One more thing that I noticed that is happening with this PC is that on startup upon requesting the web browser to open svchost fails and one of those windows to report it or not Microsoft comes up. Here are the requested logs:
Rooter.exe (v1.0) by Eric_71
¨
Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3
32_bits - x86 Family 6 Model 13 Stepping 6, GenuineIntel
¨
C:\ [Fixed-NTFS] .. ( Total:92020 Mo - Free:24662 Mo )
E:\ [CD_Rom]
¨
Scan : 20:17.10
Path : C:\Documents and Settings\Pahola Caicedo\Desktop\Rooter.exe
User : Pahola Caicedo ( Administrator -> YES )
¨
———————-\\ Processes
¨
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (616)
______ \??\C:\WINDOWS\system32\csrss.exe (1280)
______ \??\C:\WINDOWS\system32\winlogon.exe (1452)
______ C:\WINDOWS\system32\services.exe (1588)
______ C:\WINDOWS\system32\lsass.exe (1648)
______ C:\WINDOWS\system32\svchost.exe (1248)
______ C:\WINDOWS\system32\svchost.exe (1488)
______ C:\WINDOWS\System32\svchost.exe (1840)
______ C:\WINDOWS\system32\svchost.exe (512)
______ C:\WINDOWS\system32\svchost.exe (828)
______ C:\WINDOWS\System32\WLTRYSVC.EXE (1760)
______ C:\WINDOWS\System32\bcmwltry.exe (1884)
______ C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (1904)
______ C:\WINDOWS\Explorer.EXE (1976)
______ C:\WINDOWS\system32\spoolsv.exe (788)
______ C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (884)
______ C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (1024)
______ C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (1616)
______ C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (1716)
______ C:\WINDOWS\system32\svchost.exe (1960)
______ C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe (456)
______ C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (856)
______ C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (1220)
______ C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (1448)
______ C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (220)
______ C:\WINDOWS\system32\HPZipm12.exe (196)
______ C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe (668)
______ C:\WINDOWS\system32\svchost.exe (1276)
______ C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (140)
______ C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe (1020)
______ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (4012)
______ C:\WINDOWS\system32\WLTRAY.exe (4052)
______ C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (824)
______ C:\Program Files\Dell\Media Experience\DMXLauncher.exe (1352)
______ C:\WINDOWS\system32\hkcmd.exe (2376)
______ C:\WINDOWS\system32\igfxpers.exe (2540)
______ C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (2740)
______ C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (2328)
______ C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe (3188)
______ C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (3508)
______ C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (4080)
______ C:\WINDOWS\System32\DLA\DLACTRLW.EXE (3164)
______ C:\WINDOWS\system32\igfxsrvc.exe (3364)
______ C:\Program Files\Fisher-Price\Computer Cool School\FPCCSMiddleware.exe (3588)
______ C:\WINDOWS\system32\ctfmon.exe (1996)
______ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (2728)
______ C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (3024)
______ C:\Program Files\Digital Line Detect\DLG.exe (3828)
______ C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe (3992)
______ C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (1500)
______ C:\WINDOWS\System32\svchost.exe (1192)
______ C:\Program Files\Mozilla Firefox\firefox.exe (2180)
______ C:\WINDOWS\system32\NOTEPAD.EXE (3040)
______ c:\program files\common files\installshield\updateservice\isuspm.exe (2256)
______ C:\Documents and Settings\Pahola Caicedo\Desktop\Rooter.exe (1700)
______ C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (2976)
¨
———————-\\ Device\Harddisk0\
¨
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
¨
\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:49319424)
\Device\Harddisk0\Partition2 –[ MBR ]– (Start_Offset:49351680 | Length:96490759680)
\Device\Harddisk0\Partition3 (Start_Offset:96540111360 | Length:3487518720)
¨
———————-\\ Scheduled Tasks
¨
C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Pahola Caicedo at 7 25 PM.job
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\SA.DAT
¨
———————-\\ Registry
¨
¨
———————-\\ Files & Folders
¨
———————-\\ Scan completed at 20:17.33
¨
C:\Rooter$\Rooter_2.txt - (12/06/2009 | 20:17.33)
—————————————————————————————————————————————————–
OTL logfile created on: 6/12/2009 8:23:44 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Pahola Caicedo\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
494.42 Mb Total Physical Memory | 74.45 Mb Available Physical Memory | 15.06% Memory free
1.13 Gb Paging File | 0.78 Gb Available in Paging File | 68.94% Paging File free
Paging file location(s): C:\pagefile.sys 744 1488 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.86 Gb Total Space | 24.08 Gb Free Space | 26.80% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 17.26 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PAHOLAP
Current User Name: Pahola Caicedo
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\System32\WLTRYSVC.EXE ()
PRC - C:\WINDOWS\System32\bcmwltry.exe (Dell Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
PRC - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (GRISOFT s.r.o.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe (Sling Media Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe (CA, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\system32\WLTRAY.exe (Dell Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
PRC - C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe (CA)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (CA, Inc.)
PRC - C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Program Files\Fisher-Price\Computer Cool School\FPCCSMiddleware.exe ()
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
PRC - C:\Documents and Settings\Pahola Caicedo\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
SRV - (AOL ACS [Auto | Running]) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (AVG Anti-Spyware Guard [Auto | Running]) – C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (GRISOFT s.r.o.)
SRV - (CaCCProvSP [On_Demand | Running]) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (CAISafe [Auto | Running]) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (Computer Associates International, Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (HP Port Resolver [On_Demand | Stopped]) – C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE (Hewlett-Packard Company)
SRV - (HP Status Server [On_Demand | Stopped]) – C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE (Hewlett-Packard Company)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (ITMRTSVC [Auto | Running]) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (PPCtlPriv [On_Demand | Running]) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
SRV - (SlingAgentService [Auto | Running]) – C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe (Sling Media Inc.)
SRV - (UmxAgent [Auto | Running]) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
SRV - (UmxCfg [Auto | Running]) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
SRV - (UmxFwHlp [Auto | Running]) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (CA)
SRV - (UmxPol [Auto | Running]) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
SRV - (VETMSGNT [Auto | Running]) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (CA, Inc.)
SRV - (wltrysvc [Auto | Running]) – C:\WINDOWS\System32\WLTRYSVC.EXE ()
========== Driver Services (SafeList) ==========
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ASCTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (ASPI32 [System | Running]) – C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (AVG Anti-Spyware Driver [System | Running]) – C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ()
DRV - (AvgAsCln [System | Running]) – C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys (GRISOFT, s.r.o.)
DRV - (BCM43XX [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\bcmwl5.sys (Broadcom Corporation)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (catchme [On_Demand | Stopped]) – C:\WINDOWS\catchme.exe ()
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (CrystalSysInfo [On_Demand | Stopped]) – C:\Program Files\MediaCoder\SysInfo.sys ()
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DCamUSB20GAB [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\GMini20.sys (Crescentec Corporation)
DRV - (DLABOIOM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLACDBHM [System | Running]) – C:\WINDOWS\System32\Drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLADResN [Auto | Running]) – C:\WINDOWS\System32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLAIFS_M [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLAOPIOM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLARTL_N [System | Running]) – C:\WINDOWS\System32\Drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (DLAUDFAM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (drvmcdb [Boot | Running]) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (drvnddm [Auto | Running]) – C:\WINDOWS\System32\Drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (GAB20Scan [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\GABscan.sys ()
DRV - (HSFHWICH [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (ICAM5USB [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\Icam5USB.sys (Microsoft Corporation)
DRV - (KmxAgent [System | Running]) – C:\WINDOWS\System32\DRIVERS\kmxagent.sys (CA)
DRV - (KmxCF [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\KmxCF.sys (CA)
DRV - (KmxCfg [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\kmxcfg.sys (CA)
DRV - (KmxFile [System | Running]) – C:\WINDOWS\System32\DRIVERS\KmxFile.sys (CA)
DRV - (KmxFw [System | Running]) – C:\WINDOWS\System32\DRIVERS\kmxfw.sys (CA)
DRV - (KmxSbx [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\KmxSbx.sys (CA)
DRV - (KmxStart [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\kmxstart.sys (CA)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\system32\DRIVERS\omci.sys (Dell Inc)
DRV - (P1001VID [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\P1001Vid.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RTL8187B [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\RTL8187B.sys (Realtek Semiconductor Corporation )
DRV - (s616bus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\s616bus.sys (MCCI Corporation)
DRV - (s616mdfl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\s616mdfl.sys (MCCI Corporation)
DRV - (s616mdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\s616mdm.sys (MCCI Corporation)
DRV - (s616mgmt [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\s616mgmt.sys (MCCI Corporation)
DRV - (s616nd5 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\s616nd5.sys (MCCI Corporation)
DRV - (s616obex [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\s616obex.sys (MCCI Corporation)
DRV - (s616unic [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\s616unic.sys (MCCI Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (sonypvd3 [System | Stopped]) – C:\WINDOWS\system32\DRIVERS\sonypvd3.sys (Sony Corporation)
DRV - (sonypvf3 [System | Running]) – C:\WINDOWS\System32\drivers\sonypvf3.sys (Sony Corporation)
DRV - (sonypvl3 [Boot | Running]) – C:\WINDOWS\System32\drivers\sonypvl3.sys (Sony Corporation)
DRV - (sonypvt3 [System | Running]) – C:\WINDOWS\System32\drivers\sonypvt3.sys (Sony Corporation)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS (Sony Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (STAC97 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (tifm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tifm.sys (Texas Instruments)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (usbser [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usbser.sys (Microsoft Corporation)
DRV - (VET-FILT [System | Running]) – C:\WINDOWS\System32\drivers\vet-filt.sys (Computer Associates International, Inc.)
DRV - (VET-REC [System | Running]) – C:\WINDOWS\System32\drivers\vet-rec.sys (Computer Associates International, Inc.)
DRV - (VETEBOOT [On_Demand | Running]) – C:\WINDOWS\System32\drivers\veteboot.sys (Computer Associates International, Inc.)
DRV - (VETEFILE [System | Running]) – C:\WINDOWS\System32\drivers\vetefile.sys (Computer Associates International, Inc.)
DRV - (VETFDDNT [System | Running]) – C:\WINDOWS\System32\drivers\vetfddnt.sys (Computer Associates International, Inc.)
DRV - (VETMONNT [System | Running]) – C:\WINDOWS\System32\drivers\vetmonnt.sys (Computer Associates International, Inc.)
DRV - (wanatw [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://es.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl;…&channel;=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com/ig/dell?hl=en&cl;…&channel;=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11
FF - HKLM\software\mozilla\mozilla firefox 3.0.11\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/11 22:42:29 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\mozilla firefox 3.0.11\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/11 22:42:29 | 00,000,000 | —D | M]
[2009/02/21 17:09:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\mozilla\Extensions
[2009/02/21 17:09:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\mozilla\Extensions\{ae2cff10-0d52-4066-8be9-4abcf119fa79}
[2008/11/16 09:55:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/11 19:43:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\mozilla\Firefox\Profiles\wilktm3u.default\extensions
[2009/03/02 19:04:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\mozilla\Firefox\Profiles\wilktm3u.default\extensions\[removed]
[2008/11/16 09:54:40 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/06/11 22:42:29 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/06/11 22:42:19 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/11 22:42:19 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/02 20:46:56 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/02 20:46:56 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/02 20:46:57 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/02 20:46:57 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/02 20:46:57 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/02 20:46:57 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/02 20:46:57 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe (Dell Inc.)
O4 - HKLM..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl (CA, Inc.)
O4 - HKLM..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (CA, Inc.)
O4 - HKLM..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe (CA, Inc.)
O4 - HKLM..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" (CA, Inc.)
O4 - HKLM..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" (CA, Inc.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [FPCCSMiddleware] C:\Program Files\Fisher-Price\Computer Cool School\FPCCSMiddleware.exe ()
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (InstallShield Software Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall File not found
O4 - HKLM..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" (CA)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\Pahola Caicedo\Start Menu\Programs\Startup\rncsys32.exe (Gfsuroj Wunkuwaprol)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKLM\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: adobe.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mapmyfitness.com ([ws] * in Trusted sites)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/Facebo…toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Reg Error: Key error.)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}
http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {6414512b-b978-451d-a0d8-fcfdf33e833c}
http://update.microsoft.com/windowsupdate/…b?1244780141331 (WUWebControl Class)
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} http://mediaplayer.walmart.com/installer/install.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553550000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O28 - HKLM ShellExecuteHooks: {57B86673-276A-48B2-BAE7-C6DBB3020EB8} - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll (GRISOFT s.r.o.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/26 13:09:04 | 00,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/05/27 23:40:17 | 00,000,063 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\X\Shell\AutoRun\command - "" = C:\WINDOWS\system32\setup.exe – [2008/04/13 19:12:34 | 00,023,040 | —- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/12 20:22:01 | 00,000,000 | —D | M]
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[2009/06/12 20:22:01 | 00,501,760 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Pahola Caicedo\Desktop\OTL.exe
[2009/06/12 20:16:38 | 00,000,000 | —D | C] – C:\Rooter$
[2009/06/12 20:15:17 | 00,128,933 | —- | C] (Eric_71) – C:\Documents and Settings\Pahola Caicedo\Desktop\Rooter.exe
[2009/06/12 18:18:07 | 00,264,704 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Pahola Caicedo\Desktop\TFC.exe
[2009/06/11 23:19:11 | 00,000,236 | —- | C] () – C:\Documents and Settings\Pahola Caicedo\Desktop\register.bat
[2009/06/11 23:15:49 | 00,000,000 | —D | C] – C:\WINDOWS\LastGood
[2009/06/11 23:00:54 | 00,000,102 | —- | C] () – C:\Documents and Settings\Pahola Caicedo\Desktop\rename.bat
[2009/06/11 20:04:22 | 00,029,677 | —- | C] () – C:\Documents and Settings\Pahola Caicedo\Desktop\Config.bin
[2009/06/10 21:03:10 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/06/10 21:02:06 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Pahola Caicedo\Desktop\HJTInstall.exe
[2009/06/07 21:13:41 | 00,089,662 | —- | C] () – C:\WINDOWS\System32\drivers\d50103b0.sys
[2009/06/01 19:46:19 | 00,105,582 | —- | C] () – C:\Documents and Settings\Pahola Caicedo\My Documents\promocion_tmobile.tif
[2009/05/31 12:11:03 | 00,183,322 | —- | C] () – C:\Documents and Settings\Pahola Caicedo\My Documents\Certificado_nacimiento_Juan_Camilo.mdi
[2009/05/31 12:07:51 | 00,173,256 | —- | C] () – C:\Documents and Settings\Pahola Caicedo\My Documents\Certificado_nacimiento_Sebastian2.mdi
[2009/05/31 12:03:20 | 00,577,460 | —- | C] () – C:\Documents and Settings\Pahola Caicedo\My Documents\Certificado_nacimiento_Sebastian.mdi
[2009/05/31 12:01:13 | 00,000,000 | —D | C] – C:\Documents and Settings\Pahola Caicedo\My Documents\My Digital Editions
[2009/05/31 11:56:19 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2009/05/31 11:55:54 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2009/03/14 14:09:01 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2008/10/14 22:26:39 | 00,099,672 | R— | C] () – C:\WINDOWS\dibapi32.dll
[2008/10/14 22:26:38 | 00,073,728 | R— | C] () – C:\WINDOWS\System32\GABvfw.dll
[2008/10/14 22:26:38 | 00,036,352 | R— | C] () – C:\WINDOWS\System32\preview.dll
[2008/10/14 22:26:33 | 00,005,604 | R— | C] () – C:\WINDOWS\System32\drivers\GABscan.sys
[2008/01/19 11:03:24 | 00,166,912 | —- | C] () – C:\WINDOWS\System32\Lame_enc.dll
[2007/10/14 22:24:49 | 00,000,937 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2007/08/13 10:18:59 | 00,009,136 | —- | C] () – C:\WINDOWS\System32\INETWH16.DLL
[2007/07/25 08:24:28 | 00,815,104 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2007/03/10 06:51:48 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/03/03 17:05:43 | 00,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2007/03/03 17:05:30 | 00,000,171 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2007/02/01 02:03:00 | 00,372,736 | —- | C] () – C:\WINDOWS\System32\hpgt2300.dll
[2006/12/24 20:17:55 | 00,000,223 | —- | C] () – C:\WINDOWS\System32\P1001Twn.ini
[2006/09/17 00:45:59 | 00,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2006/07/02 09:16:25 | 00,000,088 | RHS- | C] () – C:\WINDOWS\System32\214DDB9A7C.sys
[2006/06/25 08:06:51 | 00,006,580 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/06/18 11:10:16 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/30 00:14:55 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/05/30 00:04:10 | 00,712,704 | —- | C] () – C:\WINDOWS\System32\DellSystemRestore.dll
[2006/05/29 23:59:02 | 00,000,301 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/05/29 23:16:32 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2006/05/29 23:16:28 | 00,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2006/05/29 23:16:24 | 00,000,390 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/18 13:47:26 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 13:12:05 | 00,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 13:01:18 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:51:28 | 00,000,677 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/10 12:51:26 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2003/02/19 21:20:16 | 00,225,280 | —- | C] () – C:\WINDOWS\System32\tifmicon.dll
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/15 17:54:04 | 00,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2001/07/06 17:30:00 | 00,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
========== Files - Modified Within 30 Days ==========
[2009/06/12 20:32:55 | 00,089,662 | —- | M] () – C:\WINDOWS\System32\drivers\d50103b0.sys
[2009/06/12 20:22:01 | 00,501,760 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Pahola Caicedo\Desktop\OTL.exe
[2009/06/12 20:15:22 | 00,128,933 | —- | M] (Eric_71) – C:\Documents and Settings\Pahola Caicedo\Desktop\Rooter.exe
[2009/06/12 20:09:27 | 00,477,404 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/06/12 20:09:27 | 00,405,878 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/06/12 20:09:27 | 00,064,262 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/06/12 20:05:43 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/06/12 20:04:34 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/06/12 20:04:30 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Pahola Caicedo\Local Settings\desktop.ini
[2009/06/12 20:04:26 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/06/12 20:04:25 | 51,850,8544 | -HS- | M] () – C:\hiberfil.sys
[2009/06/12 18:25:24 | 00,421,418 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2009/06/12 18:25:24 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2009/06/12 18:25:24 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2009/06/12 18:25:24 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2009/06/12 18:25:24 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2009/06/12 18:25:24 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2009/06/12 18:25:24 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2009/06/12 18:25:24 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2009/06/12 18:18:08 | 00,264,704 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Pahola Caicedo\Desktop\TFC.exe
[2009/06/11 23:19:11 | 00,000,236 | —- | M] () – C:\Documents and Settings\Pahola Caicedo\Desktop\register.bat
[2009/06/11 23:00:54 | 00,000,102 | —- | M] () – C:\Documents and Settings\Pahola Caicedo\Desktop\rename.bat
[2009/06/11 20:04:24 | 00,029,677 | —- | M] () – C:\Documents and Settings\Pahola Caicedo\Desktop\Config.bin
[2009/06/10 21:03:11 | 00,001,734 | —- | M] () – C:\Documents and Settings\Pahola Caicedo\Desktop\Hijackthis.lnk
[2009/06/10 21:02:07 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Pahola Caicedo\Desktop\HJTInstall.exe
[2009/06/10 20:33:16 | 00,000,532 | —- | M] () – C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Pahola Caicedo at 7 25 PM.job
[2009/06/01 19:46:22 | 00,105,582 | —- | M] () – C:\Documents and Settings\Pahola Caicedo\My Documents\promocion_tmobile.tif
[2009/05/31 12:11:03 | 00,183,322 | —- | M] () – C:\Documents and Settings\Pahola Caicedo\My Documents\Certificado_nacimiento_Juan_Camilo.mdi
[2009/05/31 12:07:51 | 00,173,256 | —- | M] () – C:\Documents and Settings\Pahola Caicedo\My Documents\Certificado_nacimiento_Sebastian2.mdi
[2009/05/31 12:03:20 | 00,577,460 | —- | M] () – C:\Documents and Settings\Pahola Caicedo\My Documents\Certificado_nacimiento_Sebastian.mdi
[2009/05/16 13:47:04 | 00,243,920 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/05/16 12:29:03 | 00,000,535 | —- | M] () – C:\WINDOWS\System32\mapisvc.inf
========== LOP Check ==========
[2009/06/12 20:05:35 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2006/11/30 21:02:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/05/29 23:58:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2009/02/21 13:15:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2007/11/11 18:21:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2007/10/19 19:43:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2008/03/22 23:42:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2008/10/05 13:17:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fisher-Price
[2006/09/20 09:05:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/10/19 22:37:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/03/27 23:01:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2007/03/03 17:10:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2006/05/29 23:59:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2007/10/19 15:38:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2006/05/30 00:10:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2006/09/17 00:27:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2006/09/01 21:44:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
[2009/04/26 15:08:19 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/05/31 11:55:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2006/05/29 23:58:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2004/08/10 13:13:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2008/11/23 14:07:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sling Media
[2009/05/31 11:56:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2007/10/24 20:44:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/01/19 18:27:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/05/29 23:58:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/06/17 23:51:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/03/13 20:26:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2007/05/14 14:26:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/06/07 21:12:12 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data
[2008/01/16 23:37:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Adobe
[2006/11/30 21:03:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\AdobeUM
[2008/03/22 23:42:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Amazon
[2009/02/21 13:15:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\AVS4YOU
[2009/02/21 13:55:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Broad Intelligence
[2006/07/06 13:49:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Corel Photo Album
[2006/06/29 21:45:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\CyberLink
[2009/02/07 12:30:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\GARMIN
[2006/12/16 18:55:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Google
[2007/10/19 22:49:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Grisoft
[2004/08/10 13:08:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Identities
[2007/05/15 23:38:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Joost
[2006/12/23 11:18:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Leadertech
[2007/09/04 22:54:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Macromedia
[2006/07/09 00:43:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\McAfee.com Personal Firewall
[2009/04/29 09:51:59 | 00,000,000 | –SD | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Microsoft
[2009/03/02 22:45:47 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Move Networks
[2008/11/16 09:55:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Mozilla
[2006/10/27 22:43:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Snapfish
[2006/12/23 11:18:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Sonic
[2006/05/29 23:51:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Sun
[2006/05/30 00:03:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Symantec
[2007/04/22 22:13:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\Viewpoint
[2007/05/17 23:35:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\vlc
[2008/04/19 00:44:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Pahola Caicedo\Application Data\WinRAR
[2009/06/10 20:33:16 | 00,000,532 | —- | M] () – C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Pahola Caicedo at 7 25 PM.job
[2004/08/04 05:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/06/12 20:04:34 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C1F4198F
< End of report >
————————————————————————————————————————————————————————
OTL Extras logfile created on: 6/12/2009 8:23:45 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Pahola Caicedo\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
494.42 Mb Total Physical Memory | 74.45 Mb Available Physical Memory | 15.06% Memory free
1.13 Gb Paging File | 0.78 Gb Available in Paging File | 68.94% Paging File free
Paging file location(s): C:\pagefile.sys 744 1488 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.86 Gb Total Space | 24.08 Gb Free Space | 26.80% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 17.26 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PAHOLAP
Current User Name: Pahola Caicedo
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ca personal firewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0D917C5F-1CF9-42E0-899F-78AC10576405}" = First Step Guide
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F40754C-F1FD-43df-B73E-9DA38399CDD6}" = hpf_ProductContext
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{14A67CE0-4F30-4607-885B-43EE27BAC746}" = Readme
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2A6282FF-B75B-463F-90F5-0A43732F690D}" = Broadcom Management Programs
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZeroInstallers
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.9
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{6F30B469-5ED7-4734-8252-B9BC962A2AB3}" = PCIxx20
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{7ADE9F27-A175-447F-A4B4-B05FA82735E1}" = HP Deskjet 6900 series
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{803805A4-A3F7-4504-8B19-9A63BC8A4551}" = Fisher-Price Computer Cool School
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A360821C-6B51-4EE4-A7E5-5E14B15004CD}" = Sony DVD Handycam USB Driver 2
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{AB6E84D0-AA30-11D1-A245-00A024C41DAA}" = Tasco SkyWatch (Remove only)
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}" = Dell Media Experience
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B6884A07-0305-47AE-9969-8F26FADC17DE}" = Games, Music, & Photos Launcher
"{BDBAAB1B-B364-465E-931D-4E2E2F0E609A}" = CA Personal Firewall
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{CB1F3886-AE9F-46fb-8325-6B0718989285}" = dj_taplugin
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007
"{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}" = Search Assist
"{E2741785-8993-4BB6-A76F-35244DC4FFB0}" = SlingPlayer
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{F18E8A0F-BE99-4305-96A5-6C0FD9D7D999}" = mobile PhoneTools
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"America Online us" = America Online (Choose which version to remove)
"AOL Connectivity Services" = AOL Connectivity Services
"AOLCoach" = AOL Coach Version 1.0(Build:20040229.1 en)
"AVGAntiSpyware75" = AVG Anti-Spyware 7.5
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CNXT_MODEM_PCI_VEN_8086&DEV;_24x6&SUBSYS;_542214F1" = Conexant D480 MDC V.9x Modem
"Creative WebCam" = Creative WebCam Driver (1.02.08.0807)
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"eTrust Suite Personal" = CA Internet Security Suite
"HijackThis" = HijackThis 2.0.2
"Hijackthis_is1" = Hijackthis 1.99.1
"InstallShield_{2A6282FF-B75B-463F-90F5-0A43732F690D}" = Broadcom Management Programs
"InstallShield_{6F30B469-5ED7-4734-8252-B9BC962A2AB3}" = Texas Instruments PCIxx20 drivers.
"InstallShield_{803805A4-A3F7-4504-8B19-9A63BC8A4551}" = Fisher-Price Computer Cool School
"InstallShield_{E2741785-8993-4BB6-A76F-35244DC4FFB0}" = SlingPlayer
"LiveUpdate" = LiveUpdate 2.6 (Symantec Corporation)
"MediaCoder" = MediaCoder 0.6.2
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Move Networks Player_is1" = Move Networks Player for Internet Explorer
"mozilla firefox (3.0.11)" = Mozilla Firefox (3.0.11)
"MSN Music Assistant" = MSN Music Assistant
"MSNINST" = MSN
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"SlingMedia.SlingSDK_is1" = Slingbox Platform SDK [removed]
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Treasures of Knowledge" = Treasures of Knowledge
"ViewpointMediaPlayer" = Viewpoint Media Player
"VobSub" = VobSub v2.23 (Remove Only)
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"XviD & MP3 Codec Pack_is1" = XviD & MP3 Codec Pack (remove only)
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)
"Xvid_is1" = Xvid 1.2.1 final uninstall
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 6/10/2009 9:38:26 PM | Computer Name = PAHOLAP | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x00406472.
Error - 6/10/2009 9:38:32 PM | Computer Name = PAHOLAP | Source = Application Error | ID = 1001
Description = Fault bucket 1017681263.
Error - 6/10/2009 11:21:06 PM | Computer Name = PAHOLAP | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 6/10/2009 11:21:12 PM | Computer Name = PAHOLAP | Source = Application Hang | ID = 1001
Description = Fault bucket 734037209.
Error - 6/11/2009 8:29:43 PM | Computer Name = PAHOLAP | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x00406472.
Error - 6/12/2009 12:10:25 AM | Computer Name = PAHOLAP | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x00406472.
Error - 6/12/2009 12:15:25 AM | Computer Name = PAHOLAP | Source = Application Error | ID = 1001
Description = Fault bucket 1017681263.
Error - 6/12/2009 12:31:52 AM | Computer Name = PAHOLAP | Source = UmxAgent | ID = 108
Description = Cannot open mailslot of Ask User client. Product 0x1, Session 0, Error
0x2.
Error - 6/12/2009 7:17:34 PM | Computer Name = PAHOLAP | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x00406472.
Error - 6/12/2009 9:06:16 PM | Computer Name = PAHOLAP | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module unknown, version 0.0.0.0, fault address 0x00406472.
[ System Events ]
Error - 6/12/2009 12:19:50 AM | Computer Name = PAHOLAP | Source = Service Control Manager | ID = 7000
Description = The Automatic Updates service failed to start due to the following
error: %%2
Error - 6/12/2009 12:20:06 AM | Computer Name = PAHOLAP | Source = Service Control Manager | ID = 7028
Description = The wuauserv Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
Error - 6/12/2009 12:22:13 AM | Computer Name = PAHOLAP | Source = Service Control Manager | ID = 7028
Description = The wuauserv Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
Error - 6/12/2009 12:22:28 AM | Computer Name = PAHOLAP | Source = Service Control Manager | ID = 7028
Description = The wuauserv Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
Error - 6/12/2009 12:22:59 AM | Computer Name = PAHOLAP | Source = DCOM | ID = 10005
Description = DCOM got error "%2" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 6/12/2009 12:23:00 AM | Computer Name = PAHOLAP | Source = Service Control Manager | ID = 7000
Description = The Automatic Updates service failed to start due to the following
error: %%2
Error - 6/12/2009 12:23:17 AM | Computer Name = PAHOLAP | Source = Service Control Manager | ID = 7028
Description = The wuauserv Registry key denied access to SYSTEM account programs
so the Service Control Manager took ownership of the Registry key.
Error - 6/12/2009 7:15:28 PM | Computer Name = PAHOLAP | Source = Service Control Manager | ID = 7000
Description = The Automatic Updates service failed to start due to the following
error: %%2
Error - 6/12/2009 7:18:59 PM | Computer Name = PAHOLAP | Source = Service Control Manager | ID = 7034
Description = The Pml Driver HPZ12 service terminated unexpectedly. It has done
this 1 time(s).
Error - 6/12/2009 9:05:47 PM | Computer Name = PAHOLAP | Source = Service Control Manager | ID = 7000
Description = The Automatic Updates service failed to start due to the following
error: %%2
< End of report >