SgtSchenk
Topic Starter
My computer has been running slowly and having trouble starting up properly. Every time run my virus scan it comes up with the same virus three times-upgrade.exe-and it just keeps happening. I have been trying to find a way to get rid of it for weeks.I would appreciate help removing this virus.
The OTL Report is:
OTL logfile created on: 10/20/2010 9:27:35 PM - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,023.00 Mb Total Physical Memory | 316.00 Mb Available Physical Memory | 31.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 9.90 Gb Free Space | 13.28% Space Free | Partition Type: NTFS
Computer Name: USER-WSDRDFVS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\User\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
PRC - C:\Program Files\Prevx\prevx.exe (Prevx)
PRC - C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\GamersFirst\LIVE!\Live.exe (GamersFirst)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\pdfforge Toolbar\SearchSettings.exe (Spigot, Inc.)
PRC - C:\Program Files\Lexmark 2600 Series\ezprint.exe (Lexmark International Inc.)
PRC - C:\Program Files\Lexmark 2600 Series\lxdnmon.exe ()
PRC - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe (Brother Industries, Ltd.)
PRC - C:\WINDOWS\system32\lxdncoms.exe ( )
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnserv.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Brother\Brmfcmon\BrMfimon.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Lexmark 5300 Series\lxdkmon.exe ()
PRC - C:\WINDOWS\system32\lxdkcoms.exe ( )
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lexmark 5300 Series\lxdkamon.exe ()
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\HPQ\Quick Launch Buttons\eabservr.exe (Hewlett-Packard )
PRC - C:\Program Files\Common Files\AOL\ACS\AOLDial.exe (America Online, Inc)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\Program Files\Hewlett-Packard\HP Mobile Printing\HPBMOBIL.EXE (Hewlett-Packard Company)
PRC - C:\Program Files\Compaq\Compaq Management Agents\cpqWebDmi\Webdmi.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Compaq\Compaq Management Agents\Cpqdmi.exe (Compaq Computer Corporation)
PRC - C:\Program Files\Compaq\Compaq Management Agents\Chkadmin.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Compaq\Compaq Management Agents\Cpqalert.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\cpqdiag\CPQDFWAG.EXE (Hewlett-Packard)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe (Intel)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\User\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\SynTPFcs.dll (Synaptics, Inc.)
========== Win32 Services (SafeList) ==========
SRV - (SeekappSrch Service) – C:\Documents and Settings\All Users\Application Data\SeekappSrch\seekapp199.exe File not found
SRV - (MyWebSearchService) – C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe File not found
SRV - (CSIScanner) – C:\Program Files\Prevx\prevx.exe (Prevx)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (lxdn_device) – C:\WINDOWS\System32\lxdncoms.exe ( )
SRV - (lxdnCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdnserv.exe ()
SRV - (lxdk_device) – C:\WINDOWS\System32\lxdkcoms.exe ( )
SRV - (lxdkCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdkserv.exe ()
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
SRV - (cpqWebDmi) – C:\Program Files\Compaq\Compaq Management Agents\cpqWebDmi\Webdmi.exe (Hewlett-Packard Company)
SRV - (cpqdmi) – C:\Program Files\Compaq\Compaq Management Agents\Cpqdmi.exe (Compaq Computer Corporation)
SRV - (CPQALERT) – C:\Program Files\Compaq\Compaq Management Agents\Cpqalert.exe (Hewlett-Packard Company)
SRV - (DfwWebAgent) – C:\WINDOWS\cpqdiag\CPQDFWAG.EXE (Hewlett-Packard)
SRV - (SoundMAX Agent Service (default)) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (WIN32SL) – C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe (Intel)
========== Driver Services (SafeList) ==========
DRV - (XDva342) – C:\WINDOWS\System32\XDva342.sys File not found
DRV - (XDva317) – C:\WINDOWS\System32\XDva317.sys File not found
DRV - (wacommousefilter) – C:\WINDOWS\System32\DRIVERS\wacommousefilter.sys File not found
DRV - (EagleNT) – C:\WINDOWS\System32\drivers\EagleNT.sys File not found
DRV - (pxscan) – C:\WINDOWS\System32\drivers\pxscan.sys (Prevx)
DRV - (pxkbf) – C:\WINDOWS\system32\drivers\pxkbf.sys (Prevx)
DRV - (pxrts) – C:\WINDOWS\system32\drivers\pxrts.sys (Prevx)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101015.007\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101015.007\NAVENG.SYS (Symantec Corporation)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (WacomVKHid) – C:\WINDOWS\system32\drivers\WacomVKHid.sys (Wacom Technology)
DRV - (w29n51) Intel® – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (PCX500) – C:\WINDOWS\system32\drivers\pcx500.sys (Cisco Systems)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (eabfiltr) – C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Company)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (CONAN) – C:\WINDOWS\system32\drivers\o2mmb.sys (O2 Micro )
DRV - (MbxStby) – C:\WINDOWS\system32\drivers\MbxStby.sys (O2 Micro)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (eabusb) – C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Company)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (ClntMgmt) – C:\WINDOWS\system32\drivers\Clntmgmt.sys (Hewlett-Packard)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (cpqdfw) – C:\WINDOWS\system32\drivers\Cpqdfw.sys ()
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid;=CT2138729
IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:4.0.53.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {4548ECB8-DA60-439A-A00D-5C893F8E1F9A}:1.0
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:[removed]
FF - prefs.js..extensions.enabledItems: {586bd060-22d6-11de-8c30-0800200c9a66}:3.6
FF - prefs.js..keyword.URL: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZUfox000&fl;=0&ptb;=0vDY5oRLBakyJGGtj5iWLA&url;=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st;=kwd&searchfor;="
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\MyWebSearch\bar\firefox\
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/12 20:07:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/19 15:44:27 | 000,000,000 | —D | M]
[2009/12/21 16:27:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2010/08/10 12:56:56 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions
[2009/12/21 16:29:20 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/17 19:37:49 | 000,000,000 | —D | M] (Revelation) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}
[2010/05/18 15:19:01 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/05/22 19:02:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\[removed]
[2010/01/17 19:37:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}\chrome\mac\browser\extensions
[2010/01/17 19:37:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}\chrome\mac\mozapps\extensions
[2010/01/17 19:37:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}\chrome\win\browser\extensions
[2010/01/17 19:37:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}\chrome\win\mozapps\extensions
[2010/01/17 18:17:37 | 000,009,941 | —- | M] () – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\searchplugins\mywebsearch.xml
[2010/08/10 12:56:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/18 11:39:42 | 000,000,000 | —D | M] (Seekapp) – C:\Program Files\Mozilla Firefox\extensions\{4548ECB8-DA60-439A-A00D-5C893F8E1F9A}
[2009/11/09 21:30:56 | 000,189,592 | —- | M] (MGame) – C:\Program Files\Mozilla Firefox\plugins\NPMFireLauncher.dll
[2009/12/21 16:27:04 | 000,002,383 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\seekapp167.xml
[2010/01/25 07:51:18 | 000,002,383 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\seekapp171.xml
[2010/02/01 11:19:26 | 000,002,383 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\seekapp173.xml
[2010/03/11 16:16:51 | 000,002,383 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\seekapp177.xml
O1 HOSTS File: ([2004/08/04 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SafeOnline BHO) - {69D72956-317C-44bd-B369-8E44D4EF9801} - C:\WINDOWS\system32\PxSecure.dll (Prevx)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll (GreenTree Applications, Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll File not found
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll (GreenTree Applications, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe (America Online, Inc)
O4 - HKLM..\Run: [ATIModeChange] C:\WINDOWS\System32\Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [ChkAdmin] C:\Program Files\Compaq\Compaq Management Agents\Chkadmin.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe (Hewlett-Packard )
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark 2600 Series\ezprint.exe (Lexmark International Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Lexmark 5300 Series Fax Server] C:\Program Files\Lexmark 5300 Series\fm3032.exe ()
O4 - HKLM..\Run: [lxdkamon] C:\Program Files\Lexmark 5300 Series\lxdkamon.exe ()
O4 - HKLM..\Run: [lxdkmon.exe] C:\Program Files\Lexmark 5300 Series\lxdkmon.exe ()
O4 - HKLM..\Run: [lxdnmon.exe] C:\Program Files\Lexmark 2600 Series\lxdnmon.exe ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe File not found
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O4 - HKCU..\Run: [Adobe Update Service] C:\WINDOWS\services.exe File not found
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [HP Mobile Printing] C:\Program Files\Hewlett-Packard\HP Mobile Printing\HPBMOBIL.EXE (Hewlett-Packard Company)
O4 - HKCU..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKLM..\RunServices: [CPQDFWAG] C:\WINDOWS\cpqdiag\CPQDFWAG.EXE (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk = C:\Program Files\GamersFirst\LIVE!\Live.exe (GamersFirst)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O9 - Extra Button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll File not found
O9 - Extra 'Tools' menuitem : AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: tenderfoot.com ([]http in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1148139928901 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1148139915952 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\My Documents\My Pictures\Flight Simulator X Demo Files\2009-10-27_20-27-3-834.BMP
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\My Documents\My Pictures\Flight Simulator X Demo Files\2009-10-27_20-27-3-834.BMP
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/05/19 22:08:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{07b9a270-4362-11df-8fbb-00038a000015}\Shell\AutoRun\command - "" = E:\RECYCLER\s-124-52-632-236-125-2632636\autorun.exe – File not found
O33 - MountPoints2\{07b9a270-4362-11df-8fbb-00038a000015}\Shell\Explore\command - "" = E:\RECYCLER\s-124-52-632-236-125-2632636\autorun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - xvidvfw.dll File not found
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/10/18 19:44:08 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\cBA APPLICATION_files
[2010/10/16 11:22:45 | 000,070,192 | —- | C] (Prevx) – C:\WINDOWS\System32\PxSecure.dll
[2010/10/16 11:22:44 | 000,074,624 | —- | C] (Prevx) – C:\WINDOWS\System32\drivers\pxrts.sys
[2010/10/16 11:22:44 | 000,030,320 | —- | C] (Prevx) – C:\WINDOWS\System32\drivers\pxscan.sys
[2010/10/16 11:22:43 | 000,024,400 | —- | C] (Prevx) – C:\WINDOWS\System32\drivers\pxkbf.sys
[2010/10/16 11:22:42 | 000,000,000 | —D | C] – C:\Program Files\Prevx
[2010/10/16 11:22:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PrevxCSI
[2010/09/24 18:41:31 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\Stuff i need to save
[2010/09/21 15:15:17 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2009/09/25 16:34:12 | 000,434,176 | —- | C] ( ) – C:\WINDOWS\System32\lxdkhcp.dll
[2009/05/21 20:34:09 | 001,101,824 | —- | C] ( ) – C:\WINDOWS\System32\lxdnserv.dll
[2009/05/21 20:34:09 | 000,843,776 | —- | C] ( ) – C:\WINDOWS\System32\lxdnusb1.dll
[2009/05/21 20:34:09 | 000,663,552 | —- | C] ( ) – C:\WINDOWS\System32\lxdnhbn3.dll
[2009/05/21 20:34:09 | 000,647,168 | —- | C] ( ) – C:\WINDOWS\System32\lxdnpmui.dll
[2009/05/21 20:34:09 | 000,569,344 | —- | C] ( ) – C:\WINDOWS\System32\lxdnlmpm.dll
[2009/05/21 20:34:09 | 000,438,272 | —- | C] ( ) – C:\WINDOWS\System32\LXDNhcp.dll
[2009/05/21 20:34:09 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxdninpa.dll
[2009/05/21 20:34:09 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdniesc.dll
[2009/05/21 20:34:09 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdnprox.dll
[2009/05/21 20:34:08 | 000,851,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdncomc.dll
[2009/05/21 20:34:08 | 000,376,832 | —- | C] ( ) – C:\WINDOWS\System32\lxdncomm.dll
[2007/05/17 10:11:04 | 000,647,168 | —- | C] ( ) – C:\WINDOWS\System32\lxdkpmui.dll
[2007/05/17 10:07:59 | 001,200,128 | —- | C] ( ) – C:\WINDOWS\System32\lxdkserv.dll
[2007/05/17 10:03:03 | 000,356,352 | —- | C] ( ) – C:\WINDOWS\System32\lxdkinpa.dll
[2007/05/17 10:02:58 | 000,565,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdklmpm.dll
[2007/05/17 10:02:41 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxdkcomm.dll
[2007/05/17 10:01:21 | 000,663,552 | —- | C] ( ) – C:\WINDOWS\System32\lxdkhbn3.dll
[2007/05/17 10:00:42 | 000,950,272 | —- | C] ( ) – C:\WINDOWS\System32\lxdkusb1.dll
[2007/05/17 10:00:29 | 000,860,160 | —- | C] ( ) – C:\WINDOWS\System32\lxdkcomc.dll
[2007/05/17 09:59:11 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdkprox.dll
[2007/05/17 09:57:01 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdkiesc.dll
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[24 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/10/20 21:11:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-688789844-1343024091-1003UA.job
[2010/10/20 18:14:54 | 000,070,192 | —- | M] (Prevx) – C:\WINDOWS\System32\PxSecure.dll
[2010/10/20 18:14:54 | 000,030,320 | —- | M] (Prevx) – C:\WINDOWS\System32\drivers\pxscan.sys
[2010/10/20 18:14:53 | 000,024,400 | —- | M] (Prevx) – C:\WINDOWS\System32\drivers\pxkbf.sys
[2010/10/20 18:10:41 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/20 18:09:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/20 18:09:30 | 1073,139,712 | -HS- | M] () – C:\hiberfil.sys
[2010/10/20 16:09:41 | 000,002,497 | —- | M] () – C:\Documents and Settings\User\Desktop\Microsoft Office Word 2003.lnk
[2010/10/20 15:12:18 | 000,002,277 | —- | M] () – C:\Documents and Settings\User\Desktop\Google Chrome.lnk
[2010/10/20 15:12:18 | 000,002,255 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/19 18:01:42 | 000,000,556 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for User.job
[2010/10/18 20:44:57 | 000,000,630 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Prevx 3.0.lnk
[2010/10/18 19:44:08 | 000,009,624 | —- | M] () – C:\Documents and Settings\User\Desktop\cBA APPLICATION.htm
[2010/10/16 11:52:51 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2010/10/16 11:22:44 | 000,074,624 | —- | M] (Prevx) – C:\WINDOWS\System32\drivers\pxrts.sys
[2010/10/16 11:22:29 | 000,000,047 | —- | M] () – C:\WINDOWS\wininit.ini
[2010/10/16 09:11:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-688789844-1343024091-1003Core.job
[2010/10/15 21:54:53 | 000,000,807 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk
[2010/10/15 21:54:53 | 000,000,779 | —- | M] () – C:\Documents and Settings\All Users\Desktop\GamersFirst LIVE!.lnk
[2010/10/12 19:55:54 | 000,000,786 | —- | M] () – C:\WINDOWS\Cpqdiag.ini
[2010/10/12 18:12:52 | 000,036,352 | —- | M] () – C:\Documents and Settings\User\My Documents\Doc1.doc
[2010/10/03 17:19:01 | 001,508,864 | —- | M] () – C:\Documents and Settings\User\My Documents\ole 1-3.doc
[2010/10/03 16:51:56 | 000,015,360 | —- | M] () – C:\Documents and Settings\User\My Documents\ole.xls
[2010/10/03 16:28:44 | 000,002,495 | —- | M] () – C:\Documents and Settings\User\Desktop\Microsoft Office Excel 2003.lnk
[2010/09/29 16:57:40 | 000,028,160 | —- | M] () – C:\Documents and Settings\User\My Documents\5 themes essay.doc
[2010/09/29 16:57:40 | 000,000,162 | -H– | M] () – C:\Documents and Settings\User\My Documents\~$themes essay.doc
[2010/09/24 18:23:17 | 000,000,637 | —- | M] () – C:\Shortcut to My Documents.lnk
[2010/09/21 15:54:19 | 000,134,144 | —- | M] () – C:\Documents and Settings\User\My Documents\logo.doc
[2010/09/21 15:54:19 | 000,000,162 | -H– | M] () – C:\Documents and Settings\User\My Documents\~$logo.doc
[2010/09/21 15:37:15 | 000,001,503 | —- | M] () – C:\Documents and Settings\User\Desktop\Paint (2).lnk
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[24 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/18 20:44:57 | 000,000,630 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Prevx 3.0.lnk
[2010/10/18 19:44:07 | 000,009,624 | —- | C] () – C:\Documents and Settings\User\Desktop\cBA APPLICATION.htm
[2010/10/16 11:22:29 | 000,000,047 | —- | C] () – C:\WINDOWS\wininit.ini
[2010/10/12 18:12:52 | 000,036,352 | —- | C] () – C:\Documents and Settings\User\My Documents\Doc1.doc
[2010/10/12 17:45:50 | 1073,139,712 | -HS- | C] () – C:\hiberfil.sys
[2010/10/03 17:19:00 | 001,508,864 | —- | C] () – C:\Documents and Settings\User\My Documents\ole 1-3.doc
[2010/10/03 16:51:56 | 000,015,360 | —- | C] () – C:\Documents and Settings\User\My Documents\ole.xls
[2010/09/29 16:57:40 | 000,000,162 | -H– | C] () – C:\Documents and Settings\User\My Documents\~$themes essay.doc
[2010/09/29 16:57:39 | 000,028,160 | —- | C] () – C:\Documents and Settings\User\My Documents\5 themes essay.doc
[2010/09/21 15:54:19 | 000,134,144 | —- | C] () – C:\Documents and Settings\User\My Documents\logo.doc
[2010/09/21 15:54:19 | 000,000,162 | -H– | C] () – C:\Documents and Settings\User\My Documents\~$logo.doc
[2010/09/21 15:37:15 | 000,001,503 | —- | C] () – C:\Documents and Settings\User\Desktop\Paint (2).lnk
[2010/06/28 09:09:31 | 000,000,000 | R— | C] () – C:\Documents and Settings\User\Application Data\KJcHb.txt
[2010/06/09 16:25:53 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/12/21 15:13:37 | 000,000,000 | —- | C] () – C:\WINDOWS\galaxy.ini
[2009/10/18 17:43:03 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2009/09/25 16:39:45 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\LXDKPMON.DLL
[2009/09/25 16:39:45 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\LXDKFXPU.DLL
[2009/09/25 16:39:25 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdkoem.dll
[2009/09/25 16:34:15 | 000,000,060 | —- | C] () – C:\WINDOWS\System32\lxdkrwrd.ini
[2009/09/25 16:34:13 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\lxdkinst.dll
[2009/09/25 16:32:44 | 000,348,160 | R— | C] () – C:\WINDOWS\System32\lxdkcoin.dll
[2009/08/26 16:10:28 | 000,138,056 | —- | C] () – C:\Documents and Settings\User\Application Data\PnkBstrK.sys
[2009/06/18 17:23:20 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\TEMP(3)
[2009/06/18 15:09:22 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\TEMP(2)
[2009/06/16 18:31:55 | 000,000,833 | —- | C] () – C:\WINDOWS\disney.ini
[2009/06/16 18:31:22 | 000,000,184 | —- | C] () – C:\WINDOWS\disneysy.ini
[2009/06/11 16:46:39 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2009/06/07 20:26:11 | 000,138,056 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/05/21 20:34:55 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdnvs.dll
[2009/05/21 20:34:54 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\lxdncoin.dll
[2009/05/21 20:34:28 | 000,782,336 | —- | C] () – C:\WINDOWS\System32\lxdndrs.dll
[2009/05/21 20:34:28 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\lxdncaps.dll
[2009/05/21 20:34:28 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdncnv4.dll
[2009/05/21 20:34:09 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\LXDNinst.dll
[2009/05/21 20:34:09 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdngrd.dll
[2009/05/18 19:40:25 | 000,000,243 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2009/05/18 19:40:25 | 000,000,094 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2009/05/18 19:40:10 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/05/18 19:40:10 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/05/18 19:39:21 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2009/05/18 19:39:21 | 000,000,086 | —- | C] () – C:\WINDOWS\Brfaxrx.ini
[2009/05/16 16:32:57 | 000,069,632 | R— | C] () – C:\WINDOWS\System32\xmltok.dll
[2009/05/16 16:32:57 | 000,036,864 | R— | C] () – C:\WINDOWS\System32\xmlparse.dll
[2008/04/08 20:36:00 | 000,037,376 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/06/06 04:25:45 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdkgrd.dll
[2007/05/22 13:22:21 | 000,692,224 | —- | C] () – C:\WINDOWS\System32\lxdkdrs.dll
[2007/05/22 06:10:00 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\lxdkcaps.dll
[2007/02/14 10:35:07 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdkcnv4.dll
[2006/07/31 21:53:18 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdkvs.dll
[2006/05/20 14:36:17 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2006/05/20 14:36:16 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2006/05/20 14:36:16 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2006/05/20 14:36:16 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2006/05/20 14:36:16 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2006/05/20 14:36:16 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2006/05/20 11:56:18 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2006/05/20 11:44:00 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/19 23:12:35 | 000,033,728 | —- | C] () – C:\WINDOWS\System32\drivers\cs_nt40.sys
[2006/05/19 23:11:54 | 000,001,582 | —- | C] () – C:\WINDOWS\ACT_CFG.INI
[2006/05/19 23:11:49 | 000,019,845 | —- | C] () – C:\WINDOWS\System32\drivers\Cpqdfw.sys
[2006/05/19 23:11:49 | 000,000,786 | —- | C] () – C:\WINDOWS\Cpqdiag.ini
[2006/05/19 23:06:20 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\SynTPCoI.dll
[2006/05/19 23:06:13 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\drivers\CPQRS.sys
[2006/05/19 14:57:18 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/09 18:13:31 | 000,831,488 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/08/09 18:13:31 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/08/09 18:12:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/05/17 14:18:28 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/04 08:00:00 | 000,013,576 | —- | C] () – C:\WINDOWS\System32\syscorecfg256.dll
[2003/12/02 18:55:14 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2003/01/07 18:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2009/09/25 16:39:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\5300 Series
[2009/06/18 17:32:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AA2DeployClient
[2010/01/17 19:15:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AA3DeployClient
[2009/10/12 09:54:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alibre Design
[2009/11/19 20:09:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2009/05/21 19:39:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2010/10/19 15:45:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/10/16 11:35:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PrevxCSI
[2010/10/12 19:52:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/10/18 16:46:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/05/17 19:57:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/07/08 15:19:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{51FC4C90-DF10-4D41-963E-DB3050C1267C}
[2009/09/23 18:31:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/08/01 14:31:37 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}
[2009/09/26 07:23:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\5300 Series
[2009/06/11 17:17:37 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Alibre Design
[2010/01/17 18:25:10 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\BitTorrent
[2009/06/11 16:52:13 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\CB Model Pro
[2010/10/20 21:39:51 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\DNA
[2009/10/14 17:38:03 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FOG Downloader
[2010/08/26 16:40:26 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\GetRightToGo
[2009/11/13 20:34:35 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\ICAClient
[2009/12/21 18:51:08 | 000,000,000 | -H-D | M] – C:\Documents and Settings\User\Application Data\ijjigame
[2009/05/28 16:07:37 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\InterVideo
[2009/05/17 06:19:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Leadertech
[2010/01/13 10:45:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Lexmark Productivity Studio
[2010/08/26 16:48:53 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Raptr
[2010/05/22 10:38:22 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Tenderfoot Games
[2010/07/29 15:52:23 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Unity
[2009/06/18 17:47:00 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\uTorrent
[2010/08/12 15:32:56 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\VBA-M
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/05/19 23:13:05 | 000,000,086 | —- | M] () – C:\ApInsTmp.log
[2006/05/19 22:08:15 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/05/19 23:07:32 | 000,000,192 | —- | M] () – C:\BcBtRmv.log
[2006/05/19 22:01:55 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2006/05/19 23:17:24 | 000,000,090 | —- | M] () – C:\chpst.log
[2006/05/19 22:08:15 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/07/28 20:38:11 | 000,000,081 | —- | M] () – C:\CTX.DAT
[2009/06/22 20:34:20 | 000,001,047 | —- | M] () – C:\error_log.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2010/10/20 18:09:30 | 1073,139,712 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2006/05/19 22:08:15 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/10/17 18:50:04 | 000,037,888 | —- | M] () – C:\JOURNAL.doc
[2006/05/19 22:08:15 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 08:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/10/20 18:09:28 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2009/08/15 22:39:00 | 000,000,204 | —- | M] () – C:\Plugins
[2006/05/19 23:15:19 | 000,000,161 | —- | M] () – C:\sedinst.log
[2006/05/19 23:15:18 | 000,000,189 | —- | M] () – C:\sedinst2.log
[2006/05/19 23:16:24 | 000,000,173 | —- | M] () – C:\setup.log
[2010/09/24 18:23:17 | 000,000,637 | —- | M] () – C:\Shortcut to My Documents.lnk
[2006/05/19 23:15:46 | 000,019,314 | —- | M] () – C:\SUNJAVA.log
[2010/08/26 16:52:53 | 000,003,072 | -HS- | M] () – C:\Thumbs.db
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/05/19 22:07:39 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/05/02 19:38:35 | 000,113,664 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdkdrpp.dll
[2008/02/26 22:05:40 | 000,115,200 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdndrpp.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/04/22 17:55:16 | 000,001,538 | -H– | M] () – C:\Documents and Settings\User\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/05/19 14:54:03 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/05/19 14:54:03 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/05/19 14:54:02 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2006/05/19 22:08:24 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/05/19 22:54:07 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/05/19 22:54:06 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-16 03:56:54
========== Alternate Data Streams ==========
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP(2):DFC5A2B2
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:522EA216
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP(3):DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 10/20/2010 9:27:35 PM - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,023.00 Mb Total Physical Memory | 316.00 Mb Available Physical Memory | 31.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 9.90 Gb Free Space | 13.28% Space Free | Partition Type: NTFS
Computer Name: USER-WSDRDFVS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
http [open] – C:\PROGRA~1\AMERIC~1.0\aol.exe -u"%1" File not found
https [open] – C:\PROGRA~1\AMERIC~1.0\aol.exe -u"%1" File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"54925:UDP" = 54925:UDP:*:Enabled:BrotherNetwork Scanner
"3420:TCP" = 3420:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface
"3093:TCP" = 3093:TCP:*:Enabled:Akamai NetSession Interface
"3350:TCP" = 3350:TCP:*:Enabled:Akamai NetSession Interface
"1041:TCP" = 1041:TCP:*:Enabled:Akamai NetSession Interface
"1044:TCP" = 1044:TCP:*:Enabled:Akamai NetSession Interface
"1043:TCP" = 1043:TCP:*:Enabled:Akamai NetSession Interface
"1490:TCP" = 1490:TCP:*:Enabled:Akamai NetSession Interface
"1040:TCP" = 1040:TCP:*:Enabled:Akamai NetSession Interface
"1345:TCP" = 1345:TCP:*:Enabled:Akamai NetSession Interface
"1399:TCP" = 1399:TCP:*:Enabled:Akamai NetSession Interface
"1595:TCP" = 1595:TCP:*:Enabled:Akamai NetSession Interface
"1045:TCP" = 1045:TCP:*:Enabled:Akamai NetSession Interface
"1220:TCP" = 1220:TCP:*:Enabled:Akamai NetSession Interface
"1579:TCP" = 1579:TCP:*:Enabled:Akamai NetSession Interface
"1818:TCP" = 1818:TCP:*:Enabled:Akamai NetSession Interface
"1042:TCP" = 1042:TCP:*:Enabled:Akamai NetSession Interface
"1142:TCP" = 1142:TCP:*:Enabled:Akamai NetSession Interface
"56625:TCP" = 56625:TCP:*:Enabled:Pando Media Booster
"56625:UDP" = 56625:UDP:*:Enabled:Pando Media Booster
"2087:TCP" = 2087:TCP:*:Enabled:Akamai NetSession Interface
"2326:TCP" = 2326:TCP:*:Enabled:Akamai NetSession Interface
"2604:TCP" = 2604:TCP:*:Enabled:Akamai NetSession Interface
"1039:TCP" = 1039:TCP:*:Enabled:Akamai NetSession Interface
"1051:TCP" = 1051:TCP:*:Enabled:Akamai NetSession Interface
"1197:TCP" = 1197:TCP:*:Enabled:Akamai NetSession Interface
"1070:TCP" = 1070:TCP:*:Enabled:Akamai NetSession Interface
"2180:TCP" = 2180:TCP:*:Enabled:Akamai NetSession Interface
"3373:TCP" = 3373:TCP:*:Enabled:Akamai NetSession Interface
"1398:TCP" = 1398:TCP:*:Enabled:Akamai NetSession Interface
"1577:TCP" = 1577:TCP:*:Enabled:Akamai NetSession Interface
"1050:TCP" = 1050:TCP:*:Enabled:Akamai NetSession Interface
"1333:TCP" = 1333:TCP:*:Enabled:Akamai NetSession Interface
"2822:TCP" = 2822:TCP:*:Enabled:Akamai NetSession Interface
"1440:TCP" = 1440:TCP:*:Enabled:Akamai NetSession Interface
"1502:TCP" = 1502:TCP:*:Enabled:Akamai NetSession Interface
"1053:TCP" = 1053:TCP:*:Enabled:Akamai NetSession Interface
"1088:TCP" = 1088:TCP:*:Enabled:Akamai NetSession Interface
"3267:TCP" = 3267:TCP:*:Enabled:Akamai NetSession Interface
"3472:TCP" = 3472:TCP:*:Enabled:Akamai NetSession Interface
"3574:TCP" = 3574:TCP:*:Enabled:Akamai NetSession Interface
"3643:TCP" = 3643:TCP:*:Enabled:Akamai NetSession Interface
"1184:TCP" = 1184:TCP:*:Enabled:Akamai NetSession Interface
"1330:TCP" = 1330:TCP:*:Enabled:Akamai NetSession Interface
"1574:TCP" = 1574:TCP:*:Enabled:Akamai NetSession Interface
"1779:TCP" = 1779:TCP:*:Enabled:Akamai NetSession Interface
"1681:TCP" = 1681:TCP:*:Enabled:Akamai NetSession Interface
"2768:TCP" = 2768:TCP:*:Enabled:Akamai NetSession Interface
"1377:TCP" = 1377:TCP:*:Enabled:Akamai NetSession Interface
"1821:TCP" = 1821:TCP:*:Enabled:Akamai NetSession Interface
"1919:TCP" = 1919:TCP:*:Enabled:Akamai NetSession Interface
"1260:TCP" = 1260:TCP:*:Enabled:Akamai NetSession Interface
"1754:TCP" = 1754:TCP:*:Enabled:Akamai NetSession Interface
"1762:TCP" = 1762:TCP:*:Enabled:Akamai NetSession Interface
"1177:TCP" = 1177:TCP:*:Enabled:Akamai NetSession Interface
"1225:TCP" = 1225:TCP:*:Enabled:Akamai NetSession Interface
"1149:TCP" = 1149:TCP:*:Enabled:Akamai NetSession Interface
"3016:TCP" = 3016:TCP:*:Enabled:Akamai NetSession Interface
"3028:TCP" = 3028:TCP:*:Enabled:Akamai NetSession Interface
"1123:TCP" = 1123:TCP:*:Enabled:Akamai NetSession Interface
"1160:TCP" = 1160:TCP:*:Enabled:Akamai NetSession Interface
"2508:TCP" = 2508:TCP:*:Enabled:Akamai NetSession Interface
"1110:TCP" = 1110:TCP:*:Enabled:Akamai NetSession Interface
"2122:TCP" = 2122:TCP:*:Enabled:Akamai NetSession Interface
"1261:TCP" = 1261:TCP:*:Enabled:Akamai NetSession Interface
"1325:TCP" = 1325:TCP:*:Enabled:Akamai NetSession Interface
"1111:TCP" = 1111:TCP:*:Enabled:Akamai NetSession Interface
"1649:TCP" = 1649:TCP:*:Enabled:Akamai NetSession Interface
"1678:TCP" = 1678:TCP:*:Enabled:Akamai NetSession Interface
"1707:TCP" = 1707:TCP:*:Enabled:Akamai NetSession Interface
"3812:TCP" = 3812:TCP:*:Enabled:Akamai NetSession Interface
"3840:TCP" = 3840:TCP:*:Enabled:Akamai NetSession Interface
"3876:TCP" = 3876:TCP:*:Enabled:Akamai NetSession Interface
"1116:TCP" = 1116:TCP:*:Enabled:Akamai NetSession Interface
"2584:TCP" = 2584:TCP:*:Enabled:Akamai NetSession Interface
"3145:TCP" = 3145:TCP:*:Enabled:Akamai NetSession Interface
"3710:TCP" = 3710:TCP:*:Enabled:Akamai NetSession Interface
"4001:TCP" = 4001:TCP:*:Enabled:Akamai NetSession Interface
"1254:TCP" = 1254:TCP:*:Enabled:Akamai NetSession Interface
"1393:TCP" = 1393:TCP:*:Enabled:Akamai NetSession Interface
"1167:TCP" = 1167:TCP:*:Enabled:Akamai NetSession Interface
"1164:TCP" = 1164:TCP:*:Enabled:Akamai NetSession Interface
"1208:TCP" = 1208:TCP:*:Enabled:Akamai NetSession Interface
"1452:TCP" = 1452:TCP:*:Enabled:Akamai NetSession Interface
"1156:TCP" = 1156:TCP:*:Enabled:Akamai NetSession Interface
"1673:TCP" = 1673:TCP:*:Enabled:Akamai NetSession Interface
"1755:TCP" = 1755:TCP:*:Enabled:Akamai NetSession Interface
"1987:TCP" = 1987:TCP:*:Enabled:Akamai NetSession Interface
"4203:TCP" = 4203:TCP:*:Enabled:Akamai NetSession Interface
"1355:TCP" = 1355:TCP:*:Enabled:Akamai NetSession Interface
"1544:TCP" = 1544:TCP:*:Enabled:Akamai NetSession Interface
"2683:TCP" = 2683:TCP:*:Enabled:Akamai NetSession Interface
"2689:TCP" = 2689:TCP:*:Enabled:Akamai NetSession Interface
"1539:TCP" = 1539:TCP:*:Enabled:Akamai NetSession Interface
"1547:TCP" = 1547:TCP:*:Enabled:Akamai NetSession Interface
"1581:TCP" = 1581:TCP:*:Enabled:Akamai NetSession Interface
"2411:TCP" = 2411:TCP:*:Enabled:Akamai NetSession Interface
"2490:TCP" = 2490:TCP:*:Enabled:Akamai NetSession Interface
"2902:TCP" = 2902:TCP:*:Enabled:Akamai NetSession Interface
"3715:TCP" = 3715:TCP:*:Enabled:Akamai NetSession Interface
"4116:TCP" = 4116:TCP:*:Enabled:Akamai NetSession Interface
"4140:TCP" = 4140:TCP:*:Enabled:Akamai NetSession Interface
"1311:TCP" = 1311:TCP:*:Enabled:Akamai NetSession Interface
"1777:TCP" = 1777:TCP:*:Enabled:Akamai NetSession Interface
"2602:TCP" = 2602:TCP:*:Enabled:Akamai NetSession Interface
"3825:TCP" = 3825:TCP:*:Enabled:Akamai NetSession Interface
"1774:TCP" = 1774:TCP:*:Enabled:Akamai NetSession Interface
"1840:TCP" = 1840:TCP:*:Enabled:Akamai NetSession Interface
"1873:TCP" = 1873:TCP:*:Enabled:Akamai NetSession Interface
"1904:TCP" = 1904:TCP:*:Enabled:Akamai NetSession Interface
"3256:TCP" = 3256:TCP:*:Enabled:Akamai NetSession Interface
"4831:TCP" = 4831:TCP:*:Enabled:Akamai NetSession Interface
"2870:TCP" = 2870:TCP:*:Enabled:Akamai NetSession Interface
"3264:TCP" = 3264:TCP:*:Enabled:Akamai NetSession Interface
"3865:TCP" = 3865:TCP:*:Enabled:Akamai NetSession Interface
"4003:TCP" = 4003:TCP:*:Enabled:Akamai NetSession Interface
"4079:TCP" = 4079:TCP:*:Enabled:Akamai NetSession Interface
"1105:TCP" = 1105:TCP:*:Enabled:Akamai NetSession Interface
"1704:TCP" = 1704:TCP:*:Enabled:Akamai NetSession Interface
"2043:TCP" = 2043:TCP:*:Enabled:Akamai NetSession Interface
"2098:TCP" = 2098:TCP:*:Enabled:Akamai NetSession Interface
"2507:TCP" = 2507:TCP:*:Enabled:Akamai NetSession Interface
"2880:TCP" = 2880:TCP:*:Enabled:Akamai NetSession Interface
"4487:TCP" = 4487:TCP:*:Enabled:Akamai NetSession Interface
"4922:TCP" = 4922:TCP:*:Enabled:Akamai NetSession Interface
"2921:TCP" = 2921:TCP:*:Enabled:Akamai NetSession Interface
"4735:TCP" = 4735:TCP:*:Enabled:Akamai NetSession Interface
"1617:TCP" = 1617:TCP:*:Enabled:Akamai NetSession Interface
"1397:TCP" = 1397:TCP:*:Enabled:Akamai NetSession Interface
"3978:TCP" = 3978:TCP:*:Enabled:Akamai NetSession Interface
"4151:TCP" = 4151:TCP:*:Enabled:Akamai NetSession Interface
"4379:TCP" = 4379:TCP:*:Enabled:Akamai NetSession Interface
"4666:TCP" = 4666:TCP:*:Enabled:Akamai NetSession Interface
"4052:TCP" = 4052:TCP:*:Enabled:Akamai NetSession Interface
"1200:TCP" = 1200:TCP:*:Enabled:Akamai NetSession Interface
"1276:TCP" = 1276:TCP:*:Enabled:Akamai NetSession Interface
"1381:TCP" = 1381:TCP:*:Enabled:Akamai NetSession Interface
"1423:TCP" = 1423:TCP:*:Enabled:Akamai NetSession Interface
"1654:TCP" = 1654:TCP:*:Enabled:Akamai NetSession Interface
"2802:TCP" = 2802:TCP:*:Enabled:Akamai NetSession Interface
"2840:TCP" = 2840:TCP:*:Enabled:Akamai NetSession Interface
"3099:TCP" = 3099:TCP:*:Enabled:Akamai NetSession Interface
"2130:TCP" = 2130:TCP:*:Enabled:Akamai NetSession Interface
"2244:TCP" = 2244:TCP:*:Enabled:Akamai NetSession Interface
"4890:TCP" = 4890:TCP:*:Enabled:Akamai NetSession Interface
"4901:TCP" = 4901:TCP:*:Enabled:Akamai NetSession Interface
"4937:TCP" = 4937:TCP:*:Enabled:Akamai NetSession Interface
"1293:TCP" = 1293:TCP:*:Enabled:Akamai NetSession Interface
"3201:TCP" = 3201:TCP:*:Enabled:Akamai NetSession Interface
"4100:TCP" = 4100:TCP:*:Enabled:Akamai NetSession Interface
"4135:TCP" = 4135:TCP:*:Enabled:Akamai NetSession Interface
"4939:TCP" = 4939:TCP:*:Enabled:Akamai NetSession Interface
"4993:TCP" = 4993:TCP:*:Enabled:Akamai NetSession Interface
"1550:TCP" = 1550:TCP:*:Enabled:Akamai NetSession Interface
"2201:TCP" = 2201:TCP:*:Enabled:Akamai NetSession Interface
"3946:TCP" = 3946:TCP:*:Enabled:Akamai NetSession Interface
"3984:TCP" = 3984:TCP:*:Enabled:Akamai NetSession Interface
"1362:TCP" = 1362:TCP:*:Enabled:Akamai NetSession Interface
"2280:TCP" = 2280:TCP:*:Enabled:Akamai NetSession Interface
"2932:TCP" = 2932:TCP:*:Enabled:Akamai NetSession Interface
"2991:TCP" = 2991:TCP:*:Enabled:Akamai NetSession Interface
"3754:TCP" = 3754:TCP:*:Enabled:Akamai NetSession Interface
"4324:TCP" = 4324:TCP:*:Enabled:Akamai NetSession Interface
"4369:TCP" = 4369:TCP:*:Enabled:Akamai NetSession Interface
"4826:TCP" = 4826:TCP:*:Enabled:Akamai NetSession Interface
"1978:TCP" = 1978:TCP:*:Enabled:Akamai NetSession Interface
"3763:TCP" = 3763:TCP:*:Enabled:Akamai NetSession Interface
"3096:TCP" = 3096:TCP:*:Enabled:Akamai NetSession Interface
"3161:TCP" = 3161:TCP:*:Enabled:Akamai NetSession Interface
"2015:TCP" = 2015:TCP:*:Enabled:Akamai NetSession Interface
"2967:TCP" = 2967:TCP:*:Enabled:Akamai NetSession Interface
"2973:TCP" = 2973:TCP:*:Enabled:Akamai NetSession Interface
"2993:TCP" = 2993:TCP:*:Enabled:Akamai NetSession Interface
"3003:TCP" = 3003:TCP:*:Enabled:Akamai NetSession Interface
"3024:TCP" = 3024:TCP:*:Enabled:Akamai NetSession Interface
"3630:TCP" = 3630:TCP:*:Enabled:Akamai NetSession Interface
"4967:TCP" = 4967:TCP:*:Enabled:Akamai NetSession Interface
"4974:TCP" = 4974:TCP:*:Enabled:Akamai NetSession Interface
"4998:TCP" = 4998:TCP:*:Enabled:Akamai NetSession Interface
"1192:TCP" = 1192:TCP:*:Enabled:Akamai NetSession Interface
"1213:TCP" = 1213:TCP:*:Enabled:Akamai NetSession Interface
"1429:TCP" = 1429:TCP:*:Enabled:Akamai NetSession Interface
"1441:TCP" = 1441:TCP:*:Enabled:Akamai NetSession Interface
"2324:TCP" = 2324:TCP:*:Enabled:Akamai NetSession Interface
"3537:TCP" = 3537:TCP:*:Enabled:Akamai NetSession Interface
"3555:TCP" = 3555:TCP:*:Enabled:Akamai NetSession Interface
"3595:TCP" = 3595:TCP:*:Enabled:Akamai NetSession Interface
"1921:TCP" = 1921:TCP:*:Enabled:Akamai NetSession Interface
"3706:TCP" = 3706:TCP:*:Enabled:Akamai NetSession Interface
"1824:TCP" = 1824:TCP:*:Enabled:Akamai NetSession Interface
"2805:TCP" = 2805:TCP:*:Enabled:Akamai NetSession Interface
"2862:TCP" = 2862:TCP:*:Enabled:Akamai NetSession Interface
"3991:TCP" = 3991:TCP:*:Enabled:Akamai NetSession Interface
"4039:TCP" = 4039:TCP:*:Enabled:Akamai NetSession Interface
"2394:TCP" = 2394:TCP:*:Enabled:Akamai NetSession Interface
"2681:TCP" = 2681:TCP:*:Enabled:Akamai NetSession Interface
"2187:TCP" = 2187:TCP:*:Enabled:Akamai NetSession Interface
"4846:TCP" = 4846:TCP:*:Enabled:Akamai NetSession Interface
"4852:TCP" = 4852:TCP:*:Enabled:Akamai NetSession Interface
"4896:TCP" = 4896:TCP:*:Enabled:Akamai NetSession Interface
"1203:TCP" = 1203:TCP:*:Enabled:Akamai NetSession Interface
"1743:TCP" = 1743:TCP:*:Enabled:Akamai NetSession Interface
"3079:TCP" = 3079:TCP:*:Enabled:Akamai NetSession Interface
"4014:TCP" = 4014:TCP:*:Enabled:Akamai NetSession Interface
"4248:TCP" = 4248:TCP:*:Enabled:Akamai NetSession Interface
"2784:TCP" = 2784:TCP:*:Enabled:Akamai NetSession Interface
"4716:TCP" = 4716:TCP:*:Enabled:Akamai NetSession Interface
"4751:TCP" = 4751:TCP:*:Enabled:Akamai NetSession Interface
"4788:TCP" = 4788:TCP:*:Enabled:Akamai NetSession Interface
"4823:TCP" = 4823:TCP:*:Enabled:Akamai NetSession Interface
"1250:TCP" = 1250:TCP:*:Enabled:Akamai NetSession Interface
"2539:TCP" = 2539:TCP:*:Enabled:Akamai NetSession Interface
"2895:TCP" = 2895:TCP:*:Enabled:Akamai NetSession Interface
"3892:TCP" = 3892:TCP:*:Enabled:Akamai NetSession Interface
"3920:TCP" = 3920:TCP:*:Enabled:Akamai NetSession Interface
"1175:TCP" = 1175:TCP:*:Enabled:Akamai NetSession Interface
"1242:TCP" = 1242:TCP:*:Enabled:Akamai NetSession Interface
"1784:TCP" = 1784:TCP:*:Enabled:Akamai NetSession Interface
"2579:TCP" = 2579:TCP:*:Enabled:Akamai NetSession Interface
"3174:TCP" = 3174:TCP:*:Enabled:Akamai NetSession Interface
"1445:TCP" = 1445:TCP:*:Enabled:Akamai NetSession Interface
"1384:TCP" = 1384:TCP:*:Enabled:Akamai NetSession Interface
"1426:TCP" = 1426:TCP:*:Enabled:Akamai NetSession Interface
"1725:TCP" = 1725:TCP:*:Enabled:Akamai NetSession Interface
"3596:TCP" = 3596:TCP:*:Enabled:Akamai NetSession Interface
"3611:TCP" = 3611:TCP:*:Enabled:Akamai NetSession Interface
"3642:TCP" = 3642:TCP:*:Enabled:Akamai NetSession Interface
"1047:TCP" = 1047:TCP:*:Enabled:Akamai NetSession Interface
"2317:TCP" = 2317:TCP:*:Enabled:Akamai NetSession Interface
"2372:TCP" = 2372:TCP:*:Enabled:Akamai NetSession Interface
"2406:TCP" = 2406:TCP:*:Enabled:Akamai NetSession Interface
"1298:TCP" = 1298:TCP:*:Enabled:Akamai NetSession Interface
"3249:TCP" = 3249:TCP:*:Enabled:Akamai NetSession Interface
"3285:TCP" = 3285:TCP:*:Enabled:Akamai NetSession Interface
"4820:TCP" = 4820:TCP:*:Enabled:Akamai NetSession Interface
"1623:TCP" = 1623:TCP:*:Enabled:Akamai NetSession Interface
"2008:TCP" = 2008:TCP:*:Enabled:Akamai NetSession Interface
"3098:TCP" = 3098:TCP:*:Enabled:Akamai NetSession Interface
"3795:TCP" = 3795:TCP:*:Enabled:Akamai NetSession Interface
"3807:TCP" = 3807:TCP:*:Enabled:Akamai NetSession Interface
"3759:TCP" = 3759:TCP:*:Enabled:Akamai NetSession Interface
"1271:TCP" = 1271:TCP:*:Enabled:Akamai NetSession Interface
"1785:TCP" = 1785:TCP:*:Enabled:Akamai NetSession Interface
"2312:TCP" = 2312:TCP:*:Enabled:Akamai NetSession Interface
"1168:TCP" = 1168:TCP:*:Enabled:Akamai NetSession Interface
"2361:TCP" = 2361:TCP:*:Enabled:Akamai NetSession Interface
"1899:TCP" = 1899:TCP:*:Enabled:Akamai NetSession Interface
"1989:TCP" = 1989:TCP:*:Enabled:Akamai NetSession Interface
"2545:TCP" = 2545:TCP:*:Enabled:Akamai NetSession Interface
"1813:TCP" = 1813:TCP:*:Enabled:Akamai NetSession Interface
"2504:TCP" = 2504:TCP:*:Enabled:Akamai NetSession Interface
"2642:TCP" = 2642:TCP:*:Enabled:Akamai NetSession Interface
"3033:TCP" = 3033:TCP:*:Enabled:Akamai NetSession Interface
"3634:TCP" = 3634:TCP:*:Enabled:Akamai NetSession Interface
"3768:TCP" = 3768:TCP:*:Enabled:Akamai NetSession Interface
"1991:TCP" = 1991:TCP:*:Enabled:Akamai NetSession Interface
"2066:TCP" = 2066:TCP:*:Enabled:Akamai NetSession Interface
"2095:TCP" = 2095:TCP:*:Enabled:Akamai NetSession Interface
"2456:TCP" = 2456:TCP:*:Enabled:Akamai NetSession Interface
"1449:TCP" = 1449:TCP:*:Enabled:Akamai NetSession Interface
"57014:TCP" = 57014:TCP:*:Enabled:Pando Media Booster
"57014:UDP" = 57014:UDP:*:Enabled:Pando Media Booster
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"57070:TCP" = 57070:TCP:*:Enabled:Pando Media Booster
"57070:UDP" = 57070:UDP:*:Enabled:Pando Media Booster
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe – File not found
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online, Inc)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – File not found
"C:\Program Files\Ubisoft\Splinter Cell Pandora Tomorrow\pandora.exe" = C:\Program Files\Ubisoft\Splinter Cell Pandora Tomorrow\pandora.exe:*:Enabled:pandora – File not found
"C:\Program Files\Ubisoft\Splinter Cell Pandora Tomorrow\online\System\shadowstrike_static_retail.exe" = C:\Program Files\Ubisoft\Splinter Cell Pandora Tomorrow\online\System\shadowstrike_static_retail.exe:*:Enabled:shadowstrike_static_retail – File not found
"C:\Program Files\Brother\Brmfl08b\FAXRX.exe" = C:\Program Files\Brother\Brmfl08b\FAXRX.exe:*:Enabled:FAXRX.EXE – ()
"C:\Documents and Settings\User\Local Settings\Application Data\Xenocode\ApplianceCaches\KumaClient.exe_v02D7169E\Native\STUBEXE\@PROGRAMFILES@\Kuma Games\Kuma.exe" = C:\Documents and Settings\User\Local Settings\Application Data\Xenocode\ApplianceCaches\KumaClient.exe_v02D7169E\Native\STUBEXE\@PROGRAMFILES@\Kuma Games\Kuma.exe:*:Enabled:Kuma – File not found
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe" = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager – (Nexon)
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe – File not found
"C:\Nexon\Combat Arms\NMService.exe" = C:\Nexon\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core – File not found
"C:\WINDOWS\system32\lxdncoms.exe" = C:\WINDOWS\system32\lxdncoms.exe:*:Enabled:Lexmark Communications System – ( )
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnpswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnpswx.exe:*:Enabled:Printer Status Window Interface – ()
"C:\Program Files\Lexmark 2600 Series\lxdnmon.exe" = C:\Program Files\Lexmark 2600 Series\lxdnmon.exe:*:Enabled:Printer Device Monitor – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnjswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnjswx.exe:*:Enabled:Job Status Window Interface – ()
"C:\Program Files\Atari\Deer Hunter 2005\DH2005.exe" = C:\Program Files\Atari\Deer Hunter 2005\DH2005.exe:*:Enabled:DH2005 – File not found
"C:\Program Files\USArmy\America's Army 2\System\ArmyOps.exe" = C:\Program Files\USArmy\America's Army 2\System\ArmyOps.exe:*:Enabled:ArmyOps – File not found
"C:\Games\NGD Studios\Regnum Online\LiveServer\ROClientGame.exe" = C:\Games\NGD Studios\Regnum Online\LiveServer\ROClientGame.exe:*:Enabled:RegnumOnline – File not found
"C:\Program Files\USArmy\America's Army 2\System\Server.exe" = C:\Program Files\USArmy\America's Army 2\System\Server.exe:*:Enabled:Server – File not found
"C:\Program Files\Softnyx\RakionIS\Bin\rakion.bin" = C:\Program Files\Softnyx\RakionIS\Bin\rakion.bin:*:Enabled:rakion – File not found
"C:\AeriaGames\12Sky\TwelveSky.exe" = C:\AeriaGames\12Sky\TwelveSky.exe:*:Disabled:TwelveSky – File not found
"C:\WINDOWS\system32\lxdkcoms.exe" = C:\WINDOWS\system32\lxdkcoms.exe:*:Enabled:Lexmark Communications System – ( )
"C:\Program Files\Lexmark 5300 Series\lxdkamon.exe" = C:\Program Files\Lexmark 5300 Series\lxdkamon.exe:*:Enabled:Lexmark Device Monitor – ()
"C:\Program Files\Lexmark 5300 Series\frun.exe" = C:\Program Files\Lexmark 5300 Series\frun.exe:*:Enabled:Lexmark Productivity Studio – ()
"C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe" = C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:*:Enabled:ABBYY FineReader – File not found
"C:\Program Files\Lexmark 5300 Series\LXDKFax.exe" = C:\Program Files\Lexmark 5300 Series\LXDKFax.exe:*:Enabled:Fax software – ()
"C:\Program Files\Lexmark 5300 Series\lxdkmon.exe" = C:\Program Files\Lexmark 5300 Series\lxdkmon.exe:*:Enabled:Printer Device Monitor – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkpswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkpswx.exe:*:Enabled:Printer Status Window Interface – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdktime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdktime.exe:*:Enabled:Lexmark Connect Time Executable – (Lexmark International, Inc.)
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkjswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkjswx.exe:*:Enabled:Job Status Window Interface – ()
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online, Inc)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – File not found
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdntime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdntime.exe:*:Enabled:Lexmark Connect Time Executable – (Lexmark International, Inc.)
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnwbgw.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnwbgw.exe:*:Enabled:Lexmark Web Gateway – ()
"C:\Program Files\Softnyx\WolfTeam\Wolfteam.bin" = C:\Program Files\Softnyx\WolfTeam\Wolfteam.bin:*:Enabled:WolfTeam – File not found
"C:\Alien Arena 7_32\crx.exe" = C:\Alien Arena 7_32\crx.exe:*:Enabled:crx – File not found
"C:\WINDOWS\Downloaded Program Files\ijjiOptimizer.exe" = C:\WINDOWS\Downloaded Program Files\ijjiOptimizer.exe:*:Enabled:ijjiOptimizer.exe – ()
"C:\ijji\ENGLISH\u_sf\soldierfront.exe" = C:\ijji\ENGLISH\u_sf\soldierfront.exe:*:Enabled:soldierfront – File not found
"C:\Program Files\ijji\ijji REACTOR\REACTOR.exe" = C:\Program Files\ijji\ijji REACTOR\REACTOR.exe:*:Enabled:Reactor Application – File not found
"C:\Program Files\Garena\Garena.exe" = C:\Program Files\Garena\Garena.exe:*:Enabled:Garena – File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Raptr\raptr.exe" = C:\Program Files\Raptr\raptr.exe:*:Enabled:Raptr Client – File not found
"C:\Program Files\Raptr\raptr_im.exe" = C:\Program Files\Raptr\raptr_im.exe:*:Enabled:Raptr IM – File not found
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – File not found
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – File not found
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*:Disabled:Combat Arms – File not found
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA – (BitTorrent, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{1881AE03-2BD4-11D4-86BF-00508B10AA88}" = Diagnostics for Windows
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1B602410-D983-4947-98FE-EE749073D15E}" = GamingHarbor Toolbar
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{388C130B-0079-46B4-A0D5-DC2DD7A89A7B}" = Citrix XenApp Plugin for Hosted Apps
"{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}" = Macromedia Flash MX
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{4CBD31CE-51DF-43C4-B3EC-7CCBAB0CD083}" = O2Micro MemoryCardBus Windows Driver
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
"{5C3DA2A1-03B2-44BD-B5AA-A44BD6E0C0C1}" = HP Integrated Wireless LAN W400-W500 Driver
"{5D97A4A7-C274-4B63-86D9-07A33435F505}" = InterVideo DVD Check
"{5E42E287-4CA5-4D59-931A-EE481817D073}" = arotkcursorset
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{71A470E1-27E7-424E-803A-F9C0D41968D3}" = Remote Diagnostics Enabling Agent
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7E20EFE6-E604-48C6-8B39-BA4742F2CDB4}" = Zune Desktop Theme
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{848AC794-8B81-440A-81AE-6474337DB527}" = Symantec AntiVirus
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D6D76A6-4328-49E8-97A7-531A74841DA5}" = Microsoft SQL Server 2008 Setup Support Files (English)
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8AC89BA-D8CB-4372-9743-1C54D23286B0}" = MSN Toolbar
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{B668CB7B-A9DF-43B6-8876-A373A8E1D438}" = HP Mobile Printing
"{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar
"{B7148D71-0A8F-4501-96B4-4E1CC67F874E}" = Microsoft Default Manager
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{B8B0FC8B-E69B-4215-AF1A-4BDFF20D794B}" = pdfforge Toolbar v1.0
"{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom Gigabit Integrated Controller
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEB326EC-8F40-47B2-BA22-BB092565D66F}" = Quick Launch Buttons 5.00 C2
"{D9461574-5FC0-4641-BBDC-D1038B196F55}" = Brother MFL-Pro Suite MFC-490CW
"{D9D937B0-E842-4130-9588-B948E876904A}" = Microsoft SQL Server 2008 Native Client
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F16F258A-6300-4A1C-BC49-7929EFF455E2}" = TIPCIxx20
"{F1DC7648-8623-442F-92B7-E118DF61872E}" = Microsoft SQL Server 2008 RsFx Driver
"{F2545484-7B1C-484A-89B8-B0F8B38BC67F}" = O2Micro SmartCardBus Reader Windows Driver Installer
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Agere Systems Soft Modem" = Agere Systems AC'97 Modem
"All ATI Software" = ATI - Software Uninstall Utility
"AOL Connectivity Services" = AOL Connectivity Services
"ATI Display Driver" = ATI Display Driver
"Ez_Themes Toolbar" = Ez_Themes Toolbar
"GamersFirst LIVE!" = GamersFirst LIVE!
"GamingHarbor Toolbar" = GamingHarbor Toolbar
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{4CBD31CE-51DF-43C4-B3EC-7CCBAB0CD083}" = O2Micro MemoryCardBus Windows Driver
"InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom Gigabit Integrated Controller
"InstallShield_{F16F258A-6300-4A1C-BC49-7929EFF455E2}" = Texas Instruments PCIxx20 drivers.
"IntMgmt" = Insight Management Agent
"Lexmark 2600 Series" = Lexmark 2600 Series
"Lexmark 5300 Series" = Lexmark 5300 Series
"LiveUpdate" = LiveUpdate 2.0 (Symantec Corporation)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Mozilla Firefox (3.5.11)" = Mozilla Firefox (3.5.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NSS" = Norton Security Scan
"OpenAL" = OpenAL
"PCSI" = Prevx
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 6.0" = RealPlayer Basic
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinNT Remote Services Deinstall Key" = Remote Services Driver
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"2a4f70b48f669acd" = AA3Deploy
"BitTorrent DNA" = DNA
"Google Chrome" = Google Chrome
"Move Media Player" = Move Media Player
"UnityWebPlayer" = Unity Web Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/16/2010 11:07:40 AM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Heuristic.ADH in File: C:\Documents and Settings\All
Users\Application Data\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\BED3DEFB\3E688669\stbasst.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: Heuristic.ADH in File: C:\Documents
and Settings\All Users\Application Data\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\mFileBagIDE.dll\bag\stbpx.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
Error - 10/16/2010 11:33:41 AM | Computer Name = USER-WSDRDFVS | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 10/16/2010 11:33:41 AM | Computer Name = USER-WSDRDFVS | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 10/16/2010 11:34:59 AM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
Error - 10/16/2010 12:42:56 PM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully.
Error - 10/16/2010 6:16:43 PM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
Error - 10/20/2010 7:42:46 PM | Computer Name = USER-WSDRDFVS | Source = MsiInstaller | ID = 1013
Description = Product: Citrix XenApp Plugin for Hosted Apps – At least one client
component is already in use. Before running Setup, please exit any of the following
programs that may be running: Program Neighborhood Citrix XenApp Plugin Program Neighborhood
Connection Center Remote Application Manager
Error - 10/20/2010 8:59:26 PM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
[ Application Events ]
Error - 10/16/2010 11:07:40 AM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Heuristic.ADH in File: C:\Documents and Settings\All
Users\Application Data\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\BED3DEFB\3E688669\stbasst.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: Heuristic.ADH in File: C:\Documents
and Settings\All Users\Application Data\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\mFileBagIDE.dll\bag\stbpx.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
Error - 10/16/2010 11:33:41 AM | Computer Name = USER-WSDRDFVS | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 10/16/2010 11:33:41 AM | Computer Name = USER-WSDRDFVS | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 10/16/2010 11:34:59 AM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
Error - 10/16/2010 12:42:56 PM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully.
Error - 10/16/2010 6:16:43 PM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
Error - 10/20/2010 7:42:46 PM | Computer Name = USER-WSDRDFVS | Source = MsiInstaller | ID = 1013
Description = Product: Citrix XenApp Plugin for Hosted Apps – At least one client
component is already in use. Before running Setup, please exit any of the following
programs that may be running: Program Neighborhood Citrix XenApp Plugin Program Neighborhood
Connection Center Remote Application Manager
Error - 10/20/2010 8:59:26 PM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
[ System Events ]
Error - 10/20/2010 5:33:46 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SAVRT
Error - 10/20/2010 5:34:50 PM | Computer Name = USER-WSDRDFVS | Source = SAVRT | ID = 458772
Description = Unable to initialize the virus scanning engine database files.
Error - 10/20/2010 5:34:50 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7000
Description = The SAVRT service failed to start due to the following error: %%31
Error - 10/20/2010 6:10:06 PM | Computer Name = USER-WSDRDFVS | Source = SAVRT | ID = 458772
Description = Unable to initialize the virus scanning engine database files.
Error - 10/20/2010 6:10:31 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdkCATSCustConnectService
service to connect.
Error - 10/20/2010 6:10:31 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7000
Description = The lxdkCATSCustConnectService service failed to start due to the
following error: %%1053
Error - 10/20/2010 6:10:31 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7000
Description = The My Web Search Service service failed to start due to the following
error: %%3
Error - 10/20/2010 6:10:34 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SAVRT
Error - 10/20/2010 6:11:15 PM | Computer Name = USER-WSDRDFVS | Source = SAVRT | ID = 458772
Description = Unable to initialize the virus scanning engine database files.
Error - 10/20/2010 6:11:15 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7000
Description = The SAVRT service failed to start due to the following error: %%31
< End of report >
The OTL Report is:
OTL logfile created on: 10/20/2010 9:27:35 PM - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,023.00 Mb Total Physical Memory | 316.00 Mb Available Physical Memory | 31.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 9.90 Gb Free Space | 13.28% Space Free | Partition Type: NTFS
Computer Name: USER-WSDRDFVS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\User\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
PRC - C:\Program Files\Prevx\prevx.exe (Prevx)
PRC - C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\GamersFirst\LIVE!\Live.exe (GamersFirst)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\pdfforge Toolbar\SearchSettings.exe (Spigot, Inc.)
PRC - C:\Program Files\Lexmark 2600 Series\ezprint.exe (Lexmark International Inc.)
PRC - C:\Program Files\Lexmark 2600 Series\lxdnmon.exe ()
PRC - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe (Brother Industries, Ltd.)
PRC - C:\WINDOWS\system32\lxdncoms.exe ( )
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnserv.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Brother\Brmfcmon\BrMfimon.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Lexmark 5300 Series\lxdkmon.exe ()
PRC - C:\WINDOWS\system32\lxdkcoms.exe ( )
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lexmark 5300 Series\lxdkamon.exe ()
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\HPQ\Quick Launch Buttons\eabservr.exe (Hewlett-Packard )
PRC - C:\Program Files\Common Files\AOL\ACS\AOLDial.exe (America Online, Inc)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\Program Files\Hewlett-Packard\HP Mobile Printing\HPBMOBIL.EXE (Hewlett-Packard Company)
PRC - C:\Program Files\Compaq\Compaq Management Agents\cpqWebDmi\Webdmi.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Compaq\Compaq Management Agents\Cpqdmi.exe (Compaq Computer Corporation)
PRC - C:\Program Files\Compaq\Compaq Management Agents\Chkadmin.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Compaq\Compaq Management Agents\Cpqalert.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\cpqdiag\CPQDFWAG.EXE (Hewlett-Packard)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe (Intel)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\User\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\SynTPFcs.dll (Synaptics, Inc.)
========== Win32 Services (SafeList) ==========
SRV - (SeekappSrch Service) – C:\Documents and Settings\All Users\Application Data\SeekappSrch\seekapp199.exe File not found
SRV - (MyWebSearchService) – C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe File not found
SRV - (CSIScanner) – C:\Program Files\Prevx\prevx.exe (Prevx)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (lxdn_device) – C:\WINDOWS\System32\lxdncoms.exe ( )
SRV - (lxdnCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdnserv.exe ()
SRV - (lxdk_device) – C:\WINDOWS\System32\lxdkcoms.exe ( )
SRV - (lxdkCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdkserv.exe ()
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
SRV - (cpqWebDmi) – C:\Program Files\Compaq\Compaq Management Agents\cpqWebDmi\Webdmi.exe (Hewlett-Packard Company)
SRV - (cpqdmi) – C:\Program Files\Compaq\Compaq Management Agents\Cpqdmi.exe (Compaq Computer Corporation)
SRV - (CPQALERT) – C:\Program Files\Compaq\Compaq Management Agents\Cpqalert.exe (Hewlett-Packard Company)
SRV - (DfwWebAgent) – C:\WINDOWS\cpqdiag\CPQDFWAG.EXE (Hewlett-Packard)
SRV - (SoundMAX Agent Service (default)) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (WIN32SL) – C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe (Intel)
========== Driver Services (SafeList) ==========
DRV - (XDva342) – C:\WINDOWS\System32\XDva342.sys File not found
DRV - (XDva317) – C:\WINDOWS\System32\XDva317.sys File not found
DRV - (wacommousefilter) – C:\WINDOWS\System32\DRIVERS\wacommousefilter.sys File not found
DRV - (EagleNT) – C:\WINDOWS\System32\drivers\EagleNT.sys File not found
DRV - (pxscan) – C:\WINDOWS\System32\drivers\pxscan.sys (Prevx)
DRV - (pxkbf) – C:\WINDOWS\system32\drivers\pxkbf.sys (Prevx)
DRV - (pxrts) – C:\WINDOWS\system32\drivers\pxrts.sys (Prevx)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101015.007\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101015.007\NAVENG.SYS (Symantec Corporation)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (WacomVKHid) – C:\WINDOWS\system32\drivers\WacomVKHid.sys (Wacom Technology)
DRV - (w29n51) Intel® – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (PCX500) – C:\WINDOWS\system32\drivers\pcx500.sys (Cisco Systems)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (eabfiltr) – C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Company)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (CONAN) – C:\WINDOWS\system32\drivers\o2mmb.sys (O2 Micro )
DRV - (MbxStby) – C:\WINDOWS\system32\drivers\MbxStby.sys (O2 Micro)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (eabusb) – C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Company)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (ClntMgmt) – C:\WINDOWS\system32\drivers\Clntmgmt.sys (Hewlett-Packard)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (cpqdfw) – C:\WINDOWS\system32\drivers\Cpqdfw.sys ()
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid;=CT2138729
IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:4.0.53.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {4548ECB8-DA60-439A-A00D-5C893F8E1F9A}:1.0
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:[removed]
FF - prefs.js..extensions.enabledItems: {586bd060-22d6-11de-8c30-0800200c9a66}:3.6
FF - prefs.js..keyword.URL: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZUfox000&fl;=0&ptb;=0vDY5oRLBakyJGGtj5iWLA&url;=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st;=kwd&searchfor;="
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\MyWebSearch\bar\firefox\
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/12 20:07:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/19 15:44:27 | 000,000,000 | —D | M]
[2009/12/21 16:27:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2010/08/10 12:56:56 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions
[2009/12/21 16:29:20 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/17 19:37:49 | 000,000,000 | —D | M] (Revelation) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}
[2010/05/18 15:19:01 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/05/22 19:02:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\[removed]
[2010/01/17 19:37:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}\chrome\mac\browser\extensions
[2010/01/17 19:37:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}\chrome\mac\mozapps\extensions
[2010/01/17 19:37:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}\chrome\win\browser\extensions
[2010/01/17 19:37:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}\chrome\win\mozapps\extensions
[2010/01/17 18:17:37 | 000,009,941 | —- | M] () – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\vglok3j4.default\searchplugins\mywebsearch.xml
[2010/08/10 12:56:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/18 11:39:42 | 000,000,000 | —D | M] (Seekapp) – C:\Program Files\Mozilla Firefox\extensions\{4548ECB8-DA60-439A-A00D-5C893F8E1F9A}
[2009/11/09 21:30:56 | 000,189,592 | —- | M] (MGame) – C:\Program Files\Mozilla Firefox\plugins\NPMFireLauncher.dll
[2009/12/21 16:27:04 | 000,002,383 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\seekapp167.xml
[2010/01/25 07:51:18 | 000,002,383 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\seekapp171.xml
[2010/02/01 11:19:26 | 000,002,383 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\seekapp173.xml
[2010/03/11 16:16:51 | 000,002,383 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\seekapp177.xml
O1 HOSTS File: ([2004/08/04 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SafeOnline BHO) - {69D72956-317C-44bd-B369-8E44D4EF9801} - C:\WINDOWS\system32\PxSecure.dll (Prevx)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll (GreenTree Applications, Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll File not found
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll (GreenTree Applications, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe (America Online, Inc)
O4 - HKLM..\Run: [ATIModeChange] C:\WINDOWS\System32\Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [ChkAdmin] C:\Program Files\Compaq\Compaq Management Agents\Chkadmin.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe (Hewlett-Packard )
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark 2600 Series\ezprint.exe (Lexmark International Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Lexmark 5300 Series Fax Server] C:\Program Files\Lexmark 5300 Series\fm3032.exe ()
O4 - HKLM..\Run: [lxdkamon] C:\Program Files\Lexmark 5300 Series\lxdkamon.exe ()
O4 - HKLM..\Run: [lxdkmon.exe] C:\Program Files\Lexmark 5300 Series\lxdkmon.exe ()
O4 - HKLM..\Run: [lxdnmon.exe] C:\Program Files\Lexmark 2600 Series\lxdnmon.exe ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe File not found
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corp.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O4 - HKCU..\Run: [Adobe Update Service] C:\WINDOWS\services.exe File not found
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [HP Mobile Printing] C:\Program Files\Hewlett-Packard\HP Mobile Printing\HPBMOBIL.EXE (Hewlett-Packard Company)
O4 - HKCU..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKLM..\RunServices: [CPQDFWAG] C:\WINDOWS\cpqdiag\CPQDFWAG.EXE (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk = C:\Program Files\GamersFirst\LIVE!\Live.exe (GamersFirst)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O9 - Extra Button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll File not found
O9 - Extra 'Tools' menuitem : AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: tenderfoot.com ([]http in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1148139928901 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1148139915952 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\My Documents\My Pictures\Flight Simulator X Demo Files\2009-10-27_20-27-3-834.BMP
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\My Documents\My Pictures\Flight Simulator X Demo Files\2009-10-27_20-27-3-834.BMP
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/05/19 22:08:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{07b9a270-4362-11df-8fbb-00038a000015}\Shell\AutoRun\command - "" = E:\RECYCLER\s-124-52-632-236-125-2632636\autorun.exe – File not found
O33 - MountPoints2\{07b9a270-4362-11df-8fbb-00038a000015}\Shell\Explore\command - "" = E:\RECYCLER\s-124-52-632-236-125-2632636\autorun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - xvidvfw.dll File not found
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/10/18 19:44:08 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\cBA APPLICATION_files
[2010/10/16 11:22:45 | 000,070,192 | —- | C] (Prevx) – C:\WINDOWS\System32\PxSecure.dll
[2010/10/16 11:22:44 | 000,074,624 | —- | C] (Prevx) – C:\WINDOWS\System32\drivers\pxrts.sys
[2010/10/16 11:22:44 | 000,030,320 | —- | C] (Prevx) – C:\WINDOWS\System32\drivers\pxscan.sys
[2010/10/16 11:22:43 | 000,024,400 | —- | C] (Prevx) – C:\WINDOWS\System32\drivers\pxkbf.sys
[2010/10/16 11:22:42 | 000,000,000 | —D | C] – C:\Program Files\Prevx
[2010/10/16 11:22:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PrevxCSI
[2010/09/24 18:41:31 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\Stuff i need to save
[2010/09/21 15:15:17 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2009/09/25 16:34:12 | 000,434,176 | —- | C] ( ) – C:\WINDOWS\System32\lxdkhcp.dll
[2009/05/21 20:34:09 | 001,101,824 | —- | C] ( ) – C:\WINDOWS\System32\lxdnserv.dll
[2009/05/21 20:34:09 | 000,843,776 | —- | C] ( ) – C:\WINDOWS\System32\lxdnusb1.dll
[2009/05/21 20:34:09 | 000,663,552 | —- | C] ( ) – C:\WINDOWS\System32\lxdnhbn3.dll
[2009/05/21 20:34:09 | 000,647,168 | —- | C] ( ) – C:\WINDOWS\System32\lxdnpmui.dll
[2009/05/21 20:34:09 | 000,569,344 | —- | C] ( ) – C:\WINDOWS\System32\lxdnlmpm.dll
[2009/05/21 20:34:09 | 000,438,272 | —- | C] ( ) – C:\WINDOWS\System32\LXDNhcp.dll
[2009/05/21 20:34:09 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxdninpa.dll
[2009/05/21 20:34:09 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdniesc.dll
[2009/05/21 20:34:09 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdnprox.dll
[2009/05/21 20:34:08 | 000,851,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdncomc.dll
[2009/05/21 20:34:08 | 000,376,832 | —- | C] ( ) – C:\WINDOWS\System32\lxdncomm.dll
[2007/05/17 10:11:04 | 000,647,168 | —- | C] ( ) – C:\WINDOWS\System32\lxdkpmui.dll
[2007/05/17 10:07:59 | 001,200,128 | —- | C] ( ) – C:\WINDOWS\System32\lxdkserv.dll
[2007/05/17 10:03:03 | 000,356,352 | —- | C] ( ) – C:\WINDOWS\System32\lxdkinpa.dll
[2007/05/17 10:02:58 | 000,565,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdklmpm.dll
[2007/05/17 10:02:41 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxdkcomm.dll
[2007/05/17 10:01:21 | 000,663,552 | —- | C] ( ) – C:\WINDOWS\System32\lxdkhbn3.dll
[2007/05/17 10:00:42 | 000,950,272 | —- | C] ( ) – C:\WINDOWS\System32\lxdkusb1.dll
[2007/05/17 10:00:29 | 000,860,160 | —- | C] ( ) – C:\WINDOWS\System32\lxdkcomc.dll
[2007/05/17 09:59:11 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdkprox.dll
[2007/05/17 09:57:01 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdkiesc.dll
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[24 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/10/20 21:11:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-688789844-1343024091-1003UA.job
[2010/10/20 18:14:54 | 000,070,192 | —- | M] (Prevx) – C:\WINDOWS\System32\PxSecure.dll
[2010/10/20 18:14:54 | 000,030,320 | —- | M] (Prevx) – C:\WINDOWS\System32\drivers\pxscan.sys
[2010/10/20 18:14:53 | 000,024,400 | —- | M] (Prevx) – C:\WINDOWS\System32\drivers\pxkbf.sys
[2010/10/20 18:10:41 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/20 18:09:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/20 18:09:30 | 1073,139,712 | -HS- | M] () – C:\hiberfil.sys
[2010/10/20 16:09:41 | 000,002,497 | —- | M] () – C:\Documents and Settings\User\Desktop\Microsoft Office Word 2003.lnk
[2010/10/20 15:12:18 | 000,002,277 | —- | M] () – C:\Documents and Settings\User\Desktop\Google Chrome.lnk
[2010/10/20 15:12:18 | 000,002,255 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/19 18:01:42 | 000,000,556 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for User.job
[2010/10/18 20:44:57 | 000,000,630 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Prevx 3.0.lnk
[2010/10/18 19:44:08 | 000,009,624 | —- | M] () – C:\Documents and Settings\User\Desktop\cBA APPLICATION.htm
[2010/10/16 11:52:51 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2010/10/16 11:22:44 | 000,074,624 | —- | M] (Prevx) – C:\WINDOWS\System32\drivers\pxrts.sys
[2010/10/16 11:22:29 | 000,000,047 | —- | M] () – C:\WINDOWS\wininit.ini
[2010/10/16 09:11:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-688789844-1343024091-1003Core.job
[2010/10/15 21:54:53 | 000,000,807 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GamersFirst LIVE!.lnk
[2010/10/15 21:54:53 | 000,000,779 | —- | M] () – C:\Documents and Settings\All Users\Desktop\GamersFirst LIVE!.lnk
[2010/10/12 19:55:54 | 000,000,786 | —- | M] () – C:\WINDOWS\Cpqdiag.ini
[2010/10/12 18:12:52 | 000,036,352 | —- | M] () – C:\Documents and Settings\User\My Documents\Doc1.doc
[2010/10/03 17:19:01 | 001,508,864 | —- | M] () – C:\Documents and Settings\User\My Documents\ole 1-3.doc
[2010/10/03 16:51:56 | 000,015,360 | —- | M] () – C:\Documents and Settings\User\My Documents\ole.xls
[2010/10/03 16:28:44 | 000,002,495 | —- | M] () – C:\Documents and Settings\User\Desktop\Microsoft Office Excel 2003.lnk
[2010/09/29 16:57:40 | 000,028,160 | —- | M] () – C:\Documents and Settings\User\My Documents\5 themes essay.doc
[2010/09/29 16:57:40 | 000,000,162 | -H– | M] () – C:\Documents and Settings\User\My Documents\~$themes essay.doc
[2010/09/24 18:23:17 | 000,000,637 | —- | M] () – C:\Shortcut to My Documents.lnk
[2010/09/21 15:54:19 | 000,134,144 | —- | M] () – C:\Documents and Settings\User\My Documents\logo.doc
[2010/09/21 15:54:19 | 000,000,162 | -H– | M] () – C:\Documents and Settings\User\My Documents\~$logo.doc
[2010/09/21 15:37:15 | 000,001,503 | —- | M] () – C:\Documents and Settings\User\Desktop\Paint (2).lnk
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[24 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\User\My Documents\*.tmp files -> C:\Documents and Settings\User\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/18 20:44:57 | 000,000,630 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Prevx 3.0.lnk
[2010/10/18 19:44:07 | 000,009,624 | —- | C] () – C:\Documents and Settings\User\Desktop\cBA APPLICATION.htm
[2010/10/16 11:22:29 | 000,000,047 | —- | C] () – C:\WINDOWS\wininit.ini
[2010/10/12 18:12:52 | 000,036,352 | —- | C] () – C:\Documents and Settings\User\My Documents\Doc1.doc
[2010/10/12 17:45:50 | 1073,139,712 | -HS- | C] () – C:\hiberfil.sys
[2010/10/03 17:19:00 | 001,508,864 | —- | C] () – C:\Documents and Settings\User\My Documents\ole 1-3.doc
[2010/10/03 16:51:56 | 000,015,360 | —- | C] () – C:\Documents and Settings\User\My Documents\ole.xls
[2010/09/29 16:57:40 | 000,000,162 | -H– | C] () – C:\Documents and Settings\User\My Documents\~$themes essay.doc
[2010/09/29 16:57:39 | 000,028,160 | —- | C] () – C:\Documents and Settings\User\My Documents\5 themes essay.doc
[2010/09/21 15:54:19 | 000,134,144 | —- | C] () – C:\Documents and Settings\User\My Documents\logo.doc
[2010/09/21 15:54:19 | 000,000,162 | -H– | C] () – C:\Documents and Settings\User\My Documents\~$logo.doc
[2010/09/21 15:37:15 | 000,001,503 | —- | C] () – C:\Documents and Settings\User\Desktop\Paint (2).lnk
[2010/06/28 09:09:31 | 000,000,000 | R— | C] () – C:\Documents and Settings\User\Application Data\KJcHb.txt
[2010/06/09 16:25:53 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/12/21 15:13:37 | 000,000,000 | —- | C] () – C:\WINDOWS\galaxy.ini
[2009/10/18 17:43:03 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2009/09/25 16:39:45 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\LXDKPMON.DLL
[2009/09/25 16:39:45 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\LXDKFXPU.DLL
[2009/09/25 16:39:25 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdkoem.dll
[2009/09/25 16:34:15 | 000,000,060 | —- | C] () – C:\WINDOWS\System32\lxdkrwrd.ini
[2009/09/25 16:34:13 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\lxdkinst.dll
[2009/09/25 16:32:44 | 000,348,160 | R— | C] () – C:\WINDOWS\System32\lxdkcoin.dll
[2009/08/26 16:10:28 | 000,138,056 | —- | C] () – C:\Documents and Settings\User\Application Data\PnkBstrK.sys
[2009/06/18 17:23:20 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\TEMP(3)
[2009/06/18 15:09:22 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\TEMP(2)
[2009/06/16 18:31:55 | 000,000,833 | —- | C] () – C:\WINDOWS\disney.ini
[2009/06/16 18:31:22 | 000,000,184 | —- | C] () – C:\WINDOWS\disneysy.ini
[2009/06/11 16:46:39 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2009/06/07 20:26:11 | 000,138,056 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/05/21 20:34:55 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdnvs.dll
[2009/05/21 20:34:54 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\lxdncoin.dll
[2009/05/21 20:34:28 | 000,782,336 | —- | C] () – C:\WINDOWS\System32\lxdndrs.dll
[2009/05/21 20:34:28 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\lxdncaps.dll
[2009/05/21 20:34:28 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdncnv4.dll
[2009/05/21 20:34:09 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\LXDNinst.dll
[2009/05/21 20:34:09 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdngrd.dll
[2009/05/18 19:40:25 | 000,000,243 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2009/05/18 19:40:25 | 000,000,094 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2009/05/18 19:40:10 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/05/18 19:40:10 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/05/18 19:39:21 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2009/05/18 19:39:21 | 000,000,086 | —- | C] () – C:\WINDOWS\Brfaxrx.ini
[2009/05/16 16:32:57 | 000,069,632 | R— | C] () – C:\WINDOWS\System32\xmltok.dll
[2009/05/16 16:32:57 | 000,036,864 | R— | C] () – C:\WINDOWS\System32\xmlparse.dll
[2008/04/08 20:36:00 | 000,037,376 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/06/06 04:25:45 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdkgrd.dll
[2007/05/22 13:22:21 | 000,692,224 | —- | C] () – C:\WINDOWS\System32\lxdkdrs.dll
[2007/05/22 06:10:00 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\lxdkcaps.dll
[2007/02/14 10:35:07 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdkcnv4.dll
[2006/07/31 21:53:18 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdkvs.dll
[2006/05/20 14:36:17 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2006/05/20 14:36:16 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2006/05/20 14:36:16 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2006/05/20 14:36:16 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2006/05/20 14:36:16 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2006/05/20 14:36:16 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2006/05/20 11:56:18 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2006/05/20 11:44:00 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/19 23:12:35 | 000,033,728 | —- | C] () – C:\WINDOWS\System32\drivers\cs_nt40.sys
[2006/05/19 23:11:54 | 000,001,582 | —- | C] () – C:\WINDOWS\ACT_CFG.INI
[2006/05/19 23:11:49 | 000,019,845 | —- | C] () – C:\WINDOWS\System32\drivers\Cpqdfw.sys
[2006/05/19 23:11:49 | 000,000,786 | —- | C] () – C:\WINDOWS\Cpqdiag.ini
[2006/05/19 23:06:20 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\SynTPCoI.dll
[2006/05/19 23:06:13 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\drivers\CPQRS.sys
[2006/05/19 14:57:18 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/09 18:13:31 | 000,831,488 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/08/09 18:13:31 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/08/09 18:12:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/05/17 14:18:28 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/04 08:00:00 | 000,013,576 | —- | C] () – C:\WINDOWS\System32\syscorecfg256.dll
[2003/12/02 18:55:14 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2003/01/07 18:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2009/09/25 16:39:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\5300 Series
[2009/06/18 17:32:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AA2DeployClient
[2010/01/17 19:15:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AA3DeployClient
[2009/10/12 09:54:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alibre Design
[2009/11/19 20:09:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2009/05/21 19:39:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2010/10/19 15:45:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/10/16 11:35:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PrevxCSI
[2010/10/12 19:52:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/10/18 16:46:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/05/17 19:57:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/07/08 15:19:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{51FC4C90-DF10-4D41-963E-DB3050C1267C}
[2009/09/23 18:31:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/08/01 14:31:37 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}
[2009/09/26 07:23:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\5300 Series
[2009/06/11 17:17:37 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Alibre Design
[2010/01/17 18:25:10 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\BitTorrent
[2009/06/11 16:52:13 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\CB Model Pro
[2010/10/20 21:39:51 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\DNA
[2009/10/14 17:38:03 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FOG Downloader
[2010/08/26 16:40:26 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\GetRightToGo
[2009/11/13 20:34:35 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\ICAClient
[2009/12/21 18:51:08 | 000,000,000 | -H-D | M] – C:\Documents and Settings\User\Application Data\ijjigame
[2009/05/28 16:07:37 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\InterVideo
[2009/05/17 06:19:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Leadertech
[2010/01/13 10:45:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Lexmark Productivity Studio
[2010/08/26 16:48:53 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Raptr
[2010/05/22 10:38:22 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Tenderfoot Games
[2010/07/29 15:52:23 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Unity
[2009/06/18 17:47:00 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\uTorrent
[2010/08/12 15:32:56 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\VBA-M
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/05/19 23:13:05 | 000,000,086 | —- | M] () – C:\ApInsTmp.log
[2006/05/19 22:08:15 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/05/19 23:07:32 | 000,000,192 | —- | M] () – C:\BcBtRmv.log
[2006/05/19 22:01:55 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2006/05/19 23:17:24 | 000,000,090 | —- | M] () – C:\chpst.log
[2006/05/19 22:08:15 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/07/28 20:38:11 | 000,000,081 | —- | M] () – C:\CTX.DAT
[2009/06/22 20:34:20 | 000,001,047 | —- | M] () – C:\error_log.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2010/10/20 18:09:30 | 1073,139,712 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2006/05/19 22:08:15 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/10/17 18:50:04 | 000,037,888 | —- | M] () – C:\JOURNAL.doc
[2006/05/19 22:08:15 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 08:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/10/20 18:09:28 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2009/08/15 22:39:00 | 000,000,204 | —- | M] () – C:\Plugins
[2006/05/19 23:15:19 | 000,000,161 | —- | M] () – C:\sedinst.log
[2006/05/19 23:15:18 | 000,000,189 | —- | M] () – C:\sedinst2.log
[2006/05/19 23:16:24 | 000,000,173 | —- | M] () – C:\setup.log
[2010/09/24 18:23:17 | 000,000,637 | —- | M] () – C:\Shortcut to My Documents.lnk
[2006/05/19 23:15:46 | 000,019,314 | —- | M] () – C:\SUNJAVA.log
[2010/08/26 16:52:53 | 000,003,072 | -HS- | M] () – C:\Thumbs.db
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/05/19 22:07:39 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/05/02 19:38:35 | 000,113,664 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdkdrpp.dll
[2008/02/26 22:05:40 | 000,115,200 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdndrpp.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/04/22 17:55:16 | 000,001,538 | -H– | M] () – C:\Documents and Settings\User\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/05/19 14:54:03 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/05/19 14:54:03 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/05/19 14:54:02 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2006/05/19 22:08:24 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/05/19 22:54:07 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/05/19 22:54:06 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-16 03:56:54
========== Alternate Data Streams ==========
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP(2):DFC5A2B2
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:522EA216
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP(3):DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 10/20/2010 9:27:35 PM - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,023.00 Mb Total Physical Memory | 316.00 Mb Available Physical Memory | 31.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 9.90 Gb Free Space | 13.28% Space Free | Partition Type: NTFS
Computer Name: USER-WSDRDFVS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
http [open] – C:\PROGRA~1\AMERIC~1.0\aol.exe -u"%1" File not found
https [open] – C:\PROGRA~1\AMERIC~1.0\aol.exe -u"%1" File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"54925:UDP" = 54925:UDP:*:Enabled:BrotherNetwork Scanner
"3420:TCP" = 3420:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface
"3093:TCP" = 3093:TCP:*:Enabled:Akamai NetSession Interface
"3350:TCP" = 3350:TCP:*:Enabled:Akamai NetSession Interface
"1041:TCP" = 1041:TCP:*:Enabled:Akamai NetSession Interface
"1044:TCP" = 1044:TCP:*:Enabled:Akamai NetSession Interface
"1043:TCP" = 1043:TCP:*:Enabled:Akamai NetSession Interface
"1490:TCP" = 1490:TCP:*:Enabled:Akamai NetSession Interface
"1040:TCP" = 1040:TCP:*:Enabled:Akamai NetSession Interface
"1345:TCP" = 1345:TCP:*:Enabled:Akamai NetSession Interface
"1399:TCP" = 1399:TCP:*:Enabled:Akamai NetSession Interface
"1595:TCP" = 1595:TCP:*:Enabled:Akamai NetSession Interface
"1045:TCP" = 1045:TCP:*:Enabled:Akamai NetSession Interface
"1220:TCP" = 1220:TCP:*:Enabled:Akamai NetSession Interface
"1579:TCP" = 1579:TCP:*:Enabled:Akamai NetSession Interface
"1818:TCP" = 1818:TCP:*:Enabled:Akamai NetSession Interface
"1042:TCP" = 1042:TCP:*:Enabled:Akamai NetSession Interface
"1142:TCP" = 1142:TCP:*:Enabled:Akamai NetSession Interface
"56625:TCP" = 56625:TCP:*:Enabled:Pando Media Booster
"56625:UDP" = 56625:UDP:*:Enabled:Pando Media Booster
"2087:TCP" = 2087:TCP:*:Enabled:Akamai NetSession Interface
"2326:TCP" = 2326:TCP:*:Enabled:Akamai NetSession Interface
"2604:TCP" = 2604:TCP:*:Enabled:Akamai NetSession Interface
"1039:TCP" = 1039:TCP:*:Enabled:Akamai NetSession Interface
"1051:TCP" = 1051:TCP:*:Enabled:Akamai NetSession Interface
"1197:TCP" = 1197:TCP:*:Enabled:Akamai NetSession Interface
"1070:TCP" = 1070:TCP:*:Enabled:Akamai NetSession Interface
"2180:TCP" = 2180:TCP:*:Enabled:Akamai NetSession Interface
"3373:TCP" = 3373:TCP:*:Enabled:Akamai NetSession Interface
"1398:TCP" = 1398:TCP:*:Enabled:Akamai NetSession Interface
"1577:TCP" = 1577:TCP:*:Enabled:Akamai NetSession Interface
"1050:TCP" = 1050:TCP:*:Enabled:Akamai NetSession Interface
"1333:TCP" = 1333:TCP:*:Enabled:Akamai NetSession Interface
"2822:TCP" = 2822:TCP:*:Enabled:Akamai NetSession Interface
"1440:TCP" = 1440:TCP:*:Enabled:Akamai NetSession Interface
"1502:TCP" = 1502:TCP:*:Enabled:Akamai NetSession Interface
"1053:TCP" = 1053:TCP:*:Enabled:Akamai NetSession Interface
"1088:TCP" = 1088:TCP:*:Enabled:Akamai NetSession Interface
"3267:TCP" = 3267:TCP:*:Enabled:Akamai NetSession Interface
"3472:TCP" = 3472:TCP:*:Enabled:Akamai NetSession Interface
"3574:TCP" = 3574:TCP:*:Enabled:Akamai NetSession Interface
"3643:TCP" = 3643:TCP:*:Enabled:Akamai NetSession Interface
"1184:TCP" = 1184:TCP:*:Enabled:Akamai NetSession Interface
"1330:TCP" = 1330:TCP:*:Enabled:Akamai NetSession Interface
"1574:TCP" = 1574:TCP:*:Enabled:Akamai NetSession Interface
"1779:TCP" = 1779:TCP:*:Enabled:Akamai NetSession Interface
"1681:TCP" = 1681:TCP:*:Enabled:Akamai NetSession Interface
"2768:TCP" = 2768:TCP:*:Enabled:Akamai NetSession Interface
"1377:TCP" = 1377:TCP:*:Enabled:Akamai NetSession Interface
"1821:TCP" = 1821:TCP:*:Enabled:Akamai NetSession Interface
"1919:TCP" = 1919:TCP:*:Enabled:Akamai NetSession Interface
"1260:TCP" = 1260:TCP:*:Enabled:Akamai NetSession Interface
"1754:TCP" = 1754:TCP:*:Enabled:Akamai NetSession Interface
"1762:TCP" = 1762:TCP:*:Enabled:Akamai NetSession Interface
"1177:TCP" = 1177:TCP:*:Enabled:Akamai NetSession Interface
"1225:TCP" = 1225:TCP:*:Enabled:Akamai NetSession Interface
"1149:TCP" = 1149:TCP:*:Enabled:Akamai NetSession Interface
"3016:TCP" = 3016:TCP:*:Enabled:Akamai NetSession Interface
"3028:TCP" = 3028:TCP:*:Enabled:Akamai NetSession Interface
"1123:TCP" = 1123:TCP:*:Enabled:Akamai NetSession Interface
"1160:TCP" = 1160:TCP:*:Enabled:Akamai NetSession Interface
"2508:TCP" = 2508:TCP:*:Enabled:Akamai NetSession Interface
"1110:TCP" = 1110:TCP:*:Enabled:Akamai NetSession Interface
"2122:TCP" = 2122:TCP:*:Enabled:Akamai NetSession Interface
"1261:TCP" = 1261:TCP:*:Enabled:Akamai NetSession Interface
"1325:TCP" = 1325:TCP:*:Enabled:Akamai NetSession Interface
"1111:TCP" = 1111:TCP:*:Enabled:Akamai NetSession Interface
"1649:TCP" = 1649:TCP:*:Enabled:Akamai NetSession Interface
"1678:TCP" = 1678:TCP:*:Enabled:Akamai NetSession Interface
"1707:TCP" = 1707:TCP:*:Enabled:Akamai NetSession Interface
"3812:TCP" = 3812:TCP:*:Enabled:Akamai NetSession Interface
"3840:TCP" = 3840:TCP:*:Enabled:Akamai NetSession Interface
"3876:TCP" = 3876:TCP:*:Enabled:Akamai NetSession Interface
"1116:TCP" = 1116:TCP:*:Enabled:Akamai NetSession Interface
"2584:TCP" = 2584:TCP:*:Enabled:Akamai NetSession Interface
"3145:TCP" = 3145:TCP:*:Enabled:Akamai NetSession Interface
"3710:TCP" = 3710:TCP:*:Enabled:Akamai NetSession Interface
"4001:TCP" = 4001:TCP:*:Enabled:Akamai NetSession Interface
"1254:TCP" = 1254:TCP:*:Enabled:Akamai NetSession Interface
"1393:TCP" = 1393:TCP:*:Enabled:Akamai NetSession Interface
"1167:TCP" = 1167:TCP:*:Enabled:Akamai NetSession Interface
"1164:TCP" = 1164:TCP:*:Enabled:Akamai NetSession Interface
"1208:TCP" = 1208:TCP:*:Enabled:Akamai NetSession Interface
"1452:TCP" = 1452:TCP:*:Enabled:Akamai NetSession Interface
"1156:TCP" = 1156:TCP:*:Enabled:Akamai NetSession Interface
"1673:TCP" = 1673:TCP:*:Enabled:Akamai NetSession Interface
"1755:TCP" = 1755:TCP:*:Enabled:Akamai NetSession Interface
"1987:TCP" = 1987:TCP:*:Enabled:Akamai NetSession Interface
"4203:TCP" = 4203:TCP:*:Enabled:Akamai NetSession Interface
"1355:TCP" = 1355:TCP:*:Enabled:Akamai NetSession Interface
"1544:TCP" = 1544:TCP:*:Enabled:Akamai NetSession Interface
"2683:TCP" = 2683:TCP:*:Enabled:Akamai NetSession Interface
"2689:TCP" = 2689:TCP:*:Enabled:Akamai NetSession Interface
"1539:TCP" = 1539:TCP:*:Enabled:Akamai NetSession Interface
"1547:TCP" = 1547:TCP:*:Enabled:Akamai NetSession Interface
"1581:TCP" = 1581:TCP:*:Enabled:Akamai NetSession Interface
"2411:TCP" = 2411:TCP:*:Enabled:Akamai NetSession Interface
"2490:TCP" = 2490:TCP:*:Enabled:Akamai NetSession Interface
"2902:TCP" = 2902:TCP:*:Enabled:Akamai NetSession Interface
"3715:TCP" = 3715:TCP:*:Enabled:Akamai NetSession Interface
"4116:TCP" = 4116:TCP:*:Enabled:Akamai NetSession Interface
"4140:TCP" = 4140:TCP:*:Enabled:Akamai NetSession Interface
"1311:TCP" = 1311:TCP:*:Enabled:Akamai NetSession Interface
"1777:TCP" = 1777:TCP:*:Enabled:Akamai NetSession Interface
"2602:TCP" = 2602:TCP:*:Enabled:Akamai NetSession Interface
"3825:TCP" = 3825:TCP:*:Enabled:Akamai NetSession Interface
"1774:TCP" = 1774:TCP:*:Enabled:Akamai NetSession Interface
"1840:TCP" = 1840:TCP:*:Enabled:Akamai NetSession Interface
"1873:TCP" = 1873:TCP:*:Enabled:Akamai NetSession Interface
"1904:TCP" = 1904:TCP:*:Enabled:Akamai NetSession Interface
"3256:TCP" = 3256:TCP:*:Enabled:Akamai NetSession Interface
"4831:TCP" = 4831:TCP:*:Enabled:Akamai NetSession Interface
"2870:TCP" = 2870:TCP:*:Enabled:Akamai NetSession Interface
"3264:TCP" = 3264:TCP:*:Enabled:Akamai NetSession Interface
"3865:TCP" = 3865:TCP:*:Enabled:Akamai NetSession Interface
"4003:TCP" = 4003:TCP:*:Enabled:Akamai NetSession Interface
"4079:TCP" = 4079:TCP:*:Enabled:Akamai NetSession Interface
"1105:TCP" = 1105:TCP:*:Enabled:Akamai NetSession Interface
"1704:TCP" = 1704:TCP:*:Enabled:Akamai NetSession Interface
"2043:TCP" = 2043:TCP:*:Enabled:Akamai NetSession Interface
"2098:TCP" = 2098:TCP:*:Enabled:Akamai NetSession Interface
"2507:TCP" = 2507:TCP:*:Enabled:Akamai NetSession Interface
"2880:TCP" = 2880:TCP:*:Enabled:Akamai NetSession Interface
"4487:TCP" = 4487:TCP:*:Enabled:Akamai NetSession Interface
"4922:TCP" = 4922:TCP:*:Enabled:Akamai NetSession Interface
"2921:TCP" = 2921:TCP:*:Enabled:Akamai NetSession Interface
"4735:TCP" = 4735:TCP:*:Enabled:Akamai NetSession Interface
"1617:TCP" = 1617:TCP:*:Enabled:Akamai NetSession Interface
"1397:TCP" = 1397:TCP:*:Enabled:Akamai NetSession Interface
"3978:TCP" = 3978:TCP:*:Enabled:Akamai NetSession Interface
"4151:TCP" = 4151:TCP:*:Enabled:Akamai NetSession Interface
"4379:TCP" = 4379:TCP:*:Enabled:Akamai NetSession Interface
"4666:TCP" = 4666:TCP:*:Enabled:Akamai NetSession Interface
"4052:TCP" = 4052:TCP:*:Enabled:Akamai NetSession Interface
"1200:TCP" = 1200:TCP:*:Enabled:Akamai NetSession Interface
"1276:TCP" = 1276:TCP:*:Enabled:Akamai NetSession Interface
"1381:TCP" = 1381:TCP:*:Enabled:Akamai NetSession Interface
"1423:TCP" = 1423:TCP:*:Enabled:Akamai NetSession Interface
"1654:TCP" = 1654:TCP:*:Enabled:Akamai NetSession Interface
"2802:TCP" = 2802:TCP:*:Enabled:Akamai NetSession Interface
"2840:TCP" = 2840:TCP:*:Enabled:Akamai NetSession Interface
"3099:TCP" = 3099:TCP:*:Enabled:Akamai NetSession Interface
"2130:TCP" = 2130:TCP:*:Enabled:Akamai NetSession Interface
"2244:TCP" = 2244:TCP:*:Enabled:Akamai NetSession Interface
"4890:TCP" = 4890:TCP:*:Enabled:Akamai NetSession Interface
"4901:TCP" = 4901:TCP:*:Enabled:Akamai NetSession Interface
"4937:TCP" = 4937:TCP:*:Enabled:Akamai NetSession Interface
"1293:TCP" = 1293:TCP:*:Enabled:Akamai NetSession Interface
"3201:TCP" = 3201:TCP:*:Enabled:Akamai NetSession Interface
"4100:TCP" = 4100:TCP:*:Enabled:Akamai NetSession Interface
"4135:TCP" = 4135:TCP:*:Enabled:Akamai NetSession Interface
"4939:TCP" = 4939:TCP:*:Enabled:Akamai NetSession Interface
"4993:TCP" = 4993:TCP:*:Enabled:Akamai NetSession Interface
"1550:TCP" = 1550:TCP:*:Enabled:Akamai NetSession Interface
"2201:TCP" = 2201:TCP:*:Enabled:Akamai NetSession Interface
"3946:TCP" = 3946:TCP:*:Enabled:Akamai NetSession Interface
"3984:TCP" = 3984:TCP:*:Enabled:Akamai NetSession Interface
"1362:TCP" = 1362:TCP:*:Enabled:Akamai NetSession Interface
"2280:TCP" = 2280:TCP:*:Enabled:Akamai NetSession Interface
"2932:TCP" = 2932:TCP:*:Enabled:Akamai NetSession Interface
"2991:TCP" = 2991:TCP:*:Enabled:Akamai NetSession Interface
"3754:TCP" = 3754:TCP:*:Enabled:Akamai NetSession Interface
"4324:TCP" = 4324:TCP:*:Enabled:Akamai NetSession Interface
"4369:TCP" = 4369:TCP:*:Enabled:Akamai NetSession Interface
"4826:TCP" = 4826:TCP:*:Enabled:Akamai NetSession Interface
"1978:TCP" = 1978:TCP:*:Enabled:Akamai NetSession Interface
"3763:TCP" = 3763:TCP:*:Enabled:Akamai NetSession Interface
"3096:TCP" = 3096:TCP:*:Enabled:Akamai NetSession Interface
"3161:TCP" = 3161:TCP:*:Enabled:Akamai NetSession Interface
"2015:TCP" = 2015:TCP:*:Enabled:Akamai NetSession Interface
"2967:TCP" = 2967:TCP:*:Enabled:Akamai NetSession Interface
"2973:TCP" = 2973:TCP:*:Enabled:Akamai NetSession Interface
"2993:TCP" = 2993:TCP:*:Enabled:Akamai NetSession Interface
"3003:TCP" = 3003:TCP:*:Enabled:Akamai NetSession Interface
"3024:TCP" = 3024:TCP:*:Enabled:Akamai NetSession Interface
"3630:TCP" = 3630:TCP:*:Enabled:Akamai NetSession Interface
"4967:TCP" = 4967:TCP:*:Enabled:Akamai NetSession Interface
"4974:TCP" = 4974:TCP:*:Enabled:Akamai NetSession Interface
"4998:TCP" = 4998:TCP:*:Enabled:Akamai NetSession Interface
"1192:TCP" = 1192:TCP:*:Enabled:Akamai NetSession Interface
"1213:TCP" = 1213:TCP:*:Enabled:Akamai NetSession Interface
"1429:TCP" = 1429:TCP:*:Enabled:Akamai NetSession Interface
"1441:TCP" = 1441:TCP:*:Enabled:Akamai NetSession Interface
"2324:TCP" = 2324:TCP:*:Enabled:Akamai NetSession Interface
"3537:TCP" = 3537:TCP:*:Enabled:Akamai NetSession Interface
"3555:TCP" = 3555:TCP:*:Enabled:Akamai NetSession Interface
"3595:TCP" = 3595:TCP:*:Enabled:Akamai NetSession Interface
"1921:TCP" = 1921:TCP:*:Enabled:Akamai NetSession Interface
"3706:TCP" = 3706:TCP:*:Enabled:Akamai NetSession Interface
"1824:TCP" = 1824:TCP:*:Enabled:Akamai NetSession Interface
"2805:TCP" = 2805:TCP:*:Enabled:Akamai NetSession Interface
"2862:TCP" = 2862:TCP:*:Enabled:Akamai NetSession Interface
"3991:TCP" = 3991:TCP:*:Enabled:Akamai NetSession Interface
"4039:TCP" = 4039:TCP:*:Enabled:Akamai NetSession Interface
"2394:TCP" = 2394:TCP:*:Enabled:Akamai NetSession Interface
"2681:TCP" = 2681:TCP:*:Enabled:Akamai NetSession Interface
"2187:TCP" = 2187:TCP:*:Enabled:Akamai NetSession Interface
"4846:TCP" = 4846:TCP:*:Enabled:Akamai NetSession Interface
"4852:TCP" = 4852:TCP:*:Enabled:Akamai NetSession Interface
"4896:TCP" = 4896:TCP:*:Enabled:Akamai NetSession Interface
"1203:TCP" = 1203:TCP:*:Enabled:Akamai NetSession Interface
"1743:TCP" = 1743:TCP:*:Enabled:Akamai NetSession Interface
"3079:TCP" = 3079:TCP:*:Enabled:Akamai NetSession Interface
"4014:TCP" = 4014:TCP:*:Enabled:Akamai NetSession Interface
"4248:TCP" = 4248:TCP:*:Enabled:Akamai NetSession Interface
"2784:TCP" = 2784:TCP:*:Enabled:Akamai NetSession Interface
"4716:TCP" = 4716:TCP:*:Enabled:Akamai NetSession Interface
"4751:TCP" = 4751:TCP:*:Enabled:Akamai NetSession Interface
"4788:TCP" = 4788:TCP:*:Enabled:Akamai NetSession Interface
"4823:TCP" = 4823:TCP:*:Enabled:Akamai NetSession Interface
"1250:TCP" = 1250:TCP:*:Enabled:Akamai NetSession Interface
"2539:TCP" = 2539:TCP:*:Enabled:Akamai NetSession Interface
"2895:TCP" = 2895:TCP:*:Enabled:Akamai NetSession Interface
"3892:TCP" = 3892:TCP:*:Enabled:Akamai NetSession Interface
"3920:TCP" = 3920:TCP:*:Enabled:Akamai NetSession Interface
"1175:TCP" = 1175:TCP:*:Enabled:Akamai NetSession Interface
"1242:TCP" = 1242:TCP:*:Enabled:Akamai NetSession Interface
"1784:TCP" = 1784:TCP:*:Enabled:Akamai NetSession Interface
"2579:TCP" = 2579:TCP:*:Enabled:Akamai NetSession Interface
"3174:TCP" = 3174:TCP:*:Enabled:Akamai NetSession Interface
"1445:TCP" = 1445:TCP:*:Enabled:Akamai NetSession Interface
"1384:TCP" = 1384:TCP:*:Enabled:Akamai NetSession Interface
"1426:TCP" = 1426:TCP:*:Enabled:Akamai NetSession Interface
"1725:TCP" = 1725:TCP:*:Enabled:Akamai NetSession Interface
"3596:TCP" = 3596:TCP:*:Enabled:Akamai NetSession Interface
"3611:TCP" = 3611:TCP:*:Enabled:Akamai NetSession Interface
"3642:TCP" = 3642:TCP:*:Enabled:Akamai NetSession Interface
"1047:TCP" = 1047:TCP:*:Enabled:Akamai NetSession Interface
"2317:TCP" = 2317:TCP:*:Enabled:Akamai NetSession Interface
"2372:TCP" = 2372:TCP:*:Enabled:Akamai NetSession Interface
"2406:TCP" = 2406:TCP:*:Enabled:Akamai NetSession Interface
"1298:TCP" = 1298:TCP:*:Enabled:Akamai NetSession Interface
"3249:TCP" = 3249:TCP:*:Enabled:Akamai NetSession Interface
"3285:TCP" = 3285:TCP:*:Enabled:Akamai NetSession Interface
"4820:TCP" = 4820:TCP:*:Enabled:Akamai NetSession Interface
"1623:TCP" = 1623:TCP:*:Enabled:Akamai NetSession Interface
"2008:TCP" = 2008:TCP:*:Enabled:Akamai NetSession Interface
"3098:TCP" = 3098:TCP:*:Enabled:Akamai NetSession Interface
"3795:TCP" = 3795:TCP:*:Enabled:Akamai NetSession Interface
"3807:TCP" = 3807:TCP:*:Enabled:Akamai NetSession Interface
"3759:TCP" = 3759:TCP:*:Enabled:Akamai NetSession Interface
"1271:TCP" = 1271:TCP:*:Enabled:Akamai NetSession Interface
"1785:TCP" = 1785:TCP:*:Enabled:Akamai NetSession Interface
"2312:TCP" = 2312:TCP:*:Enabled:Akamai NetSession Interface
"1168:TCP" = 1168:TCP:*:Enabled:Akamai NetSession Interface
"2361:TCP" = 2361:TCP:*:Enabled:Akamai NetSession Interface
"1899:TCP" = 1899:TCP:*:Enabled:Akamai NetSession Interface
"1989:TCP" = 1989:TCP:*:Enabled:Akamai NetSession Interface
"2545:TCP" = 2545:TCP:*:Enabled:Akamai NetSession Interface
"1813:TCP" = 1813:TCP:*:Enabled:Akamai NetSession Interface
"2504:TCP" = 2504:TCP:*:Enabled:Akamai NetSession Interface
"2642:TCP" = 2642:TCP:*:Enabled:Akamai NetSession Interface
"3033:TCP" = 3033:TCP:*:Enabled:Akamai NetSession Interface
"3634:TCP" = 3634:TCP:*:Enabled:Akamai NetSession Interface
"3768:TCP" = 3768:TCP:*:Enabled:Akamai NetSession Interface
"1991:TCP" = 1991:TCP:*:Enabled:Akamai NetSession Interface
"2066:TCP" = 2066:TCP:*:Enabled:Akamai NetSession Interface
"2095:TCP" = 2095:TCP:*:Enabled:Akamai NetSession Interface
"2456:TCP" = 2456:TCP:*:Enabled:Akamai NetSession Interface
"1449:TCP" = 1449:TCP:*:Enabled:Akamai NetSession Interface
"57014:TCP" = 57014:TCP:*:Enabled:Pando Media Booster
"57014:UDP" = 57014:UDP:*:Enabled:Pando Media Booster
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"57070:TCP" = 57070:TCP:*:Enabled:Pando Media Booster
"57070:UDP" = 57070:UDP:*:Enabled:Pando Media Booster
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe – File not found
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online, Inc)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – File not found
"C:\Program Files\Ubisoft\Splinter Cell Pandora Tomorrow\pandora.exe" = C:\Program Files\Ubisoft\Splinter Cell Pandora Tomorrow\pandora.exe:*:Enabled:pandora – File not found
"C:\Program Files\Ubisoft\Splinter Cell Pandora Tomorrow\online\System\shadowstrike_static_retail.exe" = C:\Program Files\Ubisoft\Splinter Cell Pandora Tomorrow\online\System\shadowstrike_static_retail.exe:*:Enabled:shadowstrike_static_retail – File not found
"C:\Program Files\Brother\Brmfl08b\FAXRX.exe" = C:\Program Files\Brother\Brmfl08b\FAXRX.exe:*:Enabled:FAXRX.EXE – ()
"C:\Documents and Settings\User\Local Settings\Application Data\Xenocode\ApplianceCaches\KumaClient.exe_v02D7169E\Native\STUBEXE\@PROGRAMFILES@\Kuma Games\Kuma.exe" = C:\Documents and Settings\User\Local Settings\Application Data\Xenocode\ApplianceCaches\KumaClient.exe_v02D7169E\Native\STUBEXE\@PROGRAMFILES@\Kuma Games\Kuma.exe:*:Enabled:Kuma – File not found
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe" = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager – (Nexon)
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe – File not found
"C:\Nexon\Combat Arms\NMService.exe" = C:\Nexon\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core – File not found
"C:\WINDOWS\system32\lxdncoms.exe" = C:\WINDOWS\system32\lxdncoms.exe:*:Enabled:Lexmark Communications System – ( )
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnpswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnpswx.exe:*:Enabled:Printer Status Window Interface – ()
"C:\Program Files\Lexmark 2600 Series\lxdnmon.exe" = C:\Program Files\Lexmark 2600 Series\lxdnmon.exe:*:Enabled:Printer Device Monitor – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnjswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnjswx.exe:*:Enabled:Job Status Window Interface – ()
"C:\Program Files\Atari\Deer Hunter 2005\DH2005.exe" = C:\Program Files\Atari\Deer Hunter 2005\DH2005.exe:*:Enabled:DH2005 – File not found
"C:\Program Files\USArmy\America's Army 2\System\ArmyOps.exe" = C:\Program Files\USArmy\America's Army 2\System\ArmyOps.exe:*:Enabled:ArmyOps – File not found
"C:\Games\NGD Studios\Regnum Online\LiveServer\ROClientGame.exe" = C:\Games\NGD Studios\Regnum Online\LiveServer\ROClientGame.exe:*:Enabled:RegnumOnline – File not found
"C:\Program Files\USArmy\America's Army 2\System\Server.exe" = C:\Program Files\USArmy\America's Army 2\System\Server.exe:*:Enabled:Server – File not found
"C:\Program Files\Softnyx\RakionIS\Bin\rakion.bin" = C:\Program Files\Softnyx\RakionIS\Bin\rakion.bin:*:Enabled:rakion – File not found
"C:\AeriaGames\12Sky\TwelveSky.exe" = C:\AeriaGames\12Sky\TwelveSky.exe:*:Disabled:TwelveSky – File not found
"C:\WINDOWS\system32\lxdkcoms.exe" = C:\WINDOWS\system32\lxdkcoms.exe:*:Enabled:Lexmark Communications System – ( )
"C:\Program Files\Lexmark 5300 Series\lxdkamon.exe" = C:\Program Files\Lexmark 5300 Series\lxdkamon.exe:*:Enabled:Lexmark Device Monitor – ()
"C:\Program Files\Lexmark 5300 Series\frun.exe" = C:\Program Files\Lexmark 5300 Series\frun.exe:*:Enabled:Lexmark Productivity Studio – ()
"C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe" = C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:*:Enabled:ABBYY FineReader – File not found
"C:\Program Files\Lexmark 5300 Series\LXDKFax.exe" = C:\Program Files\Lexmark 5300 Series\LXDKFax.exe:*:Enabled:Fax software – ()
"C:\Program Files\Lexmark 5300 Series\lxdkmon.exe" = C:\Program Files\Lexmark 5300 Series\lxdkmon.exe:*:Enabled:Printer Device Monitor – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkpswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkpswx.exe:*:Enabled:Printer Status Window Interface – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdktime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdktime.exe:*:Enabled:Lexmark Connect Time Executable – (Lexmark International, Inc.)
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkjswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkjswx.exe:*:Enabled:Job Status Window Interface – ()
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online, Inc)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – File not found
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdntime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdntime.exe:*:Enabled:Lexmark Connect Time Executable – (Lexmark International, Inc.)
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnwbgw.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdnwbgw.exe:*:Enabled:Lexmark Web Gateway – ()
"C:\Program Files\Softnyx\WolfTeam\Wolfteam.bin" = C:\Program Files\Softnyx\WolfTeam\Wolfteam.bin:*:Enabled:WolfTeam – File not found
"C:\Alien Arena 7_32\crx.exe" = C:\Alien Arena 7_32\crx.exe:*:Enabled:crx – File not found
"C:\WINDOWS\Downloaded Program Files\ijjiOptimizer.exe" = C:\WINDOWS\Downloaded Program Files\ijjiOptimizer.exe:*:Enabled:ijjiOptimizer.exe – ()
"C:\ijji\ENGLISH\u_sf\soldierfront.exe" = C:\ijji\ENGLISH\u_sf\soldierfront.exe:*:Enabled:soldierfront – File not found
"C:\Program Files\ijji\ijji REACTOR\REACTOR.exe" = C:\Program Files\ijji\ijji REACTOR\REACTOR.exe:*:Enabled:Reactor Application – File not found
"C:\Program Files\Garena\Garena.exe" = C:\Program Files\Garena\Garena.exe:*:Enabled:Garena – File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Raptr\raptr.exe" = C:\Program Files\Raptr\raptr.exe:*:Enabled:Raptr Client – File not found
"C:\Program Files\Raptr\raptr_im.exe" = C:\Program Files\Raptr\raptr_im.exe:*:Enabled:Raptr IM – File not found
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – File not found
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – File not found
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*:Disabled:Combat Arms – File not found
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA – (BitTorrent, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{1881AE03-2BD4-11D4-86BF-00508B10AA88}" = Diagnostics for Windows
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1B602410-D983-4947-98FE-EE749073D15E}" = GamingHarbor Toolbar
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{388C130B-0079-46B4-A0D5-DC2DD7A89A7B}" = Citrix XenApp Plugin for Hosted Apps
"{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}" = Macromedia Flash MX
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{4CBD31CE-51DF-43C4-B3EC-7CCBAB0CD083}" = O2Micro MemoryCardBus Windows Driver
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
"{5C3DA2A1-03B2-44BD-B5AA-A44BD6E0C0C1}" = HP Integrated Wireless LAN W400-W500 Driver
"{5D97A4A7-C274-4B63-86D9-07A33435F505}" = InterVideo DVD Check
"{5E42E287-4CA5-4D59-931A-EE481817D073}" = arotkcursorset
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{71A470E1-27E7-424E-803A-F9C0D41968D3}" = Remote Diagnostics Enabling Agent
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7E20EFE6-E604-48C6-8B39-BA4742F2CDB4}" = Zune Desktop Theme
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{848AC794-8B81-440A-81AE-6474337DB527}" = Symantec AntiVirus
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{98177940-C048-4831-A279-F3888B1E2C7F}" = InstallMgr
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D6D76A6-4328-49E8-97A7-531A74841DA5}" = Microsoft SQL Server 2008 Setup Support Files (English)
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8AC89BA-D8CB-4372-9743-1C54D23286B0}" = MSN Toolbar
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{B668CB7B-A9DF-43B6-8876-A373A8E1D438}" = HP Mobile Printing
"{B6EF6DCE-078E-4952-A7FA-352A9C349EB0}" = MSN Toolbar
"{B7148D71-0A8F-4501-96B4-4E1CC67F874E}" = Microsoft Default Manager
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{B8B0FC8B-E69B-4215-AF1A-4BDFF20D794B}" = pdfforge Toolbar v1.0
"{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom Gigabit Integrated Controller
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEB326EC-8F40-47B2-BA22-BB092565D66F}" = Quick Launch Buttons 5.00 C2
"{D9461574-5FC0-4641-BBDC-D1038B196F55}" = Brother MFL-Pro Suite MFC-490CW
"{D9D937B0-E842-4130-9588-B948E876904A}" = Microsoft SQL Server 2008 Native Client
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F16F258A-6300-4A1C-BC49-7929EFF455E2}" = TIPCIxx20
"{F1DC7648-8623-442F-92B7-E118DF61872E}" = Microsoft SQL Server 2008 RsFx Driver
"{F2545484-7B1C-484A-89B8-B0F8B38BC67F}" = O2Micro SmartCardBus Reader Windows Driver Installer
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Agere Systems Soft Modem" = Agere Systems AC'97 Modem
"All ATI Software" = ATI - Software Uninstall Utility
"AOL Connectivity Services" = AOL Connectivity Services
"ATI Display Driver" = ATI Display Driver
"Ez_Themes Toolbar" = Ez_Themes Toolbar
"GamersFirst LIVE!" = GamersFirst LIVE!
"GamingHarbor Toolbar" = GamingHarbor Toolbar
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{4CBD31CE-51DF-43C4-B3EC-7CCBAB0CD083}" = O2Micro MemoryCardBus Windows Driver
"InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom Gigabit Integrated Controller
"InstallShield_{F16F258A-6300-4A1C-BC49-7929EFF455E2}" = Texas Instruments PCIxx20 drivers.
"IntMgmt" = Insight Management Agent
"Lexmark 2600 Series" = Lexmark 2600 Series
"Lexmark 5300 Series" = Lexmark 5300 Series
"LiveUpdate" = LiveUpdate 2.0 (Symantec Corporation)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Mozilla Firefox (3.5.11)" = Mozilla Firefox (3.5.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NSS" = Norton Security Scan
"OpenAL" = OpenAL
"PCSI" = Prevx
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 6.0" = RealPlayer Basic
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinNT Remote Services Deinstall Key" = Remote Services Driver
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"2a4f70b48f669acd" = AA3Deploy
"BitTorrent DNA" = DNA
"Google Chrome" = Google Chrome
"Move Media Player" = Move Media Player
"UnityWebPlayer" = Unity Web Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/16/2010 11:07:40 AM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Heuristic.ADH in File: C:\Documents and Settings\All
Users\Application Data\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\BED3DEFB\3E688669\stbasst.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: Heuristic.ADH in File: C:\Documents
and Settings\All Users\Application Data\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\mFileBagIDE.dll\bag\stbpx.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
Error - 10/16/2010 11:33:41 AM | Computer Name = USER-WSDRDFVS | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 10/16/2010 11:33:41 AM | Computer Name = USER-WSDRDFVS | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 10/16/2010 11:34:59 AM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
Error - 10/16/2010 12:42:56 PM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully.
Error - 10/16/2010 6:16:43 PM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
Error - 10/20/2010 7:42:46 PM | Computer Name = USER-WSDRDFVS | Source = MsiInstaller | ID = 1013
Description = Product: Citrix XenApp Plugin for Hosted Apps – At least one client
component is already in use. Before running Setup, please exit any of the following
programs that may be running: Program Neighborhood Citrix XenApp Plugin Program Neighborhood
Connection Center Remote Application Manager
Error - 10/20/2010 8:59:26 PM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
[ Application Events ]
Error - 10/16/2010 11:07:40 AM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Heuristic.ADH in File: C:\Documents and Settings\All
Users\Application Data\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\BED3DEFB\3E688669\stbasst.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: Heuristic.ADH in File: C:\Documents
and Settings\All Users\Application Data\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\mFileBagIDE.dll\bag\stbpx.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
Error - 10/16/2010 11:33:41 AM | Computer Name = USER-WSDRDFVS | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 10/16/2010 11:33:41 AM | Computer Name = USER-WSDRDFVS | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 10/16/2010 11:34:59 AM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
Error - 10/16/2010 12:42:56 PM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Scheduled scan. Action: Quarantine succeeded. Action Description: The file
was quarantined successfully.
Error - 10/16/2010 6:16:43 PM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
Error - 10/20/2010 7:42:46 PM | Computer Name = USER-WSDRDFVS | Source = MsiInstaller | ID = 1013
Description = Product: Citrix XenApp Plugin for Hosted Apps – At least one client
component is already in use. Before running Setup, please exit any of the following
programs that may be running: Program Neighborhood Citrix XenApp Plugin Program Neighborhood
Connection Center Remote Application Manager
Error - 10/20/2010 8:59:26 PM | Computer Name = USER-WSDRDFVS | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents and Settings\LocalService\Local
Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FGOPDTHM\upgrade[2].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully. Threat Found!Threat: SecurityRisk.ADH in File: C:\Documents
and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\UCILQOU4\upgrade[1].cab>>upgrade.exe
by: Manual scan. Action: Quarantine succeeded. Action Description: The file was
quarantined successfully.
[ System Events ]
Error - 10/20/2010 5:33:46 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SAVRT
Error - 10/20/2010 5:34:50 PM | Computer Name = USER-WSDRDFVS | Source = SAVRT | ID = 458772
Description = Unable to initialize the virus scanning engine database files.
Error - 10/20/2010 5:34:50 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7000
Description = The SAVRT service failed to start due to the following error: %%31
Error - 10/20/2010 6:10:06 PM | Computer Name = USER-WSDRDFVS | Source = SAVRT | ID = 458772
Description = Unable to initialize the virus scanning engine database files.
Error - 10/20/2010 6:10:31 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdkCATSCustConnectService
service to connect.
Error - 10/20/2010 6:10:31 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7000
Description = The lxdkCATSCustConnectService service failed to start due to the
following error: %%1053
Error - 10/20/2010 6:10:31 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7000
Description = The My Web Search Service service failed to start due to the following
error: %%3
Error - 10/20/2010 6:10:34 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SAVRT
Error - 10/20/2010 6:11:15 PM | Computer Name = USER-WSDRDFVS | Source = SAVRT | ID = 458772
Description = Unable to initialize the virus scanning engine database files.
Error - 10/20/2010 6:11:15 PM | Computer Name = USER-WSDRDFVS | Source = Service Control Manager | ID = 7000
Description = The SAVRT service failed to start due to the following error: %%31
< End of report >