.0\msneshellx.dll [2009-03-13 82768]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll [2009-04-22 259696]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]
"Adobe Reader Speed Launcher"=c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"PDVDDXSrv"=C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [2008-05-23 128296]
"FireflyShell"=C:\Program Files (x86)\Firefly Media Server\FireflyShell.exe [2006-08-20 237568]
"AppleSyncNotifier"=C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-03-26 177472]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
"Ad-Watch"=C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe [2009-04-23 516440]
"SunJavaUpdateSched"=C:\Program Files (x86)\Java\jre6\bin\jusched.exe [2009-03-09 148888]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2009-01-05 413696]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2009-04-02 342312]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-20 138240]
"msnmsgr"=C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [2007-10-18 5724184]
"Weather"=C:\Program Files (x86)\AWS\WeatherBug\Weather.exe 1 []
"WMPNSCFG"=C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe []
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-10-08 68856]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Digital Line Detect.lnk - C:\Program Files (x86)\Digital Line Detect\DLG.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=
"NoActiveDesktopChanges"=
"ForceActiveDesktopOn"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de80d469-a825-11dd-bf77-0021703ced2b}]
shell\AutoRun\command - J:\Autorun.exe /run
shell\Shell00\command - J:\Autorun.exe /run
shell\Shell01\command - J:\Autorun.exe /action
shell\Shell02\command - J:\Autorun.exe /uninstall


======File associations======

.js - edit - C:\Windows\SysWOW64\Notepad.exe %1
.js - open - C:\Windows\SysWOW64\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-04-26 15:55:45 —-D—- C:\rsit
2009-04-26 08:57:45 —-D—- C:\ProgramData\MumboJumbo
2009-04-26 07:33:11 —-D—- C:\ProgramData\InterAction studios
2009-04-25 13:55:41 —-D—- C:\ProgramData\Playrix Entertainment
2009-04-24 08:23:07 —-D—- C:\Program Files (x86)\Trend Micro
2009-04-24 08:19:29 —-D—- C:\Program Files (x86)\Windows Live Safety Center
2009-04-22 08:27:11 —-D—- C:\Users\Jim\AppData\Roaming\Boomzap
2009-04-22 07:21:00 —-D—- C:\Users\Jim\AppData\Roaming\PlayFirst
2009-04-22 07:21:00 —-D—- C:\ProgramData\PlayFirst
2009-04-21 18:22:40 —-D—- C:\ProgramData\SugarGames
2009-04-21 18:18:40 —-D—- C:\ProgramData\JollyBear
2009-04-19 13:25:20 —-D—- C:\Users\Jim\AppData\Roaming\Divo Games
2009-04-19 13:11:17 —-D—- C:\Users\Jim\AppData\Roaming\blg
2009-04-19 13:11:17 —-D—- C:\ProgramData\blg
2009-04-19 13:06:01 —-D—- C:\Users\Jim\AppData\Roaming\Meridian93
2009-04-17 17:31:03 —-D—- C:\Users\Jim\AppData\Roaming\WildTangentv1002
2009-04-17 16:18:51 —-D—- C:\Users\Jim\AppData\Roaming\Fuzzy Games
2009-04-16 17:25:33 —-D—- C:\ProgramData\Arcade Lab
2009-04-15 17:14:21 —-D—- C:\Users\Jim\AppData\Roaming\The Flying Trapeezees
2009-04-15 17:05:41 —-D—- C:\ProgramData\GameXzone
2009-04-15 12:56:39 —-D—- C:\ProgramData\Farm Frenzy
2009-04-15 12:28:40 —-D—- C:\Users\Jim\AppData\Roaming\VisualShape
2009-04-15 12:28:40 —-D—- C:\ProgramData\VisualShape
2009-04-15 07:20:19 —-A—- C:\Windows\system32\winhttp.dll
2009-04-15 07:20:16 —-A—- C:\Windows\system32\secur32.dll
2009-04-15 07:20:16 —-A—- C:\Windows\system32\kernel32.dll
2009-04-15 07:20:16 —-A—- C:\Windows\system32\apilogen.dll
2009-04-15 07:20:16 —-A—- C:\Windows\system32\amxread.dll
2009-04-15 07:20:11 —-A—- C:\Windows\system32\sdohlp.dll
2009-04-15 07:20:11 —-A—- C:\Windows\system32\iasrecst.dll
2009-04-15 07:20:11 —-A—- C:\Windows\system32\iashost.exe
2009-04-15 07:20:11 —-A—- C:\Windows\system32\iasdatastore.dll
2009-04-15 07:20:11 —-A—- C:\Windows\system32\iasads.dll
2009-04-15 07:20:09 —-A—- C:\Windows\system32\xolehlp.dll
2009-04-15 07:20:09 —-A—- C:\Windows\system32\msdtcprx.dll
2009-04-12 08:13:54 —-D—- C:\Users\Jim\AppData\Roaming\Boolat Games
2009-04-12 08:00:50 —-D—- C:\Users\Jim\AppData\Roaming\Pogo Games
2009-04-11 14:37:59 —-D—- C:\Users\Jim\AppData\Roaming\My Games
2009-04-11 14:13:14 —-D—- C:\ProgramData\Rumbic Studio
2009-04-11 13:35:23 —-A—- C:\Windows\system32\XAudio2_2.dll
2009-04-11 13:35:23 —-A—- C:\Windows\system32\XAPOFX1_1.dll
2009-04-11 13:35:23 —-A—- C:\Windows\system32\xactengine3_2.dll
2009-04-11 13:35:23 —-A—- C:\Windows\system32\D3DX9_39.dll
2009-04-11 13:35:23 —-A—- C:\Windows\system32\d3dx10_39.dll
2009-04-11 13:35:23 —-A—- C:\Windows\system32\D3DCompiler_39.dll
2009-04-11 13:35:22 —-A—- C:\Windows\system32\XAudio2_1.dll
2009-04-11 13:35:22 —-A—- C:\Windows\system32\XAPOFX1_0.dll
2009-04-11 13:35:22 —-A—- C:\Windows\system32\xactengine3_1.dll
2009-04-11 13:35:22 —-A—- C:\Windows\system32\X3DAudio1_4.dll
2009-04-11 13:35:22 —-A—- C:\Windows\system32\D3DX9_38.dll
2009-04-11 13:35:22 —-A—- C:\Windows\system32\d3dx10_38.dll
2009-04-11 13:35:22 —-A—- C:\Windows\system32\D3DCompiler_38.dll
2009-04-11 13:35:21 —-A—- C:\Windows\system32\XAudio2_0.dll
2009-04-11 13:35:21 —-A—- C:\Windows\system32\xactengine3_0.dll
2009-04-11 13:35:21 —-A—- C:\Windows\system32\xactengine2_10.dll
2009-04-11 13:35:21 —-A—- C:\Windows\system32\X3DAudio1_3.dll
2009-04-11 13:35:21 —-A—- C:\Windows\system32\D3DX9_37.dll
2009-04-11 13:35:21 —-A—- C:\Windows\system32\d3dx10_37.dll
2009-04-11 13:35:21 —-A—- C:\Windows\system32\d3dx10_36.dll
2009-04-11 13:35:21 —-A—- C:\Windows\system32\D3DCompiler_37.dll
2009-04-11 13:35:21 —-A—- C:\Windows\system32\D3DCompiler_36.dll
2009-04-11 13:35:20 —-A—- C:\Windows\system32\xactengine2_9.dll
2009-04-11 13:35:20 —-A—- C:\Windows\system32\d3dx9_36.dll
2009-04-11 13:35:20 —-A—- C:\Windows\system32\d3dx9_35.dll
2009-04-11 13:35:20 —-A—- C:\Windows\system32\d3dx10_35.dll
2009-04-11 13:35:20 —-A—- C:\Windows\system32\D3DCompiler_35.dll
2009-04-11 13:35:19 —-A—- C:\Windows\system32\xinput1_3.dll
2009-04-11 13:35:19 —-A—- C:\Windows\system32\xactengine2_8.dll
2009-04-11 13:35:19 —-A—- C:\Windows\system32\xactengine2_7.dll
2009-04-11 13:35:19 —-A—- C:\Windows\system32\X3DAudio1_2.dll
2009-04-11 13:35:19 —-A—- C:\Windows\system32\d3dx9_34.dll
2009-04-11 13:35:19 —-A—- C:\Windows\system32\d3dx10_34.dll
2009-04-11 13:35:19 —-A—- C:\Windows\system32\d3dx10_33.dll
2009-04-11 13:35:19 —-A—- C:\Windows\system32\D3DCompiler_34.dll
2009-04-11 13:35:19 —-A—- C:\Windows\system32\D3DCompiler_33.dll
2009-04-11 13:35:18 —-A—- C:\Windows\system32\xactengine2_6.dll
2009-04-11 13:35:18 —-A—- C:\Windows\system32\xactengine2_5.dll
2009-04-11 13:35:18 —-A—- C:\Windows\system32\d3dx9_33.dll
2009-04-11 13:35:18 —-A—- C:\Windows\system32\d3dx9_32.dll
2009-04-11 13:35:18 —-A—- C:\Windows\system32\d3dx10.dll
2009-04-11 13:35:17 —-A—- C:\Windows\system32\xinput1_2.dll
2009-04-11 13:35:17 —-A—- C:\Windows\system32\xinput1_1.dll
2009-04-11 13:35:17 —-A—- C:\Windows\system32\xactengine2_4.dll
2009-04-11 13:35:17 —-A—- C:\Windows\system32\xactengine2_3.dll
2009-04-11 13:35:17 —-A—- C:\Windows\system32\xactengine2_2.dll
2009-04-11 13:35:17 —-A—- C:\Windows\system32\xactengine2_1.dll
2009-04-11 13:35:17 —-A—- C:\Windows\system32\x3daudio1_1.dll
2009-04-11 13:35:17 —-A—- C:\Windows\system32\d3dx9_31.dll
2009-04-11 13:35:11 —-A—- C:\Windows\system32\xactengine2_0.dll
2009-04-11 13:35:11 —-A—- C:\Windows\system32\x3daudio1_0.dll
2009-04-11 13:35:11 —-A—- C:\Windows\system32\d3dx9_29.dll
2009-04-11 13:35:11 —-A—- C:\Windows\system32\d3dx9_28.dll
2009-04-11 13:35:11 —-A—- C:\Windows\system32\d3dx9_27.dll
2009-04-11 13:35:10 —-A—- C:\Windows\system32\d3dx9_26.dll
2009-04-11 13:35:10 —-A—- C:\Windows\system32\d3dx9_25.dll
2009-04-11 13:35:10 —-A—- C:\Windows\system32\d3dx9_24.dll
2009-04-11 08:35:14 —-D—- C:\Users\Jim\AppData\Roaming\Alawar
2009-04-10 20:46:33 —-D—- C:\ProgramData\MonteCristo
2009-04-10 13:03:37 —-A—- C:\Windows\system32\GEARAspi.dll
2009-04-10 13:03:31 —-D—- C:\Program Files (x86)\iPod
2009-04-10 13:03:30 —-D—- C:\ProgramData\{35733029-9859-49C7-8475-1E78E2AAE413}
2009-04-10 13:03:30 —-D—- C:\Program Files (x86)\iTunes
2009-04-10 13:02:53 —-D—- C:\Program Files (x86)\Bonjour
2009-04-10 13:00:29 —-D—- C:\Program Files (x86)\Safari
2009-04-09 19:14:18 —-D—- C:\Users\Jim\AppData\Roaming\Skip-Bo
2009-04-09 17:41:31 —-D—- C:\Program Files (x86)\WildTangent
2009-04-07 23:29:43 —-D—- C:\Users\Jim\AppData\Roaming\WildTangent
2009-04-07 23:29:28 —-D—- C:\Program Files (x86)\Dell Games
2009-04-03 17:05:07 —-HD—- C:\ProgramData\CanonIJEGV
2009-04-03 16:59:29 —-HD—- C:\ProgramData\CanonIJEPPEX
2009-04-03 16:57:13 —-D—- C:\ProgramData\CanonIJ
2009-04-03 16:52:47 —-HD—- C:\ProgramData\CanonIJSolutionMenu
2009-04-03 16:51:18 —-HD—- C:\ProgramData\CanonIJScan
2009-04-03 16:50:24 —-D—- C:\Users\Jim\AppData\Roaming\Canon
2009-04-03 16:50:13 —-HD—- C:\ProgramData\CanonIJMyPrinter
2009-04-03 16:50:07 —-D—- C:\ProgramData\CanonIJPLM
2009-04-03 16:43:04 —-D—- C:\Program Files (x86)\Canon
2009-04-01 13:59:07 —-A—- C:\Windows\system32\iesetup.dll
2009-04-01 13:59:07 —-A—- C:\Windows\system32\iernonce.dll
2009-04-01 13:59:07 —-A—- C:\Windows\system32\ie4uinit.exe
2009-04-01 13:56:48 —-A—- C:\Windows\system32\jsproxy.dll
2009-04-01 13:56:48 —-A—- C:\Windows\system32\ieui.dll
2009-04-01 13:56:48 —-A—- C:\Windows\system32\ieakeng.dll
2009-04-01 13:56:48 —-A—- C:\Windows\system32\icardie.dll
2009-04-01 13:56:48 —-A—- C:\Windows\system32\corpol.dll
2009-04-01 13:56:48 —-A—- C:\Windows\system32\advpack.dll
2009-04-01 13:56:48 —-A—- C:\Windows\system32\admparse.dll
2009-04-01 13:56:47 —-A—- C:\Windows\system32\wextract.exe
2009-04-01 13:56:47 —-A—- C:\Windows\system32\msls31.dll
2009-04-01 13:56:47 —-A—- C:\Windows\system32\msfeedssync.exe
2009-04-01 13:56:47 —-A—- C:\Windows\system32\msfeedsbs.dll
2009-04-01 13:56:46 —-A—- C:\Windows\system32\pngfilt.dll
2009-04-01 13:56:46 —-A—- C:\Windows\system32\msfeeds.dll
2009-04-01 13:56:46 —-A—- C:\Windows\system32\imgutil.dll
2009-04-01 13:56:46 —-A—- C:\Windows\system32\ieapfltr.dll
2009-04-01 13:56:46 —-A—- C:\Windows\system32\dxtrans.dll
2009-04-01 13:56:46 —-A—- C:\Windows\system32\dxtmsft.dll
2009-04-01 13:56:45 —-A—- C:\Windows\system32\webcheck.dll
2009-04-01 13:56:45 —-A—- C:\Windows\system32\occache.dll
2009-04-01 13:56:45 —-A—- C:\Windows\system32\mstime.dll
2009-04-01 13:56:45 —-A—- C:\Windows\system32\mshtmled.dll
2009-04-01 13:56:45 —-A—- C:\Windows\system32\licmgr10.dll
2009-04-01 13:56:45 —-A—- C:\Windows\system32\inseng.dll
2009-04-01 13:56:45 —-A—- C:\Windows\system32\iepeers.dll
2009-04-01 13:56:45 —-A—- C:\Windows\system32\ieaksie.dll
2009-04-01 13:56:44 —-A—- C:\Windows\system32\wininet.dll
2009-04-01 13:56:44 —-A—- C:\Windows\system32\WinFXDocObj.exe
2009-04-01 13:56:44 —-A—- C:\Windows\system32\vbscript.dll
2009-04-01 13:56:44 —-A—- C:\Windows\system32\msrating.dll
2009-04-01 13:56:44 —-A—- C:\Windows\system32\jscript.dll
2009-04-01 13:56:44 —-A—- C:\Windows\system32\iedkcs32.dll
2009-04-01 13:56:44 —-A—- C:\Windows\system32\ieakui.dll
2009-04-01 13:56:43 —-A—- C:\Windows\system32\url.dll
2009-04-01 13:56:43 —-A—- C:\Windows\system32\mshtmler.dll
2009-04-01 13:56:43 —-A—- C:\Windows\system32\mshta.exe
2009-04-01 13:56:43 —-A—- C:\Windows\system32\iexpress.exe
2009-04-01 13:56:42 —-A—- C:\Windows\system32\urlmon.dll
2009-04-01 13:56:42 —-A—- C:\Windows\system32\SetIEInstalledDate.exe
2009-04-01 13:56:42 —-A—- C:\Windows\system32\SetDepNx.exe
2009-04-01 13:56:42 —-A—- C:\Windows\system32\RegisterIEPKEYs.exe
2009-04-01 13:56:42 —-A—- C:\Windows\system32\PDMSetup.exe
2009-04-01 13:56:42 —-A—- C:\Windows\system32\ieUnatt.exe
2009-04-01 13:56:42 —-A—- C:\Windows\system32\iesysprep.dll
2009-04-01 13:56:42 —-A—- C:\Windows\system32\iertutil.dll
2009-04-01 13:56:41 —-A—- C:\Windows\system32\ieframe.dll
2009-04-01 13:56:40 —-A—- C:\Windows\system32\mshtml.dll
2009-04-01 13:55:23 —-HD—- C:\Windows\msdownld.tmp

======List of files/folders modified in the last 1 months======

2009-04-26 15:55:46 —-D—- C:\Windows\Prefetch
2009-04-26 15:55:26 —-D—- C:\Windows\Temp
2009-04-26 15:53:08 —-D—- C:\Users\Jim\AppData\Roaming\MSN6
2009-04-26 14:32:56 —-D—- C:\ProgramData\WildTangent
2009-04-26 13:52:26 —-D—- C:\Users\Jim\AppData\Roaming\Macromedia
2009-04-26 13:49:34 —-D—- C:\Windows\System32
2009-04-26 13:49:34 —-D—- C:\Windows\inf
2009-04-26 08:57:45 —-HD—- C:\ProgramData
2009-04-24 09:46:54 —-SHD—- C:\System Volume Information
2009-04-24 08:23:07 —-D—- C:\Program Files (x86)
2009-04-24 08:19:30 —-SD—- C:\Windows\Downloaded Program Files
2009-04-23 20:23:20 —-D—- C:\Program Files (x86)\Mozilla Firefox
2009-04-22 08:34:51 —-SHD—- C:\Windows\Installer
2009-04-15 17:19:02 —-D—- C:\Users\Jim\AppData\Roaming\DivX
2009-04-15 12:06:51 —-D—- C:\Windows\winsxs
2009-04-15 11:55:20 —-D—- C:\Windows\SysWOW64
2009-04-15 11:55:20 —-D—- C:\Windows\system32\manifeststore
2009-04-15 11:55:20 —-D—- C:\Windows\AppPatch
2009-04-15 11:55:19 —-D—- C:\Windows\system32\wbem
2009-04-15 11:55:19 —-D—- C:\Program Files (x86)\Windows Mail
2009-04-11 13:35:17 —-RSD—- C:\Windows\assembly
2009-04-11 13:35:13 —-D—- C:\Windows\Microsoft.NET
2009-04-11 13:34:37 —-D—- C:\Windows\Logs
2009-04-10 13:03:31 —-D—- C:\Program Files (x86)\Common Files\Apple
2009-04-10 13:03:30 —-RD—- C:\Program Files
2009-04-08 16:10:12 —-D—- C:\Program Files (x86)\DVDFab 5
2009-04-08 16:09:22 —-D—- C:\Users\Jim\AppData\Roaming\Vso
2009-04-05 10:21:51 —-D—- C:\Windows
2009-04-05 10:19:40 —-D—- C:\Program Files (x86)\ATI
2009-04-01 14:17:20 —-D—- C:\Windows\rescache
2009-04-01 14:03:41 —-D—- C:\Windows\Tasks
2009-04-01 13:59:41 —-D—- C:\Program Files (x86)\Internet Explorer
2009-04-01 13:59:40 —-D—- C:\Windows\system32\migration
2009-04-01 13:59:40 —-D—- C:\Windows\system32\en-US
2009-04-01 13:59:39 —-D—- C:\Windows\PolicyDefinitions
2009-04-01 13:55:57 —-D—- C:\Program Files (x86)\MSN
2009-03-28 20:10:33 —-D—- C:\Program Files (x86)\Firefly Media Server
2009-03-28 17:21:06 —-RD—- C:\Users

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys []
R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys []
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys []
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys []
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys []
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys []
R2 RtNdPt60;Realtek NDIS Protocol Driver; C:\Windows\system32\DRIVERS\RtNdPt60.sys []
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio64.sys []
R3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\Windows\system32\drivers\AtiHdmi.sys []
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 CAXHWBS2;CAXHWBS2; C:\Windows\system32\DRIVERS\CAXHWBS2.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys []
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys []
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\CAX_DPV.sys []
R3 ksthunk;Kernel Streaming Thunks; C:\Windows\system32\drivers\ksthunk.sys []
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys []
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh64.sys []
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\CAX_CNXT.sys []
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys []
S1 ASPI32;ASPI32; C:\Windows\system32\drivers\ASPI32.sys [1999-09-10 25244]
S2 tmcomm;tmcomm; \??\C:\Windows\system32\drivers\tmcomm.sys [2008-11-13 102664]
S3 ATICDSDr;ATICDSDr; \??\C:\Users\Jim\AppData\Local\Temp\ATICDSDr.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys []
S3 e1express;Intel® PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032e.sys []
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys []
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys []
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys []
S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys []
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys []
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys []
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys []
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys []
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-03-06 132424]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe []
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 IAANTMON;Intel® Matrix Storage Event Monitor; C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2008-05-07 354840]
R2 IJPLMSVC;Inkjet Printer/Scanner Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2008-01-22 103808]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2009-04-23 953168]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio64.exe []
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
R3 iPod Service;iPod Service; C:\Program Files (x86)\iPod\bin\iPodService.exe [2009-04-02 656168]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S2 MyWebSearchService;My Web Search Service; C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwssvc.exe []
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2008-07-27 93184]
S3 GameConsoleService;GameConsoleService; C:\Program Files (x86)\Dell Games\Dell Game Console\GameConsoleService.exe [2009-03-30 250616]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-22 182768]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-20 19968]
S3 stllssvr;stllssvr; C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe [2008-03-24 74384]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files (x86)\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

—————–EOF—————–
Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :Services
    MyWebSearchService
    
    :Reg
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de80d469-a825-11dd-bf77-0021703ced2b}]
    
    :Files
    C:\Program Files\MyWebSearch
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI