more information
there's a file in c:\WINDOWS\Prefetch called MWMEX.EXE-000D1C67.pf
i can't find 'check.txt' or 'fixes.txt' on my system, logfile options are checked in 'options.'
'resident.log' reads as follows:
5/19/2010 4:25:17 PM Allowed (based on user decision) value "PadTouch" (new data: "") deleted in System Startup global entry!
5/19/2010 6:02:05 PM Allowed (based on user decision) value "TFncKy" (new data: "") deleted in System Startup global entry!
5/19/2010 6:02:27 PM Allowed (based on user decision) value "TDispVol" (new data: "") deleted in System Startup global entry!
5/19/2010 6:03:01 PM Allowed (based on user decision) value "THotkey" (new data: "") deleted in System Startup global entry!
5/19/2010 6:04:35 PM Allowed (based on user decision) value "SynTPEnh" (new data: "") deleted in System Startup global entry!
5/19/2010 6:05:43 PM Allowed (based on user decision) value "Tvs" (new data: "") deleted in System Startup global entry!
5/19/2010 6:06:09 PM Allowed (based on user decision) value "TPSMain" (new data: "") deleted in System Startup global entry!
5/19/2010 6:06:39 PM Allowed (based on user decision) value "SmoothView" (new data: "") deleted in System Startup global entry!
5/19/2010 6:07:47 PM Allowed (based on user decision) value "Pinger" (new data: "") deleted in System Startup global entry!
5/19/2010 6:09:15 PM Allowed (based on user decision) value "QuickTime Task" (new data: "") deleted in System Startup global entry!
5/19/2010 6:11:15 PM Allowed (based on user decision) value "HPDJ Taskbar Utility" (new data: "") deleted in System Startup global entry!
5/19/2010 6:13:01 PM Allowed (based on user decision) value "MSN" (new data: "") deleted in System Startup global entry!
5/19/2010 6:45:52 PM Allowed (based on user decision) value "SpybotSD TeaTimer" (new data: "") deleted in System Startup user entry!
5/21/2010 10:15:06 PM Allowed (based on user decision) value "MSN" (new data: "") deleted in System Startup global entry!
5/22/2010 4:51:52 PM Allowed (based on user decision) value "MSN" (new data: "C:\Windows\mwmev.exe") added in System Startup global entry!
5/22/2010 4:53:30 PM Allowed (based on authenticode whitelist) value "{5ED80217-570B-4DA9-BF44-BE107C0EC166}" (new data: "") added in ActiveX Distribution Unit!
thanks for your work, hth
