Whigged
Topic Starter
When streaming Pandora or playing through a media player (have tried via Winamp, WMP etc.) there will be points where the playing is interrupted, sounding like it has gotten stuck and then stutters until it catches up.
Here is the Hijack This report:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:44:18 AM, on 3/15/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17091)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe
C:\Program Files\Equitrac\Professional\Client\EQSharedEngine.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\POPUPS~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Program Files\FirmDirectory\FirmDir.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\My Documents\Downloads\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dlglobal.dl.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dlglobal.dl.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://dlglobal.dl.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://insideleboeuf.llgm.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Dewey & LeBoeuf
O1 - Hosts: 126.14.32.160 leb.hostedeet.com #eTime
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ODMAdetect] C:\SYSFILES\ODMA\ODMA.BAT
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKCU\..\Run: [PopUpStopperProfessional] "C:\PROGRA~1\PANICW~1\POP-UP~1\POPUPS~1.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: llgmprf.cmd (User 'SYSTEM')
O4 - S-1-5-18 Startup: LLGMPRF.lnk = C:\SYSFILES\LLGMPRF.cmd (User 'SYSTEM')
O4 - .DEFAULT Startup: llgmprf.cmd (User 'Default user')
O4 - .DEFAULT Startup: LLGMPRF.lnk = C:\SYSFILES\LLGMPRF.cmd (User 'Default user')
O4 - .DEFAULT User Startup: LLGMPRF.lnk = C:\SYSFILES\LLGMPRF.cmd (User 'Default user')
O4 - Startup: LLGMPRF.lnk = C:\SYSFILES\LLGMPRF.cmd
O4 - Global Startup: Google Calendar Sync.lnk = C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
O4 - Global Startup: phone.lnk = C:\Program Files\FirmDirectory\FirmDir.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.65.220.192.35
O15 - Trusted Zone: http://*.deweyleboeuf.com
O15 - Trusted Zone: http://experience.dl.com
O15 - Trusted Zone: http://*.dl.com
O15 - Trusted Zone: www.lexis.com
O15 - Trusted Zone: http://*.lexis.com
O15 - Trusted Zone: http://insideleboeuf.llgm.com
O15 - Trusted Zone: http://*.nysearch1
O15 - Trusted Zone: http://*.nysearch2
O15 - Trusted Zone: http://*.nyspprd1
O15 - Trusted Zone: *.peopleclick.com
O15 - Trusted Zone: *.peopleclick.com
O15 - Trusted Zone: http://*.peopleclick.com
O15 - Trusted Zone: http://*.ptlitsup
O15 - Trusted Zone: http://*.ptlitsup2
O15 - Trusted Zone: http://*.shipping
O15 - Trusted Zone: http://*.webapps2
O15 - Trusted Zone: http://*.webapps3
O15 - Trusted Zone: http://*.webapps4
O15 - Trusted Zone: http://*.wepappsdev
O15 - Trusted Zone: http://*.westlaw.com
O15 - Trusted Zone: *.65.220.192.35 (HKLM)
O15 - Trusted Zone: http://*.deweyleboeuf.com (HKLM)
O15 - Trusted Zone: http://experience.dl.com (HKLM)
O15 - Trusted Zone: http://*.dl.com (HKLM)
O15 - Trusted Zone: www.lexis.com (HKLM)
O15 - Trusted Zone: http://insideleboeuf.llgm.com (HKLM)
O15 - Trusted Zone: http://*.nysearch1 (HKLM)
O15 - Trusted Zone: http://*.nysearch2 (HKLM)
O15 - Trusted Zone: http://*.nyspprd1 (HKLM)
O15 - Trusted Zone: *.peopleclick.com (HKLM)
O15 - Trusted Zone: *.peopleclick.com (HKLM)
O15 - Trusted Zone: http://*.peopleclick.com (HKLM)
O15 - Trusted Zone: http://*.ptlitsup (HKLM)
O15 - Trusted Zone: http://*.ptlitsup2 (HKLM)
O15 - Trusted Zone: http://*.shipping (HKLM)
O15 - Trusted Zone: http://*.webapps2 (HKLM)
O15 - Trusted Zone: http://*.webapps3 (HKLM)
O15 - Trusted Zone: http://*.webapps4 (HKLM)
O15 - Trusted Zone: http://*.wepappsdev (HKLM)
O15 - Trusted Zone: http://*.westlaw.com (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1264613999821
O16 - DPF: {A1759073-B1B4-40FA-8BEE-455C3FFC8025} (WestAPSWestlaw Class) - https://web2.westlaw.com/clientid/apswestlaw.cab
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.3.1_02) - https://leb.hostedeet.com/WFC/plugins/j2re-1_3_1_02-win.exe
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://dl.webex.com/client/T26L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = llgm.com
O17 - HKLM\Software\..\Telephony: DomainName = llgm.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = llgm.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = llgm.com,dbllp.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = llgm.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = llgm.com,dbllp.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = llgm.com,dbllp.com
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL C:\PROGRA~1\Equitrac\PROFES~1\Client\EQDtpSp.dll C:\PROGRA~1\Equitrac\PROFES~1\Client\EQPortMonitorSpy.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: EQ Shared Engine (EQSharedEngine) - Equitrac - C:\Program Files\Equitrac\Professional\Client\EQSharedEngine.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos Client Firewall - Sophos Plc - C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe
O23 - Service: Sophos Client Firewall Manager - Sophos Plc - C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Sophos Web Intelligence Service (swi_service) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
–
End of file - 11384 bytes
Here is the Hijack This report:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:44:18 AM, on 3/15/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17091)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe
C:\Program Files\Equitrac\Professional\Client\EQSharedEngine.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\POPUPS~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Program Files\FirmDirectory\FirmDir.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\My Documents\Downloads\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dlglobal.dl.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dlglobal.dl.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://dlglobal.dl.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://insideleboeuf.llgm.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Dewey & LeBoeuf
O1 - Hosts: 126.14.32.160 leb.hostedeet.com #eTime
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ODMAdetect] C:\SYSFILES\ODMA\ODMA.BAT
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKCU\..\Run: [PopUpStopperProfessional] "C:\PROGRA~1\PANICW~1\POP-UP~1\POPUPS~1.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: llgmprf.cmd (User 'SYSTEM')
O4 - S-1-5-18 Startup: LLGMPRF.lnk = C:\SYSFILES\LLGMPRF.cmd (User 'SYSTEM')
O4 - .DEFAULT Startup: llgmprf.cmd (User 'Default user')
O4 - .DEFAULT Startup: LLGMPRF.lnk = C:\SYSFILES\LLGMPRF.cmd (User 'Default user')
O4 - .DEFAULT User Startup: LLGMPRF.lnk = C:\SYSFILES\LLGMPRF.cmd (User 'Default user')
O4 - Startup: LLGMPRF.lnk = C:\SYSFILES\LLGMPRF.cmd
O4 - Global Startup: Google Calendar Sync.lnk = C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
O4 - Global Startup: phone.lnk = C:\Program Files\FirmDirectory\FirmDir.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.65.220.192.35
O15 - Trusted Zone: http://*.deweyleboeuf.com
O15 - Trusted Zone: http://experience.dl.com
O15 - Trusted Zone: http://*.dl.com
O15 - Trusted Zone: www.lexis.com
O15 - Trusted Zone: http://*.lexis.com
O15 - Trusted Zone: http://insideleboeuf.llgm.com
O15 - Trusted Zone: http://*.nysearch1
O15 - Trusted Zone: http://*.nysearch2
O15 - Trusted Zone: http://*.nyspprd1
O15 - Trusted Zone: *.peopleclick.com
O15 - Trusted Zone: *.peopleclick.com
O15 - Trusted Zone: http://*.peopleclick.com
O15 - Trusted Zone: http://*.ptlitsup
O15 - Trusted Zone: http://*.ptlitsup2
O15 - Trusted Zone: http://*.shipping
O15 - Trusted Zone: http://*.webapps2
O15 - Trusted Zone: http://*.webapps3
O15 - Trusted Zone: http://*.webapps4
O15 - Trusted Zone: http://*.wepappsdev
O15 - Trusted Zone: http://*.westlaw.com
O15 - Trusted Zone: *.65.220.192.35 (HKLM)
O15 - Trusted Zone: http://*.deweyleboeuf.com (HKLM)
O15 - Trusted Zone: http://experience.dl.com (HKLM)
O15 - Trusted Zone: http://*.dl.com (HKLM)
O15 - Trusted Zone: www.lexis.com (HKLM)
O15 - Trusted Zone: http://insideleboeuf.llgm.com (HKLM)
O15 - Trusted Zone: http://*.nysearch1 (HKLM)
O15 - Trusted Zone: http://*.nysearch2 (HKLM)
O15 - Trusted Zone: http://*.nyspprd1 (HKLM)
O15 - Trusted Zone: *.peopleclick.com (HKLM)
O15 - Trusted Zone: *.peopleclick.com (HKLM)
O15 - Trusted Zone: http://*.peopleclick.com (HKLM)
O15 - Trusted Zone: http://*.ptlitsup (HKLM)
O15 - Trusted Zone: http://*.ptlitsup2 (HKLM)
O15 - Trusted Zone: http://*.shipping (HKLM)
O15 - Trusted Zone: http://*.webapps2 (HKLM)
O15 - Trusted Zone: http://*.webapps3 (HKLM)
O15 - Trusted Zone: http://*.webapps4 (HKLM)
O15 - Trusted Zone: http://*.wepappsdev (HKLM)
O15 - Trusted Zone: http://*.westlaw.com (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1264613999821
O16 - DPF: {A1759073-B1B4-40FA-8BEE-455C3FFC8025} (WestAPSWestlaw Class) - https://web2.westlaw.com/clientid/apswestlaw.cab
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.3.1_02) - https://leb.hostedeet.com/WFC/plugins/j2re-1_3_1_02-win.exe
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://dl.webex.com/client/T26L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = llgm.com
O17 - HKLM\Software\..\Telephony: DomainName = llgm.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = llgm.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = llgm.com,dbllp.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = llgm.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = llgm.com,dbllp.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = llgm.com,dbllp.com
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL C:\PROGRA~1\Equitrac\PROFES~1\Client\EQDtpSp.dll C:\PROGRA~1\Equitrac\PROFES~1\Client\EQPortMonitorSpy.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: EQ Shared Engine (EQSharedEngine) - Equitrac - C:\Program Files\Equitrac\Professional\Client\EQSharedEngine.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos Client Firewall - Sophos Plc - C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe
O23 - Service: Sophos Client Firewall Manager - Sophos Plc - C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Sophos Web Intelligence Service (swi_service) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
–
End of file - 11384 bytes