shaniqua79
Topic Starter
I did a scan of my computer with trend micro internet security pro and it found a file slave.exe that it could not remove from my computer. I tried to delete it and it said that I was not allowed to delete the file and then I tried to quarantine it and was unable to. I don't know how to get this file off of my computer and I need help. I went to trend micro's website and they told me to download hijackthis and post my logs to a forum. I previously posted this on the 18th and I went on vacation and the post was closed due to inactivity. The last reply told me to do a rooter scan and otlistit2. I hope that I can get some help with this problem. Thank you
Microsoft Windows XP Professional (5.1.2600) Service Pack 3
C:\ [Fixed] - NTFS - (Total:38146 Mo/Free:2013 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
Mon 03/23/2009|19:50
———————-\\ Processes..
–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINDOWS\system32\csrss.exe
———- \??\C:\WINDOWS\system32\winlogon.exe
———- C:\WINDOWS\system32\services.exe
———- C:\WINDOWS\system32\lsass.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\Explorer.EXE
———- C:\WINDOWS\system32\spoolsv.exe
———- C:\Program Files\Trend Micro\BM\TMBMSRV.exe
———- C:\Program Files\Common Files\Apple\Mobile Device
Support\bin\AppleMobileDeviceService.exe
———- C:\Program Files\Bonjour\mDNSResponder.exe
———- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
———- C:\Program Files\Java\jre6\bin\jqs.exe
———- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
———- C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
———- C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
———- C:\WINDOWS\Slave.exe
———- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
———- C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
———- C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
———- C:\WINDOWS\System32\alg.exe
———- C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
———- C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
———- C:\Program Files\ltmoh\Ltmoh.exe
———- C:\WINDOWS\AGRSMMSG.exe
———- C:\WINDOWS\system32\igfxtray.exe
———- C:\WINDOWS\system32\hkcmd.exe
———- C:\Program Files\Microsoft Hardware\Mouse\point32.exe
———- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
———- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE
———- C:\WINDOWS\System32\svchost.exe
———- C:\Program Files\iTunes\iTunesHelper.exe
———- C:\Program Files\Java\jre6\bin\jusched.exe
———- C:\WINDOWS\system32\ctfmon.exe
———- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
———- C:\Program Files\iPod\bin\iPodService.exe
———- C:\Program Files\Trend
Micro\TrendSecure\TISProToolbar\PlatformDependent\ProToolbarComm.exe
———- C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
———- C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
———- C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
———- C:\Program Files\Internet Explorer\iexplore.exe
———- C:\WINDOWS\system32\kdfmgr.exe
———- C:\WINDOWS\system32\cmd.exe
———- C:\Rooter$\RK.exe
———————-\\ Search..
———————-\\ ROOTKIT !!
———————-\\ Cracks & Keygens..
C:\DOCUME~1\Shaena\Cookies\shaena@crackle[1].txt
1 - "C:\Rooter$\Rooter_1.txt" - Mon 03/23/2009|19:51
———————-\\ Scan completed at 19:51
OTListIt logfile created on: 3/23/2009 7:55:07 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.1 Folder = C:\Documents and Settings\Shaena\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1006.80 Mb Total Physical Memory | 649.42 Mb Available Physical Memory | 64.50% Memory free
2.37 Gb Paging File | 2.01 Gb Available in Paging File | 84.88% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 21.97 Gb Free Space | 58.97% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SHAE
Current User Name: Shaena
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2008/04/13 20:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2009/03/03 04:46:13 | 00,341,256 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe
PRC - [2008/11/07 15:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/10/03 21:12:41 | 00,168,432 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
PRC - [2009/03/18 10:48:44 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2003/06/19 17:25:00 | 00,322,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2008/08/14 07:08:59 | 00,181,584 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
PRC - [2009/03/13 06:43:18 | 00,711,248 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
PRC - [2009/03/18 12:49:10 | 00,105,202 | —- | M] (TWD Industries SAS) – C:\WINDOWS\Slave.exe
PRC - [2002/09/20 10:50:10 | 00,045,056 | —- | M] (Analog Devices, Inc.) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
PRC - [2009/03/13 06:43:28 | 00,497,008 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
PRC - [2009/03/13 06:43:32 | 00,677,128 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
PRC - [2009/03/13 06:43:34 | 00,995,528 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
PRC - [2009/02/12 18:52:26 | 00,083,280 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
PRC - [2003/02/28 13:54:58 | 00,040,960 | —- | M] (adi) – C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
PRC - [2003/01/02 11:16:38 | 00,172,032 | —- | M] (Agere Systems) – C:\Program Files\ltmoh\Ltmoh.exe
PRC - [2003/04/18 05:20:10 | 00,088,363 | —- | M] (Agere Systems) – C:\WINDOWS\AGRSMMSG.exe
PRC - [2003/04/06 18:19:52 | 00,155,648 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\igfxtray.exe
PRC - [2003/04/06 18:07:38 | 00,114,688 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\hkcmd.exe
PRC - [2002/04/11 14:47:52 | 00,176,128 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Hardware\Mouse\point32.exe
PRC - [2005/02/01 23:00:00 | 00,098,304 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
PRC - [2002/04/24 21:00:00 | 00,074,240 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE
PRC - [2008/11/20 14:20:54 | 00,290,088 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/03/18 10:48:44 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2007/08/26 03:06:44 | 00,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/11/20 14:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/02/12 18:52:44 | 00,161,104 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\PlatformDependent\ProToolbarComm.exe
PRC - [2009/02/12 19:03:10 | 00,169,296 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
PRC - [2009/02/12 19:03:06 | 00,275,792 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
PRC - [2009/03/13 21:38:02 | 00,492,808 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
PRC - [2008/12/19 01:25:25 | 00,634,024 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009/03/23 19:45:52 | 00,387,288 | —- | M] (Bluegem Security) – C:\WINDOWS\system32\kdfmgr.exe
PRC - [2008/04/13 20:12:14 | 00,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\cmd.exe
PRC - [2009/03/23 19:52:32 | 00,499,200 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Shaena\Desktop\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2008/11/07 15:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - [2008/07/25 12:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe – (Bonjour Service [Auto | Running])
SRV - [2008/07/25 12:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/29 22:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/10/03 21:12:41 | 00,168,432 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [Auto | Running])
SRV - [2008/04/13 20:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2004/10/22 05:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/07/29 20:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2008/11/20 14:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
SRV - [2009/03/18 10:48:44 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2003/06/19 17:25:00 | 00,322,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE – (MDM [Auto | Running])
SRV - [2008/07/29 20:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2003/07/28 06:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2007/04/22 22:29:34 | 00,088,824 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe – (Roxio UPnP Renderer 9 [On_Demand | Stopped])
SRV - [2007/04/22 22:29:32 | 00,359,160 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe – (Roxio Upnp Server 9 [Auto | Stopped])
SRV - [2007/04/23 13:43:54 | 00,310,008 | —- | M] (Sonic Solutions) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe – (RoxLiveShare9 [Auto | Stopped])
SRV - [2007/04/23 13:43:46 | 01,010,424 | —- | M] (Sonic Solutions) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe – (RoxMediaDB9 [On_Demand | Stopped])
SRV - [2007/04/23 13:43:54 | 00,166,648 | —- | M] (Sonic Solutions) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe – (RoxWatch9 [Auto | Stopped])
SRV - [2008/08/14 07:08:59 | 00,181,584 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe – (Security Activity Dashboard Service [Auto | Running])
SRV - [2009/03/13 06:43:18 | 00,711,248 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe – (SfCtlCom [Auto | Running])
SRV - [2009/03/18 12:49:10 | 00,105,202 | —- | M] (TWD Industries SAS) – C:\WINDOWS\Slave.exe – (Slave [Auto | Running])
SRV - [2002/09/20 10:50:10 | 00,045,056 | —- | M] (Analog Devices, Inc.) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe – (SoundMAX Agent Service (default) [Auto | Running])
SRV - [2009/03/03 04:46:13 | 00,341,256 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe – (TMBMServer [Auto | Running])
SRV - [2009/03/13 06:43:28 | 00,497,008 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe – (TmPfw [Auto | Running])
SRV - [2009/03/13 06:43:32 | 00,677,128 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe – (TmProxy [Auto | Running])
SRV - [2006/10/18 21:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2003/01/10 09:51:34 | 00,098,912 | —- | M] (Andrea Electronics Corporation) – C:\WINDOWS\system32\drivers\aeaudio.sys – (aeaudio [On_Demand | Running])
DRV - [2002/12/20 08:07:34 | 01,164,576 | —- | M] (Agere Systems) – C:\WINDOWS\system32\DRIVERS\AGRSM.sys – (AgereSoftModem [On_Demand | Running])
DRV - [2007/08/28 16:08:45 | 00,015,423 | —- | M] (Linksys Corporation) – C:\WINDOWS\System32\BEFCMU10.SYS – (BEFCMU10 [On_Demand | Stopped])
DRV - [2006/10/06 18:59:06 | 00,044,224 | R— | M] (BVRP Software) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS – (BVRPMPR5 [On_Demand | Stopped])
DRV - [2002/09/25 00:09:12 | 00,140,800 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\DRIVERS\e100b325.sys – (E100B [On_Demand | Running])
DRV - [2001/08/09 20:03:00 | 00,070,084 | —- | M] (MK Systems CO., LTD.) – C:\WINDOWS\system32\Drivers\EPLPDX02.SYS – (Eplpdx02 [On_Demand | Running])
DRV - [2008/04/17 13:12:54 | 00,015,464 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [2003/04/23 04:10:06 | 00,090,907 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\DRIVERS\ialmnt5.sys – (ialm [On_Demand | Running])
DRV - [2002/04/11 14:47:52 | 00,011,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\IPFilter.sys – (IPFilter [On_Demand | Running])
DRV - File not found – – (neokdss [On_Demand | Running])
DRV - [2003/09/19 09:45:48 | 00,021,248 | —- | M] (Padus, Inc.) – C:\WINDOWS\system32\drivers\pfc.sys – (pfc [On_Demand | Running])
DRV - [2002/08/29 08:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007/03/23 05:00:00 | 00,043,528 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2006/11/07 21:02:04 | 00,022,272 | —- | M] (Research In Motion Limited) – C:\WINDOWS\System32\Drivers\RimUsb.sys – (RimUsb [On_Demand | Stopped])
DRV - [2007/01/18 12:24:58 | 00,026,496 | R— | M] (Research in Motion Ltd) – C:\WINDOWS\system32\DRIVERS\RimSerial.sys – (RimVSerPort [On_Demand | Running])
DRV - [2002/08/29 08:00:00 | 00,005,888 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\Drivers\RootMdm.sys – (ROOTMODEM [On_Demand | Running])
DRV - [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2003/01/28 05:32:02 | 00,541,376 | —- | M] (Analog Devices, Inc.) – C:\WINDOWS\system32\drivers\smwdm.sys – (smwdm [On_Demand | Running])
DRV - [2001/08/17 14:56:16 | 00,007,552 | —- | M] (Sony Corporation) – C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS – (SONYPVU1 [On_Demand | Stopped])
DRV - [2009/03/03 04:34:17 | 00,050,192 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\drivers\tmactmon.sys – (tmactmon [Auto | Running])
DRV - [2009/03/03 05:08:15 | 00,335,376 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\TM_CFW.sys – (tmcfw [On_Demand | Running])
DRV - [2009/03/03 04:34:20 | 00,150,032 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\drivers\tmcomm.sys – (tmcomm [Auto | Running])
DRV - [2009/03/03 04:34:24 | 00,050,192 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\drivers\tmevtmgr.sys – (tmevtmgr [Auto | Running])
DRV - [2009/03/05 22:17:48 | 00,036,368 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\tmpreflt.sys – (tmpreflt [Auto | Running])
DRV - [2009/03/03 19:12:44 | 00,080,400 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\tmtdi.sys – (tmtdi [System | Running])
DRV - [2009/03/05 22:17:48 | 00,205,328 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\tmxpflt.sys – (tmxpflt [Auto | Running])
DRV - [2008/10/01 13:01:28 | 00,032,000 | —- | M] (Apple, Inc.) – C:\WINDOWS\System32\Drivers\usbaapl.sys – (USBAAPL [On_Demand | Stopped])
DRV - [2009/03/05 22:17:48 | 01,195,512 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\vsapint.sys – (vsapint [Auto | Running])
DRV - [2002/08/28 18:59:26 | 00,154,624 | —- | M] (Lucent Technologies) – C:\WINDOWS\System32\DRIVERS\wlluc48.sys – (wlluc48 [On_Demand | Running])
DRV - [2003/04/23 04:15:06 | 00,113,504 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\drivers\ialmsbw.sys – ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Running])
DRV - [2003/04/23 04:14:56 | 00,078,752 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\drivers\ialmkchw.sys – ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\PROGRAM FILES\TREND MICRO\TRENDSECURE\TISPROTOOLBAR\FIREFOXEXTENSION [2009/03/19 19:59:24 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/02/13 08:52:40 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/18 10:48:46 | 00,000,000 | —D | M]
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (&Google; Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [EPSON Stylus C82 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE" /P23 "EPSON Stylus C82 Series" /O6 "USB002" /M "Stylus C82" (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [EPSON Stylus CX4800 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE" /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800" (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [LtMoh] "C:\Program Files\ltmoh\Ltmoh.exe" (Agere Systems)
O4 - HKLM..\Run: [masqform.exe] "C:\Program Files\PureEdge\Viewer 6.5\masqform.exe" -RunOnce (PureEdge™ Solutions Inc.)
O4 - HKLM..\Run: [PmProxy] "C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe" (adi)
O4 - HKLM..\Run: [POINTER] point32.exe File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" (Sonic Solutions)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" (Trend Micro Inc.)
O4 - HKCU..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1188128455940 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/14 09:42:10 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{dd348cb4-ca0d-11dc-b435-00022db216e5}\Shell\AutoRun\command - "" = F:\WD_Windows_Tools\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
NetSvcs: 6to4:
NetSvcs: AppMgmt: C:\WINDOWS\System32\appmgmts.dll (Microsoft Corporation)
NetSvcs: AudioSrv: C:\WINDOWS\System32\audiosrv.dll (Microsoft Corporation)
NetSvcs: Browser: C:\WINDOWS\System32\browser.dll (Microsoft Corporation)
NetSvcs: CryptSvc: C:\WINDOWS\System32\cryptsvc.dll (Microsoft Corporation)
NetSvcs: DMServer: C:\WINDOWS\System32\dmserver.dll (Microsoft Corp.)
NetSvcs: DHCP: C:\WINDOWS\System32\dhcpcsvc.dll (Microsoft Corporation)
NetSvcs: ERSvc: C:\WINDOWS\System32\ersvc.dll (Microsoft Corporation)
NetSvcs: EventSystem: C:\WINDOWS\System32\es.dll (Microsoft Corporation)
NetSvcs: FastUserSwitchingCompatibility: C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
NetSvcs: HidServ: C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias:
NetSvcs: Iprip:
NetSvcs: Irmon:
NetSvcs: LanmanServer: C:\WINDOWS\System32\srvsvc.dll (Microsoft Corporation)
NetSvcs: LanmanWorkstation: C:\WINDOWS\System32\wkssvc.dll (Microsoft Corporation)
NetSvcs: Messenger: C:\WINDOWS\System32\msgsvc.dll (Microsoft Corporation)
NetSvcs: Netman: C:\WINDOWS\System32\netman.dll (Microsoft Corporation)
NetSvcs: Nla: C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
NetSvcs: Ntmssvc: C:\WINDOWS\system32\ntmssvc.dll (Microsoft Corporation)
NetSvcs: NWCWorkstation:
NetSvcs: Nwsapagent:
NetSvcs: Rasauto: C:\WINDOWS\System32\rasauto.dll (Microsoft Corporation)
NetSvcs: Rasman: C:\WINDOWS\System32\rasmans.dll (Microsoft Corporation)
NetSvcs: Remoteaccess: C:\WINDOWS\System32\mprdim.dll (Microsoft Corporation)
NetSvcs: Schedule: C:\WINDOWS\system32\schedsvc.dll (Microsoft Corporation)
NetSvcs: Seclogon: C:\WINDOWS\System32\seclogon.dll (Microsoft Corporation)
NetSvcs: SENS: C:\WINDOWS\system32\sens.dll (Microsoft Corporation)
NetSvcs: Sharedaccess: C:\WINDOWS\System32\ipnathlp.dll (Microsoft Corporation)
NetSvcs: SRService: C:\WINDOWS\System32\srsvc.dll (Microsoft Corporation)
NetSvcs: Tapisrv: C:\WINDOWS\System32\tapisrv.dll (Microsoft Corporation)
NetSvcs: Themes: C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
NetSvcs: TrkWks: C:\WINDOWS\system32\trkwks.dll (Microsoft Corporation)
NetSvcs: W32Time: C:\WINDOWS\System32\w32time.dll (Microsoft Corporation)
NetSvcs: WZCSVC: C:\WINDOWS\System32\wzcsvc.dll (Microsoft Corporation)
NetSvcs: Wmi: C:\WINDOWS\System32\advapi32.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp:
NetSvcs: winmgmt: C:\WINDOWS\system32\wbem\WMIsvc.dll (Microsoft Corporation)
NetSvcs: TermService: C:\WINDOWS\System32\termsrv.dll (Microsoft Corporation)
NetSvcs: wuauserv: C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)
NetSvcs: BITS: C:\WINDOWS\system32\qmgr.dll (Microsoft Corporation)
NetSvcs: ShellHWDetection: C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
NetSvcs: helpsvc: C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
NetSvcs: xmlprov: C:\WINDOWS\System32\xmlprov.dll (Microsoft Corporation)
NetSvcs: wscsvc: C:\WINDOWS\system32\wscsvc.dll (Microsoft Corporation)
NetSvcs: WmdmPmSN: C:\WINDOWS\system32\MsPMSNSv.dll (Microsoft Corporation)
NetSvcs: napagent: C:\WINDOWS\System32\qagentrt.dll (Microsoft Corporation)
NetSvcs: hkmsvc: C:\WINDOWS\System32\kmsvc.dll (Microsoft Corporation)
SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll (Microsoft Corporation)
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: CryptSvc - %SystemRoot%\System32\cryptsvc.dll (Microsoft Corporation)
SafeBootMin: DcomLaunch - %SystemRoot%\system32\rpcss.dll (Microsoft Corporation)
SafeBootMin: dmadmin - %SystemRoot%\System32\dmadmin.exe (Microsoft Corp., Veritas Software)
SafeBootMin: dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys (Microsoft Corp., Veritas Software)
SafeBootMin: dmio.sys - %SystemRoot%\System32\drivers\dmio.sys (Microsoft Corp., Veritas Software)
SafeBootMin: dmload.sys - %SystemRoot%\System32\drivers\dmload.sys (Microsoft Corp., Veritas Software.)
SafeBootMin: dmserver - %SystemRoot%\System32\dmserver.dll (Microsoft Corp.)
SafeBootMin: EventLog - %SystemRoot%\system32\services.exe (Microsoft Corporation)
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootMin: Netlogon - %SystemRoot%\System32\lsass.exe (Microsoft Corporation)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PlugPlay - %SystemRoot%\system32\services.exe (Microsoft Corporation)
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: RpcSs - %SystemRoot%\system32\rpcss.dll (Microsoft Corporation)
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: sr.sys - %SystemRoot%\System32\DRIVERS\sr.sys (Microsoft Corporation)
SafeBootMin: SRService - %SystemRoot%\System32\srsvc.dll (Microsoft Corporation)
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: vgasave.sys - %SystemRoot%\System32\drivers\vga.sys (Microsoft Corporation)
SafeBootMin: WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: AFD - %SystemRoot%\System32\drivers\afd.sys (Microsoft Corporation)
SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll (Microsoft Corporation)
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: Browser - %SystemRoot%\System32\browser.dll (Microsoft Corporation)
SafeBootNet: CryptSvc - %SystemRoot%\System32\cryptsvc.dll (Microsoft Corporation)
SafeBootNet: DcomLaunch - %SystemRoot%\system32\rpcss.dll (Microsoft Corporation)
SafeBootNet: Dhcp - %SystemRoot%\System32\dhcpcsvc.dll (Microsoft Corporation)
SafeBootNet: dmadmin - %SystemRoot%\System32\dmadmin.exe (Microsoft Corp., Veritas Software)
SafeBootNet: dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys (Microsoft Corp., Veritas Software)
SafeBootNet: dmio.sys - %SystemRoot%\System32\drivers\dmio.sys (Microsoft Corp., Veritas Software)
SafeBootNet: dmload.sys - %SystemRoot%\System32\drivers\dmload.sys (Microsoft Corp., Veritas Software.)
SafeBootNet: dmserver - %SystemRoot%\System32\dmserver.dll (Microsoft Corp.)
SafeBootNet: DnsCache - %SystemRoot%\System32\dnsrslvr.dll (Microsoft Corporation)
SafeBootNet: EventLog - %SystemRoot%\system32\services.exe (Microsoft Corporation)
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootNet: ip6fw.sys - %SystemRoot%\system32\drivers\ip6fw.sys (Microsoft Corporation)
SafeBootNet: ipnat.sys - %SystemRoot%\System32\DRIVERS\ipnat.sys (Microsoft Corporation)
SafeBootNet: LanmanServer - %SystemRoot%\System32\srvsvc.dll (Microsoft Corporation)
SafeBootNet: LanmanWorkstation - %SystemRoot%\System32\wkssvc.dll (Microsoft Corporation)
SafeBootNet: LmHosts - %SystemRoot%\System32\lmhsvc.dll (Microsoft Corporation)
SafeBootNet: Messenger - %SystemRoot%\System32\msgsvc.dll (Microsoft Corporation)
SafeBootNet: NDIS - %SystemRoot%\System32\drivers\ndis.sys (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: Ndisuio - %SystemRoot%\System32\DRIVERS\ndisuio.sys (Microsoft Corporation)
SafeBootNet: NetBIOS - %SystemRoot%\System32\DRIVERS\netbios.sys (Microsoft Corporation)
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetBT - %SystemRoot%\System32\DRIVERS\netbt.sys (Microsoft Corporation)
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Netlogon - %SystemRoot%\System32\lsass.exe (Microsoft Corporation)
SafeBootNet: NetMan - %SystemRoot%\System32\netman.dll (Microsoft Corporation)
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NtLmSsp - %SystemRoot%\System32\lsass.exe (Microsoft Corporation)
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PlugPlay - %SystemRoot%\system32\services.exe (Microsoft Corporation)
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdpcdd.sys - %SystemRoot%\System32\DRIVERS\RDPCDD.sys (Microsoft Corporation)
SafeBootNet: rdpdd.sys - %SystemRoot%\System32\rdpdd.dll (Microsoft Corporation)
SafeBootNet: rdpwd.sys - %SystemRoot%\System32\drivers\rdpwd.sys (Microsoft Corporation)
SafeBootNet: rdsessmgr - %SystemRoot%\system32\sessmgr.exe (Microsoft Corporation)
SafeBootNet: RpcSs - %SystemRoot%\system32\rpcss.dll (Microsoft Corporation)
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: sharedaccess - %SystemRoot%\System32\ipnathlp.dll (Microsoft Corporation)
SafeBootNet: sr.sys - %SystemRoot%\System32\DRIVERS\sr.sys (Microsoft Corporation)
SafeBootNet: SRService - %SystemRoot%\System32\srsvc.dll (Microsoft Corporation)
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: Tcpip - %SystemRoot%\System32\DRIVERS\tcpip.sys (Microsoft Corporation)
SafeBootNet: TDI - Driver Group
SafeBootNet: tdpipe.sys - %SystemRoot%\System32\drivers\tdpipe.sys (Microsoft Corporation)
SafeBootNet: tdtcp.sys - %SystemRoot%\System32\drivers\tdtcp.sys (Microsoft Corporation)
SafeBootNet: termservice - %SystemRoot%\System32\termsrv.dll (Microsoft Corporation)
SafeBootNet: UploadMgr - Service
SafeBootNet: vga.sys - Driver
SafeBootNet: vgasave.sys - %SystemRoot%\System32\drivers\vga.sys (Microsoft Corporation)
SafeBootNet: WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll (Microsoft Corporation)
SafeBootNet: WZCSVC - %SystemRoot%\System32\wzcsvc.dll (Microsoft Corporation)
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608555} - Internet Explorer Classes for Java
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 11.0.3
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 11.0.3
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9212D8B4-C3CF-43E1-A1FF-8EEA311633DC} - PureEdge Viewer
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
========== Files/Folders - Created Within 30 Days ==========
[5 C:\WINDOWS\*.tmp files]
[2009/03/23 19:52:15 | 00,499,200 | —- | C] (OldTimer Tools) – C:\DOCUME~1\Shaena\Desktop\OTListIt2.exe
[2009/03/23 19:50:05 | 00,000,000 | —D | C] – C:\Rooter$
[2009/03/23 19:49:37 | 00,267,612 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\Rooter.exe
[2009/03/23 10:30:57 | 01,095,541 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\img001.jpg
[2009/03/23 07:00:20 | 00,026,112 | —- | C] () – C:\DOCUME~1\Shaena\My Documents\Attic live load.doc
[2009/03/18 13:08:30 | 00,401,720 | —- | C] (Trend Micro Inc.) – C:\DOCUME~1\Shaena\Desktop\HijackThis.exe
[2009/03/18 10:58:39 | 02,036,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_40.dll
[2009/03/18 10:58:39 | 00,452,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_40.dll
[2009/03/18 10:58:38 | 04,379,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_40.dll
[2009/03/18 10:58:36 | 00,514,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_3.dll
[2009/03/18 10:58:36 | 00,070,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_2.dll
[2009/03/18 10:58:35 | 00,235,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_3.dll
[2009/03/18 10:58:34 | 00,023,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_5.dll
[2009/03/18 10:58:32 | 00,509,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_2.dll
[2009/03/18 10:58:32 | 00,068,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_1.dll
[2009/03/18 10:58:31 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_2.dll
[2009/03/18 10:58:30 | 01,493,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_39.dll
[2009/03/18 10:58:30 | 00,467,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_39.dll
[2009/03/18 10:58:29 | 03,851,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_39.dll
[2009/03/18 10:58:27 | 00,507,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_1.dll
[2009/03/18 10:58:27 | 00,065,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_0.dll
[2009/03/18 10:58:26 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_1.dll
[2009/03/18 10:58:25 | 00,025,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_4.dll
[2009/03/18 10:58:24 | 01,491,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_38.dll
[2009/03/18 10:58:24 | 00,467,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_38.dll
[2009/03/18 10:58:23 | 03,850,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_38.dll
[2009/03/18 10:58:21 | 00,479,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_0.dll
[2009/03/18 10:58:20 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_0.dll
[2009/03/18 10:58:19 | 00,025,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_3.dll
[2009/03/18 10:58:18 | 01,420,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_37.dll
[2009/03/18 10:58:18 | 00,462,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_37.dll
[2009/03/18 10:58:17 | 03,786,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_37.dll
[2009/03/18 10:58:15 | 00,267,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_10.dll
[2009/03/18 10:58:13 | 01,374,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_36.dll
[2009/03/18 10:58:13 | 00,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_36.dll
[2009/03/18 10:58:12 | 03,734,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_36.dll
[2009/03/18 10:58:11 | 00,267,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_9.dll
[2009/03/18 10:58:10 | 01,358,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_35.dll
[2009/03/18 10:58:10 | 00,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_35.dll
[2009/03/18 10:58:08 | 03,727,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_35.dll
[2009/03/18 10:58:07 | 00,266,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_8.dll
[2009/03/18 10:58:07 | 00,017,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_2.dll
[2009/03/18 10:58:06 | 01,124,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_34.dll
[2009/03/18 10:58:06 | 00,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_34.dll
[2009/03/18 10:58:05 | 03,497,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_34.dll
[2009/03/18 10:58:04 | 00,081,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_3.dll
[2009/03/18 10:58:03 | 00,261,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_7.dll
[2009/03/18 10:57:54 | 00,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_33.dll
[2009/03/18 10:57:53 | 01,123,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_33.dll
[2009/03/18 10:57:41 | 03,495,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_33.dll
[2009/03/18 10:57:40 | 00,255,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_6.dll
[2009/03/18 10:57:39 | 00,251,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_5.dll
[2009/03/18 10:57:38 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2009/03/18 10:57:37 | 00,237,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_4.dll
[2009/03/18 10:57:37 | 00,015,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_1.dll
[2009/03/18 10:57:36 | 02,414,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_31.dll
[2009/03/18 10:57:35 | 00,236,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_3.dll
[2009/03/18 10:57:34 | 00,062,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_2.dll
[2009/03/18 10:57:33 | 00,230,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_2.dll
[2009/03/18 10:57:32 | 00,062,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_1.dll
[2009/03/18 10:57:31 | 00,229,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_1.dll
[2009/03/18 10:57:23 | 02,388,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_30.dll
[2009/03/18 10:57:22 | 00,230,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_0.dll
[2009/03/18 10:57:22 | 00,014,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_0.dll
[2009/03/18 10:57:21 | 02,332,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_29.dll
[2009/03/18 10:57:20 | 02,323,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_28.dll
[2009/03/18 10:57:20 | 00,061,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput9_1_0.dll
[2009/03/18 10:57:19 | 02,319,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_27.dll
[2009/03/18 10:57:17 | 02,297,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_26.dll
[2009/03/18 10:57:16 | 02,337,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_25.dll
[2009/03/18 10:57:12 | 02,222,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_24.dll
[2009/03/18 10:54:10 | 00,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2009/03/18 10:53:52 | 00,000,000 | —D | C] – C:\WINDOWS\Logs
[2009/03/09 09:10:22 | 00,584,901 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\img068.jpg
[2009/03/09 09:09:34 | 00,426,855 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\img064.jpg
[2009/03/09 09:09:08 | 00,649,993 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\img067.jpg
[2009/03/01 21:34:29 | 00,005,657 | —- | C] () – C:\DOCUME~1\Shaena\My Documents\2nd floor remodel.PSH
[2009/03/01 19:50:32 | 00,030,291 | —- | C] () – C:\DOCUME~1\Shaena\My Documents\Shaena's Garage Addition.PSH
[2009/02/24 18:40:08 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/03/23 19:52:32 | 00,499,200 | —- | M] (OldTimer Tools) – C:\DOCUME~1\Shaena\Desktop\OTListIt2.exe
[2009/03/23 19:49:40 | 00,267,612 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\Rooter.exe
[2009/03/23 19:45:55 | 00,192,512 | —- | M] (??????) – C:\WINDOWS\System32\kdfvmgr.exe
[2009/03/23 19:45:55 | 00,077,824 | —- | M] (Kings Information & Network) – C:\WINDOWS\System32\kdfapi.dll
[2009/03/23 19:45:55 | 00,053,248 | —- | M] (Kings Information & Network) – C:\WINDOWS\System32\Kdfhok.dll
[2009/03/23 19:45:52 | 00,387,288 | —- | M] (Bluegem Security) – C:\WINDOWS\System32\kdfmgr.exe
[2009/03/23 10:30:57 | 01,095,541 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\img001.jpg
[2009/03/23 08:50:10 | 00,649,993 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\img067.jpg
[2009/03/23 07:31:21 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/23 07:30:58 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/23 07:30:53 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/23 07:00:21 | 00,026,112 | —- | M] () – C:\DOCUME~1\Shaena\My Documents\Attic live load.doc
[2009/03/19 20:02:10 | 00,475,872 | —- | M] (Bluegem Security) – C:\WINDOWS\System32\kdfinj.dll
[2009/03/18 16:59:52 | 00,518,144 | —- | M] () – C:\DOCUME~1\Shaena\My Documents\Outback Steakhouse Recipies.doc
[2009/03/18 13:08:30 | 00,401,720 | —- | M] (Trend Micro Inc.) – C:\DOCUME~1\Shaena\Desktop\HijackThis.exe
[2009/03/18 12:49:10 | 00,105,202 | —- | M] (TWD Industries SAS) – C:\WINDOWS\Slave.exe
[2009/03/18 11:07:28 | 00,030,291 | —- | M] () – C:\DOCUME~1\Shaena\My Documents\Shaena's Garage Addition.PSH
[2009/03/18 10:35:47 | 00,005,657 | —- | M] () – C:\DOCUME~1\Shaena\My Documents\2nd floor remodel.PSH
[2009/03/16 23:12:08 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/12 09:36:57 | 00,435,498 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/12 09:36:57 | 00,068,354 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/12 09:36:56 | 00,512,960 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/12 09:33:55 | 00,297,256 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/12 09:23:29 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/09 09:10:22 | 00,584,901 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\img068.jpg
[2009/03/09 09:09:35 | 00,426,855 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\img064.jpg
[2009/03/05 22:17:48 | 01,195,512 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\vsapint.sys
[2009/03/05 22:17:48 | 00,205,328 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmxpflt.sys
[2009/03/05 22:17:48 | 00,036,368 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmpreflt.sys
[2009/03/03 19:12:44 | 00,080,400 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmtdi.sys
[2009/03/03 05:08:15 | 00,335,376 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\TM_CFW.sys
[2009/03/03 04:34:24 | 00,050,192 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2009/03/03 04:34:20 | 00,150,032 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/03/03 04:34:17 | 00,050,192 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmactmon.sys
[2009/02/25 12:55:00 | 24,768,960 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
========== Custom Scans ==========
< %systemroot%\System32\antiwpa.dll >
< %systemroot%\SYSTEM32\wpa.dll >
< %systemroot%\setup\scripts\biestart.exe >
< %systemroot%\system32\drivers\royal.sys >
< %systemroot%\system32\serauth1.dll >
< %systemroot%\system32\serauth2.dll >
< %systemroot%\system32\sysaudio.sys >
< %systemroot%\system32\wdmaud.sys >
< %systemroot%\system32\aeaudio.sys >
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\Slave.exe:SummaryInformation
< End of report >
OTListIt Extras logfile created on: 3/23/2009 7:55:07 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.1 Folder = C:\Documents and Settings\Shaena\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1006.80 Mb Total Physical Memory | 649.42 Mb Available Physical Memory | 64.50% Memory free
2.37 Gb Paging File | 2.01 Gb Available in Paging File | 84.88% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 21.97 Gb Free Space | 58.97% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SHAE
Current User Name: Shaena
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"4000:TCP" = 4000:TCP:*:Enabled:Update
"4000:UDP" = 4000:UDP:*:Enabled:Avir
"3999:TCP" = 3999:TCP:*:Enabled:ICS
"3999:UDP" = 3999:UDP:*:Enabled:Security
"3998:TCP" = 3998:TCP:*:Enabled:Internet
"3998:UDP" = 3998:UDP:*:Enabled:Firewall
"3997:TCP" = 3997:TCP:*:Enabled:Nod32
"3997:UDP" = 3997:UDP:*:Enabled:System
"3996:TCP" = 3996:TCP:*:Enabled:Yahoo
"3996:UDP" = 3996:UDP:*:Enabled:Kaspersky
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2007/04/22 22:29:34 | 00,088,824 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:*:Enabled:RoxioUPnPRenderer9
[2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2007/04/23 13:43:40 | 00,617,208 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Media Manager 9\MediaManager9.exe:*:Enabled:MediaManager9 Module
[2007/04/22 22:29:34 | 00,088,824 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:*:Enabled:RoxioUPnPRenderer9
[2004/06/04 02:58:10 | 00,196,608 | —- | M] (InterVideo Inc.) – C:\Program Files\InterVideo\DVD6\WinDVD.exe:*:Enabled:WinDVD
[2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/01/16 15:57:06 | 00,147,080 | —- | M] (ExtendMedia Inc.) – C:\Program Files\NBC Direct\StoreFrontPlayer.exe:*:Enabled:NBC Direct Beta
[2008/12/19 01:25:25 | 00,634,024 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer
[2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
[2008/11/20 14:20:48 | 14,294,824 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1FD0C5C1-B01B-4B4C-9607-E5D3B3D1318F}" = Microsoft IntelliPoint 4.1
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 12
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{40E12A55-C504-4223-AFAC-7672DBF1ACDE}" = Trend Micro Internet Security Pro
"{66D171AA-670F-4309-9C74-5BA7F7DBA0B3}" = Roxio Media Manager
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ACA2FD2-4C4A-42F3-AFB5-7B433BBDF6DB}" = InterVideo WinDVD 6
"{6DA9102E-199F-43A0-A36B-6EF48081A658}" = MobileMe Control Panel
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security Pro
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9B449C1A-4F64-4ED4-8C96-31B222E8377F}" = BlackBerry Desktop Software 4.2.2
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C91EF330-F152-44ED-A33A-0F4FF3FAF813}" = NBC Direct Beta
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}" = ArcSoft PhotoImpression 5
"{E0000650-0650-0650-0650-000000000650}" = PureEdge Viewer 6.5
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
"AC3Filter" = AC3Filter (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"BlackBerry_{9B449C1A-4F64-4ED4-8C96-31B222E8377F}" = BlackBerry Desktop Software 4.2.2
"CTDVDAudio Plugin" = Creative DVD Audio Plugin for Audigy Series
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InterActual Player" = InterActual Player
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Adapters and Drivers
"Punch! Super Home Suite" = Punch! Super Home Suite
"Silent Package Run-Time Sample" = EPSON CX 4200 4800 Guide
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/11/2009 8:50:42 AM | Computer Name = SHAE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/31/2009 9:20:43 PM | Computer Name = SHAE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/31/2009 9:23:37 PM | Computer Name = SHAE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/31/2009 9:23:42 PM | Computer Name = SHAE | Source = Application Hang | ID = 1001
Description = Fault bucket 1015682910.
Error - 2/2/2009 7:56:26 AM | Computer Name = SHAE | Source = Application Error | ID = 1000
Description = Faulting application msimn.exe, version 6.0.2900.5512, faulting module
inetcomm.dll, version 6.0.2900.5579, fault address 0x000148c1.
Error - 2/2/2009 7:56:33 AM | Computer Name = SHAE | Source = Application Error | ID = 1001
Description = Fault bucket 882718558.
Error - 2/16/2009 8:46:25 AM | Computer Name = SHAE | Source = Application Error | ID = 1000
Description = Faulting application tmarsvc.exe, version 1.0.0.1075, faulting module
LogPaser.dll, version 1.0.0.1075, fault address 0x0001269c.
Error - 2/17/2009 10:15:18 PM | Computer Name = SHAE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module mshtml.dll, version 7.0.6000.16809, fault address 0x00053b56.
Error - 3/10/2009 9:31:15 AM | Computer Name = SHAE | Source = Google_Toolbar | ID = 1
Description =
Error - 3/16/2009 12:50:33 PM | Computer Name = SHAE | Source = Google_Toolbar | ID = 1
Description =
[ System Events ]
Error - 3/20/2009 5:55:53 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
Error - 3/20/2009 6:49:08 PM | Computer Name = SHAE | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 3/20/2009 7:52:03 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
Error - 3/20/2009 7:52:22 PM | Computer Name = SHAE | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 00022DB216E5. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 3/21/2009 6:03:47 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
Error - 3/21/2009 6:04:00 PM | Computer Name = SHAE | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 00022DB216E5. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 3/22/2009 8:50:07 AM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
Error - 3/22/2009 5:03:06 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
Error - 3/23/2009 6:25:31 AM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
Error - 3/23/2009 7:42:21 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
< End of report >
Microsoft Windows XP Professional (5.1.2600) Service Pack 3
C:\ [Fixed] - NTFS - (Total:38146 Mo/Free:2013 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
Mon 03/23/2009|19:50
———————-\\ Processes..
–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINDOWS\system32\csrss.exe
———- \??\C:\WINDOWS\system32\winlogon.exe
———- C:\WINDOWS\system32\services.exe
———- C:\WINDOWS\system32\lsass.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\Explorer.EXE
———- C:\WINDOWS\system32\spoolsv.exe
———- C:\Program Files\Trend Micro\BM\TMBMSRV.exe
———- C:\Program Files\Common Files\Apple\Mobile Device
Support\bin\AppleMobileDeviceService.exe
———- C:\Program Files\Bonjour\mDNSResponder.exe
———- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
———- C:\Program Files\Java\jre6\bin\jqs.exe
———- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
———- C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
———- C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
———- C:\WINDOWS\Slave.exe
———- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
———- C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
———- C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
———- C:\WINDOWS\System32\alg.exe
———- C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
———- C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
———- C:\Program Files\ltmoh\Ltmoh.exe
———- C:\WINDOWS\AGRSMMSG.exe
———- C:\WINDOWS\system32\igfxtray.exe
———- C:\WINDOWS\system32\hkcmd.exe
———- C:\Program Files\Microsoft Hardware\Mouse\point32.exe
———- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
———- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE
———- C:\WINDOWS\System32\svchost.exe
———- C:\Program Files\iTunes\iTunesHelper.exe
———- C:\Program Files\Java\jre6\bin\jusched.exe
———- C:\WINDOWS\system32\ctfmon.exe
———- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
———- C:\Program Files\iPod\bin\iPodService.exe
———- C:\Program Files\Trend
Micro\TrendSecure\TISProToolbar\PlatformDependent\ProToolbarComm.exe
———- C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
———- C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
———- C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
———- C:\Program Files\Internet Explorer\iexplore.exe
———- C:\WINDOWS\system32\kdfmgr.exe
———- C:\WINDOWS\system32\cmd.exe
———- C:\Rooter$\RK.exe
———————-\\ Search..
———————-\\ ROOTKIT !!
———————-\\ Cracks & Keygens..
C:\DOCUME~1\Shaena\Cookies\shaena@crackle[1].txt
1 - "C:\Rooter$\Rooter_1.txt" - Mon 03/23/2009|19:51
———————-\\ Scan completed at 19:51
OTListIt logfile created on: 3/23/2009 7:55:07 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.1 Folder = C:\Documents and Settings\Shaena\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1006.80 Mb Total Physical Memory | 649.42 Mb Available Physical Memory | 64.50% Memory free
2.37 Gb Paging File | 2.01 Gb Available in Paging File | 84.88% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 21.97 Gb Free Space | 58.97% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SHAE
Current User Name: Shaena
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2008/04/13 20:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2009/03/03 04:46:13 | 00,341,256 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe
PRC - [2008/11/07 15:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/10/03 21:12:41 | 00,168,432 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
PRC - [2009/03/18 10:48:44 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2003/06/19 17:25:00 | 00,322,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2008/08/14 07:08:59 | 00,181,584 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
PRC - [2009/03/13 06:43:18 | 00,711,248 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
PRC - [2009/03/18 12:49:10 | 00,105,202 | —- | M] (TWD Industries SAS) – C:\WINDOWS\Slave.exe
PRC - [2002/09/20 10:50:10 | 00,045,056 | —- | M] (Analog Devices, Inc.) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
PRC - [2009/03/13 06:43:28 | 00,497,008 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
PRC - [2009/03/13 06:43:32 | 00,677,128 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
PRC - [2009/03/13 06:43:34 | 00,995,528 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
PRC - [2009/02/12 18:52:26 | 00,083,280 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
PRC - [2003/02/28 13:54:58 | 00,040,960 | —- | M] (adi) – C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
PRC - [2003/01/02 11:16:38 | 00,172,032 | —- | M] (Agere Systems) – C:\Program Files\ltmoh\Ltmoh.exe
PRC - [2003/04/18 05:20:10 | 00,088,363 | —- | M] (Agere Systems) – C:\WINDOWS\AGRSMMSG.exe
PRC - [2003/04/06 18:19:52 | 00,155,648 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\igfxtray.exe
PRC - [2003/04/06 18:07:38 | 00,114,688 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\hkcmd.exe
PRC - [2002/04/11 14:47:52 | 00,176,128 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Hardware\Mouse\point32.exe
PRC - [2005/02/01 23:00:00 | 00,098,304 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
PRC - [2002/04/24 21:00:00 | 00,074,240 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE
PRC - [2008/11/20 14:20:54 | 00,290,088 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/03/18 10:48:44 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2007/08/26 03:06:44 | 00,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/11/20 14:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/02/12 18:52:44 | 00,161,104 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\PlatformDependent\ProToolbarComm.exe
PRC - [2009/02/12 19:03:10 | 00,169,296 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
PRC - [2009/02/12 19:03:06 | 00,275,792 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
PRC - [2009/03/13 21:38:02 | 00,492,808 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
PRC - [2008/12/19 01:25:25 | 00,634,024 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009/03/23 19:45:52 | 00,387,288 | —- | M] (Bluegem Security) – C:\WINDOWS\system32\kdfmgr.exe
PRC - [2008/04/13 20:12:14 | 00,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\cmd.exe
PRC - [2009/03/23 19:52:32 | 00,499,200 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Shaena\Desktop\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2008/11/07 15:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - [2008/07/25 12:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe – (Bonjour Service [Auto | Running])
SRV - [2008/07/25 12:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/29 22:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/10/03 21:12:41 | 00,168,432 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [Auto | Running])
SRV - [2008/04/13 20:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2004/10/22 05:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/07/29 20:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2008/11/20 14:20:44 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
SRV - [2009/03/18 10:48:44 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2003/06/19 17:25:00 | 00,322,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE – (MDM [Auto | Running])
SRV - [2008/07/29 20:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2003/07/28 06:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2007/04/22 22:29:34 | 00,088,824 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe – (Roxio UPnP Renderer 9 [On_Demand | Stopped])
SRV - [2007/04/22 22:29:32 | 00,359,160 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe – (Roxio Upnp Server 9 [Auto | Stopped])
SRV - [2007/04/23 13:43:54 | 00,310,008 | —- | M] (Sonic Solutions) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe – (RoxLiveShare9 [Auto | Stopped])
SRV - [2007/04/23 13:43:46 | 01,010,424 | —- | M] (Sonic Solutions) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe – (RoxMediaDB9 [On_Demand | Stopped])
SRV - [2007/04/23 13:43:54 | 00,166,648 | —- | M] (Sonic Solutions) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe – (RoxWatch9 [Auto | Stopped])
SRV - [2008/08/14 07:08:59 | 00,181,584 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe – (Security Activity Dashboard Service [Auto | Running])
SRV - [2009/03/13 06:43:18 | 00,711,248 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe – (SfCtlCom [Auto | Running])
SRV - [2009/03/18 12:49:10 | 00,105,202 | —- | M] (TWD Industries SAS) – C:\WINDOWS\Slave.exe – (Slave [Auto | Running])
SRV - [2002/09/20 10:50:10 | 00,045,056 | —- | M] (Analog Devices, Inc.) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe – (SoundMAX Agent Service (default) [Auto | Running])
SRV - [2009/03/03 04:46:13 | 00,341,256 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe – (TMBMServer [Auto | Running])
SRV - [2009/03/13 06:43:28 | 00,497,008 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe – (TmPfw [Auto | Running])
SRV - [2009/03/13 06:43:32 | 00,677,128 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe – (TmProxy [Auto | Running])
SRV - [2006/10/18 21:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2003/01/10 09:51:34 | 00,098,912 | —- | M] (Andrea Electronics Corporation) – C:\WINDOWS\system32\drivers\aeaudio.sys – (aeaudio [On_Demand | Running])
DRV - [2002/12/20 08:07:34 | 01,164,576 | —- | M] (Agere Systems) – C:\WINDOWS\system32\DRIVERS\AGRSM.sys – (AgereSoftModem [On_Demand | Running])
DRV - [2007/08/28 16:08:45 | 00,015,423 | —- | M] (Linksys Corporation) – C:\WINDOWS\System32\BEFCMU10.SYS – (BEFCMU10 [On_Demand | Stopped])
DRV - [2006/10/06 18:59:06 | 00,044,224 | R— | M] (BVRP Software) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS – (BVRPMPR5 [On_Demand | Stopped])
DRV - [2002/09/25 00:09:12 | 00,140,800 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\DRIVERS\e100b325.sys – (E100B [On_Demand | Running])
DRV - [2001/08/09 20:03:00 | 00,070,084 | —- | M] (MK Systems CO., LTD.) – C:\WINDOWS\system32\Drivers\EPLPDX02.SYS – (Eplpdx02 [On_Demand | Running])
DRV - [2008/04/17 13:12:54 | 00,015,464 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [2003/04/23 04:10:06 | 00,090,907 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\DRIVERS\ialmnt5.sys – (ialm [On_Demand | Running])
DRV - [2002/04/11 14:47:52 | 00,011,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\IPFilter.sys – (IPFilter [On_Demand | Running])
DRV - File not found – – (neokdss [On_Demand | Running])
DRV - [2003/09/19 09:45:48 | 00,021,248 | —- | M] (Padus, Inc.) – C:\WINDOWS\system32\drivers\pfc.sys – (pfc [On_Demand | Running])
DRV - [2002/08/29 08:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007/03/23 05:00:00 | 00,043,528 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2006/11/07 21:02:04 | 00,022,272 | —- | M] (Research In Motion Limited) – C:\WINDOWS\System32\Drivers\RimUsb.sys – (RimUsb [On_Demand | Stopped])
DRV - [2007/01/18 12:24:58 | 00,026,496 | R— | M] (Research in Motion Ltd) – C:\WINDOWS\system32\DRIVERS\RimSerial.sys – (RimVSerPort [On_Demand | Running])
DRV - [2002/08/29 08:00:00 | 00,005,888 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\Drivers\RootMdm.sys – (ROOTMODEM [On_Demand | Running])
DRV - [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2003/01/28 05:32:02 | 00,541,376 | —- | M] (Analog Devices, Inc.) – C:\WINDOWS\system32\drivers\smwdm.sys – (smwdm [On_Demand | Running])
DRV - [2001/08/17 14:56:16 | 00,007,552 | —- | M] (Sony Corporation) – C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS – (SONYPVU1 [On_Demand | Stopped])
DRV - [2009/03/03 04:34:17 | 00,050,192 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\drivers\tmactmon.sys – (tmactmon [Auto | Running])
DRV - [2009/03/03 05:08:15 | 00,335,376 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\TM_CFW.sys – (tmcfw [On_Demand | Running])
DRV - [2009/03/03 04:34:20 | 00,150,032 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\drivers\tmcomm.sys – (tmcomm [Auto | Running])
DRV - [2009/03/03 04:34:24 | 00,050,192 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\drivers\tmevtmgr.sys – (tmevtmgr [Auto | Running])
DRV - [2009/03/05 22:17:48 | 00,036,368 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\tmpreflt.sys – (tmpreflt [Auto | Running])
DRV - [2009/03/03 19:12:44 | 00,080,400 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\tmtdi.sys – (tmtdi [System | Running])
DRV - [2009/03/05 22:17:48 | 00,205,328 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\tmxpflt.sys – (tmxpflt [Auto | Running])
DRV - [2008/10/01 13:01:28 | 00,032,000 | —- | M] (Apple, Inc.) – C:\WINDOWS\System32\Drivers\usbaapl.sys – (USBAAPL [On_Demand | Stopped])
DRV - [2009/03/05 22:17:48 | 01,195,512 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\DRIVERS\vsapint.sys – (vsapint [Auto | Running])
DRV - [2002/08/28 18:59:26 | 00,154,624 | —- | M] (Lucent Technologies) – C:\WINDOWS\System32\DRIVERS\wlluc48.sys – (wlluc48 [On_Demand | Running])
DRV - [2003/04/23 04:15:06 | 00,113,504 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\drivers\ialmsbw.sys – ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Running])
DRV - [2003/04/23 04:14:56 | 00,078,752 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\drivers\ialmkchw.sys – ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\PROGRAM FILES\TREND MICRO\TRENDSECURE\TISPROTOOLBAR\FIREFOXEXTENSION [2009/03/19 19:59:24 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/02/13 08:52:40 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/18 10:48:46 | 00,000,000 | —D | M]
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (&Google; Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [EPSON Stylus C82 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE" /P23 "EPSON Stylus C82 Series" /O6 "USB002" /M "Stylus C82" (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [EPSON Stylus CX4800 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE" /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800" (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [LtMoh] "C:\Program Files\ltmoh\Ltmoh.exe" (Agere Systems)
O4 - HKLM..\Run: [masqform.exe] "C:\Program Files\PureEdge\Viewer 6.5\masqform.exe" -RunOnce (PureEdge™ Solutions Inc.)
O4 - HKLM..\Run: [PmProxy] "C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe" (adi)
O4 - HKLM..\Run: [POINTER] point32.exe File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" (Sonic Solutions)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" (Trend Micro Inc.)
O4 - HKCU..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1188128455940 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/14 09:42:10 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{dd348cb4-ca0d-11dc-b435-00022db216e5}\Shell\AutoRun\command - "" = F:\WD_Windows_Tools\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
NetSvcs: 6to4:
NetSvcs: AppMgmt: C:\WINDOWS\System32\appmgmts.dll (Microsoft Corporation)
NetSvcs: AudioSrv: C:\WINDOWS\System32\audiosrv.dll (Microsoft Corporation)
NetSvcs: Browser: C:\WINDOWS\System32\browser.dll (Microsoft Corporation)
NetSvcs: CryptSvc: C:\WINDOWS\System32\cryptsvc.dll (Microsoft Corporation)
NetSvcs: DMServer: C:\WINDOWS\System32\dmserver.dll (Microsoft Corp.)
NetSvcs: DHCP: C:\WINDOWS\System32\dhcpcsvc.dll (Microsoft Corporation)
NetSvcs: ERSvc: C:\WINDOWS\System32\ersvc.dll (Microsoft Corporation)
NetSvcs: EventSystem: C:\WINDOWS\System32\es.dll (Microsoft Corporation)
NetSvcs: FastUserSwitchingCompatibility: C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
NetSvcs: HidServ: C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias:
NetSvcs: Iprip:
NetSvcs: Irmon:
NetSvcs: LanmanServer: C:\WINDOWS\System32\srvsvc.dll (Microsoft Corporation)
NetSvcs: LanmanWorkstation: C:\WINDOWS\System32\wkssvc.dll (Microsoft Corporation)
NetSvcs: Messenger: C:\WINDOWS\System32\msgsvc.dll (Microsoft Corporation)
NetSvcs: Netman: C:\WINDOWS\System32\netman.dll (Microsoft Corporation)
NetSvcs: Nla: C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
NetSvcs: Ntmssvc: C:\WINDOWS\system32\ntmssvc.dll (Microsoft Corporation)
NetSvcs: NWCWorkstation:
NetSvcs: Nwsapagent:
NetSvcs: Rasauto: C:\WINDOWS\System32\rasauto.dll (Microsoft Corporation)
NetSvcs: Rasman: C:\WINDOWS\System32\rasmans.dll (Microsoft Corporation)
NetSvcs: Remoteaccess: C:\WINDOWS\System32\mprdim.dll (Microsoft Corporation)
NetSvcs: Schedule: C:\WINDOWS\system32\schedsvc.dll (Microsoft Corporation)
NetSvcs: Seclogon: C:\WINDOWS\System32\seclogon.dll (Microsoft Corporation)
NetSvcs: SENS: C:\WINDOWS\system32\sens.dll (Microsoft Corporation)
NetSvcs: Sharedaccess: C:\WINDOWS\System32\ipnathlp.dll (Microsoft Corporation)
NetSvcs: SRService: C:\WINDOWS\System32\srsvc.dll (Microsoft Corporation)
NetSvcs: Tapisrv: C:\WINDOWS\System32\tapisrv.dll (Microsoft Corporation)
NetSvcs: Themes: C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
NetSvcs: TrkWks: C:\WINDOWS\system32\trkwks.dll (Microsoft Corporation)
NetSvcs: W32Time: C:\WINDOWS\System32\w32time.dll (Microsoft Corporation)
NetSvcs: WZCSVC: C:\WINDOWS\System32\wzcsvc.dll (Microsoft Corporation)
NetSvcs: Wmi: C:\WINDOWS\System32\advapi32.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp:
NetSvcs: winmgmt: C:\WINDOWS\system32\wbem\WMIsvc.dll (Microsoft Corporation)
NetSvcs: TermService: C:\WINDOWS\System32\termsrv.dll (Microsoft Corporation)
NetSvcs: wuauserv: C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)
NetSvcs: BITS: C:\WINDOWS\system32\qmgr.dll (Microsoft Corporation)
NetSvcs: ShellHWDetection: C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
NetSvcs: helpsvc: C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
NetSvcs: xmlprov: C:\WINDOWS\System32\xmlprov.dll (Microsoft Corporation)
NetSvcs: wscsvc: C:\WINDOWS\system32\wscsvc.dll (Microsoft Corporation)
NetSvcs: WmdmPmSN: C:\WINDOWS\system32\MsPMSNSv.dll (Microsoft Corporation)
NetSvcs: napagent: C:\WINDOWS\System32\qagentrt.dll (Microsoft Corporation)
NetSvcs: hkmsvc: C:\WINDOWS\System32\kmsvc.dll (Microsoft Corporation)
SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll (Microsoft Corporation)
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: CryptSvc - %SystemRoot%\System32\cryptsvc.dll (Microsoft Corporation)
SafeBootMin: DcomLaunch - %SystemRoot%\system32\rpcss.dll (Microsoft Corporation)
SafeBootMin: dmadmin - %SystemRoot%\System32\dmadmin.exe (Microsoft Corp., Veritas Software)
SafeBootMin: dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys (Microsoft Corp., Veritas Software)
SafeBootMin: dmio.sys - %SystemRoot%\System32\drivers\dmio.sys (Microsoft Corp., Veritas Software)
SafeBootMin: dmload.sys - %SystemRoot%\System32\drivers\dmload.sys (Microsoft Corp., Veritas Software.)
SafeBootMin: dmserver - %SystemRoot%\System32\dmserver.dll (Microsoft Corp.)
SafeBootMin: EventLog - %SystemRoot%\system32\services.exe (Microsoft Corporation)
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootMin: Netlogon - %SystemRoot%\System32\lsass.exe (Microsoft Corporation)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PlugPlay - %SystemRoot%\system32\services.exe (Microsoft Corporation)
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: RpcSs - %SystemRoot%\system32\rpcss.dll (Microsoft Corporation)
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: sr.sys - %SystemRoot%\System32\DRIVERS\sr.sys (Microsoft Corporation)
SafeBootMin: SRService - %SystemRoot%\System32\srsvc.dll (Microsoft Corporation)
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: vgasave.sys - %SystemRoot%\System32\drivers\vga.sys (Microsoft Corporation)
SafeBootMin: WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: AFD - %SystemRoot%\System32\drivers\afd.sys (Microsoft Corporation)
SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll (Microsoft Corporation)
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: Browser - %SystemRoot%\System32\browser.dll (Microsoft Corporation)
SafeBootNet: CryptSvc - %SystemRoot%\System32\cryptsvc.dll (Microsoft Corporation)
SafeBootNet: DcomLaunch - %SystemRoot%\system32\rpcss.dll (Microsoft Corporation)
SafeBootNet: Dhcp - %SystemRoot%\System32\dhcpcsvc.dll (Microsoft Corporation)
SafeBootNet: dmadmin - %SystemRoot%\System32\dmadmin.exe (Microsoft Corp., Veritas Software)
SafeBootNet: dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys (Microsoft Corp., Veritas Software)
SafeBootNet: dmio.sys - %SystemRoot%\System32\drivers\dmio.sys (Microsoft Corp., Veritas Software)
SafeBootNet: dmload.sys - %SystemRoot%\System32\drivers\dmload.sys (Microsoft Corp., Veritas Software.)
SafeBootNet: dmserver - %SystemRoot%\System32\dmserver.dll (Microsoft Corp.)
SafeBootNet: DnsCache - %SystemRoot%\System32\dnsrslvr.dll (Microsoft Corporation)
SafeBootNet: EventLog - %SystemRoot%\system32\services.exe (Microsoft Corporation)
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SafeBootNet: ip6fw.sys - %SystemRoot%\system32\drivers\ip6fw.sys (Microsoft Corporation)
SafeBootNet: ipnat.sys - %SystemRoot%\System32\DRIVERS\ipnat.sys (Microsoft Corporation)
SafeBootNet: LanmanServer - %SystemRoot%\System32\srvsvc.dll (Microsoft Corporation)
SafeBootNet: LanmanWorkstation - %SystemRoot%\System32\wkssvc.dll (Microsoft Corporation)
SafeBootNet: LmHosts - %SystemRoot%\System32\lmhsvc.dll (Microsoft Corporation)
SafeBootNet: Messenger - %SystemRoot%\System32\msgsvc.dll (Microsoft Corporation)
SafeBootNet: NDIS - %SystemRoot%\System32\drivers\ndis.sys (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: Ndisuio - %SystemRoot%\System32\DRIVERS\ndisuio.sys (Microsoft Corporation)
SafeBootNet: NetBIOS - %SystemRoot%\System32\DRIVERS\netbios.sys (Microsoft Corporation)
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetBT - %SystemRoot%\System32\DRIVERS\netbt.sys (Microsoft Corporation)
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Netlogon - %SystemRoot%\System32\lsass.exe (Microsoft Corporation)
SafeBootNet: NetMan - %SystemRoot%\System32\netman.dll (Microsoft Corporation)
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NtLmSsp - %SystemRoot%\System32\lsass.exe (Microsoft Corporation)
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PlugPlay - %SystemRoot%\system32\services.exe (Microsoft Corporation)
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdpcdd.sys - %SystemRoot%\System32\DRIVERS\RDPCDD.sys (Microsoft Corporation)
SafeBootNet: rdpdd.sys - %SystemRoot%\System32\rdpdd.dll (Microsoft Corporation)
SafeBootNet: rdpwd.sys - %SystemRoot%\System32\drivers\rdpwd.sys (Microsoft Corporation)
SafeBootNet: rdsessmgr - %SystemRoot%\system32\sessmgr.exe (Microsoft Corporation)
SafeBootNet: RpcSs - %SystemRoot%\system32\rpcss.dll (Microsoft Corporation)
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: sharedaccess - %SystemRoot%\System32\ipnathlp.dll (Microsoft Corporation)
SafeBootNet: sr.sys - %SystemRoot%\System32\DRIVERS\sr.sys (Microsoft Corporation)
SafeBootNet: SRService - %SystemRoot%\System32\srsvc.dll (Microsoft Corporation)
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: Tcpip - %SystemRoot%\System32\DRIVERS\tcpip.sys (Microsoft Corporation)
SafeBootNet: TDI - Driver Group
SafeBootNet: tdpipe.sys - %SystemRoot%\System32\drivers\tdpipe.sys (Microsoft Corporation)
SafeBootNet: tdtcp.sys - %SystemRoot%\System32\drivers\tdtcp.sys (Microsoft Corporation)
SafeBootNet: termservice - %SystemRoot%\System32\termsrv.dll (Microsoft Corporation)
SafeBootNet: UploadMgr - Service
SafeBootNet: vga.sys - Driver
SafeBootNet: vgasave.sys - %SystemRoot%\System32\drivers\vga.sys (Microsoft Corporation)
SafeBootNet: WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll (Microsoft Corporation)
SafeBootNet: WZCSVC - %SystemRoot%\System32\wzcsvc.dll (Microsoft Corporation)
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608555} - Internet Explorer Classes for Java
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 11.0.3
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 11.0.3
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9212D8B4-C3CF-43E1-A1FF-8EEA311633DC} - PureEdge Viewer
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
========== Files/Folders - Created Within 30 Days ==========
[5 C:\WINDOWS\*.tmp files]
[2009/03/23 19:52:15 | 00,499,200 | —- | C] (OldTimer Tools) – C:\DOCUME~1\Shaena\Desktop\OTListIt2.exe
[2009/03/23 19:50:05 | 00,000,000 | —D | C] – C:\Rooter$
[2009/03/23 19:49:37 | 00,267,612 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\Rooter.exe
[2009/03/23 10:30:57 | 01,095,541 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\img001.jpg
[2009/03/23 07:00:20 | 00,026,112 | —- | C] () – C:\DOCUME~1\Shaena\My Documents\Attic live load.doc
[2009/03/18 13:08:30 | 00,401,720 | —- | C] (Trend Micro Inc.) – C:\DOCUME~1\Shaena\Desktop\HijackThis.exe
[2009/03/18 10:58:39 | 02,036,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_40.dll
[2009/03/18 10:58:39 | 00,452,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_40.dll
[2009/03/18 10:58:38 | 04,379,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_40.dll
[2009/03/18 10:58:36 | 00,514,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_3.dll
[2009/03/18 10:58:36 | 00,070,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_2.dll
[2009/03/18 10:58:35 | 00,235,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_3.dll
[2009/03/18 10:58:34 | 00,023,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_5.dll
[2009/03/18 10:58:32 | 00,509,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_2.dll
[2009/03/18 10:58:32 | 00,068,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_1.dll
[2009/03/18 10:58:31 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_2.dll
[2009/03/18 10:58:30 | 01,493,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_39.dll
[2009/03/18 10:58:30 | 00,467,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_39.dll
[2009/03/18 10:58:29 | 03,851,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_39.dll
[2009/03/18 10:58:27 | 00,507,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_1.dll
[2009/03/18 10:58:27 | 00,065,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_0.dll
[2009/03/18 10:58:26 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_1.dll
[2009/03/18 10:58:25 | 00,025,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_4.dll
[2009/03/18 10:58:24 | 01,491,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_38.dll
[2009/03/18 10:58:24 | 00,467,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_38.dll
[2009/03/18 10:58:23 | 03,850,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_38.dll
[2009/03/18 10:58:21 | 00,479,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_0.dll
[2009/03/18 10:58:20 | 00,238,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_0.dll
[2009/03/18 10:58:19 | 00,025,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_3.dll
[2009/03/18 10:58:18 | 01,420,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_37.dll
[2009/03/18 10:58:18 | 00,462,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_37.dll
[2009/03/18 10:58:17 | 03,786,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_37.dll
[2009/03/18 10:58:15 | 00,267,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_10.dll
[2009/03/18 10:58:13 | 01,374,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_36.dll
[2009/03/18 10:58:13 | 00,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_36.dll
[2009/03/18 10:58:12 | 03,734,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_36.dll
[2009/03/18 10:58:11 | 00,267,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_9.dll
[2009/03/18 10:58:10 | 01,358,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_35.dll
[2009/03/18 10:58:10 | 00,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_35.dll
[2009/03/18 10:58:08 | 03,727,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_35.dll
[2009/03/18 10:58:07 | 00,266,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_8.dll
[2009/03/18 10:58:07 | 00,017,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_2.dll
[2009/03/18 10:58:06 | 01,124,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_34.dll
[2009/03/18 10:58:06 | 00,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_34.dll
[2009/03/18 10:58:05 | 03,497,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_34.dll
[2009/03/18 10:58:04 | 00,081,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_3.dll
[2009/03/18 10:58:03 | 00,261,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_7.dll
[2009/03/18 10:57:54 | 00,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_33.dll
[2009/03/18 10:57:53 | 01,123,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_33.dll
[2009/03/18 10:57:41 | 03,495,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_33.dll
[2009/03/18 10:57:40 | 00,255,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_6.dll
[2009/03/18 10:57:39 | 00,251,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_5.dll
[2009/03/18 10:57:38 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2009/03/18 10:57:37 | 00,237,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_4.dll
[2009/03/18 10:57:37 | 00,015,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_1.dll
[2009/03/18 10:57:36 | 02,414,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_31.dll
[2009/03/18 10:57:35 | 00,236,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_3.dll
[2009/03/18 10:57:34 | 00,062,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_2.dll
[2009/03/18 10:57:33 | 00,230,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_2.dll
[2009/03/18 10:57:32 | 00,062,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_1.dll
[2009/03/18 10:57:31 | 00,229,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_1.dll
[2009/03/18 10:57:23 | 02,388,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_30.dll
[2009/03/18 10:57:22 | 00,230,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_0.dll
[2009/03/18 10:57:22 | 00,014,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_0.dll
[2009/03/18 10:57:21 | 02,332,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_29.dll
[2009/03/18 10:57:20 | 02,323,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_28.dll
[2009/03/18 10:57:20 | 00,061,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput9_1_0.dll
[2009/03/18 10:57:19 | 02,319,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_27.dll
[2009/03/18 10:57:17 | 02,297,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_26.dll
[2009/03/18 10:57:16 | 02,337,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_25.dll
[2009/03/18 10:57:12 | 02,222,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_24.dll
[2009/03/18 10:54:10 | 00,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2009/03/18 10:53:52 | 00,000,000 | —D | C] – C:\WINDOWS\Logs
[2009/03/09 09:10:22 | 00,584,901 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\img068.jpg
[2009/03/09 09:09:34 | 00,426,855 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\img064.jpg
[2009/03/09 09:09:08 | 00,649,993 | —- | C] () – C:\DOCUME~1\Shaena\Desktop\img067.jpg
[2009/03/01 21:34:29 | 00,005,657 | —- | C] () – C:\DOCUME~1\Shaena\My Documents\2nd floor remodel.PSH
[2009/03/01 19:50:32 | 00,030,291 | —- | C] () – C:\DOCUME~1\Shaena\My Documents\Shaena's Garage Addition.PSH
[2009/02/24 18:40:08 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/03/23 19:52:32 | 00,499,200 | —- | M] (OldTimer Tools) – C:\DOCUME~1\Shaena\Desktop\OTListIt2.exe
[2009/03/23 19:49:40 | 00,267,612 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\Rooter.exe
[2009/03/23 19:45:55 | 00,192,512 | —- | M] (??????) – C:\WINDOWS\System32\kdfvmgr.exe
[2009/03/23 19:45:55 | 00,077,824 | —- | M] (Kings Information & Network) – C:\WINDOWS\System32\kdfapi.dll
[2009/03/23 19:45:55 | 00,053,248 | —- | M] (Kings Information & Network) – C:\WINDOWS\System32\Kdfhok.dll
[2009/03/23 19:45:52 | 00,387,288 | —- | M] (Bluegem Security) – C:\WINDOWS\System32\kdfmgr.exe
[2009/03/23 10:30:57 | 01,095,541 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\img001.jpg
[2009/03/23 08:50:10 | 00,649,993 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\img067.jpg
[2009/03/23 07:31:21 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/23 07:30:58 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/23 07:30:53 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/23 07:00:21 | 00,026,112 | —- | M] () – C:\DOCUME~1\Shaena\My Documents\Attic live load.doc
[2009/03/19 20:02:10 | 00,475,872 | —- | M] (Bluegem Security) – C:\WINDOWS\System32\kdfinj.dll
[2009/03/18 16:59:52 | 00,518,144 | —- | M] () – C:\DOCUME~1\Shaena\My Documents\Outback Steakhouse Recipies.doc
[2009/03/18 13:08:30 | 00,401,720 | —- | M] (Trend Micro Inc.) – C:\DOCUME~1\Shaena\Desktop\HijackThis.exe
[2009/03/18 12:49:10 | 00,105,202 | —- | M] (TWD Industries SAS) – C:\WINDOWS\Slave.exe
[2009/03/18 11:07:28 | 00,030,291 | —- | M] () – C:\DOCUME~1\Shaena\My Documents\Shaena's Garage Addition.PSH
[2009/03/18 10:35:47 | 00,005,657 | —- | M] () – C:\DOCUME~1\Shaena\My Documents\2nd floor remodel.PSH
[2009/03/16 23:12:08 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/12 09:36:57 | 00,435,498 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/12 09:36:57 | 00,068,354 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/12 09:36:56 | 00,512,960 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/12 09:33:55 | 00,297,256 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/12 09:23:29 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/09 09:10:22 | 00,584,901 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\img068.jpg
[2009/03/09 09:09:35 | 00,426,855 | —- | M] () – C:\DOCUME~1\Shaena\Desktop\img064.jpg
[2009/03/05 22:17:48 | 01,195,512 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\vsapint.sys
[2009/03/05 22:17:48 | 00,205,328 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmxpflt.sys
[2009/03/05 22:17:48 | 00,036,368 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmpreflt.sys
[2009/03/03 19:12:44 | 00,080,400 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmtdi.sys
[2009/03/03 05:08:15 | 00,335,376 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\TM_CFW.sys
[2009/03/03 04:34:24 | 00,050,192 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2009/03/03 04:34:20 | 00,150,032 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/03/03 04:34:17 | 00,050,192 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmactmon.sys
[2009/02/25 12:55:00 | 24,768,960 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
========== Custom Scans ==========
< %systemroot%\System32\antiwpa.dll >
< %systemroot%\SYSTEM32\wpa.dll >
< %systemroot%\setup\scripts\biestart.exe >
< %systemroot%\system32\drivers\royal.sys >
< %systemroot%\system32\serauth1.dll >
< %systemroot%\system32\serauth2.dll >
< %systemroot%\system32\sysaudio.sys >
< %systemroot%\system32\wdmaud.sys >
< %systemroot%\system32\aeaudio.sys >
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\Slave.exe:SummaryInformation
< End of report >
OTListIt Extras logfile created on: 3/23/2009 7:55:07 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.7.1 Folder = C:\Documents and Settings\Shaena\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1006.80 Mb Total Physical Memory | 649.42 Mb Available Physical Memory | 64.50% Memory free
2.37 Gb Paging File | 2.01 Gb Available in Paging File | 84.88% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 21.97 Gb Free Space | 58.97% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SHAE
Current User Name: Shaena
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"4000:TCP" = 4000:TCP:*:Enabled:Update
"4000:UDP" = 4000:UDP:*:Enabled:Avir
"3999:TCP" = 3999:TCP:*:Enabled:ICS
"3999:UDP" = 3999:UDP:*:Enabled:Security
"3998:TCP" = 3998:TCP:*:Enabled:Internet
"3998:UDP" = 3998:UDP:*:Enabled:Firewall
"3997:TCP" = 3997:TCP:*:Enabled:Nod32
"3997:UDP" = 3997:UDP:*:Enabled:System
"3996:TCP" = 3996:TCP:*:Enabled:Yahoo
"3996:UDP" = 3996:UDP:*:Enabled:Kaspersky
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2007/04/22 22:29:34 | 00,088,824 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:*:Enabled:RoxioUPnPRenderer9
[2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2007/04/23 13:43:40 | 00,617,208 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Media Manager 9\MediaManager9.exe:*:Enabled:MediaManager9 Module
[2007/04/22 22:29:34 | 00,088,824 | —- | M] (Sonic Solutions) – C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:*:Enabled:RoxioUPnPRenderer9
[2004/06/04 02:58:10 | 00,196,608 | —- | M] (InterVideo Inc.) – C:\Program Files\InterVideo\DVD6\WinDVD.exe:*:Enabled:WinDVD
[2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/01/16 15:57:06 | 00,147,080 | —- | M] (ExtendMedia Inc.) – C:\Program Files\NBC Direct\StoreFrontPlayer.exe:*:Enabled:NBC Direct Beta
[2008/12/19 01:25:25 | 00,634,024 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer
[2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
[2008/11/20 14:20:48 | 14,294,824 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1FD0C5C1-B01B-4B4C-9607-E5D3B3D1318F}" = Microsoft IntelliPoint 4.1
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 12
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{40E12A55-C504-4223-AFAC-7672DBF1ACDE}" = Trend Micro Internet Security Pro
"{66D171AA-670F-4309-9C74-5BA7F7DBA0B3}" = Roxio Media Manager
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ACA2FD2-4C4A-42F3-AFB5-7B433BBDF6DB}" = InterVideo WinDVD 6
"{6DA9102E-199F-43A0-A36B-6EF48081A658}" = MobileMe Control Panel
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security Pro
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9B449C1A-4F64-4ED4-8C96-31B222E8377F}" = BlackBerry Desktop Software 4.2.2
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C91EF330-F152-44ED-A33A-0F4FF3FAF813}" = NBC Direct Beta
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}" = ArcSoft PhotoImpression 5
"{E0000650-0650-0650-0650-000000000650}" = PureEdge Viewer 6.5
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
"AC3Filter" = AC3Filter (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"BlackBerry_{9B449C1A-4F64-4ED4-8C96-31B222E8377F}" = BlackBerry Desktop Software 4.2.2
"CTDVDAudio Plugin" = Creative DVD Audio Plugin for Audigy Series
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InterActual Player" = InterActual Player
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Adapters and Drivers
"Punch! Super Home Suite" = Punch! Super Home Suite
"Silent Package Run-Time Sample" = EPSON CX 4200 4800 Guide
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/11/2009 8:50:42 AM | Computer Name = SHAE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/31/2009 9:20:43 PM | Computer Name = SHAE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/31/2009 9:23:37 PM | Computer Name = SHAE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/31/2009 9:23:42 PM | Computer Name = SHAE | Source = Application Hang | ID = 1001
Description = Fault bucket 1015682910.
Error - 2/2/2009 7:56:26 AM | Computer Name = SHAE | Source = Application Error | ID = 1000
Description = Faulting application msimn.exe, version 6.0.2900.5512, faulting module
inetcomm.dll, version 6.0.2900.5579, fault address 0x000148c1.
Error - 2/2/2009 7:56:33 AM | Computer Name = SHAE | Source = Application Error | ID = 1001
Description = Fault bucket 882718558.
Error - 2/16/2009 8:46:25 AM | Computer Name = SHAE | Source = Application Error | ID = 1000
Description = Faulting application tmarsvc.exe, version 1.0.0.1075, faulting module
LogPaser.dll, version 1.0.0.1075, fault address 0x0001269c.
Error - 2/17/2009 10:15:18 PM | Computer Name = SHAE | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module mshtml.dll, version 7.0.6000.16809, fault address 0x00053b56.
Error - 3/10/2009 9:31:15 AM | Computer Name = SHAE | Source = Google_Toolbar | ID = 1
Description =
Error - 3/16/2009 12:50:33 PM | Computer Name = SHAE | Source = Google_Toolbar | ID = 1
Description =
[ System Events ]
Error - 3/20/2009 5:55:53 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
Error - 3/20/2009 6:49:08 PM | Computer Name = SHAE | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 3/20/2009 7:52:03 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
Error - 3/20/2009 7:52:22 PM | Computer Name = SHAE | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 00022DB216E5. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 3/21/2009 6:03:47 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
Error - 3/21/2009 6:04:00 PM | Computer Name = SHAE | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 00022DB216E5. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 3/22/2009 8:50:07 AM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
Error - 3/22/2009 5:03:06 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
Error - 3/23/2009 6:25:31 AM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
Error - 3/23/2009 7:42:21 PM | Computer Name = SHAE | Source = PSched | ID = 14103
Description = QoS [Adapter {DD8A5018-6747-4EDF-9D6F-155FB74CECA9}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
< End of report >