SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 01/02/2010 at 07:46 PM
Application Version : 4.32.1000
Core Rules Database Version : 4441
Trace Rules Database Version: 2265
Scan type : Complete Scan
Total Scan Time : 02:13:10
Memory items scanned : 368
Memory threats detected : 0
Registry items scanned : 5963
Registry threats detected : 0
File items scanned : 237584
File threats detected : 146
Adware.Tracking Cookie
C:\Users\debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Users\debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][3].txt
C:\Windows.old\Documents and Settings\debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Documents and Settings\debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][3].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\debby@doubleclick[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@123count[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@247realmedia[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@2o7[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@adbrite[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@adbureau[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@adrevolver[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@advertising[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@alineamedia[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@apmebf[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@atdmt[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@bizrate[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@bravenet[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@chitika[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@clickbank[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@collective-media[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@dealtime[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@dmtracker[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@doubleclick[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@ez-tracks[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@fastclick[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@findyour-siding[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@gpstracklog[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@hitbox[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@imrworldwide[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@insightexpressai[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@interclick[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@invitemedia[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@lionadtrack[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@media6degrees[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@mediaonenetwork[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@mediaplex[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@nextag[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@oddcast[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@overture[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@qnsr[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@questionmarket[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@revsci[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@roiservice[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][3].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][4].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][6].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][7].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][3].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][4].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@specificclick[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@specificmedia[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@tacoda[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@testcountry[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@thefind[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@trackalyzer[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@tradedoubler[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@trafficmp[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@traveladvertising[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@tribalfusion[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@tripod[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][10].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][11].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][3].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][4].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][5].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][6].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][7].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][8].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][9].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@xiti[1].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@yieldmanager[2].txt
C:\Windows.old\Users\Debby\AppData\Roaming\Microsoft\Windows\Cookies\Low\debby@zedo[2].txt
C:\Windows.old\Users\Debby\Application Data\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\Application Data\Microsoft\Windows\Cookies\Low\
[email protected][3].txt
C:\Windows.old\Users\Debby\Cookies\Low\
[email protected][2].txt
C:\Windows.old\Users\Debby\Cookies\Low\
[email protected][3].txt
Here's MBAM
Malwarebytes' Anti-Malware 1.43
Database version: 3485
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
1/2/2010 10:12:40 PM
mbam-log-2010-01-02 (22-12-40).txt
Scan type: Quick Scan
Objects scanned: 93356
Time elapsed: 3 minute(s), 42 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
I'm not sure I did Hijack This correctly. It didn't come up at all like the instructions given on Computer Hope page. I clicked install and save and it installed and ran scan right away. This is what it said:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:24:51 PM, on 1/2/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\F-Secure\Common\FSM32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
C:\Windows\System32\rundll32.exe
C:\PROGRA~1\Webshots\315~1.761\webshots.scr
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/mycomcast/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: agihelper.AGUtils - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - mscoree.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: agihelper.AGUtils - {0bc6e3fa-78ef-4886-842c-5a1258c4455a} - mscoree.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\3.1.5.7617\Launcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://www.popcap.com/webgames/popcaploader_v10.cabO16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: AG Core Services (AGCoreService) - AG Interactive - C:\Program Files\AGI\core\4.2\AGCoreService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\F-Secure\ORSP Client\fsorsp.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
--
End of file - 6416 bytes