This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Total Security VIRUS - Maybe more...

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I bumped into the wrong website yesterday and today I have multiple problems. Some "Total Security" thing keeps popping up on the toolbar and telling me I am infected, and then it changed my desktop background to some screen that said my files are being viewed and need to upload security software, then it just took over my computer and the screen was like a screen saver I could not get out of. Had to reboot my computer.

I ran Symantec Antivirus and it deleted like 6 files but one of them it could not.. I went to the specific tmp file and deleted it myself, but have run the hi-jack this file to post here and see if anyone sees anything else that needs to be deleted. Thanks for the help, I hate viruses!!!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:52:44 AM, on 8/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\DOCUME~1\Dustin\LOCALS~1\Temp\a.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Apple Computer\DVD@ccess\DVDAccess.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Wave Systems Corp\Common\DataServer.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Symantec AntiVirus\vpc32.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=2070814
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=2070814
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = njproxy:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: LaunchVPPathfinder BHO - {789703B2-BD36-4C89-965C-39CE74959113} - C:\Program Files\Visible Path\VP_Pathfinder.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Document Manager] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
O4 - HKLM\..\Run: [StartSecurDoc] C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Inter-Chat] C:\Program Files\ConWare\InterChat3\IC3
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [Monopod] C:\DOCUME~1\Dustin\LOCALS~1\Temp\a.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: [removed] = ?
O4 - Global Startup: EMBASSY Trust Suite Secure Update.lnk = C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Find Visible &Path - C:\Program Files\Visible Path\html\VPSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Visible Path IE Toolbar - {F6DFE485-B775-4D9D-ADBC-AF4D52D5C078} - C:\Program Files\Visible Path\VP_Pathfinder.dll (HKCU)
O9 - Extra 'Tools' menuitem: Visible Path IE Toolbar - {F6DFE485-B775-4D9D-ADBC-AF4D52D5C078} - C:\Program Files\Visible Path\VP_Pathfinder.dll (HKCU)
O16 - DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} (CentraUpdaterAxCtl Class) - https://emeeting.newyorklife.com/SiteRoots/…raUpdaterAx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5EF90065-A2C4-4C6D-993E-40EE010EBA3D} (FTWebUtils.Redirecter) - https://www.fts.newyorklife.com/formslibrar…/FTWebUtils.CAB
O16 - DPF: {67F02384-3864-4BCE-A408-EDD9BD565D51} (DemoShield DemoNow Class) - http://www.munimetrix.com/nyl/demonow.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://psodemo1.webex.com/client/pso-demo1…bex/ieatgpc.cab
O20 - AppInit_DLLs: wxvault.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Adaptive Server Anywhere - FTCS (ASANYs_FTCS) - iAnywhere Solutions, Inc. - C:\Program Files\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DataSvr2 - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Common\DataServer.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: NTRU Hybrid TSS v2.0.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 11252 bytes
Hi there I would like to see a tad more information before I start :)

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTS to your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post



THEN

Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.

Start the Sysprot.exe program.

  • Click on the Log tab.
  • In the Write to log box select all items.
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new Window should appear.
  • Make sure Scan all drives is selected and click on the Start button.
  • When it is complete a new Window will appear to indicate that the scan is finished.
  • The log will be created and saved automatically in the same folder. Open the text file and copy/paste the log here.
Essexboy

Thanks in advance for the help… Here is the OTS LOG:

OTS logfile created on: 8/21/2009 9:39:21 AM - Run 1
OTS by OldTimer - Version 3.0.10.3	 Folder = C:\Documents and Settings\Dustin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
1014.02 Mb Total Physical Memory | 500.58 Mb Available Physical Memory | 49.37% Memory free
2.38 Gb Paging File | 1.74 Gb Available in Paging File | 73.06% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 50.72 Gb Free Space | 68.12% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: LAPTOP
Current User Name: Dustin
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
 
[Processes - Safe List]
a.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\a.exe -> [2009/08/18 12:41:10 | 00,151,040 | —- | M] ()
apntex.exe -> C:\Program Files\Apoint\Apntex.exe -> [2005/07/27 13:41:08 | 00,045,056 | R— | M] (Alps Electric Co., Ltd.)
apoint.exe -> C:\Program Files\Apoint\Apoint.exe -> [2005/10/07 11:13:38 | 00,176,128 | R— | M] (Alps Electric Co., Ltd.)
applemobiledeviceservice.exe -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/06/05 09:48:14 | 00,144,712 | —- | M] (Apple Inc.)
autoupdate.exe -> C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe -> [2006/08/25 08:45:30 | 00,192,512 | —- | M] (Wave Systems Corp.)
bcmwltry.exe -> C:\WINDOWS\System32\bcmwltry.exe -> [2006/11/22 16:32:58 | 01,253,376 | —- | M] (Dell Inc.)
ccapp.exe -> C:\Program Files\Common Files\Symantec Shared\ccApp.exe -> [2006/11/21 16:38:28 | 00,052,840 | —- | M] (Symantec Corporation)
ccevtmgr.exe -> C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -> [2006/11/21 16:38:32 | 00,192,104 | —- | M] (Symantec Corporation)
ccsetmgr.exe -> C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -> [2006/11/21 16:38:40 | 00,169,576 | —- | M] (Symantec Corporation)
dataserver.exe -> C:\Program Files\Wave Systems Corp\Common\DataServer.exe -> [2006/09/05 09:09:10 | 00,315,392 | —- | M] (Wave Systems Corp.)
dbsrv9.exe -> C:\Program Files\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -> [2007/06/13 08:11:40 | 00,077,824 | —- | M] (iAnywhere Solutions, Inc.)
defwatch.exe -> C:\Program Files\Symantec AntiVirus\DefWatch.exe -> [2007/03/14 18:48:40 | 00,031,424 | —- | M] (Symantec Corporation)
dlg.exe -> C:\Program Files\Digital Line Detect\DLG.exe -> [2003/10/29 01:06:00 | 00,024,576 | —- | M] (BVRP Software)
docmgr.exe -> C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe -> [2006/09/08 07:32:54 | 00,102,400 | —- | M] (Wave Systems Corp.)
dvdaccess.exe -> C:\Program Files\Apple Computer\DVD@ccess\DVDAccess.exe -> [2003/11/21 15:16:12 | 00,888,832 | —- | M] (Apple Computer)
explorer.exe -> C:\WINDOWS\Explorer.EXE -> [2008/04/14 03:42:20 | 01,033,728 | —- | M] (Microsoft Corporation)
firefox.exe -> C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe -> [2009/08/06 16:36:13 | 00,307,704 | —- | M] (Mozilla Corporation)
hidfind.exe -> C:\Program Files\Apoint\HidFind.exe -> [2004/06/28 20:56:12 | 00,045,056 | R— | M] (Alps Electric Co., Ltd.)
hijackthis.exe -> C:\Program Files\Trend Micro\HijackThis\HijackThis.exe -> [2009/08/19 08:51:36 | 00,396,288 | —- | M] (Trend Micro Inc.)
ipodservice.exe -> C:\Program Files\iPod\bin\iPodService.exe -> [2009/06/05 11:39:14 | 00,541,992 | —- | M] (Apple Inc.)
ituneshelper.exe -> C:\Program Files\iTunes\iTunesHelper.exe -> [2009/06/05 11:39:22 | 00,292,136 | —- | M] (Apple Inc.)
jusched.exe -> C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe -> [2006/09/07 13:51:22 | 00,049,263 | —- | M] (Sun Microsystems, Inc.)
mdm.exe -> C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/19 21:25:00 | 00,322,120 | —- | M] (Microsoft Corporation)
mdnsresponder.exe -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2008/12/12 09:17:38 | 00,238,888 | —- | M] (Apple Inc.)
msmsgs.exe -> C:\Program Files\Messenger\msmsgs.exe -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
nicconfigsvc.exe -> C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe -> [2007/02/20 11:24:34 | 00,475,136 | —- | M] (Dell Inc.)
ots.exe -> C:\Documents and Settings\Dustin\Desktop\OTS.exe -> [2009/08/21 09:37:20 | 00,514,048 | —- | M] (OldTimer Tools)
pdvddxsrv.exe -> C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe -> [2007/06/08 17:40:58 | 00,128,560 | —- | M] (CyberLink Corp.)
rapimgr.exe -> C:\Program Files\Microsoft ActiveSync\rapimgr.exe -> [2006/11/13 11:39:34 | 00,199,464 | —- | M] (Microsoft Corporation)
realsched.exe -> C:\Program Files\Common Files\Real\Update_OB\realsched.exe -> [2007/12/08 11:08:29 | 00,185,632 | —- | M] (RealNetworks, Inc.)
sdpin.exe -> C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe -> [2006/06/01 07:55:20 | 00,425,984 | —- | M] (Winmagic Inc.)
spbbcsvc.exe -> C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -> [2007/01/10 15:27:38 | 01,160,792 | —- | M] (Symantec Corporation)
tcsd_win32.exe -> C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe -> [2006/06/12 09:01:14 | 00,180,224 | —- | M] ()
vptray.exe -> C:\Program Files\Symantec AntiVirus\VPTray.exe -> [2007/03/14 18:49:02 | 00,125,632 | —- | M] (Symantec Corporation)
wcescomm.exe -> C:\Program Files\Microsoft ActiveSync\Wcescomm.exe -> [2006/11/13 11:39:52 | 01,289,000 | —- | M] (Microsoft Corporation)
wltrysvc.exe -> C:\WINDOWS\System32\WLTRYSVC.EXE -> [2006/11/22 16:35:50 | 00,020,480 | —- | M] ()
wmiprvse.exe -> C:\WINDOWS\System32\wbem\wmiprvse.exe -> [2009/02/06 04:10:02 | 00,227,840 | —- | M] (Microsoft Corporation)
 
[Win32 Services - Safe List]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/06/05 09:48:14 | 00,144,712 | —- | M] (Apple Inc.)
(ASANYs_FTCS) Adaptive Server Anywhere - FTCS [Win32_Own | Auto | Running] -> C:\Program Files\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -> [2007/06/13 08:11:40 | 00,077,824 | —- | M] (iAnywhere Solutions, Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation)
(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> [2007/05/30 06:31:10 | 00,312,880 | —- | M] (GRISOFT s.r.o.)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2008/12/12 09:17:38 | 00,238,888 | —- | M] (Apple Inc.)
(ccEvtMgr) Symantec Event Manager [Win32_Own | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -> [2006/11/21 16:38:32 | 00,192,104 | —- | M] (Symantec Corporation)
(ccSetMgr) Symantec Settings Manager [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -> [2006/11/21 16:38:40 | 00,169,576 | —- | M] (Symantec Corporation)
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation)
(DataSvr2) DataSvr2 [Win32_Own | Auto | Running] -> C:\Program Files\Wave Systems Corp\Common\DataServer.exe -> [2006/09/05 09:09:10 | 00,315,392 | —- | M] (Wave Systems Corp.)
(DefWatch) Symantec AntiVirus Definition Watcher [Win32_Own | Auto | Running] -> C:\Program Files\Symantec AntiVirus\DefWatch.exe -> [2007/03/14 18:48:40 | 00,031,424 | —- | M] (Symantec Corporation)
(FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -> [2008/07/29 21:10:04 | 00,046,104 | —- | M] (Microsoft Corporation)
(GoogleDesktopManager) GoogleDesktopManager [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -> [2007/09/07 06:14:35 | 01,836,544 | —- | M] (Google)
(helpsvc) Help and Support [Win32_Shared | Auto | Running] -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/14 03:42:04 | 00,038,400 | —- | M] (Microsoft Corporation)
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -> [2004/10/22 01:24:18 | 00,073,728 | —- | M] (Macrovision Corporation)
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2008/07/29 19:24:50 | 00,881,664 | —- | M] (Microsoft Corporation)
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> C:\Program Files\iPod\bin\iPodService.exe -> [2009/06/05 11:39:14 | 00,541,992 | —- | M] (Apple Inc.)
(Irmon) Infrared Monitor [Win32_Shared | Auto | Running] -> C:\WINDOWS\System32\irmon.dll -> [2008/04/14 03:41:56 | 00,028,160 | —- | M] (Microsoft Corporation)
(LiveUpdate) LiveUpdate [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE -> [2006/09/02 15:36:33 | 02,528,960 | —- | M] (Symantec Corporation)
(MDM) Machine Debug Manager [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/19 21:25:00 | 00,322,120 | —- | M] (Microsoft Corporation)
(NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2008/07/29 19:16:38 | 00,132,096 | —- | M] (Microsoft Corporation)
(NICCONFIGSVC) NICCONFIGSVC [Win32_Own | Auto | Running] -> C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe -> [2007/02/20 11:24:34 | 00,475,136 | —- | M] (Dell Inc.)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -> [2003/07/28 10:28:22 | 00,089,136 | —- | M] (Microsoft Corporation)
(SavRoam) SavRoam [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Symantec AntiVirus\SavRoam.exe -> [2007/03/14 18:48:56 | 00,116,416 | —- | M] (symantec)
(SNDSrvc) Symantec Network Drivers Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -> [2007/02/12 16:23:10 | 00,214,672 | —- | M] (Symantec Corporation)
(SPBBCSvc) Symantec SPBBCSvc [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -> [2007/01/10 15:27:38 | 01,160,792 | —- | M] (Symantec Corporation)
(Symantec AntiVirus) Symantec AntiVirus [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Symantec AntiVirus\Rtvscan.exe -> [2007/03/14 18:48:50 | 01,816,768 | —- | M] (Symantec Corporation)
(tcsd_win32.exe) NTRU Hybrid TSS v2.0.25 TCS [Win32_Own | Auto | Running] -> C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe -> [2006/06/12 09:01:14 | 00,180,224 | —- | M] ()
(wltrysvc) Dell Wireless WLAN Tray Service [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\WLTRYSVC.EXE -> [2006/11/22 16:35:50 | 00,020,480 | —- | M] ()
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Windows Media Player\WMPNetwk.exe -> [2006/10/18 19:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
 
[Driver Services - Safe List]
(AliIde) AliIde [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\aliide.sys -> [2001/08/17 12:51:56 | 00,005,248 | —- | M] (Acer Laboratories Inc.)
(amdagp) AMD AGP Bus Filter Driver [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\amdagp.sys -> [2008/04/13 22:06:40 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.)
(ApfiltrService) Alps Touch Pad Filter Driver for Windows 2000/XP [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\Apfiltr.sys -> [2005/09/28 17:57:18 | 00,113,847 | R— | M] (Alps Electric Co., Ltd.)
(APPDRV) APPDRV [Kernel | System | Running] -> C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -> [2005/08/12 15:50:46 | 00,016,128 | —- | M] (Dell Inc)
(asc) asc [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\asc.sys -> [2001/08/17 12:52:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.)
(asc3550) asc3550 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\asc3550.sys -> [2001/08/17 12:51:58 | 00,014,848 | —- | M] (Advanced System Products, Inc.)
(AVG Anti-Spyware Driver) AVG Anti-Spyware Driver [Kernel | System | Running] -> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys -> [2007/05/30 06:10:42 | 00,011,000 | —- | M] ()
(AvgAsCln) AVG Anti-Spyware Clean Driver [Kernel | System | Running] -> C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys -> [2007/05/30 06:10:42 | 00,010,872 | —- | M] (GRISOFT, s.r.o.)
(b57w2k) Broadcom NetXtreme Gigabit Ethernet [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\b57xp32.sys -> [2005/11/10 08:25:14 | 00,142,720 | —- | M] (Broadcom Corporation)
(BCM43XX) Dell Wireless WLAN Card Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\bcmwl5.sys -> [2006/11/22 16:34:36 | 00,604,928 | —- | M] (Broadcom Corporation)
(CmdIde) CmdIde [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\cmdide.sys -> [2001/08/17 12:51:54 | 00,006,656 | —- | M] (CMD Technology, Inc.)
(dac2w2k) dac2w2k [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -> [2001/08/17 12:52:16 | 00,179,584 | —- | M] (Mylex Corporation)
(DSproct) DSproct [Kernel | On_Demand | Stopped] -> C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys -> [2006/01/10 10:07:58 | 00,004,864 | —- | M] (GTek Technologies Ltd.)
(DVDAccss) DVDAccss [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\DVDAccss.sys -> [2003/11/21 15:15:14 | 00,029,156 | —- | M] (Apple Computer, Inc.)
(E100B) Intel(R) PRO Adapter Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\e100b325.sys -> [2001/08/17 11:12:10 | 00,117,760 | —- | M] (Intel Corporation)
(eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -> [2009/02/27 03:00:00 | 00,371,248 | —- | M] (Symantec Corporation)
(EraserUtilRebootDrv) EraserUtilRebootDrv [Kernel | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -> [2009/03/16 02:00:00 | 00,101,936 | —- | M] (Symantec Corporation)
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys -> [2009/03/19 14:32:48 | 00,023,400 | —- | M] (GEAR Software Inc.)
(GTKCMOS) GTKCMOS [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\GTKCMOS.sys -> [2004/06/15 13:55:56 | 00,007,882 | —- | M] (Gteko Ltd.)
(guardian2) guardian2 [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\oz776.sys -> [2007/01/28 13:23:36 | 00,061,312 | —- | M] (O2Micro)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HDAudBus.sys -> [2008/04/13 20:06:06 | 00,144,384 | —- | M] (Windows (R) Server 2003 DDK provider)
(HSF_DPV) HSF_DPV [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HSX_DPV.sys -> [2005/11/30 23:40:56 | 00,936,960 | —- | M] (Conexant Systems, Inc.)
(HSXHWAZL) HSXHWAZL [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HSXHWAZL.sys -> [2005/11/30 23:40:12 | 00,192,512 | —- | M] (Conexant Systems, Inc.)
(ialm) ialm [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ialmnt5.sys -> [2005/12/13 16:09:34 | 01,364,574 | —- | M] (Intel Corporation)
(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys -> [2005/10/04 20:57:08 | 00,012,544 | —- | M] (Conexant)
(mraid35x) mraid35x [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\mraid35x.sys -> [2001/08/17 12:52:12 | 00,017,280 | —- | M] (American Megatrends Inc.)
(NAVENG) NAVENG [Kernel | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090815.003\NAVENG.SYS -> [2009/07/15 02:00:00 | 00,087,888 | —- | M] (Symantec Corporation)
(NAVEX15) NAVEX15 [Kernel | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090815.003\NAVEX15.SYS -> [2009/07/15 02:00:00 | 00,875,728 | —- | M] (Symantec Corporation)
(NEOFLTR_620_13649) Juniper Networks TDI Filter Driver (NEOFLTR_620_13649) [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\NEOFLTR_620_13649.SYS -> [2008/10/21 16:40:22 | 00,064,480 | —- | M] (Juniper Networks)
(nv) nv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -> [2004/08/03 21:29:56 | 01,897,408 | —- | M] (NVIDIA Corporation)
(omci) OMCI WDM Device Driver [Kernel | System | Running] -> C:\WINDOWS\System32\DRIVERS\omci.sys -> [2004/02/13 08:46:00 | 00,017,153 | —- | M] (Dell Inc)
(PBADRV) PBADRV [Kernel | Boot | Running] -> C:\WINDOWS\system32\drivers\pbadrv.sys -> [2005/12/09 14:35:00 | 00,018,816 | —- | M] (Dell Inc)
(pfc) Padus ASPI Shell [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\pfc.sys -> [2002/02/11 13:15:50 | 00,014,572 | —- | M] (Padus, Inc.)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ptilink.sys -> [2004/08/04 04:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(ql1080) ql1080 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\ql1080.sys -> [2001/08/17 12:52:20 | 00,040,320 | —- | M] (QLogic Corporation)
(ql12160) ql12160 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\ql12160.sys -> [2001/08/17 12:52:20 | 00,045,312 | —- | M] (QLogic Corporation)
(ql1280) ql1280 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\ql1280.sys -> [2001/08/17 12:52:18 | 00,049,024 | —- | M] (QLogic Corporation)
(SAVRT) SAVRT [Kernel | System | Running] -> C:\Program Files\Symantec AntiVirus\savrt.sys -> [2006/09/06 13:41:20 | 00,337,592 | —- | M] (Symantec Corporation)
(SAVRTPEL) SAVRTPEL [Kernel | System | Running] -> C:\Program Files\Symantec AntiVirus\Savrtpel.sys -> [2006/09/06 13:41:20 | 00,054,968 | —- | M] (Symantec Corporation)
(SDDisk2K) WinMagic SecureDoc [Kernel | Boot | Running] -> C:\WINDOWS\System32\drivers\SDDisk2K.sys -> [2006/01/24 11:36:44 | 00,194,048 | —- | M] ()
(SDDMI2) SDDMI2 [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DDMI2.sys -> [2004/06/09 07:29:56 | 00,006,977 | —- | M] (Gteko Ltd.)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\secdrv.sys -> [2007/11/13 04:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sfng32) Sonic Focus Plugin for Sigmatel HDA [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\sfng32.sys -> [2005/12/02 15:38:04 | 00,041,728 | —- | M] (Sonic Focus, Inc)
(sisagp) SIS AGP Bus Filter [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\sisagp.sys -> [2008/04/13 22:06:40 | 00,040,960 | —- | M] (Silicon Integrated Systems Corporation)
(SMCIRDA) SMC IrCC Miniport Device Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\smcirda.sys -> [2001/08/17 10:10:28 | 00,035,913 | —- | M] (SMC)
(Sparrow) Sparrow [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\sparrow.sys -> [2001/08/17 13:07:44 | 00,019,072 | —- | M] (Adaptec, Inc.)
(SPBBCDrv) SPBBCDrv [Kernel | System | Running] -> C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -> [2007/01/10 15:27:26 | 00,390,744 | —- | M] (Symantec Corporation)
(STHDA) SigmaTel High Definition Audio CODEC [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\sthda.sys -> [2005/12/12 13:32:54 | 01,083,576 | —- | M] (SigmaTel, Inc.)
(symc810) symc810 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\symc810.sys -> [2001/08/17 13:07:34 | 00,016,256 | —- | M] (Symbios Logic Inc.)
(symc8xx) symc8xx [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\symc8xx.sys -> [2001/08/17 13:07:36 | 00,032,640 | —- | M] (LSI Logic)
(SymEvent) SymEvent [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\SYMEVENT.SYS -> [2008/02/12 09:54:53 | 00,110,952 | —- | M] (Symantec Corporation)
(SYMREDRV) SYMREDRV [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -> [2007/02/12 16:22:36 | 00,024,720 | —- | M] (Symantec Corporation)
(SYMTDI) SYMTDI [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\SYMTDI.SYS -> [2007/02/12 16:22:40 | 00,196,752 | —- | M] (Symantec Corporation)
(sym_hi) sym_hi [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\sym_hi.sys -> [2001/08/17 13:07:40 | 00,028,384 | —- | M] (LSI Logic)
(sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\sym_u3.sys -> [2001/08/17 13:07:42 | 00,030,688 | —- | M] (LSI Logic)
(TcUsb) TC USB Kernel Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\tcusb.sys -> [2006/03/01 01:39:18 | 00,028,800 | —- | M] (UPEK Inc.)
(ultra) ultra [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\ultra.sys -> [2001/08/17 12:52:22 | 00,036,736 | —- | M] (Promise Technology, Inc.)
(usb_rndisx) USB RNDIS Adapter [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\usb8023x.sys -> [2008/04/13 22:26:50 | 00,012,800 | —- | M] (Microsoft Corporation)
(winachsf) winachsf [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HSX_CNXT.sys -> [2005/11/30 23:40:08 | 00,669,696 | —- | M] (Conexant Systems, Inc.)
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" ->  [binary data] -> 
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\"Default_Page_URL" -> www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=2070814 -> 
HKEY_LOCAL_MACHINE\: Search\\"Default_Search_URL" -> http://www.google.com/ie -> 
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> 
HKEY_LOCAL_MACHINE\: Search\\"Start Page" -> www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=2070814 -> 
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> 
HKEY_USERS\.DEFAULT\: Main\\"Default_Page_URL" -> www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=2070814 -> 
HKEY_USERS\.DEFAULT\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch -> 
HKEY_USERS\.DEFAULT\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ -> 
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> 
HKEY_USERS\S-1-5-18\: Main\\"Default_Page_URL" -> www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=2070814 -> 
HKEY_USERS\S-1-5-18\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch -> 
HKEY_USERS\S-1-5-18\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ -> 
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> 
HKEY_USERS\S-1-5-19\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch -> 
HKEY_USERS\S-1-5-19\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> 
HKEY_USERS\S-1-5-20\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch -> 
HKEY_USERS\S-1-5-20\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\] > -> -> 
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: Main\\"Default_Page_URL" -> www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=2070814 -> 
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> 
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch -> 
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: Main\\"Start Page" -> http://www.google.com/ -> 
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: SearchURL\\"" -> http://www.google.com/search?q=%s -> 
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: "ProxyEnable" -> 0 -> 
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: "ProxyOverride" -> *.local -> 
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: "ProxyServer" -> njproxy:80 -> 
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\Dustin\Application Data\Mozilla\FireFox\Profiles\e4xovvgc.default\prefs.js -> 
browser.search.selectedEngine -> "eBay" ->
browser.startup.homepage -> "http://www.google.com/ig" ->
extensions.enabledItems -> [removed]:1.10 ->
extensions.enabledItems -> {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}:[removed] ->
extensions.enabledItems -> [removed]:7 ->
extensions.enabledItems -> {20a82645-c095-46ed-80e3-08825760534b}:1.0 ->
extensions.enabledItems -> {7694c49c-9fbd-11dc-8314-0800200c9a66}:3.0.2 ->
extensions.enabledItems -> {47e5a66c-0e35-11dc-8314-0800200c9a66}:3.0.1 ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13 ->
network.proxy.http -> "njproxy" ->
network.proxy.http_port -> 80 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions ->  -> 
HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/08/10 16:29:56 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions ->  -> 
HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\COMPONENTS] -> [2009/08/19 08:40:57 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\PLUGINS] -> [2009/08/06 16:36:19 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Sunbird 0.8\extensions ->  -> 
HKLM\software\mozilla\Mozilla Sunbird 0.8\extensions\\Components -> C:\PROGRAM FILES\MOZILLA SUNBIRD\COMPONENTS [C:\PROGRAM FILES\MOZILLA SUNBIRD\COMPONENTS] -> [2009/06/19 22:16:46 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Sunbird 0.8\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA SUNBIRD\PLUGINS [C:\PROGRAM FILES\MOZILLA SUNBIRD\PLUGINS] -> [2009/06/19 22:16:46 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions ->  -> 
HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components -> C:\PROGRAM FILES\MOZILLA THUNDERBIRD\COMPONENTS [C:\PROGRAM FILES\MOZILLA THUNDERBIRD\COMPONENTS] -> [2009/08/21 08:35:28 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA THUNDERBIRD\PLUGINS [C:\PROGRAM FILES\MOZILLA THUNDERBIRD\PLUGINS] -> [2009/06/19 22:16:46 | 00,000,000 | —D | M]
< FireFox Extensions [User Folders] > -> 
 -> C:\Documents and Settings\Dustin\Application Data\mozilla\Extensions -> [2008/05/22 09:02:01 | 00,000,000 | —D | M]
 -> C:\Documents and Settings\Dustin\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2008/05/22 09:02:01 | 00,000,000 | —D | M]
 -> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
 -> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions\{47e5a66c-0e35-11dc-8314-0800200c9a66} -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
 -> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions\{7694c49c-9fbd-11dc-8314-0800200c9a66} -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
 -> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
 -> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions\[removed] -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
 -> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions\[removed] -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
 -> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions\[removed]-trash -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
< FireFox Extensions [Program Folders] > -> 
 -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\extensions -> [2009/08/06 16:36:19 | 09,747,960 | —- | M] (Mozilla Foundation)
 -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2009/08/06 16:36:19 | 09,747,960 | —- | M] (Mozilla Foundation)
< FireFox Components [Program Folders] > -> 
C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\components\ -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\components -> [2009/08/19 08:40:57 | 00,000,000 | —D | M]
browserdirprovider.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\components\browserdirprovider.dll -> [2009/08/06 16:36:11 | 00,023,032 | —- | M] (Mozilla Foundation)
brwsrcmp.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\components\brwsrcmp.dll -> [2009/08/06 16:36:11 | 00,134,648 | —- | M] (Mozilla Foundation)
< FireFox Plugins [Program Folders] > -> 
C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins -> [2009/08/06 16:36:19 | 00,000,000 | —D | M]
np32dsw.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\np32dsw.dll -> [2008/11/24 13:35:00 | 00,114,688 | —- | M] (Adobe Systems, Inc.)
npnul32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npnul32.dll -> [2009/08/06 16:36:16 | 00,065,528 | —- | M] (mozilla.org)
NPOFFICE.DLL -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\NPOFFICE.DLL -> [2007/03/22 17:23:30 | 00,017,248 | —- | M] (Microsoft Corporation)
nppdf32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\nppdf32.dll -> [2008/10/14 20:33:30 | 00,095,600 | —- | M] (Adobe Systems Inc.)
npqtplugin.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin.dll -> [2009/06/19 22:16:45 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin2.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin2.dll -> [2009/06/19 22:16:45 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin3.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin3.dll -> [2009/06/19 22:16:45 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin4.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin4.dll -> [2009/06/19 22:16:45 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin5.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin5.dll -> [2009/06/19 22:16:45 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin6.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin6.dll -> [2009/06/19 22:16:46 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin7.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin7.dll -> [2009/06/19 22:16:46 | 00,143,360 | —- | M] (Apple Inc.)
QuickTimePlugin.class -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\QuickTimePlugin.cla -> [2009/06/19 22:16:45 | 00,004,208 | —- | M] ()
ShockwavePlugin.class -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\ShockwavePlugin.cla -> [2008/11/24 13:05:16 | 00,001,144 | —- | M] ()
< FireFox SearchPlugins [Program Folders] > -> 
C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins -> [2009/02/06 07:14:27 | 00,000,000 | —D | M]
amazondotcom.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\amazondotcom.xml -> [2009/02/06 07:14:21 | 00,001,394 | —- | M] ()
answers.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\answers.xml -> [2009/02/06 07:14:21 | 00,002,193 | —- | M] ()
creativecommons.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\creativecommons.xml -> [2009/02/06 07:14:21 | 00,001,534 | —- | M] ()
eBay.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\eBay.xml -> [2009/02/06 07:14:21 | 00,002,343 | —- | M] ()
google.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\google.xml -> [2009/02/06 07:14:21 | 00,001,706 | —- | M] ()
wikipedia.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\wikipedia.xml -> [2009/02/06 07:14:21 | 00,001,178 | —- | M] ()
yahoo.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\yahoo.xml -> [2009/02/06 07:14:21 | 00,000,792 | —- | M] ()
< HOSTS File > (734 bytes and 19 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
Reset Hosts
127.0.0.1	   localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/22 22:08:42 | 00,062,080 | —- | M] (Adobe Systems Incorporated)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll [SSVHelper Class] -> [2006/09/07 14:06:08 | 00,434,279 | —- | M] (Sun Microsystems, Inc.)
{789703B2-BD36-4C89-965C-39CE74959113} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{CA6319C0-31B7-401E-A518-A07C3DB8F777} [HKLM] -> C:\Program Files\BAE\BAE.dll [CBrowserHelperObject Object] -> [2007/01/26 08:07:42 | 00,098,304 | —- | M] (Dell Inc.)
{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"!AVG Anti-Spyware" -> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe ["C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized] -> [2007/06/11 03:25:42 | 06,731,312 | —- | M] (GRISOFT s.r.o.)
"Adobe Reader Speed Launcher" -> C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008/10/15 00:04:34 | 00,039,792 | —- | M] (Adobe Systems Incorporated)
"Apoint" -> C:\Program Files\Apoint\Apoint.exe [C:\Program Files\Apoint\Apoint.exe] -> [2005/10/07 11:13:38 | 00,176,128 | R— | M] (Alps Electric Co., Ltd.)
"ccApp" -> C:\Program Files\Common Files\Symantec Shared\ccApp.exe ["C:\Program Files\Common Files\Symantec Shared\ccApp.exe"] -> [2006/11/21 16:38:28 | 00,052,840 | —- | M] (Symantec Corporation)
"Document Manager" -> C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe [C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe] -> [2006/09/08 07:32:54 | 00,102,400 | —- | M] (Wave Systems Corp.)
"ISUSPM" -> C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe ["C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler] -> File not found
"iTunesHelper" -> C:\Program Files\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2009/06/05 11:39:22 | 00,292,136 | —- | M] (Apple Inc.)
"net" -> C:\WINDOWS\System32\net.net ["C:\WINDOWS\system32\net.net"] -> [2009/08/18 12:40:40 | 00,037,263 | —- | M] (Comp)
"PDVDDXSrv" -> C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe ["C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"] -> [2007/06/08 17:40:58 | 00,128,560 | —- | M] (CyberLink Corp.)
"QuickTime Task" -> C:\Program Files\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> [2009/05/26 15:18:30 | 00,413,696 | —- | M] (Apple Inc.)
"StartSecurDoc" -> C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe [C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe] -> [2006/06/01 07:55:20 | 00,425,984 | —- | M] (Winmagic Inc.)
"SunJavaUpdateSched" -> C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe ["C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"] -> [2006/09/07 13:51:22 | 00,049,263 | —- | M] (Sun Microsystems, Inc.)
"TkBellExe" -> C:\Program Files\Common Files\Real\Update_OB\realsched.exe ["C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot] -> [2007/12/08 11:08:29 | 00,185,632 | —- | M] (RealNetworks, Inc.)
"vptray" -> C:\Program Files\Symantec AntiVirus\VPTray.exe [C:\PROGRA~1\SYMANT~1\VPTray.exe] -> [2007/03/14 18:49:02 | 00,125,632 | —- | M] (Symantec Corporation)
< Run [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"H/PC Connection Agent" -> C:\Program Files\Microsoft ActiveSync\Wcescomm.exe ["C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"] -> [2006/11/13 11:39:52 | 01,289,000 | —- | M] (Microsoft Corporation)
"Inter-Chat" ->  [C:\Program Files\ConWare\InterChat3\IC3] -> File not found
"Monopod" -> C:\Documents and Settings\Dustin\Local Settings\Temp\a.exe [C:\DOCUME~1\Dustin\LOCALS~1\Temp\a.exe] -> [2009/08/18 12:41:10 | 00,151,040 | —- | M] ()
"MSMSGS" -> C:\Program Files\Messenger\msmsgs.exe ["C:\Program Files\Messenger\msmsgs.exe" /background] -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
< Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup -> 
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe -> [2003/10/29 01:06:00 | 00,024,576 | —- | M] (BVRP Software)
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\[removed] -> C:\Program Files\Apple Computer\DVD@ccess\DVDAccess.exe -> [2003/11/21 15:16:12 | 00,888,832 | —- | M] (Apple Computer)
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\EMBASSY Trust Suite Secure Update.lnk -> C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe -> [2006/08/25 08:45:30 | 00,192,512 | —- | M] (Wave Systems Corp.)
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup -> 
< Dustin Startup Folder > -> C:\Documents and Settings\Dustin\Start Menu\Programs\Startup -> 
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoActiveDesktopChanges" ->  [0] -> File not found
\\"HonorAutoRunSetting" ->  [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
\\"DisableTaskMgr" ->  [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
\\"NoActiveDesktop" ->  [0] -> File not found
\\"NoSaveSettings" ->  [0] -> File not found
\\"ClassicShell" ->  [0] -> File not found
\\"NoThemesTab" ->  [0] -> File not found
\\"ForceActiveDesktopOn" ->  [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"DisableRegistryTools" ->  [0] -> File not found
\\"DisableTaskMgr" ->  [0] -> File not found
\\"NoDispAppearancePage" ->  [0] -> File not found
\\"NoColorChoice" ->  [0] -> File not found
\\"NoSizeChoice" ->  [0] -> File not found
\\"NoDispBackgroundPage" ->  [0] -> File not found
\\"NoDispScrSavPage" ->  [0] -> File not found
\\"NoDispCPL" ->  [0] -> File not found
\\"NoVisualStyleChoice" ->  [0] -> File not found
\\"NoDispSettingsPage" ->  [0] -> File not found
< Internet Explorer Menu Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\ -> 
E&xport; to Microsoft Excel -> C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2009/04/21 20:43:04 | 10,351,936 | —- | M] (Microsoft Corporation)
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\ -> 
E&xport; to Microsoft Excel -> C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2009/04/21 20:43:04 | 10,351,936 | —- | M] (Microsoft Corporation)
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\Software\Microsoft\Internet Explorer\MenuExt\ -> 
E&xport; to Microsoft Excel -> C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2009/04/21 20:43:04 | 10,351,936 | —- | M] (Microsoft Corporation)
Find Visible &Path; -> C:\Program Files\Visible Path\html\VPSearch.html [C:\Program Files\Visible Path\html\VPSearch.html] -> [2007/05/17 16:43:22 | 00,002,404 | —- | M] ()
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC} [HKLM] -> C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll [Menu: Sun Java Console] -> [2006/09/07 14:06:08 | 00,069,746 | —- | M] (Sun Microsystems, Inc.)
{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}:{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Button: Create Mobile Favorite] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}:{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Menu: Create Mobile Favorite…] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL [Button: Research] -> [2007/04/19 12:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/13 22:23:34 | 00,558,080 | —- | M] (Microsoft Corporation)
{F47C1DB5-ED21-4dc1-853E-D1495792D4C5}:Exec [HKLM] -> C:\Program Files\Bodog Poker\BPGame.exe [Button: Bodog Poker] -> [2008/06/10 13:26:20 | 04,231,243 | —- | M] (Bodog)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> C:\WINDOWS\System32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | —- | M] (Microsoft Corporation)
CmdMapping\\"{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}" [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
CmdMapping\\"{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}" [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite…] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 12:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 22:23:34 | 00,558,080 | —- | M] (Microsoft Corporation)
CmdMapping\\"{F47C1DB5-ED21-4dc1-853E-D1495792D4C5}" [HKLM] -> C:\Program Files\Bodog Poker\BPGame.exe [Bodog Poker] -> [2008/06/10 13:26:20 | 04,231,243 | —- | M] (Bodog)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> C:\WINDOWS\System32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | —- | M] (Microsoft Corporation)
CmdMapping\\"{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}" [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
CmdMapping\\"{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}" [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite…] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 12:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 22:23:34 | 00,558,080 | —- | M] (Microsoft Corporation)
CmdMapping\\"{F47C1DB5-ED21-4dc1-853E-D1495792D4C5}" [HKLM] -> C:\Program Files\Bodog Poker\BPGame.exe [Bodog Poker] -> [2008/06/10 13:26:20 | 04,231,243 | —- | M] (Bodog)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\Software\Microsoft\Internet Explorer\Extensions\ -> 
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"" [HKLM] ->  [Reg Error: Value error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"BandCLSID" [HKLM] ->  [Reg Error: Key error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"ButtonText" [HKLM] ->  [Reg Error: Key error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"CLSID" [HKLM] ->  [{0000031A-0000-0000-C000-000000000046}] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"Default Visible" [HKLM] ->  [Reg Error: Key error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"HotIcon" [HKLM] ->  [Reg Error: Key error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"Icon" [HKLM] ->  [Reg Error: Key error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"MenuStatusBar" [HKLM] ->  [Reg Error: Key error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"MenuText" [HKLM] ->  [Reg Error: Key error.] -> File not found
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> C:\WINDOWS\System32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | —- | M] (Microsoft Corporation)
CmdMapping\\"{1B617093-5CD4-42f5-91CA-AD1004C83588}" [HKLM] ->  [Reg Error: Key error.] -> File not found
CmdMapping\\"{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}" [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
CmdMapping\\"{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}" [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite…] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 12:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 22:23:34 | 00,558,080 | —- | M] (Microsoft Corporation)
CmdMapping\\"{F47C1DB5-ED21-4dc1-853E-D1495792D4C5}" [HKLM] -> C:\Program Files\Bodog Poker\BPGame.exe [Bodog Poker] -> [2008/06/10 13:26:20 | 04,231,243 | —- | M] (Bodog)
CmdMapping\\"{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}" [HKLM] ->  [Reg Error: Key error.] -> File not found
CmdMapping\\"{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}" [HKCU] -> C:\Program Files\Visible Path\VP_Pathfinder.dll [Visible Path IE Toolbar] -> [2007/08/29 19:31:06 | 00,122,880 | —- | M] (Visible Path Corp.)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime;=%s -> 
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 2 domain(s) found. -> 
www.agencyportal_newyorklife.com [https] -> Local intranet -> 
www.authsm_newyorklife.com [https] -> Local intranet -> 
www.ftisweb_newyorklife.com [https] -> Local intranet -> 
www.fts_newyorklife.com [https] -> Local intranet -> 
www.mcs_newyorklife.com [https] -> Local intranet -> 
www.riat_newyorklife.com [https] -> Local intranet -> 
2 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{036F8A56-0BC8-4607-8F98-D3231E6FF5ED} [HKLM] -> https://emeeting.newyorklife.com/SiteRoots/main/Install/win32/CentraUpdaterAx.cab [CentraUpdaterAxCtl Class] -> 
{17492023-C23A-453E-A040-C7C580BBF700} [HKLM] -> http://go.microsoft.com/fwlink/?linkid=39204 [Windows Genuine Advantage Validation Tool] -> 
{48DD0448-9209-4F81-9F6D-D83562940134} [HKLM] -> http://lads.myspace.com/upload/MySpaceUploader1006.cab [MySpace Uploader Control] -> 
{5EF90065-A2C4-4C6D-993E-40EE010EBA3D} [HKLM] -> https://www.fts.newyorklife.com/formslibrary/Package/FTWebUtils.CAB [FTWebUtils.Redirecter] -> 
{67F02384-3864-4BCE-A408-EDD9BD565D51} [HKLM] -> http://www.munimetrix.com/nyl/demonow.cab [DemoShield DemoNow Class] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab [Java Plug-in 1.5.0_09] -> 
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab [Reg Error: Key error.] -> 
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} [HKLM] -> http://acs.pandasoftware.com/activescan/as5free/asinst.cab [ActiveScan Installer Class] -> 
{B8BE5E93-A60C-4D26-A2DC-220313175592} [HKLM] -> http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab [MSN Games - Installer] -> 
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab [Java Plug-in 1.5.0_06] -> 
{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab [Java Plug-in 1.5.0_09] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab [Java Plug-in 1.5.0_09] -> 
{D0C0F75C-683A-4390-A791-1ACFD5599AB8} [HKLM] -> http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab [Oberon Flash Game Host] -> 
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] -> 
{E06E2E99-0AA1-11D4-ABA6-0060082AA75C} [HKLM] -> https://psodemo1.webex.com/client/pso-demo12/webex/ieatgpc.cab [GpcContainer Class] -> 
Microsoft XML Parser for Java [HKLM] -> file://C:\WINDOWS\Java\classes\xmldso.cab [Reg Error: Key error.] -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ -> 
DhcpNameServer -> [removed] [removed] -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{544444BA-3A96-4EC9-9B17-0F29612F433F}\\DhcpNameServer -> [removed] [removed]   (Dell Wireless 1390 WLAN Mini-Card) -> 
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> 
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> 
wxvault.dll -> C:\WINDOWS\System32\wxvault.dll -> [2006/09/08 07:32:02 | 00,286,720 | —- | M] ()
C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL -> C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll -> [2007/09/07 06:14:48 | 00,145,408 | —- | M] (Google)
*MultiFile Done* -> -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/14 03:42:20 | 01,033,728 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 
igfxcui -> C:\WINDOWS\System32\igfxdev.dll -> [2005/12/13 15:40:12 | 00,139,264 | —- | M] (Intel Corporation)
NavLogon -> C:\WINDOWS\System32\NavLogon.dll -> [2007/03/14 18:49:14 | 00,043,712 | —- | M] (Symantec Corporation)
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> 
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" [HKLM] -> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> [2007/05/30 06:29:58 | 00,079,408 | —- | M] (GRISOFT s.r.o.)
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> 
*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> 
wvauth -> C:\WINDOWS\System32\wvauth.dll -> [2006/09/12 11:07:24 | 00,385,024 | —- | M] (Wave Systems Corp.)
*MultiFile Done* -> -> 
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 22:23:34 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 03:42:36 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" -> C:\Program Files\Microsoft ActiveSync\rapimgr.exe [C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager] -> [2006/11/13 11:39:34 | 00,199,464 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" -> C:\Program Files\Microsoft ActiveSync\wcescomm.exe [C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager] -> [2006/11/13 11:39:52 | 01,289,000 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" -> C:\Program Files\Microsoft ActiveSync\WCESMgr.exe [C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application] -> [2006/11/13 11:39:54 | 04,270,888 | —- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 22:23:34 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 03:42:36 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\Documents and Settings\Dustin\Desktop\Diablo3-gameplaytrailer_en-US-downloader.exe" -> C:\Documents and Settings\Dustin\Desktop\Diablo3-gameplaytrailer_en-US-downloader.exe [C:\Documents and Settings\Dustin\Desktop\Diablo3-gameplaytrailer_en-US-downloader.exe:*:Enabled:Blizzard Downloader] -> File not found
"C:\Program Files\Azureus\Azureus.exe" -> C:\Program Files\Azureus\Azureus.exe [C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus] -> [2007/05/15 21:07:28 | 00,254,984 | —- | M] (Azureus Inc)
"C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008/12/12 09:17:38 | 00,238,888 | —- | M] (Apple Inc.)
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" -> C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program] -> [2007/06/08 17:40:58 | 00,128,560 | —- | M] (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe" -> C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe [C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX] -> [2007/03/02 13:33:54 | 00,063,600 | —- | M] (CyberLink Corp.)
"C:\Program Files\iCal v4.0 Web Calendar\ical.exe" -> C:\Program Files\iCal v4.0 Web Calendar\ical.exe [C:\Program Files\iCal v4.0 Web Calendar\ical.exe:*:Disabled:ical] -> [2008/01/03 11:02:06 | 02,094,080 | —- | M] ()
"C:\Program Files\InterVideo\DVD8\WinDVD.exe" -> C:\Program Files\InterVideo\DVD8\WinDVD.exe [C:\Program Files\InterVideo\DVD8\WinDVD.exe:*:Enabled:WinDVD] -> File not found
"C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2009/06/05 11:39:18 | 14,073,640 | —- | M] (Apple Inc.)
"C:\Program Files\Java\jre1.5.0_09\bin\javaw.exe" -> C:\Program Files\Java\jre1.5.0_09\bin\javaw.exe [C:\Program Files\Java\jre1.5.0_09\bin\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary] -> [2006/09/07 12:14:46 | 00,053,346 | —- | M] (Sun Microsystems, Inc.)
"C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe" -> C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe [C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe:*:Enabled:Secure Application Manager Proxy] -> [2008/10/21 16:40:18 | 00,386,440 | —- | M] (Juniper Networks)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" -> C:\Program Files\Microsoft ActiveSync\rapimgr.exe [C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager] -> [2006/11/13 11:39:34 | 00,199,464 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" -> C:\Program Files\Microsoft ActiveSync\wcescomm.exe [C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager] -> [2006/11/13 11:39:52 | 01,289,000 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" -> C:\Program Files\Microsoft ActiveSync\WCESMgr.exe [C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application] -> [2006/11/13 11:39:54 | 04,270,888 | —- | M] (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe" -> C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe [C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe:*:Enabled:Firefox] -> [2009/08/06 16:36:13 | 00,307,704 | —- | M] (Mozilla Corporation)
"C:\Program Files\Sybase\SQL Anywhere 9\win32\dbeng9.exe" -> C:\Program Files\Sybase\SQL Anywhere 9\win32\dbeng9.exe [C:\Program Files\Sybase\SQL Anywhere 9\win32\dbeng9.exe:*:Enabled:Adaptive Server Anywhere Database Engine] -> [2007/06/13 08:11:38 | 00,077,824 | —- | M] (iAnywhere Solutions, Inc.)
"C:\Program Files\Warcraft III\Warcraft III.exe" -> C:\Program Files\Warcraft III\Warcraft III.exe [C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III] -> File not found
"C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe" -> C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe [C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe:*:Enabled:SecureDoc ] -> [2006/06/01 07:55:20 | 00,425,984 | —- | M] (Winmagic Inc.)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
"AlternateShell" -> cmd.exe -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" ->  [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > ->  -> 
C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2004/08/11 16:15:00 | 00,000,000 | —- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}\Shell
\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}\Shell\\"" ->  [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}\Shell\AutoRun
\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}\Shell\AutoRun\\"" ->  [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}\Shell\AutoRun\command
\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}\Shell\AutoRun\command\\"" -> E:\Photokinz.exe [E:\Photokinz.exe] -> File not found
 
[Registry - Additional Scans - Safe List]
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 8/16/2009 12:27:04 PM Computer Name = LAPTOP | Source = Microsoft Office 11 | ID = 1000 -> Description = Faulting application winword.exe, version 11.0.8307.0, stamp 49ee835a, faulting module winword.exe, version 11.0.8307.0, stamp 49ee835a, debug? 0, fault address 0x005e61fe.
Application [ Error ] 8/18/2009 3:15:19 PM Computer Name = LAPTOP | Source = Symantec AntiVirus | ID = 16711726 -> Description =	   Security Risk Found!Risk: Packed.Generic.200 in File: C:\Documents and Settings\Dustin\Local Settings\Temp\UAC15b7.tmp by: Manual scan.  Action: Clean failed : Quarantine failed.  Action Description: The file was left unchanged.	
Application [ Error ] 8/18/2009 3:15:27 PM Computer Name = LAPTOP | Source = Symantec AntiVirus | ID = 16711731 -> Description =	   Security Risk Found!Risk: Packed.Generic.200 in File: C:\Documents and Settings\Dustin\Local Settings\Temp\UAC15b7.tmp by: Manual scan.  Action: Cleaned by Deletion.  Action Description:	  
Application [ Error ] 8/18/2009 3:15:40 PM Computer Name = LAPTOP | Source = Symantec AntiVirus | ID = 16711726 -> Description =	   Security Risk Found!Risk: Packed.Generic.205 in File: C:\Documents and Settings\Dustin\Local Settings\Temp\xcswaremon.tmp by: Manual scan.  Action: Clean failed : Quarantine failed.  Action Description: The file was left unchanged.	
Application [ Error ] 8/18/2009 3:15:40 PM Computer Name = LAPTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description =	   Risk:  in File: c:\documents and settings\dustin\local settings\application data\microsoft\windows media\9.0 by: Manual scan.  Action: Reboot Required.  Action Description:	  Risk:  in File: c:\documents and settings\dustin\local settings\application data\microsoft\windows media by: Manual scan.  Action: Reboot Required.  Action Description:	  Risk:  in File: C:\Documents and Settings\Dustin\Local Settings\Application Data\Microsoft by: Manual scan.  Action: Reboot Required.  Action Description:	  Risk:  in File: Internet browser temporary file cache by: Manual scan.  Action: Clean failed : Quarantine failed.  Action Description: The file was deleted successfully.	Risk Found!Risk: Backdoor.Tidserv!inf in File: C:\Documents and Settings\Dustin\Local Settings\Temp\UAC15c6.tmp by: Manual scan.  Action: Clean failed : Quarantine failed.  Action Description: The file was left unchanged.	
Application [ Error ] 8/18/2009 3:15:40 PM Computer Name = LAPTOP | Source = Symantec AntiVirus | ID = 16711731 -> Description =	   Security Risk Found!Risk: Packed.Generic.205 in File: C:\Documents and Settings\Dustin\Local Settings\Temp\xcswaremon.tmp by: Manual scan.  Action: Cleaned by Deletion.  Action Description:	  
Application [ Error ] 8/18/2009 4:05:59 PM Computer Name = LAPTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description =	   Risk Found!Risk: Packed.Generic.205 in File: C:\documents and settings\Dustin\local settings\Temp\xcswaremon.tmp by: Manual scan.  Action: Cleaned by Deletion.  Action Description:	  Risk:  in File: Internet browser temporary file cache by: Manual scan.  Action: Clean failed : Quarantine failed.  Action Description: The file was deleted successfully.	Risk Found!Risk: Backdoor.Tidserv in File: C:\WINDOWS\system32\drivers\UACd.sys by: Manual scan.  Action: Cleaned by Deletion.  Action Description:	  
Application [ Error ] 8/18/2009 7:58:14 PM Computer Name = LAPTOP | Source = crypt32 | ID = 131083 -> Description = Failed extract of third-party root list from auto update cab at:  with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.  
Application [ Error ] 8/18/2009 7:58:14 PM Computer Name = LAPTOP | Source = crypt32 | ID = 131083 -> Description = Failed extract of third-party root list from auto update cab at:  with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.  
Application [ Error ] 8/19/2009 10:40:31 AM Computer Name = LAPTOP | Source = Application Hang | ID = 1002 -> Description = Hanging application HijackThis.exe, version 1.99.0.1, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
System [ Error ] 8/3/2009 4:22:15 PM Computer Name = LAPTOP | Source = Dhcp | ID = 1000 -> Description = Your computer has lost the lease to its IP address 192.168.1.4 on the  Network Card with network address 001BFCD2FCD5.
System [ Error ] 8/6/2009 1:08:03 PM Computer Name = LAPTOP | Source = Dhcp | ID = 1002 -> Description = The IP address lease 192.168.1.2 for the Network Card with network address 001BFCD2FCD5 has been  denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
System [ Error ] 8/6/2009 6:39:44 PM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}.  The backup browser is stopping.
System [ Error ] 8/7/2009 2:59:01 AM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}.  The backup browser is stopping.
System [ Error ] 8/7/2009 10:40:12 AM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}.  The backup browser is stopping.
System [ Error ] 8/7/2009 9:00:01 PM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}.  The backup browser is stopping.
System [ Error ] 8/8/2009 2:18:30 AM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}.  The backup browser is stopping.
System [ Error ] 8/8/2009 10:32:43 AM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}.  The backup browser is stopping.
System [ Error ] 8/8/2009 9:45:14 PM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}.  The backup browser is stopping.
System [ Error ] 8/10/2009 10:00:09 AM Computer Name = LAPTOP | Source = Dhcp | ID = 1000 -> Description = Your computer has lost the lease to its IP address 192.168.1.4 on the  Network Card with network address 001BFCD2FCD5.
 
[Files/Folders - Created Within 30 Days]
1 C:\*.tmp files -> C:\*.tmp -> 
1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
OTS.exe -> C:\Documents and Settings\Dustin\Desktop\OTS.exe -> [2009/08/21 09:37:20 | 00,514,048 | —- | C] (OldTimer Tools)
HijackThis.lnk -> C:\Documents and Settings\Dustin\Desktop\HijackThis.lnk -> [2009/08/19 08:51:42 | 00,001,734 | —- | C] ()
Trend Micro -> C:\Program Files\Trend Micro -> [2009/08/19 08:51:36 | 00,000,000 | —D | C]
HJTInstall.exe -> C:\Documents and Settings\Dustin\Desktop\HJTInstall.exe -> [2009/08/19 08:49:11 | 00,812,344 | —- | C] (Trend Micro Inc.)
19876094 -> C:\Documents and Settings\All Users\Application Data\19876094 -> [2009/08/19 07:58:08 | 00,000,000 | —D | C]
{BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> [2009/08/18 12:41:11 | 00,000,282 | -H– | C] ()
net.net -> C:\WINDOWS\System32\net.net -> [2009/08/18 12:40:39 | 00,037,263 | —- | C] (Comp)
BVC Calendar NEW.xls -> C:\Documents and Settings\Dustin\Desktop\BVC Calendar NEW.xls -> [2009/08/17 08:36:55 | 00,230,400 | —- | C] ()
dhtmled.ocx -> C:\WINDOWS\System32\dllcache\dhtmled.ocx -> [2009/08/12 10:31:54 | 00,128,512 | —- | C] (Microsoft Corporation)
msoe.dll -> C:\WINDOWS\System32\dllcache\msoe.dll -> [2009/08/12 10:31:46 | 01,315,328 | —- | C] (Microsoft Corporation)
IECompatCache -> C:\Documents and Settings\Dustin\IECompatCache -> [2009/08/11 09:28:59 | 00,000,000 | -HSD | C]
PrivacIE -> C:\Documents and Settings\Dustin\PrivacIE -> [2009/08/11 09:18:40 | 00,000,000 | -HSD | C]
ntprint.cat -> C:\WINDOWS\System32\dllcache\ntprint.cat -> [2009/08/11 09:08:33 | 01,089,593 | —- | C] ()
XPSViewer -> C:\WINDOWS\System32\XPSViewer -> [2009/08/10 16:28:54 | 00,000,000 | —D | C]
MSBuild -> C:\Program Files\MSBuild -> [2009/08/10 16:28:48 | 00,000,000 | —D | C]
Reference Assemblies -> C:\Program Files\Reference Assemblies -> [2009/08/10 16:28:35 | 00,000,000 | —D | C]
printfilterpipelinesvc.exe -> C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe -> [2009/08/10 16:28:02 | 00,597,504 | —- | C] (Microsoft Corporation)
prntvpt.dll -> C:\WINDOWS\System32\prntvpt.dll -> [2009/08/10 16:28:02 | 00,117,760 | —- | C] (Microsoft Corporation)
filterpipelineprintproc.dll -> C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll -> [2009/08/10 16:28:02 | 00,089,088 | —- | C] (Microsoft Corporation)
xpssvcs.dll -> C:\WINDOWS\System32\xpssvcs.dll -> [2009/08/10 16:28:01 | 01,676,288 | —- | C] (Microsoft Corporation)
xpssvcs.dll -> C:\WINDOWS\System32\dllcache\xpssvcs.dll -> [2009/08/10 16:28:01 | 01,676,288 | —- | C] (Microsoft Corporation)
xpsshhdr.dll -> C:\WINDOWS\System32\xpsshhdr.dll -> [2009/08/10 16:28:01 | 00,575,488 | —- | C] (Microsoft Corporation)
xpsshhdr.dll -> C:\WINDOWS\System32\dllcache\xpsshhdr.dll -> [2009/08/10 16:28:01 | 00,575,488 | —- | C] (Microsoft Corporation)
58ba0bc4b57ee9a7f3 -> C:\58ba0bc4b57ee9a7f3 -> [2009/08/10 16:28:01 | 00,000,000 | —D | C]
Credit Reports -> C:\Documents and Settings\Dustin\Desktop\Credit Reports -> [2009/08/10 11:39:45 | 00,000,000 | —D | C]
sample.mmb -> C:\Documents and Settings\Dustin\My Documents\sample.mmb -> [2009/08/10 08:32:30 | 00,020,480 | —- | C] ()
home_budget_backup_20090810_082710.shbf -> C:\Documents and Settings\Dustin\My Documents\home_budget_backup_20090810_082710.shbf -> [2009/08/10 08:27:10 | 00,151,552 | —- | C] ()
home_budget2.shbf -> C:\Documents and Settings\Dustin\My Documents\home_budget2.shbf -> [2009/08/10 08:26:28 | 00,139,264 | —- | C] ()
home_budget.shbf -> C:\Documents and Settings\Dustin\My Documents\home_budget.shbf -> [2009/08/10 08:22:07 | 00,151,552 | —- | C] ()
home_budget.ini -> C:\Documents and Settings\Dustin\Application Data\home_budget.ini -> [2009/08/10 08:22:07 | 00,001,827 | —- | C] ()
Simple Home Budget -> C:\Documents and Settings\Dustin\Local Settings\Application Data\Simple Home Budget -> [2009/08/10 08:21:36 | 00,000,000 | —D | C]
HB -> C:\Program Files\HB -> [2009/08/10 08:08:36 | 00,000,000 | —D | C]
IETldCache -> C:\Documents and Settings\Dustin\IETldCache -> [2009/08/08 19:39:59 | 00,000,000 | -HSD | C]
~$rlsConference.doc -> C:\Documents and Settings\Dustin\My Documents\~$rlsConference.doc -> [2009/08/08 09:44:38 | 00,000,162 | -H– | C] ()
xpshims.dll -> C:\WINDOWS\System32\dllcache\xpshims.dll -> [2009/08/08 08:38:57 | 00,012,800 | —- | C] (Microsoft Corporation)
iertutil.dll -> C:\WINDOWS\System32\dllcache\iertutil.dll -> [2009/08/08 08:38:56 | 01,985,536 | —- | C] (Microsoft Corporation)
msfeeds.dll -> C:\WINDOWS\System32\dllcache\msfeeds.dll -> [2009/08/08 08:38:56 | 00,594,432 | —- | C] (Microsoft Corporation)
msfeedsbs.dll -> C:\WINDOWS\System32\dllcache\msfeedsbs.dll -> [2009/08/08 08:38:56 | 00,055,296 | —- | C] (Microsoft Corporation)
ieframe.dll -> C:\WINDOWS\System32\dllcache\ieframe.dll -> [2009/08/08 08:38:55 | 11,067,392 | —- | C] (Microsoft Corporation)
ieproxy.dll -> C:\WINDOWS\System32\dllcache\ieproxy.dll -> [2009/08/08 08:38:55 | 00,246,272 | —- | C] (Microsoft Corporation)
ie8updates -> C:\WINDOWS\ie8updates -> [2009/08/08 08:38:50 | 00,000,000 | —D | C]
iecompat.dll -> C:\WINDOWS\System32\dllcache\iecompat.dll -> [2009/08/08 08:37:29 | 00,101,376 | —- | C] (Microsoft Corporation)
WBEM -> C:\WINDOWS\WBEM -> [2009/08/08 08:36:53 | 00,000,000 | —D | C]
ie8 -> C:\WINDOWS\ie8 -> [2009/08/08 08:34:56 | 00,000,000 | -H-D | C]
0806092123(4).jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123(4).jpg -> [2009/08/06 21:33:12 | 00,072,724 | —- | C] ()
0806092123(3).jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123(3).jpg -> [2009/08/06 21:32:31 | 00,072,724 | —- | C] ()
0806092123(2).jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123(2).jpg -> [2009/08/06 21:32:08 | 00,072,724 | —- | C] ()
0806092123.jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123.jpg -> [2009/08/06 21:32:07 | 00,072,724 | —- | C] ()
GirlsConference.doc -> C:\Documents and Settings\Dustin\My Documents\GirlsConference.doc -> [2009/08/06 17:04:51 | 00,025,600 | —- | C] ()
Seahawks.jpg -> C:\Documents and Settings\Dustin\Desktop\Seahawks.jpg -> [2009/08/06 16:37:33 | 00,247,865 | —- | C] ()
mswebdvd.dll -> C:\WINDOWS\System32\dllcache\mswebdvd.dll -> [2009/08/05 03:01:48 | 00,204,800 | —- | C] (Microsoft Corporation)
xvidcore.dll -> C:\WINDOWS\System32\xvidcore.dll -> [2008/08/15 17:32:44 | 00,765,952 | —- | C] ()
xvidvfw.dll -> C:\WINDOWS\System32\xvidvfw.dll -> [2008/08/15 17:32:43 | 00,180,224 | —- | C] ()
upctrl32.INI -> C:\WINDOWS\upctrl32.INI -> [2008/05/06 15:07:39 | 00,000,000 | —- | C] ()
wcds.ini.07.3 -> C:\WINDOWS\wcds.ini.07.3 -> [2008/05/06 15:05:45 | 00,002,527 | —- | C] ()
ezdatar.ini -> C:\WINDOWS\ezdatar.ini -> [2008/05/06 14:40:36 | 00,000,193 | —- | C] ()
FTSL.INI -> C:\WINDOWS\FTSL.INI -> [2008/05/06 14:39:45 | 00,000,027 | —- | C] ()
WUNZIP32.DLL -> C:\WINDOWS\System32\WUNZIP32.DLL -> [2008/04/16 08:28:48 | 00,093,488 | —- | C] ()
FtisUtil.dll -> C:\WINDOWS\System32\FtisUtil.dll -> [2008/04/16 08:23:14 | 00,406,832 | —- | C] ()
MYCALC.DLL -> C:\WINDOWS\System32\MYCALC.DLL -> [2008/03/25 11:50:18 | 01,927,680 | —- | C] ()
wcds.ini -> C:\WINDOWS\wcds.ini -> [2008/03/11 16:31:07 | 00,002,543 | —- | C] ()
ezhelp32.dll -> C:\WINDOWS\System32\ezhelp32.dll -> [2008/03/11 16:30:28 | 00,049,152 | —- | C] ()
NYL_Screensaver_v2.ini -> C:\WINDOWS\NYL_Screensaver_v2.ini -> [2008/02/07 15:19:42 | 00,000,058 | —- | C] ()
iplayer.INI -> C:\WINDOWS\iplayer.INI -> [2008/01/14 18:39:42 | 00,000,000 | —- | C] ()
fxsperf.ini -> C:\WINDOWS\System32\fxsperf.ini -> [2008/01/10 08:36:28 | 00,001,793 | —- | C] ()
CmdLineExt03.dll -> C:\WINDOWS\System32\CmdLineExt03.dll -> [2008/01/04 17:51:38 | 00,043,520 | —- | C] ()
SIntfNT.dll -> C:\WINDOWS\System32\SIntfNT.dll -> [2008/01/04 17:50:19 | 00,021,840 | —- | C] ()
SIntf32.dll -> C:\WINDOWS\System32\SIntf32.dll -> [2008/01/04 17:50:19 | 00,017,212 | —- | C] ()
SIntf16.dll -> C:\WINDOWS\System32\SIntf16.dll -> [2008/01/04 17:50:18 | 00,012,067 | —- | C] ()
SCapPro.INI -> C:\WINDOWS\SCapPro.INI -> [2007/12/10 14:46:39 | 00,000,072 | —- | C] ()
cdplayer.ini -> C:\WINDOWS\cdplayer.ini -> [2007/12/08 11:10:02 | 00,007,374 | —- | C] ()
newload.INI -> C:\WINDOWS\newload.INI -> [2007/09/06 07:32:21 | 00,000,000 | —- | C] ()
ZPORT4AS.dll -> C:\WINDOWS\System32\ZPORT4AS.dll -> [2007/08/24 13:05:16 | 00,011,776 | —- | C] ()
VPC32.INI -> C:\WINDOWS\VPC32.INI -> [2007/08/23 17:30:25 | 00,000,000 | —- | C] ()
STERWENT.INI -> C:\WINDOWS\STERWENT.INI -> [2007/08/21 13:15:42 | 00,000,460 | -H– | C] ()
PrintFix.dll -> C:\WINDOWS\System32\PrintFix.dll -> [2007/08/21 13:13:48 | 00,045,056 | —- | C] ()
ezmail.ini -> C:\WINDOWS\ezmail.ini -> [2007/08/21 13:05:07 | 00,000,314 | —- | C] ()
lcppn201.dll -> C:\WINDOWS\System32\lcppn201.dll -> [2007/08/21 13:05:02 | 03,203,072 | —- | C] ()
ftcsutil.INI -> C:\WINDOWS\ftcsutil.INI -> [2007/08/21 13:04:28 | 00,000,000 | —- | C] ()
dtidb.dll -> C:\WINDOWS\System32\dtidb.dll -> [2007/08/21 13:03:59 | 00,269,312 | —- | C] ()
ic32.ini -> C:\WINDOWS\System32\ic32.ini -> [2007/08/21 13:03:57 | 00,000,151 | —- | C] ()
CTREESTD.DLL -> C:\WINDOWS\System32\CTREESTD.DLL -> [2007/08/21 13:03:56 | 00,163,840 | —- | C] ()
U2LSQRT.DLL -> C:\WINDOWS\System32\U2LSQRT.DLL -> [2007/08/21 13:03:56 | 00,082,432 | —- | C] ()
U2LESBSE.DLL -> C:\WINDOWS\System32\U2LESBSE.DLL -> [2007/08/21 13:03:56 | 00,070,656 | —- | C] ()
U2LEXPO.DLL -> C:\WINDOWS\System32\U2LEXPO.DLL -> [2007/08/21 13:03:56 | 00,063,488 | —- | C] ()
U2LPDXTM.DLL -> C:\WINDOWS\System32\U2LPDXTM.DLL -> [2007/08/21 13:03:56 | 00,053,248 | —- | C] ()
U2LSSM.DLL -> C:\WINDOWS\System32\U2LSSM.DLL -> [2007/08/21 13:03:56 | 00,040,960 | —- | C] ()
U2LBAR.DLL -> C:\WINDOWS\System32\U2LBAR.DLL -> [2007/08/21 13:03:56 | 00,040,960 | —- | C] ()
U2LCAPS.DLL -> C:\WINDOWS\System32\U2LCAPS.DLL -> [2007/08/21 13:03:56 | 00,038,400 | —- | C] ()
U2LSTR.DLL -> C:\WINDOWS\System32\U2LSTR.DLL -> [2007/08/21 13:03:56 | 00,033,280 | —- | C] ()
U2LTIME.DLL -> C:\WINDOWS\System32\U2LTIME.DLL -> [2007/08/21 13:03:56 | 00,030,720 | —- | C] ()
U2LTEC1.DLL -> C:\WINDOWS\System32\U2LTEC1.DLL -> [2007/08/21 13:03:56 | 00,028,672 | —- | C] ()
U2LSTRNG.DLL -> C:\WINDOWS\System32\U2LSTRNG.DLL -> [2007/08/21 13:03:56 | 00,027,136 | —- | C] ()
U2LTDATE.DLL -> C:\WINDOWS\System32\U2LTDATE.DLL -> [2007/08/21 13:03:56 | 00,026,624 | —- | C] ()
U2LJUL.DLL -> C:\WINDOWS\System32\U2LJUL.DLL -> [2007/08/21 13:03:56 | 00,026,112 | —- | C] ()
U2LASC.DLL -> C:\WINDOWS\System32\U2LASC.DLL -> [2007/08/21 13:03:56 | 00,026,112 | —- | C] ()
PG32CONV.DLL -> C:\WINDOWS\System32\PG32CONV.DLL -> [2007/08/21 13:03:55 | 00,100,352 | —- | C] ()
U25TOTAL.DLL -> C:\WINDOWS\System32\U25TOTAL.DLL -> [2007/08/21 13:03:55 | 00,059,904 | —- | C] ()
P2SMCUBE.DLL -> C:\WINDOWS\System32\P2SMCUBE.DLL -> [2007/08/21 13:03:54 | 00,282,624 | —- | C] ()
P2MOLAP.DLL -> C:\WINDOWS\System32\P2MOLAP.DLL -> [2007/08/21 13:03:54 | 00,270,336 | —- | C] ()
P2SOLAP.DLL -> C:\WINDOWS\System32\P2SOLAP.DLL -> [2007/08/21 13:03:54 | 00,258,048 | —- | C] ()
CRUTL14.DLL -> C:\WINDOWS\System32\CRUTL14.DLL -> [2007/08/21 13:03:53 | 00,299,008 | —- | C] ()
LFFAX60N.DLL -> C:\WINDOWS\System32\LFFAX60N.DLL -> [2007/08/21 13:03:53 | 00,176,128 | —- | C] ()
LFCMP60N.DLL -> C:\WINDOWS\System32\LFCMP60N.DLL -> [2007/08/21 13:03:53 | 00,141,824 | —- | C] ()
LTFIL60N.DLL -> C:\WINDOWS\System32\LTFIL60N.DLL -> [2007/08/21 13:03:53 | 00,043,008 | —- | C] ()
LFEPS60N.DLL -> C:\WINDOWS\System32\LFEPS60N.DLL -> [2007/08/21 13:03:53 | 00,022,528 | —- | C] ()
LFBMP60N.DLL -> C:\WINDOWS\System32\LFBMP60N.DLL -> [2007/08/21 13:03:53 | 00,022,016 | —- | C] ()
IMPLODE.DLL -> C:\WINDOWS\System32\IMPLODE.DLL -> [2007/08/21 13:03:53 | 00,017,920 | —- | C] ()
SWCGUIDE.INI -> C:\WINDOWS\SWCGUIDE.INI -> [2007/08/21 13:03:23 | 00,000,036 | —- | C] ()
hpbafd.ini -> C:\WINDOWS\hpbafd.ini -> [2007/08/21 12:21:02 | 00,000,169 | —- | C] ()
SecurDoc.INI -> C:\WINDOWS\SecurDoc.INI -> [2007/08/21 12:13:33 | 00,000,000 | —- | C] ()
ODBC.INI -> C:\WINDOWS\ODBC.INI -> [2007/08/20 21:04:37 | 00,001,053 | —- | C] ()
smscfg.ini -> C:\WINDOWS\smscfg.ini -> [2007/08/14 18:14:37 | 00,000,061 | —- | C] ()
bioapi_mds300.dll -> C:\WINDOWS\System32\bioapi_mds300.dll -> [2007/08/14 18:09:01 | 00,143,360 | —- | C] ()
bioapi100.dll -> C:\WINDOWS\System32\bioapi100.dll -> [2007/08/14 18:09:01 | 00,106,496 | —- | C] ()
preflib.dll -> C:\WINDOWS\System32\preflib.dll -> [2007/08/14 18:04:16 | 00,086,016 | —- | C] ()
bcm1xsup.dll -> C:\WINDOWS\System32\bcm1xsup.dll -> [2007/08/14 18:04:14 | 00,757,760 | —- | C] ()
OEMINFO.INI -> C:\WINDOWS\System32\OEMINFO.INI -> [2007/08/14 17:42:06 | 00,001,120 | —- | C] ()
AmRes_en.dll -> C:\WINDOWS\System32\AmRes_en.dll -> [2006/09/12 11:07:36 | 00,184,320 | —- | C] ()
AmRes_es.dll -> C:\WINDOWS\System32\AmRes_es.dll -> [2006/09/12 11:01:48 | 00,196,608 | —- | C] ()
AmRes_ko.dll -> C:\WINDOWS\System32\AmRes_ko.dll -> [2006/09/12 11:01:42 | 00,192,512 | —- | C] ()
AmRes_de.dll -> C:\WINDOWS\System32\AmRes_de.dll -> [2006/09/12 11:01:34 | 00,196,608 | —- | C] ()
AmRes_pt-BR.dll -> C:\WINDOWS\System32\AmRes_pt-BR.dll -> [2006/09/12 11:01:28 | 00,184,320 | —- | C] ()
AmRes_fr.dll -> C:\WINDOWS\System32\AmRes_fr.dll -> [2006/09/12 11:01:20 | 00,192,512 | —- | C] ()
AmRes_ja.dll -> C:\WINDOWS\System32\AmRes_ja.dll -> [2006/09/12 11:01:12 | 00,188,416 | —- | C] ()
AmRes_ru.dll -> C:\WINDOWS\System32\AmRes_ru.dll -> [2006/09/12 11:01:06 | 00,208,896 | —- | C] ()
AmRes_it.dll -> C:\WINDOWS\System32\AmRes_it.dll -> [2006/09/12 11:00:58 | 00,196,608 | —- | C] ()
AmRes_zh-CHS.dll -> C:\WINDOWS\System32\AmRes_zh-CHS.dll -> [2006/09/12 11:00:52 | 00,176,128 | —- | C] ()
AmRes_zh-CHT.dll -> C:\WINDOWS\System32\AmRes_zh-CHT.dll -> [2006/09/12 11:00:44 | 00,172,032 | —- | C] ()
wxvault.dll -> C:\WINDOWS\System32\wxvault.dll -> [2006/09/08 07:32:02 | 00,286,720 | —- | C] ()
detoured.dll -> C:\WINDOWS\System32\detoured.dll -> [2006/09/08 07:30:44 | 00,004,096 | —- | C] ()
Internationalization_en.dll -> C:\WINDOWS\System32\Internationalization_en.dll -> [2006/09/05 09:05:32 | 00,077,824 | —- | C] ()
Internationalization_pt.dll -> C:\WINDOWS\System32\Internationalization_pt.dll -> [2006/09/05 08:26:06 | 00,073,728 | —- | C] ()
Internationalization_zh-CHT.dll -> C:\WINDOWS\System32\Internationalization_zh-CHT.dll -> [2006/09/05 08:25:54 | 00,069,632 | —- | C] ()
Internationalization_ko.dll -> C:\WINDOWS\System32\Internationalization_ko.dll -> [2006/09/05 08:25:42 | 00,073,728 | —- | C] ()
Internationalization_es.dll -> C:\WINDOWS\System32\Internationalization_es.dll -> [2006/09/05 08:25:32 | 00,077,824 | —- | C] ()
Internationalization_ru.dll -> C:\WINDOWS\System32\Internationalization_ru.dll -> [2006/09/05 08:25:20 | 00,077,824 | —- | C] ()
Internationalization_ja.dll -> C:\WINDOWS\System32\Internationalization_ja.dll -> [2006/09/05 08:25:10 | 00,073,728 | —- | C] ()
Internationalization_it.dll -> C:\WINDOWS\System32\Internationalization_it.dll -> [2006/09/05 08:24:58 | 00,081,920 | —- | C] ()
Internationalization_de.dll -> C:\WINDOWS\System32\Internationalization_de.dll -> [2006/09/05 08:24:48 | 00,081,920 | —- | C] ()
Internationalization_fr.dll -> C:\WINDOWS\System32\Internationalization_fr.dll -> [2006/09/05 08:24:36 | 00,081,920 | —- | C] ()
Internationalization_zh-CHS.dll -> C:\WINDOWS\System32\Internationalization_zh-CHS.dll -> [2006/09/05 08:24:26 | 00,069,632 | —- | C] ()
TspPopup_RUS.dll -> C:\WINDOWS\System32\TspPopup_RUS.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
TspPopup_ITA.dll -> C:\WINDOWS\System32\TspPopup_ITA.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
TspPopup_FRA.dll -> C:\WINDOWS\System32\TspPopup_FRA.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
TspPopup_ESN.dll -> C:\WINDOWS\System32\TspPopup_ESN.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
TspPopup_ENU.dll -> C:\WINDOWS\System32\TspPopup_ENU.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
TspPopup_DEU.dll -> C:\WINDOWS\System32\TspPopup_DEU.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
TspPopup_CHS.dll -> C:\WINDOWS\System32\TspPopup_CHS.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
Tsp.dll -> C:\WINDOWS\System32\Tsp.dll -> [2006/06/12 09:01:16 | 00,348,160 | —- | C] ()
SDMigrate.dll -> C:\WINDOWS\System32\SDMigrate.dll -> [2006/06/01 07:55:20 | 00,040,960 | —- | C] ()
SDInst.dll -> C:\WINDOWS\System32\SDInst.dll -> [2006/06/01 07:55:10 | 00,032,839 | —- | C] ()
Uninst.dll -> C:\WINDOWS\System32\Uninst.dll -> [2006/06/01 07:50:44 | 00,041,030 | —- | C] ()
sdck.dll -> C:\WINDOWS\System32\sdck.dll -> [2006/06/01 07:46:32 | 00,176,190 | —- | C] ()
SDDisk2K.sys -> C:\WINDOWS\System32\drivers\SDDisk2K.sys -> [2006/01/24 11:36:44 | 00,194,048 | —- | C] ()
pbadrvdll.dll -> C:\WINDOWS\System32\pbadrvdll.dll -> [2005/12/01 13:41:20 | 00,057,344 | —- | C] ()
wmpki.dll -> C:\WINDOWS\System32\wmpki.dll -> [2005/09/23 08:03:38 | 00,389,120 | —- | C] ()
DemoLicense.dll -> C:\WINDOWS\System32\DemoLicense.dll -> [2005/09/20 12:36:06 | 00,798,720 | —- | C] ()
wmcv.dll -> C:\WINDOWS\System32\wmcv.dll -> [2005/06/17 09:21:50 | 00,036,864 | —- | C] ()
orun32.ini -> C:\WINDOWS\orun32.ini -> [2004/08/11 16:24:19 | 00,000,831 | —- | C] ()
win.ini -> C:\WINDOWS\win.ini -> [2004/08/11 16:00:37 | 00,000,683 | —- | C] ()
system.ini -> C:\WINDOWS\system.ini -> [2004/08/11 16:00:35 | 00,000,227 | —- | C] ()
lmgr10.dll -> C:\WINDOWS\System32\lmgr10.dll -> [2004/07/21 14:03:14 | 00,917,504 | —- | C] ()
ADsSecurity.dll -> C:\WINDOWS\System32\ADsSecurity.dll -> [2004/07/20 13:27:52 | 00,057,344 | —- | C] ()
sdlibeay.dll -> C:\WINDOWS\System32\sdlibeay.dll -> [2004/07/19 13:46:40 | 00,876,544 | —- | C] ()
xltZlib.dll -> C:\WINDOWS\System32\xltZlib.dll -> [2004/03/18 17:01:20 | 00,072,192 | —- | C] ()
POSTLOG2.DLL -> C:\WINDOWS\System32\POSTLOG2.DLL -> [2003/12/18 08:09:06 | 00,159,744 | —- | C] ()
OUTLPERF.INI -> C:\WINDOWS\System32\OUTLPERF.INI -> [2003/01/07 13:05:08 | 00,002,695 | —- | C] ()
RASFUNCS.DLL -> C:\WINDOWS\System32\RASFUNCS.DLL -> [2002/03/19 12:42:02 | 00,045,056 | —- | C] ()
IAPI.INI -> C:\WINDOWS\IAPI.INI -> [2002/03/12 07:01:26 | 00,032,881 | —- | C] ()
FTUtilities.dll -> C:\WINDOWS\System32\FTUtilities.dll -> [2002/03/05 08:47:58 | 00,061,440 | —- | C] ()
IAPI5.DLL -> C:\WINDOWS\System32\IAPI5.DLL -> [2002/03/01 12:03:26 | 00,253,952 | —- | C] ()
NYLCERT2.DLL -> C:\WINDOWS\System32\NYLCERT2.DLL -> [2002/02/06 13:03:16 | 00,065,536 | —- | C] ()
MAPIPROF.DLL -> C:\WINDOWS\System32\MAPIPROF.DLL -> [2001/10/04 12:34:56 | 00,118,784 | —- | C] ()
iapismapi.dll -> C:\WINDOWS\System32\iapismapi.dll -> [2001/08/22 12:34:12 | 00,045,056 | —- | C] ()
iapiemapi.dll -> C:\WINDOWS\System32\iapiemapi.dll -> [2001/08/22 12:34:04 | 00,057,344 | —- | C] ()
NYLUTIL7.DLL -> C:\WINDOWS\System32\NYLUTIL7.DLL -> [2001/08/22 11:30:22 | 00,024,576 | —- | C] ()
FTAACREQ.DLL -> C:\WINDOWS\System32\FTAACREQ.DLL -> [2001/06/13 07:06:00 | 00,049,152 | —- | C] ()
MSRTEDIT.DLL -> C:\WINDOWS\System32\MSRTEDIT.DLL -> [1999/01/22 12:46:58 | 00,065,536 | —- | C] ()
VBALINK.DLL -> C:\WINDOWS\System32\VBALINK.DLL -> [1993/08/24 08:19:20 | 00,037,568 | —- | C] ()
 
[Files/Folders - Modified Within 30 Days]
1 C:\Documents and Settings\Dustin\My Documents\*.tmp files -> C:\Documents and Settings\Dustin\My Documents\*.tmp -> 
994 C:\Documents and Settings\Dustin\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Dustin\Local Settings\Temp\*.tmp -> 
My Money.mny -> C:\Documents and Settings\Dustin\My Documents\My Money.mny -> [2009/08/21 09:37:37 | 03,952,640 | —- | M] ()
OTS.exe -> C:\Documents and Settings\Dustin\Desktop\OTS.exe -> [2009/08/21 09:37:20 | 00,514,048 | —- | M] (OldTimer Tools)
{BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> [2009/08/21 09:25:57 | 00,000,282 | -H– | M] ()
Word.lnk -> C:\Documents and Settings\Dustin\Desktop\Word.lnk -> [2009/08/21 08:32:35 | 00,002,497 | —- | M] ()
d3d9caps.dat -> C:\WINDOWS\System32\d3d9caps.dat -> [2009/08/19 14:07:43 | 00,001,324 | —- | M] ()
Excel.lnk -> C:\Documents and Settings\Dustin\Desktop\Excel.lnk -> [2009/08/19 10:35:01 | 00,002,495 | —- | M] ()
HijackThis.lnk -> C:\Documents and Settings\Dustin\Desktop\HijackThis.lnk -> [2009/08/19 08:51:42 | 00,001,734 | —- | M] ()
HJTInstall.exe -> C:\Documents and Settings\Dustin\Desktop\HJTInstall.exe -> [2009/08/19 08:49:15 | 00,812,344 | —- | M] (Trend Micro Inc.)
PerfStringBackup.INI -> C:\WINDOWS\System32\PerfStringBackup.INI -> [2009/08/19 08:43:42 | 00,561,868 | —- | M] ()
perfh009.dat -> C:\WINDOWS\System32\perfh009.dat -> [2009/08/19 08:43:42 | 00,471,576 | —- | M] ()
perfc009.dat -> C:\WINDOWS\System32\perfc009.dat -> [2009/08/19 08:43:42 | 00,080,574 | —- | M] ()
wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2009/08/19 08:39:26 | 00,002,206 | —- | M] ()
SA.DAT -> C:\WINDOWS\tasks\SA.DAT -> [2009/08/19 08:38:31 | 00,000,006 | -H– | M] ()
bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2009/08/19 08:38:24 | 00,002,048 | –S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2009/08/19 08:38:20 | 10,633,46176 | -HS- | M] ()
NTUSER.DAT -> C:\Documents and Settings\Dustin\NTUSER.DAT -> [2009/08/19 08:34:08 | 05,242,880 | —- | M] ()
ntuser.ini -> C:\Documents and Settings\Dustin\ntuser.ini -> [2009/08/19 07:41:02 | 00,000,278 | -HS- | M] ()
a.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\a.exe -> [2009/08/18 12:41:10 | 00,151,040 | —- | M] ()
net.net -> C:\WINDOWS\System32\net.net -> [2009/08/18 12:40:40 | 00,037,263 | —- | M] (Comp)
BVC Calendar NEW.xls -> C:\Documents and Settings\Dustin\Desktop\BVC Calendar NEW.xls -> [2009/08/17 12:51:09 | 00,230,400 | —- | M] ()
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2009/08/16 14:14:12 | 00,004,646 | —- | M] ()
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2009/08/16 14:14:12 | 00,004,232 | —- | M] ()
imsins.BAK -> C:\WINDOWS\imsins.BAK -> [2009/08/12 12:31:55 | 00,001,374 | —- | M] ()
FNTCACHE.DAT -> C:\WINDOWS\System32\FNTCACHE.DAT -> [2009/08/10 17:54:01 | 00,124,520 | —- | M] ()
Perflib_Perfdata_fec.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_fec.dat -> [2009/08/10 16:28:03 | 00,016,384 | —- | M] ()
My Money Backup.mbf -> C:\Documents and Settings\Dustin\My Documents\My Money Backup.mbf -> [2009/08/10 09:07:29 | 01,126,960 | R— | M] ()
sample.mmb -> C:\Documents and Settings\Dustin\My Documents\sample.mmb -> [2009/08/10 08:59:55 | 00,020,480 | —- | M] ()
home_budget.ini -> C:\Documents and Settings\Dustin\Application Data\home_budget.ini -> [2009/08/10 08:27:10 | 00,001,827 | —- | M] ()
home_budget_backup_20090810_082710.shbf -> C:\Documents and Settings\Dustin\My Documents\home_budget_backup_20090810_082710.shbf -> [2009/08/10 08:26:38 | 00,151,552 | —- | M] ()
home_budget.shbf -> C:\Documents and Settings\Dustin\My Documents\home_budget.shbf -> [2009/08/10 08:26:38 | 00,151,552 | —- | M] ()
home_budget2.shbf -> C:\Documents and Settings\Dustin\My Documents\home_budget2.shbf -> [2009/08/10 08:26:38 | 00,139,264 | —- | M] ()
~$rlsConference.doc -> C:\Documents and Settings\Dustin\My Documents\~$rlsConference.doc -> [2009/08/08 09:44:38 | 00,000,162 | -H– | M] ()
GirlsConference.doc -> C:\Documents and Settings\Dustin\My Documents\GirlsConference.doc -> [2009/08/07 21:27:19 | 00,025,600 | —- | M] ()
0806092123(4).jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123(4).jpg -> [2009/08/06 21:33:14 | 00,072,724 | —- | M] ()
0806092123(3).jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123(3).jpg -> [2009/08/06 21:32:32 | 00,072,724 | —- | M] ()
0806092123(2).jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123(2).jpg -> [2009/08/06 21:32:09 | 00,072,724 | —- | M] ()
0806092123.jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123.jpg -> [2009/08/06 21:32:08 | 00,072,724 | —- | M] ()
Seahawks.jpg -> C:\Documents and Settings\Dustin\Desktop\Seahawks.jpg -> [2009/08/06 16:37:36 | 00,247,865 | —- | M] ()
mswebdvd.dll -> C:\WINDOWS\System32\mswebdvd.dll -> [2009/08/05 03:01:48 | 00,204,800 | —- | M] (Microsoft Corporation)
mswebdvd.dll -> C:\WINDOWS\System32\dllcache\mswebdvd.dll -> [2009/08/05 03:01:48 | 00,204,800 | —- | M] (Microsoft Corporation)
MRT.exe -> C:\WINDOWS\System32\MRT.exe -> [2009/07/29 18:49:14 | 24,281,536 | —- | M] (Microsoft Corporation)
dhtmled.ocx -> C:\WINDOWS\System32\dllcache\dhtmled.ocx -> [2009/07/27 16:27:12 | 00,128,512 | —- | M] (Microsoft Corporation)
ExchangePerflog_8484fa314873542ecfcccd43.dat -> C:\Documents and Settings\Dustin\Local Settings\Temp\ExchangePerflog_8484fa314873542ecfcccd43.dat -> [2008/10/06 10:09:01 | 00,131,336 | —- | M] ()
index.dat -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2008/10/05 21:35:46 | 00,049,152 | —- | M] ()
index.dat -> C:\WINDOWS\Temp\History\History.IE5\index.dat -> [2008/10/05 21:35:46 | 00,032,768 | —- | M] ()
index.dat -> C:\WINDOWS\Temp\Cookies\index.dat -> [2008/10/05 21:35:46 | 00,016,384 | —- | M] ()
NeoterisSetupApp.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\Juniper Networks\setup\NeoterisSetupApp.exe -> [2008/08/26 16:54:48 | 00,050,552 | RHS- | M] ()
FTIS200822.EXE -> C:\Documents and Settings\Dustin\Local Settings\Temp\Updates\FTIS200822.EXE -> [2008/07/16 12:15:32 | 02,994,331 | —- | M] ()
SMSetup.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\SEA35\SMSetup.exe -> [2008/06/30 07:19:17 | 00,099,680 | —- | M] (Smith Micro Software, Inc.)
SunWin32FunctionCalls_754447.dll -> C:\Documents and Settings\Dustin\Local Settings\Temp\SunWin32FunctionCalls_754447.dll -> [2008/06/16 11:06:09 | 00,061,440 | —- | M] (Centra Software, Inc.)
FTIS200821.EXE -> C:\Documents and Settings\Dustin\Local Settings\Temp\Updates\FTIS200821.EXE -> [2008/05/31 11:55:55 | 02,059,956 | —- | M] ()
_WUTL95.DLL -> C:\WINDOWS\Temp\_WUTL95.DLL -> [2008/05/06 15:08:26 | 00,036,864 | —- | M] (InstallShield Corporation, Inc.)
iTunesSetupAdmin[1].exe -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\PU926I5W\iTunesSetupAdmin[1].exe -> [2008/04/21 17:04:06 | 00,075,048 | —- | M] (Apple Inc.)
FTIS200811.EXE -> C:\Documents and Settings\Dustin\Local Settings\Temp\Updates\FTIS200811.EXE -> [2008/03/12 11:36:46 | 04,396,006 | —- | M] ()
iTunesSetupAdmin[1].exe -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\IMC15QXS\iTunesSetupAdmin[1].exe -> [2008/03/10 17:03:38 | 00,075,048 | —- | M] (Apple Inc.)
g2a_hook.dll -> C:\Documents and Settings\Dustin\Local Settings\Temp\~CL151.tmp\g2a_hook.dll -> [2008/03/10 14:49:31 | 00,010,752 | —- | M] (Citrix Online)
InstallRegister.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\InstallRegister.exe -> [2008/02/07 12:39:58 | 00,013,824 | —- | M] ()
hhcolreg.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\hhcolreg.dat -> [2008/01/14 17:26:56 | 00,008,132 | —- | M] ()
opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Office\Data\opa11.dat -> [2007/09/07 06:44:11 | 00,008,556 | —- | M] ()
data.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Office\Data\data.dat -> [2007/08/21 08:33:29 | 00,001,372 | —- | M] ()
521538c.DLL -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\521538c.DLL -> [2005/04/13 09:31:44 | 00,086,016 | —- | M] ()
FTSLmntr.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\FTSLmntr.exe -> [2004/03/26 11:01:24 | 00,036,864 | —- | M] ()
ylpgscat.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\ylpgscat.dat -> [2003/06/18 11:00:00 | 12,283,223 | —- | M] ()
college.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\college.dat -> [2003/06/18 11:00:00 | 00,327,746 | —- | M] ()
about.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\about.dat -> [2003/06/18 11:00:00 | 00,001,528 | —- | M] ()
moreinfo.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\moreinfo.dat -> [2003/06/18 11:00:00 | 00,000,102 | —- | M] ()
FTSL.dll -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\FTSL.dll -> [2002/02/20 11:32:48 | 00,061,440 | —- | M] ()
FTSLCtrlPnl.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\FTSLCtrlPnl.exe -> [2001/11/02 11:35:12 | 00,045,056 | —- | M] ()
MsiZap.Exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\MsiZap.Exe -> [2001/08/17 10:58:46 | 00,069,632 | —- | M] (Microsoft Corporation)
ISUninst.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\ISUninst.exe -> [1998/10/29 14:45:06 | 00,306,688 | —- | M] (InstallShield Software Corporation)
_ISDel.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\WZS24F.tmp\_ISDel.exe -> [1998/10/27 12:06:48 | 00,027,648 | —- | M] (InstallShield Software Corporation)
_Setup.dll -> C:\Documents and Settings\Dustin\Local Settings\Temp\WZS24F.tmp\_Setup.dll -> [1998/09/29 15:34:56 | 00,034,816 | —- | M] (InstallShield Software Corporation)
521537c.DLL -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\521537c.DLL -> [1998/09/22 17:05:48 | 00,129,536 | —- | M] (InstallShield Software Corporation)
Ctl3d32.dll -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\Ctl3d32.dll -> [1995/07/13 16:46:26 | 00,027,136 | —- | M] (Microsoft Corporation)
 
[File - Lop Check]
Application Data -> C:\Documents and Settings\Administrator\Application Data -> [2007/08/14 18:07:03 | 00,000,000 | RH-D | M]
New York Life -> C:\Documents and Settings\Administrator\Application Data\New York Life -> [2007/08/21 13:05:37 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\All Users\Application Data -> [2009/08/19 07:58:08 | 00,000,000 | RH-D | M]
{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> [2009/04/28 06:59:31 | 00,000,000 | —D | M]
19876094 -> C:\Documents and Settings\All Users\Application Data\19876094 -> [2009/08/19 07:58:13 | 00,000,000 | —D | M]
ACASystems -> C:\Documents and Settings\All Users\Application Data\ACASystems -> [2007/12/03 12:46:30 | 00,000,000 | —D | M]
Azureus -> C:\Documents and Settings\All Users\Application Data\Azureus -> [2007/08/23 05:50:14 | 00,000,000 | —D | M]
CyberLink -> C:\Documents and Settings\All Users\Application Data\CyberLink -> [2007/11/05 07:32:24 | 00,000,000 | —D | M]
Dell -> C:\Documents and Settings\All Users\Application Data\Dell -> [2007/08/14 18:10:57 | 00,000,000 | —D | M]
Grisoft -> C:\Documents and Settings\All Users\Application Data\Grisoft -> [2007/08/24 14:58:26 | 00,000,000 | —D | M]
Juniper Networks -> C:\Documents and Settings\All Users\Application Data\Juniper Networks -> [2008/12/08 08:38:23 | 00,000,000 | —D | M]
ListGrabber Standard 2008 -> C:\Documents and Settings\All Users\Application Data\ListGrabber Standard 2008 -> [2007/12/28 12:55:38 | 00,000,000 | —D | M]
New York Life -> C:\Documents and Settings\All Users\Application Data\New York Life -> [2007/08/21 13:05:37 | 00,000,000 | —D | M]
SBSI -> C:\Documents and Settings\All Users\Application Data\SBSI -> [2004/08/11 16:25:52 | 00,000,000 | —D | M]
Wave Systems Corp -> C:\Documents and Settings\All Users\Application Data\Wave Systems Corp -> [2007/08/23 05:40:31 | 00,000,000 | —D | M]
WinZip -> C:\Documents and Settings\All Users\Application Data\WinZip -> [2007/09/26 17:08:10 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\Default User\Application Data -> [2008/06/23 10:49:56 | 00,000,000 | RH-D | M]
New York Life -> C:\Documents and Settings\Default User\Application Data\New York Life -> [2007/08/21 13:05:37 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\Dustin\Application Data -> [2009/08/10 09:00:29 | 00,000,000 | RH-D | M]
1&1 -> C:\Documents and Settings\Dustin\Application Data\1&1 -> [2008/03/01 16:08:26 | 00,000,000 | —D | M]
ACASystems -> C:\Documents and Settings\Dustin\Application Data\ACASystems -> [2007/12/03 12:46:30 | 00,000,000 | —D | M]
Azureus -> C:\Documents and Settings\Dustin\Application Data\Azureus -> [2007/08/23 17:08:21 | 00,000,000 | —D | M]
Centra -> C:\Documents and Settings\Dustin\Application Data\Centra -> [2008/05/12 10:19:38 | 00,000,000 | —D | M]
CyberLink -> C:\Documents and Settings\Dustin\Application Data\CyberLink -> [2007/11/05 07:32:31 | 00,000,000 | —D | M]
Dell -> C:\Documents and Settings\Dustin\Application Data\Dell -> [2007/08/20 14:48:38 | 00,000,000 | —D | M]
dvdcss -> C:\Documents and Settings\Dustin\Application Data\dvdcss -> [2008/03/12 13:07:20 | 00,000,000 | —D | M]
EndNote -> C:\Documents and Settings\Dustin\Application Data\EndNote -> [2009/06/26 06:38:02 | 00,000,000 | —D | M]
eRoom -> C:\Documents and Settings\Dustin\Application Data\eRoom -> [2007/12/06 10:10:49 | 00,000,000 | —D | M]
G-Lock Software -> C:\Documents and Settings\Dustin\Application Data\G-Lock Software -> [2007/09/12 12:24:24 | 00,000,000 | —D | M]
Grisoft -> C:\Documents and Settings\Dustin\Application Data\Grisoft -> [2007/08/24 14:58:47 | 00,000,000 | —D | M]
InterVideo -> C:\Documents and Settings\Dustin\Application Data\InterVideo -> [2008/03/12 12:52:03 | 00,000,000 | —D | M]
Juniper Networks -> C:\Documents and Settings\Dustin\Application Data\Juniper Networks -> [2009/08/08 09:14:13 | 00,000,000 | —D | M]
Move Networks -> C:\Documents and Settings\Dustin\Application Data\Move Networks -> [2009/05/07 05:19:58 | 00,000,000 | —D | M]
Netscape -> C:\Documents and Settings\Dustin\Application Data\Netscape -> [2007/10/25 07:18:16 | 00,000,000 | —D | M]
New York Life -> C:\Documents and Settings\Dustin\Application Data\New York Life -> [2007/08/21 13:05:37 | 00,000,000 | —D | M]
Saba -> C:\Documents and Settings\Dustin\Application Data\Saba -> [2008/05/12 10:20:14 | 00,000,000 | —D | M]
Thunderbird -> C:\Documents and Settings\Dustin\Application Data\Thunderbird -> [2008/03/15 09:23:34 | 00,000,000 | —D | M]
Visible Path -> C:\Documents and Settings\Dustin\Application Data\Visible Path -> [2009/08/16 10:27:02 | 00,000,000 | —D | M]
Wave Systems Corp -> C:\Documents and Settings\Dustin\Application Data\Wave Systems Corp -> [2009/08/21 09:39:21 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\LocalService\Application Data -> [2008/02/05 18:22:41 | 00,000,000 | —D | M]
New York Life -> C:\Documents and Settings\LocalService\Application Data\New York Life -> [2007/08/21 13:05:37 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\NetworkService\Application Data -> [2004/08/11 16:20:16 | 00,000,000 | —D | M]
New York Life -> C:\Documents and Settings\NetworkService\Application Data\New York Life -> [2007/08/21 13:05:37 | 00,000,000 | —D | M]
C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2009/08/21 09:25:53 | 00,000,000 | –SD | M]
AppleSoftwareUpdate.job -> C:\WINDOWS\Tasks\AppleSoftwareUpdate.job -> [2009/07/15 22:26:05 | 00,000,284 | —- | M] ()
desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2004/08/04 04:00:00 | 00,000,065 | RH– | M] ()
SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2009/08/19 08:38:31 | 00,000,006 | -H– | M] ()
{BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> [2009/08/21 09:25:57 | 00,000,282 | -H– | M] ()
 
[File - Purity Scan]
 
< End of report >


HOWEVER - When I ran the SysProt toolkit it caused my computer to crash.. blue screen of death… that said:

Problem deteced…

DRIVER_IRQL_NOT_LESS_OR_EQUAL

After I rebooted I was able to get this log from the sysprot folder, hope it has everything you need… let me know hoe to proceed. Thanks!!

SysProt AntiRootkit v1.0.1.0
by swatkat

********************************************************************************
**********
********************************************************************************
**********

Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No

Name: System
PID: 4
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\smss.exe
PID: 796
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\csrss.exe
PID: 852
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\winlogon.exe
PID: 876
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\services.exe
PID: 920
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\lsass.exe
PID: 932
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1100
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1188
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1256
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1380
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1512
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PID: 1776
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
PID: 1812
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\WLTRYSVC.EXE
PID: 1828
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\BCMWLTRY.EXE
PID: 1848
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\spoolsv.exe
PID: 1896
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\scardsvr.exe
PID: 200
Hidden: No
Window Visible: No

Name: C:\WINDOWS\explorer.exe
PID: 196
Hidden: No
Window Visible: No

Name: C:\Program Files\Apoint\Apoint.exe
PID: 692
Hidden: No
Window Visible: No

Name: C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
PID: 700
Hidden: No
Window Visible: No

Name: C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe
PID: 708
Hidden: No
Window Visible: No

Name: C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PID: 716
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PID: 728
Hidden: No
Window Visible: No

Name: C:\PROGRA~1\SYMANT~1\VPTray.exe
PID: 740
Hidden: No
Window Visible: No

Name: C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
PID: 748
Hidden: No
Window Visible: No

Name: C:\Program Files\iTunes\iTunesHelper.exe
PID: 1060
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\ctfmon.exe
PID: 376
Hidden: No
Window Visible: No

Name: C:\Program Files\Messenger\msmsgs.exe
PID: 432
Hidden: No
Window Visible: No

Name: C:\Program Files\Microsoft ActiveSync\wcescomm.exe
PID: 468
Hidden: No
Window Visible: No

Name: C:\Program Files\Apoint\hidfind.exe
PID: 560
Hidden: No
Window Visible: No

Name: C:\Program Files\Digital Line Detect\DLG.exe
PID: 640
Hidden: No
Window Visible: No

Name: C:\Program Files\Apple Computer\DVD@ccess\DVDAccess.exe
PID: 1388
Hidden: No
Window Visible: No

Name: C:\Program Files\Apoint\ApntEx.exe
PID: 1408
Hidden: No
Window Visible: No

Name: C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
PID: 1672
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 1680
Hidden: No
Window Visible: No

Name: C:\PROGRA~1\MICROS~3\rapimgr.exe
PID: 1744
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PID: 2052
Hidden: No
Window Visible: No

Name: C:\Program Files\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
PID: 2116
Hidden: No
Window Visible: No

Name: C:\Program Files\Bonjour\mDNSResponder.exe
PID: 2328
Hidden: No
Window Visible: No

Name: C:\Program Files\Wave Systems Corp\Common\DataServer.exe
PID: 2384
Hidden: No
Window Visible: No

Name: C:\Program Files\Symantec AntiVirus\DefWatch.exe
PID: 2604
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PID: 2664
Hidden: No
Window Visible: No

Name: C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PID: 2896
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\svchost.exe
PID: 2944
Hidden: No
Window Visible: No

Name: C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
PID: 2968
Hidden: No
Window Visible: No

Name: C:\Program Files\iPod\bin\iPodService.exe
PID: 3360
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\wbem\wmiprvse.exe
PID: 3824
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\alg.exe
PID: 3912
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PID: 3996
Hidden: No
Window Visible: No

Name: C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
PID: 664
Hidden: No
Window Visible: No

Name: C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe
PID: 356
Hidden: No
Window Visible: No

Name: C:\WINDOWS\system32\ctfmon.exe
PID: 2008
Hidden: No
Window Visible: No

Name: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PID: 388
Hidden: No
Window Visible: No

Name: C:\DOCUME~1\Dustin\LOCALS~1\Temp\a.exe
PID: 3800
Hidden: No
Window Visible: No

Name: C:\Documents and Settings\Dustin\Desktop\temp222\SysProt\SysProt.exe
PID: 2260
Hidden: No
Window Visible: Yes

********************************************************************************
**********
*****************************************************
Hi, OK I see them so lets go kill. You will lose your desktop during this fix and the system will reboot

Start OTS. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Unregister Dlls]
[Processes - Safe List]
YY -> a.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\a.exe
[Registry - Safe List]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YY -> "net" -> C:\WINDOWS\System32\net.net ["C:\WINDOWS\system32\net.net"]
< Run [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YY -> "Monopod" -> C:\Documents and Settings\Dustin\Local Settings\Temp\a.exe [C:\DOCUME~1\Dustin\LOCALS~1\Temp\a.exe]
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls
YY -> wxvault.dll -> C:\WINDOWS\System32\wxvault.dll
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
[Files/Folders - Created Within 30 Days]
NY -> 19876094 -> C:\Documents and Settings\All Users\Application Data\19876094
NY -> net.net -> C:\WINDOWS\System32\net.net
[Files/Folders - Modified Within 30 Days]
NY -> {BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
NY -> a.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\a.exe
NY -> net.net -> C:\WINDOWS\System32\net.net
[File - Lop Check]
NY -> {BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[Empty Temp Folders]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here.

I will review the information when it comes back in.

THEN

Download ComboFix from one of these locations:


Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
Here is my new OTS log… I am working on the rest.. All Processes Killed [Processes - Safe List] No active process named a.exe was found! C:\Documents and Settings\Dustin\Local Settings\Temp\a.exe moved successfully. [Registry - Safe List] Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\net deleted successfully. C:\WINDOWS\System32\net.net moved successfully. Registry value HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Monopod deleted successfully. File C:\Documents and Settings\Dustin\Local Settings\Temp\a.exe not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:wxvault.dll deleted successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\wxvault.dll C:\WINDOWS\System32\wxvault.dll NOT unregistered. C:\WINDOWS\System32\wxvault.dll moved successfully. [Files/Folders - Created Within 30 Days] C:\Documents and Settings\All Users\Application Data\19876094 folder moved successfully. File C:\WINDOWS\System32\net.net not found! [Files/Folders - Modified Within 30 Days] C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job moved successfully. File C:\Documents and Settings\Dustin\Local Settings\Temp\a.exe not found! File C:\WINDOWS\System32\net.net not found! [File - Lop Check] File C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job not found! [Empty Temp Folders] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Dustin ->Temp folder emptied: 540708721 bytes ->Temporary Internet Files folder emptied: 182896786 bytes ->Java cache emptied: 19359962 bytes ->FireFox cache emptied: 78972424 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 752032 bytes %systemdrive% .tmp files removed: 1052106752 bytes C:\WINDOWS\msdownld.tmp folder deleted successfully. %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 2577 bytes Windows Temp folder emptied: 177974041 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1957.76 mb < End of fix log > OTS by OldTimer - Version 3.0.10.3 fix logfile created on 08212009_125923 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Here is my ComboFix log…




ComboFix 09-08-20.07 - Dustin 08/21/2009 13:23.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.623 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Installer\252cec.msi
c:\windows\Installer\310b8.msi
c:\windows\Installer\40e06a3.msi
c:\windows\Installer\9028e.msi
c:\windows\Installer\e836fa.msi
c:\windows\run.log
c:\windows\system32\config\systemprofile\Desktop\Total Security 2009.lnk
c:\windows\system32\config\systemprofile\Start Menu\Programs\Total Security
c:\windows\system32\config\systemprofile\Start Menu\Programs\Total Security\Total Security 2009.lnk
c:\windows\system32\drivers\kbiwkmydtubyvp.sys
c:\windows\system32\kbiwkmetlmoejj.dll
c:\windows\system32\kbiwkmiqxovree.dat
c:\windows\system32\kbiwkmkgpxnhrq.dll
c:\windows\system32\kbiwkmvmxbmmot.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_kbiwkmtavhkylk
——-\Legacy_kbiwkmtavhkylk


((((((((((((((((((((((((( Files Created from 2009-07-21 to 2009-08-21 )))))))))))))))))))))))))))))))
.

2009-08-21 18:59 . 2009-08-21 18:59 ——– d—–w- C:\_OTS
2009-08-19 14:51 . 2009-08-19 14:51 ——– d—–w- c:\program files\Trend Micro
2009-08-19 13:37 . 2009-08-19 13:37 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-12 16:31 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll
2009-08-11 15:28 . 2009-08-11 15:28 ——– d-sh–w- c:\documents and settings\Dustin\IECompatCache
2009-08-11 15:18 . 2009-08-11 15:18 ——– d-sh–w- c:\documents and settings\Dustin\PrivacIE
2009-08-10 22:28 . 2009-08-10 22:28 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-10 22:28 . 2009-08-10 22:28 ——– d—–w- c:\program files\MSBuild
2009-08-10 22:28 . 2009-08-10 22:28 ——– d—–w- c:\program files\Reference Assemblies
2009-08-10 22:28 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-10 22:28 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-10 22:28 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-10 22:28 . 2009-08-10 22:28 ——– d—–w- C:\58ba0bc4b57ee9a7f3
2009-08-10 22:28 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-10 22:28 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-10 22:28 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-10 22:28 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-10 22:24 . 2009-08-10 22:24 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2009-08-10 14:21 . 2009-08-10 14:21 ——– d—–w- c:\documents and settings\Dustin\Local Settings\Application Data\Simple Home Budget
2009-08-10 14:08 . 2009-08-10 14:31 ——– d—–w- c:\program files\HB
2009-08-09 01:39 . 2009-08-09 01:39 ——– d-sh–w- c:\documents and settings\Dustin\IETldCache
2009-08-08 14:38 . 2009-07-03 17:09 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2009-08-08 14:38 . 2009-07-03 17:09 594432 ——w- c:\windows\system32\dllcache\msfeeds.dll
2009-08-08 14:38 . 2009-07-03 17:09 55296 ——w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-08-08 14:38 . 2009-07-03 17:09 1985536 ——w- c:\windows\system32\dllcache\iertutil.dll
2009-08-08 14:38 . 2009-07-20 00:48 11067392 ——w- c:\windows\system32\dllcache\ieframe.dll
2009-08-08 14:38 . 2009-07-03 17:09 246272 ——w- c:\windows\system32\dllcache\ieproxy.dll
2009-08-08 14:38 . 2009-08-08 14:39 ——– d—–w- c:\windows\ie8updates
2009-08-08 14:37 . 2009-07-01 07:08 101376 ——w- c:\windows\system32\dllcache\iecompat.dll
2009-08-08 14:34 . 2009-08-08 14:37 ——– dc-h–w- c:\windows\ie8
2009-08-05 09:01 . 2009-08-05 09:01 204800 ——w- c:\windows\system32\dllcache\mswebdvd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-21 19:05 . 2008-05-12 19:29 ——– d—–w- c:\program files\Mozilla Firefox 3 Beta 5
2009-08-21 16:06 . 2008-03-15 15:23 ——– d—–w- c:\program files\Mozilla Thunderbird
2009-08-21 15:39 . 2007-08-22 23:31 ——– d—–w- c:\documents and settings\Dustin\Application Data\Wave Systems Corp
2009-08-19 20:07 . 2009-01-24 01:01 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-08-18 18:31 . 2007-08-15 00:14 21800 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-18 18:30 . 2008-02-12 15:53 ——– d—–w- c:\program files\Symantec AntiVirus
2009-08-16 16:27 . 2008-02-14 13:43 ——– d—–w- c:\documents and settings\Dustin\Application Data\Visible Path
2009-08-10 14:31 . 2009-06-26 12:35 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-08-08 15:14 . 2008-08-20 15:17 ——– d—–w- c:\documents and settings\Dustin\Application Data\Juniper Networks
2009-08-07 04:46 . 2008-03-28 10:52 ——– d—–w- c:\program files\Microsoft Silverlight
2009-08-05 09:01 . 2004-08-11 22:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2004-08-11 22:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 05:43 . 2004-08-11 22:00 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2004-08-11 22:00 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-26 12:38 . 2009-06-26 12:38 ——– d—–w- c:\documents and settings\Dustin\Application Data\EndNote
2009-06-26 12:37 . 2009-06-26 12:36 ——– d—–w- c:\program files\EndNote X
2009-06-26 12:37 . 2009-06-26 12:37 ——– d—–w- c:\program files\Common Files\Risxtd
2009-06-25 08:25 . 2004-08-11 22:00 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-11 22:00 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-11 22:00 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-11 22:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-08-11 22:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-11 22:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 16:54 . 2007-08-21 13:14 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-06-24 14:14 . 2007-08-15 00:07 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-24 11:18 . 2004-08-11 22:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-08-11 22:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-11 22:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2004-08-11 22:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-08-11 22:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 15:19 . 2004-08-11 22:11 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2004-08-11 22:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2004-08-11 22:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-08 18:00 . 2009-06-17 12:03 110592 —-a-w- c:\documents and settings\Dustin\Application Data\Mozilla\Firefox\Profiles\e4xovvgc.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
2009-06-03 19:09 . 2004-08-11 22:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2007-09-06 13:02 . 2007-09-06 13:02 135680 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Inter-Chat"="c:\program files\ConWare\InterChat3\IC3" [X]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"Document Manager"="c:\program files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe" [2006-09-08 102400]
"StartSecurDoc"="c:\program files\WinMagic\SecureDoc-NT\SDPin.exe" [2006-06-01 425984]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-06-08 128560]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 52840]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-03-15 125632]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_09\bin\jusched.exe" [2006-09-07 49263]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-12-08 185632]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]

c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-8-14 24576]
[removed] - c:\program files\Apple Computer\DVD@ccess\DVDAccess.exe [2007-11-5 888832]
EMBASSY Trust Suite Secure Update.lnk - c:\program files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe [2006-8-25 192512]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\WinMagic\\SecureDoc-NT\\SDPin.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Sybase\\SQL Anywhere 9\\win32\\dbeng9.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\Java\\jre1.5.0_09\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox 3 Beta 5\\firefox.exe"=
"c:\\Program Files\\Juniper Networks\\Secure Application Manager\\dsSamProxy.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iCal v4.0 Web Calendar\\ical.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8078:TCP"= 8078:TCP:Finchsync
"8082:TCP"= 8082:TCP:finch
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 SDDisk2K;WinMagic SecureDoc;c:\windows\system32\drivers\SDDisk2K.sys [1/24/2006 11:36 AM 194048]
R1 NEOFLTR_620_13649;Juniper Networks TDI Filter Driver (NEOFLTR_620_13649);c:\windows\system32\drivers\NEOFLTR_620_13649.sys [10/21/2008 4:40 PM 64480]
R2 ASANYs_FTCS;Adaptive Server Anywhere - FTCS;c:\program files\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -hvASANYs_FTCS –> c:\program files\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -hvASANYs_FTCS [?]
R2 DVDAccss;DVDAccss;c:\windows\system32\drivers\DVDAccss.sys [11/5/2007 7:26 AM 29156]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [4/24/2009 6:02 PM 101936]
S3 GTKCMOS;GTKCMOS;c:\windows\system32\GTKCMOS.sys [6/15/2004 1:55 PM 7882]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [3/14/2007 6:48 PM 116416]
S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\Dustin\Desktop\temp222\SysProt\SysProtDrv.sys [8/21/2009 9:50 AM 44288]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-ISUSPM - c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
SafeBoot-AVG Anti-Spyware Driver


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = njproxy:80
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Find Visible &Path - c:\program files\Visible Path\html\VPSearch.html
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - hxxps://emeeting.newyorklife.com/SiteRoots/main/Install/win32/CentraUpdaterAx.cab
DPF: {5EF90065-A2C4-4C6D-993E-40EE010EBA3D} - hxxps://www.fts.newyorklife.com/formslibrary/Package/FTWebUtils.CAB
DPF: {67F02384-3864-4BCE-A408-EDD9BD565D51} - hxxp://www.munimetrix.com/nyl/demonow.cab
FF - ProfilePath - c:\docume~1\Dustin\APPLIC~1\Mozilla\Firefox\Profiles\e4xovvgc.default\
FF - prefs.js: browser.search.selectedEngine - eBay
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - component: c:\documents and settings\Dustin\Application Data\Mozilla\Firefox\Profiles\e4xovvgc.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
FF - component: c:\documents and settings\Dustin\Application Data\Mozilla\Firefox\Profiles\e4xovvgc.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\documents and settings\Dustin\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: c:\documents and settings\Dustin\Application Data\Mozilla\plugins\npPxPlay.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJPI150_09.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-21 13:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(872)
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'lsass.exe'(928)
c:\windows\system32\wvauth.dll
c:\windows\system32\biolsp.dll

- - - - - - - > 'explorer.exe'(900)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\scardsvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Wave Systems Corp\Common\DataServer.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\program files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\Apoint\hidfind.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\progra~1\MICROS~3\rapimgr.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-08-21 13:50 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-21 19:50

Pre-Run: 56,228,089,856 bytes free
Post-Run: 56,094,199,808 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

257 — E O F — 2009-08-17 14:04




The only issue I have now is when the computer starts up it says:

Docmgr.exe Unable to locate component
Application failed to start because wxvault.dll was not found. Re-installing the app will fix this problem.

AND

SDPin
Do you really want to close SDPin? <—— This one pops up each time I restart the computer.


The search engine working correctly though, so looks like you fixed it. Let me know what to do with the above two issues…. Thanks!!
The first one is from wavedoc, the second from securedock. Due to the infection you may need to reinstall those programmes Are you experiencing any other problems
OK before you go though lets clear my rubbish :)

Now the best part of the day —– Your log now appears clean :thumbup:

A good workman always cleans up after himself so..Run OTS and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 15.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u15-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u15-windows-i586-p.exe and select "Run as an Administrator.")

XP
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done

SPRING CLEAN

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

THEN

Download and run Auslogics Disc Defragmenter

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SuperAntispyware Run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit
  • Microsoft Windows Update


To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wavey:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI