This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] trojan horse

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I did a scan of my computer with trend micro internet security pro and it found a file slave.exe that it could not remove from my computer. I tried to delete it and it said that I was not allowed to delete the file and then I tried to quarantine it and was unable to. I don't know how to get this file off of my computer and I need help. I went to trend micro's website and they told me to download hijackthis and post my logs to a forum. I previously posted this on the 18th and I went on vacation and the post was closed due to inactivity. The last reply told me to do a rooter scan and otlistit2. I hope that I can get some help with this problem. Thank you

Microsoft Windows XP Professional (5.1.2600) Service Pack 3

C:\ [Fixed] - NTFS - (Total:38146 Mo/Free:2013 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)

Mon 03/23/2009|19:50

———————-\\ Processes..

–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINDOWS\system32\csrss.exe
———- \??\C:\WINDOWS\system32\winlogon.exe
———- C:\WINDOWS\system32\services.exe
———- C:\WINDOWS\system32\lsass.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\Explorer.EXE
———- C:\WINDOWS\system32\spoolsv.exe
———- C:\Program Files\Trend Micro\BM\TMBMSRV.exe
———- C:\Program Files\Common Files\Apple\Mobile Device

Support\bin\AppleMobileDeviceService.exe
———- C:\Program Files\Bonjour\mDNSResponder.exe
———- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
———- C:\Program Files\Java\jre6\bin\jqs.exe
———- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
———- C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
———- C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
———- C:\WINDOWS\Slave.exe
———- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
———- C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
———- C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
———- C:\WINDOWS\System32\alg.exe
———- C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
———- C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
———- C:\Program Files\ltmoh\Ltmoh.exe
———- C:\WINDOWS\AGRSMMSG.exe
———- C:\WINDOWS\system32\igfxtray.exe
———- C:\WINDOWS\system32\hkcmd.exe
———- C:\Program Files\Microsoft Hardware\Mouse\point32.exe
———- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
———- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE
———- C:\WINDOWS\System32\svchost.exe
———- C:\Program Files\iTunes\iTunesHelper.exe
———- C:\Program Files\Java\jre6\bin\jusched.exe
———- C:\WINDOWS\system32\ctfmon.exe
———- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
———- C:\Program Files\iPod\bin\iPodService.exe
———- C:\Program Files\Trend

Micro\TrendSecure\TISProToolbar\PlatformDependent\ProToolbarComm.exe
———- C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
———- C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
———- C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
———- C:\Program Files\Internet Explorer\iexplore.exe
———- C:\WINDOWS\system32\kdfmgr.exe
———- C:\WINDOWS\system32\cmd.exe
———- C:\Rooter$\RK.exe

———————-\\ Search..

———————-\\ ROOTKIT !!


———————-\\ Cracks & Keygens..

C:\DOCUME~1\Shaena\Cookies\shaena@crackle[1].txt


1 - "C:\Rooter$\Rooter_1.txt" - Mon 03/23/2009|19:51

———————-\\ Scan completed at 19:51


OTListIt logfile created on: 3/23/2009 7:55:07 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.1 Folder = C:\Documents and Settings\Shaena\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1006.80 Mb Total Physical Memory | 649.42 Mb Available Physical Memory | 64.50% Memory free
2.37 Gb Paging File | 2.01 Gb Available in Paging File | 84.88% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 21.97 Gb Free Space | 58.97% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SHAE
Current User Name: Shaena
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2008/04/13 20:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2009/03/03 04:46:13 | 00,341,256 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe
PRC - [2008/11/07 15:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/10/03 21:12:41 | 00,168,432 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
PRC - [2009/03/18 10:48:44 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2003/06/19 17:25:00 | 00,322,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2008/08/14 07:08:59 | 00,181,584 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
PRC - [2009/03/13 06:43:18 | 00,711,248 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
PRC - [2009/03/18 12:49:10 | 00,105,202 | —- | M] (TWD Industries SAS) – C:\WINDOWS\Slave.exe
PRC - [2002/09/20 10:50:10 | 00,045,056 | —- | M] (Analog Devices, Inc.) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
PRC - [2009/03/13 06:43:28 | 00,497,008 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
PRC - [2009/03/13 06:43:32 | 00,677,128 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
PRC - [2009/03/13 06:43:34 | 00,995,528 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
PRC - [2009/02/12 18:52:26 | 00,083,280 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
PRC - [2003/02/28 13:54:58 | 00,040,960 | —- | M] (adi) – C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
PRC - [2003/01/02 11:16:38 | 00,172,032 | —- | M] (Agere Systems) – C:\Program Files\ltmoh\Ltmoh.exe
PRC - [2003/04/18 05:20:10 | 00,088,363 | —- | M] (Agere Systems) – C:\WINDOWS\AGRSMMSG.exe
PRC - [2003/04/06 18:19:52 | 00,155,648 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\igfxtray.exe
PRC - [2003/04/06 18:07:38 | 00,114,688 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\hkcmd.exe
PRC - [2002/04/11 14:47:52 | 00,176,128 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Hardware\Mouse\point32.exe
PRC - [2005/02/01 23:00:00 | 00,098,304 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
PRC - [2002/04/24 21:00:00 | 00,074,240 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE
PRC - [2008/11/20 14:20:54 | 00,290,088 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/03/18 10:48:44 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2007/08/26 03:06:44 | 00,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/11/20 14:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/02/12 18:52:44 | 00,161,104 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\PlatformDependent\ProToolbarComm.exe
PRC - [2009/02/12 19:03:10 | 00,169,296 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
PRC - [2009/02/12 19:03:06 | 00,275,792 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
PRC - [2009/03/13 21:38:02 | 00,492,808 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
PRC - [2008/12/19 01:25:25 | 00,634,024 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009/03/23 19:45:52 | 00,387,288 | —- | M] (Bluegem Security) – C:\WINDOWS\system32\kdfmgr.exe
PRC - [2008/04/13 20:12:14 | 00,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\cmd.exe
PRC - [2009/03/23 19:52:32 | 00,499,200 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Shaena\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/11/07 15:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - [2008/07/25 12:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe – (Bonjour Service [Auto | Running])
SRV - [2008/07/25 12:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/29 22:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/10/03 21:12:41 | 00,168,432 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [Auto | Running])
SRV - [2008/04/13 20:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2004/10/22 05:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/07/29 20:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2008/11/20 14:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
SRV - [2009/03/18 10:48:44 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2003/06/19 17:25:00 | 00,322,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE – (MDM [Auto | Running])
SRV - [2008/07/29 20:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2003/07/28 06:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2007/04/22 22:29:34 | 00,088,824 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe – (Roxio UPnP Renderer 9 [On_Demand | Stopped])
SRV - [2007/04/22 22:29:32 | 00,359,160 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe – (Roxio Upnp Server 9 [Auto | Stopped])
SRV - [2007/04/23 13:43:54 | 00,310,008 | —- | M] (Sonic Solutions) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe – (RoxLiveShare9 [Auto | Stopped])
SRV - [2007/04/23 13:43:46 | 01,010,424 | —- | M] (Sonic Solutions) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe – (RoxMediaDB9 [On_Demand | Stopped])
SRV - [2007/04/23 13:43:54 | 00,166,648 | —- | M] (Sonic Solutions) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe – (RoxWatch9 [Auto | Stopped])
SRV - [2008/08/14 07:08:59 | 00,181,584 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe – (Security Activity Dashboard Service [Auto | Running])
SRV - [2009/03/13 06:43:18 | 00,711,248 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe – (SfCtlCom [Auto | Running])
SRV - [2009/03/18 12:49:10 | 00,105,202 | —- | M] (TWD Industries SAS) – C:\WINDOWS\Slave.exe – (Slave [Auto | Running])
SRV - [2002/09/20 10:50:10 | 00,045,056 | —- | M] (Analog Devices, Inc.) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe – (SoundMAX Agent Service (default) [Auto | Running])
SRV - [2009/03/03 04:46:13 | 00,341,256 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe – (TMBMServer [Auto | Running])
SRV - [2009/03/13 06:43:28 | 00,497,008 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe – (TmPfw [Auto | Running])
SRV - [2009/03/13 06:43:32 | 00,677,128 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe – (TmProxy [Auto | Running])
SRV - [2006/10/18 21:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2003/01/10 09:51:34 | 00,098,912 | —- | M] (Andrea Electronics Corporation) – C:\WINDOWS\system32\drivers\aeaudio.sys – (aeaudio [On_Demand | Running])
DRV - [2002/12/20 08:07:34 | 01,164,576 | —- | M] (Agere Systems) – C:\WINDOWS\system32\DRIVERS\AGRSM.sys – (AgereSoftModem [On_Demand | Running])
DRV - [2007/08/28 16:08:45 | 00,015,423 | —- | M] (Linksys Corporation) – C:\WINDOWS\System32\BEFCMU10.SYS – (BEFCMU10 [On_Demand | Stopped])
DRV - [2006/10/06 18:59:06 | 00,044,224 | R— | M] (BVRP Software) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS – (BVRPMPR5 [On_Demand | Stopped])
DRV - [2002/09/25 00:09:12 | 00,140,800 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\DRIVERS\e100b325.sys – (E100B [On_Demand | Running])
DRV - [2001/08/09 20:03:00 | 00,070,084 | —- | M] (MK Systems CO., LTD.) – C:\WINDOWS\system32\Drivers\EPLPDX02.SYS – (Eplpdx02 [On_Demand | Running])
DRV - [2008/04/17 13:12:54 | 00,015,464 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [2003/04/23 04:10:06 | 00,090,907 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\DRIVERS\ialmnt5.sys – (ialm [On_Demand | Running])
DRV - [2002/04/11 14:47:52 | 00,011,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\IPFilter.sys – (IPFilter [On_Demand | Running])
DRV - File not found – – (neokdss [On_Demand | Running])
DRV - [2003/09/19 09:45:48 | 00,021,248 | —- | M] (Padus, Inc.) – C:\WINDOWS\system32\drivers\pfc.sys – (pfc [On_Demand | Running])
DRV - [2002/08/29 08:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007/03/23 05:00:00 | 00,043,528 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2006/11/07 21:02:04 | 00,022,272 | —- | M] (Research In Motion Limited) – C:\WINDOWS\System32\Drivers\RimUsb.sys – (RimUsb [On_Demand | Stopped])
DRV - [2007/01/18 12:24:58 | 00,026,496 | R— | M] (Research in Motion Ltd) – C:\WINDOWS\system32\DRIVERS\RimSerial.sys – (RimVSerPort [On_Demand | Running])
DRV - [2002/08/29 08:00:00 | 00,005,888 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\Drivers\RootMdm.sys – (ROOTMODEM [On_Demand | Running])
DRV - [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2003/01/28 05:32:02 | 00,541,376 | —- | M] (Analog Devices, Inc.) – C:\WINDOWS\system32\drivers\smwdm.sys – (smwdm [On_Demand | Running])
DRV - [2001/08/17 14:56:16 | 00,007,552 | —- | M] (Sony Corporation) – C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS – (SONYPVU1 [On_Demand | Stopped])
DRV - [2009/03/03 04:34:17 | 00,050,192 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\drivers\tmactmon.sys – (tmactmon [Auto | Running])
DRV - [2009/03/03 05:08:15 | 00,335,376 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\TM_CFW.sys – (tmcfw [On_Demand | Running])
DRV - [2009/03/03 04:34:20 | 00,150,032 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\drivers\tmcomm.sys – (tmcomm [Auto | Running])
DRV - [2009/03/03 04:34:24 | 00,050,192 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\drivers\tmevtmgr.sys – (tmevtmgr [Auto | Running])
DRV - [2009/03/05 22:17:48 | 00,036,368 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\tmpreflt.sys – (tmpreflt [Auto | Running])
DRV - [2009/03/03 19:12:44 | 00,080,400 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\tmtdi.sys – (tmtdi [System | Running])
DRV - [2009/03/05 22:17:48 | 00,205,328 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\tmxpflt.sys – (tmxpflt [Auto | Running])
DRV - [2008/10/01 13:01:28 | 00,032,000 | —- | M] (Apple, Inc.) – C:\WINDOWS\System32\Drivers\usbaapl.sys – (USBAAPL [On_Demand | Stopped])
DRV - [2009/03/05 22:17:48 | 01,195,512 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\vsapint.sys – (vsapint [Auto | Running])
DRV - [2002/08/28 18:59:26 | 00,154,624 | —- | M] (Lucent Technologies) – C:\WINDOWS\System32\DRIVERS\wlluc48.sys – (wlluc48 [On_Demand | Running])
DRV - [2003/04/23 04:15:06 | 00,113,504 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\drivers\ialmsbw.sys – ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Running])
DRV - [2003/04/23 04:14:56 | 00,078,752 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\drivers\ialmkchw.sys – ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\PROGRAM FILES\TREND MICRO\TRENDSECURE\TISPROTOOLBAR\FIREFOXEXTENSION [2009/03/19 19:59:24 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/02/13 08:52:40 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/18 10:48:46 | 00,000,000 | —D | M]


O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (&Google; Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [EPSON Stylus C82 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE" /P23 "EPSON Stylus C82 Series" /O6 "USB002" /M "Stylus C82" (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [EPSON Stylus CX4800 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE" /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800" (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [LtMoh] "C:\Program Files\ltmoh\Ltmoh.exe" (Agere Systems)
O4 - HKLM..\Run: [masqform.exe] "C:\Program Files\PureEdge\Viewer 6.5\masqform.exe" -RunOnce (PureEdge™ Solutions Inc.)
O4 - HKLM..\Run: [PmProxy] "C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe" (adi)
O4 - HKLM..\Run: [POINTER] point32.exe File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" (Sonic Solutions)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" (Trend Micro Inc.)
O4 - HKCU..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1188128455940 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/14 09:42:10 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{dd348cb4-ca0d-11dc-b435-00022db216e5}\Shell\AutoRun\command - "" = F:\WD_Windows_Tools\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
NetSvcs: 6to4:
NetSvcs: AppMgmt: C:\WINDOWS\System32\appmgmts.dll (Microsoft Corporation)
NetSvcs: AudioSrv: C:\WINDOWS\System32\audiosrv.dll (Microsoft Corporation)
NetSvcs: Browser: C:\WINDOWS\System32\browser.dll (Microsoft Corporation)
NetSvcs: CryptSvc: C:\WINDOWS\System32\cryptsvc.dll (Microsoft Corporation)
NetSvcs: DMServer: C:\WINDOWS\System32\dmserver.dll (Microsoft Corp.)
NetSvcs: DHCP: C:\WINDOWS\System32\dhcpcsvc.dll (Microsoft Corporation)
NetSvcs: ERSvc: C:\WINDOWS\System32\ersvc.dll (Microsoft Corporation)
NetSvcs: EventSystem: C:\WINDOWS\System32\es.dll (Microsoft Corporation)
NetSvcs: FastUserSwitchingCompatibility: C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
NetSvcs: HidServ: C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias:
NetSvcs: Iprip:
NetSvcs: Irmon:
NetSvcs: LanmanServer: C:\WINDOWS\System32\srvsvc.dll (Microsoft Corporation)
NetSvcs: LanmanWorkstation: C:\WINDOWS\System32\wkssvc.dll (Microsoft Corporation)
NetSvcs: Messenger: C:\WINDOWS\System32\msgsvc.dll (Microsoft Corporation)
NetSvcs: Netman: C:\WINDOWS\System32\netman.dll (Microsoft Corporation)
NetSvcs: Nla: C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
NetSvcs: Ntmssvc: C:\WINDOWS\system32\ntmssvc.dll (Microsoft Corporation)
NetSvcs: NWCWorkstation:
NetSvcs: Nwsapagent:
NetSvcs: Rasauto: C:\WINDOWS\System32\rasauto.dll (Microsoft Corporation)
NetSvcs: Rasman: C:\WINDOWS\System32\rasmans.dll (Microsoft Corporation)
NetSvcs: Remoteaccess: C:\WINDOWS\System32\mprdim.dll (Microsoft Corporation)
NetSvcs: Schedule: C:\WINDOWS\system32\schedsvc.dll (Microsoft Corporation)
NetSvcs: Seclogon: C:\WINDOWS\System32\seclogon.dll (Microsoft Corporation)
NetSvcs: SENS: C:\WINDOWS\system32\sens.dll (Microsoft Corporation)
NetSvcs: Sharedaccess: C:\WINDOWS\System32\ipnathlp.dll (Microsoft Corporation)
NetSvcs: SRService: C:\WINDOWS\System32\srsvc.dll (Microsoft Corporation)
NetSvcs: Tapisrv: C:\WINDOWS\System32\tapisrv.dll (Microsoft Corporation)
NetSvcs: Themes: C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
NetSvcs: TrkWks: C:\WINDOWS\system32\trkwks.dll (Microsoft Corporation)
NetSvcs: W32Time: C:\WINDOWS\System32\w32time.dll (Microsoft Corporation)
NetSvcs: WZCSVC: C:\WINDOWS\System32\wzcsvc.dll (Microsoft Corporation)
NetSvcs: Wmi: C:\WINDOWS\System32\advapi32.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp:
NetSvcs: winmgmt: C:\WINDOWS\system32\wbem\WMIsvc.dll (Microsoft Corporation)
NetSvcs: TermService: C:\WINDOWS\System32\termsrv.dll (Microsoft Corporation)
NetSvcs: wuauserv: C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)
NetSvcs: BITS: C:\WINDOWS\system32\qmgr.dll (Microsoft Corporation)
NetSvcs: ShellHWDetection: C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
NetSvcs: helpsvc: C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
NetSvcs: xmlprov: C:\WINDOWS\System32\xmlprov.dll (Microsoft Corporation)
NetSvcs: wscsvc: C:\WINDOWS\system32\wscsvc.dll (Microsoft Corporation)
NetSvcs: WmdmPmSN: C:\WINDOWS\system32\MsPMSNSv.dll (Microsoft Corporation)
NetSvcs: napagent: C:\WINDOWS\System32\qagentrt.dll (Microsoft Corporation)
NetSvcs: hkmsvc: C:\WINDOWS\System32\kmsvc.dll (Microsoft Corporation)
SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll (Microsoft Corporation)
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: CryptSvc - %SystemRoot%\System32\cryptsvc.dll (Microsoft Corporation)
SafeBootMin: DcomLaunch - %SystemRoot%\system32\rpcss.dll (Microsoft Corporation)
SafeBootMin: dmadmin - %SystemRoot%\System32\dmadmin.exe (Microsoft Corp., Veritas Software)
SafeBootMin: dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys (Microsoft Corp., Veritas Software)
SafeBootMin: dmio.sys - %SystemRoot%\System32\drivers\dmio.sys (Microsoft Corp., Veritas Software)
SafeBootMin: dmload.sys - %SystemRoot%\System32\drivers\dmload.sys (Microsoft Corp., Veritas Software.)
SafeBootMin: dmserver - %SystemRoot%\System32\dmserver.dll (Microsoft Corp.)
SafeBootMin: EventLog - %SystemRoot%\system32\services.exe (Microsoft Corporation)
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootMin: Netlogon - %SystemRoot%\System32\lsass.exe (Microsoft Corporation)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PlugPlay - %SystemRoot%\system32\services.exe (Microsoft Corporation)
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: RpcSs - %SystemRoot%\system32\rpcss.dll (Microsoft Corporation)
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: sr.sys - %SystemRoot%\System32\DRIVERS\sr.sys (Microsoft Corporation)
SafeBootMin: SRService - %SystemRoot%\System32\srsvc.dll (Microsoft Corporation)
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: vgasave.sys - %SystemRoot%\System32\drivers\vga.sys (Microsoft Corporation)
SafeBootMin: WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: AFD - %SystemRoot%\System32\drivers\afd.sys (Microsoft Corporation)
SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll (Microsoft Corporation)
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: Browser - %SystemRoot%\System32\browser.dll (Microsoft Corporation)
SafeBootNet: CryptSvc - %SystemRoot%\System32\cryptsvc.dll (Microsoft Corporation)
SafeBootNet: DcomLaunch - %SystemRoot%\system32\rpcss.dll (Microsoft Corporation)
SafeBootNet: Dhcp - %SystemRoot%\System32\dhcpcsvc.dll (Microsoft Corporation)
SafeBootNet: dmadmin - %SystemRoot%\System32\dmadmin.exe (Microsoft Corp., Veritas Software)
SafeBootNet: dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys (Microsoft Corp., Veritas Software)
SafeBootNet: dmio.sys - %SystemRoot%\System32\drivers\dmio.sys (Microsoft Corp., Veritas Software)
SafeBootNet: dmload.sys - %SystemRoot%\System32\drivers\dmload.sys (Microsoft Corp., Veritas Software.)
SafeBootNet: dmserver - %SystemRoot%\System32\dmserver.dll (Microsoft Corp.)
SafeBootNet: DnsCache - %SystemRoot%\System32\dnsrslvr.dll (Microsoft Corporation)
SafeBootNet: EventLog - %SystemRoot%\system32\services.exe (Microsoft Corporation)
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootNet: ip6fw.sys - %SystemRoot%\system32\drivers\ip6fw.sys (Microsoft Corporation)
SafeBootNet: ipnat.sys - %SystemRoot%\System32\DRIVERS\ipnat.sys (Microsoft Corporation)
SafeBootNet: LanmanServer - %SystemRoot%\System32\srvsvc.dll (Microsoft Corporation)
SafeBootNet: LanmanWorkstation - %SystemRoot%\System32\wkssvc.dll (Microsoft Corporation)
SafeBootNet: LmHosts - %SystemRoot%\System32\lmhsvc.dll (Microsoft Corporation)
SafeBootNet: Messenger - %SystemRoot%\System32\msgsvc.dll (Microsoft Corporation)
SafeBootNet: NDIS - %SystemRoot%\System32\drivers\ndis.sys (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: Ndisuio - %SystemRoot%\System32\DRIVERS\ndisuio.sys (Microsoft Corporation)
SafeBootNet: NetBIOS - %SystemRoot%\System32\DRIVERS\netbios.sys (Microsoft Corporation)
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetBT - %SystemRoot%\System32\DRIVERS\netbt.sys (Microsoft Corporation)
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Netlogon - %SystemRoot%\System32\lsass.exe (Microsoft Corporation)
SafeBootNet: NetMan - %SystemRoot%\System32\netman.dll (Microsoft Corporation)
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NtLmSsp - %SystemRoot%\System32\lsass.exe (Microsoft Corporation)
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PlugPlay - %SystemRoot%\system32\services.exe (Microsoft Corporation)
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdpcdd.sys - %SystemRoot%\System32\DRIVERS\RDPCDD.sys (Microsoft Corporation)
SafeBootNet: rdpdd.sys - %SystemRoot%\System32\rdpdd.dll (Microsoft Corporation)
SafeBootNet: rdpwd.sys - %SystemRoot%\System32\drivers\rdpwd.sys (Microsoft Corporation)
SafeBootNet: rdsessmgr - %SystemRoot%\system32\sessmgr.exe (Microsoft Corporation)
SafeBootNet: RpcSs - %SystemRoot%\system32\rpcss.dll (Microsoft Corporation)
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: sharedaccess - %SystemRoot%\System32\ipnathlp.dll (Microsoft Corporation)
SafeBootNet: sr.sys - %SystemRoot%\System32\DRIVERS\sr.sys (Microsoft Corporation)
SafeBootNet: SRService - %SystemRoot%\System32\srsvc.dll (Microsoft Corporation)
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: Tcpip - %SystemRoot%\System32\DRIVERS\tcpip.sys (Microsoft Corporation)
SafeBootNet: TDI - Driver Group
SafeBootNet: tdpipe.sys - %SystemRoot%\System32\drivers\tdpipe.sys (Microsoft Corporation)
SafeBootNet: tdtcp.sys - %SystemRoot%\System32\drivers\tdtcp.sys (Microsoft Corporation)
SafeBootNet: termservice - %SystemRoot%\System32\termsrv.dll (Microsoft Corporation)
SafeBootNet: UploadMgr - Service
SafeBootNet: vga.sys - Driver
SafeBootNet: vgasave.sys - %SystemRoot%\System32\drivers\vga.sys (Microsoft Corporation)
SafeBootNet: WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll (Microsoft Corporation)
SafeBootNet: WZCSVC - %SystemRoot%\System32\wzcsvc.dll (Microsoft Corporation)
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608555} - Internet Explorer Classes for Java
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 11.0.3
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 11.0.3
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9212D8B4-C3CF-43E1-A1FF-8EEA311633DC} - PureEdge Viewer
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

========== Files/Folders - Created Within 30 Days ==========

[5 C:\WINDOWS\*.tmp files]
[2009/03/23 19:52:15 | 00,499,200 | —- | C] (OldTimer Tools) – C:\DOCUME~1\Shaena\Desktop\OTListIt2.exe
[2009/03/23 19:50:05 | 00,000,000 | —D | C] – C:\Rooter$
[2009/03/23 19:49:37 | 00,267,612 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\Rooter.exe
[2009/03/23 10:30:57 | 01,095,541 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\img001.jpg
[2009/03/23 07:00:20 | 00,026,112 | —- | C] () – C:\DOCUME~1\Shaena\My Documents\Attic live load.doc
[2009/03/18 13:08:30 | 00,401,720 | —- | C] (Trend Micro Inc.) – C:\DOCUME~1\Shaena\Desktop\HijackThis.exe
[2009/03/18 10:58:39 | 02,036,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_40.dll
[2009/03/18 10:58:39 | 00,452,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_40.dll
[2009/03/18 10:58:38 | 04,379,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_40.dll
[2009/03/18 10:58:36 | 00,514,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_3.dll
[2009/03/18 10:58:36 | 00,070,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_2.dll
[2009/03/18 10:58:35 | 00,235,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_3.dll
[2009/03/18 10:58:34 | 00,023,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_5.dll
[2009/03/18 10:58:32 | 00,509,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_2.dll
[2009/03/18 10:58:32 | 00,068,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_1.dll
[2009/03/18 10:58:31 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_2.dll
[2009/03/18 10:58:30 | 01,493,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_39.dll
[2009/03/18 10:58:30 | 00,467,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_39.dll
[2009/03/18 10:58:29 | 03,851,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_39.dll
[2009/03/18 10:58:27 | 00,507,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_1.dll
[2009/03/18 10:58:27 | 00,065,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_0.dll
[2009/03/18 10:58:26 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_1.dll
[2009/03/18 10:58:25 | 00,025,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_4.dll
[2009/03/18 10:58:24 | 01,491,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_38.dll
[2009/03/18 10:58:24 | 00,467,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_38.dll
[2009/03/18 10:58:23 | 03,850,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_38.dll
[2009/03/18 10:58:21 | 00,479,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_0.dll
[2009/03/18 10:58:20 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_0.dll
[2009/03/18 10:58:19 | 00,025,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_3.dll
[2009/03/18 10:58:18 | 01,420,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_37.dll
[2009/03/18 10:58:18 | 00,462,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_37.dll
[2009/03/18 10:58:17 | 03,786,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_37.dll
[2009/03/18 10:58:15 | 00,267,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_10.dll
[2009/03/18 10:58:13 | 01,374,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_36.dll
[2009/03/18 10:58:13 | 00,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_36.dll
[2009/03/18 10:58:12 | 03,734,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_36.dll
[2009/03/18 10:58:11 | 00,267,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_9.dll
[2009/03/18 10:58:10 | 01,358,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_35.dll
[2009/03/18 10:58:10 | 00,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_35.dll
[2009/03/18 10:58:08 | 03,727,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_35.dll
[2009/03/18 10:58:07 | 00,266,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_8.dll
[2009/03/18 10:58:07 | 00,017,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_2.dll
[2009/03/18 10:58:06 | 01,124,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_34.dll
[2009/03/18 10:58:06 | 00,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_34.dll
[2009/03/18 10:58:05 | 03,497,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_34.dll
[2009/03/18 10:58:04 | 00,081,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_3.dll
[2009/03/18 10:58:03 | 00,261,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_7.dll
[2009/03/18 10:57:54 | 00,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_33.dll
[2009/03/18 10:57:53 | 01,123,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_33.dll
[2009/03/18 10:57:41 | 03,495,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_33.dll
[2009/03/18 10:57:40 | 00,255,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_6.dll
[2009/03/18 10:57:39 | 00,251,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_5.dll
[2009/03/18 10:57:38 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2009/03/18 10:57:37 | 00,237,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_4.dll
[2009/03/18 10:57:37 | 00,015,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_1.dll
[2009/03/18 10:57:36 | 02,414,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_31.dll
[2009/03/18 10:57:35 | 00,236,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_3.dll
[2009/03/18 10:57:34 | 00,062,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_2.dll
[2009/03/18 10:57:33 | 00,230,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_2.dll
[2009/03/18 10:57:32 | 00,062,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_1.dll
[2009/03/18 10:57:31 | 00,229,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_1.dll
[2009/03/18 10:57:23 | 02,388,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_30.dll
[2009/03/18 10:57:22 | 00,230,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_0.dll
[2009/03/18 10:57:22 | 00,014,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_0.dll
[2009/03/18 10:57:21 | 02,332,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_29.dll
[2009/03/18 10:57:20 | 02,323,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_28.dll
[2009/03/18 10:57:20 | 00,061,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput9_1_0.dll
[2009/03/18 10:57:19 | 02,319,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_27.dll
[2009/03/18 10:57:17 | 02,297,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_26.dll
[2009/03/18 10:57:16 | 02,337,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_25.dll
[2009/03/18 10:57:12 | 02,222,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_24.dll
[2009/03/18 10:54:10 | 00,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2009/03/18 10:53:52 | 00,000,000 | —D | C] – C:\WINDOWS\Logs
[2009/03/09 09:10:22 | 00,584,901 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\img068.jpg
[2009/03/09 09:09:34 | 00,426,855 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\img064.jpg
[2009/03/09 09:09:08 | 00,649,993 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\img067.jpg
[2009/03/01 21:34:29 | 00,005,657 | —- | C] () – C:\DOCUME~1\Shaena\My Documents\2nd floor remodel.PSH
[2009/03/01 19:50:32 | 00,030,291 | —- | C] () – C:\DOCUME~1\Shaena\My Documents\Shaena's Garage Addition.PSH
[2009/02/24 18:40:08 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/03/23 19:52:32 | 00,499,200 | —- | M] (OldTimer Tools) – C:\DOCUME~1\Shaena\Desktop\OTListIt2.exe
[2009/03/23 19:49:40 | 00,267,612 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\Rooter.exe
[2009/03/23 19:45:55 | 00,192,512 | —- | M] (??????) – C:\WINDOWS\System32\kdfvmgr.exe
[2009/03/23 19:45:55 | 00,077,824 | —- | M] (Kings Information & Network) – C:\WINDOWS\System32\kdfapi.dll
[2009/03/23 19:45:55 | 00,053,248 | —- | M] (Kings Information & Network) – C:\WINDOWS\System32\Kdfhok.dll
[2009/03/23 19:45:52 | 00,387,288 | —- | M] (Bluegem Security) – C:\WINDOWS\System32\kdfmgr.exe
[2009/03/23 10:30:57 | 01,095,541 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\img001.jpg
[2009/03/23 08:50:10 | 00,649,993 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\img067.jpg
[2009/03/23 07:31:21 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/23 07:30:58 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/23 07:30:53 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/23 07:00:21 | 00,026,112 | —- | M] () – C:\DOCUME~1\Shaena\My Documents\Attic live load.doc
[2009/03/19 20:02:10 | 00,475,872 | —- | M] (Bluegem Security) – C:\WINDOWS\System32\kdfinj.dll
[2009/03/18 16:59:52 | 00,518,144 | —- | M] () – C:\DOCUME~1\Shaena\My Documents\Outback Steakhouse Recipies.doc
[2009/03/18 13:08:30 | 00,401,720 | —- | M] (Trend Micro Inc.) – C:\DOCUME~1\Shaena\Desktop\HijackThis.exe
[2009/03/18 12:49:10 | 00,105,202 | —- | M] (TWD Industries SAS) – C:\WINDOWS\Slave.exe
[2009/03/18 11:07:28 | 00,030,291 | —- | M] () – C:\DOCUME~1\Shaena\My Documents\Shaena's Garage Addition.PSH
[2009/03/18 10:35:47 | 00,005,657 | —- | M] () – C:\DOCUME~1\Shaena\My Documents\2nd floor remodel.PSH
[2009/03/16 23:12:08 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/12 09:36:57 | 00,435,498 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/12 09:36:57 | 00,068,354 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/12 09:36:56 | 00,512,960 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/12 09:33:55 | 00,297,256 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/12 09:23:29 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/09 09:10:22 | 00,584,901 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\img068.jpg
[2009/03/09 09:09:35 | 00,426,855 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\img064.jpg
[2009/03/05 22:17:48 | 01,195,512 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\vsapint.sys
[2009/03/05 22:17:48 | 00,205,328 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmxpflt.sys
[2009/03/05 22:17:48 | 00,036,368 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmpreflt.sys
[2009/03/03 19:12:44 | 00,080,400 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmtdi.sys
[2009/03/03 05:08:15 | 00,335,376 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\TM_CFW.sys
[2009/03/03 04:34:24 | 00,050,192 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2009/03/03 04:34:20 | 00,150,032 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/03/03 04:34:17 | 00,050,192 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmactmon.sys
[2009/02/25 12:55:00 | 24,768,960 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe

========== Custom Scans ==========


< %systemroot%\System32\antiwpa.dll >

< %systemroot%\SYSTEM32\wpa.dll >

< %systemroot%\setup\scripts\biestart.exe >

< %systemroot%\system32\drivers\royal.sys >

< %systemroot%\system32\serauth1.dll >

< %systemroot%\system32\serauth2.dll >

< %systemroot%\system32\sysaudio.sys >

< %systemroot%\system32\wdmaud.sys >

< %systemroot%\system32\aeaudio.sys >

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\WINDOWS\Slave.exe:SummaryInformation
< End of report >


OTListIt Extras logfile created on: 3/23/2009 7:55:07 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.1 Folder = C:\Documents and Settings\Shaena\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1006.80 Mb Total Physical Memory | 649.42 Mb Available Physical Memory | 64.50% Memory free
2.37 Gb Paging File | 2.01 Gb Available in Paging File | 84.88% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 21.97 Gb Free Space | 58.97% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SHAE
Current User Name: Shaena
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"4000:TCP" = 4000:TCP:*:Enabled:Update
"4000:UDP" = 4000:UDP:*:Enabled:Avir
"3999:TCP" = 3999:TCP:*:Enabled:ICS
"3999:UDP" = 3999:UDP:*:Enabled:Security
"3998:TCP" = 3998:TCP:*:Enabled:Internet
"3998:UDP" = 3998:UDP:*:Enabled:Firewall
"3997:TCP" = 3997:TCP:*:Enabled:Nod32
"3997:UDP" = 3997:UDP:*:Enabled:System
"3996:TCP" = 3996:TCP:*:Enabled:Yahoo
"3996:UDP" = 3996:UDP:*:Enabled:Kaspersky

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2007/04/22 22:29:34 | 00,088,824 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:*:Enabled:RoxioUPnPRenderer9
[2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2007/04/23 13:43:40 | 00,617,208 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Media Manager 9\MediaManager9.exe:*:Enabled:MediaManager9 Module
[2007/04/22 22:29:34 | 00,088,824 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:*:Enabled:RoxioUPnPRenderer9
[2004/06/04 02:58:10 | 00,196,608 | —- | M] (InterVideo Inc.) – C:\Program Files\InterVideo\DVD6\WinDVD.exe:*:Enabled:WinDVD
[2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/01/16 15:57:06 | 00,147,080 | —- | M] (ExtendMedia Inc.) – C:\Program Files\NBC Direct\StoreFrontPlayer.exe:*:Enabled:NBC Direct Beta
[2008/12/19 01:25:25 | 00,634,024 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer
[2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
[2008/11/20 14:20:48 | 14,294,824 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1FD0C5C1-B01B-4B4C-9607-E5D3B3D1318F}" = Microsoft IntelliPoint 4.1
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 12
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{40E12A55-C504-4223-AFAC-7672DBF1ACDE}" = Trend Micro Internet Security Pro
"{66D171AA-670F-4309-9C74-5BA7F7DBA0B3}" = Roxio Media Manager
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ACA2FD2-4C4A-42F3-AFB5-7B433BBDF6DB}" = InterVideo WinDVD 6
"{6DA9102E-199F-43A0-A36B-6EF48081A658}" = MobileMe Control Panel
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security Pro
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9B449C1A-4F64-4ED4-8C96-31B222E8377F}" = BlackBerry Desktop Software 4.2.2
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C91EF330-F152-44ED-A33A-0F4FF3FAF813}" = NBC Direct Beta
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}" = ArcSoft PhotoImpression 5
"{E0000650-0650-0650-0650-000000000650}" = PureEdge Viewer 6.5
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
"AC3Filter" = AC3Filter (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"BlackBerry_{9B449C1A-4F64-4ED4-8C96-31B222E8377F}" = BlackBerry Desktop Software 4.2.2
"CTDVDAudio Plugin" = Creative DVD Audio Plugin for Audigy Series
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InterActual Player" = InterActual Player
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Adapters and Drivers
"Punch! Super Home Suite" = Punch! Super Home Suite
"Silent Package Run-Time Sample" = EPSON CX 4200 4800 Guide
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/11/2009 8:50:42 AM | Computer Name = SHAE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/31/2009 9:20:43 PM | Computer Name = SHAE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/31/2009 9:23:37 PM | Computer Name = SHAE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/31/2009 9:23:42 PM | Computer Name = SHAE | Source = Application Hang | ID = 1001
Description = Fault bucket 1015682910.

Error - 2/2/2009 7:56:26 AM | Computer Name = SHAE | Source = Application Error | ID = 1000
Description = Faulting application msimn.exe, version 6.0.2900.5512, faulting module
inetcomm.dll, version 6.0.2900.5579, fault address 0x000148c1.

Error - 2/2/2009 7:56:33 AM | Computer Name = SHAE | Source = Application Error | ID = 1001
Description = Fault bucket 882718558.

Error - 2/16/2009 8:46:25 AM | Computer Name = SHAE | Source = Application Error | ID = 1000
Description = Faulting application tmarsvc.exe, version 1.0.0.1075, faulting module
LogPaser.dll, version 1.0.0.1075, fault address 0x0001269c.

Error - 2/17/2009 10:15:18 PM | Computer Name = SHAE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module mshtml.dll, version 7.0.6000.16809, fault address 0x00053b56.

Error - 3/10/2009 9:31:15 AM | Computer Name = SHAE | Source = Google_Toolbar | ID = 1
Description =

Error - 3/16/2009 12:50:33 PM | Computer Name = SHAE | Source = Google_Toolbar | ID = 1
Description =

[ System Events ]
Error - 3/20/2009 5:55:53 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.

Error - 3/20/2009 6:49:08 PM | Computer Name = SHAE | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 3/20/2009 7:52:03 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.

Error - 3/20/2009 7:52:22 PM | Computer Name = SHAE | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 00022DB216E5. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 3/21/2009 6:03:47 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.

Error - 3/21/2009 6:04:00 PM | Computer Name = SHAE | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 00022DB216E5. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 3/22/2009 8:50:07 AM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.

Error - 3/22/2009 5:03:06 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.

Error - 3/23/2009 6:25:31 AM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.

Error - 3/23/2009 7:42:21 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.


< End of report >
Hi Shaniqua79, Sorry to close your thread - logs are deemed inactive if there is no response after 5 days, if you have to go away again, just let me know and I'll keep the thread open. I will be looking over your logs now and get back to you shortly with further instructions CB
Hi Shaniqua79

Can you confirm for me that you are aware that you have a program installed on your computer called

REMOTE ANYTHING

by TWD Industries

and that you are aware of this program

If so what do you use it for?

This Program uses slave.exe

It is a program that can remotely control PCs via the Internet or on a LAN as if you were at the keyboard of the distant computer.

There may be a legitimate reason for this program to be installed. Please advise.
I did not know that I had that program on my computer. I don't need it nor do I want it on my computer. If I remove the program will it get rid of the file slave.exe?
I would think it should…I'm not too familiar with the program myself, but first see if it shows up in your programs list and see if it has it's own uninstaller. If not then go to Add/Remove programs and remove it from there.

But you should probably investigate a little to see where it came from first before uninstalling it, do you use the computer for work purposes, do you share this computer with anyone else.

If it was put there by your work it may be needed for a legitimate reason.
This is purchased softwaresometimes used in a work environment or a school environment if you take classes on-line for example.
So it had to have been downloaded and installed by someone.

Info for the program can be found here:
http://www.remote-anything.com/

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI