This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] svchost.exe - Application Error

51 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
Im usually really good at computers but im having this problems i cant fix.

im using a dell laptop, inspiron 1501, Windows XP
and about a month ago this "error" kept appear:

svchost.exe - Application Error
The instructions at "0x75606e6a" referenced memory at "0x00000008". The memory could not be "read".
Click on OK to terminate the program

im unable to connect to the internet or have any wireless connectivity, the dell wireless card states that i CAN
connect to my wireless router but it can not get the address.
i tried system restore but it wont do it, my sound doesnt work, media player has been acting weird, and my display
keeps changing to the old style of windows XP.

i already tried using avg and its clean, i have also used ATF-Cleaner and deleted everything that was found, and
i have also tried to use Malware bytes' anut-malware, but my computer doesnt want to open it.

my HJT log is as followed:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:29:35 PM, on 5/12/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\WINDOWS\stsystra.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\AIM6\aolsoftware.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p…IEGetPlugin.ocx
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1206151895937
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWire…loadControl.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1585FBE0-752E-4197-8232-7556E48D91B2}: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CS1\Services\Tcpip\..\{1585FBE0-752E-4197-8232-7556E48D91B2}: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CS2\Services\Tcpip\..\{1585FBE0-752E-4197-8232-7556E48D91B2}: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CS3\Services\Tcpip\..\{1585FBE0-752E-4197-8232-7556E48D91B2}: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.135,85.255.112.198
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcx_device - - C:\WINDOWS\system32\dlcxcoms.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 11842 bytes



thank you
Hi lets see if we can resolve this problem. First it appears that you may have two antivirus programmes Trend Micro and AVG

Anti-Virus programs take up an enormous amount of your computer's resources when they are actively scanning your computer. Having two anti-virus programs running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash.

If you choose to install more than one Anti-Virus program on your computer, then only one of them should be active in memory at a time.

There are basically two types of these programs:
On-Access and On-Demand

On-Access Scanners
As the name implies, are scanners that run in the background all the time the PC is turned on and running. The main function of an On-Access scanner is to monitor activity on your machine.

On-Demand Scanners
As the name implies, are scanners that only run when you ask them to.
Such as:
Online Scans and scanners that run on your machine but are not actively scanning your machine

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O17 - HKLM\System\CCS\Services\Tcpip\..\{1585FBE0-752E-4197-8232-7556E48D91B2}: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CS1\Services\Tcpip\..\{1585FBE0-752E-4197-8232-7556E48D91B2}: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CS2\Services\Tcpip\..\{1585FBE0-752E-4197-8232-7556E48D91B2}: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CS3\Services\Tcpip\..\{1585FBE0-752E-4197-8232-7556E48D91B2}: NameServer = 85.255.112.135,85.255.112.198
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.135,85.255.112.198

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.

THEN

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTScanit2 to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanit folder and double-click on OTScanit.exe to start the program.
  • Check the box that says Scan All Users
  • Check the Radio button for Rootkit check YES
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EventViewer Errors/Warnings (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
im not able to find the box that says radio something in OTScanIt, i did the scan without it and the log is as followed.

OTScanIt2 logfile created on: 5/12/2009 6:52:58 PM - Run 1
OTScanIt2 by OldTimer - Version 1.0.14.0	 Folder = C:\Documents and Settings\Kevin\Desktop\OTScanIt2
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
893.98 Mb Total Physical Memory | 328.92 Mb Available Physical Memory | 36.79% Memory free
2.12 Gb Paging File | 1.52 Gb Available in Paging File | 72.06% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.11 Gb Total Space | 34.47 Gb Free Space | 49.88% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 955.72 Mb Total Space | 877.38 Mb Free Space | 91.80% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: KEVIN
Current User Name: Kevin
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
 
[Processes - Safe List]
aim6.exe -> %ProgramFiles%\AIM6\aim6.exe -> [2008/10/17 10:45:06 | 00,049,960 | —- | M] (AOL LLC)
aolsoftware.exe -> %ProgramFiles%\AIM6\aolsoftware.exe -> [2008/05/02 13:25:42 | 00,041,824 | —- | M] (AOL LLC)
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/03/26 15:31:20 | 00,132,424 | —- | M] (Apple Inc.)
ati2evxx.exe -> %SystemRoot%\system32\Ati2evxx.exe -> [2007/10/16 23:16:12 | 00,430,080 | —- | M] (ATI Technologies Inc.)
ati2evxx.exe -> %SystemRoot%\system32\Ati2evxx.exe -> [2007/10/16 23:16:12 | 00,430,080 | —- | M] (ATI Technologies Inc.)
avgnsx.exe -> %ProgramFiles%\AVG\AVG8\avgnsx.exe -> [2009/04/27 16:24:05 | 00,594,200 | —- | M] (AVG Technologies CZ, s.r.o.)
avgrsx.exe -> %ProgramFiles%\AVG\AVG8\avgrsx.exe -> [2009/04/27 16:24:05 | 00,485,144 | —- | M] (AVG Technologies CZ, s.r.o.)
avgtray.exe -> %ProgramFiles%\AVG\AVG8\avgtray.exe -> [2009/04/27 16:24:04 | 01,932,568 | —- | M] (AVG Technologies CZ, s.r.o.)
avgwdsvc.exe -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2009/04/27 16:24:03 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.)
bcmwltry.exe -> %SystemRoot%\System32\bcmwltry.exe -> [2007/05/09 23:59:38 | 01,253,376 | —- | M] (Dell Inc.)
cpshelprunner.exe -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe -> [2006/11/05 11:55:48 | 00,010,752 | —- | M] (Sonic Solutions)
dlcxcoms.exe -> %SystemRoot%\system32\dlcxcoms.exe -> [2006/05/18 16:36:10 | 00,495,616 | —- | M] ( )
dlcxmon.exe -> %ProgramFiles%\Dell Photo AIO Printer 926\dlcxmon.exe -> [2006/06/14 08:51:38 | 00,286,720 | —- | M] ()
dlg.exe -> %ProgramFiles%\Digital Line Detect\DLG.exe -> [2003/10/29 03:06:00 | 00,024,576 | —- | M] (BVRP Software)
dsagnt.exe -> %ProgramFiles%\Dell Support\DSAgnt.exe -> [2006/08/28 22:57:12 | 00,395,776 | —- | M] (Gteko Ltd.)
dvdlauncher.exe -> %ProgramFiles%\CyberLink\PowerDVD\DVDLauncher.exe -> [2005/12/09 21:29:52 | 00,049,152 | —- | M] (CyberLink Corp.)
ehmsas.exe -> %SystemRoot%\eHome\ehmsas.exe -> [2005/08/05 15:56:28 | 00,046,592 | —- | M] (Microsoft Corporation)
ehrecvr.exe -> %SystemRoot%\eHome\ehRecvr.exe -> [2006/10/09 16:16:56 | 00,237,568 | —- | M] (Microsoft Corporation)
ehsched.exe -> %SystemRoot%\eHome\ehSched.exe -> [2005/08/05 15:56:32 | 00,102,912 | —- | M] (Microsoft Corporation)
ehtray.exe -> %SystemRoot%\ehome\ehtray.exe -> [2005/09/29 15:01:14 | 00,067,584 | —- | M] (Microsoft Corporation)
explorer.exe -> %SystemRoot%\Explorer.EXE -> [2007/06/13 06:23:07 | 01,033,216 | —- | M] (Microsoft Corporation)
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2009/04/02 16:10:56 | 00,656,168 | —- | M] (Apple Inc.)
issch.exe -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe -> [2005/06/10 10:44:02 | 00,081,920 | —- | M] (InstallShield Software Corporation)
isuspm.exe -> %CommonProgramFiles%\installshield\updateservice\isuspm.exe -> [2005/06/10 10:44:02 | 00,249,856 | —- | M] (InstallShield Software Corporation)
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> [2009/04/02 16:11:02 | 00,342,312 | —- | M] (Apple Inc.)
mcrdsvc.exe -> %SystemRoot%\ehome\mcrdsvc.exe -> [2005/08/05 15:27:08 | 00,099,328 | —- | M] (Microsoft Corporation)
mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.)
memcard.exe -> %ProgramFiles%\Dell Photo AIO Printer 926\memcard.exe -> [2006/06/27 07:34:50 | 00,299,008 | —- | M] ()
msnmsgr.exe -> %ProgramFiles%\Windows Live\Messenger\MsnMsgr.Exe -> [2007/10/18 11:34:02 | 05,724,184 | —- | M] (Microsoft Corporation)
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2009/04/11 16:32:52 | 00,494,080 | —- | M] (OldTimer Tools)
pccguide.exe -> %ProgramFiles%\Trend Micro\Internet Security 14\pccguide.exe -> [2006/11/21 14:02:24 | 01,807,960 | —- | M] (Trend Micro Inc.)
pcctlcom.exe -> %ProgramFiles%\Trend Micro\Internet Security 14\PcCtlCom.exe -> [2008/05/19 16:17:14 | 01,475,936 | —- | M] (Trend Micro Inc.)
psiservice.exe -> %SystemRoot%\system32\PSIService.exe -> [2007/06/05 13:20:32 | 00,177,704 | —- | M] ()
quickset.exe -> %ProgramFiles%\Dell\QuickSet\quickset.exe -> [2007/02/20 13:29:08 | 01,191,936 | —- | M] (Dell Inc)
roxmediadb9.exe -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe -> [2006/11/05 12:15:12 | 00,880,640 | —- | M] (Sonic Solutions)
roxwatch9.exe -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe -> [2006/11/05 12:13:00 | 00,159,744 | —- | M] (Sonic Solutions)
roxwatchtray9.exe -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe -> [2006/11/05 12:22:16 | 00,221,184 | —- | M] (Sonic Solutions)
snmp.exe -> %SystemRoot%\System32\snmp.exe -> [2004/08/10 07:00:00 | 00,032,768 | —- | M] (Microsoft Corporation)
stsystra.exe -> %SystemRoot%\stsystra.exe -> [2006/09/22 13:06:26 | 00,282,624 | —- | M] (SigmaTel, Inc.)
syntpenh.exe -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe -> [2006/09/22 13:47:54 | 00,761,947 | —- | M] (Synaptics, Inc.)
tcpsvcs.exe -> %SystemRoot%\system32\tcpsvcs.exe -> [2004/08/10 07:00:00 | 00,019,456 | —- | M] (Microsoft Corporation)
tmas_oemon.exe -> %ProgramFiles%\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe -> [2006/08/04 17:15:28 | 00,321,040 | —- | M] (Trend Micro Inc.)
tmntsrv.exe -> %ProgramFiles%\Trend Micro\Internet Security 14\Tmntsrv.exe -> [2007/11/09 04:19:18 | 00,345,696 | —- | M] (Trend Micro Inc.)
tmpfw.exe -> %ProgramFiles%\Trend Micro\Internet Security 14\TmPfw.exe -> [2006/11/09 16:03:42 | 00,923,216 | —- | M] (Trend Micro Inc.)
tmproxy.exe -> %ProgramFiles%\Trend Micro\Internet Security 14\tmproxy.exe -> [2006/11/09 16:04:02 | 00,566,872 | —- | M] (Trend Micro Inc.)
viewpointservice.exe -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 17:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation)
wltray.exe -> %SystemRoot%\system32\WLTRAY.exe -> [2007/05/09 23:59:46 | 01,392,640 | —- | M] (Dell Inc.)
wltrysvc.exe -> %SystemRoot%\System32\WLTRYSVC.EXE -> [2007/05/09 23:59:48 | 00,020,480 | —- | M] ()
wscntfy.exe -> %SystemRoot%\system32\wscntfy.exe -> [2004/08/10 07:00:00 | 00,013,824 | —- | M] (Microsoft Corporation)
 
[Win32 Services - Safe List]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/03/26 15:31:20 | 00,132,424 | —- | M] (Apple Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe -> [2004/07/15 03:49:26 | 00,032,768 | —- | M] (Microsoft Corporation)
(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> %SystemRoot%\system32\Ati2evxx.exe -> [2007/10/16 23:16:12 | 00,430,080 | —- | M] (ATI Technologies Inc.)
(avg8wd) AVG Free8 WatchDog [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2009/04/27 16:24:03 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.)
(dlcx_device) dlcx_device [Win32_Own | On_Demand | Running] -> %SystemRoot%\system32\dlcxcoms.exe -> [2006/05/18 16:36:10 | 00,495,616 | —- | M] ( )
(ehRecvr) Media Center Receiver Service [Win32_Own | Auto | Running] -> %SystemRoot%\eHome\ehRecvr.exe -> [2006/10/09 16:16:56 | 00,237,568 | —- | M] (Microsoft Corporation)
(ehSched) Media Center Scheduler Service [Win32_Own | Auto | Running] -> %SystemRoot%\eHome\ehSched.exe -> [2005/08/05 15:56:32 | 00,102,912 | —- | M] (Microsoft Corporation)
(FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> [2008/08/26 00:13:22 | 00,654,848 | —- | M] (Macrovision Europe Ltd.)
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2009/01/04 02:34:21 | 00,138,168 | —- | M] (Google)
(helpsvc) Help and Support [Win32_Shared | Auto | Stopped] -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2004/08/10 07:00:00 | 00,038,912 | —- | M] (Microsoft Corporation)
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\1050\Intel 32\IDriverT.exe -> [2004/10/22 04:24:18 | 00,073,728 | —- | M] (Macrovision Corporation)
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2009/04/02 16:10:56 | 00,656,168 | —- | M] (Apple Inc.)
(McrdSvc) Media Center Extender Service [Win32_Own | Auto | Running] -> %SystemRoot%\ehome\mcrdsvc.exe -> [2005/08/05 15:27:08 | 00,099,328 | —- | M] (Microsoft Corporation)
(MHN) MHN [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\System32\mhn.dll -> [2004/08/10 06:11:50 | 00,085,504 | —- | M] (Microsoft Corporation)
(odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2007/08/24 04:19:12 | 00,443,776 | —- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2006/10/26 15:03:08 | 00,145,184 | —- | M] (Microsoft Corporation)
(PcCtlCom) Trend Micro Central Control Component [Win32_Own | Auto | Running] -> %ProgramFiles%\Trend Micro\Internet Security 14\PcCtlCom.exe -> [2008/05/19 16:17:14 | 01,475,936 | —- | M] (Trend Micro Inc.)
(ProtexisLicensing) ProtexisLicensing [Win32_Own | Auto | Running] -> %SystemRoot%\system32\PSIService.exe -> [2007/06/05 13:20:32 | 00,177,704 | —- | M] ()
(RoxMediaDB9) RoxMediaDB9 [Win32_Own | On_Demand | Running] -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe -> [2006/11/05 12:15:12 | 00,880,640 | —- | M] (Sonic Solutions)
(RoxWatch9) Roxio Hard Drive Watcher 9 [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe -> [2006/11/05 12:13:00 | 00,159,744 | —- | M] (Sonic Solutions)
(SimpTcp) Simple TCP/IP Services [Win32_Shared | Auto | Running] -> %SystemRoot%\system32\tcpsvcs.exe -> [2004/08/10 07:00:00 | 00,019,456 | —- | M] (Microsoft Corporation)
(SNMP) SNMP Service [Win32_Own | Auto | Running] -> %SystemRoot%\System32\snmp.exe -> [2004/08/10 07:00:00 | 00,032,768 | —- | M] (Microsoft Corporation)
(stllssvr) stllssvr [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\SureThing Shared\stllssvr.exe -> [2006/09/14 15:54:34 | 00,073,728 | —- | M] (MicroVision Development, Inc.)
(Tmntsrv) Trend Micro Real-time Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Trend Micro\Internet Security 14\Tmntsrv.exe -> [2007/11/09 04:19:18 | 00,345,696 | —- | M] (Trend Micro Inc.)
(TmPfw) Trend Micro Personal Firewall [Win32_Own | Auto | Running] -> %ProgramFiles%\Trend Micro\Internet Security 14\TmPfw.exe -> [2006/11/09 16:03:42 | 00,923,216 | —- | M] (Trend Micro Inc.)
(tmproxy) Trend Micro Proxy Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Trend Micro\Internet Security 14\tmproxy.exe -> [2006/11/09 16:04:02 | 00,566,872 | —- | M] (Trend Micro Inc.)
(usnjsvc) Messenger Sharing Folders USN Journal Reader service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\Messenger\usnsvc.exe -> [2007/10/18 11:31:54 | 00,098,328 | —- | M] (Microsoft Corporation)
(Viewpoint Manager Service) Viewpoint Manager Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 17:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation)
(WLSetupSvc) Windows Live Setup Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Live\installer\WLSetupSvc.exe -> [2007/10/25 15:27:54 | 00,266,240 | —- | M] (Microsoft Corporation)
(wltrysvc) Dell Wireless WLAN Tray Service [Win32_Own | Auto | Running] -> %SystemRoot%\System32\WLTRYSVC.EXE -> [2007/05/09 23:59:48 | 00,020,480 | —- | M] ()
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Media Player\WMPNetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
 
[Driver Services - Safe List]
(AliIde) AliIde [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\aliide.sys -> [2001/08/17 15:51:56 | 00,005,248 | —- | M] (Acer Laboratories Inc.)
(amdagp) AMD AGP Bus Filter Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\amdagp.sys -> [2004/08/04 01:07:44 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.)
(AmdK8) AMD Processor Driver [Kernel | System | Running] -> %SystemRoot%\system32\DRIVERS\AmdK8.sys -> [2006/07/01 23:39:40 | 00,036,864 | —- | M] (Advanced Micro Devices)
(APPDRV) APPDRV [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\APPDRV.SYS -> [2005/08/12 17:50:46 | 00,016,128 | —- | M] (Dell Inc)
(asc) asc [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\asc.sys -> [2001/08/17 15:52:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.)
(asc3550) asc3550 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\asc3550.sys -> [2001/08/17 15:51:58 | 00,014,848 | —- | M] (Advanced System Products, Inc.)
(ASCTRM) ASCTRM [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\asctrm.sys -> [2008/03/21 16:55:40 | 00,008,552 | —- | M] (Windows (R) 2000 DDK provider)
(ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ati2mtag.sys -> [2007/10/16 23:16:14 | 01,777,152 | —- | M] (ATI Technologies Inc.)
(AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Running] -> %SystemRoot%\System32\Drivers\avgldx86.sys -> [2009/04/27 16:24:23 | 00,325,640 | —- | M] (AVG Technologies CZ, s.r.o.)
(AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> %SystemRoot%\System32\Drivers\avgmfx86.sys -> [2009/04/27 16:24:21 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.)
(AvgTdiX) AVG Free8 Network Redirector [Kernel | System | Running] -> %SystemRoot%\System32\Drivers\avgtdix.sys -> [2009/04/27 16:24:32 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.)
(BCM43XX) Dell Wireless WLAN Card Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\bcmwl5.sys -> [2007/05/09 23:59:42 | 00,604,928 | —- | M] (Broadcom Corporation)
(bcm4sbxp) Broadcom 440x 10/100 Integrated Controller XP Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\bcm4sbxp.sys -> [2006/08/17 15:55:16 | 00,044,544 | —- | M] (Broadcom Corporation)
(BVRPMPR5) BVRPMPR5 NDIS Protocol Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\BVRPMPR5.SYS -> [2007/07/12 13:58:54 | 00,049,904 | R— | M] (Avanquest Software)
(CmdIde) CmdIde [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\cmdide.sys -> [2001/08/17 15:51:54 | 00,006,656 | —- | M] (CMD Technology, Inc.)
(dac2w2k) dac2w2k [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\dac2w2k.sys -> [2001/08/17 15:52:16 | 00,179,584 | —- | M] (Mylex Corporation)
(DSproct) DSproct [Kernel | On_Demand | Running] -> %ProgramFiles%\Dell Support\GTAction\triggers\DSproct.sys -> [2006/01/10 12:07:58 | 00,004,864 | —- | M] (GTek Technologies Ltd.)
(E100B) Intel(R) PRO Adapter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\e100b325.sys -> [2001/08/17 14:12:10 | 00,117,760 | —- | M] (Intel Corporation)
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\GEARAspiWDM.sys -> [2009/03/19 16:32:48 | 00,023,400 | —- | M] (GEAR Software Inc.)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HDAudBus.sys -> [2004/08/12 18:45:54 | 00,137,728 | —- | M] (Windows (R) Server 2003 DDK provider)
(HSF_DPV) HSF_DPV [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSX_DPV.sys -> [2005/12/01 09:40:56 | 00,936,960 | —- | M] (Conexant Systems, Inc.)
(HSXHWAZL) HSXHWAZL [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSXHWAZL.sys -> [2005/12/01 09:40:12 | 00,192,512 | —- | M] (Conexant Systems, Inc.)
(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\mdmxsdk.sys -> [2005/10/05 06:57:08 | 00,012,544 | —- | M] (Conexant)
(mraid35x) mraid35x [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\mraid35x.sys -> [2001/08/17 15:52:12 | 00,017,280 | —- | M] (American Megatrends Inc.)
(nv) nv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\nv4_mini.sys -> [2004/08/04 00:29:56 | 01,897,408 | —- | M] (NVIDIA Corporation)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ptilink.sys -> [2004/08/10 07:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\System32\Drivers\PxHelp20.sys -> [2006/08/16 04:00:00 | 00,036,592 | —- | M] (Sonic Solutions)
(ql1080) ql1080 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\ql1080.sys -> [2001/08/17 15:52:20 | 00,040,320 | —- | M] (QLogic Corporation)
(ql12160) ql12160 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\ql12160.sys -> [2001/08/17 15:52:20 | 00,045,312 | —- | M] (QLogic Corporation)
(ql1280) ql1280 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\ql1280.sys -> [2001/08/17 15:52:18 | 00,049,024 | —- | M] (QLogic Corporation)
(rimmptsk) rimmptsk [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\rimmptsk.sys -> [2005/07/15 01:58:14 | 00,028,544 | —- | M] (REDC)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\secdrv.sys -> [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sisagp) SIS AGP Bus Filter [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\sisagp.sys -> [2004/08/04 01:07:44 | 00,041,088 | —- | M] (Silicon Integrated Systems Corporation)
(SONYPVU1) Sony USB Filter Driver (SONYPVU1) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\SONYPVU1.SYS -> [2001/08/17 13:56:16 | 00,007,552 | —- | M] (Sony Corporation)
(Sparrow) Sparrow [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\sparrow.sys -> [2001/08/17 16:07:44 | 00,019,072 | —- | M] (Adaptec, Inc.)
(STHDA) SigmaTel High Definition Audio CODEC [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\sthda.sys -> [2006/09/22 13:06:26 | 01,171,464 | —- | M] (SigmaTel, Inc.)
(symc810) symc810 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\symc810.sys -> [2001/08/17 16:07:34 | 00,016,256 | —- | M] (Symbios Logic Inc.)
(symc8xx) symc8xx [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\symc8xx.sys -> [2001/08/17 16:07:36 | 00,032,640 | —- | M] (LSI Logic)
(sym_hi) sym_hi [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\sym_hi.sys -> [2001/08/17 16:07:40 | 00,028,384 | —- | M] (LSI Logic)
(sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\sym_u3.sys -> [2001/08/17 16:07:42 | 00,030,688 | —- | M] (LSI Logic)
(SynTP) Synaptics TouchPad Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\SynTP.sys -> [2006/09/22 13:47:52 | 00,191,872 | —- | M] (Synaptics, Inc.)
(tmcfw) Trend Micro Common Firewall Service [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\TM_CFW.sys -> [2006/11/09 16:04:20 | 00,280,392 | —- | M] (Trend Micro Inc.)
(tmpreflt) tmpreflt [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\tmpreflt.sys -> [2008/11/26 18:42:40 | 00,036,368 | —- | M] (Trend Micro Inc.)
(tmtdi) Trend Micro TDI Driver [Kernel | System | Running] -> %SystemRoot%\system32\DRIVERS\tmtdi.sys -> [2006/11/09 16:04:20 | 00,073,288 | —- | M] (Trend Micro Inc.)
(tmxpflt) tmxpflt [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\TmXPFlt.sys -> [2008/11/26 18:42:42 | 00,205,328 | —- | M] (Trend Micro Inc.)
(ultra) ultra [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\ultra.sys -> [2001/08/17 15:52:22 | 00,036,736 | —- | M] (Promise Technology, Inc.)
(USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\usbaapl.sys -> [2009/03/26 15:23:46 | 00,036,864 | —- | M] (Apple, Inc.)
(usbbus) LGE CDMA Composite USB Device [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\lgusbbus.sys -> [2007/04/09 09:53:24 | 00,012,672 | —- | M] (LG Electronics Inc.)
(UsbDiag) LGE CDMA USB Serial Port [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\lgusbdiag.sys -> [2007/04/09 09:56:22 | 00,021,248 | —- | M] (LG Electronics Inc.)
(USBModem) LGE CDMA USB Modem [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\lgusbmodem.sys -> [2007/04/09 09:55:08 | 00,022,912 | —- | M] (LG Electronics Inc.)
(USB_RNDIS) USB Remote NDIS Network Device Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\usb8023.sys -> [2004/12/08 11:34:36 | 00,012,800 | —- | M] (Microsoft Corporation)
(vsapint) vsapint [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\vsapint.sys -> [2008/11/26 18:39:56 | 01,195,384 | —- | M] (Trend Micro Inc.)
(winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSX_CNXT.sys -> [2005/12/01 09:40:08 | 00,669,696 | —- | M] (Conexant Systems, Inc.)
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> Reg Error: Invalid data type. -> 
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Page_Transitions" -> Reg Error: Invalid data type. -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> 
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> 
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> 
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\] > -> -> 
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> 
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\: Main\\"Page_Transitions" -> Reg Error: Invalid data type. -> 
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\: Main\\"Start Page" -> http://www.myspace.com/ -> 
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\: "ProxyEnable" -> 0 -> 
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\: "ProxyOverride" -> *.local -> 
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\Kevin\Application Data\Mozilla\FireFox\Profiles\d2011s7p.default\prefs.js -> 
browser.startup.homepage -> "http://www.myspace.com/" ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
< FireFox Extensions [User Folders] > -> 
 -> C:\Documents and Settings\Kevin\Application Data\mozilla\Extensions -> [2009/03/18 15:53:09 | 00,000,000 | —D | M]
 -> C:\Documents and Settings\Kevin\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2009/03/18 15:53:09 | 00,000,000 | —D | M]
 -> C:\Documents and Settings\Kevin\Application Data\mozilla\Firefox\Profiles\d2011s7p.default\extensions -> [2009/02/22 19:08:19 | 00,096,270 | —- | M] ()
< HOSTS File > (29 bytes and 2 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
Reset Hosts
127.0.0.1	   localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/12/18 04:16:42 | 00,059,032 | —- | M] (Adobe Systems Incorporated)
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> %ProgramFiles%\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2009/04/27 16:24:07 | 01,078,552 | —- | M] (AVG Technologies CZ, s.r.o.)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\ssv.dll [SSVHelper Class] -> [2005/11/10 14:22:12 | 00,184,423 | —- | M] (Sun Microsystems, Inc.)
{7E853D72-626A-48EC-A868-BA8D5E23E045} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> %CommonProgramFiles%\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Windows Live Sign-in Helper] -> [2009/02/17 17:11:04 | 00,408,440 | —- | M] (Microsoft Corporation)
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\google\googletoolbar1.dll [Google Toolbar Helper] -> [2009/01/04 02:34:18 | 02,403,392 | R— | M] (Google Inc.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"Locked" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\] > -> HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\google\googletoolbar1.dll [&Google] -> [2009/01/04 02:34:18 | 02,403,392 | R— | M] (Google Inc.)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"ATICCC" -> %ProgramFiles%\ATI Technologies\ATI.ACE\CLIStart.exe ["C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"] -> [2006/05/10 12:12:06 | 00,090,112 | —- | M] ()
"AVG8_TRAY" -> %ProgramFiles%\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> [2009/04/27 16:24:04 | 01,932,568 | —- | M] (AVG Technologies CZ, s.r.o.)
"Broadcom Wireless Manager UI" -> %SystemRoot%\system32\WLTRAY.exe [C:\WINDOWS\system32\WLTRAY.exe] -> [2007/05/09 23:59:46 | 01,392,640 | —- | M] (Dell Inc.)
"Dell QuickSet" -> %ProgramFiles%\Dell\QuickSet\quickset.exe [C:\Program Files\Dell\QuickSet\quickset.exe] -> [2007/02/20 13:29:08 | 01,191,936 | —- | M] (Dell Inc)
"DLCXCATS" -> %SystemRoot%\System32\spool\DRIVERS\W32X86\3\DLCXtime.DLL [rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16] -> [2006/06/07 12:17:18 | 00,106,496 | —- | M] ()
"dlcxmon.exe" -> %ProgramFiles%\Dell Photo AIO Printer 926\dlcxmon.exe ["C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"] -> [2006/06/14 08:51:38 | 00,286,720 | —- | M] ()
"DVDLauncher" -> %ProgramFiles%\CyberLink\PowerDVD\DVDLauncher.exe ["C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"] -> [2005/12/09 21:29:52 | 00,049,152 | —- | M] (CyberLink Corp.)
"ehTray" -> %SystemRoot%\ehome\ehtray.exe [C:\WINDOWS\ehome\ehtray.exe] -> [2005/09/29 15:01:14 | 00,067,584 | —- | M] (Microsoft Corporation)
"ISUSPM Startup" -> %CommonProgramFiles%\InstallShield\UpdateService\isuspm.exe ["c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup] -> [2005/06/10 10:44:02 | 00,249,856 | —- | M] (InstallShield Software Corporation)
"ISUSScheduler" -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe ["C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start] -> [2005/06/10 10:44:02 | 00,081,920 | —- | M] (InstallShield Software Corporation)
"iTunesHelper" -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2009/04/02 16:11:02 | 00,342,312 | —- | M] (Apple Inc.)
"KernelFaultCheck" ->  [%systemroot%\system32\dumprep 0 -k] -> File not found
"MemoryCardManager" -> %ProgramFiles%\Dell Photo AIO Printer 926\memcard.exe ["C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"] -> [2006/06/27 07:34:50 | 00,299,008 | —- | M] ()
"pccguide.exe" -> %ProgramFiles%\Trend Micro\Internet Security 14\pccguide.exe ["C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"] -> [2006/11/21 14:02:24 | 01,807,960 | —- | M] (Trend Micro Inc.)
"QuickTime Task" -> %ProgramFiles%\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\QTTask.exe" -atboottime] -> [2009/01/05 16:18:48 | 00,413,696 | —- | M] (Apple Inc.)
"RoxWatchTray" -> %CommonProgramFiles%\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe ["C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"] -> [2006/11/05 12:22:16 | 00,221,184 | —- | M] (Sonic Solutions)
"SigmatelSysTrayApp" -> %SystemRoot%\stsystra.exe [stsystra.exe] -> [2006/09/22 13:06:26 | 00,282,624 | —- | M] (SigmaTel, Inc.)
"SynTPEnh" -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] -> [2006/09/22 13:47:54 | 00,761,947 | —- | M] (Synaptics, Inc.)
< Run [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\] > -> HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Aim6" -> %ProgramFiles%\AIM6\aim6.exe ["C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp] -> [2008/10/17 10:45:06 | 00,049,960 | —- | M] (AOL LLC)
"DellSupport" ->  ["C:\Program Files\Dell Support\DSAgnt.exe" /startup] -> File not found
"ModemOnHold" -> %ProgramFiles%\NetWaiting\netWaiting.exe [C:\Program Files\NetWaiting\netWaiting.exe] -> [2003/09/10 03:24:00 | 00,020,480 | —- | M] ()
"MSMSGS" -> %ProgramFiles%\Messenger\msmsgs.exe ["C:\Program Files\Messenger\msmsgs.exe" /background] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
"MsnMsgr" -> %ProgramFiles%\Windows Live\Messenger\MsnMsgr.Exe ["C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background] -> [2007/10/18 11:34:02 | 05,724,184 | —- | M] (Microsoft Corporation)
"OE_OEM" -> %ProgramFiles%\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe ["C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe"] -> [2006/08/04 17:15:28 | 00,321,040 | —- | M] (Trend Micro Inc.)
< Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup -> 
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
%AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> [2008/04/23 03:38:16 | 00,029,696 | —- | M] (Adobe Systems Incorporated)
%AllUsersProfile%\Start Menu\Programs\Startup\Digital Line Detect.lnk -> %ProgramFiles%\Digital Line Detect\DLG.exe -> [2003/10/29 03:06:00 | 00,024,576 | —- | M] (BVRP Software)
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup -> 
< Kevin Startup Folder > -> C:\Documents and Settings\Kevin\Start Menu\Programs\Startup -> 
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"HonorAutoRunSetting" ->  [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
\\"InstallVisualStyle" -> %SystemRoot%\Resources\Themes\Royale\Royale.mss [C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles] -> File not found
\\"InstallTheme" -> %SystemRoot%\Resources\Themes\Royale.the [C:\WINDOWS\Resources\Themes\Royale.theme] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005] > -> HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\npjpi150_06.dll [Menu: Sun Java Console] -> [2005/11/10 14:22:12 | 00,069,746 | —- | M] (Sun Microsystems, Inc.)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [Button: Send to OneNote] -> [2007/12/13 03:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\ONBttnIE.dll [Menu: S&end to OneNote] -> [2007/12/13 03:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\REFIEBAR.DLL [Button: Research] -> [2006/10/26 21:12:22 | 00,040,424 | —- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2006/10/10 08:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\npjpi150_06.dll [Sun Java Console] -> [2005/11/10 14:22:12 | 00,069,746 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\npjpi150_06.dll [Sun Java Console] -> [2005/11/10 14:22:12 | 00,069,746 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\] > -> HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\npjpi150_06.dll [Sun Java Console] -> [2005/11/10 14:22:12 | 00,069,746 | —- | M] (Sun Microsystems, Inc.)
CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2006/10/10 08:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\] > -> HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\] > -> HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab [Shockwave ActiveX Control] -> 
{459E93B6-150E-45D5-8D4B-45C66FC035FE} [HKLM] -> http://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx [get_atlcom Class] -> 
{4871A87A-BFDD-4106-8153-FFDE2BAC2967} [HKLM] -> http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab [DLM Control] -> 
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} [HKLM] -> http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab [MSN Photo Upload Tool] -> 
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [HKLM] -> http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1206151895937 [MUWebControl Class] -> 
{8A0019EB-51FA-4AE5-A40B-C0496BBFC739} [HKLM] -> http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab [Verizon Wireless Media Upload] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab [Java Plug-in 1.5.0_06] -> 
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab [Reg Error: Key error.] -> 
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab [Java Plug-in 1.5.0_06] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab [Java Plug-in 1.5.0_06] -> 
{D0C0F75C-683A-4390-A791-1ACFD5599AB8} [HKLM] -> http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab [Oberon Flash Game Host] -> 
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{6B9D471B-52F7-43CD-ABE5-21D7EA940D16} ->	(Dell Wireless 1390 WLAN Mini-Card) -> 
{9230E000-B006-4CA8-9A48-142F2C1A919D} ->	(Motorola SURFboard SB5120 USB Cable Modem) -> 
{C36D746A-1CBD-48B6-AD9A-D43E2D232B45} ->	(Dell Wireless 1390 WLAN Mini-Card) -> 
{EEE03215-180F-422E-8124-CC1F850C06B5} ->	(Broadcom 440x 10/100 Integrated Controller) -> 
IE Styles -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
Explorer.exe -> %SystemRoot%\Explorer.exe -> [2007/06/13 06:23:07 | 01,033,216 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 
AtiExtEvent -> %SystemRoot%\system32\Ati2evxx.dll -> [2007/10/16 23:16:12 | 00,090,112 | —- | M] (ATI Technologies Inc.)
avgrsstarter -> %SystemRoot%\system32\avgrsstx.dll -> [2009/04/27 16:24:34 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.)
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006/10/10 08:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/10 07:00:00 | 00,140,800 | —- | M] (Microsoft Corporation)
"C:\Program Files\America Online 9.0\waol.exe" -> C:\Program Files\America Online 9.0\waol.exe [C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe [C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007/10/02 17:18:24 | 00,304,488 | —- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007/10/18 11:34:02 | 05,724,184 | —- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006/10/10 08:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/10 07:00:00 | 00,140,800 | —- | M] (Microsoft Corporation)
"C:\Program Files\AIM6\aim6.exe" -> C:\Program Files\AIM6\aim6.exe [C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM] -> [2008/10/17 10:45:06 | 00,049,960 | —- | M] (AOL LLC)
"C:\Program Files\America Online 9.0\waol.exe" -> C:\Program Files\America Online 9.0\waol.exe [C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008/12/12 11:17:38 | 00,238,888 | —- | M] (Apple Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe [C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" -> C:\Program Files\Common Files\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> [2006/11/03 03:17:27 | 00,010,800 | —- | M] (AOL LLC)
"C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] -> File not found
"C:\Program Files\Messenger\msmsgs.exe" -> C:\Program Files\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> [2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" -> C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE [C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote] -> [2008/05/21 06:54:40 | 01,022,496 | —- | M] (Microsoft Corporation)
"C:\Program Files\MySpace\IM\MySpaceIM.exe" -> C:\Program Files\MySpace\IM\MySpaceIM.exe [C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpaceIM] -> File not found
"C:\Program Files\Vuze\Azureus.exe" -> C:\Program Files\Vuze\Azureus.exe [C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus] -> File not found
"C:\Program Files\Windows Live\Messenger\livecall.exe" -> C:\Program Files\Windows Live\Messenger\livecall.exe [C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)] -> [2007/10/02 17:18:24 | 00,304,488 | —- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" -> C:\Program Files\Windows Live\Messenger\msnmsgr.exe [C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger] -> [2007/10/18 11:34:02 | 05,724,184 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\system32\dlcxcoms.exe" -> C:\WINDOWS\system32\dlcxcoms.exe [C:\WINDOWS\system32\dlcxcoms.exe:*:Enabled:Lexmark Communications System] -> [2006/05/18 16:36:10 | 00,495,616 | —- | M] ( )
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
"AlternateShell" -> cmd.exe -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" -> %SystemRoot%\system32\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2004/08/10 07:00:00 | 00,049,536 | —- | M] (Microsoft Corporation)
< Drives with AutoRun files > ->  -> 
C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2005/08/16 06:43:04 | 00,000,000 | —- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
\{361ac05d-0e0d-11da-9aa9-806d6172696f}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell
\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\\"" ->  [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun
\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\\"" ->  [Auto&Play] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command
\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command\\"" -> E:\setup.exe [E:\setup.exe] -> File not found
\{75f25ca4-7266-11dd-9fd1-0019b94c5607}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{75f25ca4-7266-11dd-9fd1-0019b94c5607}\Shell
\{75f25ca4-7266-11dd-9fd1-0019b94c5607}\Shell\\"" ->  [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{75f25ca4-7266-11dd-9fd1-0019b94c5607}\Shell\AutoRun
\{75f25ca4-7266-11dd-9fd1-0019b94c5607}\Shell\AutoRun\\"" ->  [Auto&Play] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{75f25ca4-7266-11dd-9fd1-0019b94c5607}\Shell\AutoRun\command
\{75f25ca4-7266-11dd-9fd1-0019b94c5607}\Shell\AutoRun\command\\"" -> E:\LaunchU3.exe [E:\LaunchU3.exe] -> File not found
 
[Registry - Additional Scans - Safe List]
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 5/9/2009 12:08:17 AM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 12:08:17 AM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80040206.
Application [ Error ] 5/9/2009 12:08:45 AM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 12:08:45 AM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80040206.
Application [ Error ] 5/9/2009 1:24:16 AM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 1:24:16 AM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80040206.
Application [ Error ] 5/9/2009 4:31:01 PM Computer Name = KEVIN | Source = PerfNet | ID = 2004 -> Description = Unable to open the Server service. Server performance data  will not be returned. Error code returned is in data DWORD 0.
Application [ Error ] 5/9/2009 9:19:27 PM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 9:19:27 PM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80040206.
Application [ Error ] 5/11/2009 6:43:24 PM Computer Name = KEVIN | Source = PerfNet | ID = 2004 -> Description = Unable to open the Server service. Server performance data  will not be returned. Error code returned is in data DWORD 0.
Application [ Error ] 5/9/2009 12:08:17 AM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 12:08:17 AM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80040206.
Application [ Error ] 5/9/2009 12:08:45 AM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 12:08:45 AM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80040206.
Application [ Error ] 5/9/2009 1:24:16 AM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 1:24:16 AM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80040206.
Application [ Error ] 5/9/2009 4:31:01 PM Computer Name = KEVIN | Source = PerfNet | ID = 2004 -> Description = Unable to open the Server service. Server performance data  will not be returned. Error code returned is in data DWORD 0.
Application [ Error ] 5/9/2009 9:19:27 PM Computer Name = KEVIN | Source = EventSystem | ID = 4609 -> Description = The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this erro
Application [ Error ] 5/9/2009 9:19:27 PM Computer Name = KEVIN | Source = VSS | ID = 8193 -> Description = Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80040206.
Application [ Error ] 5/11/2009 6:43:24 PM Computer Name = KEVIN | Source = PerfNet | ID = 2004 -> Description = Unable to open the Server service. Server performance data  will not be returned. Error code returned is in data DWORD 0.
System [ Error ] 5/11/2009 6:50:00 PM Computer Name = KEVIN | Source = Service Control Manager | ID = 7034 -> Description = The Remote Access Connection Manager service terminated unexpectedly.  It has done this 8 time(s).
System [ Error ] 5/11/2009 6:56:10 PM Computer Name = KEVIN | Source = DCOM | ID = 10010 -> Description = The server {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E} did not register with DCOM within the required timeout.
System [ Error ] 5/11/2009 6:56:22 PM Computer Name = KEVIN | Source = DCOM | ID = 10005 -> Description = DCOM got error "%109" attempting to start the service netman with arguments ""  in order to run the server:  {BA126AE5-2166-11D1-B1D0-00805FC1270E}
System [ Error ] 5/11/2009 6:58:22 PM Computer Name = KEVIN | Source = DCOM | ID = 10005 -> Description = DCOM got error "%109" attempting to start the service netman with arguments ""  in order to run the server:  {BA126AE5-2166-11D1-B1D0-00805FC1270E}
System [ Error ] 5/11/2009 7:06:23 PM Computer Name = KEVIN | Source = DCOM | ID = 10005 -> Description = DCOM got error "%109" attempting to start the service netman with arguments ""  in order to run the server:  {BA126AE5-2166-11D1-B1D0-00805FC1270E}
System [ Error ] 5/11/2009 7:08:24 PM Computer Name = KEVIN | Source = DCOM | ID = 10005 -> Description = DCOM got error "%109" attempting to start the service netman with arguments ""  in order to run the server:  {BA126AE5-2166-11D1-B1D0-00805FC1270E}
System [ Error ] 5/11/2009 7:26:24 PM Computer Name = KEVIN | Source = DCOM | ID = 10005 -> Description = DCOM got error "%109" attempting to start the service netman with arguments ""  in order to run the server:  {BA126AE5-2166-11D1-B1D0-00805FC1270E}
System [ Error ] 5/11/2009 11:15:26 PM Computer Name = KEVIN | Source = Service Control Manager | ID = 7032 -> Description = The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error:   %%1056
System [ Error ] 5/11/2009 11:27:53 PM Computer Name = KEVIN | Source = Service Control Manager | ID = 7032 -> Description = The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error:   %%1056
System [ Error ] 5/12/2009 4:27:36 PM Computer Name = KEVIN | Source = DCOM | ID = 10010 -> Description = The server {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E} did not register with DCOM within the required timeout.
 
[Files/Folders - Created Within 30 Days]
1 C:\Documents and Settings\Kevin\Desktop\*.tmp files -> C:\Documents and Settings\Kevin\Desktop\*.tmp -> 
OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2009/05/12 18:49:31 | 00,000,000 | —D | C]
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/05/06 21:45:23 | 00,015,504 | —- | C] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/05/06 21:45:23 | 00,000,696 | —- | C] ()
mbamswissarmy.sys -> %SystemRoot%\System32\drivers\mbamswissarmy.sys -> [2009/05/06 21:45:20 | 00,038,496 | —- | C] (Malwarebytes Corporation)
Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [2009/05/06 21:45:19 | 00,000,000 | —D | C]
Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [2009/05/06 21:45:18 | 00,000,000 | —D | C]
mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> [2009/05/06 21:43:48 | 02,967,800 | —- | C] (Malwarebytes Corporation									)
sqmdata03.sqm -> %SystemDrive%\sqmdata03.sqm -> [2009/05/06 15:39:16 | 00,000,268 | -H– | C] ()
sqmnoopt03.sqm -> %SystemDrive%\sqmnoopt03.sqm -> [2009/05/06 15:39:16 | 00,000,244 | -H– | C] ()
iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2009/05/06 15:38:45 | 00,002,137 | —- | C] ()
{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> %AllUsersProfile%\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> [2009/05/06 15:37:32 | 00,000,000 | —D | C]
QuickTime Player.lnk -> %AllUsersProfile%\Desktop\QuickTime Player.lnk -> [2009/05/06 15:36:31 | 00,001,604 | —- | C] ()
QuickTime -> %ProgramFiles%\QuickTime -> [2009/05/06 15:36:07 | 00,000,000 | —D | C]
HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [2009/05/06 00:33:34 | 00,001,734 | —- | C] ()
Starcraft -> %UserProfile%\Desktop\Starcraft -> [2009/05/02 23:31:45 | 00,000,000 | —D | C]
Kevin000000.ERR -> %SystemDrive%\Kevin000000.ERR -> [2009/05/01 15:33:27 | 00,010,700 | —- | C] ()
e8d0a704bbf74f9049 -> %SystemDrive%\e8d0a704bbf74f9049 -> [2009/04/27 23:17:42 | 00,000,000 | —D | C]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2009/04/27 22:53:23 | 93,747,2000 | -HS- | C] ()
CSC -> %SystemRoot%\CSC -> [2009/04/27 22:45:50 | 00,000,000 | —D | C]
7798df00f2fdb8ede340ed7042ac5e97 -> %SystemDrive%\7798df00f2fdb8ede340ed7042ac5e97 -> [2009/04/27 18:37:10 | 00,000,000 | —D | C]
$AVG8.VAULT$ -> %SystemDrive%\$AVG8.VAULT$ -> [2009/04/27 16:33:12 | 00,000,000 | -H-D | C]
avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2009/04/27 16:24:34 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.)
AVG Free 8.5.lnk -> %AllUsersProfile%\Desktop\AVG Free 8.5.lnk -> [2009/04/27 16:24:34 | 00,001,507 | —- | C] ()
avgtdix.sys -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2009/04/27 16:24:32 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.)
avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2009/04/27 16:24:23 | 00,325,640 | —- | C] (AVG Technologies CZ, s.r.o.)
avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2009/04/27 16:24:21 | 00,027,656 | —- | C] (AVG Technologies CZ, s.r.o.)
incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2009/04/27 16:24:17 | 34,395,507 | —- | C] ()
avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [2009/04/27 16:24:17 | 06,061,540 | —- | C] ()
miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [2009/04/27 16:24:17 | 00,401,372 | —- | C] ()
microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2009/04/27 16:24:17 | 00,057,798 | —- | C] ()
Avg -> %SystemRoot%\System32\drivers\Avg -> [2009/04/27 16:24:17 | 00,000,000 | —D | C]
AVG -> %ProgramFiles%\AVG -> [2009/04/27 16:24:03 | 00,000,000 | —D | C]
avg8 -> %AllUsersProfile%\Application Data\avg8 -> [2009/04/27 16:24:02 | 00,000,000 | —D | C]
The Effects of Pressure on the Wound Healing.ppt -> %UserProfile%\Desktop\The Effects of Pressure on the Wound Healing.ppt -> [2009/04/27 16:21:35 | 00,034,304 | —- | C] ()
WindowsXP-KB936929-SP3-x86-ENU.exe -> %UserProfile%\Desktop\WindowsXP-KB936929-SP3-x86-ENU.exe -> [2009/04/27 16:21:14 | 33,180,5736 | —- | C] (Microsoft Corporation)
RegistryEasy.exe -> %UserProfile%\My Documents\RegistryEasy.exe -> [2009/04/27 15:53:33 | 03,208,448 | —- | C] (RegistryEasy, Inc.										  )
SvchostFixWizard.exe -> %UserProfile%\My Documents\SvchostFixWizard.exe -> [2009/04/27 15:53:33 | 00,973,882 | —- | C] (Security Stronghold										 )
Schedule Task Weekly.job -> %SystemRoot%\tasks\Schedule Task Weekly.job -> [2009/04/27 15:45:03 | 00,000,394 | —- | C] ()
Registry Easy -> %ProgramFiles%\Registry Easy -> [2009/04/27 15:44:56 | 00,000,000 | —D | C]
RegistryEasy.exe -> %UserProfile%\Desktop\RegistryEasy.exe -> [2009/04/27 15:44:35 | 03,208,448 | —- | C] (RegistryEasy, Inc.										  )
winhelp.GID -> %SystemRoot%\System32\winhelp.GID -> [2009/04/25 20:59:44 | 00,008,628 | -H– | C] ()
Help -> %UserProfile%\Local Settings\Application Data\Help -> [2009/04/25 20:59:44 | 00,000,000 | —D | C]
Help -> %AppData%\Help -> [2009/04/25 20:59:44 | 00,000,000 | —D | C]
Graphing Calculator -> %UserProfile%\Desktop\Graphing Calculator -> [2009/04/16 23:11:01 | 00,000,000 | —D | C]
rpcnetp.dll -> %SystemRoot%\System32\rpcnetp.dll -> [2009/03/29 18:49:40 | 00,017,408 | —- | C] ()
TDSSnlum.dll -> %SystemRoot%\System32\TDSSnlum.dll -> [2009/01/20 15:44:21 | 00,002,204 | —- | C] ()
45439F8962.sys -> %SystemRoot%\System32\45439F8962.sys -> [2008/07/13 00:47:53 | 00,000,088 | RHS- | C] ()
62899F4345.sys -> %SystemRoot%\System32\62899F4345.sys -> [2008/06/09 21:28:20 | 00,000,104 | RHS- | C] ()
dlcxvs.dll -> %SystemRoot%\System32\dlcxvs.dll -> [2008/06/09 00:27:26 | 00,040,960 | —- | C] ()
dlcxcoin.dll -> %SystemRoot%\System32\dlcxcoin.dll -> [2008/06/09 00:27:17 | 00,331,776 | —- | C] ()
dlcxdrs.dll -> %SystemRoot%\System32\dlcxdrs.dll -> [2008/06/09 00:26:07 | 00,692,224 | —- | C] ()
dlcxcaps.dll -> %SystemRoot%\System32\dlcxcaps.dll -> [2008/06/09 00:26:07 | 00,065,536 | —- | C] ()
dlcxcnv4.dll -> %SystemRoot%\System32\dlcxcnv4.dll -> [2008/06/09 00:26:06 | 00,061,440 | —- | C] ()
dlcxinst.dll -> %SystemRoot%\System32\dlcxinst.dll -> [2008/06/09 00:15:59 | 00,389,120 | —- | C] ()
dlcxinpa.dll -> %SystemRoot%\System32\dlcxinpa.dll -> [2008/06/09 00:15:58 | 00,413,696 | —- | C] ( )
dlcxiesc.dll -> %SystemRoot%\System32\dlcxiesc.dll -> [2008/06/09 00:15:58 | 00,393,216 | —- | C] ( )
dlcxusb1.dll -> %SystemRoot%\System32\dlcxusb1.dll -> [2008/06/09 00:15:57 | 00,983,040 | —- | C] ( )
dlcxutil.dll -> %SystemRoot%\System32\dlcxutil.dll -> [2008/06/09 00:15:57 | 00,450,560 | —- | C] ()
dlcxserv.dll -> %SystemRoot%\System32\dlcxserv.dll -> [2008/06/09 00:15:56 | 01,187,840 | —- | C] ( )
dlcxprox.dll -> %SystemRoot%\System32\dlcxprox.dll -> [2008/06/09 00:15:56 | 00,163,840 | —- | C] ( )
dlcxpplc.dll -> %SystemRoot%\System32\dlcxpplc.dll -> [2008/06/09 00:15:56 | 00,114,688 | —- | C] ( )
dlcxpmui.dll -> %SystemRoot%\System32\dlcxpmui.dll -> [2008/06/09 00:15:55 | 00,651,264 | —- | C] ( )
dlcxlmpm.dll -> %SystemRoot%\System32\dlcxlmpm.dll -> [2008/06/09 00:15:55 | 00,532,480 | —- | C] ( )
dlcxinsb.dll -> %SystemRoot%\System32\dlcxinsb.dll -> [2008/06/09 00:15:54 | 00,176,128 | —- | C] ()
dlcxins.dll -> %SystemRoot%\System32\dlcxins.dll -> [2008/06/09 00:15:54 | 00,167,936 | —- | C] ()
dlcxjswr.dll -> %SystemRoot%\System32\dlcxjswr.dll -> [2008/06/09 00:15:54 | 00,135,168 | —- | C] ()
dlcxinsr.dll -> %SystemRoot%\System32\dlcxinsr.dll -> [2008/06/09 00:15:54 | 00,106,496 | —- | C] ()
dlcxhbn3.dll -> %SystemRoot%\System32\dlcxhbn3.dll -> [2008/06/09 00:15:53 | 00,688,128 | —- | C] ( )
dlcxgrd.dll -> %SystemRoot%\System32\dlcxgrd.dll -> [2008/06/09 00:15:53 | 00,188,416 | —- | C] ()
dlcxcub.dll -> %SystemRoot%\System32\dlcxcub.dll -> [2008/06/09 00:15:52 | 00,086,016 | —- | C] ()
dlcxcomc.dll -> %SystemRoot%\System32\dlcxcomc.dll -> [2008/06/09 00:15:51 | 00,610,304 | —- | C] ( )
dlcxcomm.dll -> %SystemRoot%\System32\dlcxcomm.dll -> [2008/06/09 00:15:51 | 00,421,888 | —- | C] ( )
dlcxcu.dll -> %SystemRoot%\System32\dlcxcu.dll -> [2008/06/09 00:15:51 | 00,073,728 | —- | C] ()
dlcxcur.dll -> %SystemRoot%\System32\dlcxcur.dll -> [2008/06/09 00:15:51 | 00,036,864 | —- | C] ()
DLCXcfg.dll -> %SystemRoot%\System32\DLCXcfg.dll -> [2008/06/09 00:15:50 | 00,073,728 | —- | C] ()
0CB5F02B6E.sys -> %SystemRoot%\System32\0CB5F02B6E.sys -> [2008/03/25 12:11:12 | 00,000,168 | RHS- | C] ()
KGyGaAvL.sys -> %SystemRoot%\System32\KGyGaAvL.sys -> [2008/03/25 11:46:25 | 00,008,510 | -HS- | C] ()
smscfg.ini -> %SystemRoot%\smscfg.ini -> [2008/03/21 17:01:22 | 00,000,061 | —- | C] ()
wininit.ini -> %SystemRoot%\wininit.ini -> [2008/03/21 16:51:05 | 00,000,120 | —- | C] ()
msoffice.ini -> %SystemRoot%\msoffice.ini -> [2008/03/21 16:45:25 | 00,000,002 | —- | C] ()
preflib.dll -> %SystemRoot%\System32\preflib.dll -> [2008/03/21 16:40:26 | 00,086,016 | —- | C] ()
bcm1xsup.dll -> %SystemRoot%\System32\bcm1xsup.dll -> [2008/03/21 16:40:25 | 00,757,760 | —- | C] ()
OEMINFO.INI -> %SystemRoot%\System32\OEMINFO.INI -> [2008/03/20 20:13:12 | 00,001,120 | —- | C] ()
CddbPlaylist2Roxio.dll -> %SystemRoot%\System32\CddbPlaylist2Roxio.dll -> [2006/09/17 00:36:50 | 00,520,192 | —- | C] ()
CddbFileTaggerRoxio.dll -> %SystemRoot%\System32\CddbFileTaggerRoxio.dll -> [2006/09/17 00:36:50 | 00,204,800 | —- | C] ()
fxsperf.ini -> %SystemRoot%\System32\fxsperf.ini -> [2005/08/16 06:37:24 | 00,001,793 | —- | C] ()
win.ini -> %SystemRoot%\win.ini -> [2005/08/16 06:18:43 | 00,000,528 | —- | C] ()
system.ini -> %SystemRoot%\system.ini -> [2005/08/16 06:18:41 | 00,000,231 | —- | C] ()
psisdecd.dll -> %SystemRoot%\System32\psisdecd.dll -> [2005/08/05 16:01:54 | 00,235,008 | —- | C] ()
 
[Files/Folders - Modified Within 30 Days]
4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
1 C:\Documents and Settings\Kevin\Desktop\*.tmp files -> C:\Documents and Settings\Kevin\Desktop\*.tmp -> 
53 C:\Documents and Settings\Kevin\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Kevin\Local Settings\Temp\*.tmp -> 
53 C:\Documents and Settings\Kevin\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Kevin\Local Settings\Temp\*.tmp -> 
8 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> 
wklnhst.dat -> %AppData%\wklnhst.dat -> [2009/05/12 00:06:59 | 00,020,498 | —- | M] ()
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2009/05/11 18:47:04 | 00,000,006 | -H– | M] ()
Perflib_Perfdata_e0c.dat -> %SystemRoot%\Temp\Perflib_Perfdata_e0c.dat -> [2009/05/11 18:45:28 | 00,016,384 | —- | M] ()
iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2009/05/11 18:43:32 | 00,002,137 | —- | M] ()
wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2009/05/11 18:42:53 | 00,002,206 | —- | M] ()
bootstat.dat -> %SystemRoot%\bootstat.dat -> [2009/05/11 18:42:52 | 00,002,048 | –S- | M] ()
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2009/05/11 18:42:47 | 93,747,2000 | -HS- | M] ()
Perflib_Perfdata_cf8.dat -> %SystemRoot%\Temp\Perflib_Perfdata_cf8.dat -> [2009/05/09 16:32:25 | 00,016,384 | —- | M] ()
rpcnetp.dll -> %SystemRoot%\System32\rpcnetp.dll -> [2009/05/09 16:32:24 | 00,017,408 | —- | M] ()
rpcnetp.exe -> %SystemRoot%\System32\rpcnetp.exe -> [2009/05/09 16:29:27 | 00,017,408 | —- | M] ()
Perflib_Perfdata_d8c.dat -> %SystemRoot%\Temp\Perflib_Perfdata_d8c.dat -> [2009/05/09 00:06:57 | 00,016,384 | —- | M] ()
Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/05/07 22:09:40 | 00,000,696 | —- | M] ()
Perflib_Perfdata_ce0.dat -> %SystemRoot%\Temp\Perflib_Perfdata_ce0.dat -> [2009/05/07 21:56:20 | 00,016,384 | —- | M] ()
mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> [2009/05/06 21:21:20 | 02,967,800 | —- | M] (Malwarebytes Corporation									)
NTUSER.DAT -> %UserProfile%\NTUSER.DAT -> [2009/05/06 16:40:49 | 06,029,312 | —- | M] ()
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2009/05/06 15:39:20 | 03,772,432 | -H– | M] ()
sqmdata03.sqm -> %SystemDrive%\sqmdata03.sqm -> [2009/05/06 15:39:16 | 00,000,268 | -H– | M] ()
sqmnoopt03.sqm -> %SystemDrive%\sqmnoopt03.sqm -> [2009/05/06 15:39:16 | 00,000,244 | -H– | M] ()
QuickTime Player.lnk -> %AllUsersProfile%\Desktop\QuickTime Player.lnk -> [2009/05/06 15:36:31 | 00,001,604 | —- | M] ()
HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [2009/05/06 00:33:34 | 00,001,734 | —- | M] ()
Kevin000000.ERR -> %SystemDrive%\Kevin000000.ERR -> [2009/05/02 23:21:54 | 00,010,700 | —- | M] ()
ntuser.ini -> %UserProfile%\ntuser.ini -> [2009/04/27 22:48:11 | 00,000,178 | -HS- | M] ()
Schedule Task Weekly.job -> %SystemRoot%\tasks\Schedule Task Weekly.job -> [2009/04/27 19:02:25 | 00,000,394 | —- | M] ()
Ahmbed.gz -> %UserProfile%\Ahmbed.gz -> [2009/04/27 16:54:29 | 00,005,742 | —- | M] ()
avgrsstx.dll -> %SystemRoot%\System32\avgrsstx.dll -> [2009/04/27 16:24:34 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.)
AVG Free 8.5.lnk -> %AllUsersProfile%\Desktop\AVG Free 8.5.lnk -> [2009/04/27 16:24:34 | 00,001,507 | —- | M] ()
avgtdix.sys -> %SystemRoot%\System32\drivers\avgtdix.sys -> [2009/04/27 16:24:32 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.)
avgldx86.sys -> %SystemRoot%\System32\drivers\avgldx86.sys -> [2009/04/27 16:24:23 | 00,325,640 | —- | M] (AVG Technologies CZ, s.r.o.)
incavi.avm -> %SystemRoot%\System32\drivers\Avg\incavi.avm -> [2009/04/27 16:24:21 | 34,395,507 | —- | M] ()
avgmfx86.sys -> %SystemRoot%\System32\drivers\avgmfx86.sys -> [2009/04/27 16:24:21 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.)
avi7.avg -> %SystemRoot%\System32\drivers\Avg\avi7.avg -> [2009/04/27 16:24:17 | 06,061,540 | —- | M] ()
miniavi.avg -> %SystemRoot%\System32\drivers\Avg\miniavi.avg -> [2009/04/27 16:24:17 | 00,401,372 | —- | M] ()
microavi.avg -> %SystemRoot%\System32\drivers\Avg\microavi.avg -> [2009/04/27 16:24:17 | 00,057,798 | —- | M] ()
opa12.dat -> %AllUsersProfile%\Application Data\Microsoft\OFFICE\DATA\opa12.dat -> [2009/04/27 16:23:01 | 00,008,468 | —- | M] ()
WindowsXP-KB936929-SP3-x86-ENU.exe -> %UserProfile%\Desktop\WindowsXP-KB936929-SP3-x86-ENU.exe -> [2009/04/27 16:17:44 | 33,180,5736 | —- | M] (Microsoft Corporation)
RegistryEasy.exe -> %UserProfile%\My Documents\RegistryEasy.exe -> [2009/04/27 15:44:24 | 03,208,448 | —- | M] (RegistryEasy, Inc.										  )
RegistryEasy.exe -> %UserProfile%\Desktop\RegistryEasy.exe -> [2009/04/27 15:44:24 | 03,208,448 | —- | M] (RegistryEasy, Inc.										  )
SvchostFixWizard.exe -> %UserProfile%\My Documents\SvchostFixWizard.exe -> [2009/04/27 15:35:20 | 00,973,882 | —- | M] (Security Stronghold										 )
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2009/04/26 19:07:46 | 02,311,136 | —- | M] ()
imsins.BAK -> %SystemRoot%\imsins.BAK -> [2009/04/25 21:18:42 | 00,001,917 | —- | M] ()
winhelp.GID -> %SystemRoot%\System32\winhelp.GID -> [2009/04/25 20:59:49 | 00,008,628 | -H– | M] ()
qmgr1.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2009/04/25 20:36:24 | 00,004,232 | —- | M] ()
The Effects of Pressure on the Wound Healing.ppt -> %UserProfile%\Desktop\The Effects of Pressure on the Wound Healing.ppt -> [2009/04/21 14:01:18 | 00,034,304 | —- | M] ()
qmgr0.dat -> %AllUsersProfile%\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2009/04/03 16:09:03 | 00,004,617 | —- | M] ()
7Z.DLL -> %UserProfile%\Local Settings\Temp\_PASFX615\7Z.DLL -> [2009/01/31 02:19:22 | 00,076,800 | —- | M] (Igor Pavlov)
7Z.DLL -> %UserProfile%\Local Settings\Temp\_PASFX58\7Z.DLL -> [2008/08/25 23:10:26 | 00,076,288 | —- | M] ()
wklntsk1.dat -> %AllUsersProfile%\Application Data\Microsoft\Works\wklntsk1.dat -> [2008/03/25 23:26:39 | 00,162,475 | —- | M] ()
wkcalcat.dat -> %AllUsersProfile%\Application Data\Microsoft\Works\wkcalcat.dat -> [2008/03/25 21:55:10 | 00,016,384 | —- | M] ()
uninst.dll -> %UserProfile%\Local Settings\Temp\uninst.dll -> [2004/09/01 11:56:56 | 00,114,688 | —- | M] ()
TFR97.exe -> %UserProfile%\Local Settings\Temp\TFR97.exe -> [2004/01/20 17:44:42 | 00,132,608 | —- | M] (Microsoft Corp.)
 
[File - Lop Check]
Application Data -> C:\Documents and Settings\Administrator\Application Data -> [2008/03/21 17:00:54 | 00,000,000 | RH-D | M]
ATI -> C:\Documents and Settings\Administrator\Application Data\ATI -> [2008/03/21 16:46:56 | 00,000,000 | —D | M]
Roxio -> C:\Documents and Settings\Administrator\Application Data\Roxio -> [2008/03/21 17:00:54 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\All Users\Application Data -> [2009/05/06 21:45:19 | 00,000,000 | RH-D | M]
{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> [2009/05/06 15:38:02 | 00,000,000 | —D | M]
acccore -> C:\Documents and Settings\All Users\Application Data\acccore -> [2008/08/03 02:29:26 | 00,000,000 | —D | M]
Azureus -> C:\Documents and Settings\All Users\Application Data\Azureus -> [2009/02/18 18:41:03 | 00,000,000 | —D | M]
Corel -> C:\Documents and Settings\All Users\Application Data\Corel -> [2008/03/25 12:02:28 | 00,000,000 | —D | M]
Dell -> C:\Documents and Settings\All Users\Application Data\Dell -> [2008/03/22 19:05:18 | 00,000,000 | —D | M]
DellFaxCtr -> C:\Documents and Settings\All Users\Application Data\DellFaxCtr -> [2008/06/09 00:16:47 | 00,000,000 | —D | M]
FLEXnet -> C:\Documents and Settings\All Users\Application Data\FLEXnet -> [2008/08/26 00:45:10 | 00,000,000 | —D | M]
Roxio -> C:\Documents and Settings\All Users\Application Data\Roxio -> [2008/10/18 12:47:53 | 00,000,000 | —D | M]
Sony -> C:\Documents and Settings\All Users\Application Data\Sony -> [2008/12/27 18:11:16 | 00,000,000 | —D | M]
Viewpoint -> C:\Documents and Settings\All Users\Application Data\Viewpoint -> [2009/01/03 20:45:11 | 00,000,000 | —D | M]
YAHOO -> C:\Documents and Settings\All Users\Application Data\YAHOO -> [2008/03/21 16:49:10 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\Default User\Application Data -> [2008/03/21 17:00:54 | 00,000,000 | RH-D | M]
ATI -> C:\Documents and Settings\Default User\Application Data\ATI -> [2008/03/21 16:46:56 | 00,000,000 | —D | M]
Roxio -> C:\Documents and Settings\Default User\Application Data\Roxio -> [2008/03/21 17:00:54 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\Kevin\Application Data -> [2009/05/12 00:06:59 | 00,000,000 | -H-D | M]
acccore -> C:\Documents and Settings\Kevin\Application Data\acccore -> [2008/05/24 03:17:20 | 00,000,000 | —D | M]
ATI -> C:\Documents and Settings\Kevin\Application Data\ATI -> [2008/03/21 16:46:56 | 00,000,000 | —D | M]
Azureus -> C:\Documents and Settings\Kevin\Application Data\Azureus -> [2009/03/18 15:53:39 | 00,000,000 | —D | M]
Corel -> C:\Documents and Settings\Kevin\Application Data\Corel -> [2008/07/14 00:07:27 | 00,000,000 | —D | M]
Corel Photo Album -> C:\Documents and Settings\Kevin\Application Data\Corel Photo Album -> [2008/06/10 17:09:38 | 00,000,000 | —D | M]
CyberLink -> C:\Documents and Settings\Kevin\Application Data\CyberLink -> [2008/03/21 16:38:05 | 00,000,000 | —D | M]
DellFaxCtr -> C:\Documents and Settings\Kevin\Application Data\DellFaxCtr -> [2008/06/09 20:02:06 | 00,000,000 | —D | M]
Download Manager -> C:\Documents and Settings\Kevin\Application Data\Download Manager -> [2009/02/21 01:52:34 | 00,000,000 | —D | M]
GetRightToGo -> C:\Documents and Settings\Kevin\Application Data\GetRightToGo -> [2009/01/15 19:06:18 | 00,000,000 | —D | M]
LimeWire -> C:\Documents and Settings\Kevin\Application Data\LimeWire -> [2008/12/23 15:12:22 | 00,000,000 | —D | M]
MSNInstaller -> C:\Documents and Settings\Kevin\Application Data\MSNInstaller -> [2008/04/24 16:21:43 | 00,000,000 | —D | M]
Roxio -> C:\Documents and Settings\Kevin\Application Data\Roxio -> [2008/03/21 17:21:59 | 00,000,000 | —D | M]
SoundSpectrum -> C:\Documents and Settings\Kevin\Application Data\SoundSpectrum -> [2008/05/26 22:57:47 | 00,000,000 | —D | M]
Template -> C:\Documents and Settings\Kevin\Application Data\Template -> [2008/03/25 21:55:03 | 00,000,000 | —D | M]
U3 -> C:\Documents and Settings\Kevin\Application Data\U3 -> [2009/02/22 22:37:32 | 00,000,000 | —D | M]
Viewpoint -> C:\Documents and Settings\Kevin\Application Data\Viewpoint -> [2008/04/05 22:02:23 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\LocalService\Application Data -> [2008/03/21 17:01:05 | 00,000,000 | —D | M]
Roxio -> C:\Documents and Settings\LocalService\Application Data\Roxio -> [2008/03/21 17:01:05 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\NetworkService\Application Data -> [2005/08/16 06:49:40 | 00,000,000 | —D | M]
C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2009/04/27 15:45:03 | 00,000,000 | –SD | M]
AppleSoftwareUpdate.job -> C:\WINDOWS\Tasks\AppleSoftwareUpdate.job -> [2009/04/03 09:28:02 | 00,000,284 | —- | M] ()
desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2004/08/10 07:00:00 | 00,000,065 | RH– | M] ()
SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2009/05/11 18:47:04 | 00,000,006 | -H– | M] ()
Schedule Task Weekly.job -> C:\WINDOWS\Tasks\Schedule Task Weekly.job -> [2009/04/27 19:02:25 | 00,000,394 | —- | M] ()
 
[File - Purity Scan]
 
 
[Alternate Data Streams]
@Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
< End of report >


whats next?
oh and what do you suggest i do with the anti-virus? because trend-micro was unable to detected about 5 trojan horses that avg was able to find?
I would probably recommend keeping AVG. However, the choice is yours.

That showed that if there is any malware left it is hidden so I will use a strong scanner now

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
another with the computer, for some reason the computer is unable to gain internet. i have another laptop connected to the same wireless router, it is just no getting internet. and me getting internet stops me from download and install the microsoft windows recovery console. is there another thing im able to use?
well no, the one with the svchost didnt have any internet, and the one without the svchost did have internet…
but for some weird reason, i gain internet back and i havent noticed any svchost errors..
and now that i have internet, i was able to get the recovery console and ran the log..

here it is:
ComboFix 09-05-15.01 - Kevin 05/15/2009 23:49.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.894.209 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: PC-cillin Internet Security - Virus Protection *On-access scanning disabled* (Outdated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: PC-cillin Internet Security - Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.

((((((((((((((((((((((((( Files Created from 2009-04-16 to 2009-05-16 )))))))))))))))))))))))))))))))
.

2009-05-12 22:56 . 2009-05-12 22:56 ——– d—–w C:\_OTScanIt
2009-05-07 01:45 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-07 01:45 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-07 01:45 . 2009-05-07 01:45 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-07 01:45 . 2009-05-08 02:09 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-06 19:38 . 2009-03-19 20:32 23400 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-06 19:38 . 2008-04-17 16:12 107368 —-a-w c:\windows\system32\GEARAspi.dll
2009-05-06 19:37 . 2009-05-06 19:38 ——– d—–w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-06 19:36 . 2009-05-06 19:36 ——– d—–w c:\program files\QuickTime
2009-05-06 19:34 . 2009-03-26 19:23 36864 —-a-w c:\windows\system32\drivers\usbaapl.sys
2009-05-06 19:34 . 2009-03-26 19:23 1900544 —-a-w c:\windows\system32\usbaaplrc.dll
2009-04-28 03:17 . 2009-04-28 03:21 ——– d—–w C:\e8d0a704bbf74f9049
2009-04-27 22:37 . 2009-04-27 22:37 ——– d—–w C:\7798df00f2fdb8ede340ed7042ac5e97
2009-04-27 20:33 . 2009-05-13 00:57 ——– d–h–w C:\$AVG8.VAULT$
2009-04-27 20:24 . 2009-04-27 20:24 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-04-27 20:24 . 2009-04-27 20:24 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-27 20:24 . 2009-04-27 20:24 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-27 20:24 . 2009-04-27 20:24 ——– d—–w c:\windows\system32\drivers\Avg
2009-04-27 20:24 . 2009-04-27 20:24 ——– d—–w c:\program files\AVG
2009-04-27 20:24 . 2009-05-14 21:01 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-27 19:44 . 2009-04-27 19:49 ——– d—–w c:\program files\Registry Easy
2009-04-26 00:59 . 2009-04-26 00:59 ——– d—–w c:\documents and settings\Kevin\Local Settings\Application Data\Help

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-15 05:08 . 2009-03-29 22:49 17408 —-a-w c:\windows\system32\rpcnetp.dll
2009-05-15 05:05 . 2009-03-29 22:46 17408 —-a-w c:\windows\system32\rpcnetp.exe
2009-05-14 21:06 . 2008-03-21 20:40 ——– d—–w c:\program files\Dell
2009-05-12 04:06 . 2008-03-26 01:55 20498 —-a-w c:\documents and settings\Kevin\Application Data\wklnhst.dat
2009-05-06 19:38 . 2008-10-25 17:06 ——– d—–w c:\program files\iTunes
2009-05-06 19:37 . 2008-10-01 03:55 ——– d—–w c:\program files\Common Files\Apple
2009-05-06 19:37 . 2008-08-26 04:26 ——– d—–w c:\program files\Bonjour
2009-05-06 04:33 . 2008-03-21 20:51 ——– d—–w c:\program files\Trend Micro
2009-05-03 03:29 . 2008-06-09 04:28 ——– d—–w c:\program files\dl_cats
2009-04-26 01:16 . 2008-03-21 20:47 58648 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-04-03 03:57 . 2008-04-03 03:57 251 —-a-w c:\program files\wt3d.ini
2008-06-10 01:26 . 2008-03-25 16:11 168 –sh–r c:\windows\system32\0CB5F02B6E.sys
2008-07-13 07:56 . 2008-07-13 04:47 88 –sh–r c:\windows\system32\45439F8962.sys
2008-07-13 07:55 . 2008-06-10 01:28 104 –sh–r c:\windows\system32\62899F4345.sys
2008-07-13 07:56 . 2008-03-25 15:46 8510 –sha-w c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-05-14_21.39.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-16 02:24 . 2009-05-16 02:24 16384 c:\windows\Temp\Perflib_Perfdata_db4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"OE_OEM"="c:\program files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" [2006-08-04 321040]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-08-29 395776]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-17 49960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-09-22 761947]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-02-20 1191936]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-05-10 1392640]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 1807960]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2006-06-14 286720]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-06-27 299008]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-06-07 106496]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-27 1932568]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-09-22 282624]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-3-21 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-27 20:24 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\system32\\dlcxcoms.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/27/2009 4:24 PM 325640]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/27/2009 4:24 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [4/27/2009 4:24 PM 298264]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [11/9/2007 4:19 AM 345696]
R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [11/9/2007 4:19 AM 923216]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [11/9/2007 4:20 AM 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [11/9/2007 4:19 AM 566872]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/21/2008 4:49 PM 24652]
R3 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service –> c:\windows\system32\dlcxcoms.exe -service [?]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [11/9/2007 4:20 AM 280392]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{75f25ca4-7266-11dd-9fd1-0019b94c5607}]
\Shell\AutoRun\command - E:\LaunchU3.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-05-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-04-27 c:\windows\Tasks\Schedule Task Weekly.job
- c:\program files\Registry Easy\RE.exe [2009-04-27 20:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.myspace.com/
uInternet Settings,ProxyOverride = *.local
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-15 23:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3562189915-3449170300-1929132256-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1268)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(4488)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Bonjour\mdnsNSP.dll
.
Completion time: 2009-05-16 23:53
ComboFix-quarantined-files.txt 2009-05-16 03:52
ComboFix2.txt 2009-05-15 01:25
ComboFix3.txt 2009-05-14 21:41

Pre-Run: 47,620,104,192 bytes free
Post-Run: 47,562,956,800 bytes free

171 — E O F — 2009-03-06 08:00
there really isnt any problems with it, the only i would say is that the connection to the internet is slow, as well as the internet itself and programs loading but im think its because of the two anti-virus as you stated before i have been scanning the computer with AVG and i have found a couple trojan horses and deleted them, but besides that the computer is starting to look back to normal
OK lets confirm that before I start giving you a speed up run :)

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.
theres wass three: Malwarebytes' Anti-Malware 1.36 Database version: 2142 Windows 5.1.2600 Service Pack 2 5/16/2009 7:24:38 PM mbam-log-2009-05-16 (19-24-38).txt Scan type: Quick Scan Objects scanned: 90464 Time elapsed: 9 minute(s), 28 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 1 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{1585fbe0-752e-4197-8232-7556e48d91b2}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully. Folders Infected: C:\WINDOWS\tmpie (Backdoor.Bot) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\tmpie\newpw.txt (Backdoor.Bot) -> Quarantined and deleted successfully.
heres the log: Malwarebytes' Anti-Malware 1.36 Database version: 2142 Windows 5.1.2600 Service Pack 2 5/17/2009 12:24:54 PM mbam-log-2009-05-17 (12-24-54).txt Scan type: Quick Scan Objects scanned: 90862 Time elapsed: 12 minute(s), 3 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Excellent - thank you very much

All that is left now - subject to no further problems ………

Now the best part of the day —– Your log now appears clean :thumbup:

A good workman always cleans up after himself so..Run OTListit and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 13.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u13-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u13-windows-i586-p.exe and select "Run as an Administrator.")

XP
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done


Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SuperAntispyware Run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI