OTL Extras logfile created on: 7/14/2009 6:58:35 AM - Run 1
OTL by OldTimer - Version 3.0.7.1 Folder = C:\Documents and Settings\user\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 68.71% Memory free
3.83 Gb Paging File | 3.13 Gb Available in Paging File | 81.67% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 213.28 Gb Free Space | 91.58% Space Free | Partition Type: NTFS
Drive D: | 590.85 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: USER-WF8HS4UOJS
Current User Name: user
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\CA Personal Firewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2007/03/08 01:25:56 | 09,950,760 | —- | M] (Intuit, Inc.) – C:\Program Files\TurboTax\Deluxe 2006\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax
[2007/07/31 11:08:09 | 03,679,784 | —- | M] (Intuit, Inc.) – C:\Program Files\TurboTax\Deluxe 2006\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager
[2008/04/13 19:12:21 | 00,142,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console
File not found – C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online
[2008/11/24 22:16:44 | 01,020,776 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote
[2008/04/13 13:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/03/05 23:29:49 | 10,343,712 | —- | M] (Intuit, Inc.) – C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax
[2007/10/22 19:56:52 | 03,597,600 | —- | M] (Intuit, Inc.) – C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager
[2008/04/13 19:12:25 | 01,414,656 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console
[2008/10/10 06:45:26 | 00,013,088 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server
[2006/10/23 07:50:37 | 00,071,216 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\acs\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer
[2006/10/23 07:50:35 | 00,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\acs\AOLacsd.exe:*:Enabled:AOL Connectivity Service
[2008/06/24 13:34:50 | 00,041,824 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\1245198878\ee\aolsoftware.exe:*:Enabled:AOL Shared Components
[2008/11/06 06:42:59 | 00,039,208 | —- | M] (AOL, LLC.) – C:\Program Files\AOL 9.1a\waol.exe:*:Enabled:AOL
[2007/04/02 07:33:32 | 00,063,120 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed
[2006/11/03 02:17:27 | 00,010,800 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader
[2008/09/02 12:41:04 | 00,206,120 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL System Information
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{12BDDF23-B1DB-49C8-92D3-3E6841CCED61}" = Microsoft Streets and Trips 2002
"{1367D815-EC9F-4e2f-9FB9-E40A075AD19B}" = DNAMigrator
"{2681A52E-FCFA-4982-A030-7B652BDD346C}" = CA Personal Firewall
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 14
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{2D87E961-577B-492B-AD54-1368680FB9A7}" = Virtual Earth 3D (Beta)
"{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}" = TurboTax ItsDeductible 2005
"{3215EBED-1D06-42fb-A05C-A752A46FB24C}" = Canon MP530
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36495C59-089C-49D1-BD15-9E5BD86DC9A1}" = ItsDeductible Express
"{3CBBB9E3-9F95-476E-AA0D-A79DA1DC9512}" = Fence Designer 5.7.4
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{7F1B3341-A94E-4F5C-B587-CA0EB964221E}" = Microsoft Money Shared Libraries
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A1B7B9B3-E1D2-41CA-9B4A-F18DC2710704}" = Microsoft Works 6.0
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2
"{AEAD18F3-6481-4ef4-96B5-A24D5ADAC30D}" = CA Anti-Spyware
"{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}" = Works Synchronization
"{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom Gigabit Integrated Controller
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1E693A4-B1D5-4DCD-B68D-2087835B7184}" = ScanSoft OmniPage SE 4.0
"{C3A439E4-7303-491F-A678-CEA36A87D517}" = Microsoft Works Suite Add-in for Microsoft Word
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CDB98E2F-7B2A-42C2-B718-F1F6B31586DF}" = CA Website Inspector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF5193F7-6B37-11D5-B7D2-00AA00A204F1}" = Microsoft Money 2002 System Pack
"{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}" = Presto! PageManager 7.15.14
"{DC19E750-988B-4005-A355-85EF66055EFE}" = Works Suite OS Pack
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{E7298FD5-1386-11D5-8D6C-0050DAD32D95}" = Microsoft Money 2002
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"{ED95E1BA-8C35-4D78-8A20-FD5A728711E2}" = Broderbund Family Lawyer
"{F05A5232-CE5E-4274-AB27-44EB8105898D}" = CA Pest Patrol Realtime Protection
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AOL Toolbar" = AOL Toolbar
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F30&SUBSYS;_205514F1" = PCI SoftV92 Modem
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"eTrust Suite Personal" = CA Internet Security Suite
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{3CBBB9E3-9F95-476E-AA0D-A79DA1DC9512}" = Fence Designer 5.7.4
"InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom Gigabit Integrated Controller
"InstallShield_{ED95E1BA-8C35-4D78-8A20-FD5A728711E2}" = Broderbund Family Lawyer
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate1.6" = LiveUpdate 1.6 (Symantec Corporation)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Money2008b" = Microsoft Money Plus
"MP Navigator 2.2" = Canon MP Navigator 2.2
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Norton CleanSweep" = Norton CleanSweep
"PROSet" = Intel® PRO Network Adapters and Drivers
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"SeaStorm 3D Screensaver" = SeaStorm 3D Screensaver (remove only)
"SMSERIAL" = Motorola SM56 Speakerphone Modem
"TurboTax 2008" = TurboTax 2008
"TurboTax Deluxe 2004" = TurboTax Deluxe 2004
"TurboTax Deluxe 2005" = TurboTax Deluxe 2005
"TurboTax Deluxe 2007" = TurboTax Deluxe 2007
"TurboTax Deluxe Deduction Maximizer 2006" = TurboTax Deluxe Deduction Maximizer 2006
"VETWIN32Vp5" = CA Anti-Virus
"ViewpointMediaPlayer" = Viewpoint Media Player
"Webshots Desktop_is1" = Webshots Desktop
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2002Setup" = Microsoft Works 2002 Setup Launcher
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Sansa Updater" = Sansa Updater
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/30/2009 5:21:48 PM | Computer Name = USER-WF8HS4UOJS | Source = .NET Runtime 2.0 Error Reporting | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16827, stamp 49a74cd5,
faulting module unknown, version 0.0.0.0, stamp 00000000, debug? 0, fault address
0xee7b7f3e.
Error - 5/4/2009 8:46:28 PM | Computer Name = USER-WF8HS4UOJS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16827, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 5/7/2009 11:41:54 AM | Computer Name = USER-WF8HS4UOJS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 5/7/2009 11:41:54 AM | Computer Name = USER-WF8HS4UOJS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 5/7/2009 11:41:54 AM | Computer Name = USER-WF8HS4UOJS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 5/9/2009 2:13:06 PM | Computer Name = USER-WF8HS4UOJS | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16827, faulting
module mshtml.dll, version 7.0.6000.16825, fault address 0x000a75d7.
Error - 5/9/2009 2:13:13 PM | Computer Name = USER-WF8HS4UOJS | Source = Application Error | ID = 1001
Description = Fault bucket 1228213560.
Error - 5/13/2009 12:59:27 AM | Computer Name = USER-WF8HS4UOJS | Source = Google Update | ID = 20
Description =
Error - 5/13/2009 1:59:27 AM | Computer Name = USER-WF8HS4UOJS | Source = Google Update | ID = 20
Description =
Error - 5/13/2009 2:59:27 AM | Computer Name = USER-WF8HS4UOJS | Source = Google Update | ID = 20
Description =
[ OSession Events ]
Error - 11/4/2008 9:36:50 AM | Computer Name = USER-WF8HS4UOJS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 180
seconds with 60 seconds of active time. This session ended with a crash.
Error - 11/4/2008 9:43:58 AM | Computer Name = USER-WF8HS4UOJS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 331
seconds with 60 seconds of active time. This session ended with a crash.
Error - 11/4/2008 9:48:43 AM | Computer Name = USER-WF8HS4UOJS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 262
seconds with 240 seconds of active time. This session ended with a crash.
Error - 11/4/2008 9:52:27 AM | Computer Name = USER-WF8HS4UOJS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 159
seconds with 0 seconds of active time. This session ended with a crash.
Error - 11/4/2008 10:13:10 AM | Computer Name = USER-WF8HS4UOJS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 226
seconds with 60 seconds of active time. This session ended with a crash.
Error - 11/4/2008 10:13:51 AM | Computer Name = USER-WF8HS4UOJS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 23
seconds with 0 seconds of active time. This session ended with a crash.
Error - 11/4/2008 10:15:26 AM | Computer Name = USER-WF8HS4UOJS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 31
seconds with 0 seconds of active time. This session ended with a crash.
Error - 11/4/2008 10:18:47 AM | Computer Name = USER-WF8HS4UOJS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 165
seconds with 60 seconds of active time. This session ended with a crash.
Error - 11/4/2008 10:19:51 AM | Computer Name = USER-WF8HS4UOJS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 39
seconds with 0 seconds of active time. This session ended with a crash.
Error - 11/4/2008 10:27:44 AM | Computer Name = USER-WF8HS4UOJS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 53
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 7/3/2009 10:48:41 PM | Computer Name = USER-WF8HS4UOJS | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.
Error - 7/4/2009 8:04:50 AM | Computer Name = USER-WF8HS4UOJS | Source = Service Control Manager | ID = 7000
Description = The Genesys Logic USB Scanner Controller NT 5.0 service failed to
start due to the following error: %%2
Error - 7/5/2009 3:06:41 AM | Computer Name = USER-WF8HS4UOJS | Source = Service Control Manager | ID = 7000
Description = The Genesys Logic USB Scanner Controller NT 5.0 service failed to
start due to the following error: %%2
Error - 7/5/2009 3:07:42 AM | Computer Name = USER-WF8HS4UOJS | Source = DCOM | ID = 10010
Description = The server {1F87137D-0E7C-44D5-8C73-4EFFB68962F2} did not register
with DCOM within the required timeout.
Error - 7/5/2009 11:12:09 PM | Computer Name = USER-WF8HS4UOJS | Source = Service Control Manager | ID = 7000
Description = The Genesys Logic USB Scanner Controller NT 5.0 service failed to
start due to the following error: %%2
Error - 7/7/2009 4:14:32 PM | Computer Name = USER-WF8HS4UOJS | Source = Service Control Manager | ID = 7000
Description = The Genesys Logic USB Scanner Controller NT 5.0 service failed to
start due to the following error: %%2
Error - 7/8/2009 1:37:36 PM | Computer Name = USER-WF8HS4UOJS | Source = Service Control Manager | ID = 7000
Description = The Genesys Logic USB Scanner Controller NT 5.0 service failed to
start due to the following error: %%2
Error - 7/13/2009 5:41:04 PM | Computer Name = USER-WF8HS4UOJS | Source = Service Control Manager | ID = 7000
Description = The Genesys Logic USB Scanner Controller NT 5.0 service failed to
start due to the following error: %%2
Error - 7/13/2009 8:03:25 PM | Computer Name = USER-WF8HS4UOJS | Source = Service Control Manager | ID = 7000
Description = The Genesys Logic USB Scanner Controller NT 5.0 service failed to
start due to the following error: %%2
Error - 7/13/2009 10:56:10 PM | Computer Name = USER-WF8HS4UOJS | Source = Print | ID = 6161
Description = The document
http://forums.whatthetech.com/Driving_me_n…erything_frezze
owned by user failed to print on printer Canon MP530 Series Printer. Data type:
NT EMF 1.008. Size of the spool file in bytes: 2490368. Number of bytes printed:
358468. Total number of pages in the document: 10. Number of pages printed: 0.
Client machine: \\USER-WF8HS4UOJS. Win32 error code returned by the print processor:
13 (0xd).
< End of report >
OTL logfile created on: 7/14/2009 6:58:35 AM - Run 1
OTL by OldTimer - Version 3.0.7.1 Folder = C:\Documents and Settings\user\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 68.71% Memory free
3.83 Gb Paging File | 3.13 Gb Available in Paging File | 81.67% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 213.28 Gb Free Space | 91.58% Space Free | Partition Type: NTFS
Drive D: | 590.85 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: USER-WF8HS4UOJS
Current User Name: user
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2009/01/09 17:25:52 | 00,797,176 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
PRC - [2009/01/09 17:25:52 | 00,154,104 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
PRC - [2008/09/02 14:53:28 | 00,289,272 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
PRC - [2009/01/09 17:25:52 | 01,153,528 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
PRC - [2006/10/23 07:50:35 | 00,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
PRC - [2008/11/01 20:06:18 | 00,144,696 | —- | M] (Computer Associates International, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
PRC - [2009/03/01 03:58:17 | 00,128,240 | —- | M] (Computer Associates International, Inc.) – C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
PRC - [2008/10/10 06:45:26 | 00,013,088 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2008/09/29 20:48:58 | 00,283,888 | —- | M] (CA, Inc.) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
PRC - [2009/06/30 01:34:57 | 00,133,104 | —- | M] (Google Inc.) – C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
PRC - [2009/05/21 11:34:05 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/03/01 03:58:17 | 00,292,080 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
PRC - [2008/04/13 19:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2009/03/05 03:57:54 | 00,435,440 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
PRC - [2009/03/01 03:58:17 | 00,259,312 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
PRC - [2005/09/20 12:32:24 | 00,077,824 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\hkcmd.exe
PRC - [2005/09/20 12:36:20 | 00,114,688 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\igfxpers.exe
PRC - [2004/10/14 16:42:54 | 01,404,928 | —- | M] (Analog Devices, Inc.) – C:\Program Files\Analog Devices\Core\smax4pnp.exe
PRC - [2009/03/01 03:58:18 | 00,374,000 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\casc.exe
PRC - [2009/03/01 03:58:17 | 00,271,600 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
PRC - [2006/11/04 03:51:17 | 00,544,768 | R— | M] (Motorola Inc.) – C:\WINDOWS\sm56hlpr.exe
PRC - [1999/04/15 05:00:00 | 00,028,672 | —- | M] (Symantec Corporation) – C:\Program Files\Norton CleanSweep\Qdcsfs.exe
PRC - [2006/10/11 12:45:12 | 00,075,304 | —- | M] (ScanSoft, Inc.) – C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
PRC - [2009/03/05 03:57:54 | 00,636,144 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
PRC - [2009/01/21 09:20:39 | 00,185,872 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2001/08/16 23:41:58 | 00,028,738 | —- | M] (Microsoft® Corporation) – C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
PRC - [2009/05/21 11:34:07 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008/06/24 13:34:50 | 00,041,824 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\1245198878\ee\AOLSoftware.exe
PRC - [2009/06/30 16:59:52 | 00,079,872 | —- | M] (SanDisk Corporation) – C:\Documents and Settings\user\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2009/03/01 03:58:16 | 00,222,448 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
PRC - [2006/10/09 14:56:34 | 01,650,688 | —- | M] (Webshots.com) – C:\Program Files\Webshots\Webshots.scr
PRC - [2006/10/23 14:04:42 | 00,001,536 | —- | M] () – c:\program files\common files\aol\1245198878\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
PRC - [2008/06/24 13:34:50 | 00,041,824 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\1245198878\ee\aolsoftware.exe
PRC - [2008/04/13 19:12:41 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wscntfy.exe
PRC - [2008/11/06 06:42:59 | 00,039,208 | —- | M] (AOL, LLC.) – C:\Program Files\AOL 9.1a\waol.exe
PRC - [2008/11/06 06:42:59 | 00,054,568 | —- | M] (AOL, LLC.) – C:\Program Files\AOL 9.1a\shellmon.exe
PRC - [2007/03/13 09:41:02 | 00,042,032 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\1245198878\ee\anotify.exe
PRC - [2007/04/02 07:33:32 | 00,063,120 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
PRC - [2009/07/14 06:57:44 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - [2006/10/23 07:50:35 | 00,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe – (AOL ACS [Auto | Running])
SRV - [2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2009/03/01 03:58:17 | 00,259,312 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe – (CaCCProvSP [On_Demand | Running])
SRV - [2008/11/01 20:06:18 | 00,144,696 | —- | M] (Computer Associates International, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe – (CAISafe [Auto | Running])
SRV - [2009/03/01 03:58:17 | 00,128,240 | —- | M] (Computer Associates International, Inc.) – C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe – (ccSchedulerSVC [Auto | Running])
SRV - [2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/29 21:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009/03/16 22:29:55 | 00,133,104 | —- | M] (Google Inc.) – C:\Program Files\Google\Update\GoogleUpdate.exe – (gupdate1c9a6b0afb47928 [Auto | Stopped])
SRV - [2009/03/25 07:37:45 | 00,183,280 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [Auto | Stopped])
SRV - [2008/04/13 19:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2008/07/29 19:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2008/10/10 06:45:26 | 00,013,088 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe – (IntuitUpdateService [Auto | Running])
SRV - [2008/09/29 20:48:58 | 00,283,888 | —- | M] (CA, Inc.) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe – (ITMRTSVC [Auto | Running])
SRV - [2009/05/21 11:34:05 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2008/07/29 19:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/11/04 01:06:28 | 00,441,712 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2009/03/01 03:58:16 | 00,222,448 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe – (PPCtlPriv [On_Demand | Running])
SRV - [2009/01/09 17:25:52 | 01,153,528 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe – (UmxAgent [Auto | Running])
SRV - [2009/01/09 17:25:52 | 00,797,176 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe – (UmxCfg [Auto | Running])
SRV - [2009/01/09 17:25:52 | 00,154,104 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe – (UmxFwHlp [Auto | Running])
SRV - [2008/09/02 14:53:28 | 00,289,272 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe – (UmxPol [Auto | Running])
SRV - [2009/03/01 03:58:17 | 00,292,080 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe – (VETMSGNT [Auto | Running])
SRV - [2006/10/18 21:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2003/07/22 13:10:50 | 00,024,544 | R— | M] (Licensed for Sysinfo Lab) – C:\WINDOWS\System32\DRIVERS\ASTRA32.SYS – (ASTRA32 [On_Demand | Stopped])
DRV - [2004/08/23 16:49:30 | 00,121,472 | —- | M] (Broadcom Corporation) – C:\WINDOWS\System32\DRIVERS\b57xp32.sys – (b57w2k [On_Demand | Running])
DRV - [2006/10/06 15:49:00 | 00,044,224 | R— | M] (BVRP Software) – C:\WINDOWS\System32\drivers\BVRPMPR5.SYS – (BVRPMPR5 [On_Demand | Stopped])
DRV - [2003/10/28 13:51:04 | 00,130,048 | R— | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\e1000325.sys – (E1000 [On_Demand | Stopped])
DRV - [2001/08/17 14:11:06 | 00,066,591 | —- | M] (3Com Corporation) – C:\WINDOWS\System32\DRIVERS\el90xbc5.sys – (EL90XBC [On_Demand | Stopped])
DRV - [2004/09/29 02:35:30 | 00,219,136 | R— | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys – (HSFHWBS2 [On_Demand | Stopped])
DRV - [2004/09/29 02:33:50 | 01,036,928 | R— | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSF_DP.sys – (HSF_DP [On_Demand | Stopped])
DRV - [2005/09/20 13:00:54 | 01,302,332 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys – (ialm [On_Demand | Running])
DRV - [2009/01/09 17:25:52 | 00,072,696 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\kmxagent.sys – (KmxAgent [System | Running])
DRV - [2009/01/09 17:25:52 | 00,144,376 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\KmxCF.sys – (KmxCF [Auto | Running])
DRV - [2009/01/09 17:25:52 | 00,205,304 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\kmxcfg.sys – (KmxCfg [On_Demand | Running])
DRV - [2008/08/25 16:18:58 | 00,052,728 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\KmxFile.sys – (KmxFile [System | Running])
DRV - [2009/01/09 17:25:52 | 00,115,704 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\kmxfw.sys – (KmxFw [System | Running])
DRV - [2008/07/30 14:38:08 | 00,058,872 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\KmxSbx.sys – (KmxSbx [Auto | Running])
DRV - [2009/01/09 17:25:52 | 00,107,512 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\kmxstart.sys – (KmxStart [Boot | Running])
DRV - [2004/03/16 23:04:14 | 00,013,059 | R— | M] (Conexant) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys – (mdmxsdk [Auto | Running])
DRV - [2001/08/17 16:57:38 | 00,016,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\MODEMCSA.sys – (MODEMCSA [On_Demand | Running])
DRV - [2003/07/16 11:36:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007/11/13 05:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2004/09/17 11:02:54 | 00,732,928 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\System32\drivers\senfilt.sys – (senfilt [On_Demand | Running])
DRV - [2006/11/04 03:51:17 | 00,923,826 | R— | M] (Motorola Inc.) – C:\WINDOWS\System32\DRIVERS\smserial.sys – (smserial [On_Demand | Running])
DRV - [2005/03/22 13:08:40 | 00,260,224 | —- | M] (Analog Devices, Inc.) – C:\WINDOWS\System32\drivers\smwdm.sys – (smwdm [On_Demand | Running])
DRV - [2001/08/17 13:56:16 | 00,007,552 | —- | M] (Sony Corporation) – C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS – (SONYPVU1 [On_Demand | Stopped])
DRV - [2009/03/01 03:58:17 | 00,026,352 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-filt.sys – (VET-FILT [System | Running])
DRV - [2009/03/01 03:58:17 | 00,021,104 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-rec.sys – (VET-REC [System | Running])
DRV - [2008/12/05 23:50:36 | 00,108,368 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\veteboot.sys – (VETEBOOT [On_Demand | Running])
DRV - [2008/12/05 23:50:36 | 00,880,560 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetefile.sys – (VETEFILE [System | Running])
DRV - [2009/03/01 03:58:17 | 00,021,488 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetfddnt.sys – (VETFDDNT [System | Running])
DRV - [2009/03/01 03:58:17 | 00,161,008 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetmonnt.sys – (VETMONNT [System | Running])
DRV - [2003/01/10 16:13:04 | 00,033,588 | R— | M] (America Online, Inc.) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys – (wanatw [On_Demand | Running])
DRV - [2004/09/29 02:34:24 | 00,702,592 | R— | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys – (winachsf [On_Demand | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/src…autosearch.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - URLSearchHook: {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll File not found
IE - URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\{e9259cba-e7ad-4f74-863f-ef9fe935394d}: C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\Firefox [2009/01/23 13:29:46 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{8b02914c-4e6b-4410-90e1-1a2b1b69b12d}: C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\Firefox [2009/01/23 13:29:45 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2009/01/21 09:21:10 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/05/20 09:43:50 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/03/31 18:00:25 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{8b02914c-4e6b-4410-90e1-1a2b1b69b12d}: C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\Firefox [2009/01/23 13:29:45 | 00,000,000 | —D | M]
O1 HOSTS File: (262898 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 9120 more lines…
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (AOL Toolbar Loader) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O2 - BHO: (eMusic Toolbar) - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (CA Toolbar Helper) - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll (CallingID Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (CA Toolbar) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll (CallingID Ltd.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (eMusic Toolbar) - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll File not found
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (CA Toolbar) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll (CallingID Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (eMusic Toolbar) - {9EE802E8-C931-47AB-B570-AA8F791598CA} - C:\Program Files\eMusic\tbeMu0.dll File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AOLAspSunset2] C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe File not found
O4 - HKLM..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe (AOL LLC)
O4 - HKLM..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (CA, Inc.)
O4 - HKLM..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe (CA, Inc.)
O4 - HKLM..\Run: [CAPPActiveProtection] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe (CA, Inc.)
O4 - HKLM..\Run: [CaPPcl] \Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe ()
O4 - HKLM..\Run: [CAVRID] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1245198878\ee\AOLSoftware.exe (AOL LLC)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [MoneyStartUp10.0] C:\Program Files\Microsoft Money\System\Activation.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [QD FastAndSafe] \PROGRA~1\NORTON~1\QDCSFS.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SMSERIAL] C:\WINDOWS\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [AOL Fast Start] C:\Program Files\AOL 9.1a\AOL.EXE (AOL, LLC.)
O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\user\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk.disabled ()
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\Launcher.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &AOL; Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: &Search; - File not found
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKLM\..Trusted Domains: 46 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: 46 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4}
http://download.microsoft.com/download/7/0…tualEarth3D.cab (SentinelVE3D Class)
O16 - DPF: {3BB1D69B-A780-4BE1-876E-F3D488877135}
http://download.microsoft.com/download/3/B…tualEarth3D.cab (SentinelProxy Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1156365104561 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (UmxSbxExw.dll) - C:\WINDOWS\System32\UmxSbxExw.dll (CA)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\sdra64.exe) - C:\WINDOWS\System32\sdra64.exe [FILE handle not seen by OS]
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\WINDOWS\System32\UmxWnp.Dll (CA)
O24 - Desktop Components:0 () -
http://photos-b.ak.fbcdn.net/hphotos-ak-sn…7_5561416_n.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {1869181A-9F50-4FCF-8BFF-1B8588ECB85C} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\CIDLinkAdvisor.dll (CallingID Ltd.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/12/27 13:39:46 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/02/06 17:29:05 | 00,000,465 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[6 C:\WINDOWS\*.tmp files]
[2009/07/14 06:57:38 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTL.exe
[2009/07/13 22:11:53 | 00,359,929 | —- | C] () – C:\Documents and Settings\user\Desktop\dds.pif
[2009/07/13 21:53:53 | 00,278,221 | —- | C] () – C:\Documents and Settings\user\Desktop\gmer.zip
[2009/07/13 20:46:51 | 00,001,734 | —- | C] () – C:\Documents and Settings\user\Desktop\HijackThis.lnk
[2009/07/13 20:46:50 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/13 15:30:09 | 02,371,013 | —- | C] () – C:\Documents and Settings\user\My Documents\8541-Evian.wmv
[2009/07/11 08:23:57 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/07/11 08:23:57 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/07/08 21:49:44 | 00,000,000 | -H– | C] () – C:\Documents and Settings\user\My Documents\Default.rdp
[2009/07/02 09:29:42 | 00,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\Flagrante_increibe_1
[2009/06/30 11:08:11 | 00,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\dobry
[2009/06/30 01:35:24 | 00,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/06/30 01:35:24 | 00,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/06/25 12:48:20 | 00,000,000 | —D | C] – C:\Documents and Settings\user\My Documents\sammy.seansblackberry018
[2009/06/19 11:16:04 | 00,000,651 | —- | C] () – C:\Documents and Settings\user\Desktop\AOL.lnk
[2009/06/16 20:54:39 | 00,000,000 | —D | C] – C:\Program Files\AOL Toolbar
[2009/06/16 20:52:35 | 00,000,000 | —D | C] – C:\WINDOWS\aolshare
[2009/06/16 20:52:29 | 00,000,000 | —D | C] – C:\Program Files\AOL 9.1a
[2009/06/16 19:41:34 | 00,000,000 | —D | C] – C:\Program Files\AOL 9.1
[2009/06/16 19:35:43 | 00,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\toaster
[2009/06/16 19:34:53 | 00,001,916 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL Spyware Protection.lnk
[2009/06/16 19:28:06 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Macromedia
[2009/06/16 19:26:58 | 00,000,000 | —D | C] – C:\Program Files\Common Files\aolshare
[2009/06/16 19:21:59 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2009/06/16 17:22:18 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2009/01/21 09:23:24 | 00,000,024 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2009/01/12 12:33:13 | 00,002,851 | —- | C] () – C:\WINDOWS\DNAPrinters.ini
[2008/05/07 13:21:47 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\IPPCPUID.DLL
[2008/05/07 13:21:19 | 00,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2008/05/07 13:18:56 | 00,000,416 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2007/12/06 09:03:41 | 00,002,907 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/05/29 11:13:16 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2007/05/29 11:00:40 | 00,065,536 | R— | C] () – C:\WINDOWS\sm56spn.dll
[2007/05/29 11:00:39 | 00,065,536 | R— | C] () – C:\WINDOWS\sm56itl.dll
[2007/05/29 11:00:39 | 00,065,536 | R— | C] () – C:\WINDOWS\sm56ger.dll
[2007/05/29 11:00:39 | 00,065,536 | R— | C] () – C:\WINDOWS\sm56fra.dll
[2007/05/29 11:00:39 | 00,065,536 | R— | C] () – C:\WINDOWS\sm56eng.dll
[2007/05/29 11:00:39 | 00,065,536 | R— | C] () – C:\WINDOWS\sm56brz.dll
[2007/05/29 11:00:39 | 00,049,152 | R— | C] () – C:\WINDOWS\sm56jpn.dll
[2007/05/29 11:00:39 | 00,045,056 | R— | C] () – C:\WINDOWS\sm56cht.dll
[2007/05/29 11:00:39 | 00,045,056 | R— | C] () – C:\WINDOWS\sm56chs.dll
[2007/05/17 20:45:37 | 00,000,030 | —- | C] () – C:\WINDOWS\ACMonitor_X83.ini
[2007/05/17 20:44:11 | 00,004,672 | —- | C] () – C:\WINDOWS\System32\LXASUSCI.DLL
[2007/05/17 18:06:25 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/02/23 13:05:46 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/12/27 13:51:30 | 00,135,168 | R— | C] () – C:\WINDOWS\System32\e1000msg.dll
[2005/12/27 11:12:13 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/07/16 11:45:02 | 00,000,711 | —- | C] () – C:\WINDOWS\win.ini
[2003/07/16 11:41:30 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini
[2001/10/25 13:20:08 | 00,102,400 | —- | C] () – C:\WINDOWS\System32\LXASBCE.DLL
[2001/10/25 13:20:08 | 00,000,643 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
========== Files - Modified Within 30 Days ==========
[7 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[2009/07/14 06:57:44 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\user\Desktop\OTL.exe
[2009/07/14 06:54:02 | 00,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{05083F62-BD28-404E-A477-15783C3B39D1}.job
[2009/07/14 06:40:00 | 00,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/07/14 01:40:15 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/07/13 22:59:57 | 00,054,649 | —- | M] () – C:\VETlog.dmp
[2009/07/13 22:58:48 | 00,000,711 | —- | M] () – C:\WINDOWS\win.ini
[2009/07/13 22:11:53 | 00,359,929 | —- | M] () – C:\Documents and Settings\user\Desktop\dds.pif
[2009/07/13 21:53:54 | 00,278,221 | —- | M] () – C:\Documents and Settings\user\Desktop\gmer.zip
[2009/07/13 20:46:51 | 00,001,734 | —- | M] () – C:\Documents and Settings\user\Desktop\HijackThis.lnk
[2009/07/13 20:28:42 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/07/13 19:04:32 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/07/13 19:03:02 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/07/13 19:02:58 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/07/13 19:02:14 | 00,682,470 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2009/07/13 19:02:14 | 00,000,272 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2009/07/13 19:02:14 | 00,000,256 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k1
[2009/07/13 19:02:14 | 00,000,256 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k0
[2009/07/13 19:02:14 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2009/07/13 19:02:14 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2009/07/13 19:02:14 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2009/07/13 19:02:14 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2009/07/13 19:02:14 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2009/07/13 19:02:14 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2009/07/13 19:02:14 | 00,000,028 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k7
[2009/07/13 19:02:14 | 00,000,028 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k6
[2009/07/13 19:02:14 | 00,000,028 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k5
[2009/07/13 19:02:14 | 00,000,028 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k4
[2009/07/13 19:02:14 | 00,000,028 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k3
[2009/07/13 19:02:14 | 00,000,028 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k2
[2009/07/13 16:37:36 | 02,798,714 | -H– | M] () – C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db
[2009/07/13 15:30:18 | 02,371,013 | —- | M] () – C:\Documents and Settings\user\My Documents\8541-Evian.wmv
[2009/07/12 08:28:53 | 00,044,635 | —- | M] () – C:\Documents and Settings\user\My Documents\Tools in Garage.doc
[2009/07/11 08:23:57 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/07/11 08:23:57 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/07/10 21:34:26 | 00,040,960 | —- | M] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/08 21:49:44 | 00,000,000 | -H– | M] () – C:\Documents and Settings\user\My Documents\Default.rdp
[2009/07/04 22:38:30 | 00,064,533 | —- | M] () – C:\Documents and Settings\user\My Documents\HOUSE COSTS.xlsx
[2009/06/28 18:45:47 | 00,001,548 | —- | M] () – C:\Documents and Settings\user\Desktop\CCleaner.lnk
[2009/06/19 11:16:51 | 00,000,651 | —- | M] () – C:\Documents and Settings\user\Desktop\AOL.lnk
[2009/06/16 20:56:10 | 00,000,715 | —- | M] () – C:\WINDOWS\aolback.exe.lnk
[2009/06/16 19:36:49 | 00,001,916 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AOL Spyware Protection.lnk
[2009/06/16 17:22:18 | 00,000,002 | —- | M] () – C:\WINDOWS\msoffice.ini
[2009/06/16 17:04:17 | 00,002,907 | —- | M] () – C:\WINDOWS\wininit.ini
========== LOP Check ==========
[2009/07/13 23:48:02 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/01/23 13:29:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2008/05/07 13:04:11 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/01/14 19:10:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA-SupportBridge
[2006/02/23 13:05:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2009/01/23 12:27:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/06/16 17:16:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2007/05/17 18:14:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2008/05/07 13:18:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2007/05/25 09:53:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/06/07 08:35:04 | 00,000,000 | RH-D | M] – C:\Documents and Settings\user\Application Data
[2009/06/30 17:05:35 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Amazon
[2007/05/31 11:30:16 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Cabos
[2009/07/13 21:14:49 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\CallingID
[2009/07/13 21:47:48 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Canon
[2007/05/30 16:57:21 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\CyberLink
[2009/02/05 18:26:43 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\eMusic
[2008/09/14 20:14:37 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Family Lawyer
[2008/01/18 22:00:28 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\GetRightToGo
[2009/01/22 22:44:52 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Intuit
[2007/10/06 08:57:54 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\MP3Rocket
[2008/05/07 15:11:25 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\NewSoft
[2008/03/04 20:15:02 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Roxio
[2008/11/11 20:27:55 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\SanDisk
[2008/05/07 13:18:51 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\ScanSoft
[2007/05/25 09:53:37 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Viewpoint
[2007/05/18 16:38:09 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Webshots
[2007/05/17 18:16:30 | 00,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\You've Got Pictures Screensaver
[2003/07/16 11:31:17 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/07/13 20:28:42 | 00,000,868 | —- | M] () – C:\WINDOWS\Tasks\Google Software Updater.job
[2009/07/14 01:40:15 | 00,000,882 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2009/07/14 06:40:00 | 00,000,886 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2009/07/13 19:03:02 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/02/17 23:47:57 | 00,000,256 | —- | M] () – C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job
[2009/07/14 06:54:02 | 00,000,420 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{05083F62-BD28-404E-A477-15783C3B39D1}.job
========== Purity Check ==========
< End of report >
GMER 1.0.15.14972 -
http://www.gmer.net
Rootkit scan 2009-07-14 06:51:55
Windows 5.1.2600 Service Pack 3
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwCreateKey [0xA90CCB35]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwCreateSymbolicLinkObject [0xA90CD856]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwMakeTemporaryObject [0xA90CDBA7]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwOpenKey [0xA90CCA99]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwOpenSection [0xA90CD57B]
SSDT \SystemRoot\System32\DRIVERS\kmxagent.sys (HIPS Agent Driver/CA) ZwSetInformationProcess [0xA9578CE8]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwSetSystemInformation [0xA90CD983]
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs VET-REC.SYS (CA Antivirus File Protection Driver/Computer Associates International, Inc.)
Device \Driver\Tcpip \Device\Ip kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\Modem \Device\00000060 kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\Tcpip \Device\Tcp kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\Tcpip \Device\Udp kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\Tcpip \Device\RawIp kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\Tcpip \Device\IPMULTICAST kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\AFD \Device\Afd KmxCF.sys (HIPS Content Filter Driver/CA)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat VET-REC.SYS (CA Antivirus File Protection Driver/Computer Associates International, Inc.)
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\sdra64.exe 356864 bytes executable
File C:\WINDOWS\system32\lowsec 0 bytes
File C:\WINDOWS\system32\lowsec\local.ds 39457 bytes
File C:\WINDOWS\system32\lowsec\user.ds 0 bytes
—- EOF - GMER 1.0.15 —-