Rootkit Log:
RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows XP
Version 5.1.2600 (Service Pack 2)
Number of processors #2
==============================================
>Drivers
==============================================
0xB92EE000 C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 6049792 bytes (Intel Corporation, Intel Graphics Miniport Driver)
0xB8E52000 C:\WINDOWS\system32\DRIVERS\NETw5x32.sys 4202496 bytes (Intel Corporation, Intel® Wireless WiFi Link Driver)
0xBF296000 C:\WINDOWS\System32\igxpdx32.DLL 3461120 bytes (Intel Corporation, DirectDraw® Driver for Intel® Graphics Technology)
0xBF058000 C:\WINDOWS\System32\igxpdv32.DLL 2351104 bytes (Intel Corporation, Component GHAL Driver)
0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2142208 bytes (Microsoft Corporation, NT Kernel & System)
0x804D7000 PnpManager 2142208 bytes
0x804D7000 RAW 2142208 bytes
0x804D7000 WMIxWDM 2142208 bytes
0xBF800000 Win32k 1851392 bytes
0xBF800000 C:\WINDOWS\System32\win32k.sys 1851392 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0xB8CC8000 C:\WINDOWS\system32\DRIVERS\btkrnl.sys 987136 bytes (Broadcom Corporation., Bluetooth Bus Enumerator)
0xA862A000 C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 987136 bytes (Conexant Systems, Inc., HSF_DP driver)
0xA8133000 C:\WINDOWS\System32\Drivers\dump_iaStor.sys 897024 bytes
0xB9D9F000 iaStor.sys 897024 bytes (Intel Corporation, Intel Matrix Storage Manager driver - ia32)
0xA8771000 C:\WINDOWS\system32\drivers\CHDAU32.sys 868352 bytes (Conexant Systems Inc., High Definition Audio Function Driver)
0xA8577000 C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 733184 bytes (Conexant Systems, Inc., HSF_CNXT driver)
0xA761A000 C:\WINDOWS\system32\Drivers\CVPNDRVA.sys 589824 bytes (Cisco Systems, Inc., Cisco Systems VPN Client IPSec Driver)
0xB9BE0000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)
0xA8389000 C:\WINDOWS\system32\drivers\csatdi.sys 471040 bytes (Cisco Systems, Inc., Cisco Security Agent component)
0xB8DE1000 C:\WINDOWS\System32\Drivers\wdf01000.sys 462848 bytes (Microsoft Corporation, Kernel Mode Driver Framework Runtime)
0xA8236000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 454656 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0xB9CAD000 CMGShCEF.sys 442368 bytes (CREDANT Technologies, Inc., CMG Shield for Windows Driver)
0xB9EED000 C:\WINDOWS\system32\DRIVERS\CmgCrypt.SYS 376832 bytes (CREDANT Technologies, Inc., Credant Cryptographic Library)
0xB9B57000 csacentr.sys 376832 bytes (Cisco Systems, Inc., Cisco Security Agent component)
0xB8B0D000 C:\WINDOWS\system32\DRIVERS\update.sys 364544 bytes (Microsoft Corporation, Update Driver)
0xA8424000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 360448 bytes (Microsoft Corporation, TCP/IP Protocol Driver)
0xA7343000 C:\WINDOWS\system32\DRIVERS\srv.sys 356352 bytes (Microsoft Corporation, Server driver)
0xB9A5C000 mfehidk.sys 335872 bytes (McAfee, Inc., McAfee Link Driver)
0xB9AE7000 csanet.sys 315392 bytes (Cisco Systems, Inc., Cisco Security Agent component)
0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
0xB929C000 C:\WINDOWS\system32\DRIVERS\e1y5132.sys 253952 bytes (Intel Corporation, Intel® Gigabit Network Connection NDIS 5.1 deserialized driver)
0xA871B000 C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 212992 bytes (Conexant Systems, Inc., HSF_HWAZL WDM driver)
0xBF024000 C:\WINDOWS\System32\igxpgd32.dll 212992 bytes (Intel Corporation, Intel Graphics 2D Driver)
0xB8BB1000 C:\WINDOWS\system32\DRIVERS\rdpdr.sys 200704 bytes (Microsoft Corporation, Microsoft RDP Device redirector)
0xB9F79000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT)
0xA82A5000 C:\WINDOWS\system32\DRIVERS\RCUVCMNP.sys 188416 bytes (Ricoh co.,Ltd., Ricoh UVC miniport driver)
0xB9BB3000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)
0xA78B2000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 180224 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0xA6648000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)
0xA82D3000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0xA8340000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)
0xB9EA8000 dmio.sys 155648 bytes (Microsoft Corp., Veritas Software, NT Disk Manager I/O Driver)
0xB9254000 C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 151552 bytes (Windows ® Server 2003 DDK provider, High Definition Audio Bus Driver v1.0a)
0xA6673000 C:\WINDOWS\system32\drivers\aec.sys 143360 bytes (Microsoft Corporation, Microsoft Acoustic Echo Canceller)
0xB9B34000 csafile.sys 143360 bytes (Cisco Systems, Inc., Cisco Security Agent component)
0xB8B66000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)
0xA6FB0000 C:\WINDOWS\System32\Drivers\RDPWD.SYS 143360 bytes (Microsoft Corporation, RDP Terminal Stack Driver (US/Canada Only, Not for Export))
0xB9279000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 143360 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0xA831E000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0xA874F000 C:\WINDOWS\system32\drivers\portcls.sys 139264 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0xA8368000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 135168 bytes (Microsoft Corporation, IP Network Address Translator)
0x806E2000 ACPI_HAL 134400 bytes
0x806E2000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0xB9D19000 fltMgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0xB9F49000 CmgHiber.sys 126976 bytes (CREDANT Technologies, Inc., CmgHiber Device Driver)
0xB9ECE000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver)
0xB9AC9000 Apsx86.sys 122880 bytes (Lenovo., Shockproof Disk Driver)
0xB8CAA000 C:\WINDOWS\system32\DRIVERS\dne2000.sys 122880 bytes (Deterministic Networks, Inc., Deterministic Network Enhancer)
0xB9AAE000 Mup.sys 110592 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0xB9D85000 nvata.sys 106496 bytes (NVIDIA Corporation, NVIDIA® nForce™ IDE Performance Driver)
0xB9D6B000 nvatabus.sys 106496 bytes (NVIDIA Corporation, NVIDIA® nForce™ IDE Performance Driver)
0xB9D39000 symmpi.sys 106496 bytes (LSI Corporation, LSI Fusion-MPT MiniPort Driver (ScsiPort))
0xB9E7A000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)
0xA7F4B000 C:\WINDOWS\System32\DLA\DLAIFS_M.SYS 98304 bytes (Roxio, Drive Letter Access Component)
0xB9D53000 C:\WINDOWS\system32\DRIVERS\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver)
0xA7E7E000 C:\WINDOWS\System32\DLA\DLAUDF_M.SYS 94208 bytes (Roxio, Drive Letter Access Component)
0xB9C84000 DRVMCDB.SYS 94208 bytes (Sonic Solutions, Device Driver)
0xB9C6D000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0xB8C93000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0xA7F35000 C:\WINDOWS\System32\DLA\DLAUDFAM.SYS 90112 bytes (Roxio, Drive Letter Access Component)
0xB9E92000 nvraid.sys 90112 bytes (NVIDIA Corporation, NVIDIA® nForce™ RAID Driver)
0xA37D9000 C:\WINDOWS\system32\drivers\mfeavfk.sys 86016 bytes (McAfee, Inc., Anti-Virus File System Filter Driver)
0xA6696000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)
0xB92DA000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)
0xA847C000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)
0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)
0xBF012000 C:\WINDOWS\System32\igxprd32.dll 73728 bytes (Intel Corporation, Intel Graphics 2D Rotation Driver)
0xB9C9B000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver)
0xA37EE000 C:\WINDOWS\system32\drivers\mfeapfk.sys 69632 bytes (McAfee, Inc., Access Protection Filter Driver)
0xB9F68000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0xB8BE2000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)
0xBA288000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver)
0xBA188000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0xA67FA000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)
0xBA178000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)
0xA8003000 C:\WINDOWS\system32\DRIVERS\LV_Tracker.sys 57344 bytes
0xB8C53000 C:\WINDOWS\system32\drivers\mfetdik.sys 57344 bytes (McAfee, Inc., Anti-Virus Mini-Firewall Driver)
0xA6932000 C:\WINDOWS\system32\drivers\swmidi.sys 57344 bytes (Microsoft Corporation, Microsoft GS Wavetable Synthesizer)
0xBA2B8000 C:\WINDOWS\system32\DRIVERS\WDFLDR.SYS 57344 bytes (Microsoft Corporation, Kernel Mode Driver Framework Loader)
0xBA0C8000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)
0xBA118000 csareg.sys 53248 bytes (Cisco Systems, Inc., Cisco Security Agent component)
0xA67CA000 C:\WINDOWS\system32\drivers\DMusic.sys 53248 bytes (Microsoft Corporation, Microsoft Kernel DLS Synthesizer)
0xBA298000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver)
0xBA2D8000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0xBA0D8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0xBA2F8000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0xB8C23000 C:\WINDOWS\system32\DRIVERS\STREAM.SYS 49152 bytes (Microsoft Corporation, WDM CODEC Class Device Driver 2.0)
0xBA128000 agp440.sys 45056 bytes (Microsoft Corporation, 440 NT AGP Filter)
0xBA2C8000 C:\WINDOWS\system32\DRIVERS\css_drv.sys 45056 bytes (Cisco Systems, Inc., Cisco Secure Services Driver)
0xBA248000 C:\WINDOWS\System32\Drivers\DRVNDDM.SYS 45056 bytes (Roxio, Device Driver Manager)
0xBA0B8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)
0xBA2E8000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0xBA0F8000 CmgShREG.sys 40960 bytes (CREDANT Technologies, Inc., CMG Shield for Windows Driver)
0xBA278000 C:\WINDOWS\system32\DRIVERS\HECI.sys 40960 bytes (Intel Corporation, Intel® Management Engine Interface)
0xBA158000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)
0xBA108000 PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0xBA318000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)
0xBA2A8000 C:\WINDOWS\system32\DRIVERS\tp4track.sys 40960 bytes (Lenovo Group Limited, PS/2 TrackPoint Mouse Filter Driver)
0xBA0E8000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)
0xB8C03000 C:\WINDOWS\System32\Drivers\Fips.SYS 36864 bytes (Microsoft Corporation, FIPS Crypto Driver)
0xBA1C8000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver)
0xBA0A8000 isapnp.sys 36864 bytes (Microsoft Corporation, PNP ISA Bus Driver)
0xBA308000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)
0xB8C43000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)
0xA68DA000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0xB8C63000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0xBA350000 ApsHM86.sys 32768 bytes (Lenovo., ThinkVantage Active Protection System HID Digitizer Activity Monitor Driver)
0xBA460000 C:\WINDOWS\system32\DRIVERS\btport.sys 32768 bytes (Broadcom Corporation., Bluetooth BTPORT Driver for Windows 2000)
0xBA3A0000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver)
0xBA338000 msvmscsi.sys 32768 bytes (Microsoft Corporation, Virtual Machine SCSI Miniport Driver)
0xBA430000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)
0xBA488000 C:\WINDOWS\System32\Drivers\CCDevice.SYS 28672 bytes (Altiris, Carbon Copy Kernel mode Driver)
0xBA360000 C:\WINDOWS\System32\DLA\DLABMFSM.SYS 28672 bytes (Roxio, Drive Letter Access Component)
0xBA390000 C:\WINDOWS\System32\DLA\DLABOIOM.SYS 28672 bytes (Roxio, Drive Letter Access Component)
0xBA3F8000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
0xBA328000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0xBA458000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 28672 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0xBA3E0000 C:\WINDOWS\System32\Drivers\DLARTL_M.SYS 24576 bytes (Roxio, Shared Driver Component)
0xBA380000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver)
0xBA480000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver)
0xA80BB000 C:\WINDOWS\System32\Drivers\TDTCP.SYS 24576 bytes (Microsoft Corporation, TCP Transport Driver)
0xBA408000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0xA80D3000 C:\WINDOWS\System32\DLA\DLAOPIOM.SYS 20480 bytes (Roxio, Drive Letter Access Component)
0xBA348000 DozeHDD.sys 20480 bytes (Lenovo., Doze Mode Kernel Driver for HDD control)
0xBA490000 C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys 20480 bytes (Lenovo., ThinkPad Power Management Driver)
0xBA3D0000 C:\WINDOWS\system32\DRIVERS\iPassP.sys 20480 bytes (Cisco Systems, Inc., IEEE 802.1X Protocol Driver)
0xBA340000 megasas.sys 20480 bytes (LSI Corporation, MEGASAS RAID Controller Driver for XP 32)
0xBA418000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)
0xBA330000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)
0xBA370000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)
0xBA388000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver)
0xBA4A0000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)
0xBA400000 C:\WINDOWS\system32\DRIVERS\TPHKDRV.sys 20480 bytes (Lenovo Group Limited, ThinkPad Hotkey Driver)
0xBA3E8000 C:\WINDOWS\System32\drivers\Tppwrif.sys 20480 bytes
0xBA3D8000 C:\WINDOWS\System32\drivers\TSMAPIP.SYS 20480 bytes
0xBA428000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 20480 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0xBA450000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)
0xBA4C0000 C:\WINDOWS\system32\DRIVERS\BATTC.SYS 16384 bytes (Microsoft Corporation, Battery Class Driver)
0xB98E7000 C:\WINDOWS\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0xA72DF000 C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 16384 bytes (Conexant, Diagnostic Interface x86 Driver)
0xB991B000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)
0xA7D56000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)
0xB9923000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator)
0xB98F3000 C:\WINDOWS\system32\DRIVERS\tpm.sys 16384 bytes (Intel Corporation, Intel® Trusted Platform Module Driver)
0xBA4C4000 ACPIEC.sys 12288 bytes (Microsoft Corporation, ACPI Embedded Controller Driver)
0xB991F000 C:\WINDOWS\System32\drivers\ANC.SYS 12288 bytes (IBM Corp., IBM Access Connections - ANC)
0xBA4B8000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)
0xBA4BC000 compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)
0xA8418000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)
0xB98C3000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0xB98BF000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0xA7B62000 C:\WINDOWS\system32\DRIVERS\s24trans.sys 12288 bytes (Intel Corporation, Intel WLAN Packet Driver)
0xBA4C8000 vmscsi.sys 12288 bytes (VMware, Inc., VMware SCSI Controller Driver)
0xB98D7000 C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 12288 bytes (Microsoft Corporation, Windows Management Interface for ACPI)
0xBA5AC000 aliide.sys 8192 bytes (Acer Laboratories Inc., ALi mini IDE Driver)
0xBA608000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)
0xBA5AE000 cmdide.sys 8192 bytes (CMD Technology, Inc., CMD PCI IDE Bus Driver)
0xBA600000 C:\WINDOWS\System32\Drivers\DLACDBHM.SYS 8192 bytes (Roxio, Shared Driver Component)
0xBA668000 C:\WINDOWS\System32\DLA\DLAPoolM.SYS 8192 bytes (Roxio, Drive Letter Access Component)
0xBA5B6000 dmload.sys 8192 bytes (Microsoft Corp., Veritas Software., NT Disk Manager Startup Driver)
0xBA604000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)
0xBA61A000 C:\WINDOWS\system32\Drivers\IBMBLDID.sys 8192 bytes
0xBA5B4000 intelide.sys 8192 bytes (Microsoft Corporation, Intel PCI IDE Driver)
0xBA5A8000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0xBA60C000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)
0xBA610000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)
0xBA5E0000 C:\WINDOWS\system32\DRIVERS\serscan.sys 8192 bytes (Microsoft Corporation, Serial Imaging Device Driver)
0xBA61C000 C:\WINDOWS\system32\drivers\splitter.sys 8192 bytes (Microsoft Corporation, Microsoft Kernel Audio Splitter)
0xBA5E6000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0xBA5B0000 toside.sys 8192 bytes (Microsoft Corporation, Toshiba PCI IDE Controller)
0xBA5F2000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
0xBA5B2000 viaide.sys 8192 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)
0xBA5AA000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0xBA706000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)
0xBA7B9000 C:\WINDOWS\System32\DLA\DLADResM.SYS 4096 bytes (Roxio, Drive Letter Access Component)
0xBA7A2000 C:\WINDOWS\system32\drivers\drmkaud.sys 4096 bytes (Microsoft Corporation, Microsoft Kernel DRM Audio Descrambler Filter)
0xBA76C000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)
0xBA77F000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)
0xBA671000 C:\WINDOWS\system32\DRIVERS\OPRGHDLR.SYS 4096 bytes (Microsoft Corporation, ACPI Operation Registration Driver)
0xBA670000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)
==============================================
>Stealth
==============================================
0x051C0000 Hidden Image–>PWMUIAux.resources.dll [ EPROCESS 0x85079948 ] PID: 3392, 102400 bytes
0x04F20000 Hidden Image–>UIAutomationTypes.dll [ EPROCESS 0x85079948 ] PID: 3392, 110592 bytes
0x04800000 Hidden Image–>WindowsBase.dll [ EPROCESS 0x85079948 ] PID: 3392, 1257472 bytes
0x04060000 Hidden Image–>PWMUICtl.DLL [ EPROCESS 0x85079948 ] PID: 3392, 1449984 bytes
0x04E30000 Hidden Image–>System.Printing.dll [ EPROCESS 0x85079948 ] PID: 3392, 364544 bytes
0x04940000 Hidden Image–>PresentationCore.dll [ EPROCESS 0x85079948 ] PID: 3392, 4206592 bytes
0x04F40000 Hidden Image–>PresentationCFFRasterizer.dll [ EPROCESS 0x85079948 ] PID: 3392, 45056 bytes
0x04270000 Hidden Image–>msvcm80.dll [ EPROCESS 0x85079948 ] PID: 3392, 507904 bytes
0x042F0000 Hidden Image–>PresentationFramework.dll [ EPROCESS 0x85079948 ] PID: 3392, 5296128 bytes
0x04260000 Hidden Image–>UIAutomationProvider.dll [ EPROCESS 0x85079948 ] PID: 3392, 53248 bytes
0x04E90000 Hidden Image–>ReachFramework.dll [ EPROCESS 0x85079948 ] PID: 3392, 536576 bytes
0xA6A9F6E8 Unknown thread object [ ETHREAD 0x851FB020 ] , 600 bytes
0x04D50000 Hidden Image–>PresentationUI.dll [ EPROCESS 0x85079948 ] PID: 3392, 872448 bytes
OTL Log:
OTL logfile created on: 12/21/2010 9:01:40 PM - Run 1
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Documents and Settings\mauvaidy\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 44.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 2914 2914 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 35.75 Gb Free Space | 23.99% Space Free | Partition Type: NTFS
Computer Name: MAUVAIDY-WXP | User Name: mauvaidy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\mauvaidy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\WebEx\Connect\wbxcOIEx.exe (WebEx)
PRC - C:\Program Files\WebEx\Connect\connect.exe (Cisco WebEx)
PRC - C:\WINDOWS\system32\EmsServiceHelper.exe (CREDANT Technologies, Inc.)
PRC - C:\WINDOWS\system32\EmsService.exe (CREDANT Technologies, Inc.)
PRC - C:\WINDOWS\system32\CmgShieldSvc.exe (CREDANT Technologies, Inc.)
PRC - C:\WINDOWS\system32\CmgShieldUI.exe (CREDANT Technologies, Inc.)
PRC - C:\Program Files\Cisco\CSAgent\bin\csacontrol.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Cisco\CSAgent\bin\leventmgr.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Cisco\CSAgent\bin\dcgate.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Cisco\CSAgent\bin\okclient.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
PRC - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
PRC - C:\Program Files\WebEx\Productivity Tools\ptSrv.exe (Cisco WebEx LLC)
PRC - C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe (Cisco WebEx LLC)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
PRC - C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe (Lenovo )
PRC - C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Lenovo Group Limited)
PRC - C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe (Altiris, Inc.)
PRC - C:\Program Files\Altiris\Altiris Agent\AeXAgentUIHost.exe (Altiris, Inc.)
PRC - C:\Program Files\Lenovo\TrackPoint\tp4serv.exe (Lenovo Group Limited)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe (McAfee, Inc.)
PRC - C:\Program Files\Iron Mountain\Connected BackupPC\AgentService.exe (Iron Mountain Incorporated)
PRC - C:\Program Files\Iron Mountain\Connected BackupPC\Agent.exe (Iron Mountain Incorporated)
PRC - C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe (Lenovo Group Limited)
PRC - C:\WINDOWS\system32\ibmpmsvc.exe (Lenovo)
PRC - C:\Program Files\SpybotS&D;\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\Mctray.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
PRC - C:\Program Files\RotateImage\RCIMGDIR.exe (Ricoh co.,Ltd.)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\WINDOWS\system32\TpShocks.exe (Lenovo.)
PRC - C:\WINDOWS\system32\TPHDEXLG.exe (Lenovo.)
PRC - C:\Program Files\Cisco\Cisco Secure Services Client\Cisco_SSCgui.exe ()
PRC - C:\Program Files\Cisco\Cisco Secure Services Client\Cisco_SSCservice.exe ()
PRC - C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe (iPass, Inc.)
PRC - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe (iPass, Inc.)
PRC - C:\Program Files\Cisco Systems\CEPS\CEPSWatch.exe (Cisco Systems)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\WINDOWS\system32\HPZinw12.exe (HP)
PRC - C:\Program Files\Altiris\Carbon Copy\Client.exe (Altiris)
PRC - C:\Program Files\Altiris\Carbon Copy\ShellKer.exe (Altiris)
PRC - C:\WINDOWS\system32\CCSRVC.exe (Altiris)
PRC - C:\WINDOWS\system32\TaskSwitch.exe ()
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\mauvaidy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\csauser.dll (Cisco Systems, Inc.)
MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)
MOD - C:\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\WINDOWS\system32\csadetoured.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\AMInit32.dll (Altiris, Inc.)
MOD - C:\Program Files\Lenovo\HOTKEY\HKVOLKEY.dll (Lenovo Group Limited)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (SessionLauncher) – C:\DOCUME~1\mauvaidy\LOCALS~1\Temp\DX9\SessionLauncher.exe File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (EMS) – C:\WINDOWS\System32\EmsService.exe (CREDANT Technologies, Inc.)
SRV - (CMGShield) – C:\WINDOWS\system32\CmgShieldSvc.exe (CREDANT Technologies, Inc.)
SRV - (CSAgent) – C:\Program Files\Cisco\CSAgent\bin\CSAControl.exe (Cisco Systems, Inc.)
SRV - (btwdins) – C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (DozeSvc) – C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE (Lenovo.)
SRV - (Power Manager DBC Service) – C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe ()
SRV - (AcSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (Lenovo )
SRV - (AcPrfMgrSvc) – C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe (Lenovo )
SRV - (LENOVO.CAMMUTE) – C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Lenovo Group Limited)
SRV - (AeXNSClient) – C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe (Altiris, Inc.)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe (McAfee, Inc.)
SRV - (mfevtp) – C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McTaskManager) – C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
SRV - (McAfeeEngineService) – C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe (McAfee, Inc.)
SRV - (AgentService) – C:\Program Files\Iron Mountain\Connected BackupPC\AgentService.exe (Iron Mountain Incorporated)
SRV - (IBMPMSVC) – C:\WINDOWS\system32\ibmpmsvc.exe (Lenovo)
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\WiFi\bin\WLKEEPER.exe (Intel® Corporation)
SRV - (S24EventMonitor) – C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (CVPND) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (TPHDEXLGSVC) – C:\WINDOWS\system32\TPHDEXLG.exe (Lenovo.)
SRV - (Cisco Secure Services Client) – C:\Program Files\Cisco\Cisco Secure Services Client\Cisco_SSCservice.exe ()
SRV - (iPassConnectEngine) – C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe (iPass, Inc.)
SRV - (RoxMediaDB10) – C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (iPassPeriodicUpdateApp) – C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe (iPass, Inc.)
SRV - (iPassPeriodicUpdateService) – C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe (iPass, Inc.)
SRV - (CEPS Watch) – C:\Program Files\Cisco Systems\CEPS\CEPSWatch.exe (Cisco Systems)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (CarbonCopyScheduler) – C:\WINDOWS\system32\SchdSrvc.exe (Altiris)
SRV - (CarbonCopy32) – C:\WINDOWS\system32\CCSRVC.exe (Altiris)
========== Driver Services (SafeList) ==========
DRV - (PCASp50) – C:\WINDOWS\System32\Drivers\PCASp50.sys File not found
DRV - (CmgShieldNP) – C:\WINDOWS\system32\CmgShieldNP.dll (CREDANT Technologies, Inc.)
DRV - (CmgShieldCEF) – C:\WINDOWS\system32\DRIVERS\CMGShCEF.sys (CREDANT Technologies, Inc.)
DRV - (CmgHiber) – C:\WINDOWS\system32\DRIVERS\CmgHiber.sys (CREDANT Technologies, Inc.)
DRV - (CMGShieldReg) – C:\WINDOWS\system32\DRIVERS\CmgShREG.sys (CREDANT Technologies, Inc.)
DRV - (iPassP) iPass Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\iPassP.sys (Cisco Systems, Inc.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (csanet) – C:\WINDOWS\system32\drivers\csanet.sys (Cisco Systems, Inc.)
DRV - (csatdi) – C:\WINDOWS\system32\drivers\csatdi.sys (Cisco Systems, Inc.)
DRV - (csareg) – C:\WINDOWS\system32\drivers\csareg.sys (Cisco Systems, Inc.)
DRV - (csafile) – C:\WINDOWS\system32\drivers\csafile.sys (Cisco Systems, Inc.)
DRV - (csacenter) – C:\WINDOWS\system32\drivers\csacentr.sys (Cisco Systems, Inc.)
DRV - (DozeHDD) – C:\WINDOWS\System32\DRIVERS\DozeHDD.sys (Lenovo.)
DRV - (TPPWRIF) – C:\WINDOWS\system32\drivers\TPPWRIF.SYS ()
DRV - (CnxtHdAudService) – C:\WINDOWS\system32\drivers\CHDAU32.sys (Conexant Systems Inc.)
DRV - (Netaapl) – C:\WINDOWS\system32\drivers\netaapl.sys (Apple Inc.)
DRV - (Tp4Track) – C:\WINDOWS\system32\drivers\tp4track.sys (Lenovo Group Limited)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdik) – C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (LV_Tracker) – C:\WINDOWS\system32\drivers\LV_Tracker.sys ()
DRV - (5U875UVC) – C:\WINDOWS\system32\drivers\RCUVCMNP.sys (Ricoh co.,Ltd.)
DRV - (TSMAPIP) – C:\WINDOWS\system32\drivers\TSMAPIP.SYS ()
DRV - (vmscsi) – C:\WINDOWS\system32\DRIVERS\vmscsi.sys (VMware, Inc.)
DRV - (IBMPMDRV) – C:\WINDOWS\system32\drivers\ibmpmdrv.sys (Lenovo.)
DRV - (NETw5x32) Intel® – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (iaStor) – C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (e1yexpress) Intel® – C:\WINDOWS\system32\drivers\e1y5132.sys (Intel Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (vmx_svga) – C:\WINDOWS\system32\drivers\vmx_svga.sys (VMware, Inc.)
DRV - (megasas) – C:\WINDOWS\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (CVPNDRVA) – C:\WINDOWS\system32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (Shockprf) – C:\WINDOWS\System32\DRIVERS\Apsx86.sys (Lenovo.)
DRV - (TPDIGIMN) – C:\WINDOWS\System32\DRIVERS\ApsHM86.sys (Lenovo.)
DRV - (TPHKDRV) – C:\WINDOWS\system32\drivers\TPHKDRV.sys (Lenovo Group Limited)
DRV - (IBMTPCHK) – C:\WINDOWS\system32\drivers\IBMBLDID.sys ()
DRV - (CiscoSSD) – C:\WINDOWS\system32\drivers\css_drv.sys (Cisco Systems, Inc.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (Symmpi) – C:\WINDOWS\system32\DRIVERS\symmpi.sys (LSI Corporation)
DRV - (DNE) – C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (tpm) – C:\WINDOWS\system32\drivers\tpm.sys (Intel Corporation)
DRV - (HECI) Intel® – C:\WINDOWS\system32\drivers\HECI.sys (Intel Corporation)
DRV - (msvmscsi) – C:\WINDOWS\system32\DRIVERS\msvmscsi.sys (Microsoft Corporation)
DRV - (DLADResM) – C:\WINDOWS\system32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (nvraid) NVIDIA nForce™ – C:\WINDOWS\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nvatabus) – C:\WINDOWS\system32\DRIVERS\nvatabus.sys (NVIDIA Corporation)
DRV - (DRVMCDB) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DRVNDDM) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (CVirtA) – C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (nvata) – C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (ANC) – C:\WINDOWS\system32\drivers\ANC.sys (IBM Corp.)
DRV - (CCDevice) – C:\WINDOWS\System32\drivers\CCDevice.sys (Altiris)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (es1371) Creative AudioPCI (ES1371,ES1373) (WDM) – C:\WINDOWS\system32\drivers\es1371mp.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://wwwin.cisco.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/06 14:11:35 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/22 05:06:37 | 000,000,000 | —D | M]
[2010/07/06 20:53:40 | 000,000,000 | —D | M] – C:\Documents and Settings\mauvaidy\Application Data\Mozilla\Extensions
[2010/07/14 10:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\mauvaidy\Application Data\Mozilla\Firefox\Profiles\f1vbqquq.default\extensions
[2010/07/06 20:52:45 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/25 05:23:16 | 000,101,760 | —- | M] (Cisco WebEx LLC) – C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll
[2010/05/25 05:23:28 | 000,064,384 | —- | M] (Cisco WebEx LLC) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2007/10/10 20:54:00 | 000,368,701 | —- | M] (Cisco Systems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npvw32.dll
O1 HOSTS File: ([2010/12/18 11:44:17 | 000,427,654 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-domains-registrations.com
O1 - Hosts: 127.0.0.1 www.1-domains-registrations.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 14727 more lines…
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\SpybotS&D;\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files\WebEx\Productivity Tools\ptonecli.dll (Cisco WebEx LLC)
O3 - HKLM\..\Toolbar: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files\WebEx\Productivity Tools\ptonecli.dll (Cisco WebEx LLC)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AeXAgentLogon] C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe (Altiris, Inc.)
O4 - HKLM..\Run: [AgentUiRunKey] C:\Program Files\Iron Mountain\Connected BackupPC\Agent.exe (Iron Mountain Incorporated)
O4 - HKLM..\Run: [CiscoCSSCgui] C:\Program Files\Cisco\Cisco Secure Services Client\Cisco_SSCgui.exe ()
O4 - HKLM..\Run: [CmgShieldUI] C:\WINDOWS\system32\CmgShieldUI.exe (CREDANT Technologies, Inc.)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [EmsService] C:\WINDOWS\System32\EmsServiceHelper.exe (CREDANT Technologies, Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PWRMGRTR] C:\Program Files\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [RotateImage] C:\Program Files\RotateImage\RCIMGDIR.exe (Ricoh co.,Ltd.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4 - HKLM..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TpShocks] C:\WINDOWS\System32\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [TrackPointSrv] C:\Program Files\Lenovo\TrackPoint\tp4serv.exe (Lenovo Group Limited)
O4 - HKCU..\Run: [Cisco WebEx Connect] C:\Program Files\WebEx\Connect\connect.exe (Cisco WebEx)
O4 - HKCU..\Run: [PTOneClick] C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe (Cisco WebEx LLC)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\SpybotS&D;\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Cisco Security Agent.lnk = C:\Program Files\Cisco\CSAgent\bin\okclient.exe (Cisco Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Manage Printers.lnk = C:\Program Files\Cisco Systems\CEPS\AddPrinter.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk = C:\WINDOWS\Installer\{A7091E1D-36A4-47F1-A739-173CC341414F}\Icon3E5562ED7.ico ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: UseDesktopIniCache = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteChangeNotify = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartRunNoHOMEPATH = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDetailsThumbnailOnNetwork = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\SpybotS&D;\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: cisco.com ([]* in Local intranet)
O15 - HKLM\..Trusted Domains: cisco.com ([]http in Local intranet)
O15 - HKLM\..Trusted Domains: cisco.com ([]https in Local intranet)
O15 - HKLM\..Trusted Domains: cisco.com ([www] http in Trusted sites)
O15 - HKLM\..Trusted Domains: cisco.com ([www] https in Trusted sites)
O15 - HKLM\..Trusted Domains: cisco.com ([wwwin] http in Trusted sites)
O15 - HKLM\..Trusted Domains: cisco.com ([wwwin] https in Trusted sites)
O15 - HKLM\..Trusted Domains: cisco.com ([wwwin-asiapac] http in Trusted sites)
O15 - HKLM\..Trusted Domains: cisco.com ([wwwin-asiapac] https in Trusted sites)
O15 - HKLM\..Trusted Domains: cisco.com ([wwwin-emea] http in Trusted sites)
O15 - HKLM\..Trusted Domains: cisco.com ([wwwin-emea] https in Trusted sites)
O15 - HKLM\..Trusted Domains: linksys.com ([]* in Trusted sites)
O15 - HKLM\..Trusted Domains: scientificatlanta.com ([]* in Trusted sites)
O15 - HKLM\..Trusted Domains: webex.com ([]* in Trusted sites)
O15 - HKLM\..Trusted Domains: webex.com ([]http in Local intranet)
O15 - HKLM\..Trusted Domains: webex.com ([]https in Local intranet)
O15 - HKCU\..Trusted Domains: cisco.com ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: cisco.com ([www] * in Local intranet)
O15 - HKCU\..Trusted Domains: cisco.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: cisco.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: cisco.com ([wwwin] * in Local intranet)
O15 - HKCU\..Trusted Domains: cisco.com ([wwwin] http in Trusted sites)
O15 - HKCU\..Trusted Domains: cisco.com ([wwwin] https in Trusted sites)
O15 - HKCU\..Trusted Domains: cisco.com ([wwwin-asiapac] http in Trusted sites)
O15 - HKCU\..Trusted Domains: cisco.com ([wwwin-asiapac] https in Trusted sites)
O15 - HKCU\..Trusted Domains: cisco.com ([wwwin-emea] * in Local intranet)
O15 - HKCU\..Trusted Domains: cisco.com ([wwwin-emea] http in Trusted sites)
O15 - HKCU\..Trusted Domains: cisco.com ([wwwin-emea] https in Trusted sites)
O15 - HKCU\..Trusted Domains: linksys.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: scientificatlanta.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: webex.com ([]* in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/windowsupd…b?1235100574953 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = cisco.com
O20 - AppInit_DLLs: (AMINIT32.dll) - C:\WINDOWS\System32\AMInit32.dll (Altiris, Inc.)
O20 - AppInit_DLLs: (csauser.dll) - C:\WINDOWS\System32\csauser.dll (Cisco Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (tvt_gina.dll) - C:\WINDOWS\System32\tvt_gina.dll (Lenovo)
O20 - Winlogon\Notify\ACNotify: DllName - ACNotify.dll - C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll (Lenovo )
O20 - Winlogon\Notify\CMGShieldNP: DllName - CmgShieldNP.dll - C:\WINDOWS\System32\CmgShieldNP.dll (CREDANT Technologies, Inc.)
O20 - Winlogon\Notify\csscsso: DllName - csscsso.dll - C:\WINDOWS\System32\csscsso.dll (Cisco Systems Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\tpfnf2: DllName - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - C:\Program Files\Lenovo\HOTKEY\tphklock.dll - C:\Program Files\Lenovo\HOTKEY\tphklock.dll (Lenovo Group Limited)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/19 22:24:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{439dc063-c711-11df-999d-904ce5dbd6f1}\Shell\AutoRun\command - "" = D:\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/12/21 20:57:36 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\mauvaidy\Desktop\OTL.exe
[2010/12/20 09:07:40 | 000,000,000 | —D | C] – C:\Documents and Settings\mauvaidy\Local Settings\Application Data\Cisco
[2010/12/20 08:57:51 | 000,000,000 | —D | C] – C:\Documents and Settings\mauvaidy\Application Data\Cisco
[2010/12/20 08:56:45 | 000,000,000 | —D | C] – C:\Documents and Settings\mauvaidy\Local Settings\Application Data\Downloaded Installations
[2010/12/17 23:04:47 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/12/16 09:50:21 | 000,000,000 | —D | C] – C:\Documents and Settings\mauvaidy\My Documents\MyConnectFiles
[2010/12/10 09:50:34 | 000,000,000 | —D | C] – C:\Documents and Settings\mauvaidy\Application Data\GSplit
[2010/12/10 09:50:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\GSplit
[2010/12/10 09:50:28 | 000,000,000 | —D | C] – C:\Program Files\GSplit
[2010/12/04 17:44:28 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2010/12/01 12:12:25 | 000,000,000 | —D | C] – C:\Documents and Settings\mauvaidy\Desktop\Network Proximity
[2010/11/28 11:23:10 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/11/28 11:23:07 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/11/28 11:09:51 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Apple Computer
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/21 21:16:01 | 000,000,990 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1303643608-725345543-760804UA.job
[2010/12/21 20:57:37 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\mauvaidy\Desktop\OTL.exe
[2010/12/21 20:55:06 | 000,133,632 | —- | M] () – C:\Documents and Settings\mauvaidy\Desktop\RKUnhookerLE.EXE
[2010/12/21 20:48:07 | 000,002,447 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
[2010/12/21 20:47:53 | 000,000,306 | —- | M] () – C:\WINDOWS\tasks\PMTask.job
[2010/12/21 20:46:44 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/21 20:29:37 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/12/21 20:29:30 | 2038,439,936 | -HS- | M] () – C:\hiberfil.sys
[2010/12/21 15:42:28 | 000,002,021 | —- | M] () – C:\Documents and Settings\mauvaidy\Application Data\Microsoft\Internet Explorer\Quick Launch\CUPC.lnk
[2010/12/21 14:16:04 | 000,000,938 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1303643608-725345543-760804Core.job
[2010/12/20 10:21:41 | 000,031,744 | —- | M] () – C:\Documents and Settings\mauvaidy\Desktop\Advisory_101210.doc
[2010/12/18 20:04:09 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/12/18 11:44:17 | 000,427,654 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/12/17 09:48:17 | 000,002,412 | RHS- | M] () – C:\Documents and Settings\All Users\ntuser.pol
[2010/12/17 09:05:35 | 000,002,283 | —- | M] () – C:\Documents and Settings\mauvaidy\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2010/12/16 18:40:37 | 000,004,711 | —- | M] () – C:\Documents and Settings\mauvaidy\wincmd.ini
[2010/12/16 18:14:51 | 000,001,946 | —- | M] () – C:\Documents and Settings\mauvaidy\wcx_ftp.ini
[2010/12/15 19:50:07 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/12/15 09:21:16 | 012,852,129 | —- | M] () – C:\Documents and Settings\mauvaidy\Desktop\24837-050.zip
[2010/12/09 09:52:11 | 000,426,910 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20101218-114417.backup
[2010/12/08 09:01:06 | 000,000,165 | —- | M] () – C:\WINDOWS\setup.iss
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/21 20:55:06 | 000,133,632 | —- | C] () – C:\Documents and Settings\mauvaidy\Desktop\RKUnhookerLE.EXE
[2010/12/21 15:42:28 | 000,002,021 | —- | C] () – C:\Documents and Settings\mauvaidy\Application Data\Microsoft\Internet Explorer\Quick Launch\CUPC.lnk
[2010/12/20 10:21:45 | 000,031,744 | —- | C] () – C:\Documents and Settings\mauvaidy\Desktop\Advisory_101210.doc
[2010/12/20 08:56:47 | 002,461,254 | —- | C] () – C:\Program Files\Common Files\UnifiedClientInstall.log
[2010/12/18 11:19:31 | 001,828,288 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/12/15 09:18:23 | 012,852,129 | —- | C] () – C:\Documents and Settings\mauvaidy\Desktop\24837-050.zip
[2010/12/13 13:04:32 | 000,002,283 | —- | C] () – C:\Documents and Settings\mauvaidy\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2010/10/27 09:26:53 | 000,000,146 | —- | C] () – C:\Documents and Settings\mauvaidy\Local Settings\Application Data\Settings.ini
[2010/10/08 11:31:16 | 000,000,162 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/09/02 18:33:12 | 000,005,120 | —- | C] () – C:\Documents and Settings\mauvaidy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/26 16:03:38 | 000,004,224 | —- | C] () – C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2010/07/26 15:23:22 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2010/07/26 15:23:22 | 000,000,118 | —- | C] () – C:\WINDOWS\wininit.ini
[2010/07/26 15:14:11 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2010/07/26 15:14:11 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2010/07/26 15:14:11 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2010/07/26 15:14:11 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2010/07/26 15:14:11 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2010/07/26 15:14:11 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2010/07/06 16:59:06 | 000,004,096 | -H– | C] () – C:\Documents and Settings\mauvaidy\Local Settings\Application Data\keyfile3.drm
[2010/06/29 15:43:12 | 000,000,280 | —- | C] () – C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2010/06/28 16:58:45 | 000,037,928 | —- | C] () – C:\Documents and Settings\mauvaidy\Application Data\Comma Separated Values (Windows).ADR
[2010/06/28 08:39:34 | 000,000,000 | —- | C] () – C:\WINDOWS\client.INI
[2010/06/26 17:08:59 | 000,000,167 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2010/06/26 17:08:22 | 000,000,686 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2010/06/26 16:50:55 | 000,002,553 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/06/26 16:50:30 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2010/06/25 13:04:25 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\wisenet.dll
[2010/06/23 09:35:19 | 000,004,608 | —- | C] () – C:\WINDOWS\System32\drivers\TSMAPIP.SYS
[2010/06/23 09:34:27 | 000,004,442 | —- | C] () – C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2010/06/23 09:29:52 | 000,079,360 | —- | C] () – C:\WINDOWS\System32\CEPSProvidor.dll
[2010/05/25 09:57:38 | 002,860,384 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2009/12/18 13:17:58 | 000,045,384 | —- | C] () – C:\WINDOWS\System32\drivers\LV_Tracker.sys
[2009/11/13 20:10:26 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\atonres.dll
[2009/11/13 20:10:26 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\WbxMSAI.dll
[2009/11/13 20:10:26 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\atonecli.dll
[2009/11/13 20:10:26 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\WbxRMenu.dll
[2009/06/09 17:00:34 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/05/08 14:34:19 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v5002.dll
[2009/02/19 17:19:34 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/12/02 16:09:10 | 000,888,832 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2008/12/02 16:09:10 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2008/12/02 16:09:06 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\depends.dll
[2008/12/02 16:08:26 | 000,003,256 | —- | C] () – C:\WINDOWS\System32\OemInfo.ini
[2008/06/19 17:08:52 | 000,197,408 | —- | C] () – C:\WINDOWS\System32\vpnapi.dll
[2008/06/19 17:08:44 | 000,193,312 | —- | C] () – C:\WINDOWS\System32\CSGina.dll
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2005/05/19 09:39:48 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/01/09 19:34:36 | 000,018,925 | —- | C] () – C:\WINDOWS\iptv.ini
[2002/03/06 14:08:24 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\ssm.dll
[2001/11/14 12:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[2001/07/07 02:00:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2010/06/23 09:14:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cisco
[2010/10/06 13:42:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Credant
[2010/10/19 09:13:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Email Backup Optimization
[2010/08/16 13:12:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iPass
[2010/07/20 12:10:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2010/07/20 12:10:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2010/07/26 15:22:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2010/07/09 13:04:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/08/27 08:00:45 | 000,000,000 | —D | M] – C:\Documents and Settings\mauvaidy\Application Data\Avaya
[2010/12/20 08:57:51 | 000,000,000 | —D | M] – C:\Documents and Settings\mauvaidy\Application Data\Cisco
[2010/12/10 09:50:34 | 000,000,000 | —D | M] – C:\Documents and Settings\mauvaidy\Application Data\GSplit
[2010/07/10 15:37:56 | 000,000,000 | —D | M] – C:\Documents and Settings\mauvaidy\Application Data\Helios
[2010/06/25 16:12:00 | 000,000,000 | —D | M] – C:\Documents and Settings\mauvaidy\Application Data\IronPort
[2010/06/25 10:53:47 | 000,000,000 | —D | M] – C:\Documents and Settings\mauvaidy\Application Data\Sametime
[2010/07/01 19:36:15 | 000,000,000 | —D | M] – C:\Documents and Settings\mauvaidy\Application Data\Trondent Development Corp
[2010/12/16 15:28:57 | 000,000,000 | —D | M] – C:\Documents and Settings\mauvaidy\Application Data\webex
[2010/12/21 20:48:39 | 000,000,000 | —D | M] – C:\Documents and Settings\mauvaidy\Application Data\WebEx Connect
[2010/06/25 14:13:50 | 000,000,000 | —D | M] – C:\Documents and Settings\mauvaidy\Application Data\Windows Desktop Search
[2010/06/25 14:13:59 | 000,000,000 | —D | M] – C:\Documents and Settings\mauvaidy\Application Data\Windows Search
[2010/12/21 20:47:53 | 000,000,306 | —- | M] () – C:\WINDOWS\Tasks\PMTask.job
========== Purity Check ==========
< End of report >
OTL Extras Log:
OTL Extras logfile created on: 12/21/2010 9:01:40 PM - Run 1
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Documents and Settings\mauvaidy\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 44.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 2914 2914 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 35.75 Gb Free Space | 23.99% Space Free | Partition Type: NTFS
Computer Name: MAUVAIDY-WXP | User Name: mauvaidy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.js [@ = JSFile] – C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
jsfile [open] – %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation)
jsefile [open] – %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
vbefile [open] – %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation)
vbsfile [open] – %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation)
wsffile [open] – %SystemRoot%\System32\CScript.exe "%1" %* (Microsoft Corporation)
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [CmdHere] – C:\WINDOWS\System32\cmd.exe /k cd /d %1 (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\WebEx\Connect\wbxcOIEx.exe" = C:\Program Files\WebEx\Connect\wbxcOIEx.exe:*:Enabled:wbxcOIEx – (WebEx)
"C:\Program Files\WebEx\Connect\widget.exe" = C:\Program Files\WebEx\Connect\widget.exe:*:Enabled:widget – ()
"C:\Program Files\WebEx\Connect\connect.exe" = C:\Program Files\WebEx\Connect\connect.exe:*:Enabled:WebEx Connect – (Cisco WebEx)
"C:\Program Files\McAfee\Common Framework\FrameworkService.exe" = C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service – (McAfee, Inc.)
"C:\Documents and Settings\mauvaidy\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\mauvaidy\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Cisco Systems\Cisco Unified Personal Communicator\CUPCK9.exe" = C:\Program Files\Cisco Systems\Cisco Unified Personal Communicator\CUPCK9.exe:*:Enabled:Cisco Unified Personal Communicator – (Cisco Systems, Inc.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\McAfee\Common Framework\FrameworkService.exe" = C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service – (McAfee, Inc.)
"C:\Program Files\WebEx\Connect\wbxcOIEx.exe" = C:\Program Files\WebEx\Connect\wbxcOIEx.exe:*:Enabled:wbxcOIEx – (WebEx)
"C:\Program Files\WebEx\Connect\widget.exe" = C:\Program Files\WebEx\Connect\widget.exe:*:Enabled:widget – ()
"C:\Program Files\WebEx\Connect\connect.exe" = C:\Program Files\WebEx\Connect\connect.exe:*:Enabled:WebEx Connect – (Cisco WebEx)
"C:\Documents and Settings\mauvaidy\Local Settings\Temp\7zS1371\setup\HPZnet01.exe" = C:\Documents and Settings\mauvaidy\Local Settings\Temp\7zS1371\setup\HPZnet01.exe:*:Enabled:hpznet01.exe – File not found
"C:\Documents and Settings\mauvaidy\Local Settings\Temp\7zS1371\setup\hponicifs01.exe" = C:\Documents and Settings\mauvaidy\Local Settings\Temp\7zS1371\setup\hponicifs01.exe:*:Enabled:hponicifs01.exe – File not found
"C:\Program Files\Yahoo\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Documents and Settings\mauvaidy\Local Settings\Temp\7zS1859\setup\HPZnet01.exe" = C:\Documents and Settings\mauvaidy\Local Settings\Temp\7zS1859\setup\HPZnet01.exe:*:Enabled:hpznet01.exe – File not found
"C:\Documents and Settings\mauvaidy\Local Settings\Temp\7zS1859\setup\hponicifs01.exe" = C:\Documents and Settings\mauvaidy\Local Settings\Temp\7zS1859\setup\hponicifs01.exe:*:Enabled:hponicifs01.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\Iron Mountain\Connected BackupPC\Agent.exe" = C:\Program Files\Iron Mountain\Connected BackupPC\Agent.exe:*:Enabled:Agent User Interface – (Iron Mountain Incorporated)
"C:\Documents and Settings\mauvaidy\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\mauvaidy\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\totalcmd\TOTALCMD.EXE" = C:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit – (Ghisler Software GmbH)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Cisco Systems\Cisco Unified Personal Communicator\CUPCK9.exe" = C:\Program Files\Cisco Systems\Cisco Unified Personal Communicator\CUPCK9.exe:*:Enabled:Cisco Unified Personal Communicator – (Cisco Systems, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Central Data
"{098122AB-C605-4853-B441-C0A4EB359B75}" = DirectXInstallService
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{110AB5CA-ABB0-460C-B832-10ED00159EEA}" = Altiris Inventory Rule Agent
"{147BCE03-C0F1-4C9F-8157-6A89B6D2D973}" = McAfee VirusScan Enterprise
"{182EAE12-7DEE-4D0C-AEC0-31178F397748}" = Ironport Outlook Plugin
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Central Tools
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2851123E-5786-41BE-A3F1-A9B21E499EEB}" = Altiris Task Synchronization Agent
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Drag-to-Disc
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35C0A1E4-D02A-412C-841F-266DBB116ABB}" = Intel® PROSet/Wireless WiFi Software
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{393E4C89-67E9-43BF-AD29-94D19F7624F7}" = Connected Backup/PC Agent
"{3C79DC59-6099-323B-B27B-90B45542B270}" = Google Talk Plugin
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage Active Protection System
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AA455FB-BFEE-473C-AA0E-4FDA505F6FB7}" = IBM Lotus Sametime Connect 7.5
"{4E381DC2-981E-4C5D-8FBA-92BB13CFBB11}" = iPassConnect
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{537BF16E-7412-448C-95D8-846E85A1D817}" = Roxio Creator Business Edition
"{5ECDB603-437C-11D2-AFC6-0060082B1429}" = IPTV Viewer
"{65706020-7B6F-41F2-8047-FC69579E386A}" = Presentation Director
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{69333A04-5134-40A5-A055-9166A7AA1EC8}" =
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Central Audio
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
"{7EB114D8-207F-45AE-BABD-1669715F2630}" = ThinkVantage Access Connections
"{82EB6CEA-749A-410F-8AD2-372A286BA3BE}" = Integrated Camera Driver Installer Package Ver.1.32.500.0
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8843CC2B-E648-43D8-A763-1B5F56173FED}" = WebEx Recorder and Player
"{88C6A6D9-324C-46E8-BA87-563D14021442}_is1" = ThinkVantage Communications Utility
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{C8BD4E7E-25B9-4DEB-A950-2E7A048CA490}" =
"{90120000-001F-0409-0000-0000000FF1CE}_VISSTD_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-001F-0409-0000-0000000FF1CE}_VISSTD_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_VISSTD_{C8BD4E7E-25B9-4DEB-A950-2E7A048CA490}" =
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{C8BD4E7E-25B9-4DEB-A950-2E7A048CA490}" =
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_VISSTD_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-001F-040C-0000-0000000FF1CE}_VISSTD_{C8BD4E7E-25B9-4DEB-A950-2E7A048CA490}" =
"{90120000-001F-040C-0000-0000000FF1CE}_VISSTD_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{C8BD4E7E-25B9-4DEB-A950-2E7A048CA490}" =
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISSTD_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISSTD_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISSTD_{C8BD4E7E-25B9-4DEB-A950-2E7A048CA490}" =
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-0053-0000-0000-0000000FF1CE}" = Microsoft Office Visio Standard 2007
"{90120000-0053-0000-0000-0000000FF1CE}_VISSTD_{0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-0053-0000-0000-0000000FF1CE}_VISSTD_{C8BD4E7E-25B9-4DEB-A950-2E7A048CA490}" =
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}_VISSTD_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-0054-0409-0000-0000000FF1CE}_VISSTD_{C8BD4E7E-25B9-4DEB-A950-2E7A048CA490}" =
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{C8BD4E7E-25B9-4DEB-A950-2E7A048CA490}" =
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VISSTD_{8228E3BC-CA46-4BD0-9D8D-FAECDB842B60}" =
"{90120000-006E-0409-0000-0000000FF1CE}_VISSTD_{C8BD4E7E-25B9-4DEB-A950-2E7A048CA490}" =
"{90120000-006E-0409-0000-0000000FF1CE}_VISSTD_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VISSTD_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-0052-0409-0000-0000000FF1CE}" = Microsoft Office Visio Viewer 2007
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{9ECF7817-DB11-4FBA-9DF1-296A578D513A}" = Adobe Shockwave Player 11.5
"{A066194B-DC8F-449A-8E0F-B57BDD3A2072}" = SyncToy 2.1 (x86)
"{A0A1EB01-A6FD-423A-8480-364055A7C961}" = Altiris Software Delivery Solution Agent
"{A0E64EBA-8BF0-49FB-90C0-BB3D781A2016}" = ThinkPad Power Manager
"{A106D3BA-CF1F-4E13-8161-4ACA153E2F96}" = Graphviz
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3DD4B4B-6696-44A8-84C4-BAC339EE7E5B}" = Cisco Secure Services Client
"{A7050037-F0EA-4BAB-BCD5-FC05507D6147}" = Alt-Tab Task Switcher Powertoy for Windows XP
"{A7091E1D-36A4-47F1-A739-173CC341414F}" = Cisco Systems VPN Client 5.0.03.0560
"{AA5A50E9-ECDC-432C-95B0-F1E4B642CD41}" = CMG Windows Shield
"{AA7E5DEC-1F8C-4AE4-B38B-6ED113754813}" = Cisco Unified Personal Communicator
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB6FFA58-F491-11D3-8951-000000015799}" = iPassConnect
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AC76BA86-7AD7-2447-0000-900000000003}" = Chinese Simplified Fonts Support For Adobe Reader 9
"{AC76BA86-7AD7-2448-0000-900000000003}" = Chinese Traditional Fonts Support For Adobe Reader 9
"{AC76BA86-7AD7-5670-0000-900000000003}" = Korean Fonts Support For Adobe Reader 9
"{AC76BA86-7AD7-5760-0000-900000000003}" = Japanese Fonts Support For Adobe Reader 9
"{B05B22B8-72AE-4DC3-8D6F-FBC2233CAF41}" = Roxio Creator Business Edition
"{B2AE44CB-2AAB-4C08-A54B-D264BD604DA8}" = Citrix Presentation Server Client
"{B37C842A-B624-46B8-A727-654E72F1C91A}" = Calculator Powertoy for Windows XP
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Central Copy
"{B6EC7388-E277-4A5B-8C8F-71067A41BA64}" = TextPad 5
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BC13AD87-65E7-4963-A2DA-1ED419D3DC34}" = Altiris Carbon Copy Solution Agent
"{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2
"{BE60267F-7576-4397-A917-A6962A2E0969}" = SofToken II
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBFE16BF-E2B9-4F81-8669-0B989CBB776A}" = Altiris Local Security Agent
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D002159B-91CD-48E5-96D1-C476BA3DECB3}" = 3100_3200_3300_Help
"{D3227BD6-7D66-4B96-BA01-C21FB1F2224D}" = 3100_3200_3300trb
"{D3A80508-CD83-4CA3-8671-914A1BC78B61}" = Microsoft Sync Framework 2.0 Provider Services (x86) ENU
"{D62C9F08-473A-4AF4-9453-DAD78F46B5D3}" = Network Recording Player
"{D7D51E50-4E60-48BF-9BCD-0DD4C0E250A2}" = WebEx Productivity Tools
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DD63D620-BEFC-4D46-AAC2-5086689D09B0}" = IronPort Plug-in for Microsoft Outlook
"{DE499746-67B9-11D4-97CE-0050DA10E5AE}" = Cisco Security Agent ([removed])
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{E1D94FAD-CFA4-4B76-91D9-28F5AB18A431}" = 3300
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EAE92314-0E5F-4068-8A5E-38EAADC1C04C}" = Cisco WebEx Connect
"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Central Core
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F18DB86D-BC16-4E01-BCCE-63F62B931D82}" = InterVideo Register Manager
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
"{F982B30D-1403-44C8-92C9-FAC25CC0722E}" = Microsoft Office 2007 HyperLink Patch
"{FAE36873-1941-4076-A9A5-48812B5EA0B7}" = iTunes
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
"{FC350782-8982-4BBE-B9BA-B474CCDC935A}" = Altiris Application Metering Agent
"{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"{FF63121D-91C6-42CC-B341-F1AA729728E7}" = Microsoft Sync Framework 2.0 Core Components (x86) ENU
"ActiveTouchMeetingClient" = WebEx
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Altiris Carbon Copy Solution Agent 6.1" = Altiris Carbon Copy Solution Agent 6.1
"Altiris PCTransplant" = Altiris_PCTransplant
"AltirisAgent" = Altiris Agent
"AltirisPatchManagementAgent" = Altiris Patch Management Agent
"Applications_Win32_Cisco_AltirisAgentRedirector" = Applications_Win32_Cisco_AltirisAgentRedirector
"Applications_Win32_Cisco_OutlookFreeBusyServerConfiguration" = Applications_Win32_Cisco_OutlookFreeBusyServerConfiguration
"Applications_Win32_Cisco_OutlookJunkEmailFilterLists" = Applications_Win32_Cisco_OutlookJunkEmailFilterLists
"Applications_Win32_Cisco_PCSetupGuide" = Applications_Win32_Cisco_PCSetupGuide
"Applications_Win32_Cisco_VPNProfileUpdate" = Applications_Win32_Cisco_VPNProfileUpdate
"Cisco CEPS" = Cisco CEPS
"Cisco_BMPAudit" = Cisco_BMPAudit
"CiscoPCSolutionWizard" = Cisco PC Solution Wizard
"CNXT_AUDIO_HDA" = Conexant 20561 SmartAudio HD
"CNXT_MODEM_HDA_HSF" = ThinkPad Modem Adapter
"Connected" =
"GSplit3Set" = GSplit 3
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Document Viewer" = HP Document Viewer 7.0
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"ie8" = Windows Internet Explorer 8
"IEzones" = IEzones
"Intel® PRO Network Connections Drivers - Custom Settings" = Intel® PRO Network Connections Drivers - Custom Settings
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Anti-Spyware Enterprise Module" = McAfee AntiSpyware Enterprise Module
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"OnScreenDisplay" = On Screen Display
"OS_Win32_WindowsXP_Updates_PerformanceStability" = OS_Win32_WindowsXP_Updates_PerformanceStability
"Password Safe" = Password Safe
"Power Management Driver" = ThinkPad Power Management Driver
"ProInst" = Intel PROSet Wireless
"PROPLUS" = Microsoft Office Professional Plus 2007
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"ThinkVantage Active Protection System - Custom Settings" = ThinkVantage Active Protection System - Custom Settings
"Totalcmd" = Total Commander (Remove or Repair)
"TrackPoint" = ThinkPad TrackPoint Driver
"VISSTD" = Microsoft Office Visio Standard 2007
"VLC media player" = VLC media player 1.1.4
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.7.1
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 12/21/2010 2:23:51 PM | Computer Name = MAUVAIDY-WXP | Source = Userenv | ID = 1085
Description = The Group Policy client-side extension Security failed to execute.
Please look for any errors reported earlier by that extension.
Error - 12/21/2010 4:09:56 PM | Computer Name = MAUVAIDY-WXP | Source = Userenv | ID = 1085
Description = The Group Policy client-side extension Security failed to execute.
Please look for any errors reported earlier by that extension.
Error - 12/21/2010 5:32:36 PM | Computer Name = MAUVAIDY-WXP | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 12/21/2010 5:46:57 PM | Computer Name = MAUVAIDY-WXP | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 6020 (0x1784) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.1.0.524
/ 5400.1158 Object being scanned = \Device\HarddiskVolume1\Documents and Settings\All
Users\Application Data\Spybot - Search & Destroy\ProcCache.sbc by C:\Program Files\SpybotS&D;\TeaTimer.exe
4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)
Error - 12/21/2010 5:46:58 PM | Computer Name = MAUVAIDY-WXP | Source = McLogEvent | ID = 1008
Description = The McShield service terminated unexpectedly. Please review event 5019
or 5051 for details. The McShield service will be restarted in 10 seconds;
Error - 12/21/2010 9:30:36 PM | Computer Name = MAUVAIDY-WXP | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 12/21/2010 9:31:39 PM | Computer Name = MAUVAIDY-WXP | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 12/21/2010 9:46:30 PM | Computer Name = MAUVAIDY-WXP | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 12/21/2010 9:48:43 PM | Computer Name = MAUVAIDY-WXP | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 4260 (0x10a4) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.1.0.524
/ 5400.1158 Object being scanned = \Device\HarddiskVolume1\Data\Downloads\Cisco\MSVisioStd_2007_SP2.exe
by C:\WINDOWS\Explorer.EXE 4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0)
5006(0)(0) 5004(0)(0)
Error - 12/21/2010 9:48:44 PM | Computer Name = MAUVAIDY-WXP | Source = McLogEvent | ID = 1008
Description = The McShield service terminated unexpectedly. Please review event 5019
or 5051 for details. The McShield service will be restarted in 5 seconds;
[ OSession Events ]
Error - 12/8/2010 2:21:55 PM | Computer Name = MAUVAIDY-WXP | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 12516
seconds with 3660 seconds of active time. This session ended with a crash.
Error - 12/13/2010 5:47:27 PM | Computer Name = MAUVAIDY-WXP | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 24686
seconds with 4380 seconds of active time. This session ended with a crash.
Error - 12/17/2010 9:25:42 AM | Computer Name = MAUVAIDY-WXP | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6535.5005, Microsoft Office Version: 12.0.6425.1000. This session lasted 54
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/17/2010 9:26:40 AM | Computer Name = MAUVAIDY-WXP | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6535.5005, Microsoft Office Version: 12.0.6425.1000. This session lasted 45
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/17/2010 10:18:58 AM | Computer Name = MAUVAIDY-WXP | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 3
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/17/2010 10:19:32 AM | Computer Name = MAUVAIDY-WXP | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/17/2010 12:14:44 PM | Computer Name = MAUVAIDY-WXP | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/17/2010 12:43:27 PM | Computer Name = MAUVAIDY-WXP | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.
Error - 12/17/2010 5:29:11 PM | Computer Name = MAUVAIDY-WXP | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 17129
seconds with 2400 seconds of active time. This session ended with a crash.
Error - 12/17/2010 5:32:54 PM | Computer Name = MAUVAIDY-WXP | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 12/21/2010 9:31:32 PM | Computer Name = MAUVAIDY-WXP | Source = DCOM | ID = 10016
Description = The machine-default permission settings do not grant Local Activation
permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}
to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.
Error - 12/21/2010 9:31:33 PM | Computer Name = MAUVAIDY-WXP | Source = DCOM | ID = 10016
Description = The machine-default permission settings do not grant Local Activation
permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}
to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.
Error - 12/21/2010 9:31:33 PM | Computer Name = MAUVAIDY-WXP | Source = DCOM | ID = 10016
Description = The machine-default permission settings do not grant Local Activation
permission for the COM Server application with CLSID {A4199E55-EBB9-49E5-AF1A-7A5408B2E206}
to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.
Error - 12/21/2010 9:33:20 PM | Computer Name = MAUVAIDY-WXP | Source = Service Control Manager | ID = 7022
Description = The AgentService service hung on starting.
Error - 12/21/2010 9:47:37 PM | Computer Name = MAUVAIDY-WXP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.
Error - 12/21/2010 9:47:51 PM | Computer Name = MAUVAIDY-WXP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
Error - 12/21/2010 9:48:25 PM | Computer Name = MAUVAIDY-WXP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
Error - 12/21/2010 9:48:44 PM | Computer Name = MAUVAIDY-WXP | Source = Service Control Manager | ID = 7034
Description = The McAfee McShield service terminated unexpectedly. It has done
this 1 time(s).
Error - 12/21/2010 9:49:09 PM | Computer Name = MAUVAIDY-WXP | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
Error - 12/21/2010 10:02:40 PM | Computer Name = MAUVAIDY-WXP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.
< End of report >