Essexboy
Thanks in advance for the help… Here is the OTS LOG:
OTS logfile created on: 8/21/2009 9:39:21 AM - Run 1
OTS by OldTimer - Version 3.0.10.3 Folder = C:\Documents and Settings\Dustin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1014.02 Mb Total Physical Memory | 500.58 Mb Available Physical Memory | 49.37% Memory free
2.38 Gb Paging File | 1.74 Gb Available in Paging File | 73.06% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 50.72 Gb Free Space | 68.12% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LAPTOP
Current User Name: Dustin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
[Processes - Safe List]
a.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\a.exe -> [2009/08/18 12:41:10 | 00,151,040 | —- | M] ()
apntex.exe -> C:\Program Files\Apoint\Apntex.exe -> [2005/07/27 13:41:08 | 00,045,056 | R— | M] (Alps Electric Co., Ltd.)
apoint.exe -> C:\Program Files\Apoint\Apoint.exe -> [2005/10/07 11:13:38 | 00,176,128 | R— | M] (Alps Electric Co., Ltd.)
applemobiledeviceservice.exe -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/06/05 09:48:14 | 00,144,712 | —- | M] (Apple Inc.)
autoupdate.exe -> C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe -> [2006/08/25 08:45:30 | 00,192,512 | —- | M] (Wave Systems Corp.)
bcmwltry.exe -> C:\WINDOWS\System32\bcmwltry.exe -> [2006/11/22 16:32:58 | 01,253,376 | —- | M] (Dell Inc.)
ccapp.exe -> C:\Program Files\Common Files\Symantec Shared\ccApp.exe -> [2006/11/21 16:38:28 | 00,052,840 | —- | M] (Symantec Corporation)
ccevtmgr.exe -> C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -> [2006/11/21 16:38:32 | 00,192,104 | —- | M] (Symantec Corporation)
ccsetmgr.exe -> C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -> [2006/11/21 16:38:40 | 00,169,576 | —- | M] (Symantec Corporation)
dataserver.exe -> C:\Program Files\Wave Systems Corp\Common\DataServer.exe -> [2006/09/05 09:09:10 | 00,315,392 | —- | M] (Wave Systems Corp.)
dbsrv9.exe -> C:\Program Files\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -> [2007/06/13 08:11:40 | 00,077,824 | —- | M] (iAnywhere Solutions, Inc.)
defwatch.exe -> C:\Program Files\Symantec AntiVirus\DefWatch.exe -> [2007/03/14 18:48:40 | 00,031,424 | —- | M] (Symantec Corporation)
dlg.exe -> C:\Program Files\Digital Line Detect\DLG.exe -> [2003/10/29 01:06:00 | 00,024,576 | —- | M] (BVRP Software)
docmgr.exe -> C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe -> [2006/09/08 07:32:54 | 00,102,400 | —- | M] (Wave Systems Corp.)
dvdaccess.exe -> C:\Program Files\Apple Computer\DVD@ccess\DVDAccess.exe -> [2003/11/21 15:16:12 | 00,888,832 | —- | M] (Apple Computer)
explorer.exe -> C:\WINDOWS\Explorer.EXE -> [2008/04/14 03:42:20 | 01,033,728 | —- | M] (Microsoft Corporation)
firefox.exe -> C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe -> [2009/08/06 16:36:13 | 00,307,704 | —- | M] (Mozilla Corporation)
hidfind.exe -> C:\Program Files\Apoint\HidFind.exe -> [2004/06/28 20:56:12 | 00,045,056 | R— | M] (Alps Electric Co., Ltd.)
hijackthis.exe -> C:\Program Files\Trend Micro\HijackThis\HijackThis.exe -> [2009/08/19 08:51:36 | 00,396,288 | —- | M] (Trend Micro Inc.)
ipodservice.exe -> C:\Program Files\iPod\bin\iPodService.exe -> [2009/06/05 11:39:14 | 00,541,992 | —- | M] (Apple Inc.)
ituneshelper.exe -> C:\Program Files\iTunes\iTunesHelper.exe -> [2009/06/05 11:39:22 | 00,292,136 | —- | M] (Apple Inc.)
jusched.exe -> C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe -> [2006/09/07 13:51:22 | 00,049,263 | —- | M] (Sun Microsystems, Inc.)
mdm.exe -> C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/19 21:25:00 | 00,322,120 | —- | M] (Microsoft Corporation)
mdnsresponder.exe -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2008/12/12 09:17:38 | 00,238,888 | —- | M] (Apple Inc.)
msmsgs.exe -> C:\Program Files\Messenger\msmsgs.exe -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
nicconfigsvc.exe -> C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe -> [2007/02/20 11:24:34 | 00,475,136 | —- | M] (Dell Inc.)
ots.exe -> C:\Documents and Settings\Dustin\Desktop\OTS.exe -> [2009/08/21 09:37:20 | 00,514,048 | —- | M] (OldTimer Tools)
pdvddxsrv.exe -> C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe -> [2007/06/08 17:40:58 | 00,128,560 | —- | M] (CyberLink Corp.)
rapimgr.exe -> C:\Program Files\Microsoft ActiveSync\rapimgr.exe -> [2006/11/13 11:39:34 | 00,199,464 | —- | M] (Microsoft Corporation)
realsched.exe -> C:\Program Files\Common Files\Real\Update_OB\realsched.exe -> [2007/12/08 11:08:29 | 00,185,632 | —- | M] (RealNetworks, Inc.)
sdpin.exe -> C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe -> [2006/06/01 07:55:20 | 00,425,984 | —- | M] (Winmagic Inc.)
spbbcsvc.exe -> C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -> [2007/01/10 15:27:38 | 01,160,792 | —- | M] (Symantec Corporation)
tcsd_win32.exe -> C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe -> [2006/06/12 09:01:14 | 00,180,224 | —- | M] ()
vptray.exe -> C:\Program Files\Symantec AntiVirus\VPTray.exe -> [2007/03/14 18:49:02 | 00,125,632 | —- | M] (Symantec Corporation)
wcescomm.exe -> C:\Program Files\Microsoft ActiveSync\Wcescomm.exe -> [2006/11/13 11:39:52 | 01,289,000 | —- | M] (Microsoft Corporation)
wltrysvc.exe -> C:\WINDOWS\System32\WLTRYSVC.EXE -> [2006/11/22 16:35:50 | 00,020,480 | —- | M] ()
wmiprvse.exe -> C:\WINDOWS\System32\wbem\wmiprvse.exe -> [2009/02/06 04:10:02 | 00,227,840 | —- | M] (Microsoft Corporation)
[Win32 Services - Safe List]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/06/05 09:48:14 | 00,144,712 | —- | M] (Apple Inc.)
(ASANYs_FTCS) Adaptive Server Anywhere - FTCS [Win32_Own | Auto | Running] -> C:\Program Files\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -> [2007/06/13 08:11:40 | 00,077,824 | —- | M] (iAnywhere Solutions, Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation)
(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> [2007/05/30 06:31:10 | 00,312,880 | —- | M] (GRISOFT s.r.o.)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> C:\Program Files\Bonjour\mDNSResponder.exe -> [2008/12/12 09:17:38 | 00,238,888 | —- | M] (Apple Inc.)
(ccEvtMgr) Symantec Event Manager [Win32_Own | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -> [2006/11/21 16:38:32 | 00,192,104 | —- | M] (Symantec Corporation)
(ccSetMgr) Symantec Settings Manager [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -> [2006/11/21 16:38:40 | 00,169,576 | —- | M] (Symantec Corporation)
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation)
(DataSvr2) DataSvr2 [Win32_Own | Auto | Running] -> C:\Program Files\Wave Systems Corp\Common\DataServer.exe -> [2006/09/05 09:09:10 | 00,315,392 | —- | M] (Wave Systems Corp.)
(DefWatch) Symantec AntiVirus Definition Watcher [Win32_Own | Auto | Running] -> C:\Program Files\Symantec AntiVirus\DefWatch.exe -> [2007/03/14 18:48:40 | 00,031,424 | —- | M] (Symantec Corporation)
(FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -> [2008/07/29 21:10:04 | 00,046,104 | —- | M] (Microsoft Corporation)
(GoogleDesktopManager) GoogleDesktopManager [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -> [2007/09/07 06:14:35 | 01,836,544 | —- | M] (Google)
(helpsvc) Help and Support [Win32_Shared | Auto | Running] -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/14 03:42:04 | 00,038,400 | —- | M] (Microsoft Corporation)
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -> [2004/10/22 01:24:18 | 00,073,728 | —- | M] (Macrovision Corporation)
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2008/07/29 19:24:50 | 00,881,664 | —- | M] (Microsoft Corporation)
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> C:\Program Files\iPod\bin\iPodService.exe -> [2009/06/05 11:39:14 | 00,541,992 | —- | M] (Apple Inc.)
(Irmon) Infrared Monitor [Win32_Shared | Auto | Running] -> C:\WINDOWS\System32\irmon.dll -> [2008/04/14 03:41:56 | 00,028,160 | —- | M] (Microsoft Corporation)
(LiveUpdate) LiveUpdate [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE -> [2006/09/02 15:36:33 | 02,528,960 | —- | M] (Symantec Corporation)
(MDM) Machine Debug Manager [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/19 21:25:00 | 00,322,120 | —- | M] (Microsoft Corporation)
(NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2008/07/29 19:16:38 | 00,132,096 | —- | M] (Microsoft Corporation)
(NICCONFIGSVC) NICCONFIGSVC [Win32_Own | Auto | Running] -> C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe -> [2007/02/20 11:24:34 | 00,475,136 | —- | M] (Dell Inc.)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -> [2003/07/28 10:28:22 | 00,089,136 | —- | M] (Microsoft Corporation)
(SavRoam) SavRoam [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Symantec AntiVirus\SavRoam.exe -> [2007/03/14 18:48:56 | 00,116,416 | —- | M] (symantec)
(SNDSrvc) Symantec Network Drivers Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -> [2007/02/12 16:23:10 | 00,214,672 | —- | M] (Symantec Corporation)
(SPBBCSvc) Symantec SPBBCSvc [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -> [2007/01/10 15:27:38 | 01,160,792 | —- | M] (Symantec Corporation)
(Symantec AntiVirus) Symantec AntiVirus [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Symantec AntiVirus\Rtvscan.exe -> [2007/03/14 18:48:50 | 01,816,768 | —- | M] (Symantec Corporation)
(tcsd_win32.exe) NTRU Hybrid TSS v2.0.25 TCS [Win32_Own | Auto | Running] -> C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe -> [2006/06/12 09:01:14 | 00,180,224 | —- | M] ()
(wltrysvc) Dell Wireless WLAN Tray Service [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\WLTRYSVC.EXE -> [2006/11/22 16:35:50 | 00,020,480 | —- | M] ()
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Windows Media Player\WMPNetwk.exe -> [2006/10/18 19:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
[Driver Services - Safe List]
(AliIde) AliIde [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\aliide.sys -> [2001/08/17 12:51:56 | 00,005,248 | —- | M] (Acer Laboratories Inc.)
(amdagp) AMD AGP Bus Filter Driver [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\amdagp.sys -> [2008/04/13 22:06:40 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.)
(ApfiltrService) Alps Touch Pad Filter Driver for Windows 2000/XP [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\Apfiltr.sys -> [2005/09/28 17:57:18 | 00,113,847 | R— | M] (Alps Electric Co., Ltd.)
(APPDRV) APPDRV [Kernel | System | Running] -> C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -> [2005/08/12 15:50:46 | 00,016,128 | —- | M] (Dell Inc)
(asc) asc [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\asc.sys -> [2001/08/17 12:52:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.)
(asc3550) asc3550 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\asc3550.sys -> [2001/08/17 12:51:58 | 00,014,848 | —- | M] (Advanced System Products, Inc.)
(AVG Anti-Spyware Driver) AVG Anti-Spyware Driver [Kernel | System | Running] -> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys -> [2007/05/30 06:10:42 | 00,011,000 | —- | M] ()
(AvgAsCln) AVG Anti-Spyware Clean Driver [Kernel | System | Running] -> C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys -> [2007/05/30 06:10:42 | 00,010,872 | —- | M] (GRISOFT, s.r.o.)
(b57w2k) Broadcom NetXtreme Gigabit Ethernet [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\b57xp32.sys -> [2005/11/10 08:25:14 | 00,142,720 | —- | M] (Broadcom Corporation)
(BCM43XX) Dell Wireless WLAN Card Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\bcmwl5.sys -> [2006/11/22 16:34:36 | 00,604,928 | —- | M] (Broadcom Corporation)
(CmdIde) CmdIde [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\cmdide.sys -> [2001/08/17 12:51:54 | 00,006,656 | —- | M] (CMD Technology, Inc.)
(dac2w2k) dac2w2k [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -> [2001/08/17 12:52:16 | 00,179,584 | —- | M] (Mylex Corporation)
(DSproct) DSproct [Kernel | On_Demand | Stopped] -> C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys -> [2006/01/10 10:07:58 | 00,004,864 | —- | M] (GTek Technologies Ltd.)
(DVDAccss) DVDAccss [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\DVDAccss.sys -> [2003/11/21 15:15:14 | 00,029,156 | —- | M] (Apple Computer, Inc.)
(E100B) Intel(R) PRO Adapter Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\e100b325.sys -> [2001/08/17 11:12:10 | 00,117,760 | —- | M] (Intel Corporation)
(eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -> [2009/02/27 03:00:00 | 00,371,248 | —- | M] (Symantec Corporation)
(EraserUtilRebootDrv) EraserUtilRebootDrv [Kernel | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -> [2009/03/16 02:00:00 | 00,101,936 | —- | M] (Symantec Corporation)
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys -> [2009/03/19 14:32:48 | 00,023,400 | —- | M] (GEAR Software Inc.)
(GTKCMOS) GTKCMOS [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\GTKCMOS.sys -> [2004/06/15 13:55:56 | 00,007,882 | —- | M] (Gteko Ltd.)
(guardian2) guardian2 [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\oz776.sys -> [2007/01/28 13:23:36 | 00,061,312 | —- | M] (O2Micro)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HDAudBus.sys -> [2008/04/13 20:06:06 | 00,144,384 | —- | M] (Windows (R) Server 2003 DDK provider)
(HSF_DPV) HSF_DPV [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HSX_DPV.sys -> [2005/11/30 23:40:56 | 00,936,960 | —- | M] (Conexant Systems, Inc.)
(HSXHWAZL) HSXHWAZL [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HSXHWAZL.sys -> [2005/11/30 23:40:12 | 00,192,512 | —- | M] (Conexant Systems, Inc.)
(ialm) ialm [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ialmnt5.sys -> [2005/12/13 16:09:34 | 01,364,574 | —- | M] (Intel Corporation)
(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys -> [2005/10/04 20:57:08 | 00,012,544 | —- | M] (Conexant)
(mraid35x) mraid35x [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\mraid35x.sys -> [2001/08/17 12:52:12 | 00,017,280 | —- | M] (American Megatrends Inc.)
(NAVENG) NAVENG [Kernel | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090815.003\NAVENG.SYS -> [2009/07/15 02:00:00 | 00,087,888 | —- | M] (Symantec Corporation)
(NAVEX15) NAVEX15 [Kernel | On_Demand | Running] -> C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090815.003\NAVEX15.SYS -> [2009/07/15 02:00:00 | 00,875,728 | —- | M] (Symantec Corporation)
(NEOFLTR_620_13649) Juniper Networks TDI Filter Driver (NEOFLTR_620_13649) [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\NEOFLTR_620_13649.SYS -> [2008/10/21 16:40:22 | 00,064,480 | —- | M] (Juniper Networks)
(nv) nv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -> [2004/08/03 21:29:56 | 01,897,408 | —- | M] (NVIDIA Corporation)
(omci) OMCI WDM Device Driver [Kernel | System | Running] -> C:\WINDOWS\System32\DRIVERS\omci.sys -> [2004/02/13 08:46:00 | 00,017,153 | —- | M] (Dell Inc)
(PBADRV) PBADRV [Kernel | Boot | Running] -> C:\WINDOWS\system32\drivers\pbadrv.sys -> [2005/12/09 14:35:00 | 00,018,816 | —- | M] (Dell Inc)
(pfc) Padus ASPI Shell [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\pfc.sys -> [2002/02/11 13:15:50 | 00,014,572 | —- | M] (Padus, Inc.)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ptilink.sys -> [2004/08/04 04:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(ql1080) ql1080 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\ql1080.sys -> [2001/08/17 12:52:20 | 00,040,320 | —- | M] (QLogic Corporation)
(ql12160) ql12160 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\ql12160.sys -> [2001/08/17 12:52:20 | 00,045,312 | —- | M] (QLogic Corporation)
(ql1280) ql1280 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\ql1280.sys -> [2001/08/17 12:52:18 | 00,049,024 | —- | M] (QLogic Corporation)
(SAVRT) SAVRT [Kernel | System | Running] -> C:\Program Files\Symantec AntiVirus\savrt.sys -> [2006/09/06 13:41:20 | 00,337,592 | —- | M] (Symantec Corporation)
(SAVRTPEL) SAVRTPEL [Kernel | System | Running] -> C:\Program Files\Symantec AntiVirus\Savrtpel.sys -> [2006/09/06 13:41:20 | 00,054,968 | —- | M] (Symantec Corporation)
(SDDisk2K) WinMagic SecureDoc [Kernel | Boot | Running] -> C:\WINDOWS\System32\drivers\SDDisk2K.sys -> [2006/01/24 11:36:44 | 00,194,048 | —- | M] ()
(SDDMI2) SDDMI2 [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DDMI2.sys -> [2004/06/09 07:29:56 | 00,006,977 | —- | M] (Gteko Ltd.)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\secdrv.sys -> [2007/11/13 04:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sfng32) Sonic Focus Plugin for Sigmatel HDA [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\sfng32.sys -> [2005/12/02 15:38:04 | 00,041,728 | —- | M] (Sonic Focus, Inc)
(sisagp) SIS AGP Bus Filter [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\sisagp.sys -> [2008/04/13 22:06:40 | 00,040,960 | —- | M] (Silicon Integrated Systems Corporation)
(SMCIRDA) SMC IrCC Miniport Device Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\smcirda.sys -> [2001/08/17 10:10:28 | 00,035,913 | —- | M] (SMC)
(Sparrow) Sparrow [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\sparrow.sys -> [2001/08/17 13:07:44 | 00,019,072 | —- | M] (Adaptec, Inc.)
(SPBBCDrv) SPBBCDrv [Kernel | System | Running] -> C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -> [2007/01/10 15:27:26 | 00,390,744 | —- | M] (Symantec Corporation)
(STHDA) SigmaTel High Definition Audio CODEC [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\sthda.sys -> [2005/12/12 13:32:54 | 01,083,576 | —- | M] (SigmaTel, Inc.)
(symc810) symc810 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\symc810.sys -> [2001/08/17 13:07:34 | 00,016,256 | —- | M] (Symbios Logic Inc.)
(symc8xx) symc8xx [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\symc8xx.sys -> [2001/08/17 13:07:36 | 00,032,640 | —- | M] (LSI Logic)
(SymEvent) SymEvent [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\SYMEVENT.SYS -> [2008/02/12 09:54:53 | 00,110,952 | —- | M] (Symantec Corporation)
(SYMREDRV) SYMREDRV [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -> [2007/02/12 16:22:36 | 00,024,720 | —- | M] (Symantec Corporation)
(SYMTDI) SYMTDI [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\SYMTDI.SYS -> [2007/02/12 16:22:40 | 00,196,752 | —- | M] (Symantec Corporation)
(sym_hi) sym_hi [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\sym_hi.sys -> [2001/08/17 13:07:40 | 00,028,384 | —- | M] (LSI Logic)
(sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\sym_u3.sys -> [2001/08/17 13:07:42 | 00,030,688 | —- | M] (LSI Logic)
(TcUsb) TC USB Kernel Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\tcusb.sys -> [2006/03/01 01:39:18 | 00,028,800 | —- | M] (UPEK Inc.)
(ultra) ultra [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\ultra.sys -> [2001/08/17 12:52:22 | 00,036,736 | —- | M] (Promise Technology, Inc.)
(usb_rndisx) USB RNDIS Adapter [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\usb8023x.sys -> [2008/04/13 22:26:50 | 00,012,800 | —- | M] (Microsoft Corporation)
(winachsf) winachsf [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HSX_CNXT.sys -> [2005/11/30 23:40:08 | 00,669,696 | —- | M] (Conexant Systems, Inc.)
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> [binary data] ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\"Default_Page_URL" -> www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=2070814 ->
HKEY_LOCAL_MACHINE\: Search\\"Default_Search_URL" -> http://www.google.com/ie ->
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
HKEY_LOCAL_MACHINE\: Search\\"Start Page" -> www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=2070814 ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: Main\\"Default_Page_URL" -> www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=2070814 ->
HKEY_USERS\.DEFAULT\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch ->
HKEY_USERS\.DEFAULT\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ ->
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: Main\\"Default_Page_URL" -> www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=2070814 ->
HKEY_USERS\S-1-5-18\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch ->
HKEY_USERS\S-1-5-18\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ ->
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
HKEY_USERS\S-1-5-19\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch ->
HKEY_USERS\S-1-5-19\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
HKEY_USERS\S-1-5-20\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch ->
HKEY_USERS\S-1-5-20\: Main\\"Start Page" -> http://securityresponse.symantec.com/avcenter/fix_homepage/ ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\] > -> ->
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: Main\\"Default_Page_URL" -> www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=2070814 ->
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch ->
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: Main\\"Start Page" -> http://www.google.com/ ->
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: SearchURL\\"" -> http://www.google.com/search?q=%s ->
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: "ProxyEnable" -> 0 ->
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: "ProxyOverride" -> *.local ->
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\: "ProxyServer" -> njproxy:80 ->
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\Dustin\Application Data\Mozilla\FireFox\Profiles\e4xovvgc.default\prefs.js ->
browser.search.selectedEngine -> "eBay" ->
browser.startup.homepage -> "http://www.google.com/ig" ->
extensions.enabledItems -> [removed]:1.10 ->
extensions.enabledItems -> {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}:[removed] ->
extensions.enabledItems -> [removed]:7 ->
extensions.enabledItems -> {20a82645-c095-46ed-80e3-08825760534b}:1.0 ->
extensions.enabledItems -> {7694c49c-9fbd-11dc-8314-0800200c9a66}:3.0.2 ->
extensions.enabledItems -> {47e5a66c-0e35-11dc-8314-0800200c9a66}:3.0.1 ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13 ->
network.proxy.http -> "njproxy" ->
network.proxy.http_port -> 80 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions -> ->
HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/08/10 16:29:56 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\COMPONENTS] -> [2009/08/19 08:40:57 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\PLUGINS] -> [2009/08/06 16:36:19 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Sunbird 0.8\extensions -> ->
HKLM\software\mozilla\Mozilla Sunbird 0.8\extensions\\Components -> C:\PROGRAM FILES\MOZILLA SUNBIRD\COMPONENTS [C:\PROGRAM FILES\MOZILLA SUNBIRD\COMPONENTS] -> [2009/06/19 22:16:46 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Sunbird 0.8\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA SUNBIRD\PLUGINS [C:\PROGRAM FILES\MOZILLA SUNBIRD\PLUGINS] -> [2009/06/19 22:16:46 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions -> ->
HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components -> C:\PROGRAM FILES\MOZILLA THUNDERBIRD\COMPONENTS [C:\PROGRAM FILES\MOZILLA THUNDERBIRD\COMPONENTS] -> [2009/08/21 08:35:28 | 00,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA THUNDERBIRD\PLUGINS [C:\PROGRAM FILES\MOZILLA THUNDERBIRD\PLUGINS] -> [2009/06/19 22:16:46 | 00,000,000 | —D | M]
< FireFox Extensions [User Folders] > ->
-> C:\Documents and Settings\Dustin\Application Data\mozilla\Extensions -> [2008/05/22 09:02:01 | 00,000,000 | —D | M]
-> C:\Documents and Settings\Dustin\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2008/05/22 09:02:01 | 00,000,000 | —D | M]
-> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
-> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions\{47e5a66c-0e35-11dc-8314-0800200c9a66} -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
-> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions\{7694c49c-9fbd-11dc-8314-0800200c9a66} -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
-> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
-> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions\[removed] -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
-> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions\[removed] -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
-> C:\Documents and Settings\Dustin\Application Data\mozilla\Firefox\Profiles\e4xovvgc.default\extensions\[removed]-trash -> [2009/08/10 17:57:14 | 00,097,494 | —- | M] ()
< FireFox Extensions [Program Folders] > ->
-> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\extensions -> [2009/08/06 16:36:19 | 09,747,960 | —- | M] (Mozilla Foundation)
-> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2009/08/06 16:36:19 | 09,747,960 | —- | M] (Mozilla Foundation)
< FireFox Components [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\components\ -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\components -> [2009/08/19 08:40:57 | 00,000,000 | —D | M]
browserdirprovider.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\components\browserdirprovider.dll -> [2009/08/06 16:36:11 | 00,023,032 | —- | M] (Mozilla Foundation)
brwsrcmp.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\components\brwsrcmp.dll -> [2009/08/06 16:36:11 | 00,134,648 | —- | M] (Mozilla Foundation)
< FireFox Plugins [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins -> [2009/08/06 16:36:19 | 00,000,000 | —D | M]
np32dsw.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\np32dsw.dll -> [2008/11/24 13:35:00 | 00,114,688 | —- | M] (Adobe Systems, Inc.)
npnul32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npnul32.dll -> [2009/08/06 16:36:16 | 00,065,528 | —- | M] (mozilla.org)
NPOFFICE.DLL -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\NPOFFICE.DLL -> [2007/03/22 17:23:30 | 00,017,248 | —- | M] (Microsoft Corporation)
nppdf32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\nppdf32.dll -> [2008/10/14 20:33:30 | 00,095,600 | —- | M] (Adobe Systems Inc.)
npqtplugin.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin.dll -> [2009/06/19 22:16:45 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin2.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin2.dll -> [2009/06/19 22:16:45 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin3.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin3.dll -> [2009/06/19 22:16:45 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin4.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin4.dll -> [2009/06/19 22:16:45 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin5.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin5.dll -> [2009/06/19 22:16:45 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin6.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin6.dll -> [2009/06/19 22:16:46 | 00,143,360 | —- | M] (Apple Inc.)
npqtplugin7.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\npqtplugin7.dll -> [2009/06/19 22:16:46 | 00,143,360 | —- | M] (Apple Inc.)
QuickTimePlugin.class -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\QuickTimePlugin.cla -> [2009/06/19 22:16:45 | 00,004,208 | —- | M] ()
ShockwavePlugin.class -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\plugins\ShockwavePlugin.cla -> [2008/11/24 13:05:16 | 00,001,144 | —- | M] ()
< FireFox SearchPlugins [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins -> [2009/02/06 07:14:27 | 00,000,000 | —D | M]
amazondotcom.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\amazondotcom.xml -> [2009/02/06 07:14:21 | 00,001,394 | —- | M] ()
answers.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\answers.xml -> [2009/02/06 07:14:21 | 00,002,193 | —- | M] ()
creativecommons.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\creativecommons.xml -> [2009/02/06 07:14:21 | 00,001,534 | —- | M] ()
eBay.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\eBay.xml -> [2009/02/06 07:14:21 | 00,002,343 | —- | M] ()
google.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\google.xml -> [2009/02/06 07:14:21 | 00,001,706 | —- | M] ()
wikipedia.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\wikipedia.xml -> [2009/02/06 07:14:21 | 00,001,178 | —- | M] ()
yahoo.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX 3 BETA 5\searchplugins\yahoo.xml -> [2009/02/06 07:14:21 | 00,000,792 | —- | M] ()
< HOSTS File > (734 bytes and 19 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
Reset Hosts
127.0.0.1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/22 22:08:42 | 00,062,080 | —- | M] (Adobe Systems Incorporated)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll [SSVHelper Class] -> [2006/09/07 14:06:08 | 00,434,279 | —- | M] (Sun Microsystems, Inc.)
{789703B2-BD36-4C89-965C-39CE74959113} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{CA6319C0-31B7-401E-A518-A07C3DB8F777} [HKLM] -> C:\Program Files\BAE\BAE.dll [CBrowserHelperObject Object] -> [2007/01/26 08:07:42 | 00,098,304 | —- | M] (Dell Inc.)
{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"!AVG Anti-Spyware" -> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe ["C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized] -> [2007/06/11 03:25:42 | 06,731,312 | —- | M] (GRISOFT s.r.o.)
"Adobe Reader Speed Launcher" -> C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008/10/15 00:04:34 | 00,039,792 | —- | M] (Adobe Systems Incorporated)
"Apoint" -> C:\Program Files\Apoint\Apoint.exe [C:\Program Files\Apoint\Apoint.exe] -> [2005/10/07 11:13:38 | 00,176,128 | R— | M] (Alps Electric Co., Ltd.)
"ccApp" -> C:\Program Files\Common Files\Symantec Shared\ccApp.exe ["C:\Program Files\Common Files\Symantec Shared\ccApp.exe"] -> [2006/11/21 16:38:28 | 00,052,840 | —- | M] (Symantec Corporation)
"Document Manager" -> C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe [C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe] -> [2006/09/08 07:32:54 | 00,102,400 | —- | M] (Wave Systems Corp.)
"ISUSPM" -> C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe ["C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler] -> File not found
"iTunesHelper" -> C:\Program Files\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2009/06/05 11:39:22 | 00,292,136 | —- | M] (Apple Inc.)
"net" -> C:\WINDOWS\System32\net.net ["C:\WINDOWS\system32\net.net"] -> [2009/08/18 12:40:40 | 00,037,263 | —- | M] (Comp)
"PDVDDXSrv" -> C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe ["C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"] -> [2007/06/08 17:40:58 | 00,128,560 | —- | M] (CyberLink Corp.)
"QuickTime Task" -> C:\Program Files\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> [2009/05/26 15:18:30 | 00,413,696 | —- | M] (Apple Inc.)
"StartSecurDoc" -> C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe [C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe] -> [2006/06/01 07:55:20 | 00,425,984 | —- | M] (Winmagic Inc.)
"SunJavaUpdateSched" -> C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe ["C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"] -> [2006/09/07 13:51:22 | 00,049,263 | —- | M] (Sun Microsystems, Inc.)
"TkBellExe" -> C:\Program Files\Common Files\Real\Update_OB\realsched.exe ["C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot] -> [2007/12/08 11:08:29 | 00,185,632 | —- | M] (RealNetworks, Inc.)
"vptray" -> C:\Program Files\Symantec AntiVirus\VPTray.exe [C:\PROGRA~1\SYMANT~1\VPTray.exe] -> [2007/03/14 18:49:02 | 00,125,632 | —- | M] (Symantec Corporation)
< Run [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"H/PC Connection Agent" -> C:\Program Files\Microsoft ActiveSync\Wcescomm.exe ["C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"] -> [2006/11/13 11:39:52 | 01,289,000 | —- | M] (Microsoft Corporation)
"Inter-Chat" -> [C:\Program Files\ConWare\InterChat3\IC3] -> File not found
"Monopod" -> C:\Documents and Settings\Dustin\Local Settings\Temp\a.exe [C:\DOCUME~1\Dustin\LOCALS~1\Temp\a.exe] -> [2009/08/18 12:41:10 | 00,151,040 | —- | M] ()
"MSMSGS" -> C:\Program Files\Messenger\msmsgs.exe ["C:\Program Files\Messenger\msmsgs.exe" /background] -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
< Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup ->
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe -> [2003/10/29 01:06:00 | 00,024,576 | —- | M] (BVRP Software)
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\[removed] -> C:\Program Files\Apple Computer\DVD@ccess\DVDAccess.exe -> [2003/11/21 15:16:12 | 00,888,832 | —- | M] (Apple Computer)
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\EMBASSY Trust Suite Secure Update.lnk -> C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe -> [2006/08/25 08:45:30 | 00,192,512 | —- | M] (Wave Systems Corp.)
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup ->
< Dustin Startup Folder > -> C:\Documents and Settings\Dustin\Start Menu\Programs\Startup ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoActiveDesktopChanges" -> [0] -> File not found
\\"HonorAutoRunSetting" -> [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" -> [0] -> File not found
\\"legalnoticecaption" -> [] -> File not found
\\"legalnoticetext" -> [] -> File not found
\\"shutdownwithoutlogon" -> [1] -> File not found
\\"undockwithoutlogon" -> [1] -> File not found
\\"DisableTaskMgr" -> [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
\\"NoActiveDesktop" -> [0] -> File not found
\\"NoSaveSettings" -> [0] -> File not found
\\"ClassicShell" -> [0] -> File not found
\\"NoThemesTab" -> [0] -> File not found
\\"ForceActiveDesktopOn" -> [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"DisableRegistryTools" -> [0] -> File not found
\\"DisableTaskMgr" -> [0] -> File not found
\\"NoDispAppearancePage" -> [0] -> File not found
\\"NoColorChoice" -> [0] -> File not found
\\"NoSizeChoice" -> [0] -> File not found
\\"NoDispBackgroundPage" -> [0] -> File not found
\\"NoDispScrSavPage" -> [0] -> File not found
\\"NoDispCPL" -> [0] -> File not found
\\"NoVisualStyleChoice" -> [0] -> File not found
\\"NoDispSettingsPage" -> [0] -> File not found
< Internet Explorer Menu Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport; to Microsoft Excel -> C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2009/04/21 20:43:04 | 10,351,936 | —- | M] (Microsoft Corporation)
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport; to Microsoft Excel -> C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2009/04/21 20:43:04 | 10,351,936 | —- | M] (Microsoft Corporation)
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport; to Microsoft Excel -> C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2009/04/21 20:43:04 | 10,351,936 | —- | M] (Microsoft Corporation)
Find Visible &Path; -> C:\Program Files\Visible Path\html\VPSearch.html [C:\Program Files\Visible Path\html\VPSearch.html] -> [2007/05/17 16:43:22 | 00,002,404 | —- | M] ()
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC} [HKLM] -> C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll [Menu: Sun Java Console] -> [2006/09/07 14:06:08 | 00,069,746 | —- | M] (Sun Microsystems, Inc.)
{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}:{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Button: Create Mobile Favorite] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}:{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Menu: Create Mobile Favorite…] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL [Button: Research] -> [2007/04/19 12:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/13 22:23:34 | 00,558,080 | —- | M] (Microsoft Corporation)
{F47C1DB5-ED21-4dc1-853E-D1495792D4C5}:Exec [HKLM] -> C:\Program Files\Bodog Poker\BPGame.exe [Button: Bodog Poker] -> [2008/06/10 13:26:20 | 04,231,243 | —- | M] (Bodog)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> C:\WINDOWS\System32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | —- | M] (Microsoft Corporation)
CmdMapping\\"{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}" [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
CmdMapping\\"{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}" [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite…] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 12:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 22:23:34 | 00,558,080 | —- | M] (Microsoft Corporation)
CmdMapping\\"{F47C1DB5-ED21-4dc1-853E-D1495792D4C5}" [HKLM] -> C:\Program Files\Bodog Poker\BPGame.exe [Bodog Poker] -> [2008/06/10 13:26:20 | 04,231,243 | —- | M] (Bodog)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> C:\WINDOWS\System32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | —- | M] (Microsoft Corporation)
CmdMapping\\"{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}" [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
CmdMapping\\"{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}" [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite…] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 12:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 22:23:34 | 00,558,080 | —- | M] (Microsoft Corporation)
CmdMapping\\"{F47C1DB5-ED21-4dc1-853E-D1495792D4C5}" [HKLM] -> C:\Program Files\Bodog Poker\BPGame.exe [Bodog Poker] -> [2008/06/10 13:26:20 | 04,231,243 | —- | M] (Bodog)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\Software\Microsoft\Internet Explorer\Extensions\ ->
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"" [HKLM] -> [Reg Error: Value error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"BandCLSID" [HKLM] -> [Reg Error: Key error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"ButtonText" [HKLM] -> [Reg Error: Key error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"CLSID" [HKLM] -> [{0000031A-0000-0000-C000-000000000046}] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"Default Visible" [HKLM] -> [Reg Error: Key error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"HotIcon" [HKLM] -> [Reg Error: Key error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"Icon" [HKLM] -> [Reg Error: Key error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"MenuStatusBar" [HKLM] -> [Reg Error: Key error.] -> File not found
{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}\\"MenuText" [HKLM] -> [Reg Error: Key error.] -> File not found
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> C:\WINDOWS\System32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | —- | M] (Microsoft Corporation)
CmdMapping\\"{1B617093-5CD4-42f5-91CA-AD1004C83588}" [HKLM] -> [Reg Error: Key error.] -> File not found
CmdMapping\\"{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}" [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
CmdMapping\\"{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}" [HKLM] -> C:\Program Files\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite…] -> [2006/11/13 11:39:34 | 00,158,504 | —- | M] (Microsoft Corporation)
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 12:10:18 | 00,063,840 | —- | M] (Microsoft Corporation)
CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 22:23:34 | 00,558,080 | —- | M] (Microsoft Corporation)
CmdMapping\\"{F47C1DB5-ED21-4dc1-853E-D1495792D4C5}" [HKLM] -> C:\Program Files\Bodog Poker\BPGame.exe [Bodog Poker] -> [2008/06/10 13:26:20 | 04,231,243 | —- | M] (Bodog)
CmdMapping\\"{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}" [HKLM] -> [Reg Error: Key error.] -> File not found
CmdMapping\\"{F6DFE485-B775-4D9D-ADBC-AF4D52D5C078}" [HKCU] -> C:\Program Files\Visible Path\VP_Pathfinder.dll [Visible Path IE Toolbar] -> [2007/08/29 19:31:06 | 00,122,880 | —- | M] (Visible Path Corp.)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/14 03:42:30 | 01,695,232 | —- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime;=%s ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 2 domain(s) found. ->
www.agencyportal_newyorklife.com [https] -> Local intranet ->
www.authsm_newyorklife.com [https] -> Local intranet ->
www.ftisweb_newyorklife.com [https] -> Local intranet ->
www.fts_newyorklife.com [https] -> Local intranet ->
www.mcs_newyorklife.com [https] -> Local intranet ->
www.riat_newyorklife.com [https] -> Local intranet ->
2 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\] > -> HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-1053775303-232762173-4029903589-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{036F8A56-0BC8-4607-8F98-D3231E6FF5ED} [HKLM] -> https://emeeting.newyorklife.com/SiteRoots/main/Install/win32/CentraUpdaterAx.cab [CentraUpdaterAxCtl Class] ->
{17492023-C23A-453E-A040-C7C580BBF700} [HKLM] -> http://go.microsoft.com/fwlink/?linkid=39204 [Windows Genuine Advantage Validation Tool] ->
{48DD0448-9209-4F81-9F6D-D83562940134} [HKLM] -> http://lads.myspace.com/upload/MySpaceUploader1006.cab [MySpace Uploader Control] ->
{5EF90065-A2C4-4C6D-993E-40EE010EBA3D} [HKLM] -> https://www.fts.newyorklife.com/formslibrary/Package/FTWebUtils.CAB [FTWebUtils.Redirecter] ->
{67F02384-3864-4BCE-A408-EDD9BD565D51} [HKLM] -> http://www.munimetrix.com/nyl/demonow.cab [DemoShield DemoNow Class] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab [Java Plug-in 1.5.0_09] ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab [Reg Error: Key error.] ->
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} [HKLM] -> http://acs.pandasoftware.com/activescan/as5free/asinst.cab [ActiveScan Installer Class] ->
{B8BE5E93-A60C-4D26-A2DC-220313175592} [HKLM] -> http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab [MSN Games - Installer] ->
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab [Java Plug-in 1.5.0_06] ->
{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab [Java Plug-in 1.5.0_09] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab [Java Plug-in 1.5.0_09] ->
{D0C0F75C-683A-4390-A791-1ACFD5599AB8} [HKLM] -> http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab [Oberon Flash Game Host] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] ->
{E06E2E99-0AA1-11D4-ABA6-0060082AA75C} [HKLM] -> https://psodemo1.webex.com/client/pso-demo12/webex/ieatgpc.cab [GpcContainer Class] ->
Microsoft XML Parser for Java [HKLM] -> file://C:\WINDOWS\Java\classes\xmldso.cab [Reg Error: Key error.] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> [removed] [removed] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{544444BA-3A96-4EC9-9B17-0F29612F433F}\\DhcpNameServer -> [removed] [removed] (Dell Wireless 1390 WLAN Mini-Card) ->
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->
wxvault.dll -> C:\WINDOWS\System32\wxvault.dll -> [2006/09/08 07:32:02 | 00,286,720 | —- | M] ()
C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL -> C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll -> [2007/09/07 06:14:48 | 00,145,408 | —- | M] (Google)
*MultiFile Done* -> ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/14 03:42:20 | 01,033,728 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
igfxcui -> C:\WINDOWS\System32\igfxdev.dll -> [2005/12/13 15:40:12 | 00,139,264 | —- | M] (Intel Corporation)
NavLogon -> C:\WINDOWS\System32\NavLogon.dll -> [2007/03/14 18:49:14 | 00,043,712 | —- | M] (Symantec Corporation)
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" [HKLM] -> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> [2007/05/30 06:29:58 | 00,079,408 | —- | M] (GRISOFT s.r.o.)
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages ->
*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages ->
wvauth -> C:\WINDOWS\System32\wvauth.dll -> [2006/09/12 11:07:24 | 00,385,024 | —- | M] (Wave Systems Corp.)
*MultiFile Done* -> ->
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 22:23:34 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 03:42:36 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" -> C:\Program Files\Microsoft ActiveSync\rapimgr.exe [C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager] -> [2006/11/13 11:39:34 | 00,199,464 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" -> C:\Program Files\Microsoft ActiveSync\wcescomm.exe [C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager] -> [2006/11/13 11:39:52 | 01,289,000 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" -> C:\Program Files\Microsoft ActiveSync\WCESMgr.exe [C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application] -> [2006/11/13 11:39:54 | 04,270,888 | —- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 22:23:34 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/14 03:42:36 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\Documents and Settings\Dustin\Desktop\Diablo3-gameplaytrailer_en-US-downloader.exe" -> C:\Documents and Settings\Dustin\Desktop\Diablo3-gameplaytrailer_en-US-downloader.exe [C:\Documents and Settings\Dustin\Desktop\Diablo3-gameplaytrailer_en-US-downloader.exe:*:Enabled:Blizzard Downloader] -> File not found
"C:\Program Files\Azureus\Azureus.exe" -> C:\Program Files\Azureus\Azureus.exe [C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus] -> [2007/05/15 21:07:28 | 00,254,984 | —- | M] (Azureus Inc)
"C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008/12/12 09:17:38 | 00,238,888 | —- | M] (Apple Inc.)
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" -> C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program] -> [2007/06/08 17:40:58 | 00,128,560 | —- | M] (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe" -> C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe [C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX] -> [2007/03/02 13:33:54 | 00,063,600 | —- | M] (CyberLink Corp.)
"C:\Program Files\iCal v4.0 Web Calendar\ical.exe" -> C:\Program Files\iCal v4.0 Web Calendar\ical.exe [C:\Program Files\iCal v4.0 Web Calendar\ical.exe:*:Disabled:ical] -> [2008/01/03 11:02:06 | 02,094,080 | —- | M] ()
"C:\Program Files\InterVideo\DVD8\WinDVD.exe" -> C:\Program Files\InterVideo\DVD8\WinDVD.exe [C:\Program Files\InterVideo\DVD8\WinDVD.exe:*:Enabled:WinDVD] -> File not found
"C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2009/06/05 11:39:18 | 14,073,640 | —- | M] (Apple Inc.)
"C:\Program Files\Java\jre1.5.0_09\bin\javaw.exe" -> C:\Program Files\Java\jre1.5.0_09\bin\javaw.exe [C:\Program Files\Java\jre1.5.0_09\bin\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary] -> [2006/09/07 12:14:46 | 00,053,346 | —- | M] (Sun Microsystems, Inc.)
"C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe" -> C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe [C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe:*:Enabled:Secure Application Manager Proxy] -> [2008/10/21 16:40:18 | 00,386,440 | —- | M] (Juniper Networks)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" -> C:\Program Files\Microsoft ActiveSync\rapimgr.exe [C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager] -> [2006/11/13 11:39:34 | 00,199,464 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" -> C:\Program Files\Microsoft ActiveSync\wcescomm.exe [C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager] -> [2006/11/13 11:39:52 | 01,289,000 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" -> C:\Program Files\Microsoft ActiveSync\WCESMgr.exe [C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application] -> [2006/11/13 11:39:54 | 04,270,888 | —- | M] (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe" -> C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe [C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe:*:Enabled:Firefox] -> [2009/08/06 16:36:13 | 00,307,704 | —- | M] (Mozilla Corporation)
"C:\Program Files\Sybase\SQL Anywhere 9\win32\dbeng9.exe" -> C:\Program Files\Sybase\SQL Anywhere 9\win32\dbeng9.exe [C:\Program Files\Sybase\SQL Anywhere 9\win32\dbeng9.exe:*:Enabled:Adaptive Server Anywhere Database Engine] -> [2007/06/13 08:11:38 | 00,077,824 | —- | M] (iAnywhere Solutions, Inc.)
"C:\Program Files\Warcraft III\Warcraft III.exe" -> C:\Program Files\Warcraft III\Warcraft III.exe [C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III] -> File not found
"C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe" -> C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe [C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe:*:Enabled:SecureDoc ] -> [2006/06/01 07:55:20 | 00,425,984 | —- | M] (Winmagic Inc.)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2004/08/11 16:15:00 | 00,000,000 | —- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}\Shell
\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}\Shell\\"" -> [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}\Shell\AutoRun
\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}\Shell\AutoRun\\"" -> [Auto&Play;] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}\Shell\AutoRun\command
\{8ffcdaea-d5b0-11dd-bd64-001c230ac25d}\Shell\AutoRun\command\\"" -> E:\Photokinz.exe [E:\Photokinz.exe] -> File not found
[Registry - Additional Scans - Safe List]
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 8/16/2009 12:27:04 PM Computer Name = LAPTOP | Source = Microsoft Office 11 | ID = 1000 -> Description = Faulting application winword.exe, version 11.0.8307.0, stamp 49ee835a, faulting module winword.exe, version 11.0.8307.0, stamp 49ee835a, debug? 0, fault address 0x005e61fe.
Application [ Error ] 8/18/2009 3:15:19 PM Computer Name = LAPTOP | Source = Symantec AntiVirus | ID = 16711726 -> Description = Security Risk Found!Risk: Packed.Generic.200 in File: C:\Documents and Settings\Dustin\Local Settings\Temp\UAC15b7.tmp by: Manual scan. Action: Clean failed : Quarantine failed. Action Description: The file was left unchanged.
Application [ Error ] 8/18/2009 3:15:27 PM Computer Name = LAPTOP | Source = Symantec AntiVirus | ID = 16711731 -> Description = Security Risk Found!Risk: Packed.Generic.200 in File: C:\Documents and Settings\Dustin\Local Settings\Temp\UAC15b7.tmp by: Manual scan. Action: Cleaned by Deletion. Action Description:
Application [ Error ] 8/18/2009 3:15:40 PM Computer Name = LAPTOP | Source = Symantec AntiVirus | ID = 16711726 -> Description = Security Risk Found!Risk: Packed.Generic.205 in File: C:\Documents and Settings\Dustin\Local Settings\Temp\xcswaremon.tmp by: Manual scan. Action: Clean failed : Quarantine failed. Action Description: The file was left unchanged.
Application [ Error ] 8/18/2009 3:15:40 PM Computer Name = LAPTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description = Risk: in File: c:\documents and settings\dustin\local settings\application data\microsoft\windows media\9.0 by: Manual scan. Action: Reboot Required. Action Description: Risk: in File: c:\documents and settings\dustin\local settings\application data\microsoft\windows media by: Manual scan. Action: Reboot Required. Action Description: Risk: in File: C:\Documents and Settings\Dustin\Local Settings\Application Data\Microsoft by: Manual scan. Action: Reboot Required. Action Description: Risk: in File: Internet browser temporary file cache by: Manual scan. Action: Clean failed : Quarantine failed. Action Description: The file was deleted successfully. Risk Found!Risk: Backdoor.Tidserv!inf in File: C:\Documents and Settings\Dustin\Local Settings\Temp\UAC15c6.tmp by: Manual scan. Action: Clean failed : Quarantine failed. Action Description: The file was left unchanged.
Application [ Error ] 8/18/2009 3:15:40 PM Computer Name = LAPTOP | Source = Symantec AntiVirus | ID = 16711731 -> Description = Security Risk Found!Risk: Packed.Generic.205 in File: C:\Documents and Settings\Dustin\Local Settings\Temp\xcswaremon.tmp by: Manual scan. Action: Cleaned by Deletion. Action Description:
Application [ Error ] 8/18/2009 4:05:59 PM Computer Name = LAPTOP | Source = Symantec AntiVirus | ID = 16711685 -> Description = Risk Found!Risk: Packed.Generic.205 in File: C:\documents and settings\Dustin\local settings\Temp\xcswaremon.tmp by: Manual scan. Action: Cleaned by Deletion. Action Description: Risk: in File: Internet browser temporary file cache by: Manual scan. Action: Clean failed : Quarantine failed. Action Description: The file was deleted successfully. Risk Found!Risk: Backdoor.Tidserv in File: C:\WINDOWS\system32\drivers\UACd.sys by: Manual scan. Action: Cleaned by Deletion. Action Description:
Application [ Error ] 8/18/2009 7:58:14 PM Computer Name = LAPTOP | Source = crypt32 | ID = 131083 -> Description = Failed extract of third-party root list from auto update cab at: with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
Application [ Error ] 8/18/2009 7:58:14 PM Computer Name = LAPTOP | Source = crypt32 | ID = 131083 -> Description = Failed extract of third-party root list from auto update cab at: with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
Application [ Error ] 8/19/2009 10:40:31 AM Computer Name = LAPTOP | Source = Application Hang | ID = 1002 -> Description = Hanging application HijackThis.exe, version 1.99.0.1, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
System [ Error ] 8/3/2009 4:22:15 PM Computer Name = LAPTOP | Source = Dhcp | ID = 1000 -> Description = Your computer has lost the lease to its IP address 192.168.1.4 on the Network Card with network address 001BFCD2FCD5.
System [ Error ] 8/6/2009 1:08:03 PM Computer Name = LAPTOP | Source = Dhcp | ID = 1002 -> Description = The IP address lease 192.168.1.2 for the Network Card with network address 001BFCD2FCD5 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
System [ Error ] 8/6/2009 6:39:44 PM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}. The backup browser is stopping.
System [ Error ] 8/7/2009 2:59:01 AM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}. The backup browser is stopping.
System [ Error ] 8/7/2009 10:40:12 AM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}. The backup browser is stopping.
System [ Error ] 8/7/2009 9:00:01 PM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}. The backup browser is stopping.
System [ Error ] 8/8/2009 2:18:30 AM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}. The backup browser is stopping.
System [ Error ] 8/8/2009 10:32:43 AM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}. The backup browser is stopping.
System [ Error ] 8/8/2009 9:45:14 PM Computer Name = LAPTOP | Source = BROWSER | ID = 8032 -> Description = The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{544444BA-3A96-4EC9-9B17-0F29612F433F}. The backup browser is stopping.
System [ Error ] 8/10/2009 10:00:09 AM Computer Name = LAPTOP | Source = Dhcp | ID = 1000 -> Description = Your computer has lost the lease to its IP address 192.168.1.4 on the Network Card with network address 001BFCD2FCD5.
[Files/Folders - Created Within 30 Days]
1 C:\*.tmp files -> C:\*.tmp ->
1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
OTS.exe -> C:\Documents and Settings\Dustin\Desktop\OTS.exe -> [2009/08/21 09:37:20 | 00,514,048 | —- | C] (OldTimer Tools)
HijackThis.lnk -> C:\Documents and Settings\Dustin\Desktop\HijackThis.lnk -> [2009/08/19 08:51:42 | 00,001,734 | —- | C] ()
Trend Micro -> C:\Program Files\Trend Micro -> [2009/08/19 08:51:36 | 00,000,000 | —D | C]
HJTInstall.exe -> C:\Documents and Settings\Dustin\Desktop\HJTInstall.exe -> [2009/08/19 08:49:11 | 00,812,344 | —- | C] (Trend Micro Inc.)
19876094 -> C:\Documents and Settings\All Users\Application Data\19876094 -> [2009/08/19 07:58:08 | 00,000,000 | —D | C]
{BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> [2009/08/18 12:41:11 | 00,000,282 | -H– | C] ()
net.net -> C:\WINDOWS\System32\net.net -> [2009/08/18 12:40:39 | 00,037,263 | —- | C] (Comp)
BVC Calendar NEW.xls -> C:\Documents and Settings\Dustin\Desktop\BVC Calendar NEW.xls -> [2009/08/17 08:36:55 | 00,230,400 | —- | C] ()
dhtmled.ocx -> C:\WINDOWS\System32\dllcache\dhtmled.ocx -> [2009/08/12 10:31:54 | 00,128,512 | —- | C] (Microsoft Corporation)
msoe.dll -> C:\WINDOWS\System32\dllcache\msoe.dll -> [2009/08/12 10:31:46 | 01,315,328 | —- | C] (Microsoft Corporation)
IECompatCache -> C:\Documents and Settings\Dustin\IECompatCache -> [2009/08/11 09:28:59 | 00,000,000 | -HSD | C]
PrivacIE -> C:\Documents and Settings\Dustin\PrivacIE -> [2009/08/11 09:18:40 | 00,000,000 | -HSD | C]
ntprint.cat -> C:\WINDOWS\System32\dllcache\ntprint.cat -> [2009/08/11 09:08:33 | 01,089,593 | —- | C] ()
XPSViewer -> C:\WINDOWS\System32\XPSViewer -> [2009/08/10 16:28:54 | 00,000,000 | —D | C]
MSBuild -> C:\Program Files\MSBuild -> [2009/08/10 16:28:48 | 00,000,000 | —D | C]
Reference Assemblies -> C:\Program Files\Reference Assemblies -> [2009/08/10 16:28:35 | 00,000,000 | —D | C]
printfilterpipelinesvc.exe -> C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe -> [2009/08/10 16:28:02 | 00,597,504 | —- | C] (Microsoft Corporation)
prntvpt.dll -> C:\WINDOWS\System32\prntvpt.dll -> [2009/08/10 16:28:02 | 00,117,760 | —- | C] (Microsoft Corporation)
filterpipelineprintproc.dll -> C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll -> [2009/08/10 16:28:02 | 00,089,088 | —- | C] (Microsoft Corporation)
xpssvcs.dll -> C:\WINDOWS\System32\xpssvcs.dll -> [2009/08/10 16:28:01 | 01,676,288 | —- | C] (Microsoft Corporation)
xpssvcs.dll -> C:\WINDOWS\System32\dllcache\xpssvcs.dll -> [2009/08/10 16:28:01 | 01,676,288 | —- | C] (Microsoft Corporation)
xpsshhdr.dll -> C:\WINDOWS\System32\xpsshhdr.dll -> [2009/08/10 16:28:01 | 00,575,488 | —- | C] (Microsoft Corporation)
xpsshhdr.dll -> C:\WINDOWS\System32\dllcache\xpsshhdr.dll -> [2009/08/10 16:28:01 | 00,575,488 | —- | C] (Microsoft Corporation)
58ba0bc4b57ee9a7f3 -> C:\58ba0bc4b57ee9a7f3 -> [2009/08/10 16:28:01 | 00,000,000 | —D | C]
Credit Reports -> C:\Documents and Settings\Dustin\Desktop\Credit Reports -> [2009/08/10 11:39:45 | 00,000,000 | —D | C]
sample.mmb -> C:\Documents and Settings\Dustin\My Documents\sample.mmb -> [2009/08/10 08:32:30 | 00,020,480 | —- | C] ()
home_budget_backup_20090810_082710.shbf -> C:\Documents and Settings\Dustin\My Documents\home_budget_backup_20090810_082710.shbf -> [2009/08/10 08:27:10 | 00,151,552 | —- | C] ()
home_budget2.shbf -> C:\Documents and Settings\Dustin\My Documents\home_budget2.shbf -> [2009/08/10 08:26:28 | 00,139,264 | —- | C] ()
home_budget.shbf -> C:\Documents and Settings\Dustin\My Documents\home_budget.shbf -> [2009/08/10 08:22:07 | 00,151,552 | —- | C] ()
home_budget.ini -> C:\Documents and Settings\Dustin\Application Data\home_budget.ini -> [2009/08/10 08:22:07 | 00,001,827 | —- | C] ()
Simple Home Budget -> C:\Documents and Settings\Dustin\Local Settings\Application Data\Simple Home Budget -> [2009/08/10 08:21:36 | 00,000,000 | —D | C]
HB -> C:\Program Files\HB -> [2009/08/10 08:08:36 | 00,000,000 | —D | C]
IETldCache -> C:\Documents and Settings\Dustin\IETldCache -> [2009/08/08 19:39:59 | 00,000,000 | -HSD | C]
~$rlsConference.doc -> C:\Documents and Settings\Dustin\My Documents\~$rlsConference.doc -> [2009/08/08 09:44:38 | 00,000,162 | -H– | C] ()
xpshims.dll -> C:\WINDOWS\System32\dllcache\xpshims.dll -> [2009/08/08 08:38:57 | 00,012,800 | —- | C] (Microsoft Corporation)
iertutil.dll -> C:\WINDOWS\System32\dllcache\iertutil.dll -> [2009/08/08 08:38:56 | 01,985,536 | —- | C] (Microsoft Corporation)
msfeeds.dll -> C:\WINDOWS\System32\dllcache\msfeeds.dll -> [2009/08/08 08:38:56 | 00,594,432 | —- | C] (Microsoft Corporation)
msfeedsbs.dll -> C:\WINDOWS\System32\dllcache\msfeedsbs.dll -> [2009/08/08 08:38:56 | 00,055,296 | —- | C] (Microsoft Corporation)
ieframe.dll -> C:\WINDOWS\System32\dllcache\ieframe.dll -> [2009/08/08 08:38:55 | 11,067,392 | —- | C] (Microsoft Corporation)
ieproxy.dll -> C:\WINDOWS\System32\dllcache\ieproxy.dll -> [2009/08/08 08:38:55 | 00,246,272 | —- | C] (Microsoft Corporation)
ie8updates -> C:\WINDOWS\ie8updates -> [2009/08/08 08:38:50 | 00,000,000 | —D | C]
iecompat.dll -> C:\WINDOWS\System32\dllcache\iecompat.dll -> [2009/08/08 08:37:29 | 00,101,376 | —- | C] (Microsoft Corporation)
WBEM -> C:\WINDOWS\WBEM -> [2009/08/08 08:36:53 | 00,000,000 | —D | C]
ie8 -> C:\WINDOWS\ie8 -> [2009/08/08 08:34:56 | 00,000,000 | -H-D | C]
0806092123(4).jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123(4).jpg -> [2009/08/06 21:33:12 | 00,072,724 | —- | C] ()
0806092123(3).jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123(3).jpg -> [2009/08/06 21:32:31 | 00,072,724 | —- | C] ()
0806092123(2).jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123(2).jpg -> [2009/08/06 21:32:08 | 00,072,724 | —- | C] ()
0806092123.jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123.jpg -> [2009/08/06 21:32:07 | 00,072,724 | —- | C] ()
GirlsConference.doc -> C:\Documents and Settings\Dustin\My Documents\GirlsConference.doc -> [2009/08/06 17:04:51 | 00,025,600 | —- | C] ()
Seahawks.jpg -> C:\Documents and Settings\Dustin\Desktop\Seahawks.jpg -> [2009/08/06 16:37:33 | 00,247,865 | —- | C] ()
mswebdvd.dll -> C:\WINDOWS\System32\dllcache\mswebdvd.dll -> [2009/08/05 03:01:48 | 00,204,800 | —- | C] (Microsoft Corporation)
xvidcore.dll -> C:\WINDOWS\System32\xvidcore.dll -> [2008/08/15 17:32:44 | 00,765,952 | —- | C] ()
xvidvfw.dll -> C:\WINDOWS\System32\xvidvfw.dll -> [2008/08/15 17:32:43 | 00,180,224 | —- | C] ()
upctrl32.INI -> C:\WINDOWS\upctrl32.INI -> [2008/05/06 15:07:39 | 00,000,000 | —- | C] ()
wcds.ini.07.3 -> C:\WINDOWS\wcds.ini.07.3 -> [2008/05/06 15:05:45 | 00,002,527 | —- | C] ()
ezdatar.ini -> C:\WINDOWS\ezdatar.ini -> [2008/05/06 14:40:36 | 00,000,193 | —- | C] ()
FTSL.INI -> C:\WINDOWS\FTSL.INI -> [2008/05/06 14:39:45 | 00,000,027 | —- | C] ()
WUNZIP32.DLL -> C:\WINDOWS\System32\WUNZIP32.DLL -> [2008/04/16 08:28:48 | 00,093,488 | —- | C] ()
FtisUtil.dll -> C:\WINDOWS\System32\FtisUtil.dll -> [2008/04/16 08:23:14 | 00,406,832 | —- | C] ()
MYCALC.DLL -> C:\WINDOWS\System32\MYCALC.DLL -> [2008/03/25 11:50:18 | 01,927,680 | —- | C] ()
wcds.ini -> C:\WINDOWS\wcds.ini -> [2008/03/11 16:31:07 | 00,002,543 | —- | C] ()
ezhelp32.dll -> C:\WINDOWS\System32\ezhelp32.dll -> [2008/03/11 16:30:28 | 00,049,152 | —- | C] ()
NYL_Screensaver_v2.ini -> C:\WINDOWS\NYL_Screensaver_v2.ini -> [2008/02/07 15:19:42 | 00,000,058 | —- | C] ()
iplayer.INI -> C:\WINDOWS\iplayer.INI -> [2008/01/14 18:39:42 | 00,000,000 | —- | C] ()
fxsperf.ini -> C:\WINDOWS\System32\fxsperf.ini -> [2008/01/10 08:36:28 | 00,001,793 | —- | C] ()
CmdLineExt03.dll -> C:\WINDOWS\System32\CmdLineExt03.dll -> [2008/01/04 17:51:38 | 00,043,520 | —- | C] ()
SIntfNT.dll -> C:\WINDOWS\System32\SIntfNT.dll -> [2008/01/04 17:50:19 | 00,021,840 | —- | C] ()
SIntf32.dll -> C:\WINDOWS\System32\SIntf32.dll -> [2008/01/04 17:50:19 | 00,017,212 | —- | C] ()
SIntf16.dll -> C:\WINDOWS\System32\SIntf16.dll -> [2008/01/04 17:50:18 | 00,012,067 | —- | C] ()
SCapPro.INI -> C:\WINDOWS\SCapPro.INI -> [2007/12/10 14:46:39 | 00,000,072 | —- | C] ()
cdplayer.ini -> C:\WINDOWS\cdplayer.ini -> [2007/12/08 11:10:02 | 00,007,374 | —- | C] ()
newload.INI -> C:\WINDOWS\newload.INI -> [2007/09/06 07:32:21 | 00,000,000 | —- | C] ()
ZPORT4AS.dll -> C:\WINDOWS\System32\ZPORT4AS.dll -> [2007/08/24 13:05:16 | 00,011,776 | —- | C] ()
VPC32.INI -> C:\WINDOWS\VPC32.INI -> [2007/08/23 17:30:25 | 00,000,000 | —- | C] ()
STERWENT.INI -> C:\WINDOWS\STERWENT.INI -> [2007/08/21 13:15:42 | 00,000,460 | -H– | C] ()
PrintFix.dll -> C:\WINDOWS\System32\PrintFix.dll -> [2007/08/21 13:13:48 | 00,045,056 | —- | C] ()
ezmail.ini -> C:\WINDOWS\ezmail.ini -> [2007/08/21 13:05:07 | 00,000,314 | —- | C] ()
lcppn201.dll -> C:\WINDOWS\System32\lcppn201.dll -> [2007/08/21 13:05:02 | 03,203,072 | —- | C] ()
ftcsutil.INI -> C:\WINDOWS\ftcsutil.INI -> [2007/08/21 13:04:28 | 00,000,000 | —- | C] ()
dtidb.dll -> C:\WINDOWS\System32\dtidb.dll -> [2007/08/21 13:03:59 | 00,269,312 | —- | C] ()
ic32.ini -> C:\WINDOWS\System32\ic32.ini -> [2007/08/21 13:03:57 | 00,000,151 | —- | C] ()
CTREESTD.DLL -> C:\WINDOWS\System32\CTREESTD.DLL -> [2007/08/21 13:03:56 | 00,163,840 | —- | C] ()
U2LSQRT.DLL -> C:\WINDOWS\System32\U2LSQRT.DLL -> [2007/08/21 13:03:56 | 00,082,432 | —- | C] ()
U2LESBSE.DLL -> C:\WINDOWS\System32\U2LESBSE.DLL -> [2007/08/21 13:03:56 | 00,070,656 | —- | C] ()
U2LEXPO.DLL -> C:\WINDOWS\System32\U2LEXPO.DLL -> [2007/08/21 13:03:56 | 00,063,488 | —- | C] ()
U2LPDXTM.DLL -> C:\WINDOWS\System32\U2LPDXTM.DLL -> [2007/08/21 13:03:56 | 00,053,248 | —- | C] ()
U2LSSM.DLL -> C:\WINDOWS\System32\U2LSSM.DLL -> [2007/08/21 13:03:56 | 00,040,960 | —- | C] ()
U2LBAR.DLL -> C:\WINDOWS\System32\U2LBAR.DLL -> [2007/08/21 13:03:56 | 00,040,960 | —- | C] ()
U2LCAPS.DLL -> C:\WINDOWS\System32\U2LCAPS.DLL -> [2007/08/21 13:03:56 | 00,038,400 | —- | C] ()
U2LSTR.DLL -> C:\WINDOWS\System32\U2LSTR.DLL -> [2007/08/21 13:03:56 | 00,033,280 | —- | C] ()
U2LTIME.DLL -> C:\WINDOWS\System32\U2LTIME.DLL -> [2007/08/21 13:03:56 | 00,030,720 | —- | C] ()
U2LTEC1.DLL -> C:\WINDOWS\System32\U2LTEC1.DLL -> [2007/08/21 13:03:56 | 00,028,672 | —- | C] ()
U2LSTRNG.DLL -> C:\WINDOWS\System32\U2LSTRNG.DLL -> [2007/08/21 13:03:56 | 00,027,136 | —- | C] ()
U2LTDATE.DLL -> C:\WINDOWS\System32\U2LTDATE.DLL -> [2007/08/21 13:03:56 | 00,026,624 | —- | C] ()
U2LJUL.DLL -> C:\WINDOWS\System32\U2LJUL.DLL -> [2007/08/21 13:03:56 | 00,026,112 | —- | C] ()
U2LASC.DLL -> C:\WINDOWS\System32\U2LASC.DLL -> [2007/08/21 13:03:56 | 00,026,112 | —- | C] ()
PG32CONV.DLL -> C:\WINDOWS\System32\PG32CONV.DLL -> [2007/08/21 13:03:55 | 00,100,352 | —- | C] ()
U25TOTAL.DLL -> C:\WINDOWS\System32\U25TOTAL.DLL -> [2007/08/21 13:03:55 | 00,059,904 | —- | C] ()
P2SMCUBE.DLL -> C:\WINDOWS\System32\P2SMCUBE.DLL -> [2007/08/21 13:03:54 | 00,282,624 | —- | C] ()
P2MOLAP.DLL -> C:\WINDOWS\System32\P2MOLAP.DLL -> [2007/08/21 13:03:54 | 00,270,336 | —- | C] ()
P2SOLAP.DLL -> C:\WINDOWS\System32\P2SOLAP.DLL -> [2007/08/21 13:03:54 | 00,258,048 | —- | C] ()
CRUTL14.DLL -> C:\WINDOWS\System32\CRUTL14.DLL -> [2007/08/21 13:03:53 | 00,299,008 | —- | C] ()
LFFAX60N.DLL -> C:\WINDOWS\System32\LFFAX60N.DLL -> [2007/08/21 13:03:53 | 00,176,128 | —- | C] ()
LFCMP60N.DLL -> C:\WINDOWS\System32\LFCMP60N.DLL -> [2007/08/21 13:03:53 | 00,141,824 | —- | C] ()
LTFIL60N.DLL -> C:\WINDOWS\System32\LTFIL60N.DLL -> [2007/08/21 13:03:53 | 00,043,008 | —- | C] ()
LFEPS60N.DLL -> C:\WINDOWS\System32\LFEPS60N.DLL -> [2007/08/21 13:03:53 | 00,022,528 | —- | C] ()
LFBMP60N.DLL -> C:\WINDOWS\System32\LFBMP60N.DLL -> [2007/08/21 13:03:53 | 00,022,016 | —- | C] ()
IMPLODE.DLL -> C:\WINDOWS\System32\IMPLODE.DLL -> [2007/08/21 13:03:53 | 00,017,920 | —- | C] ()
SWCGUIDE.INI -> C:\WINDOWS\SWCGUIDE.INI -> [2007/08/21 13:03:23 | 00,000,036 | —- | C] ()
hpbafd.ini -> C:\WINDOWS\hpbafd.ini -> [2007/08/21 12:21:02 | 00,000,169 | —- | C] ()
SecurDoc.INI -> C:\WINDOWS\SecurDoc.INI -> [2007/08/21 12:13:33 | 00,000,000 | —- | C] ()
ODBC.INI -> C:\WINDOWS\ODBC.INI -> [2007/08/20 21:04:37 | 00,001,053 | —- | C] ()
smscfg.ini -> C:\WINDOWS\smscfg.ini -> [2007/08/14 18:14:37 | 00,000,061 | —- | C] ()
bioapi_mds300.dll -> C:\WINDOWS\System32\bioapi_mds300.dll -> [2007/08/14 18:09:01 | 00,143,360 | —- | C] ()
bioapi100.dll -> C:\WINDOWS\System32\bioapi100.dll -> [2007/08/14 18:09:01 | 00,106,496 | —- | C] ()
preflib.dll -> C:\WINDOWS\System32\preflib.dll -> [2007/08/14 18:04:16 | 00,086,016 | —- | C] ()
bcm1xsup.dll -> C:\WINDOWS\System32\bcm1xsup.dll -> [2007/08/14 18:04:14 | 00,757,760 | —- | C] ()
OEMINFO.INI -> C:\WINDOWS\System32\OEMINFO.INI -> [2007/08/14 17:42:06 | 00,001,120 | —- | C] ()
AmRes_en.dll -> C:\WINDOWS\System32\AmRes_en.dll -> [2006/09/12 11:07:36 | 00,184,320 | —- | C] ()
AmRes_es.dll -> C:\WINDOWS\System32\AmRes_es.dll -> [2006/09/12 11:01:48 | 00,196,608 | —- | C] ()
AmRes_ko.dll -> C:\WINDOWS\System32\AmRes_ko.dll -> [2006/09/12 11:01:42 | 00,192,512 | —- | C] ()
AmRes_de.dll -> C:\WINDOWS\System32\AmRes_de.dll -> [2006/09/12 11:01:34 | 00,196,608 | —- | C] ()
AmRes_pt-BR.dll -> C:\WINDOWS\System32\AmRes_pt-BR.dll -> [2006/09/12 11:01:28 | 00,184,320 | —- | C] ()
AmRes_fr.dll -> C:\WINDOWS\System32\AmRes_fr.dll -> [2006/09/12 11:01:20 | 00,192,512 | —- | C] ()
AmRes_ja.dll -> C:\WINDOWS\System32\AmRes_ja.dll -> [2006/09/12 11:01:12 | 00,188,416 | —- | C] ()
AmRes_ru.dll -> C:\WINDOWS\System32\AmRes_ru.dll -> [2006/09/12 11:01:06 | 00,208,896 | —- | C] ()
AmRes_it.dll -> C:\WINDOWS\System32\AmRes_it.dll -> [2006/09/12 11:00:58 | 00,196,608 | —- | C] ()
AmRes_zh-CHS.dll -> C:\WINDOWS\System32\AmRes_zh-CHS.dll -> [2006/09/12 11:00:52 | 00,176,128 | —- | C] ()
AmRes_zh-CHT.dll -> C:\WINDOWS\System32\AmRes_zh-CHT.dll -> [2006/09/12 11:00:44 | 00,172,032 | —- | C] ()
wxvault.dll -> C:\WINDOWS\System32\wxvault.dll -> [2006/09/08 07:32:02 | 00,286,720 | —- | C] ()
detoured.dll -> C:\WINDOWS\System32\detoured.dll -> [2006/09/08 07:30:44 | 00,004,096 | —- | C] ()
Internationalization_en.dll -> C:\WINDOWS\System32\Internationalization_en.dll -> [2006/09/05 09:05:32 | 00,077,824 | —- | C] ()
Internationalization_pt.dll -> C:\WINDOWS\System32\Internationalization_pt.dll -> [2006/09/05 08:26:06 | 00,073,728 | —- | C] ()
Internationalization_zh-CHT.dll -> C:\WINDOWS\System32\Internationalization_zh-CHT.dll -> [2006/09/05 08:25:54 | 00,069,632 | —- | C] ()
Internationalization_ko.dll -> C:\WINDOWS\System32\Internationalization_ko.dll -> [2006/09/05 08:25:42 | 00,073,728 | —- | C] ()
Internationalization_es.dll -> C:\WINDOWS\System32\Internationalization_es.dll -> [2006/09/05 08:25:32 | 00,077,824 | —- | C] ()
Internationalization_ru.dll -> C:\WINDOWS\System32\Internationalization_ru.dll -> [2006/09/05 08:25:20 | 00,077,824 | —- | C] ()
Internationalization_ja.dll -> C:\WINDOWS\System32\Internationalization_ja.dll -> [2006/09/05 08:25:10 | 00,073,728 | —- | C] ()
Internationalization_it.dll -> C:\WINDOWS\System32\Internationalization_it.dll -> [2006/09/05 08:24:58 | 00,081,920 | —- | C] ()
Internationalization_de.dll -> C:\WINDOWS\System32\Internationalization_de.dll -> [2006/09/05 08:24:48 | 00,081,920 | —- | C] ()
Internationalization_fr.dll -> C:\WINDOWS\System32\Internationalization_fr.dll -> [2006/09/05 08:24:36 | 00,081,920 | —- | C] ()
Internationalization_zh-CHS.dll -> C:\WINDOWS\System32\Internationalization_zh-CHS.dll -> [2006/09/05 08:24:26 | 00,069,632 | —- | C] ()
TspPopup_RUS.dll -> C:\WINDOWS\System32\TspPopup_RUS.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
TspPopup_ITA.dll -> C:\WINDOWS\System32\TspPopup_ITA.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
TspPopup_FRA.dll -> C:\WINDOWS\System32\TspPopup_FRA.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
TspPopup_ESN.dll -> C:\WINDOWS\System32\TspPopup_ESN.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
TspPopup_ENU.dll -> C:\WINDOWS\System32\TspPopup_ENU.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
TspPopup_DEU.dll -> C:\WINDOWS\System32\TspPopup_DEU.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
TspPopup_CHS.dll -> C:\WINDOWS\System32\TspPopup_CHS.dll -> [2006/06/12 09:01:18 | 00,024,576 | —- | C] ()
Tsp.dll -> C:\WINDOWS\System32\Tsp.dll -> [2006/06/12 09:01:16 | 00,348,160 | —- | C] ()
SDMigrate.dll -> C:\WINDOWS\System32\SDMigrate.dll -> [2006/06/01 07:55:20 | 00,040,960 | —- | C] ()
SDInst.dll -> C:\WINDOWS\System32\SDInst.dll -> [2006/06/01 07:55:10 | 00,032,839 | —- | C] ()
Uninst.dll -> C:\WINDOWS\System32\Uninst.dll -> [2006/06/01 07:50:44 | 00,041,030 | —- | C] ()
sdck.dll -> C:\WINDOWS\System32\sdck.dll -> [2006/06/01 07:46:32 | 00,176,190 | —- | C] ()
SDDisk2K.sys -> C:\WINDOWS\System32\drivers\SDDisk2K.sys -> [2006/01/24 11:36:44 | 00,194,048 | —- | C] ()
pbadrvdll.dll -> C:\WINDOWS\System32\pbadrvdll.dll -> [2005/12/01 13:41:20 | 00,057,344 | —- | C] ()
wmpki.dll -> C:\WINDOWS\System32\wmpki.dll -> [2005/09/23 08:03:38 | 00,389,120 | —- | C] ()
DemoLicense.dll -> C:\WINDOWS\System32\DemoLicense.dll -> [2005/09/20 12:36:06 | 00,798,720 | —- | C] ()
wmcv.dll -> C:\WINDOWS\System32\wmcv.dll -> [2005/06/17 09:21:50 | 00,036,864 | —- | C] ()
orun32.ini -> C:\WINDOWS\orun32.ini -> [2004/08/11 16:24:19 | 00,000,831 | —- | C] ()
win.ini -> C:\WINDOWS\win.ini -> [2004/08/11 16:00:37 | 00,000,683 | —- | C] ()
system.ini -> C:\WINDOWS\system.ini -> [2004/08/11 16:00:35 | 00,000,227 | —- | C] ()
lmgr10.dll -> C:\WINDOWS\System32\lmgr10.dll -> [2004/07/21 14:03:14 | 00,917,504 | —- | C] ()
ADsSecurity.dll -> C:\WINDOWS\System32\ADsSecurity.dll -> [2004/07/20 13:27:52 | 00,057,344 | —- | C] ()
sdlibeay.dll -> C:\WINDOWS\System32\sdlibeay.dll -> [2004/07/19 13:46:40 | 00,876,544 | —- | C] ()
xltZlib.dll -> C:\WINDOWS\System32\xltZlib.dll -> [2004/03/18 17:01:20 | 00,072,192 | —- | C] ()
POSTLOG2.DLL -> C:\WINDOWS\System32\POSTLOG2.DLL -> [2003/12/18 08:09:06 | 00,159,744 | —- | C] ()
OUTLPERF.INI -> C:\WINDOWS\System32\OUTLPERF.INI -> [2003/01/07 13:05:08 | 00,002,695 | —- | C] ()
RASFUNCS.DLL -> C:\WINDOWS\System32\RASFUNCS.DLL -> [2002/03/19 12:42:02 | 00,045,056 | —- | C] ()
IAPI.INI -> C:\WINDOWS\IAPI.INI -> [2002/03/12 07:01:26 | 00,032,881 | —- | C] ()
FTUtilities.dll -> C:\WINDOWS\System32\FTUtilities.dll -> [2002/03/05 08:47:58 | 00,061,440 | —- | C] ()
IAPI5.DLL -> C:\WINDOWS\System32\IAPI5.DLL -> [2002/03/01 12:03:26 | 00,253,952 | —- | C] ()
NYLCERT2.DLL -> C:\WINDOWS\System32\NYLCERT2.DLL -> [2002/02/06 13:03:16 | 00,065,536 | —- | C] ()
MAPIPROF.DLL -> C:\WINDOWS\System32\MAPIPROF.DLL -> [2001/10/04 12:34:56 | 00,118,784 | —- | C] ()
iapismapi.dll -> C:\WINDOWS\System32\iapismapi.dll -> [2001/08/22 12:34:12 | 00,045,056 | —- | C] ()
iapiemapi.dll -> C:\WINDOWS\System32\iapiemapi.dll -> [2001/08/22 12:34:04 | 00,057,344 | —- | C] ()
NYLUTIL7.DLL -> C:\WINDOWS\System32\NYLUTIL7.DLL -> [2001/08/22 11:30:22 | 00,024,576 | —- | C] ()
FTAACREQ.DLL -> C:\WINDOWS\System32\FTAACREQ.DLL -> [2001/06/13 07:06:00 | 00,049,152 | —- | C] ()
MSRTEDIT.DLL -> C:\WINDOWS\System32\MSRTEDIT.DLL -> [1999/01/22 12:46:58 | 00,065,536 | —- | C] ()
VBALINK.DLL -> C:\WINDOWS\System32\VBALINK.DLL -> [1993/08/24 08:19:20 | 00,037,568 | —- | C] ()
[Files/Folders - Modified Within 30 Days]
1 C:\Documents and Settings\Dustin\My Documents\*.tmp files -> C:\Documents and Settings\Dustin\My Documents\*.tmp ->
994 C:\Documents and Settings\Dustin\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Dustin\Local Settings\Temp\*.tmp ->
My Money.mny -> C:\Documents and Settings\Dustin\My Documents\My Money.mny -> [2009/08/21 09:37:37 | 03,952,640 | —- | M] ()
OTS.exe -> C:\Documents and Settings\Dustin\Desktop\OTS.exe -> [2009/08/21 09:37:20 | 00,514,048 | —- | M] (OldTimer Tools)
{BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> [2009/08/21 09:25:57 | 00,000,282 | -H– | M] ()
Word.lnk -> C:\Documents and Settings\Dustin\Desktop\Word.lnk -> [2009/08/21 08:32:35 | 00,002,497 | —- | M] ()
d3d9caps.dat -> C:\WINDOWS\System32\d3d9caps.dat -> [2009/08/19 14:07:43 | 00,001,324 | —- | M] ()
Excel.lnk -> C:\Documents and Settings\Dustin\Desktop\Excel.lnk -> [2009/08/19 10:35:01 | 00,002,495 | —- | M] ()
HijackThis.lnk -> C:\Documents and Settings\Dustin\Desktop\HijackThis.lnk -> [2009/08/19 08:51:42 | 00,001,734 | —- | M] ()
HJTInstall.exe -> C:\Documents and Settings\Dustin\Desktop\HJTInstall.exe -> [2009/08/19 08:49:15 | 00,812,344 | —- | M] (Trend Micro Inc.)
PerfStringBackup.INI -> C:\WINDOWS\System32\PerfStringBackup.INI -> [2009/08/19 08:43:42 | 00,561,868 | —- | M] ()
perfh009.dat -> C:\WINDOWS\System32\perfh009.dat -> [2009/08/19 08:43:42 | 00,471,576 | —- | M] ()
perfc009.dat -> C:\WINDOWS\System32\perfc009.dat -> [2009/08/19 08:43:42 | 00,080,574 | —- | M] ()
wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2009/08/19 08:39:26 | 00,002,206 | —- | M] ()
SA.DAT -> C:\WINDOWS\tasks\SA.DAT -> [2009/08/19 08:38:31 | 00,000,006 | -H– | M] ()
bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2009/08/19 08:38:24 | 00,002,048 | –S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2009/08/19 08:38:20 | 10,633,46176 | -HS- | M] ()
NTUSER.DAT -> C:\Documents and Settings\Dustin\NTUSER.DAT -> [2009/08/19 08:34:08 | 05,242,880 | —- | M] ()
ntuser.ini -> C:\Documents and Settings\Dustin\ntuser.ini -> [2009/08/19 07:41:02 | 00,000,278 | -HS- | M] ()
a.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\a.exe -> [2009/08/18 12:41:10 | 00,151,040 | —- | M] ()
net.net -> C:\WINDOWS\System32\net.net -> [2009/08/18 12:40:40 | 00,037,263 | —- | M] (Comp)
BVC Calendar NEW.xls -> C:\Documents and Settings\Dustin\Desktop\BVC Calendar NEW.xls -> [2009/08/17 12:51:09 | 00,230,400 | —- | M] ()
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2009/08/16 14:14:12 | 00,004,646 | —- | M] ()
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2009/08/16 14:14:12 | 00,004,232 | —- | M] ()
imsins.BAK -> C:\WINDOWS\imsins.BAK -> [2009/08/12 12:31:55 | 00,001,374 | —- | M] ()
FNTCACHE.DAT -> C:\WINDOWS\System32\FNTCACHE.DAT -> [2009/08/10 17:54:01 | 00,124,520 | —- | M] ()
Perflib_Perfdata_fec.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_fec.dat -> [2009/08/10 16:28:03 | 00,016,384 | —- | M] ()
My Money Backup.mbf -> C:\Documents and Settings\Dustin\My Documents\My Money Backup.mbf -> [2009/08/10 09:07:29 | 01,126,960 | R— | M] ()
sample.mmb -> C:\Documents and Settings\Dustin\My Documents\sample.mmb -> [2009/08/10 08:59:55 | 00,020,480 | —- | M] ()
home_budget.ini -> C:\Documents and Settings\Dustin\Application Data\home_budget.ini -> [2009/08/10 08:27:10 | 00,001,827 | —- | M] ()
home_budget_backup_20090810_082710.shbf -> C:\Documents and Settings\Dustin\My Documents\home_budget_backup_20090810_082710.shbf -> [2009/08/10 08:26:38 | 00,151,552 | —- | M] ()
home_budget.shbf -> C:\Documents and Settings\Dustin\My Documents\home_budget.shbf -> [2009/08/10 08:26:38 | 00,151,552 | —- | M] ()
home_budget2.shbf -> C:\Documents and Settings\Dustin\My Documents\home_budget2.shbf -> [2009/08/10 08:26:38 | 00,139,264 | —- | M] ()
~$rlsConference.doc -> C:\Documents and Settings\Dustin\My Documents\~$rlsConference.doc -> [2009/08/08 09:44:38 | 00,000,162 | -H– | M] ()
GirlsConference.doc -> C:\Documents and Settings\Dustin\My Documents\GirlsConference.doc -> [2009/08/07 21:27:19 | 00,025,600 | —- | M] ()
0806092123(4).jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123(4).jpg -> [2009/08/06 21:33:14 | 00,072,724 | —- | M] ()
0806092123(3).jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123(3).jpg -> [2009/08/06 21:32:32 | 00,072,724 | —- | M] ()
0806092123(2).jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123(2).jpg -> [2009/08/06 21:32:09 | 00,072,724 | —- | M] ()
0806092123.jpg -> C:\Documents and Settings\Dustin\Desktop\0806092123.jpg -> [2009/08/06 21:32:08 | 00,072,724 | —- | M] ()
Seahawks.jpg -> C:\Documents and Settings\Dustin\Desktop\Seahawks.jpg -> [2009/08/06 16:37:36 | 00,247,865 | —- | M] ()
mswebdvd.dll -> C:\WINDOWS\System32\mswebdvd.dll -> [2009/08/05 03:01:48 | 00,204,800 | —- | M] (Microsoft Corporation)
mswebdvd.dll -> C:\WINDOWS\System32\dllcache\mswebdvd.dll -> [2009/08/05 03:01:48 | 00,204,800 | —- | M] (Microsoft Corporation)
MRT.exe -> C:\WINDOWS\System32\MRT.exe -> [2009/07/29 18:49:14 | 24,281,536 | —- | M] (Microsoft Corporation)
dhtmled.ocx -> C:\WINDOWS\System32\dllcache\dhtmled.ocx -> [2009/07/27 16:27:12 | 00,128,512 | —- | M] (Microsoft Corporation)
ExchangePerflog_8484fa314873542ecfcccd43.dat -> C:\Documents and Settings\Dustin\Local Settings\Temp\ExchangePerflog_8484fa314873542ecfcccd43.dat -> [2008/10/06 10:09:01 | 00,131,336 | —- | M] ()
index.dat -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2008/10/05 21:35:46 | 00,049,152 | —- | M] ()
index.dat -> C:\WINDOWS\Temp\History\History.IE5\index.dat -> [2008/10/05 21:35:46 | 00,032,768 | —- | M] ()
index.dat -> C:\WINDOWS\Temp\Cookies\index.dat -> [2008/10/05 21:35:46 | 00,016,384 | —- | M] ()
NeoterisSetupApp.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\Juniper Networks\setup\NeoterisSetupApp.exe -> [2008/08/26 16:54:48 | 00,050,552 | RHS- | M] ()
FTIS200822.EXE -> C:\Documents and Settings\Dustin\Local Settings\Temp\Updates\FTIS200822.EXE -> [2008/07/16 12:15:32 | 02,994,331 | —- | M] ()
SMSetup.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\SEA35\SMSetup.exe -> [2008/06/30 07:19:17 | 00,099,680 | —- | M] (Smith Micro Software, Inc.)
SunWin32FunctionCalls_754447.dll -> C:\Documents and Settings\Dustin\Local Settings\Temp\SunWin32FunctionCalls_754447.dll -> [2008/06/16 11:06:09 | 00,061,440 | —- | M] (Centra Software, Inc.)
FTIS200821.EXE -> C:\Documents and Settings\Dustin\Local Settings\Temp\Updates\FTIS200821.EXE -> [2008/05/31 11:55:55 | 02,059,956 | —- | M] ()
_WUTL95.DLL -> C:\WINDOWS\Temp\_WUTL95.DLL -> [2008/05/06 15:08:26 | 00,036,864 | —- | M] (InstallShield Corporation, Inc.)
iTunesSetupAdmin[1].exe -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\PU926I5W\iTunesSetupAdmin[1].exe -> [2008/04/21 17:04:06 | 00,075,048 | —- | M] (Apple Inc.)
FTIS200811.EXE -> C:\Documents and Settings\Dustin\Local Settings\Temp\Updates\FTIS200811.EXE -> [2008/03/12 11:36:46 | 04,396,006 | —- | M] ()
iTunesSetupAdmin[1].exe -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\IMC15QXS\iTunesSetupAdmin[1].exe -> [2008/03/10 17:03:38 | 00,075,048 | —- | M] (Apple Inc.)
g2a_hook.dll -> C:\Documents and Settings\Dustin\Local Settings\Temp\~CL151.tmp\g2a_hook.dll -> [2008/03/10 14:49:31 | 00,010,752 | —- | M] (Citrix Online)
InstallRegister.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\InstallRegister.exe -> [2008/02/07 12:39:58 | 00,013,824 | —- | M] ()
hhcolreg.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\hhcolreg.dat -> [2008/01/14 17:26:56 | 00,008,132 | —- | M] ()
opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Office\Data\opa11.dat -> [2007/09/07 06:44:11 | 00,008,556 | —- | M] ()
data.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Office\Data\data.dat -> [2007/08/21 08:33:29 | 00,001,372 | —- | M] ()
521538c.DLL -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\521538c.DLL -> [2005/04/13 09:31:44 | 00,086,016 | —- | M] ()
FTSLmntr.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\FTSLmntr.exe -> [2004/03/26 11:01:24 | 00,036,864 | —- | M] ()
ylpgscat.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\ylpgscat.dat -> [2003/06/18 11:00:00 | 12,283,223 | —- | M] ()
college.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\college.dat -> [2003/06/18 11:00:00 | 00,327,746 | —- | M] ()
about.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\about.dat -> [2003/06/18 11:00:00 | 00,001,528 | —- | M] ()
moreinfo.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\moreinfo.dat -> [2003/06/18 11:00:00 | 00,000,102 | —- | M] ()
FTSL.dll -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\FTSL.dll -> [2002/02/20 11:32:48 | 00,061,440 | —- | M] ()
FTSLCtrlPnl.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\FTSLCtrlPnl.exe -> [2001/11/02 11:35:12 | 00,045,056 | —- | M] ()
MsiZap.Exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\MsiZap.Exe -> [2001/08/17 10:58:46 | 00,069,632 | —- | M] (Microsoft Corporation)
ISUninst.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\ISUninst.exe -> [1998/10/29 14:45:06 | 00,306,688 | —- | M] (InstallShield Software Corporation)
_ISDel.exe -> C:\Documents and Settings\Dustin\Local Settings\Temp\WZS24F.tmp\_ISDel.exe -> [1998/10/27 12:06:48 | 00,027,648 | —- | M] (InstallShield Software Corporation)
_Setup.dll -> C:\Documents and Settings\Dustin\Local Settings\Temp\WZS24F.tmp\_Setup.dll -> [1998/09/29 15:34:56 | 00,034,816 | —- | M] (InstallShield Software Corporation)
521537c.DLL -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\521537c.DLL -> [1998/09/22 17:05:48 | 00,129,536 | —- | M] (InstallShield Software Corporation)
Ctl3d32.dll -> C:\Documents and Settings\Dustin\Local Settings\Temp\_ISTMP3.DIR\_ISTMP0.DIR\Ctl3d32.dll -> [1995/07/13 16:46:26 | 00,027,136 | —- | M] (Microsoft Corporation)
[File - Lop Check]
Application Data -> C:\Documents and Settings\Administrator\Application Data -> [2007/08/14 18:07:03 | 00,000,000 | RH-D | M]
New York Life -> C:\Documents and Settings\Administrator\Application Data\New York Life -> [2007/08/21 13:05:37 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\All Users\Application Data -> [2009/08/19 07:58:08 | 00,000,000 | RH-D | M]
{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> [2009/04/28 06:59:31 | 00,000,000 | —D | M]
19876094 -> C:\Documents and Settings\All Users\Application Data\19876094 -> [2009/08/19 07:58:13 | 00,000,000 | —D | M]
ACASystems -> C:\Documents and Settings\All Users\Application Data\ACASystems -> [2007/12/03 12:46:30 | 00,000,000 | —D | M]
Azureus -> C:\Documents and Settings\All Users\Application Data\Azureus -> [2007/08/23 05:50:14 | 00,000,000 | —D | M]
CyberLink -> C:\Documents and Settings\All Users\Application Data\CyberLink -> [2007/11/05 07:32:24 | 00,000,000 | —D | M]
Dell -> C:\Documents and Settings\All Users\Application Data\Dell -> [2007/08/14 18:10:57 | 00,000,000 | —D | M]
Grisoft -> C:\Documents and Settings\All Users\Application Data\Grisoft -> [2007/08/24 14:58:26 | 00,000,000 | —D | M]
Juniper Networks -> C:\Documents and Settings\All Users\Application Data\Juniper Networks -> [2008/12/08 08:38:23 | 00,000,000 | —D | M]
ListGrabber Standard 2008 -> C:\Documents and Settings\All Users\Application Data\ListGrabber Standard 2008 -> [2007/12/28 12:55:38 | 00,000,000 | —D | M]
New York Life -> C:\Documents and Settings\All Users\Application Data\New York Life -> [2007/08/21 13:05:37 | 00,000,000 | —D | M]
SBSI -> C:\Documents and Settings\All Users\Application Data\SBSI -> [2004/08/11 16:25:52 | 00,000,000 | —D | M]
Wave Systems Corp -> C:\Documents and Settings\All Users\Application Data\Wave Systems Corp -> [2007/08/23 05:40:31 | 00,000,000 | —D | M]
WinZip -> C:\Documents and Settings\All Users\Application Data\WinZip -> [2007/09/26 17:08:10 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\Default User\Application Data -> [2008/06/23 10:49:56 | 00,000,000 | RH-D | M]
New York Life -> C:\Documents and Settings\Default User\Application Data\New York Life -> [2007/08/21 13:05:37 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\Dustin\Application Data -> [2009/08/10 09:00:29 | 00,000,000 | RH-D | M]
1&1 -> C:\Documents and Settings\Dustin\Application Data\1&1 -> [2008/03/01 16:08:26 | 00,000,000 | —D | M]
ACASystems -> C:\Documents and Settings\Dustin\Application Data\ACASystems -> [2007/12/03 12:46:30 | 00,000,000 | —D | M]
Azureus -> C:\Documents and Settings\Dustin\Application Data\Azureus -> [2007/08/23 17:08:21 | 00,000,000 | —D | M]
Centra -> C:\Documents and Settings\Dustin\Application Data\Centra -> [2008/05/12 10:19:38 | 00,000,000 | —D | M]
CyberLink -> C:\Documents and Settings\Dustin\Application Data\CyberLink -> [2007/11/05 07:32:31 | 00,000,000 | —D | M]
Dell -> C:\Documents and Settings\Dustin\Application Data\Dell -> [2007/08/20 14:48:38 | 00,000,000 | —D | M]
dvdcss -> C:\Documents and Settings\Dustin\Application Data\dvdcss -> [2008/03/12 13:07:20 | 00,000,000 | —D | M]
EndNote -> C:\Documents and Settings\Dustin\Application Data\EndNote -> [2009/06/26 06:38:02 | 00,000,000 | —D | M]
eRoom -> C:\Documents and Settings\Dustin\Application Data\eRoom -> [2007/12/06 10:10:49 | 00,000,000 | —D | M]
G-Lock Software -> C:\Documents and Settings\Dustin\Application Data\G-Lock Software -> [2007/09/12 12:24:24 | 00,000,000 | —D | M]
Grisoft -> C:\Documents and Settings\Dustin\Application Data\Grisoft -> [2007/08/24 14:58:47 | 00,000,000 | —D | M]
InterVideo -> C:\Documents and Settings\Dustin\Application Data\InterVideo -> [2008/03/12 12:52:03 | 00,000,000 | —D | M]
Juniper Networks -> C:\Documents and Settings\Dustin\Application Data\Juniper Networks -> [2009/08/08 09:14:13 | 00,000,000 | —D | M]
Move Networks -> C:\Documents and Settings\Dustin\Application Data\Move Networks -> [2009/05/07 05:19:58 | 00,000,000 | —D | M]
Netscape -> C:\Documents and Settings\Dustin\Application Data\Netscape -> [2007/10/25 07:18:16 | 00,000,000 | —D | M]
New York Life -> C:\Documents and Settings\Dustin\Application Data\New York Life -> [2007/08/21 13:05:37 | 00,000,000 | —D | M]
Saba -> C:\Documents and Settings\Dustin\Application Data\Saba -> [2008/05/12 10:20:14 | 00,000,000 | —D | M]
Thunderbird -> C:\Documents and Settings\Dustin\Application Data\Thunderbird -> [2008/03/15 09:23:34 | 00,000,000 | —D | M]
Visible Path -> C:\Documents and Settings\Dustin\Application Data\Visible Path -> [2009/08/16 10:27:02 | 00,000,000 | —D | M]
Wave Systems Corp -> C:\Documents and Settings\Dustin\Application Data\Wave Systems Corp -> [2009/08/21 09:39:21 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\LocalService\Application Data -> [2008/02/05 18:22:41 | 00,000,000 | —D | M]
New York Life -> C:\Documents and Settings\LocalService\Application Data\New York Life -> [2007/08/21 13:05:37 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\NetworkService\Application Data -> [2004/08/11 16:20:16 | 00,000,000 | —D | M]
New York Life -> C:\Documents and Settings\NetworkService\Application Data\New York Life -> [2007/08/21 13:05:37 | 00,000,000 | —D | M]
C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2009/08/21 09:25:53 | 00,000,000 | –SD | M]
AppleSoftwareUpdate.job -> C:\WINDOWS\Tasks\AppleSoftwareUpdate.job -> [2009/07/15 22:26:05 | 00,000,284 | —- | M] ()
desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2004/08/04 04:00:00 | 00,000,065 | RH– | M] ()
SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2009/08/19 08:38:31 | 00,000,006 | -H– | M] ()
{BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job -> [2009/08/21 09:25:57 | 00,000,282 | -H– | M] ()
[File - Purity Scan]
< End of report >
HOWEVER - When I ran the SysProt toolkit it caused my computer to crash.. blue screen of death… that said:
Problem deteced…
DRIVER_IRQL_NOT_LESS_OR_EQUAL
After I rebooted I was able to get this log from the sysprot folder, hope it has everything you need… let me know hoe to proceed. Thanks!!
SysProt AntiRootkit v1.0.1.0
by swatkat
********************************************************************************
**********
********************************************************************************
**********
Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No
Name: System
PID: 4
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\smss.exe
PID: 796
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\csrss.exe
PID: 852
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\winlogon.exe
PID: 876
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 920
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\lsass.exe
PID: 932
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1100
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1188
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1256
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1380
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1512
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PID: 1776
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
PID: 1812
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\WLTRYSVC.EXE
PID: 1828
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\BCMWLTRY.EXE
PID: 1848
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\spoolsv.exe
PID: 1896
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\scardsvr.exe
PID: 200
Hidden: No
Window Visible: No
Name: C:\WINDOWS\explorer.exe
PID: 196
Hidden: No
Window Visible: No
Name: C:\Program Files\Apoint\Apoint.exe
PID: 692
Hidden: No
Window Visible: No
Name: C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
PID: 700
Hidden: No
Window Visible: No
Name: C:\Program Files\WinMagic\SecureDoc-NT\SDPin.exe
PID: 708
Hidden: No
Window Visible: No
Name: C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PID: 716
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PID: 728
Hidden: No
Window Visible: No
Name: C:\PROGRA~1\SYMANT~1\VPTray.exe
PID: 740
Hidden: No
Window Visible: No
Name: C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
PID: 748
Hidden: No
Window Visible: No
Name: C:\Program Files\iTunes\iTunesHelper.exe
PID: 1060
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ctfmon.exe
PID: 376
Hidden: No
Window Visible: No
Name: C:\Program Files\Messenger\msmsgs.exe
PID: 432
Hidden: No
Window Visible: No
Name: C:\Program Files\Microsoft ActiveSync\wcescomm.exe
PID: 468
Hidden: No
Window Visible: No
Name: C:\Program Files\Apoint\hidfind.exe
PID: 560
Hidden: No
Window Visible: No
Name: C:\Program Files\Digital Line Detect\DLG.exe
PID: 640
Hidden: No
Window Visible: No
Name: C:\Program Files\Apple Computer\DVD@ccess\DVDAccess.exe
PID: 1388
Hidden: No
Window Visible: No
Name: C:\Program Files\Apoint\ApntEx.exe
PID: 1408
Hidden: No
Window Visible: No
Name: C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
PID: 1672
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1680
Hidden: No
Window Visible: No
Name: C:\PROGRA~1\MICROS~3\rapimgr.exe
PID: 1744
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PID: 2052
Hidden: No
Window Visible: No
Name: C:\Program Files\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
PID: 2116
Hidden: No
Window Visible: No
Name: C:\Program Files\Bonjour\mDNSResponder.exe
PID: 2328
Hidden: No
Window Visible: No
Name: C:\Program Files\Wave Systems Corp\Common\DataServer.exe
PID: 2384
Hidden: No
Window Visible: No
Name: C:\Program Files\Symantec AntiVirus\DefWatch.exe
PID: 2604
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PID: 2664
Hidden: No
Window Visible: No
Name: C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PID: 2896
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 2944
Hidden: No
Window Visible: No
Name: C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
PID: 2968
Hidden: No
Window Visible: No
Name: C:\Program Files\iPod\bin\iPodService.exe
PID: 3360
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wbem\wmiprvse.exe
PID: 3824
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\alg.exe
PID: 3912
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PID: 3996
Hidden: No
Window Visible: No
Name: C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
PID: 664
Hidden: No
Window Visible: No
Name: C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe
PID: 356
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ctfmon.exe
PID: 2008
Hidden: No
Window Visible: No
Name: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PID: 388
Hidden: No
Window Visible: No
Name: C:\DOCUME~1\Dustin\LOCALS~1\Temp\a.exe
PID: 3800
Hidden: No
Window Visible: No
Name: C:\Documents and Settings\Dustin\Desktop\temp222\SysProt\SysProt.exe
PID: 2260
Hidden: No
Window Visible: Yes
********************************************************************************
**********
*****************************************************