im not able to find the box that says radio something in OTScanIt, i did the scan without it and the log is as followed.
OTScanIt2 logfile created on: 5/12/2009 6:52:58 PM - Run 1
OTScanIt2 by OldTimer - Version 1.0.14.0 Folder = C:\Documents and Settings\Kevin\Desktop\OTScanIt2
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
893.98 Mb Total Physical Memory | 328.92 Mb Available Physical Memory | 36.79% Memory free
2.12 Gb Paging File | 1.52 Gb Available in Paging File | 72.06% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.11 Gb Total Space | 34.47 Gb Free Space | 49.88% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 955.72 Mb Total Space | 877.38 Mb Free Space | 91.80% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KEVIN
Current User Name: Kevin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
[Processes - Safe List]
aim6.exe -> %ProgramFiles%\AIM6\aim6.exe -> [2008/10/17 10:45:06 | 00,049,960 | —- | M] (AOL LLC)
aolsoftware.exe -> %ProgramFiles%\AIM6\aolsoftware.exe -> [2008/05/02 13:25:42 | 00,041,824 | —- | M] (AOL LLC)
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/03/26 15:31:20 | 00,132,424 | —- | M] (Apple Inc.)
ati2evxx.exe -> %SystemRoot%\system32\Ati2evxx.exe -> [2007/10/16 23:16:12 | 00,430,080 | —- | M] (ATI Technologies Inc.)
ati2evxx.exe -> %SystemRoot%\system32\Ati2evxx.exe -> [2007/10/16 23:16:12 | 00,430,080 | —- | M] (ATI Technologies Inc.)
avgnsx.exe -> %ProgramFiles%\AVG\AVG8\avgnsx.exe -> [2009/04/27 16:24:05 | 00,594,200 | —- | M] (AVG Technologies CZ, s.r.o.)
avgrsx.exe -> %ProgramFiles%\AVG\AVG8\avgrsx.exe -> [2009/04/27 16:24:05 | 00,485,144 | —- | M] (AVG Technologies CZ, s.r.o.)
avgtray.exe -> %ProgramFiles%\AVG\AVG8\avgtray.exe -> [2009/04/27 16:24:04 | 01,932,568 | —- | M] (AVG Technologies CZ, s.r.o.)
avgwdsvc.exe -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2009/04/27 16:24:03 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.)
bcmwltry.exe -> %SystemRoot%\System32\bcmwltry.exe -> [2007/05/09 23:59:38 | 01,253,376 | —- | M] (Dell Inc.)
cpshelprunner.exe -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe -> [2006/11/05 11:55:48 | 00,010,752 | —- | M] (Sonic Solutions)
dlcxcoms.exe -> %SystemRoot%\system32\dlcxcoms.exe -> [2006/05/18 16:36:10 | 00,495,616 | —- | M] ( )
dlcxmon.exe -> %ProgramFiles%\Dell Photo AIO Printer 926\dlcxmon.exe -> [2006/06/14 08:51:38 | 00,286,720 | —- | M] ()
dlg.exe -> %ProgramFiles%\Digital Line Detect\DLG.exe -> [2003/10/29 03:06:00 | 00,024,576 | —- | M] (BVRP Software)
dsagnt.exe -> %ProgramFiles%\Dell Support\DSAgnt.exe -> [2006/08/28 22:57:12 | 00,395,776 | —- | M] (Gteko Ltd.)
dvdlauncher.exe -> %ProgramFiles%\CyberLink\PowerDVD\DVDLauncher.exe -> [2005/12/09 21:29:52 | 00,049,152 | —- | M] (CyberLink Corp.)
ehmsas.exe -> %SystemRoot%\eHome\ehmsas.exe -> [2005/08/05 15:56:28 | 00,046,592 | —- | M] (Microsoft Corporation)
ehrecvr.exe -> %SystemRoot%\eHome\ehRecvr.exe -> [2006/10/09 16:16:56 | 00,237,568 | —- | M] (Microsoft Corporation)
ehsched.exe -> %SystemRoot%\eHome\ehSched.exe -> [2005/08/05 15:56:32 | 00,102,912 | —- | M] (Microsoft Corporation)
ehtray.exe -> %SystemRoot%\ehome\ehtray.exe -> [2005/09/29 15:01:14 | 00,067,584 | —- | M] (Microsoft Corporation)
explorer.exe -> %SystemRoot%\Explorer.EXE -> [2007/06/13 06:23:07 | 01,033,216 | —- | M] (Microsoft Corporation)
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2009/04/02 16:10:56 | 00,656,168 | —- | M] (Apple Inc.)
issch.exe -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe -> [2005/06/10 10:44:02 | 00,081,920 | —- | M] (InstallShield Software Corporation)
isuspm.exe -> %CommonProgramFiles%\installshield\updateservice\isuspm.exe -> [2005/06/10 10:44:02 | 00,249,856 | —- | M] (InstallShield Software Corporation)
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> [2009/04/02 16:11:02 | 00,342,312 | —- | M] (Apple Inc.)
mcrdsvc.exe -> %SystemRoot%\ehome\mcrdsvc.exe -> [2005/08/05 15:27:08 | 00,099,328 | —- | M] (Microsoft Corporation)
mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.)
memcard.exe -> %ProgramFiles%\Dell Photo AIO Printer 926\memcard.exe -> [2006/06/27 07:34:50 | 00,299,008 | —- | M] ()
msnmsgr.exe -> %ProgramFiles%\Windows Live\Messenger\MsnMsgr.Exe -> [2007/10/18 11:34:02 | 05,724,184 | —- | M] (Microsoft Corporation)
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2009/04/11 16:32:52 | 00,494,080 | —- | M] (OldTimer Tools)
pccguide.exe -> %ProgramFiles%\Trend Micro\Internet Security 14\pccguide.exe -> [2006/11/21 14:02:24 | 01,807,960 | —- | M] (Trend Micro Inc.)
pcctlcom.exe -> %ProgramFiles%\Trend Micro\Internet Security 14\PcCtlCom.exe -> [2008/05/19 16:17:14 | 01,475,936 | —- | M] (Trend Micro Inc.)
psiservice.exe -> %SystemRoot%\system32\PSIService.exe -> [2007/06/05 13:20:32 | 00,177,704 | —- | M] ()
quickset.exe -> %ProgramFiles%\Dell\QuickSet\quickset.exe -> [2007/02/20 13:29:08 | 01,191,936 | —- | M] (Dell Inc)
roxmediadb9.exe -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe -> [2006/11/05 12:15:12 | 00,880,640 | —- | M] (Sonic Solutions)
roxwatch9.exe -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe -> [2006/11/05 12:13:00 | 00,159,744 | —- | M] (Sonic Solutions)
roxwatchtray9.exe -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe -> [2006/11/05 12:22:16 | 00,221,184 | —- | M] (Sonic Solutions)
snmp.exe -> %SystemRoot%\System32\snmp.exe -> [2004/08/10 07:00:00 | 00,032,768 | —- | M] (Microsoft Corporation)
stsystra.exe -> %SystemRoot%\stsystra.exe -> [2006/09/22 13:06:26 | 00,282,624 | —- | M] (SigmaTel, Inc.)
syntpenh.exe -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe -> [2006/09/22 13:47:54 | 00,761,947 | —- | M] (Synaptics, Inc.)
tcpsvcs.exe -> %SystemRoot%\system32\tcpsvcs.exe -> [2004/08/10 07:00:00 | 00,019,456 | —- | M] (Microsoft Corporation)
tmas_oemon.exe -> %ProgramFiles%\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe -> [2006/08/04 17:15:28 | 00,321,040 | —- | M] (Trend Micro Inc.)
tmntsrv.exe -> %ProgramFiles%\Trend Micro\Internet Security 14\Tmntsrv.exe -> [2007/11/09 04:19:18 | 00,345,696 | —- | M] (Trend Micro Inc.)
tmpfw.exe -> %ProgramFiles%\Trend Micro\Internet Security 14\TmPfw.exe -> [2006/11/09 16:03:42 | 00,923,216 | —- | M] (Trend Micro Inc.)
tmproxy.exe -> %ProgramFiles%\Trend Micro\Internet Security 14\tmproxy.exe -> [2006/11/09 16:04:02 | 00,566,872 | —- | M] (Trend Micro Inc.)
viewpointservice.exe -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 17:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation)
wltray.exe -> %SystemRoot%\system32\WLTRAY.exe -> [2007/05/09 23:59:46 | 01,392,640 | —- | M] (Dell Inc.)
wltrysvc.exe -> %SystemRoot%\System32\WLTRYSVC.EXE -> [2007/05/09 23:59:48 | 00,020,480 | —- | M] ()
wscntfy.exe -> %SystemRoot%\system32\wscntfy.exe -> [2004/08/10 07:00:00 | 00,013,824 | —- | M] (Microsoft Corporation)
[Win32 Services - Safe List]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/03/26 15:31:20 | 00,132,424 | —- | M] (Apple Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe -> [2004/07/15 03:49:26 | 00,032,768 | —- | M] (Microsoft Corporation)
(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> %SystemRoot%\system32\Ati2evxx.exe -> [2007/10/16 23:16:12 | 00,430,080 | —- | M] (ATI Technologies Inc.)
(avg8wd) AVG Free8 WatchDog [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2009/04/27 16:24:03 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.)
(dlcx_device) dlcx_device [Win32_Own | On_Demand | Running] -> %SystemRoot%\system32\dlcxcoms.exe -> [2006/05/18 16:36:10 | 00,495,616 | —- | M] ( )
(ehRecvr) Media Center Receiver Service [Win32_Own | Auto | Running] -> %SystemRoot%\eHome\ehRecvr.exe -> [2006/10/09 16:16:56 | 00,237,568 | —- | M] (Microsoft Corporation)
(ehSched) Media Center Scheduler Service [Win32_Own | Auto | Running] -> %SystemRoot%\eHome\ehSched.exe -> [2005/08/05 15:56:32 | 00,102,912 | —- | M] (Microsoft Corporation)
(FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> [2008/08/26 00:13:22 | 00,654,848 | —- | M] (Macrovision Europe Ltd.)
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2009/01/04 02:34:21 | 00,138,168 | —- | M] (Google)
(helpsvc) Help and Support [Win32_Shared | Auto | Stopped] -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2004/08/10 07:00:00 | 00,038,912 | —- | M] (Microsoft Corporation)
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\1050\Intel 32\IDriverT.exe -> [2004/10/22 04:24:18 | 00,073,728 | —- | M] (Macrovision Corporation)
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2009/04/02 16:10:56 | 00,656,168 | —- | M] (Apple Inc.)
(McrdSvc) Media Center Extender Service [Win32_Own | Auto | Running] -> %SystemRoot%\ehome\mcrdsvc.exe -> [2005/08/05 15:27:08 | 00,099,328 | —- | M] (Microsoft Corporation)
(MHN) MHN [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\mhn.dll -> [2004/08/10 06:11:50 | 00,085,504 | —- | M] (Microsoft Corporation)
(odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2007/08/24 04:19:12 | 00,443,776 | —- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2006/10/26 15:03:08 | 00,145,184 | —- | M] (Microsoft Corporation)
(PcCtlCom) Trend Micro Central Control Component [Win32_Own | Auto | Running] -> %ProgramFiles%\Trend Micro\Internet Security 14\PcCtlCom.exe -> [2008/05/19 16:17:14 | 01,475,936 | —- | M] (Trend Micro Inc.)
(ProtexisLicensing) ProtexisLicensing [Win32_Own | Auto | Running] -> %SystemRoot%\system32\PSIService.exe -> [2007/06/05 13:20:32 | 00,177,704 | —- | M] ()
(RoxMediaDB9) RoxMediaDB9 [Win32_Own | On_Demand | Running] -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe -> [2006/11/05 12:15:12 | 00,880,640 | —- | M] (Sonic Solutions)
(RoxWatch9) Roxio Hard Drive Watcher 9 [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe -> [2006/11/05 12:13:00 | 00,159,744 | —- | M] (Sonic Solutions)
(SimpTcp) Simple TCP/IP Services [Win32_Shared | Auto | Running] -> %SystemRoot%\system32\tcpsvcs.exe -> [2004/08/10 07:00:00 | 00,019,456 | —- | M] (Microsoft Corporation)
(SNMP) SNMP Service [Win32_Own | Auto | Running] -> %SystemRoot%\System32\snmp.exe -> [2004/08/10 07:00:00 | 00,032,768 | —- | M] (Microsoft Corporation)
(stllssvr) stllssvr [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\SureThing Shared\stllssvr.exe -> [2006/09/14 15:54:34 | 00,073,728 | —- | M] (MicroVision Development, Inc.)
(Tmntsrv) Trend Micro Real-time Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Trend Micro\Internet Security 14\Tmntsrv.exe -> [2007/11/09 04:19:18 | 00,345,696 | —- | M] (Trend Micro Inc.)
(TmPfw) Trend Micro Personal Firewall [Win32_Own | Auto | Running] -> %ProgramFiles%\Trend Micro\Internet Security 14\TmPfw.exe -> [2006/11/09 16:03:42 | 00,923,216 | —- | M] (Trend Micro Inc.)
(tmproxy) Trend Micro Proxy Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Trend Micro\Internet Security 14\tmproxy.exe -> [2006/11/09 16:04:02 | 00,566,872 | —- | M] (Trend Micro Inc.)
(usnjsvc) Messenger Sharing Folders USN Journal Reader service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\Messenger\usnsvc.exe -> [2007/10/18 11:31:54 | 00,098,328 | —- | M] (Microsoft Corporation)
(Viewpoint Manager Service) Viewpoint Manager Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 17:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation)
(WLSetupSvc) Windows Live Setup Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\installer\WLSetupSvc.exe -> [2007/10/25 15:27:54 | 00,266,240 | —- | M] (Microsoft Corporation)
(wltrysvc) Dell Wireless WLAN Tray Service [Win32_Own | Auto | Running] -> %SystemRoot%\System32\WLTRYSVC.EXE -> [2007/05/09 23:59:48 | 00,020,480 | —- | M] ()
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Media Player\WMPNetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
[Driver Services - Safe List]
(AliIde) AliIde [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\aliide.sys -> [2001/08/17 15:51:56 | 00,005,248 | —- | M] (Acer Laboratories Inc.)
(amdagp) AMD AGP Bus Filter Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\amdagp.sys -> [2004/08/04 01:07:44 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.)
(AmdK8) AMD Processor Driver [Kernel | System | Running] -> %SystemRoot%\system32\DRIVERS\AmdK8.sys -> [2006/07/01 23:39:40 | 00,036,864 | —- | M] (Advanced Micro Devices)
(APPDRV) APPDRV [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\APPDRV.SYS -> [2005/08/12 17:50:46 | 00,016,128 | —- | M] (Dell Inc)
(asc) asc [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\asc.sys -> [2001/08/17 15:52:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.)
(asc3550) asc3550 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\asc3550.sys -> [2001/08/17 15:51:58 | 00,014,848 | —- | M] (Advanced System Products, Inc.)
(ASCTRM) ASCTRM [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\asctrm.sys -> [2008/03/21 16:55:40 | 00,008,552 | —- | M] (Windows (R) 2000 DDK provider)
(ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ati2mtag.sys -> [2007/10/16 23:16:14 | 01,777,152 | —- | M] (ATI Technologies Inc.)
(AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Running] -> %SystemRoot%\System32\Drivers\avgldx86.sys -> [2009/04/27 16:24:23 | 00,325,640 | —- | M] (AVG Technologies CZ, s.r.o.)
(AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> %SystemRoot%\System32\Drivers\avgmfx86.sys -> [2009/04/27 16:24:21 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.)
(AvgTdiX) AVG Free8 Network Redirector [Kernel | System | Running] -> %SystemRoot%\System32\Drivers\avgtdix.sys -> [2009/04/27 16:24:32 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.)
(BCM43XX) Dell Wireless WLAN Card Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\bcmwl5.sys -> [2007/05/09 23:59:42 | 00,604,928 | —- | M] (Broadcom Corporation)
(bcm4sbxp) Broadcom 440x 10/100 Integrated Controller XP Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\bcm4sbxp.sys -> [2006/08/17 15:55:16 | 00,044,544 | —- | M] (Broadcom Corporation)
(BVRPMPR5) BVRPMPR5 NDIS Protocol Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\BVRPMPR5.SYS -> [2007/07/12 13:58:54 | 00,049,904 | R— | M] (Avanquest Software)
(CmdIde) CmdIde [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\cmdide.sys -> [2001/08/17 15:51:54 | 00,006,656 | —- | M] (CMD Technology, Inc.)
(dac2w2k) dac2w2k [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\dac2w2k.sys -> [2001/08/17 15:52:16 | 00,179,584 | —- | M] (Mylex Corporation)
(DSproct) DSproct [Kernel | On_Demand | Running] -> %ProgramFiles%\Dell Support\GTAction\triggers\DSproct.sys -> [2006/01/10 12:07:58 | 00,004,864 | —- | M] (GTek Technologies Ltd.)
(E100B) Intel(R) PRO Adapter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\e100b325.sys -> [2001/08/17 14:12:10 | 00,117,760 | —- | M] (Intel Corporation)
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\GEARAspiWDM.sys -> [2009/03/19 16:32:48 | 00,023,400 | —- | M] (GEAR Software Inc.)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HDAudBus.sys -> [2004/08/12 18:45:54 | 00,137,728 | —- | M] (Windows (R) Server 2003 DDK provider)
(HSF_DPV) HSF_DPV [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSX_DPV.sys -> [2005/12/01 09:40:56 | 00,936,960 | —- | M] (Conexant Systems, Inc.)
(HSXHWAZL) HSXHWAZL [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSXHWAZL.sys -> [2005/12/01 09:40:12 | 00,192,512 | —- | M] (Conexant Systems, Inc.)
(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\mdmxsdk.sys -> [2005/10/05 06:57:08 | 00,012,544 | —- | M] (Conexant)
(mraid35x) mraid35x [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\mraid35x.sys -> [2001/08/17 15:52:12 | 00,017,280 | —- | M] (American Megatrends Inc.)
(nv) nv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\nv4_mini.sys -> [2004/08/04 00:29:56 | 01,897,408 | —- | M] (NVIDIA Corporation)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ptilink.sys -> [2004/08/10 07:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\System32\Drivers\PxHelp20.sys -> [2006/08/16 04:00:00 | 00,036,592 | —- | M] (Sonic Solutions)
(ql1080) ql1080 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\ql1080.sys -> [2001/08/17 15:52:20 | 00,040,320 | —- | M] (QLogic Corporation)
(ql12160) ql12160 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\ql12160.sys -> [2001/08/17 15:52:20 | 00,045,312 | —- | M] (QLogic Corporation)
(ql1280) ql1280 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\ql1280.sys -> [2001/08/17 15:52:18 | 00,049,024 | —- | M] (QLogic Corporation)
(rimmptsk) rimmptsk [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\rimmptsk.sys -> [2005/07/15 01:58:14 | 00,028,544 | —- | M] (REDC)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\secdrv.sys -> [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sisagp) SIS AGP Bus Filter [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\sisagp.sys -> [2004/08/04 01:07:44 | 00,041,088 | —- | M] (Silicon Integrated Systems Corporation)
(SONYPVU1) Sony USB Filter Driver (SONYPVU1) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\SONYPVU1.SYS -> [2001/08/17 13:56:16 | 00,007,552 | —- | M] (Sony Corporation)
(Sparrow) Sparrow [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\sparrow.sys -> [2001/08/17 16:07:44 | 00,019,072 | —- | M] (Adaptec, Inc.)
(STHDA) SigmaTel High Definition Audio CODEC [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\sthda.sys -> [2006/09/22 13:06:26 | 01,171,464 | —- | M] (SigmaTel, Inc.)
(symc810) symc810 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\symc810.sys -> [2001/08/17 16:07:34 | 00,016,256 | —- | M] (Symbios Logic Inc.)
(symc8xx) symc8xx [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\symc8xx.sys -> [2001/08/17 16:07:36 | 00,032,640 | —- | M] (LSI Logic)
(sym_hi) sym_hi [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\sym_hi.sys -> [2001/08/17 16:07:40 | 00,028,384 | —- | M] (LSI Logic)
(sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\sym_u3.sys -> [2001/08/17 16:07:42 | 00,030,688 | —- | M] (LSI Logic)
(SynTP) Synaptics TouchPad Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\SynTP.sys -> [2006/09/22 13:47:52 | 00,191,872 | —- | M] (Synaptics, Inc.)
(tmcfw) Trend Micro Common Firewall Service [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\TM_CFW.sys -> [2006/11/09 16:04:20 | 00,280,392 | —- | M] (Trend Micro Inc.)
(tmpreflt) tmpreflt [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\tmpreflt.sys -> [2008/11/26 18:42:40 | 00,036,368 | —- | M] (Trend Micro Inc.)
(tmtdi) Trend Micro TDI Driver [Kernel | System | Running] -> %SystemRoot%\system32\DRIVERS\tmtdi.sys -> [2006/11/09 16:04:20 | 00,073,288 | —- | M] (Trend Micro Inc.)
(tmxpflt) tmxpflt [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\TmXPFlt.sys -> [2008/11/26 18:42:42 | 00,205,328 | —- | M] (Trend Micro Inc.)
(ultra) ultra [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\ultra.sys -> [2001/08/17 15:52:22 | 00,036,736 | —- | M] (Promise Technology, Inc.)
(USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\usbaapl.sys -> [2009/03/26 15:23:46 | 00,036,864 | —- | M] (Apple, Inc.)
(usbbus) LGE CDMA Composite USB Device [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\lgusbbus.sys -> [2007/04/09 09:53:24 | 00,012,672 | —- | M] (LG Electronics Inc.)
(UsbDiag) LGE CDMA USB Serial Port [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\lgusbdiag.sys -> [2007/04/09 09:56:22 | 00,021,248 | —- | M] (LG Electronics Inc.)
(USBModem) LGE CDMA USB Modem [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\lgusbmodem.sys -> [2007/04/09 09:55:08 | 00,022,912 | —- | M] (LG Electronics Inc.)
(USB_RNDIS) USB Remote NDIS Network Device Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\usb8023.sys -> [2004/12/08 11:34:36 | 00,012,800 | —- | M] (Microsoft Corporation)
(vsapint) vsapint [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\vsapint.sys -> [2008/11/26 18:39:56 | 01,195,384 | —- | M] (Trend Micro Inc.)
(winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSX_CNXT.sys -> [2005/12/01 09:40:08 | 00,669,696 | —- | M] (Conexant Systems, Inc.)
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> Reg Error: Invalid data type. ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Page_Transitions" -> Reg Error: Invalid data type. ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\] > -> ->
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\: Main\\"Page_Transitions" -> Reg Error: Invalid data type. ->
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\: Main\\"Start Page" -> http://www.myspace.com/ ->
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\: "ProxyEnable" -> 0 ->
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\: "ProxyOverride" -> *.local ->
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\Kevin\Application Data\Mozilla\FireFox\Profiles\d2011s7p.default\prefs.js ->
browser.startup.homepage -> "http://www.myspace.com/" ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
< FireFox Extensions [User Folders] > ->
-> C:\Documents and Settings\Kevin\Application Data\mozilla\Extensions -> [2009/03/18 15:53:09 | 00,000,000 | —D | M]
-> C:\Documents and Settings\Kevin\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2009/03/18 15:53:09 | 00,000,000 | —D | M]
-> C:\Documents and Settings\Kevin\Application Data\mozilla\Firefox\Profiles\d2011s7p.default\extensions -> [2009/02/22 19:08:19 | 00,096,270 | —- | M] ()
< HOSTS File > (29 bytes and 2 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
Reset Hosts
127.0.0.1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/12/18 04:16:42 | 00,059,032 | —- | M] (Adobe Systems Incorporated)
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> %ProgramFiles%\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2009/04/27 16:24:07 | 01,078,552 | —- | M] (AVG Technologies CZ, s.r.o.)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\ssv.dll [SSVHelper Class] -> [2005/11/10 14:22:12 | 00,184,423 | —- | M] (Sun Microsystems, Inc.)
{7E853D72-626A-48EC-A868-BA8D5E23E045} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> %CommonProgramFiles%\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Windows Live Sign-in Helper] -> [2009/02/17 17:11:04 | 00,408,440 | —- | M] (Microsoft Corporation)
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\google\googletoolbar1.dll [Google Toolbar Helper] -> [2009/01/04 02:34:18 | 02,403,392 | R— | M] (Google Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"Locked" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\] > -> HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\google\googletoolbar1.dll [&Google] -> [2009/01/04 02:34:18 | 02,403,392 | R— | M] (Google Inc.)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"ATICCC" -> %ProgramFiles%\ATI Technologies\ATI.ACE\CLIStart.exe ["C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"] -> [2006/05/10 12:12:06 | 00,090,112 | —- | M] ()
"AVG8_TRAY" -> %ProgramFiles%\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> [2009/04/27 16:24:04 | 01,932,568 | —- | M] (AVG Technologies CZ, s.r.o.)
"Broadcom Wireless Manager UI" -> %SystemRoot%\system32\WLTRAY.exe [C:\WINDOWS\system32\WLTRAY.exe] -> [2007/05/09 23:59:46 | 01,392,640 | —- | M] (Dell Inc.)
"Dell QuickSet" -> %ProgramFiles%\Dell\QuickSet\quickset.exe [C:\Program Files\Dell\QuickSet\quickset.exe] -> [2007/02/20 13:29:08 | 01,191,936 | —- | M] (Dell Inc)
"DLCXCATS" -> %SystemRoot%\System32\spool\DRIVERS\W32X86\3\DLCXtime.DLL [rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16] -> [2006/06/07 12:17:18 | 00,106,496 | —- | M] ()
"dlcxmon.exe" -> %ProgramFiles%\Dell Photo AIO Printer 926\dlcxmon.exe ["C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"] -> [2006/06/14 08:51:38 | 00,286,720 | —- | M] ()
"DVDLauncher" -> %ProgramFiles%\CyberLink\PowerDVD\DVDLauncher.exe ["C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"] -> [2005/12/09 21:29:52 | 00,049,152 | —- | M] (CyberLink Corp.)
"ehTray" -> %SystemRoot%\ehome\ehtray.exe [C:\WINDOWS\ehome\ehtray.exe] -> [2005/09/29 15:01:14 | 00,067,584 | —- | M] (Microsoft Corporation)
"ISUSPM Startup" -> %CommonProgramFiles%\InstallShield\UpdateService\isuspm.exe ["c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup] -> [2005/06/10 10:44:02 | 00,249,856 | —- | M] (InstallShield Software Corporation)
"ISUSScheduler" -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe ["C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start] -> [2005/06/10 10:44:02 | 00,081,920 | —- | M] (InstallShield Software Corporation)
"iTunesHelper" -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2009/04/02 16:11:02 | 00,342,312 | —- | M] (Apple Inc.)
"KernelFaultCheck" -> [%systemroot%\system32\dumprep 0 -k] -> File not found
"MemoryCardManager" -> %ProgramFiles%\Dell Photo AIO Printer 926\memcard.exe ["C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"] -> [2006/06/27 07:34:50 | 00,299,008 | —- | M] ()
"pccguide.exe" -> %ProgramFiles%\Trend Micro\Internet Security 14\pccguide.exe ["C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"] -> [2006/11/21 14:02:24 | 01,807,960 | —- | M] (Trend Micro Inc.)
"QuickTime Task" -> %ProgramFiles%\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\QTTask.exe" -atboottime] -> [2009/01/05 16:18:48 | 00,413,696 | —- | M] (Apple Inc.)
"RoxWatchTray" -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe ["C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"] -> [2006/11/05 12:22:16 | 00,221,184 | —- | M] (Sonic Solutions)
"SigmatelSysTrayApp" -> %SystemRoot%\stsystra.exe [stsystra.exe] -> [2006/09/22 13:06:26 | 00,282,624 | —- | M] (SigmaTel, Inc.)
"SynTPEnh" -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] -> [2006/09/22 13:47:54 | 00,761,947 | —- | M] (Synaptics, Inc.)
< Run [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\] > -> HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Aim6" -> %ProgramFiles%\AIM6\aim6.exe ["C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp] -> [2008/10/17 10:45:06 | 00,049,960 | —- | M] (AOL LLC)
"DellSupport" -> ["C:\Program Files\Dell Support\DSAgnt.exe" /startup] -> File not found
"ModemOnHold" -> %ProgramFiles%\NetWaiting\netWaiting.exe [C:\Program Files\NetWaiting\netWaiting.exe] -> [2003/09/10 03:24:00 | 00,020,480 | —- | M] ()
"MSMSGS" -> %ProgramFiles%\Messenger\msmsgs.exe ["C:\Program Files\Messenger\msmsgs.exe" /background] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
"MsnMsgr" -> %ProgramFiles%\Windows Live\Messenger\MsnMsgr.Exe ["C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background] -> [2007/10/18 11:34:02 | 05,724,184 | —- | M] (Microsoft Corporation)
"OE_OEM" -> %ProgramFiles%\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe ["C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe"] -> [2006/08/04 17:15:28 | 00,321,040 | —- | M] (Trend Micro Inc.)
< Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup ->
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> [2008/04/23 03:38:16 | 00,029,696 | —- | M] (Adobe Systems Incorporated)
%AllUsersProfile%\Start Menu\Programs\Startup\Digital Line Detect.lnk -> %ProgramFiles%\Digital Line Detect\DLG.exe -> [2003/10/29 03:06:00 | 00,024,576 | —- | M] (BVRP Software)
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup ->
< Kevin Startup Folder > -> C:\Documents and Settings\Kevin\Start Menu\Programs\Startup ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"HonorAutoRunSetting" -> [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" -> [0] -> File not found
\\"legalnoticecaption" -> [] -> File not found
\\"legalnoticetext" -> [] -> File not found
\\"shutdownwithoutlogon" -> [1] -> File not found
\\"undockwithoutlogon" -> [1] -> File not found
\\"InstallVisualStyle" -> %SystemRoot%\Resources\Themes\Royale\Royale.mss [C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles] -> File not found
\\"InstallTheme" -> %SystemRoot%\Resources\Themes\Royale.the [C:\WINDOWS\Resources\Themes\Royale.theme] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005] > -> HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\npjpi150_06.dll [Menu: Sun Java Console] -> [2005/11/10 14:22:12 | 00,069,746 | —- | M] (Sun Microsystems, Inc.)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [Button: Send to OneNote] -> [2007/12/13 03:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [Menu: S&end to OneNote] -> [2007/12/13 03:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [Button: Research] -> [2006/10/26 21:12:22 | 00,040,424 | —- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2006/10/10 08:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\npjpi150_06.dll [Sun Java Console] -> [2005/11/10 14:22:12 | 00,069,746 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\npjpi150_06.dll [Sun Java Console] -> [2005/11/10 14:22:12 | 00,069,746 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\] > -> HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\npjpi150_06.dll [Sun Java Console] -> [2005/11/10 14:22:12 | 00,069,746 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2006/10/10 08:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\] > -> HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\] > -> HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab [Shockwave ActiveX Control] ->
{459E93B6-150E-45D5-8D4B-45C66FC035FE} [HKLM] -> http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx [get_atlcom Class] ->
{4871A87A-BFDD-4106-8153-FFDE2BAC2967} [HKLM] -> http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab [DLM Control] ->
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} [HKLM] -> http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab [MSN Photo Upload Tool] ->
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [HKLM] -> http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1206151895937 [MUWebControl Class] ->
{8A0019EB-51FA-4AE5-A40B-C0496BBFC739} [HKLM] -> http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab [Verizon Wireless Media Upload] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab [Java Plug-in 1.5.0_06] ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab [Reg Error: Key error.] ->
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab [Java Plug-in 1.5.0_06] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab [Java Plug-in 1.5.0_06] ->
{D0C0F75C-683A-4390-A791-1ACFD5599AB8} [HKLM] -> http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab [Oberon Flash Game Host] ->
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{6B9D471B-52F7-43CD-ABE5-21D7EA940D16} -> (Dell Wireless 1390 WLAN Mini-Card) ->
{9230E000-B006-4CA8-9A48-142F2C1A919D} -> (Motorola SURFboard SB5120 USB Cable Modem) ->
{C36D746A-1CBD-48B6-AD9A-D43E2D232B45} -> (Dell Wireless 1390 WLAN Mini-Card) ->
{EEE03215-180F-422E-8124-CC1F850C06B5} -> (Broadcom 440x 10/100 Integrated Controller) ->
IE Styles -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> %SystemRoot%\Explorer.exe -> [2007/06/13 06:23:07 | 01,033,216 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
AtiExtEvent -> %SystemRoot%\system32\Ati2evxx.dll -> [2007/10/16 23:16:12 | 00,090,112 | —- | M] (ATI Technologies Inc.)
avgrsstarter -> %SystemRoot%\system32\avgrsstx.dll -> [2009/04/27 16:24:34 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.)
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006/10/10 08:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/10 07:00:00 | 00,140,800 | —- | M] (Microsoft Corporation)
"C:\Program Files\America Online 9.0\waol.exe" -> C:\Program Files\America Online 9.0\waol.exe [C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe [C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007/10/02 17:18:24 | 00,304,488 | —- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007/10/18 11:34:02 | 05,724,184 | —- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006/10/10 08:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/10 07:00:00 | 00,140,800 | —- | M] (Microsoft Corporation)
"C:\Program Files\AIM6\aim6.exe" -> C:\Program Files\AIM6\aim6.exe [C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM] -> [2008/10/17 10:45:06 | 00,049,960 | —- | M] (AOL LLC)
"C:\Program Files\America Online 9.0\waol.exe" -> C:\Program Files\America Online 9.0\waol.exe [C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe [C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" -> C:\Program Files\Common Files\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> [2006/11/03 03:17:27 | 00,010,800 | —- | M] (AOL LLC)
"C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] -> File not found
"C:\Program Files\Messenger\msmsgs.exe" -> C:\Program Files\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" -> C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE [C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote] -> [2008/05/21 06:54:40 | 01,022,496 | —- | M] (Microsoft Corporation)
"C:\Program Files\MySpace\IM\MySpaceIM.exe" -> C:\Program Files\MySpace\IM\MySpaceIM.exe [C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpaceIM] -> File not found
"C:\Program Files\Vuze\Azureus.exe" -> C:\Program Files\Vuze\Azureus.exe [C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus] -> File not found
"C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007/10/02 17:18:24 | 00,304,488 | —- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007/10/18 11:34:02 | 05,724,184 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\system32\dlcxcoms.exe" -> C:\WINDOWS\system32\dlcxcoms.exe [C:\WINDOWS\system32\dlcxcoms.exe:*:Enabled:Lexmark Communications System] -> [2006/05/18 16:36:10 | 00,495,616 | —- | M] ( )
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> %SystemRoot%\system32\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2004/08/10 07:00:00 | 00,049,536 | —- | M] (Microsoft Corporation)
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2005/08/16 06:43:04 | 00,000,000 | —- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
\{361ac05d-0e0d-11da-9aa9-806d6172696f}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell
\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\\"" -> [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun
\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\\"" -> [Auto&Play] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command
\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command\\"" -> E:\setup.exe [E:\setup.exe] -> File not found
\{75f25ca4-7266-11dd-9fd1-0019b94c5607}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{75f25ca4-7266-11dd-9fd1-0019b94c5607}\Shell
\{75f25ca4-7266-11dd-9fd1-0019b94c5607}\Shell\\"" -> [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{75f25ca4-7266-11dd-9fd1-0019b94c5607}\Shell\AutoRun
\{75f25ca4-7266-11dd-9fd1-0019b94c5607}\Shell\AutoRun\\"" -> [Auto&Play] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{75f25ca4-7266-11dd-9fd1-0019b94c5607}\Shell\AutoRun\command
\{75f25ca4-7266-11dd-9fd1-0019b94c5607}\Shell\AutoRun\command\\"" -> E:\LaunchU3.exe [E:\LaunchU3.exe] -> File not found
[Registry - Additional Scans - Safe List]
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 5/9/2009 12:08:17 AM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing. HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 12:08:17 AM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.
Application [ Error ] 5/9/2009 12:08:45 AM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing. HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 12:08:45 AM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.
Application [ Error ] 5/9/2009 1:24:16 AM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing. HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 1:24:16 AM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.
Application [ Error ] 5/9/2009 4:31:01 PM Computer Name = KEVIN | Source = PerfNet | ID = 2004 -> Description = Unable to open the Server service. Server performance data will not be returned. Error code returned is in data DWORD 0.
Application [ Error ] 5/9/2009 9:19:27 PM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing. HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 9:19:27 PM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.
Application [ Error ] 5/11/2009 6:43:24 PM Computer Name = KEVIN | Source = PerfNet | ID = 2004 -> Description = Unable to open the Server service. Server performance data will not be returned. Error code returned is in data DWORD 0.
Application [ Error ] 5/9/2009 12:08:17 AM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing. HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 12:08:17 AM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.
Application [ Error ] 5/9/2009 12:08:45 AM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing. HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 12:08:45 AM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.
Application [ Error ] 5/9/2009 1:24:16 AM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing. HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 1:24:16 AM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.
Application [ Error ] 5/9/2009 4:31:01 PM Computer Name = KEVIN | Source = PerfNet | ID = 2004 -> Description = Unable to open the Server service. Server performance data will not be returned. Error code returned is in data DWORD 0.
Application [ Error ] 5/9/2009 9:19:27 PM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing. HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 9:19:27 PM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.
Application [ Error ] 5/11/2009 6:43:24 PM Computer Name = KEVIN | Source = PerfNet | ID = 2004 -> Description = Unable to open the Server service. Server performance data will not be returned. Error code returned is in data DWORD 0.
System [ Error ] 5/11/2009 6:50:00 PM Computer Name = KEVIN | Source = Service Control Manager | ID = 7034 -> Description = The Remote Access Connection Manager service terminated unexpectedly. It has done this 8 time(s).
System [ Error ] 5/11/2009 6:56:10 PM Computer Name = KEVIN | Source = DCOM | ID = 10010 -> Description = The server {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E} did not register with DCOM within the required timeout.
System [ Error ] 5/11/2009 6:56:22 PM Computer Name = KEVIN | Source = DCOM | ID = 10005 -> Description = DCOM got error "%109" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
System [ Error ] 5/11/2009 6:58:22 PM Computer Name = KEVIN | Source = DCOM | ID = 10005 -> Description = DCOM got error "%109" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
System [ Error ] 5/11/2009 7:06:23 PM Computer Name = KEVIN | Source = DCOM | ID = 10005 -> Description = DCOM got error "%109" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
System [ Error ] 5/11/2009 7:08:24 PM Computer Name = KEVIN | Source = DCOM | ID = 10005 -> Description = DCOM got error "%109" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
System [ Error ] 5/11/2009 7:26:24 PM Computer Name = KEVIN | Source = DCOM | ID = 10005 -> Description = DCOM got error "%109" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
System [ Error ] 5/11/2009 11:15:26 PM Computer Name = KEVIN | Source = Service Control Manager | ID = 7032 -> Description = The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: %%1056
System [ Error ] 5/11/2009 11:27:53 PM Computer Name = KEVIN | Source = Service Control Manager | ID = 7032 -> Description = The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: %%1056
System [ Error ] 5/12/2009 4:27:36 PM Computer Name = KEVIN | Source = DCOM | ID = 10010 -> Description = The server {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E} did not register with DCOM within the required timeout.
[Files/Folders - Created Within 30 Days]
1 C:\Documents and Settings\Kevin\Desktop\*.tmp files -> C:\Documents and Settings\Kevin\Desktop\*.tmp ->
OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2009/05/12 18:49:31 | 00,000,000 | —D | C]
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/05/06 21:45:23 | 00,015,504 | —- | C] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/05/06 21:45:23 | 00,000,696 | —- | C] ()
mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009/05/06 21:45:20 | 00,038,496 | —- | C] (Malwarebytes Corporation)
Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [2009/05/06 21:45:19 | 00,000,000 | —D | C]
Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [2009/05/06 21:45:18 | 00,000,000 | —D | C]
mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> [2009/05/06 21:43:48 | 02,967,800 | —- | C] (Malwarebytes Corporation )
sqmdata03.sqm -> %SystemDrive%\sqmdata03.sqm -> [2009/05/06 15:39:16 | 00,000,268 | -H– | C] ()
sqmnoopt03.sqm -> %SystemDrive%\sqmnoopt03.sqm -> [2009/05/06 15:39:16 | 00,000,244 | -H– | C] ()
iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2009/05/06 15:38:45 | 00,002,137 | —- | C] ()
{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> %AllUsersProfile%\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> [2009/05/06 15:37:32 | 00,000,000 | —D | C]
QuickTime Player.lnk -> %AllUsersProfile%\Desktop\QuickTime Player.lnk -> [2009/05/06 15:36:31 | 00,001,604 | —- | C] ()
QuickTime -> %ProgramFiles%\QuickTime -> [2009/05/06 15:36:07 | 00,000,000 | —D | C]
HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [2009/05/06 00:33:34 | 00,001,734 | —- | C] ()
Starcraft -> %UserProfile%\Desktop\Starcraft -> [2009/05/02 23:31:45 | 00,000,000 | —D | C]
Kevin000000.ERR -> %SystemDrive%\Kevin000000.ERR -> [2009/05/01 15:33:27 | 00,010,700 | —- | C] ()
e8d0a704bbf74f9049 -> %SystemDrive%\e8d0a704bbf74f9049 -> [2009/04/27 23:17:42 | 00,000,000 | —D | C]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2009/04/27 22:53:23 | 93,747,2000 | -HS- | C] ()
CSC -> %SystemRoot%\CSC -> [2009/04/27 22:45:50 | 00,000,000 | —D | C]
7798df00f2fdb8ede340ed7042ac5e97 -> %SystemDrive%\7798df00f2fdb8ede340ed7042ac5e97 -> [2009/04/27 18:37:10 | 00,000,000 | —D | C]
$AVG8.VAULT$ -> %SystemDrive%\$AVG8.VAULT$ -> [2009/04/27 16:33:12 | 00,000,000 | -H-D | C]
avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2009/04/27 16:24:34 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.)
AVG Free 8.5.lnk -> %AllUsersProfile%\Desktop\AVG Free 8.5.lnk -> [2009/04/27 16:24:34 | 00,001,507 | —- | C] ()
avgtdix.sys -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2009/04/27 16:24:32 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.)
avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2009/04/27 16:24:23 | 00,325,640 | —- | C] (AVG Technologies CZ, s.r.o.)
avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2009/04/27 16:24:21 | 00,027,656 | —- | C] (AVG Technologies CZ, s.r.o.)
incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2009/04/27 16:24:17 | 34,395,507 | —- | C] ()
avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [2009/04/27 16:24:17 | 06,061,540 | —- | C] ()
miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [2009/04/27 16:24:17 | 00,401,372 | —- | C] ()
microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2009/04/27 16:24:17 | 00,057,798 | —- | C] ()
Avg -> %SystemRoot%\System32\drivers\Avg -> [2009/04/27 16:24:17 | 00,000,000 | —D | C]
AVG -> %ProgramFiles%\AVG -> [2009/04/27 16:24:03 | 00,000,000 | —D | C]
avg8 -> %AllUsersProfile%\Application Data\avg8 -> [2009/04/27 16:24:02 | 00,000,000 | —D | C]
The Effects of Pressure on the Wound Healing.ppt -> %UserProfile%\Desktop\The Effects of Pressure on the Wound Healing.ppt -> [2009/04/27 16:21:35 | 00,034,304 | —- | C] ()
WindowsXP-KB936929-SP3-x86-ENU.exe -> %UserProfile%\Desktop\WindowsXP-KB936929-SP3-x86-ENU.exe -> [2009/04/27 16:21:14 | 33,180,5736 | —- | C] (Microsoft Corporation)
RegistryEasy.exe -> %UserProfile%\My Documents\RegistryEasy.exe -> [2009/04/27 15:53:33 | 03,208,448 | —- | C] (RegistryEasy, Inc. )
SvchostFixWizard.exe -> %UserProfile%\My Documents\SvchostFixWizard.exe -> [2009/04/27 15:53:33 | 00,973,882 | —- | C] (Security Stronghold )
Schedule Task Weekly.job -> %SystemRoot%\tasks\Schedule Task Weekly.job -> [2009/04/27 15:45:03 | 00,000,394 | —- | C] ()
Registry Easy -> %ProgramFiles%\Registry Easy -> [2009/04/27 15:44:56 | 00,000,000 | —D | C]
RegistryEasy.exe -> %UserProfile%\Desktop\RegistryEasy.exe -> [2009/04/27 15:44:35 | 03,208,448 | —- | C] (RegistryEasy, Inc. )
winhelp.GID -> %SystemRoot%\System32\winhelp.GID -> [2009/04/25 20:59:44 | 00,008,628 | -H– | C] ()
Help -> %UserProfile%\Local Settings\Application Data\Help -> [2009/04/25 20:59:44 | 00,000,000 | —D | C]
Help -> %AppData%\Help -> [2009/04/25 20:59:44 | 00,000,000 | —D | C]
Graphing Calculator -> %UserProfile%\Desktop\Graphing Calculator -> [2009/04/16 23:11:01 | 00,000,000 | —D | C]
rpcnetp.dll -> %SystemRoot%\System32\rpcnetp.dll -> [2009/03/29 18:49:40 | 00,017,408 | —- | C] ()
TDSSnlum.dll -> %SystemRoot%\System32\TDSSnlum.dll -> [2009/01/20 15:44:21 | 00,002,204 | —- | C] ()
45439F8962.sys -> %SystemRoot%\System32\45439F8962.sys -> [2008/07/13 00:47:53 | 00,000,088 | RHS- | C] ()
62899F4345.sys -> %SystemRoot%\System32\62899F4345.sys -> [2008/06/09 21:28:20 | 00,000,104 | RHS- | C] ()
dlcxvs.dll -> %SystemRoot%\System32\dlcxvs.dll -> [2008/06/09 00:27:26 | 00,040,960 | —- | C] ()
dlcxcoin.dll -> %SystemRoot%\System32\dlcxcoin.dll -> [2008/06/09 00:27:17 | 00,331,776 | —- | C] ()
dlcxdrs.dll -> %SystemRoot%\System32\dlcxdrs.dll -> [2008/06/09 00:26:07 | 00,692,224 | —- | C] ()
dlcxcaps.dll -> %SystemRoot%\System32\dlcxcaps.dll -> [2008/06/09 00:26:07 | 00,065,536 | —- | C] ()
dlcxcnv4.dll -> %SystemRoot%\System32\dlcxcnv4.dll -> [2008/06/09 00:26:06 | 00,061,440 | —- | C] ()
dlcxinst.dll -> %SystemRoot%\System32\dlcxinst.dll -> [2008/06/09 00:15:59 | 00,389,120 | —- | C] ()
dlcxinpa.dll -> %SystemRoot%\System32\dlcxinpa.dll -> [2008/06/09 00:15:58 | 00,413,696 | —- | C] ( )
dlcxiesc.dll -> %SystemRoot%\System32\dlcxiesc.dll -> [2008/06/09 00:15:58 | 00,393,216 | —- | C] ( )
dlcxusb1.dll -> %SystemRoot%\System32\dlcxusb1.dll -> [2008/06/09 00:15:57 | 00,983,040 | —- | C] ( )
dlcxutil.dll -> %SystemRoot%\System32\dlcxutil.dll -> [2008/06/09 00:15:57 | 00,450,560 | —- | C] ()
dlcxserv.dll -> %SystemRoot%\System32\dlcxserv.dll -> [2008/06/09 00:15:56 | 01,187,840 | —- | C] ( )
dlcxprox.dll -> %SystemRoot%\System32\dlcxprox.dll -> [2008/06/09 00:15:56 | 00,163,840 | —- | C] ( )
dlcxpplc.dll -> %SystemRoot%\System32\dlcxpplc.dll -> [2008/06/09 00:15:56 | 00,114,688 | —- | C] ( )
dlcxpmui.dll -> %SystemRoot%\System32\dlcxpmui.dll -> [2008/06/09 00:15:55 | 00,651,264 | —- | C] ( )
dlcxlmpm.dll -> %SystemRoot%\System32\dlcxlmpm.dll -> [2008/06/09 00:15:55 | 00,532,480 | —- | C] ( )
dlcxinsb.dll -> %SystemRoot%\System32\dlcxinsb.dll -> [2008/06/09 00:15:54 | 00,176,128 | —- | C] ()
dlcxins.dll -> %SystemRoot%\System32\dlcxins.dll -> [2008/06/09 00:15:54 | 00,167,936 | —- | C] ()
dlcxjswr.dll -> %SystemRoot%\System32\dlcxjswr.dll -> [2008/06/09 00:15:54 | 00,135,168 | —- | C] ()
dlcxinsr.dll -> %SystemRoot%\System32\dlcxinsr.dll -> [2008/06/09 00:15:54 | 00,106,496 | —- | C] ()
dlcxhbn3.dll -> %SystemRoot%\System32\dlcxhbn3.dll -> [2008/06/09 00:15:53 | 00,688,128 | —- | C] ( )
dlcxgrd.dll -> %SystemRoot%\System32\dlcxgrd.dll -> [2008/06/09 00:15:53 | 00,188,416 | —- | C] ()
dlcxcub.dll -> %SystemRoot%\System32\dlcxcub.dll -> [2008/06/09 00:15:52 | 00,086,016 | —- | C] ()
dlcxcomc.dll -> %SystemRoot%\System32\dlcxcomc.dll -> [2008/06/09 00:15:51 | 00,610,304 | —- | C] ( )
dlcxcomm.dll -> %SystemRoot%\System32\dlcxcomm.dll -> [2008/06/09 00:15:51 | 00,421,888 | —- | C] ( )
dlcxcu.dll -> %SystemRoot%\System32\dlcxcu.dll -> [2008/06/09 00:15:51 | 00,073,728 | —- | C] ()
dlcxcur.dll -> %SystemRoot%\System32\dlcxcur.dll -> [2008/06/09 00:15:51 | 00,036,864 | —- | C] ()
DLCXcfg.dll -> %SystemRoot%\System32\DLCXcfg.dll -> [2008/06/09 00:15:50 | 00,073,728 | —- | C] ()
0CB5F02B6E.sys -> %SystemRoot%\System32\0CB5F02B6E.sys -> [2008/03/25 12:11:12 | 00,000,168 | RHS- | C] ()
KGyGaAvL.sys -> %SystemRoot%\System32\KGyGaAvL.sys -> [2008/03/25 11:46:25 | 00,008,510 | -HS- | C] ()
smscfg.ini -> %SystemRoot%\smscfg.ini -> [2008/03/21 17:01:22 | 00,000,061 | —- | C] ()
wininit.ini -> %SystemRoot%\wininit.ini -> [2008/03/21 16:51:05 | 00,000,120 | —- | C] ()
msoffice.ini -> %SystemRoot%\msoffice.ini -> [2008/03/21 16:45:25 | 00,000,002 | —- | C] ()
preflib.dll -> %SystemRoot%\System32\preflib.dll -> [2008/03/21 16:40:26 | 00,086,016 | —- | C] ()
bcm1xsup.dll -> %SystemRoot%\System32\bcm1xsup.dll -> [2008/03/21 16:40:25 | 00,757,760 | —- | C] ()
OEMINFO.INI -> %SystemRoot%\System32\OEMINFO.INI -> [2008/03/20 20:13:12 | 00,001,120 | —- | C] ()
CddbPlaylist2Roxio.dll -> %SystemRoot%\System32\CddbPlaylist2Roxio.dll -> [2006/09/17 00:36:50 | 00,520,192 | —- | C] ()
CddbFileTaggerRoxio.dll -> %SystemRoot%\System32\CddbFileTaggerRoxio.dll -> [2006/09/17 00:36:50 | 00,204,800 | —- | C] ()
fxsperf.ini -> %SystemRoot%\System32\fxsperf.ini -> [2005/08/16 06:37:24 | 00,001,793 | —- | C] ()
win.ini -> %SystemRoot%\win.ini -> [2005/08/16 06:18:43 | 00,000,528 | —- | C] ()
system.ini -> %SystemRoot%\system.ini -> [2005/08/16 06:18:41 | 00,000,231 | —- | C] ()
psisdecd.dll -> %SystemRoot%\System32\psisdecd.dll -> [2005/08/05 16:01:54 | 00,235,008 | —- | C] ()
[Files/Folders - Modified Within 30 Days]
4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
1 C:\Documents and Settings\Kevin\Desktop\*.tmp files -> C:\Documents and Settings\Kevin\Desktop\*.tmp ->
53 C:\Documents and Settings\Kevin\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Kevin\Local Settings\Temp\*.tmp ->
53 C:\Documents and Settings\Kevin\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Kevin\Local Settings\Temp\*.tmp ->
8 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp ->
wklnhst.dat -> %AppData%\wklnhst.dat -> [2009/05/12 00:06:59 | 00,020,498 | —- | M] ()
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2009/05/11 18:47:04 | 00,000,006 | -H– | M] ()
Perflib_Perfdata_e0c.dat -> %SystemRoot%\Temp\Perflib_Perfdata_e0c.dat -> [2009/05/11 18:45:28 | 00,016,384 | —- | M] ()
iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2009/05/11 18:43:32 | 00,002,137 | —- | M] ()
wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2009/05/11 18:42:53 | 00,002,206 | —- | M] ()
bootstat.dat -> %SystemRoot%\bootstat.dat -> [2009/05/11 18:42:52 | 00,002,048 | –S- | M] ()
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2009/05/11 18:42:47 | 93,747,2000 | -HS- | M] ()
Perflib_Perfdata_cf8.dat -> %SystemRoot%\Temp\Perflib_Perfdata_cf8.dat -> [2009/05/09 16:32:25 | 00,016,384 | —- | M] ()
rpcnetp.dll -> %SystemRoot%\System32\rpcnetp.dll -> [2009/05/09 16:32:24 | 00,017,408 | —- | M] ()
rpcnetp.exe -> %SystemRoot%\System32\rpcnetp.exe -> [2009/05/09 16:29:27 | 00,017,408 | —- | M] ()
Perflib_Perfdata_d8c.dat -> %SystemRoot%\Temp\Perflib_Perfdata_d8c.dat -> [2009/05/09 00:06:57 | 00,016,384 | —- | M] ()
Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/05/07 22:09:40 | 00,000,696 | —- | M] ()
Perflib_Perfdata_ce0.dat -> %SystemRoot%\Temp\Perflib_Perfdata_ce0.dat -> [2009/05/07 21:56:20 | 00,016,384 | —- | M] ()
mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> [2009/05/06 21:21:20 | 02,967,800 | —- | M] (Malwarebytes Corporation )
NTUSER.DAT -> %UserProfile%\NTUSER.DAT -> [2009/05/06 16:40:49 | 06,029,312 | —- | M] ()
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2009/05/06 15:39:20 | 03,772,432 | -H– | M] ()
sqmdata03.sqm -> %SystemDrive%\sqmdata03.sqm -> [2009/05/06 15:39:16 | 00,000,268 | -H– | M] ()
sqmnoopt03.sqm -> %SystemDrive%\sqmnoopt03.sqm -> [2009/05/06 15:39:16 | 00,000,244 | -H– | M] ()
QuickTime Player.lnk -> %AllUsersProfile%\Desktop\QuickTime Player.lnk -> [2009/05/06 15:36:31 | 00,001,604 | —- | M] ()
HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [2009/05/06 00:33:34 | 00,001,734 | —- | M] ()
Kevin000000.ERR -> %SystemDrive%\Kevin000000.ERR -> [2009/05/02 23:21:54 | 00,010,700 | —- | M] ()
ntuser.ini -> %UserProfile%\ntuser.ini -> [2009/04/27 22:48:11 | 00,000,178 | -HS- | M] ()
Schedule Task Weekly.job -> %SystemRoot%\tasks\Schedule Task Weekly.job -> [2009/04/27 19:02:25 | 00,000,394 | —- | M] ()
Ahmbed.gz -> %UserProfile%\Ahmbed.gz -> [2009/04/27 16:54:29 | 00,005,742 | —- | M] ()
avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2009/04/27 16:24:34 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.)
AVG Free 8.5.lnk -> %AllUsersProfile%\Desktop\AVG Free 8.5.lnk -> [2009/04/27 16:24:34 | 00,001,507 | —- | M] ()
avgtdix.sys -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2009/04/27 16:24:32 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.)
avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2009/04/27 16:24:23 | 00,325,640 | —- | M] (AVG Technologies CZ, s.r.o.)
incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2009/04/27 16:24:21 | 34,395,507 | —- | M] ()
avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2009/04/27 16:24:21 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.)
avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [2009/04/27 16:24:17 | 06,061,540 | —- | M] ()
miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [2009/04/27 16:24:17 | 00,401,372 | —- | M] ()
microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2009/04/27 16:24:17 | 00,057,798 | —- | M] ()
opa12.dat -> %AllUsersProfile%\Application Data\Microsoft\OFFICE\DATA\opa12.dat -> [2009/04/27 16:23:01 | 00,008,468 | —- | M] ()
WindowsXP-KB936929-SP3-x86-ENU.exe -> %UserProfile%\Desktop\WindowsXP-KB936929-SP3-x86-ENU.exe -> [2009/04/27 16:17:44 | 33,180,5736 | —- | M] (Microsoft Corporation)
RegistryEasy.exe -> %UserProfile%\My Documents\RegistryEasy.exe -> [2009/04/27 15:44:24 | 03,208,448 | —- | M] (RegistryEasy, Inc. )
RegistryEasy.exe -> %UserProfile%\Desktop\RegistryEasy.exe -> [2009/04/27 15:44:24 | 03,208,448 | —- | M] (RegistryEasy, Inc. )
SvchostFixWizard.exe -> %UserProfile%\My Documents\SvchostFixWizard.exe -> [2009/04/27 15:35:20 | 00,973,882 | —- | M] (Security Stronghold )
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2009/04/26 19:07:46 | 02,311,136 | —- | M] ()
imsins.BAK -> %SystemRoot%\imsins.BAK -> [2009/04/25 21:18:42 | 00,001,917 | —- | M] ()
winhelp.GID -> %SystemRoot%\System32\winhelp.GID -> [2009/04/25 20:59:49 | 00,008,628 | -H– | M] ()
qmgr1.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2009/04/25 20:36:24 | 00,004,232 | —- | M] ()
The Effects of Pressure on the Wound Healing.ppt -> %UserProfile%\Desktop\The Effects of Pressure on the Wound Healing.ppt -> [2009/04/21 14:01:18 | 00,034,304 | —- | M] ()
qmgr0.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2009/04/03 16:09:03 | 00,004,617 | —- | M] ()
7Z.DLL -> %UserProfile%\Local Settings\Temp\_PASFX615\7Z.DLL -> [2009/01/31 02:19:22 | 00,076,800 | —- | M] (Igor Pavlov)
7Z.DLL -> %UserProfile%\Local Settings\Temp\_PASFX58\7Z.DLL -> [2008/08/25 23:10:26 | 00,076,288 | —- | M] ()
wklntsk1.dat -> %AllUsersProfile%\Application Data\Microsoft\Works\wklntsk1.dat -> [2008/03/25 23:26:39 | 00,162,475 | —- | M] ()
wkcalcat.dat -> %AllUsersProfile%\Application Data\Microsoft\Works\wkcalcat.dat -> [2008/03/25 21:55:10 | 00,016,384 | —- | M] ()
uninst.dll -> %UserProfile%\Local Settings\Temp\uninst.dll -> [2004/09/01 11:56:56 | 00,114,688 | —- | M] ()
TFR97.exe -> %UserProfile%\Local Settings\Temp\TFR97.exe -> [2004/01/20 17:44:42 | 00,132,608 | —- | M] (Microsoft Corp.)
[File - Lop Check]
Application Data -> C:\Documents and Settings\Administrator\Application Data -> [2008/03/21 17:00:54 | 00,000,000 | RH-D | M]
ATI -> C:\Documents and Settings\Administrator\Application Data\ATI -> [2008/03/21 16:46:56 | 00,000,000 | —D | M]
Roxio -> C:\Documents and Settings\Administrator\Application Data\Roxio -> [2008/03/21 17:00:54 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\All Users\Application Data -> [2009/05/06 21:45:19 | 00,000,000 | RH-D | M]
{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> [2009/05/06 15:38:02 | 00,000,000 | —D | M]
acccore -> C:\Documents and Settings\All Users\Application Data\acccore -> [2008/08/03 02:29:26 | 00,000,000 | —D | M]
Azureus -> C:\Documents and Settings\All Users\Application Data\Azureus -> [2009/02/18 18:41:03 | 00,000,000 | —D | M]
Corel -> C:\Documents and Settings\All Users\Application Data\Corel -> [2008/03/25 12:02:28 | 00,000,000 | —D | M]
Dell -> C:\Documents and Settings\All Users\Application Data\Dell -> [2008/03/22 19:05:18 | 00,000,000 | —D | M]
DellFaxCtr -> C:\Documents and Settings\All Users\Application Data\DellFaxCtr -> [2008/06/09 00:16:47 | 00,000,000 | —D | M]
FLEXnet -> C:\Documents and Settings\All Users\Application Data\FLEXnet -> [2008/08/26 00:45:10 | 00,000,000 | —D | M]
Roxio -> C:\Documents and Settings\All Users\Application Data\Roxio -> [2008/10/18 12:47:53 | 00,000,000 | —D | M]
Sony -> C:\Documents and Settings\All Users\Application Data\Sony -> [2008/12/27 18:11:16 | 00,000,000 | —D | M]
Viewpoint -> C:\Documents and Settings\All Users\Application Data\Viewpoint -> [2009/01/03 20:45:11 | 00,000,000 | —D | M]
YAHOO -> C:\Documents and Settings\All Users\Application Data\YAHOO -> [2008/03/21 16:49:10 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\Default User\Application Data -> [2008/03/21 17:00:54 | 00,000,000 | RH-D | M]
ATI -> C:\Documents and Settings\Default User\Application Data\ATI -> [2008/03/21 16:46:56 | 00,000,000 | —D | M]
Roxio -> C:\Documents and Settings\Default User\Application Data\Roxio -> [2008/03/21 17:00:54 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\Kevin\Application Data -> [2009/05/12 00:06:59 | 00,000,000 | -H-D | M]
acccore -> C:\Documents and Settings\Kevin\Application Data\acccore -> [2008/05/24 03:17:20 | 00,000,000 | —D | M]
ATI -> C:\Documents and Settings\Kevin\Application Data\ATI -> [2008/03/21 16:46:56 | 00,000,000 | —D | M]
Azureus -> C:\Documents and Settings\Kevin\Application Data\Azureus -> [2009/03/18 15:53:39 | 00,000,000 | —D | M]
Corel -> C:\Documents and Settings\Kevin\Application Data\Corel -> [2008/07/14 00:07:27 | 00,000,000 | —D | M]
Corel Photo Album -> C:\Documents and Settings\Kevin\Application Data\Corel Photo Album -> [2008/06/10 17:09:38 | 00,000,000 | —D | M]
CyberLink -> C:\Documents and Settings\Kevin\Application Data\CyberLink -> [2008/03/21 16:38:05 | 00,000,000 | —D | M]
DellFaxCtr -> C:\Documents and Settings\Kevin\Application Data\DellFaxCtr -> [2008/06/09 20:02:06 | 00,000,000 | —D | M]
Download Manager -> C:\Documents and Settings\Kevin\Application Data\Download Manager -> [2009/02/21 01:52:34 | 00,000,000 | —D | M]
GetRightToGo -> C:\Documents and Settings\Kevin\Application Data\GetRightToGo -> [2009/01/15 19:06:18 | 00,000,000 | —D | M]
LimeWire -> C:\Documents and Settings\Kevin\Application Data\LimeWire -> [2008/12/23 15:12:22 | 00,000,000 | —D | M]
MSNInstaller -> C:\Documents and Settings\Kevin\Application Data\MSNInstaller -> [2008/04/24 16:21:43 | 00,000,000 | —D | M]
Roxio -> C:\Documents and Settings\Kevin\Application Data\Roxio -> [2008/03/21 17:21:59 | 00,000,000 | —D | M]
SoundSpectrum -> C:\Documents and Settings\Kevin\Application Data\SoundSpectrum -> [2008/05/26 22:57:47 | 00,000,000 | —D | M]
Template -> C:\Documents and Settings\Kevin\Application Data\Template -> [2008/03/25 21:55:03 | 00,000,000 | —D | M]
U3 -> C:\Documents and Settings\Kevin\Application Data\U3 -> [2009/02/22 22:37:32 | 00,000,000 | —D | M]
Viewpoint -> C:\Documents and Settings\Kevin\Application Data\Viewpoint -> [2008/04/05 22:02:23 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\LocalService\Application Data -> [2008/03/21 17:01:05 | 00,000,000 | —D | M]
Roxio -> C:\Documents and Settings\LocalService\Application Data\Roxio -> [2008/03/21 17:01:05 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\NetworkService\Application Data -> [2005/08/16 06:49:40 | 00,000,000 | —D | M]
C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2009/04/27 15:45:03 | 00,000,000 | –SD | M]
AppleSoftwareUpdate.job -> C:\WINDOWS\Tasks\AppleSoftwareUpdate.job -> [2009/04/03 09:28:02 | 00,000,284 | —- | M] ()
desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2004/08/10 07:00:00 | 00,000,065 | RH– | M] ()
SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2009/05/11 18:47:04 | 00,000,006 | -H– | M] ()
Schedule Task Weekly.job -> C:\WINDOWS\Tasks\Schedule Task Weekly.job -> [2009/04/27 19:02:25 | 00,000,394 | —- | M] ()
[File - Purity Scan]
[Alternate Data Streams]
@Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
< End of report >
whats next?