This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Redirects and pop-ups

94 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I'm having problems with being redirected while using Google and pop-ups while I'm in other sites. I've downloaded HijackThis and the logfile is pasted below. I'd appreciate any help I can get in resolving these problems.

Thanks!
mesh


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:32:39 PM, on 11/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Acer\Empowering Technology\admtray.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\DOCUME~1\Maryann\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: {b22b} - {2036fda0-476f-42db-ae49-d9554ff6b675} - C:\WINDOWS\system32\jxmjgz.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: {84778876-6b84-fffb-2f74-e28f6c983e0d} - {d0e389c6-f82e-47f2-bfff-48b667887748} - C:\WINDOWS\system32\uvegyt.dll
O2 - BHO: (no name) - {D31EE8A2-DCB4-4ACD-ADDF-FEC2B9D2F21D} - C:\WINDOWS\system32\qoMffFYr.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: (no name) - {fba9acc7-9a24-4a1f-972c-807dde81eceb} - C:\WINDOWS\system32\heyehita.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Acer\OrbiCam\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O5 "LPT1:" /M "Stylus Photo R340"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [rirawapola] Rundll32.exe "C:\WINDOWS\system32\demohajo.dll",s
O4 - HKLM\..\Run: [320d18a1] rundll32.exe "C:\WINDOWS\system32\srvrnhpn.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [rirawapola] Rundll32.exe "C:\WINDOWS\system32\demohajo.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [rirawapola] Rundll32.exe "C:\WINDOWS\system32\demohajo.dll",s (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL,C:\WINDOWS\system32\pazodoga.dll uvegyt.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe (file missing)
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Maryann/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg

–
End of file - 15823 bytes
Hello

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
How long should the Lop S&D scan take? I've disabled all antivirus protection and turned off other programs. Still getting the "Please Wait" screen after nearly 40 minutes. mesh
Do this

Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
  • Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program. Make sure you close all other programs and don't use the PC while the scan runs.
  • Under File Age at the top, change it from 30 days to 90 days
  • Under Additional Scans check the boxes beside Reg - ColumnHandlers, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, Reg - NetSvcs, Reg - Protocol Filters, Reg - Protocol Handlers, Reg - SafeBoot Minimal, Reg - SafeBoot Network, Reg - Session Manager Settings, Reg - Winsock2 Catalogs, File - Lop Check, File - Purity Scan, Files - Signature Check, and Evnt - EventViewer Logs ( Last 10 Errors).
  • Under Rootkit Search change it to Yes
  • Under the Custom Scans box at the bottom left paste the following in

    C:\Windows\Prefetch\*.* /s
    %systemroot%\system32\drivers\*.dat
    C:\WINDOWS\Temp\bca4e2da.$$$
    C:\WINDOWS\Temp\ed47fa.$
    C:\WINDOWS\Temp\fa56d7ec.$$$
    C:\Windows\System32\antiwpa.dll
    c:\windows\system32\drivers\winfilse.exe
    c:\windows\system32\drivers\srosa2.sys
    c:\windows\system32\drivers\srosa.sys
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services|{FBE1D620-5418-4AAE-A0F0-316D590663A1} /rs
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services|tds /rs
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services|SROSA /rs
    C:\Program Files\*crack*.
    C:\Program Files\*keygen*.
    C:\*crack*.
    C:\*keygen*.
    C:\*.zip
    C:\*.rar
    C:\*.exe
    C:\Program Files\*.zip
    C:\Program Files\*.rar
    C:\Program Files\*.exe
    C:\Program Files\Common Files\*bak*.
    C:\WINDOWS\SYSTEM32\*bak*.
    C:\Program Files\*bak*.




  • Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and post the information back here in an attachment. I will review it when it comes in. The last line is < End of Report >, so make sure that is the last line in the attached report.


Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way
Ok, I followed the directions word for word including not using the computer while the scan was running. All seemed to be going well until it got to the Rootkit search where a C: window opened up with the infomation below. The scan froze up at that point…

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
McAfee Backup = C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Ok, scan worked this time. Here's the report…

OTScanIt2 logfile created on: 12/1/2008 9:54:04 AM - Run 9
OTScanIt2 by OldTimer - Version 1.0.2.0	 Folder = C:\Documents and Settings\Maryann\Desktop\OTScanIt2
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.00 Gb Total Physical Memory | 1.38 Gb Available Physical Memory | 69.27% Memory free
3.85 Gb Paging File | 3.30 Gb Available in Paging File | 85.91% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.82 Gb Total Space | 27.73 Gb Free Space | 38.62% Space Free | Partition Type: FAT32
Drive D: | 72.31 Gb Total Space | 72.31 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: MOM
Current User Name: Maryann
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 90 Days
 
[Processes - Safe List]
admserv.exe -> %SystemDrive%\Acer\Empowering Technology\admServ.exe -> [2005/10/24 16:40:52 | 01,314,816 | —- | M] (Avocent Inc.)
admtray.exe -> %SystemDrive%\Acer\Empowering Technology\admtray.exe -> [2005/10/24 16:45:32 | 02,462,208 | —- | M] (Avocent Inc.)
apdproxy.exe -> %ProgramFiles%\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe -> [2007/03/09 11:09:58 | 00,063,712 | —- | M] (Adobe Systems Incorporated)
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/10/01 13:06:14 | 00,116,040 | —- | M] (Apple Inc.)
cameraassistant.exe -> %ProgramFiles%\Acer\OrbiCam\CameraAssistant.exe -> [2006/06/26 15:47:48 | 00,331,776 | —- | M] (Acer)
clcapsvc.exe -> %ProgramFiles%\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe -> [2006/08/09 22:29:36 | 00,254,050 | —- | M] ()
clmlserver.exe -> %ProgramFiles%\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe -> [2006/08/09 22:28:36 | 00,061,440 | —- | M] (Cyberlink)
clmlservice.exe -> %ProgramFiles%\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe -> [2006/08/09 22:28:36 | 01,077,376 | —- | M] (Cyberlink)
clsched.exe -> %ProgramFiles%\Acer\Acer Arcade\Kernel\TV\CLSched.exe -> [2006/08/09 22:29:38 | 00,114,784 | —- | M] ()
cvpnd.exe -> %ProgramFiles%\Cisco Systems\VPN Client\cvpnd.exe -> [2004/12/06 16:18:18 | 01,437,712 | —- | M] (Cisco Systems, Inc.)
edsloader.exe -> %SystemDrive%\Acer\Empowering Technology\eDataSecurity\eDSloader.exe -> [2005/12/27 15:50:28 | 00,069,632 | —- | M] (HiTRUST)
elkctrl.exe -> %SystemRoot%\system32\ElkCtrl.exe -> [2004/11/01 18:22:22 | 00,262,144 | —- | M] (Logitech Inc.)
epower_dmc.exe -> %SystemDrive%\Acer\Empowering Technology\ePower\ePower_DMC.exe -> [2006/08/10 19:29:14 | 00,352,256 | —- | M] (Acer Incorporated)
evteng.exe -> %ProgramFiles%\Intel\Wireless\Bin\EvtEng.exe -> [2005/11/28 11:29:00 | 00,114,753 | —- | M] (Intel Corporation)
googledesktop.exe -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktop.exe -> [2008/09/02 15:44:54 | 00,029,744 | —- | M] (Google)
googledesktop.exe -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktop.exe -> [2008/09/02 15:44:54 | 00,029,744 | —- | M] (Google)
googletoolbarnotifier.exe -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> [2007/06/26 12:21:14 | 00,068,856 | —- | M] (Google Inc.)
groovemonitor.exe -> %ProgramFiles%\Microsoft Office\Office12\GrooveMonitor.exe -> [2007/08/24 07:00:48 | 00,033,648 | —- | M] (Microsoft Corporation)
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/10/01 18:57:00 | 00,536,872 | —- | M] (Apple Inc.)
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> [2008/10/01 18:57:12 | 00,289,576 | —- | M] (Apple Inc.)
jusched.exe -> %ProgramFiles%\Java\jre1.6.0_07\bin\jusched.exe -> [2008/06/10 04:27:04 | 00,144,784 | —- | M] (Sun Microsystems, Inc.)
lmanager.exe -> %SystemDrive%\PROGRA~1\LAUNCH~1\LManager.exe -> [2006/07/20 22:15:32 | 00,593,920 | —- | M] (Dritek System Inc.)
lssrvc.exe -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> [2006/05/18 16:52:06 | 00,049,152 | —- | M] (Hewlett-Packard Company)
lvcomsx.exe -> %SystemRoot%\system32\LVCOMSX.EXE -> [2006/06/23 10:39:54 | 00,225,280 | —- | M] (Logitech)
lvprcsrv.exe -> %CommonProgramFiles%\logitech\lvmvfm\LVPrcSrv.exe -> [2006/06/23 10:40:58 | 00,086,016 | —- | M] (Logitech)
mbackmonitor.exe -> %ProgramFiles%\McAfee\MBK\MBackMonitor.exe -> [2007/01/16 13:59:46 | 00,071,208 | —- | M] (McAfee)
mcafeedatabackup.exe -> %ProgramFiles%\McAfee\MBK\McAfeeDataBackup.exe -> [2007/01/16 13:59:50 | 04,838,952 | —- | M] (McAfee)
mcagent.exe -> %SystemDrive%\PROGRA~1\mcafee.com\agent\mcagent.exe -> [2007/11/01 18:12:38 | 00,582,992 | —- | M] (McAfee, Inc.)
mcmscsvc.exe -> %SystemDrive%\PROGRA~1\McAfee\MSC\mcmscsvc.exe -> [2008/01/09 15:50:22 | 00,767,976 | —- | M] (McAfee, Inc.)
mcnasvc.exe -> %SystemDrive%\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe -> [2008/01/25 01:38:12 | 02,458,128 | —- | M] (McAfee, Inc.)
mcproxy.exe -> %SystemDrive%\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe -> [2007/08/15 12:36:04 | 00,359,248 | —- | M] (McAfee, Inc.)
mcshield.exe -> %SystemDrive%\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe -> [2007/07/24 12:02:14 | 00,144,704 | —- | M] (McAfee, Inc.)
mcuimgr.exe -> %SystemDrive%\PROGRA~1\mcafee\msc\mcuimgr.exe -> [2007/11/01 18:12:38 | 00,265,040 | —- | M] (McAfee, Inc.)
mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.)
monitor.exe -> %SystemDrive%\Acer\Empowering Technology\eRecovery\Monitor.exe -> [2006/01/24 18:00:08 | 00,397,312 | —- | M] (acer Inc.)
mpfsrv.exe -> %ProgramFiles%\McAfee\MPF\MPFSrv.exe -> [2007/07/18 15:54:42 | 00,856,864 | —- | M] (McAfee, Inc.)
nvsvc32.exe -> %SystemRoot%\system32\nvsvc32.exe -> [2006/07/20 05:58:00 | 00,143,426 | —- | M] (NVIDIA Corporation)
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2008/11/30 14:41:16 | 00,477,184 | —- | M] (OldTimer Tools)
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2008/11/30 14:41:16 | 00,477,184 | —- | M] (OldTimer Tools)
pcmservice.exe -> %ProgramFiles%\Acer\Acer Arcade\PCMService.exe -> [2006/08/09 22:29:08 | 00,151,552 | —- | M] (CyberLink Corp.)
regsrvc.exe -> %ProgramFiles%\Intel\Wireless\Bin\RegSrvc.exe -> [2005/11/28 11:28:14 | 00,217,164 | —- | M] (Intel Corporation)
richvideo.exe -> %ProgramFiles%\CyberLink\Shared Files\RichVideo.exe -> [2005/01/21 04:37:16 | 00,143,360 | —- | M] ()
rthdcpl.exe -> %SystemRoot%\RTHDCPL.EXE -> [2007/03/21 14:49:20 | 16,126,464 | R— | M] (Realtek Semiconductor Corp.)
rtkbtmnt.exe -> %SystemDrive%\DOCUME~1\Maryann\LOCALS~1\Temp\RtkBtMnt.exe -> [2007/05/02 23:43:32 | 00,208,896 | —- | M] (Realtek Semiconductor Corp.)
rundll32.exe -> %SystemRoot%\system32\rundll32.exe -> [2004/08/04 05:00:00 | 00,033,280 | —- | M] (Microsoft Corporation)
rundll32.exe -> %SystemRoot%\system32\RUNDLL32.EXE -> [2004/08/04 05:00:00 | 00,033,280 | —- | M] (Microsoft Corporation)
rundll32.exe -> %SystemRoot%\system32\rundll32.exe -> [2004/08/04 05:00:00 | 00,033,280 | —- | M] (Microsoft Corporation)
s24evmon.exe -> %ProgramFiles%\Intel\Wireless\Bin\S24EvMon.exe -> [2005/11/28 11:31:32 | 00,540,745 | —- | M] (Intel Corporation )
symlcsvc.exe -> %CommonProgramFiles%\Symantec Shared\CCPD-LC\symlcsvc.exe -> [2008/06/11 18:51:50 | 01,251,720 | —- | M] ()
syntpenh.exe -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe -> [2006/03/03 13:07:38 | 00,761,946 | —- | M] (Synaptics, Inc.)
unsecapp.exe -> %SystemRoot%\system32\wbem\unsecapp.exe -> [2004/08/04 05:00:00 | 00,016,896 | —- | M] (Microsoft Corporation)
wmiprvse.exe -> %SystemRoot%\system32\wbem\wmiprvse.exe -> [2004/08/04 05:00:00 | 00,218,112 | —- | M] (Microsoft Corporation)
wmiprvse.exe -> %SystemRoot%\system32\wbem\wmiprvse.exe -> [2004/08/04 05:00:00 | 00,218,112 | —- | M] (Microsoft Corporation)
 
[Win32 Services - Safe List]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/10/01 13:06:14 | 00,116,040 | —- | M] (Apple Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/10/24 01:47:22 | 00,033,800 | —- | M] (Microsoft Corporation)
(AWService) AdminWorks Agent X6 [Win32_Own | Auto | Running] -> %SystemDrive%\Acer\Empowering Technology\admServ.exe -> [2005/10/24 16:40:52 | 01,314,816 | —- | M] (Avocent Inc.)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.)
(BthServ) Bluetooth Support Service [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\bthserv.dll -> [2004/08/04 05:00:00 | 00,030,208 | —- | M] (Microsoft Corporation)
(CLCapSvc) CyberLink Background Capture Service (CBCS) [Win32_Own | Auto | Running] -> %ProgramFiles%\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe -> [2006/08/09 22:29:36 | 00,254,050 | —- | M] ()
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation)
(CLSched) CyberLink Task Scheduler (CTS) [Win32_Own | Auto | Running] -> %ProgramFiles%\Acer\Acer Arcade\Kernel\TV\CLSched.exe -> [2006/08/09 22:29:38 | 00,114,784 | —- | M] ()
(CVPND) Cisco Systems, Inc. VPN Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Cisco Systems\VPN Client\cvpnd.exe -> [2004/12/06 16:18:18 | 01,437,712 | —- | M] (Cisco Systems, Inc.)
(CyberLink Media Library Service) CyberLink Media Library Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe -> [2006/08/09 22:28:36 | 00,061,440 | —- | M] (Cyberlink)
(EvtEng) Intel(R) PROSet/Wireless Event Log [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\EvtEng.exe -> [2005/11/28 11:29:00 | 00,114,753 | —- | M] (Intel Corporation)
(GoogleDesktopManager-061008-081103) Google Desktop Manager 5.7.806.10245 [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktop.exe -> [2008/09/02 15:44:54 | 00,029,744 | —- | M] (Google)
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2007/01/31 21:42:44 | 00,138,168 | —- | M] (Google)
(helpsvc) Help and Support [Win32_Shared | Auto | Running] -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2004/08/04 05:00:00 | 00,038,912 | —- | M] (Microsoft Corporation)
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/10/01 18:57:00 | 00,536,872 | —- | M] (Apple Inc.)
(Irmon) Infrared Monitor [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\irmon.dll -> [2004/09/30 10:49:36 | 00,027,136 | —- | M] (Microsoft Corporation)
(LightScribeService) LightScribeService Direct Disc Labeling Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> [2006/05/18 16:52:06 | 00,049,152 | —- | M] (Hewlett-Packard Company)
(LVPrcSrv) Logitech Process Monitor [Win32_Own | Auto | Running] -> %CommonProgramFiles%\logitech\lvmvfm\LVPrcSrv.exe -> [2006/06/23 10:40:58 | 00,086,016 | —- | M] (Logitech)
(MBackMonitor) MBackMonitor [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee\MBK\MBackMonitor.exe -> [2007/01/16 13:59:46 | 00,071,208 | —- | M] (McAfee)
(mcmscsvc) McAfee Services [Win32_Own | Auto | Running] -> %SystemDrive%\PROGRA~1\McAfee\MSC\mcmscsvc.exe -> [2008/01/09 15:50:22 | 00,767,976 | —- | M] (McAfee, Inc.)
(McNASvc) McAfee Network Agent [Win32_Own | Auto | Running] -> %SystemDrive%\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe -> [2008/01/25 01:38:12 | 02,458,128 | —- | M] (McAfee, Inc.)
(McODS) McAfee Scanner [Win32_Own | On_Demand | Stopped] -> %SystemDrive%\PROGRA~1\McAfee\VIRUSS~1\mcods.exe -> [2007/11/07 09:35:40 | 00,378,184 | —- | M] (McAfee, Inc.)
(McProxy) McAfee Proxy Service [Win32_Own | Auto | Running] -> %SystemDrive%\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe -> [2007/08/15 12:36:04 | 00,359,248 | —- | M] (McAfee, Inc.)
(McShield) McAfee Real-time Scanner [Win32_Own | Unknown | Running] -> %SystemDrive%\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe -> [2007/07/24 12:02:14 | 00,144,704 | —- | M] (McAfee, Inc.)
(McSysmon) McAfee SystemGuards [Win32_Own | Disabled | Stopped] -> %SystemDrive%\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe -> [2007/12/05 10:04:10 | 00,695,624 | —- | M] (McAfee, Inc.)
(Microsoft Office Groove Audit Service) Microsoft Office Groove Audit Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Microsoft Office\Office12\GrooveAuditService.exe -> [2007/08/24 06:59:20 | 00,068,464 | —- | M] (Microsoft Corporation)
(MpfService) McAfee Personal Firewall Service [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee\MPF\MPFSrv.exe -> [2007/07/18 15:54:42 | 00,856,864 | —- | M] (McAfee, Inc.)
(NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\nvsvc32.exe -> [2006/07/20 05:58:00 | 00,143,426 | —- | M] (NVIDIA Corporation)
(odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2007/08/24 03:19:12 | 00,443,776 | —- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2006/10/26 14:03:08 | 00,145,184 | —- | M] (Microsoft Corporation)
(RegSrvc) Intel(R) PROSet/Wireless Registry Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\RegSrvc.exe -> [2005/11/28 11:28:14 | 00,217,164 | —- | M] (Intel Corporation)
(RichVideo) Cyberlink RichVideo Service(CRVS) [Win32_Own | Auto | Running] -> %ProgramFiles%\CyberLink\Shared Files\RichVideo.exe -> [2005/01/21 04:37:16 | 00,143,360 | —- | M] ()
(S24EventMonitor) Intel(R) PROSet/Wireless Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\S24EvMon.exe -> [2005/11/28 11:31:32 | 00,540,745 | —- | M] (Intel Corporation )
(Symantec Core LC) Symantec Core LC [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\CCPD-LC\symlcsvc.exe -> [2008/06/11 18:51:50 | 01,251,720 | —- | M] ()
(winvnc) VNC Server [Win32_Own | On_Demand | Stopped] ->  -> File not found
 
[Driver Services - Safe List]
(AegisP) AEGIS Protocol (IEEE 802.1x) v3.4.9.0 [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\AegisP.sys -> [2006/12/26 02:46:28 | 00,021,275 | —- | M] (Meetinghouse Data Communications)
(AliIde) AliIde [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\aliide.sys -> [2004/08/04 05:00:00 | 00,005,248 | —- | M] (Acer Laboratories Inc.)
(amdagp) AMD AGP Bus Filter Driver [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\amdagp.sys -> [2004/08/03 23:07:44 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.)
(asc) asc [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\asc.sys -> [2004/08/04 05:00:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.)
(asc3550) asc3550 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\asc3550.sys -> [2004/08/04 05:00:00 | 00,014,848 | —- | M] (Advanced System Products, Inc.)
(bcm4sbxp) Broadcom 440x 10/100 Integrated Controller XP Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\bcm4sbxp.sys -> [2005/10/31 14:17:00 | 00,045,312 | —- | M] (Broadcom Corporation)
(BthEnum) Bluetooth Request Block Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\BthEnum.sys -> [2004/08/04 05:00:00 | 00,017,024 | —- | M] (Microsoft Corporation)
(BthPan) Bluetooth Device (Personal Area Network) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\bthpan.sys -> [2004/08/04 05:00:00 | 00,100,992 | —- | M] (Microsoft Corporation)
(BTHPORT) Bluetooth Port Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\BTHport.sys -> [2008/06/13 08:10:50 | 00,272,128 | —- | M] (Microsoft Corporation)
(BTHUSB) Bluetooth Radio USB Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\BTHUSB.sys -> [2004/08/04 05:00:00 | 00,018,944 | —- | M] (Microsoft Corporation)
(CmdIde) CmdIde [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\cmdide.sys -> [2004/08/04 05:00:00 | 00,006,656 | —- | M] (CMD Technology, Inc.)
(CVirtA) Cisco Systems VPN Adapter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\CVirtA.sys -> [2003/05/01 13:26:34 | 00,005,220 | —- | M] (Cisco Systems, Inc.)
(CVPNDRVA) Cisco Systems IPsec Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\Drivers\CVPNDRVA.sys -> [2004/12/06 16:17:18 | 00,268,872 | —- | M] (Cisco Systems, Inc.)
(dac2w2k) dac2w2k [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\dac2w2k.sys -> [2004/08/04 05:00:00 | 00,179,584 | —- | M] (Mylex Corporation)
(DKbFltr) Dritek Keyboard Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\DKbFltr.sys -> [2004/12/08 14:10:00 | 00,016,896 | —- | M] (Dritek System Inc.)
(DNE) Deterministic Network Enhancer Miniport [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\dne2000.sys -> [2003/07/24 18:55:50 | 00,139,604 | —- | M] (Deterministic Networks, Inc.)
(eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> %CommonProgramFiles%\Symantec Shared\EENGINE\eeCtrl.sys -> [2007/02/06 03:00:00 | 00,383,800 | —- | M] (Symantec Corporation)
(EMSCR) EMSCR [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\EMS7SK.sys -> [2006/06/16 19:17:36 | 00,061,056 | —- | M] (ENE Technology Inc.)
(EpmPsd) Acer EPM Power Scheme Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\epm-psd.sys -> [2006/01/23 12:41:04 | 00,004,096 | —- | M] (Acer Value Labs, USA)
(EpmShd) Acer EPM System Hardware Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\epm-shd.sys -> [2006/01/23 12:41:04 | 00,078,208 | —- | M] (Acer Value Labs, USA)
(ESDCR) ESDCR [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ESD7SK.sys -> [2006/06/16 19:17:38 | 00,040,064 | —- | M] (ENE Technology Inc.)
(ESMCR) ESMCR [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ESM7SK.sys -> [2006/06/16 19:17:38 | 00,074,752 | —- | M] (ENE Technology Inc.)
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\Drivers\GEARAspiWDM.sys -> [2008/04/17 13:12:54 | 00,015,464 | —- | M] (GEAR Software Inc.)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HDAudBus.sys -> [2005/01/07 17:07:18 | 00,138,752 | —- | M] (Windows (R) Server 2003 DDK provider)
(HSFHWAZL) HSFHWAZL [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSFHWAZL.sys -> [2005/10/24 10:20:52 | 00,218,496 | —- | M] (Conexant Systems, Inc.)
(HSF_DPV) HSF_DPV [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSF_DPV.sys -> [2005/10/18 16:53:24 | 00,998,656 | —- | M] (Conexant Systems, Inc.)
(ialm) ialm [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\ialmnt5.sys -> [2006/03/23 12:47:06 | 01,166,972 | —- | M] (Intel Corporation)
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\RtkHDAud.sys -> [2007/03/26 19:21:06 | 04,395,008 | R— | M] (Realtek Semiconductor Corp.)
(lv321av) Logitech USB PC Camera (VC0321) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\lv321av.sys -> [2006/06/19 12:20:24 | 01,097,728 | —- | M] (Logitech)
(lvmvdrv) Logitech Machine Vision Engine Loader [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\lvmvdrv.sys -> [2006/06/23 10:40:58 | 02,400,128 | —- | M] ()
(LVPrcMon) Logitech LVPrcMon Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\LVPrcMon.sys -> [2006/06/23 10:40:58 | 00,016,768 | —- | M] ()
(LVUSBSta) Logitech USB Monitor Filter [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\lvusbsta.sys -> [2006/06/19 12:16:16 | 00,039,424 | —- | M] (Logitech)
(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\mdmxsdk.sys -> [2005/10/05 15:57:08 | 00,012,544 | —- | M] (Conexant)
(mfeavfk) McAfee Inc. mfeavfk [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\mfeavfk.sys -> [2007/11/22 06:44:08 | 00,079,304 | —- | M] (McAfee, Inc.)
(mfebopk) McAfee Inc. mfebopk [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\mfebopk.sys -> [2007/11/22 06:44:08 | 00,035,240 | —- | M] (McAfee, Inc.)
(mfehidk) McAfee Inc. mfehidk [Kernel | System | Running] -> %SystemRoot%\system32\drivers\mfehidk.sys -> [2007/11/22 06:44:08 | 00,201,320 | —- | M] (McAfee, Inc.)
(mferkdk) McAfee Inc. mferkdk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\mferkdk.sys -> [2007/11/22 06:44:04 | 00,033,832 | —- | M] (McAfee, Inc.)
(mfesmfk) McAfee Inc. mfesmfk [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\mfesmfk.sys -> [2007/12/02 12:51:42 | 00,040,488 | —- | M] (McAfee, Inc.)
(MPFP) MPFP [Kernel | System | Running] -> %SystemRoot%\System32\Drivers\Mpfp.sys -> [2007/07/13 06:20:24 | 00,113,952 | —- | M] (McAfee, Inc.)
(mraid35x) mraid35x [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\mraid35x.sys -> [2004/08/04 05:00:00 | 00,017,280 | —- | M] (American Megatrends Inc.)
(NdisFilt) OSA NdisFilter Protocol [Kernel | On_Demand | Running] -> %SystemRoot%\System32\Drivers\NdisFilt.sys -> [2005/09/13 15:34:40 | 00,004,392 | —- | M] (OSA Technologies)
(NETMNT) Acer NetMonitor Protocol [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\NETMNT.sys -> [2005/05/02 12:13:42 | 00,009,600 | —- | M] ()
(NPF) NetGroup Packet Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\npf.sys -> [2006/01/23 12:41:42 | 00,032,512 | —- | M] (CACE Technologies)
(NTIDrvr) Upper Class Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\NTIDrvr.sys -> [2006/08/23 03:01:10 | 00,006,144 | —- | M] (NewTech Infosystems, Inc.)
(nv) nv [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\nv4_mini.sys -> [2006/07/20 05:58:00 | 03,685,152 | —- | M] (NVIDIA Corporation)
(OsaFsLoc) OsaFsLoc [Kernel | System | Running] -> %SystemRoot%\system32\drivers\OsaFsLoc.sys -> [2005/10/15 18:20:44 | 00,012,106 | —- | M] (OSA Technologies)
(osaio) osaio [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\osaio.sys -> [2005/06/30 16:58:24 | 00,007,296 | —- | M] (OSA Technologies, An Avocent Company)
(osanbm) osanbm [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\osanbm.sys -> [2005/01/14 15:57:16 | 00,004,010 | —- | M] (Windows (R) 2000 DDK provider)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ptilink.sys -> [2004/08/04 05:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(ql1080) ql1080 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\ql1080.sys -> [2004/08/04 05:00:00 | 00,040,320 | —- | M] (QLogic Corporation)
(ql12160) ql12160 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\ql12160.sys -> [2004/08/04 05:00:00 | 00,045,312 | —- | M] (QLogic Corporation)
(ql1280) ql1280 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\ql1280.sys -> [2004/08/04 05:00:00 | 00,049,024 | —- | M] (QLogic Corporation)
(RFCOMM) Bluetooth Device (RFCOMM Protocol TDI) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\rfcomm.sys -> [2004/08/04 05:00:00 | 00,059,648 | —- | M] (Microsoft Corporation)
(s24trans) WLAN Transport [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\s24trans.sys -> [2005/11/28 12:09:26 | 00,013,568 | —- | M] (Intel Corporation)
(sdbus) sdbus [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\sdbus.sys -> [2004/08/04 05:00:00 | 00,067,584 | —- | M] (Microsoft Corporation)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\secdrv.sys -> [2007/11/13 04:25:54 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sisagp) SIS AGP Bus Filter [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\sisagp.sys -> [2004/08/03 23:07:44 | 00,041,088 | —- | M] (Silicon Integrated Systems Corporation)
(SMCIRDA) SMSC IrCC Miniport Device Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\smcirda.sys -> [2005/10/31 14:16:00 | 00,046,080 | —- | M] (SMSC)
(Sparrow) Sparrow [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\sparrow.sys -> [2004/08/04 05:00:00 | 00,019,072 | —- | M] (Adaptec, Inc.)
(symc810) symc810 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\symc810.sys -> [2004/08/04 05:00:00 | 00,016,256 | —- | M] (Symbios Logic Inc.)
(symc8xx) symc8xx [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\symc8xx.sys -> [2004/08/04 05:00:00 | 00,032,640 | —- | M] (LSI Logic)
(symlcbrd) symlcbrd [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\symlcbrd.sys -> [2006/08/23 03:38:10 | 00,010,344 | —- | M] (Symantec Corporation)
(sym_hi) sym_hi [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\sym_hi.sys -> [2004/08/04 05:00:00 | 00,028,384 | —- | M] (LSI Logic)
(sym_u3) sym_u3 [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\sym_u3.sys -> [2004/08/04 05:00:00 | 00,030,688 | —- | M] (LSI Logic)
(SynTP) Synaptics TouchPad Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\SynTP.sys -> [2006/03/03 12:52:30 | 00,192,672 | —- | M] (Synaptics, Inc.)
(UBHelper) UBHelper [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\UBHelper.sys -> [2004/12/17 17:14:44 | 00,013,952 | —- | M] ()
(ultra) ultra [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\ultra.sys -> [2004/08/04 05:00:00 | 00,036,736 | —- | M] (Promise Technology, Inc.)
(vsdatant) vsdatant [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\vsdatant.sys -> [2003/08/28 21:40:26 | 00,189,792 | —- | M] (Zone Labs Inc.)
(w39n51) Intel(R) PRO/Wireless 3945ABG Adapter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\w39n51.sys -> [2006/04/03 12:17:24 | 01,429,632 | —- | M] (Intel® Corporation)
(winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HSF_CNXT.sys -> [2005/10/18 16:52:30 | 00,721,280 | —- | M] (Conexant Systems, Inc.)
(WmiAcpi) Microsoft Windows Management Interface for ACPI [Kernel | System | Running] -> %SystemRoot%\system32\DRIVERS\wmiacpi.sys -> [2004/08/03 23:07:42 | 00,008,832 | —- | M] (Microsoft Corporation)
(WS2IFSL) Windows Socket 2.0 Non-IFS Service Provider Support Environment [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\drivers\ws2ifsl.sys -> [2004/08/04 05:00:00 | 00,012,032 | —- | M] (Microsoft Corporation)
(int15.sys) int15.sys [Kernel | Auto | Running] -> %SystemDrive%\Acer\Empowering Technology\eRecovery\int15.sys -> [2005/01/13 14:46:16 | 00,069,632 | —- | M] ()
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" ->  -> 
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://en.us.acer.yahoo.com -> 
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://www.google.com/ie -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.google.com -> 
HKEY_CURRENT_USER\: Main\\"SearchMigratedDefaultName" -> Yahoo! Search -> 
HKEY_CURRENT_USER\: Main\\"SearchMigratedDefaultURL" -> http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 -> 
HKEY_CURRENT_USER\: Main\\"Start Page" -> about:blank -> 
HKEY_CURRENT_USER\: SearchURL\\"" -> http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com -> 
HKEY_CURRENT_USER\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn0\yt.dll [Yahoo! Toolbar] -> [2007/09/05 15:48:58 | 00,816,400 | —- | M] (Yahoo! Inc.)
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 -> 
HKEY_CURRENT_USER\: "ProxyOverride" -> *.local -> 
< FireFox Settings [Default Profile] > -> C:\Documents and Settings\Maryann\Application Data\Mozilla\FireFox\Profiles\b1p0iryz.default\prefs.js -> 
browser.startup.homepage_override.mstone -> "rv:1.8.1.4" ->
< HOSTS File > (734 bytes and 19 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
127.0.0.1	   localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{02478D38-C3F9-4EFB-9B51-7695ECA05670} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn0\yt.dll [&Yahoo! Toolbar Helper] -> [2007/09/05 15:48:58 | 00,816,400 | —- | M] (Yahoo! Inc.)
{4e5ffa00-4f7f-43c2-874d-43b84ce07067} [HKLM] -> %SystemRoot%\system32\examuy.dll [Reg Error: Value  does not exist or could not be read.] -> [2008/11/30 22:30:20 | 00,129,024 | —- | M] ()
{7274C06D-C70A-4DEF-876E-BBE9F9E6E1E1} [HKLM] -> %SystemRoot%\system32\qoMffFYr.dll [Reg Error: Value  does not exist or could not be read.] -> [2008/11/26 11:12:36 | 00,318,464 | —- | M] ()
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\ssv.dll [SSVHelper Class] -> [2008/06/10 04:27:02 | 00,509,328 | —- | M] (Sun Microsystems, Inc.)
{8bc485fd-d543-44f0-8a1d-9c6e90fc088f} [HKLM] -> %SystemRoot%\system32\veglaf.dll [Reg Error: Value  does not exist or could not be read.] -> [2008/11/30 22:30:02 | 00,075,776 | —- | M] ()
{A057A204-BACC-4D26-CEC4-75A487FD6484} [HKLM] -> %SystemDrive%\PROGRA~1\mypoints\mypoints.dll [MYPOINTS] -> [2008/10/29 18:45:34 | 01,909,248 | —- | M] (Infospace									)
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\google\googletoolbar3.dll [Google Toolbar Helper] -> [2007/01/19 23:55:32 | 02,403,392 | R— | M] (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> %ProgramFiles%\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [Google Toolbar Notifier BHO] -> [2008/10/30 19:56:50 | 00,737,776 | —- | M] (Google Inc.)
{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} [HKLM] -> %ProgramFiles%\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [EpsonToolBandKicker Class] -> [2005/02/22 13:50:34 | 00,368,640 | —- | M] (SEIKO EPSON CORPORATION)
{fba9acc7-9a24-4a1f-972c-807dde81eceb} [HKLM] -> %SystemRoot%\system32\heyehita.dll [Reg Error: Value  does not exist or could not be read.] -> [2008/08/28 21:17:10 | 00,061,952 | -HS- | M] ()
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\google\googletoolbar3.dll [&Google] -> [2007/01/19 23:55:32 | 02,403,392 | R— | M] (Google Inc.)
"{5CBE3B7C-1E47-477e-A7DD-396DB0476E29}" [HKLM] -> %SystemRoot%\system32\eDStoolbar.dll [Acer eDataSecurity Management] -> [2006/02/22 12:50:56 | 00,106,496 | —- | M] (HiTRUST)
"{A057A204-BACC-4D26-CEC4-75A487FD6484}" [HKLM] -> %SystemDrive%\PROGRA~1\mypoints\mypoints.dll [MYPOINTS] -> [2008/10/29 18:45:34 | 01,909,248 | —- | M] (Infospace									)
"{EE5D279F-081B-4404-994D-C6B60AAEBA6D}" [HKLM] -> %ProgramFiles%\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [EPSON Web-To-Page] -> [2005/02/22 13:50:34 | 00,368,640 | —- | M] (SEIKO EPSON CORPORATION)
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn0\yt.dll [Yahoo! Toolbar] -> [2007/09/05 15:48:58 | 00,816,400 | —- | M] (Yahoo! Inc.)
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 
ShellBrowser\\"{C4069E3A-68F1-403E-B40E-20066696354B}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> %ProgramFiles%\google\googletoolbar3.dll [&Google] -> [2007/01/19 23:55:32 | 02,403,392 | R— | M] (Google Inc.)
WebBrowser\\"{5BED3930-2E9E-76D8-BACC-80DF2188D455}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\"{A057A204-BACC-4D26-CEC4-75A487FD6484}" [HKLM] -> %SystemDrive%\PROGRA~1\mypoints\mypoints.dll [MYPOINTS] -> [2008/10/29 18:45:34 | 01,909,248 | —- | M] (Infospace									)
WebBrowser\\"{EE5D279F-081B-4404-994D-C6B60AAEBA6D}" [HKLM] -> %ProgramFiles%\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [EPSON Web-To-Page] -> [2005/02/22 13:50:34 | 00,368,640 | —- | M] (SEIKO EPSON CORPORATION)
WebBrowser\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn0\yt.dll [Yahoo! Toolbar] -> [2007/09/05 15:48:58 | 00,816,400 | —- | M] (Yahoo! Inc.)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"" ->  [] -> File not found
"320d18a1" -> %SystemRoot%\system32\eyjeocid.DLL [rundll32.exe "C:\WINDOWS\system32\eyjeocid.dll",b] -> [2008/11/30 22:29:36 | 00,072,704 | —- | M] ()
"Acer ePower Management" -> %SystemDrive%\Acer\Empowering Technology\ePower\Acer ePower Management.exe [C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot] -> [2006/05/22 12:54:00 | 03,080,704 | —- | M] (Acer Value Labs, Taiwan)
"ADMTray.exe" -> %SystemDrive%\Acer\Empowering Technology\admtray.exe ["C:\Acer\Empowering Technology\admtray.exe"] -> [2005/10/24 16:45:32 | 02,462,208 | —- | M] (Avocent Inc.)
"Adobe Photo Downloader" -> %ProgramFiles%\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe ["C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"] -> [2007/03/09 11:09:58 | 00,063,712 | —- | M] (Adobe Systems Incorporated)
"Adobe Reader Speed Launcher" -> %ProgramFiles%\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008/01/11 22:16:38 | 00,039,792 | —- | M] (Adobe Systems Incorporated)
"Alcmtr" -> %SystemRoot%\ALCMTR.EXE [ALCMTR.EXE] -> [2005/05/03 18:43:28 | 00,069,632 | —- | M] (Realtek Semiconductor Corp.)
"AppleSyncNotifier" -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe] -> [2008/09/03 20:12:50 | 00,111,936 | —- | M] (Apple Inc.)
"AzMixerSel" -> %ProgramFiles%\Realtek\InstallShield\AzMixerSel.exe [C:\Program Files\Realtek\InstallShield\AzMixerSel.exe] -> [2005/12/21 15:02:36 | 00,053,248 | —- | M] (Realtek Semiconductor Corp.)
"BluetoothAuthenticationAgent" -> %SystemRoot%\system32\bthprops.CPL [rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent] -> [2004/08/04 05:00:00 | 00,110,592 | —- | M] (Microsoft Corporation)
"eDataSecurity Loader" -> %SystemDrive%\Acer\Empowering Technology\eDataSecurity\eDSloader.exe [C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe] -> [2005/12/27 15:50:28 | 00,069,632 | —- | M] (HiTRUST)
"ePower_DMC" -> %SystemDrive%\Acer\Empowering Technology\ePower\ePower_DMC.exe [C:\Acer\Empowering Technology\ePower\ePower_DMC.exe] -> [2006/08/10 19:29:14 | 00,352,256 | —- | M] (Acer Incorporated)
"EPSON Stylus Photo R340 Series" -> %SystemRoot%\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O5 "LPT1:" /M "Stylus Photo R340"] -> [2005/04/26 04:00:00 | 00,098,304 | —- | M] (SEIKO EPSON CORPORATION)
"eRecoveryService" -> %SystemDrive%\Acer\Empowering Technology\eRecovery\Monitor.exe [C:\Acer\Empowering Technology\eRecovery\Monitor.exe] -> [2006/01/24 18:00:08 | 00,397,312 | —- | M] (acer Inc.)
"Google Desktop Search" ->  ["C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup] -> File not found
"GrooveMonitor" -> %ProgramFiles%\Microsoft Office\Office12\GrooveMonitor.exe ["C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"] -> [2007/08/24 07:00:48 | 00,033,648 | —- | M] (Microsoft Corporation)
"igfxhkcmd" -> %SystemRoot%\system32\hkcmd.exe [C:\WINDOWS\system32\hkcmd.exe] -> [2006/03/23 12:13:40 | 00,077,824 | —- | M] (Intel Corporation)
"igfxpers" -> %SystemRoot%\system32\igfxpers.exe [C:\WINDOWS\system32\igfxpers.exe] -> [2006/03/23 12:17:50 | 00,118,784 | —- | M] (Intel Corporation)
"igfxtray" -> %SystemRoot%\system32\igfxtray.exe [C:\WINDOWS\system32\igfxtray.exe] -> [2006/03/23 12:17:04 | 00,094,208 | —- | M] (Intel Corporation)
"IMJPMIG8.1" -> %SystemRoot%\IME\imjp8_1\IMJPMIG.EXE ["C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32] -> [2004/08/04 05:00:00 | 00,208,952 | —- | M] (Microsoft Corporation)
"iTunesHelper" -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2008/10/01 18:57:12 | 00,289,576 | —- | M] (Apple Inc.)
"LaunchApp" -> %SystemRoot%\Alaunch.exe [Alaunch] -> [2005/06/22 09:36:20 | 00,520,192 | —- | M] (Acer Inc.)
"LManager" -> %SystemDrive%\PROGRA~1\LAUNCH~1\LManager.exe [C:\PROGRA~1\LAUNCH~1\LManager.exe] -> [2006/07/20 22:15:32 | 00,593,920 | —- | M] (Dritek System Inc.)
"LogitechCameraAssistant" -> %ProgramFiles%\Acer\OrbiCam\CameraAssistant.exe [C:\Program Files\Acer\OrbiCam\CameraAssistant.exe] -> [2006/06/26 15:47:48 | 00,331,776 | —- | M] (Acer)
"LogitechCameraService(E)" -> %SystemRoot%\system32\ElkCtrl.exe [C:\WINDOWS\system32\ElkCtrl.exe /automation] -> [2004/11/01 18:22:22 | 00,262,144 | —- | M] (Logitech Inc.)
"LogitechVideo[inspector]" -> %ProgramFiles%\Acer\OrbiCam\InstallHelper.exe [C:\Program Files\Acer\OrbiCam\InstallHelper.exe /inspect] -> [2006/06/26 15:55:20 | 00,073,728 | —- | M] (Acer)
"LVCOMSX" -> %SystemRoot%\system32\LVCOMSX.EXE [C:\WINDOWS\system32\LVCOMSX.EXE] -> [2006/06/23 10:39:54 | 00,225,280 | —- | M] (Logitech)
"MBkLogOnHook" -> %ProgramFiles%\McAfee\MBK\LogOnHook.exe [C:\Program Files\McAfee\MBK\LogOnHook.exe] -> [2007/01/08 11:22:46 | 00,020,480 | —- | M] (McAfee)
"McAfee Backup" -> %ProgramFiles%\McAfee\MBK\McAfeeDataBackup.exe [C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe] -> [2007/01/16 13:59:50 | 04,838,952 | —- | M] (McAfee)
"mcagent_exe" -> %ProgramFiles%\McAfee.com\Agent\mcagent.exe [C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey] -> [2007/11/01 18:12:38 | 00,582,992 | —- | M] (McAfee, Inc.)
"MSPY2002" -> \WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC] -> [2004/08/04 05:00:00 | 00,059,392 | —- | M] ()
"ntiMUI" -> %ProgramFiles%\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe [C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe] -> [2006/05/15 11:15:06 | 00,045,056 | —- | M] ()
"NvCplDaemon" -> %SystemRoot%\system32\NvCpl.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2006/07/20 05:58:00 | 07,581,696 | —- | M] (NVIDIA Corporation)
"NvMediaCenter" -> %SystemRoot%\system32\NvMcTray.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit] -> [2006/07/20 05:58:00 | 00,086,016 | —- | M] (NVIDIA Corporation)
"nwiz" -> %SystemRoot%\system32\nwiz.exe [nwiz.exe /install] -> [2006/07/20 05:58:00 | 01,519,616 | —- | M] ()
"PCMService" -> %ProgramFiles%\Acer\Acer Arcade\PCMService.exe ["C:\Program Files\Acer\Acer Arcade\PCMService.exe"] -> [2006/08/09 22:29:08 | 00,151,552 | —- | M] (CyberLink Corp.)
"PHIME2002A" -> %SystemRoot%\system32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName] -> [2004/08/04 05:00:00 | 00,455,168 | —- | M] (Microsoft Corporation)
"PHIME2002ASync" -> \WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC] -> [2004/08/04 05:00:00 | 00,455,168 | —- | M] ()
"QuickTime Task" -> %ProgramFiles%\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> [2008/09/06 15:09:14 | 00,413,696 | —- | M] (Apple Inc.)
"rirawapola" -> %SystemRoot%\system32\demohajo.DLL [Rundll32.exe "C:\WINDOWS\system32\demohajo.dll",s] -> [2008/08/28 21:17:10 | 00,061,952 | -HS- | M] ()
"RTHDCPL" -> %SystemRoot%\RTHDCPL.EXE [RTHDCPL.EXE] -> [2007/03/21 14:49:20 | 16,126,464 | R— | M] (Realtek Semiconductor Corp.)
"SunJavaUpdateSched" -> %ProgramFiles%\Java\jre1.6.0_07\bin\jusched.exe ["C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"] -> [2008/06/10 04:27:04 | 00,144,784 | —- | M] (Sun Microsystems, Inc.)
"SynTPEnh" -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] -> [2006/03/03 13:07:38 | 00,761,946 | —- | M] (Synaptics, Inc.)
"WinVNC" -> %ProgramFiles%\TightVNC\WinVNC.exe ["C:\Program Files\TightVNC\WinVNC.exe" -servicehelper] -> File not found
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"swg" -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> [2007/06/26 12:21:14 | 00,068,856 | —- | M] (Google Inc.)
"updateMgr" -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9] -> File not found
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
%AllUsersProfile%\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk -> %ProgramFiles%\Cisco Systems\VPN Client\vpngui.exe -> [2004/12/06 16:18:22 | 01,474,576 | —- | M] (Cisco Systems, Inc.)
< Maryann Startup Folder > -> C:\Documents and Settings\Maryann\Start Menu\Programs\Startup -> 
%UserProfile%\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk -> %ProgramFiles%\Microsoft Office\Office12\ONENOTEM.EXE -> [2007/12/07 20:44:36 | 00,101,440 | —- | M] (Microsoft Corporation)
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
\\"NoBandCustomize" ->  [0] -> File not found
\\"NoMovingBands" ->  [0] -> File not found
\\"NoCloseDragDropBands" ->  [0] -> File not found
\\"NoSetTaskbar" ->  [0] -> File not found
\\"NoToolbarsOnTaskbar" ->  [0] -> File not found
\\"NoSaveSettings" ->  [0] -> File not found
\\"NoActiveDesktop" ->  [0] -> File not found
\\"ClassicShell" ->  [0] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> 
&eBay Search -> %ProgramFiles%\eBay\eBay Toolbar2\eBayTb.dll [res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html] -> File not found
E&xport to Microsoft Excel -> %SystemDrive%\PROGRA~1\MICROS~4\Office12\EXCEL.EXE [res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000] -> [2008/07/30 03:25:02 | 17,930,264 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Menu: Sun Java Console] -> [2008/06/10 04:27:02 | 00,132,496 | —- | M] (Sun Microsystems, Inc.)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> %SystemDrive%\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll [Button: Send to OneNote] -> [2007/12/13 02:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> %SystemDrive%\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll [Menu: S&end to OneNote] -> [2007/12/13 02:20:58 | 00,606,288 | —- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %SystemDrive%\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL [Button: Research] -> [2006/10/26 20:12:22 | 00,040,424 | —- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2006/10/10 06:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2004/10/13 10:24:38 | 01,694,208 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2004/10/13 10:24:38 | 01,694,208 | —- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/13 10:24:38 | 01,694,208 | —- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 
update_microsoft.com [http] -> Trusted sites -> 
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} [HKLM] -> http://upload.facebook.com/controls/FacebookPhotoUploader3.cab[Facebook Photo Uploader 4 Control] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1220404172398&h=389c871dea29a6d78db8a31000ba26a3/&filename=jinstall-6u7-windows-i586-jc.cab[Java Plug-in 1.6.0_07] -> 
{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab[Java Plug-in 1.5.0_11] -> 
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab[Java Plug-in 1.6.0_01] -> 
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab[Java Plug-in 1.6.0_02] -> 
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab[Java Plug-in 1.6.0_07] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab[Java Plug-in 1.6.0_07] -> 
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> 
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{4BBD2084-F950-408B-B3C2-31AD3D4F2A3E} ->	(Broadcom 440x 10/100 Integrated Controller) -> 
{85A7FC9C-911D-4141-9F2F-3EBED9E85850} ->	() -> 
{9483339E-B024-4293-BD0D-BE1C63933A1C} ->	(Intel(R) PRO/Wireless 3945ABG Network Connection) -> 
{E1F03A83-4639-4726-9F79-644561FD2E84} ->	() -> 
{E9B00B7B-F433-424E-AF0B-D087D652E608} ->	() -> 
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> 
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> 
C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL -> %SystemDrive%\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL -> [2008/09/02 15:44:56 | 00,113,664 | —- | M] (Google)
C:\WINDOWS\system32\pazodoga.dll examuy.dll -> %SystemRoot%\system32\pazodoga.dll examuy.dll -> File not found
*MultiFile Done* -> -> 
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 
igfxcui -> %SystemRoot%\system32\igfxdev.dll -> [2006/03/23 12:12:42 | 00,139,264 | —- | M] (Intel Corporation)
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> 
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\GrooveShellExtensions.dll [Groove GFS Stub Execution Hook] -> [2007/08/24 07:01:22 | 02,212,224 | —- | M] (Microsoft Corporation)
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> 
*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> 
C:\WINDOWS\system32\qoMffFYr -> %SystemRoot%\system32\qoMffFYr.dll -> [2008/11/26 11:12:36 | 00,318,464 | —- | M] ()
*MultiFile Done* -> -> 
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006/10/10 06:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/04 05:00:00 | 00,140,800 | —- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2006/10/10 06:44:50 | 00,557,568 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2004/08/04 05:00:00 | 00,140,800 | —- | M] (Microsoft Corporation)
"C:\Program Files\Acer\Acer Arcade\PCMService.exe" -> C:\Program Files\Acer\Acer Arcade\PCMService.exe [C:\Program Files\Acer\Acer Arcade\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program] -> [2006/08/09 22:29:08 | 00,151,552 | —- | M] (CyberLink Corp.)
"C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008/08/29 10:18:44 | 00,238,888 | —- | M] (Apple Inc.)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" -> C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe [C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent] -> [2008/01/25 01:38:12 | 02,458,128 | —- | M] (McAfee, Inc.)
"C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2008/10/01 18:57:04 | 14,258,472 | —- | M] (Apple Inc.)
"C:\Program Files\Messenger\msmsgs.exe" -> C:\Program Files\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> [2004/10/13 10:24:38 | 01,694,208 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" -> C:\Program Files\Microsoft Office\Office12\GROOVE.EXE [C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove] -> [2007/08/29 00:23:36 | 00,340,856 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" -> C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE [C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote] -> [2008/05/21 05:54:40 | 01,022,496 | —- | M] (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" -> C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook] -> [2008/05/21 04:37:24 | 12,844,576 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\Explorer.EXE" -> C:\WINDOWS\Explorer.EXE [C:\WINDOWS\Explorer.EXE:*:Enabled:Explorer] -> [2007/06/13 05:23:08 | 01,033,216 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\System32\logonui.exe" -> C:\WINDOWS\System32\logonui.exe [C:\WINDOWS\System32\logonui.exe:*:Enabled:logonui] -> [2004/08/04 05:00:00 | 00,514,560 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\System32\LSASS.EXE" -> C:\WINDOWS\System32\LSASS.EXE [C:\WINDOWS\System32\LSASS.EXE:*:Enabled:lsass] -> [2004/08/04 05:00:00 | 00,013,312 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\System32\SERVICES.EXE" -> C:\WINDOWS\System32\SERVICES.EXE [C:\WINDOWS\System32\SERVICES.EXE:*:Enabled:services] -> [2004/08/04 05:00:00 | 00,108,032 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\System32\WINLOGON.EXE" -> C:\WINDOWS\System32\WINLOGON.EXE [C:\WINDOWS\System32\WINLOGON.EXE:*:Enabled:winlogon] -> [2004/08/04 05:00:00 | 00,502,272 | —- | M] (Microsoft Corporation)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
"AlternateShell" -> cmd.exe -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" -> %SystemRoot%\system32\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2004/08/04 05:00:00 | 00,049,536 | —- | M] (Microsoft Corporation)
< Drives with AutoRun files > ->  -> 
C:\AUTOEXEC.BAT [PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | ] -> %SystemDrive%\AUTOEXEC.BAT [ FAT32 ] -> [2006/08/23 03:02:06 | 00,000,050 | —- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
 
[Registry - Additional Scans - Safe List]
< ColumnHandlers - Folder [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\ -> 
{F9DB5320-233E-11D1-9F84-707F02C10627} [HKLM] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\PDFShell.dll [PDF Shell Extension] -> [2007/05/10 22:54:08 | 00,372,736 | —- | M] (Adobe Systems, Inc.)
< Desktop Components > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\ -> 
0 -> [Key] -> 
0 -> FriendlyName =  -> 
0 -> Source = file:///C:/DOCUME~1/Maryann/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg -> 
0 -> SubscribedURL = file:///C:/DOCUME~1/Maryann/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg -> 
1 -> [Key] -> 
1 -> FriendlyName = My Current Home Page -> 
1 -> Source = About:Home -> 
1 -> SubscribedURL = About:Home -> 
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> 
.bat [@ = batfile] -> "%1" %* -> 
.chm [@ = chm.file] -> %SystemRoot%\hh.exe -> [2005/05/26 17:22:02 | 00,010,752 | —- | M] (Microsoft Corporation)
.cmd [@ = cmdfile] -> "%1" %* -> 
.com [@ = comfile] -> "%1" %* -> 
.exe [@ = exefile] -> "%1" %* -> 
.hlp [@ = hlpfile] -> %SystemRoot%\System32\winhlp32.exe -> [2004/08/04 05:00:00 | 00,008,192 | —- | M] (Microsoft Corporation)
.hta [@ = htafile] -> %SystemRoot%\system32\mshta.exe -> [2006/10/17 11:56:10 | 00,045,568 | —- | M] (Microsoft Corporation)
.html [@ = htmlfile] -> %ProgramFiles%\Internet Explorer\IEXPLORE.EXE -> [2008/08/23 00:56:16 | 00,635,848 | —- | M] (Microsoft Corporation)
.inf [@ = inffile] -> %SystemRoot%\System32\NOTEPAD.EXE -> [2004/08/04 05:00:00 | 00,069,120 | —- | M] (Microsoft Corporation)
.ini [@ = inifile] -> %SystemRoot%\System32\NOTEPAD.EXE -> [2004/08/04 05:00:00 | 00,069,120 | —- | M] (Microsoft Corporation)
.js [@ = JSFile] -> %SystemRoot%\System32\WScript.exe -> [2004/08/04 05:00:00 | 00,114,688 | —- | M] (Microsoft Corporation)
.jse [@ = JSEFile] -> %SystemRoot%\System32\WScript.exe -> [2004/08/04 05:00:00 | 00,114,688 | —- | M] (Microsoft Corporation)
.pif [@ = piffile] -> "%1" %* -> 
.reg [@ = regfile] -> %SystemRoot%\regedit.exe -> [2004/08/04 05:00:00 | 00,146,432 | —- | M] (Microsoft Corporation)
.scr [@ = scrfile] -> "%1" /S -> 
.txt [@ = txtfile] -> %SystemRoot%\system32\NOTEPAD.EXE -> [2004/08/04 05:00:00 | 00,069,120 | —- | M] (Microsoft Corporation)
.vbe [@ = VBEFile] -> %SystemRoot%\System32\WScript.exe -> [2004/08/04 05:00:00 | 00,114,688 | —- | M] (Microsoft Corporation)
.vbs [@ = VBSFile] -> %SystemRoot%\System32\WScript.exe -> [2004/08/04 05:00:00 | 00,114,688 | —- | M] (Microsoft Corporation)
.wsf [@ = WSFFile] -> %SystemRoot%\System32\WScript.exe -> [2004/08/04 05:00:00 | 00,114,688 | —- | M] (Microsoft Corporation)
.wsh [@ = WSHFile] -> %SystemRoot%\System32\WScript.exe -> [2004/08/04 05:00:00 | 00,114,688 | —- | M] (Microsoft Corporation)
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost > -> ->
*netsvcs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ->
6to4 ->  [] -> 
Ias ->  [] -> 
Iprip ->  [] -> 
Irmon -> C:\WINDOWS\System32\irmon.dll [C:\WINDOWS\System32\irmon.dll] -> [2004/09/30 10:49:36 | 00,027,136 | —- | M] (Microsoft Corporation)
NWCWorkstation ->  [] -> 
Nwsapagent ->  [] -> 
WmdmPmSp ->  [] -> 
helpsvc -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll] -> [2004/08/04 05:00:00 | 00,038,912 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< Protocol Filters [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\ -> 
text/xml:{807563E5-5146-11D5-A672-00B0D022E945} [HKLM] -> %SystemDrive%\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL[Microsoft Office InfoPath XML Mime Filter] -> [2006/10/26 21:41:48 | 00,044,344 | —- | M] (Microsoft Corporation)
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> 
grooveLocalGWS:{88FED34C-F0CA-4636-A375-3CB6248B04CD} [HKLM] -> %ProgramFiles%\Microsoft Office\Office12\GrooveSystemServices.dll[Local Groove Web Services Protocol] -> [2007/08/24 07:01:46 | 00,224,128 | —- | M] (Microsoft Corporation)
ipp: [HKLM] -> No CLSID value
ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> %SystemDrive%\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL[MSDAMON.BINDER] -> [2007/08/28 23:55:14 | 01,014,128 | —- | M] (Microsoft Corporation)
msdaipp: [HKLM] -> No CLSID value
msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> %SystemDrive%\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL[MSDAMON.BINDER] -> [2007/08/28 23:55:14 | 01,014,128 | —- | M] (Microsoft Corporation)
msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> %SystemDrive%\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDAIPP.DLL[MSDAIPP.BINDER] -> [2007/08/28 23:55:14 | 01,014,128 | —- | M] (Microsoft Corporation)
ms-help:{314111c7-a502-11d2-bbca-00c04f8ec294} [HKLM] -> %CommonProgramFiles%\Microsoft Shared\Help\hxds.dll[HxProtocol Class] -> [2006/10/26 13:45:02 | 00,873,216 | —- | M] (Microsoft Corporation)
< SafeBoot-Minimal Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ -> 
{36FC9E60-C465-11CF-8056-444553540000} -> Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} -> CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} -> DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} -> Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} -> Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} -> Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} -> Mouse
{4D36E977-E325-11CE-BFC1-08002BE10318} -> PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} -> SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} -> System
{4D36E980-E325-11CE-BFC1-08002BE10318} -> Floppy disk drive
{71A27CDD-812A-11D0-BEC7-08002BE2092F} -> Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} -> Human Interface Devices
Base -> Driver Group
Boot Bus Extender -> Driver Group
Boot file system -> Driver Group
File system -> Driver Group
Filter -> Driver Group
HelpSvc -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2004/08/04 05:00:00 | 00,038,912 | —- | M] (Microsoft Corporation)
mcmscsvc -> %SystemDrive%\PROGRA~1\McAfee\MSC\mcmscsvc.exe -> [2008/01/09 15:50:22 | 00,767,976 | —- | M] (McAfee, Inc.)
MCODS -> %SystemDrive%\PROGRA~1\McAfee\VIRUSS~1\mcods.exe -> [2007/11/07 09:35:40 | 00,378,184 | —- | M] (McAfee, Inc.)
PCI Configuration -> Driver Group
PNP Filter -> Driver Group
Primary disk -> Driver Group
SCSI Class -> Driver Group
sermouse.sys -> Driver
System Bus Extender -> Driver Group
vga.sys -> Driver
< SafeBoot-Network Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ -> 
{36FC9E60-C465-11CF-8056-444553540000} -> Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} -> CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} -> DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} -> Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} -> Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} -> Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} -> Mouse
{4D36E972-E325-11CE-BFC1-08002BE10318} -> Net
{4D36E973-E325-11CE-BFC1-08002BE10318} -> NetClient
{4D36E974-E325-11CE-BFC1-08002BE10318} -> NetService
{4D36E975-E325-11CE-BFC1-08002BE10318} -> NetTrans
{4D36E977-E325-11CE-BFC1-08002BE10318} -> PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} -> SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} -> System
{4D36E980-E325-11CE-BFC1-08002BE10318} -> Floppy disk drive
{71A27CDD-812A-11D0-BEC7-08002BE2092F} -> Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} -> Human Interface Devices
Base -> Driver Group
Boot Bus Extender -> Driver Group
Boot file system -> Driver Group
File system -> Driver Group
Filter -> Driver Group
HelpSvc -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2004/08/04 05:00:00 | 00,038,912 | —- | M] (Microsoft Corporation)
mcmscsvc -> %SystemDrive%\PROGRA~1\McAfee\MSC\mcmscsvc.exe -> [2008/01/09 15:50:22 | 00,767,976 | —- | M] (McAfee, Inc.)
MCODS -> %SystemDrive%\PROGRA~1\McAfee\VIRUSS~1\mcods.exe -> [2007/11/07 09:35:40 | 00,378,184 | —- | M] (McAfee, Inc.)
MpfService -> %ProgramFiles%\McAfee\MPF\MPFSrv.exe -> [2007/07/18 15:54:42 | 00,856,864 | —- | M] (McAfee, Inc.)
NDIS Wrapper -> Driver Group
NetBIOSGroup -> Driver Group
NetDDEGroup -> Driver Group
Network -> Driver Group
NetworkProvider -> Driver Group
PCI Configuration -> Driver Group
PNP Filter -> Driver Group
PNP_TDI -> Driver Group
Primary disk -> Driver Group
rdpdd.sys -> %SystemRoot%\System32\rdpdd.dll -> [2004/08/04 05:00:00 | 00,092,168 | —- | M] (Microsoft Corporation)
SCSI Class -> Driver Group
sermouse.sys -> Driver
Streams Drivers -> Driver Group
System Bus Extender -> Driver Group
TDI -> Driver Group
vga.sys -> Driver
< Session Manager Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager -> 
"BootExecute" -> autocheck autochk *; -> 
"ExcludeFromKnownDlls" ->  -> 
*ObjectDirectories* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\\ObjectDirectories -> 
\Windows ->  -> File not found
\RPC Control ->  -> File not found
*MultiFile Done* -> -> 
< Session Manager Environment Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment -> 
"ComSpec" -> C:\WINDOWS\system32\cmd.exe -> [2004/08/04 05:00:00 | 00,388,608 | —- | M] (Microsoft Corporation)
"TEMP" -> %SystemRoot%\TEMP -> 
"TMP" -> %SystemRoot%\TEMP -> 
"windir" -> %SystemRoot% -> 
*Path* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\\Path -> 
%SystemRoot%\system32 -> %SystemRoot%\system32 -> [2006/08/10 13:27:22 | 00,000,000 | —D | M]
%SystemRoot% -> %SystemRoot% -> [2006/08/10 13:27:22 | 00,000,000 | —D | M]
%SystemRoot%\System32\Wbem -> %SystemRoot%\System32\Wbem -> [2006/08/23 02:22:00 | 00,000,000 | —D | M]
C:\Program Files\Intel\Wireless\Bin\ -> %ProgramFiles%\Intel\Wireless\Bin -> [2006/12/26 02:44:58 | 00,000,000 | —D | M]
C:\Program Files\QuickTime\QTSystem\ -> %ProgramFiles%\QuickTime\QTSystem -> [2008/09/09 19:37:14 | 00,000,000 | —D | M]
*MultiFile Done* -> -> 
*PATHEXT* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\\PATHEXT -> 
.COM ->  -> File not found
.EXE ->  -> File not found
.BAT ->  -> File not found
.CMD ->  -> File not found
.VBS ->  -> File not found
.VBE ->  -> File not found
.JS ->  -> File not found
.JSE ->  -> File not found
.WSF ->  -> File not found
.WSH ->  -> File not found
*MultiFile Done* -> -> 
< Session Manager FileRenameOperations Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\FileRenameOperations -> 
< Session Manager KnownDlls Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDlls -> 
"advapi32" -> C:\WINDOWS\system32\advapi32.dll -> [2004/08/04 05:00:00 | 00,616,960 | —- | M] (Microsoft Corporation)
"comdlg32" -> C:\WINDOWS\system32\comdlg32.dll -> [2004/08/04 05:00:00 | 00,276,992 | —- | M] (Microsoft Corporation)
"DllDirectory" -> C:\WINDOWS\system32 -> [2006/08/10 13:27:22 | 00,000,000 | —D | M]
"gdi32" -> C:\WINDOWS\system32\gdi32.dll -> [2008/02/20 01:51:06 | 00,282,624 | —- | M] (Microsoft Corporation)
"imagehlp" -> C:\WINDOWS\system32\imagehlp.dll -> [2004/08/04 05:00:00 | 00,144,384 | —- | M] (Microsoft Corporation)
"kernel32" -> C:\WINDOWS\system32\kernel32.dll -> [2007/04/16 10:52:54 | 00,984,576 | —- | M] (Microsoft Corporation)
"lz32" -> C:\WINDOWS\system32\lz32.dll -> [2004/08/04 05:00:00 | 00,002,560 | —- | M] (Microsoft Corporation)
"ole32" -> C:\WINDOWS\system32\ole32.dll -> [2005/07/25 22:39:48 | 01,285,120 | —- | M] (Microsoft Corporation)
"oleaut32" -> C:\WINDOWS\system32\oleaut32.dll -> [2007/12/04 12:38:14 | 00,550,912 | —- | M] (Microsoft Corporation)
"olecli32" -> C:\WINDOWS\system32\olecli32.dll -> [2005/07/25 22:39:48 | 00,074,752 | —- | M] (Microsoft Corporation)
"olecnv32" -> C:\WINDOWS\system32\olecnv32.dll -> [2005/07/25 22:39:50 | 00,037,888 | —- | M] (Microsoft Corporation)
"olesvr32" -> C:\WINDOWS\system32\olesvr32.dll -> [2004/08/04 05:00:00 | 00,022,016 | —- | M] (Microsoft Corporation)
"olethk32" -> C:\WINDOWS\system32\olethk32.dll -> [2004/08/04 05:00:00 | 00,069,120 | —- | M] (Microsoft Corporation)
"rpcrt4" -> C:\WINDOWS\system32\rpcrt4.dll -> [2007/07/09 08:16:16 | 00,582,656 | —- | M] (Microsoft Corporation)
"shell32" -> C:\WINDOWS\system32\shell32.dll -> [2007/10/25 21:34:02 | 08,460,288 | —- | M] (Microsoft Corporation)
"url" -> C:\WINDOWS\system32\url.dll -> [2008/08/26 02:24:30 | 00,105,984 | —- | M] (Microsoft Corporation)
"urlmon" -> C:\WINDOWS\system32\urlmon.dll -> [2008/08/26 02:24:32 | 01,159,680 | —- | M] (Microsoft Corporation)
"user32" -> C:\WINDOWS\system32\user32.dll -> [2007/03/08 10:36:28 | 00,577,536 | —- | M] (Microsoft Corporation)
"version" -> C:\WINDOWS\system32\version.dll -> [2004/08/04 05:00:00 | 00,018,944 | —- | M] (Microsoft Corporation)
"wininet" -> C:\WINDOWS\system32\wininet.dll -> [2008/08/26 02:24:32 | 00,826,368 | —- | M] (Microsoft Corporation)
"wldap32" -> C:\WINDOWS\system32\wldap32.dll -> [2004/08/04 05:00:00 | 00,172,032 | —- | M] (Microsoft Corporation)
< Session Manager SFC Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SFC -> 
"CommonFilesDir" -> C:\Program Files\Common Files -> [2006/08/23 02:29:22 | 00,000,000 | —D | M]
"ProgramFilesDir" -> C:\Program Files -> [2006/08/23 02:39:18 | 00,000,000 | R–D | M]
< Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ -> 
NameSpace_Catalog5\Catalog_Entries\000000000004 [Bluetooth Namespace] -> %SystemRoot%\system32\wshbth.dll -> [2004/08/04 05:00:00 | 00,108,032 | —- | M] (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] -> %ProgramFiles%\Bonjour\mdnsNSP.dll -> [2008/08/29 09:53:50 | 00,147,456 | —- | M] (Apple Inc.)
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 11/29/2008 11:33:52 PM Computer Name = MOM | Source = Microsoft Office 12 | ID = 2001 -> Description = Rejected Safe Mode action : Microsoft Office Outlook.
Application [ Error ] 11/30/2008 1:50:43 AM Computer Name = MOM | Source = Application Error | ID = 1000 -> Description = Faulting application , version 0.0.0.0, faulting module unknown, version 0.0.0.0, fault address 0x00000000.
Application [ Error ] 11/30/2008 9:41:23 PM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application OTScanIt2.exe, version 1.0.2.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 11/30/2008 9:41:31 PM Computer Name = MOM | Source = Application Hang | ID = 1001 -> Description = Fault bucket 1035555179.
Application [ Error ] 11/30/2008 9:52:06 PM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application OTScanIt2.exe, version 1.0.2.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 11/30/2008 10:04:16 PM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application OTScanIt2.exe, version 1.0.2.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 11/30/2008 10:14:21 PM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application OTScanIt2.exe, version 1.0.2.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 11/30/2008 10:26:41 PM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application OTScanIt2.exe, version 1.0.2.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 11/30/2008 10:32:43 PM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application OTScanIt2.exe, version 1.0.2.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 12/1/2008 10:11:24 AM Computer Name = MOM | Source = Application Hang | ID = 1002 -> Description = Hanging application iexplore.exe, version 7.0.6000.16735, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
OSession [ Error ] 1/4/2008 11:40:33 AM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6023.5000, Microsoft Office Version: 12.0.4518.1014. This session lasted 1093 seconds with 120 seconds of active time.  This session ended with a crash.
OSession [ Error ] 7/25/2008 6:52:13 PM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 8719 seconds with 180 seconds of active time.  This session ended with a crash.
OSession [ Error ] 10/5/2008 8:35:16 PM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 28199 seconds with 0 seconds of active time.  This session ended with a crash.
OSession [ Error ] 10/13/2008 7:04:04 PM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 88 seconds with 0 seconds of active time.  This session ended with a crash.
OSession [ Error ] 10/24/2008 4:12:55 PM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 27501 seconds with 240 seconds of active time.  This session ended with a crash.
OSession [ Error ] 11/5/2008 8:40:51 PM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 46 seconds with 0 seconds of active time.  This session ended with a crash.
OSession [ Error ] 11/9/2008 12:57:31 PM Computer Name = MOM | Source = Microsoft Office 12 Sessions | ID = 7001 -> Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 111 seconds with 0 seconds of active time.  This session ended with a crash.
System [ Error ] 11/30/2008 12:05:15 AM Computer Name = MOM | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1058" attempting to start the service wuauserv with arguments ""  in order to run the server:  {E60687F7-01A1-40AA-86AC-DB1CBF673334}
System [ Error ] 11/30/2008 12:09:26 AM Computer Name = MOM | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1058" attempting to start the service wuauserv with arguments ""  in order to run the server:  {E60687F7-01A1-40AA-86AC-DB1CBF673334}
System [ Error ] 11/30/2008 12:19:18 AM Computer Name = MOM | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1058" attempting to start the service wuauserv with arguments ""  in order to run the server:  {E60687F7-01A1-40AA-86AC-DB1CBF673334}
System [ Error ] 11/30/2008 12:20:34 AM Computer Name = MOM | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1058" attempting to start the service wuauserv with arguments ""  in order to run the server:  {E60687F7-01A1-40AA-86AC-DB1CBF673334}
System [ Error ] 11/30/2008 1:36:52 PM Computer Name = MOM | Source = DCOM | ID = 10010 -> Description = The server {6A972E27-93E2-4F98-8367-4101B2073814} did not register with DCOM within the required timeout.
System [ Error ] 11/30/2008 2:04:48 PM Computer Name = MOM | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1058" attempting to start the service wuauserv with arguments ""  in order to run the server:  {E60687F7-01A1-40AA-86AC-DB1CBF673334}
System [ Error ] 11/30/2008 10:45:45 PM Computer Name = MOM | Source = Service Control Manager | ID = 7011 -> Description = Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
System [ Error ] 12/1/2008 11:15:40 AM Computer Name = MOM | Source = DCOM | ID = 10010 -> Description = The server {6A972E27-93E2-4F98-8367-4101B2073814} did not register with DCOM within the required timeout.
System [ Error ] 12/1/2008 11:40:49 AM Computer Name = MOM | Source = Srv | ID = 2000 -> Description = The server's call to a system service failed unexpectedly.
System [ Error ] 12/1/2008 11:40:49 AM Computer Name = MOM | Source = Srv | ID = 2000 -> Description = The server's call to a system service failed unexpectedly.
 
[Files/Folders - Created Within 90 Days]
3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
36 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> 
examuy.dll -> %SystemRoot%\System32\examuy.dll -> [2008/11/30 22:30:19 | 00,129,024 | —- | C] ()
bsghddwu.dll -> %SystemRoot%\System32\bsghddwu.dll -> [2008/11/30 22:30:19 | 00,129,024 | —- | C] ()
ujnjymct.dll -> %SystemRoot%\System32\ujnjymct.dll -> [2008/11/30 22:30:02 | 00,129,024 | —- | C] ()
wthvwwmy.dll -> %SystemRoot%\System32\wthvwwmy.dll -> [2008/11/30 22:30:00 | 00,075,776 | —- | C] ()
veglaf.dll -> %SystemRoot%\System32\veglaf.dll -> [2008/11/30 22:30:00 | 00,075,776 | —- | C] ()
dicoejye.ini -> %SystemRoot%\System32\dicoejye.ini -> [2008/11/30 22:29:34 | 01,691,436 | -HS- | C] ()
eyjeocid.dll -> %SystemRoot%\System32\eyjeocid.dll -> [2008/11/30 22:29:34 | 00,072,704 | —- | C] ()
OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2008/11/30 19:02:16 | 00,000,000 | —D | C]
OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/11/30 19:00:18 | 00,536,920 | —- | C] ()
yvzcxo.dll -> %SystemRoot%\System32\yvzcxo.dll -> [2008/11/30 16:46:38 | 00,075,776 | —- | C] ()
ofmnnjam.dll -> %SystemRoot%\System32\ofmnnjam.dll -> [2008/11/30 16:46:38 | 00,075,776 | —- | C] ()
lecbjl.dll -> %SystemRoot%\System32\lecbjl.dll -> [2008/11/30 16:46:37 | 00,129,024 | —- | C] ()
lbwtoaac.dll -> %SystemRoot%\System32\lbwtoaac.dll -> [2008/11/30 16:46:36 | 00,129,024 | —- | C] ()
LopSD.exe -> %UserProfile%\Desktop\LopSD.exe -> [2008/11/30 15:44:00 | 00,529,069 | —- | C] ()
Lop SD -> %SystemDrive%\Lop SD -> [2008/11/30 10:21:31 | 00,000,000 | —D | C]
ERDNT -> %SystemRoot%\ERDNT -> [2008/11/29 19:44:00 | 00,000,000 | —D | C]
NTREGOPT.lnk -> %UserProfile%\Desktop\NTREGOPT.lnk -> [2008/11/29 19:43:29 | 00,000,519 | —- | C] ()
ERUNT.lnk -> %UserProfile%\Desktop\ERUNT.lnk -> [2008/11/29 19:43:29 | 00,000,500 | —- | C] ()
ERUNT -> %ProgramFiles%\ERUNT -> [2008/11/29 19:43:28 | 00,000,000 | —D | C]
erunt_setup.exe -> %UserProfile%\Desktop\erunt_setup.exe -> [2008/11/29 19:42:30 | 00,791,393 | —- | C] (Lars Hederer												)
Trend Micro -> %ProgramFiles%\Trend Micro -> [2008/11/29 19:32:31 | 00,000,000 | —D | C]
HJTInstall.exe -> %UserProfile%\Desktop\HJTInstall.exe -> [2008/11/29 19:32:13 | 00,812,344 | —- | C] (Trend Micro Inc.)
Hijackthis -> %ProgramFiles%\Hijackthis -> [2008/11/29 19:18:05 | 00,000,000 | —D | C]
nphnrvrs.ini -> %SystemRoot%\System32\nphnrvrs.ini -> [2008/11/29 16:48:13 | 01,691,436 | -HS- | C] ()
uvegyt.dll -> %SystemRoot%\System32\uvegyt.dll -> [2008/11/29 16:45:16 | 00,129,024 | —- | C] ()
snghoxvm.dll -> %SystemRoot%\System32\snghoxvm.dll -> [2008/11/29 16:45:15 | 00,129,024 | —- | C] ()
rmirseiq.ini -> %SystemRoot%\System32\rmirseiq.ini -> [2008/11/29 16:44:57 | 01,691,436 | -HS- | C] ()
jxmjgz.dll -> %SystemRoot%\System32\jxmjgz.dll -> [2008/11/29 16:44:33 | 00,075,776 | —- | C] ()
sxnbkwiy.dll -> %SystemRoot%\System32\sxnbkwiy.dll -> [2008/11/29 16:44:30 | 00,075,776 | —- | C] ()
~.exe -> %SystemRoot%\System32\~.exe -> [2008/11/28 21:17:08 | 00,061,952 | —- | C] ()
qomdne.dll -> %SystemRoot%\System32\qomdne.dll -> [2008/11/28 16:04:01 | 00,075,776 | —- | C] ()
hpuvxyhp.dll -> %SystemRoot%\System32\hpuvxyhp.dll -> [2008/11/28 16:04:00 | 00,075,776 | —- | C] ()
mfftix.dll -> %SystemRoot%\System32\mfftix.dll -> [2008/11/28 16:01:03 | 00,129,024 | —- | C] ()
aujmlggl.dll -> %SystemRoot%\System32\aujmlggl.dll -> [2008/11/28 16:01:01 | 00,129,024 | —- | C] ()
uwnnvtfw.ini -> %SystemRoot%\System32\uwnnvtfw.ini -> [2008/11/28 15:59:51 | 01,691,436 | -HS- | C] ()
McAfee -> %AppData%\McAfee -> [2008/11/28 11:28:01 | 00,000,000 | —D | C]
llwdna.dll -> %SystemRoot%\System32\llwdna.dll -> [2008/11/27 14:26:26 | 00,129,024 | —- | C] ()
sisbqrnt.dll -> %SystemRoot%\System32\sisbqrnt.dll -> [2008/11/27 14:26:25 | 00,129,024 | —- | C] ()
durgjtqm.ini -> %SystemRoot%\System32\durgjtqm.ini -> [2008/11/27 14:25:18 | 01,691,436 | -HS- | C] ()
uqveuyne.dll -> %SystemRoot%\System32\uqveuyne.dll -> [2008/11/27 14:21:24 | 00,075,776 | —- | C] ()
azpfhp.dll -> %SystemRoot%\System32\azpfhp.dll -> [2008/11/27 14:21:24 | 00,075,776 | —- | C] ()
zjstnc.dll -> %SystemRoot%\System32\zjstnc.dll -> [2008/11/27 14:11:10 | 00,075,776 | —- | C] ()
eskmtlpl.dll -> %SystemRoot%\System32\eskmtlpl.dll -> [2008/11/27 14:11:09 | 00,075,776 | —- | C] ()
appmgmt -> %SystemRoot%\System32\appmgmt -> [2008/11/27 01:03:27 | 00,000,000 | —D | C]
pss -> %SystemRoot%\pss -> [2008/11/26 23:03:40 | 00,000,000 | —D | C]
Config.MPF -> %SystemRoot%\System32\Config.MPF -> [2008/11/26 15:59:20 | 00,004,069 | —- | C] ()
McAfee Security Center.lnk -> %AllUsersProfile%\Desktop\McAfee Security Center.lnk -> [2008/11/26 15:43:49 | 00,000,579 | —- | C] ()
dunzip32.dll -> %SystemRoot%\System32\dunzip32.dll -> [2008/11/26 15:43:10 | 00,143,360 | —- | C] (Inner Media, Inc.)
mferkdk.sys -> %SystemRoot%\System32\drivers\mferkdk.sys -> [2008/11/26 15:39:27 | 00,033,832 | —- | C] (McAfee, Inc.)
mfehidk.sys -> %SystemRoot%\System32\drivers\mfehidk.sys -> [2008/11/26 15:39:22 | 00,201,320 | —- | C] (McAfee, Inc.)
mfeavfk.sys -> %SystemRoot%\System32\drivers\mfeavfk.sys -> [2008/11/26 15:39:22 | 00,079,304 | —- | C] (McAfee, Inc.)
mfesmfk.sys -> %SystemRoot%\System32\drivers\mfesmfk.sys -> [2008/11/26 15:39:22 | 00,040,488 | —- | C] (McAfee, Inc.)
mfebopk.sys -> %SystemRoot%\System32\drivers\mfebopk.sys -> [2008/11/26 15:39:22 | 00,035,240 | —- | C] (McAfee, Inc.)
Mpfp.sys -> %SystemRoot%\System32\drivers\Mpfp.sys -> [2008/11/26 15:39:01 | 00,113,952 | —- | C] (McAfee, Inc.)
McDefragTask.job -> %SystemRoot%\tasks\McDefragTask.job -> [2008/11/26 15:38:24 | 00,000,344 | —- | C] ()
McQcTask.job -> %SystemRoot%\tasks\McQcTask.job -> [2008/11/26 15:38:23 | 00,000,336 | —- | C] ()
McAfee.com -> %ProgramFiles%\McAfee.com -> [2008/11/26 15:37:50 | 00,000,000 | —D | C]
McAfee -> %CommonProgramFiles%\McAfee -> [2008/11/26 15:37:36 | 00,000,000 | —D | C]
McAfee -> %ProgramFiles%\McAfee -> [2008/11/26 15:37:19 | 00,000,000 | —D | C]
McAfee -> %AllUsersProfile%\Application Data\McAfee -> [2008/11/26 15:16:45 | 00,000,000 | —D | C]
DMSetup-Serial.exe -> %UserProfile%\Desktop\DMSetup-Serial.exe -> [2008/11/26 15:16:18 | 01,226,248 | —- | C] (McAfee, Inc.)
txrjmu.dll -> %SystemRoot%\System32\txrjmu.dll -> [2008/11/26 11:36:50 | 00,075,776 | —- | C] ()
thqwcnrr.dll -> %SystemRoot%\System32\thqwcnrr.dll -> [2008/11/26 11:36:50 | 00,075,776 | —- | C] ()
atrfes.dll -> %SystemRoot%\System32\atrfes.dll -> [2008/11/26 11:36:25 | 00,075,776 | —- | C] ()
qmlsajge.dll -> %SystemRoot%\System32\qmlsajge.dll -> [2008/11/26 11:36:21 | 00,075,776 | —- | C] ()
ezwjpw.dll -> %SystemRoot%\System32\ezwjpw.dll -> [2008/11/26 11:15:41 | 00,129,024 | —- | C] ()
vvufqhjy.dll -> %SystemRoot%\System32\vvufqhjy.dll -> [2008/11/26 11:15:39 | 00,129,024 | —- | C] ()
rYFffMoq.ini2 -> %SystemRoot%\System32\rYFffMoq.ini2 -> [2008/11/26 11:12:38 | 00,901,656 | -HS- | C] ()
rYFffMoq.ini -> %SystemRoot%\System32\rYFffMoq.ini -> [2008/11/26 11:12:38 | 00,901,656 | -HS- | C] ()
qoMffFYr.dll -> %SystemRoot%\System32\qoMffFYr.dll -> [2008/11/26 11:12:29 | 00,318,464 | —- | C] ()
MSINET.OCX -> %SystemRoot%\System32\MSINET.OCX -> [2008/11/25 23:29:39 | 00,115,016 | —- | C] (Microsoft Corporation)
MSINET.oca -> %SystemRoot%\System32\MSINET.oca -> [2008/11/25 23:29:39 | 00,029,184 | —- | C] ()
MSINET.DEP -> %SystemRoot%\System32\MSINET.DEP -> [2008/11/25 23:29:39 | 00,002,407 | —- | C] ()
2008-09-Faith Formation calendar.pdf -> %UserProfile%\Desktop\2008-09-Faith Formation calendar.pdf -> [2008/11/23 19:27:01 | 00,277,116 | —- | C] ()
~$ristmas lists.docx -> %UserProfile%\My Documents\~$ristmas lists.docx -> [2008/11/23 13:43:44 | 00,000,162 | -H– | C] ()
Christmas lists.docx -> %UserProfile%\My Documents\Christmas lists.docx -> [2008/11/23 13:43:43 | 00,013,677 | —- | C] ()
OneNote Notebooks -> %UserProfile%\My Documents\OneNote Notebooks -> [2008/11/23 13:06:03 | 00,000,000 | —D | C]
OneNote 2007 Screen Clipper and Launcher.lnk -> %UserProfile%\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk -> [2008/11/23 13:06:02 | 00,000,855 | —- | C] ()
FOUND.020 -> %SystemDrive%\FOUND.020 -> [2008/11/17 20:40:24 | 00,000,000 | -HSD | C]
osaio.sys -> %SystemRoot%\System32\drivers\osaio.sys -> [2008/11/13 18:08:59 | 00,007,296 | —- | C] (OSA Technologies, An Avocent Company)
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2008/11/13 18:08:57 | 00,000,006 | -H– | C] ()
FOUND.019 -> %SystemDrive%\FOUND.019 -> [2008/11/13 18:07:32 | 00,000,000 | -HSD | C]
110908_bento_closeup.JPG -> %UserProfile%\Desktop\110908_bento_closeup.JPG -> [2008/11/09 22:31:45 | 00,306,112 | —- | C] ()
110908_bento.JPG -> %UserProfile%\Desktop\110908_bento.JPG -> [2008/11/09 22:31:05 | 00,938,713 | —- | C] ()
Reading Log.docx -> %UserProfile%\My Documents\Reading Log.docx -> [2008/11/09 18:50:23 | 00,011,382 | —- | C] ()
~$ading Log.docx -> %UserProfile%\My Documents\~$ading Log.docx -> [2008/11/09 18:50:23 | 00,000,162 | -H– | C] ()
my-neighbor-totoro-tonari-no-totoro-piano-duet[1].pdf -> %UserProfile%\My Documents\my-neighbor-totoro-tonari-no-totoro-piano-duet[1].pdf -> [2008/11/08 22:36:04 | 00,377,436 | —- | C] ()
gen's page -> %UserProfile%\Desktop\gen's page -> [2008/11/02 19:02:13 | 00,000,000 | —D | C]
CURRENT EVENTS worksheet.doc -> %UserProfile%\My Documents\CURRENT EVENTS worksheet.doc -> [2008/10/29 21:29:54 | 00,025,088 | —- | C] ()
2009 calendar.docx -> %UserProfile%\Desktop\2009 calendar.docx -> [2008/10/22 19:20:10 | 00,035,851 | —- | C] ()
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2008/10/19 23:32:56 | 04,843,052 | -H– | C] ()
bthservsdp.dat -> %SystemRoot%\bthservsdp.dat -> [2008/10/18 23:17:05 | 00,000,012 | —- | C] ()
FOUND.018 -> %SystemDrive%\FOUND.018 -> [2008/10/18 22:07:44 | 00,000,000 | -HSD | C]
iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2008/10/17 14:50:46 | 00,002,137 | —- | C] ()
iPod -> %ProgramFiles%\iPod -> [2008/10/17 14:50:28 | 00,000,000 | —D | C]
iTunes -> %ProgramFiles%\iTunes -> [2008/10/17 14:50:27 | 00,000,000 | —D | C]
{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> %AllUsersProfile%\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> [2008/10/17 14:50:27 | 00,000,000 | —D | C]
christmas2.JPG -> %UserProfile%\My Documents\christmas2.JPG -> [2008/10/12 21:52:00 | 00,779,018 | —- | C] ()
christmas2.JPG -> %UserProfile%\Desktop\christmas2.JPG -> [2008/10/12 21:52:00 | 00,779,018 | —- | C] ()
Amelia.jpg -> %UserProfile%\Desktop\Amelia.jpg -> [2008/10/12 21:52:00 | 00,098,782 | —- | C] ()
FOUND.017 -> %SystemDrive%\FOUND.017 -> [2008/10/12 19:00:26 | 00,000,000 | -HSD | C]
Metformin_IV_Contrast_Sept_2008_lisa[1].doc -> %UserProfile%\Desktop\Metformin_IV_Contrast_Sept_2008_lisa[1].doc -> [2008/10/08 19:14:17 | 00,058,880 | —- | C] ()
FOUND.016 -> %SystemDrive%\FOUND.016 -> [2008/10/08 18:20:56 | 00,000,000 | -HSD | C]
cruises.doc -> %UserProfile%\Desktop\cruises.doc -> [2008/10/04 19:25:03 | 00,019,968 | —- | C] ()
Smarter_than_a_5th_grader%281%29(1).xls -> %UserProfile%\Desktop\Smarter_than_a_5th_grader%281%29(1).xls -> [2008/10/03 13:47:16 | 00,152,576 | —- | C] ()
Oct-Dec2008.docx -> %UserProfile%\Desktop\Oct-Dec2008.docx -> [2008/10/02 20:58:46 | 00,017,099 | —- | C] ()
msxml4.dll -> %SystemRoot%\System32\msxml4.dll -> [2008/09/30 16:43:34 | 01,286,152 | —- | C] (Microsoft Corporation)
Cruise -> %UserProfile%\Desktop\Cruise -> [2008/09/25 23:43:33 | 00,000,000 | —D | C]
clip_image001.jpg -> %UserProfile%\My Documents\clip_image001.jpg -> [2008/09/24 19:43:06 | 00,200,640 | —- | C] ()
marscam.ini -> %SystemRoot%\marscam.ini -> [2008/09/20 15:20:41 | 00,000,037 | —- | C] ()
Bug chart.docx -> %AllUsersProfile%\Documents\Bug chart.docx -> [2008/09/20 13:45:18 | 00,011,106 | —- | C] ()
~$g chart.docx -> %AllUsersProfile%\Documents\~$g chart.docx -> [2008/09/20 13:45:18 | 00,000,162 | -H– | C] ()
Sept 12 LArts.pdf -> %AllUsersProfile%\Documents\Sept 12 LArts.pdf -> [2008/09/13 16:42:57 | 00,124,655 | —- | C] ()
Life Science Assignments.doc -> %AllUsersProfile%\Documents\Life Science Assignments.doc -> [2008/09/13 16:39:21 | 00,062,464 | —- | C] ()
Bonjour -> %ProgramFiles%\Bonjour -> [2008/09/09 19:39:23 | 00,000,000 | —D | C]
QuickTime -> %ProgramFiles%\QuickTime -> [2008/09/09 19:37:12 | 00,000,000 | —D | C]
FOUND.015 -> %SystemDrive%\FOUND.015 -> [2008/09/02 22:35:28 | 00,000,000 | -HSD | C]
Sun -> %ProgramFiles%\Sun -> [2008/09/02 20:10:42 | 00,000,000 | —D | C]
 
[Files/Folders - Modified Within 90 Days]
3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
36 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> 
C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help -> [2006/08/23 02:40:56 | 00,000,000 | —D | M]
hhcolreg.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\hhcolreg.dat -> [2008/11/26 19:06:50 | 00,001,306 | —- | M] ()
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader -> [2006/12/26 18:14:40 | 00,000,000 | —D | M]
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2008/11/11 23:27:04 | 00,055,955 | —- | M] ()
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2008/11/11 23:27:04 | 00,055,570 | —- | M] ()
C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA -> [2007/06/02 19:26:56 | 00,000,000 | —D | M]
opa12.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa12.dat -> [2007/06/02 19:33:34 | 00,008,416 | —- | M] ()
C:\Documents and Settings\Maryann\Local Settings\Temp\ -> C:\Documents and Settings\Maryann\Local Settings\Temp -> [2006/08/23 02:29:04 | 00,000,000 | —D | M]
RtkBtMnt.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\RtkBtMnt.exe -> [2007/05/02 23:43:32 | 00,208,896 | —- | M] (Realtek Semiconductor Corp.)
gds1033.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\gds1033.exe -> [2007/03/14 04:16:08 | 00,746,600 | —- | M] ()
ycomp_setup.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\ycomp_setup.exe -> [2006/09/12 15:57:58 | 00,866,840 | —- | M] ()
ose00000.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\ose00000.exe -> [2006/10/30 05:35:16 | 00,145,184 | R— | M] (Microsoft Corporation)
jre-6u2-windows-i586-p-iftw_7070c3f7.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\jre-6u2-windows-i586-p-iftw_7070c3f7.exe -> [2007/07/12 15:45:16 | 00,382,352 | —- | M] (Sun Microsystems, Inc.)
ytb_7.0.8.0_1.4.1_ysp_1.2_pub_us_setup_.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\ytb_7.0.8.0_1.4.1_ysp_1.2_pub_us_setup_.exe -> [2007/11/07 18:45:00 | 01,788,000 | —- | M] (Yahoo! Inc.)
wic.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\wic.exe -> [2008/06/11 18:27:58 | 01,227,048 | —- | M] (Microsoft Corporation)
dotnet.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\dotnet.exe -> [2008/06/11 18:28:52 | 24,758,792 | —- | M] (Microsoft Corporation)
SymLCSVC.EXE -> C:\Documents and Settings\Maryann\Local Settings\Temp\SymLCSVC.EXE -> [2008/11/26 15:30:44 | 01,119,888 | —- | M] (Symantec Corporation)
1549 C:\Documents and Settings\Maryann\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Maryann\Local Settings\Temp\*.tmp -> 
C:\Documents and Settings\Maryann\Local Settings\Temp\_ir_sf7_temp_0\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\_ir_sf7_temp_0 -> [2007/09/15 10:37:32 | 00,000,000 | —D | M]
irsetup.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\_ir_sf7_temp_0\irsetup.exe -> [2007/09/15 10:37:32 | 00,473,600 | —- | M] ()
C:\Documents and Settings\Maryann\Local Settings\Temp\Adobe Reader 8\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Adobe Reader 8 -> [2007/06/21 22:54:00 | 00,000,000 | —D | M]
Setup.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Adobe Reader 8\Setup.exe -> [2007/05/11 03:50:42 | 00,304,784 | —- | M] (Adobe Systems Incorporated)
C:\Documents and Settings\Maryann\Local Settings\Temp\Adobe Reader 8_\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Adobe Reader 8_ -> [2007/11/04 01:15:04 | 00,000,000 | —D | M]
Setup.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Adobe Reader 8_\Setup.exe -> [2007/05/11 03:50:42 | 00,304,784 | —- | M] (Adobe Systems Incorporated)
C:\Documents and Settings\Maryann\Local Settings\Temp\ICD1.tmp\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\ICD1.tmp\ -> [2007/03/05 20:45:18 | 00,000,000 | —D | M]
jinstall.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\ICD1.tmp\jinstall.exe -> [2007/01/30 16:28:04 | 00,245,873 | —- | M] (Sun Microsystems, Inc.)
C:\Documents and Settings\Maryann\Local Settings\Temp\ICD2.tmp\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\ICD2.tmp\ -> [2008/09/02 20:08:16 | 00,000,000 | —D | M]
jinstall.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\ICD2.tmp\jinstall.exe -> [2008/06/10 04:55:10 | 00,376,832 | —- | M] (Sun Microsystems, Inc.)
C:\Documents and Settings\Maryann\Local Settings\Temp\pft4~tmp\Disk1\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\pft4~tmp\Disk1 -> [2008/01/20 09:44:26 | 00,000,000 | —D | M]
Setup.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\pft4~tmp\Disk1\Setup.exe -> [2000/10/05 16:00:06 | 00,054,272 | —- | M] (InstallShield Software Corporation)
C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164 -> [2007/04/04 22:59:32 | 00,000,000 | —D | M]
ChCfg.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\ChCfg.exe -> [2006/08/01 15:02:32 | 00,049,152 | —- | M] ()
SetCDfmt.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\SetCDfmt.exe -> [2001/12/03 01:27:00 | 00,023,552 | —- | M] ()
Setup.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\Setup.exe -> [2005/11/14 16:24:00 | 00,121,064 | —- | M] (Macrovision Corporation)
C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K_XP\us\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K_XP\us -> [2007/04/04 22:59:32 | 00,000,000 | —D | M]
kb888111w2ksp4.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K_XP\us\kb888111w2ksp4.exe -> [2005/01/07 18:18:00 | 00,742,104 | R— | M] (Microsoft Corporation)
kb888111xpsp1.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K_XP\us\kb888111xpsp1.exe -> [2005/01/07 18:15:00 | 00,774,360 | R— | M] (Microsoft Corporation)
kb888111xpsp2.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K_XP\us\kb888111xpsp2.exe -> [2005/01/10 11:15:00 | 00,720,088 | R— | M] (Microsoft Corporation)
C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K3\us\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K3\us -> [2007/04/04 22:59:32 | 00,000,000 | —D | M]
kb888111srvrtm.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\MSHDQFE\Win2K3\us\kb888111srvrtm.exe -> [2005/01/07 18:23:00 | 00,771,288 | R— | M] (Microsoft Corporation)
C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM -> [2007/04/04 22:59:32 | 00,000,000 | —D | M]
Alcmtr.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\Alcmtr.exe -> [2005/05/03 18:43:28 | 00,069,632 | —- | M] (Realtek Semiconductor Corp.)
AlcWzrd.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\AlcWzrd.exe -> [2006/05/04 16:26:36 | 02,808,832 | —- | M] (RealTek Semicoductor Corp.)
CPLUtl64.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\CPLUtl64.exe -> [2006/03/30 18:58:22 | 00,037,376 | —- | M] ()
MicCal.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\MicCal.exe -> [2006/10/11 17:42:58 | 02,157,568 | —- | M] (Realtek Semiconductor Corp.)
RTHDCPL.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\RTHDCPL.exe -> [2007/03/21 14:49:20 | 16,126,464 | —- | M] (Realtek Semiconductor Corp.)
RTLCPL.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\RTLCPL.exe -> [2007/03/23 19:19:10 | 09,715,200 | —- | M] (Realtek Semiconductor Corp.)
RtlUpd.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\RtlUpd.exe -> [2007/01/16 10:39:36 | 01,191,936 | —- | M] (Realtek Semiconductor Corp.)
RtlUpd64.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\RtlUpd64.exe -> [2007/01/16 10:39:24 | 01,356,800 | —- | M] (Realtek Semiconductor Corp.)
SkyTel.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\SkyTel.exe -> [2007/03/16 15:06:54 | 01,822,720 | —- | M] (Realtek Semiconductor Corp.)
SoundMan.exe -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\SoundMan.exe -> [2006/07/21 16:14:36 | 00,086,016 | —- | M] (Realtek Semiconductor Corp.)
C:\Documents and Settings\Maryann\Local Settings\Temp\_PASFX531\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\_PASFX531 -> [2008/03/11 22:43:56 | 00,000,000 | —D | M]
7Z.DLL -> C:\Documents and Settings\Maryann\Local Settings\Temp\_PASFX531\7Z.DLL -> [2008/03/11 22:43:58 | 00,076,288 | —- | M] ()
C:\Documents and Settings\Maryann\Local Settings\Temp\PRE2AD.tmp\x64\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\PRE2AD.tmp\x64 -> [2008/11/26 15:36:44 | 00,000,000 | —D | M]
McShield.DLL -> C:\Documents and Settings\Maryann\Local Settings\Temp\PRE2AD.tmp\x64\McShield.DLL -> [2007/07/24 12:01:38 | 00,024,384 | —- | M] (McAfee, Inc.)
C:\Documents and Settings\Maryann\Local Settings\Temp\TempFolder.aaa\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\TempFolder.aaa\ -> [2008/01/20 09:43:44 | 00,000,000 | —D | M]
proj.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\TempFolder.aaa\proj.dll -> [2008/01/20 09:43:44 | 00,151,552 | —- | M] (Macromedia, Inc.)
dirapi.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\TempFolder.aaa\dirapi.dll -> [2008/01/20 09:43:46 | 01,097,728 | —- | M] (Macromedia, Inc.)
iml32.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\TempFolder.aaa\iml32.dll -> [2008/01/20 09:43:46 | 00,561,152 | —- | M] (Macromedia, Inc.)
msvcrt.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\TempFolder.aaa\msvcrt.dll -> [2008/01/20 09:43:46 | 00,266,293 | —- | M] (Microsoft Corporation)
C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164 -> [2007/04/04 22:59:32 | 00,000,000 | —D | M]
RtlExUpd.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\RtlExUpd.dll -> [2007/01/12 16:54:44 | 00,520,192 | —- | M] (Realtek Semiconductor Corp.)
C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\ -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM -> [2007/04/04 22:59:32 | 00,000,000 | —D | M]
RTCOMDLL.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\RTCOMDLL.dll -> [2007/03/15 14:39:04 | 00,262,144 | —- | M] ()
RtlCPAPI.dll -> C:\Documents and Settings\Maryann\Local Settings\Temp\Temporary Directory 1 for WDM_R164.zip\WDM_R164\WDM\RtlCPAPI.dll -> [2007/03/07 14:59:30 | 00,131,072 | —- | M] ()
C:\Documents and Settings\Maryann\Local Settings\Temp\ -> C:\Documents and Settings\Maryann\Local Settings\Temp -> [2006/08/23 02:29:04 | 00,000,000 | —D | M]
symcprop.dat -> C:\Documents and Settings\Maryann\Local Settings\Temp\symcprop.dat -> [2008/11/26 15:30:16 | 00,008,708 | —- | M] ()
SSALiveUpdate.dat -> C:\Documents and Settings\Maryann\Local Settings\Temp\SSALiveUpdate.dat -> [2008/11/26 15:27:14 | 00,000,124 | —- | M] ()
AVRES_OPTRF_LiveUpdate.dat -> C:\Documents and Settings\Maryann\Local Settings\Temp\AVRES_OPTRF_LiveUpdate.dat -> [2008/11/26 15:26:28 | 00,000,124 | —- | M] ()
AVSTELiveUpdate.dat -> C:\Documents and Settings\Maryann\Local Settings\Temp\AVSTELiveUpdate.dat -> [2008/11/26 15:30:16 | 00,000,124 | —- | M] ()
1549 C:\Documents and Settings\Maryann\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Maryann\Local Settings\Temp\*.tmp -> 
C:\WINDOWS\Temp\ -> C:\WINDOWS\Temp -> [2006/08/23 04:03:42 | 00,000,000 | —D | M]
GVista.exe -> C:\WINDOWS\Temp\GVista.exe -> [2006/03/09 01:24:30 | 00,628,030 | —- | M] ()
setup.exe -> C:\WINDOWS\Temp\setup.exe -> [2004/12/09 17:58:00 | 00,438,272 | —- | M] (Dritek System Inc.)
Uninstall_eRecovery.exe -> C:\WINDOWS\Temp\Uninstall_eRecovery.exe -> [2005/09/26 16:40:32 | 00,258,048 | —- | M] (Acer Inc.)
3 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> 
C:\WINDOWS\Temp\EMEAWG\ -> C:\WINDOWS\Temp\EMEAWG -> [2006/12/26 02:51:16 | 00,000,000 | —D | M]
Setup.exe -> C:\WINDOWS\Temp\EMEAWG\Setup.exe -> [2006/09/23 12:19:10 | 00,165,888 | —- | M] (Microsoft Corporation)
CC_Install.exe -> C:\WINDOWS\Temp\EMEAWG\CC_Install.exe -> [2006/09/23 12:05:32 | 00,049,152 | —- | M] (Acer Inc.)
C:\WINDOWS\Temp\ -> C:\WINDOWS\Temp -> [2006/08/23 04:03:42 | 00,000,000 | —D | M]
CloseProcessWindow.dll -> C:\WINDOWS\Temp\CloseProcessWindow.dll -> [2004/11/03 09:06:50 | 00,159,744 | —- | M] (acer inc.)
HkWndMsgU.dll -> C:\WINDOWS\Temp\HkWndMsgU.dll -> [2006/01/09 14:53:30 | 00,192,512 | —- | M] (Dritek System Inc.)
HkWndMsgU64.dll -> C:\WINDOWS\Temp\HkWndMsgU64.dll -> [2006/01/09 14:54:24 | 00,218,624 | —- | M] (Dritek System Inc.)
MMDUtl.dll -> C:\WINDOWS\Temp\MMDUtl.dll -> [2006/02/08 18:38:40 | 00,208,896 | —- | M] (Dritek System Inc.)
SetupDev.dll -> C:\WINDOWS\Temp\SetupDev.dll -> [2004/11/01 11:58:42 | 00,057,344 | —- | M] (Dritek System Inc.)
3 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> 
C:\WINDOWS\Temp\EMEAWG\ -> C:\WINDOWS\Temp\EMEAWG -> [2006/12/26 02:51:16 | 00,000,000 | —D | M]
Microsoft.VisualBasic.Compatibility.dll -> C:\WINDOWS\Temp\EMEAWG\Microsoft.VisualBasic.Compatibility.dll -> [2003/03/19 01:53:26 | 00,237,568 | —- | M] (Microsoft Corporation)
C:\WINDOWS\Temp\ -> C:\WINDOWS\Temp -> [2006/08/23 04:03:42 | 00,000,000 | —D | M]
Perflib_Perfdata_54c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_54c.dat -> [2008/11/26 11:13:16 | 00,016,384 | —- | M] ()
Perflib_Perfdata_f24.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f24.dat -> [2008/11/27 11:13:50 | 00,016,384 | —- | M] ()
Perflib_Perfdata_16ac.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_16ac.dat -> [2008/11/28 11:22:16 | 00,016,384 | —- | M] ()
Perflib_Perfdata_cf4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cf4.dat -> [2008/11/28 15:58:48 | 00,016,384 | —- | M] ()
Perflib_Perfdata_d10.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d10.dat -> [2008/11/29 16:43:38 | 00,016,384 | —- | M] ()
Perflib_Perfdata_8d4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_8d4.dat -> [2008/11/30 10:22:06 | 00,016,384 | —- | M] ()
Perflib_Perfdata_e5c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e5c.dat -> [2008/11/30 22:28:36 | 00,016,384 | —- | M] ()
3 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> 
C:\WINDOWS\Temp\Cookies\ -> C:\WINDOWS\Temp\Cookies -> [2006/12/26 00:34:18 | 00,000,000 | -HSD | M]
index.dat -> C:\WINDOWS\Temp\Cookies\index.dat -> [2008/12/01 07:15:00 | 00,016,384 | —- | M] ()
C:\WINDOWS\Temp\History\History.IE5\ -> C:\WINDOWS\Temp\History\History.IE5\ -> [2006/12/26 00:34:18 | 00,000,000 | -HSD | M]
index.dat -> C:\WINDOWS\Temp\History\History.IE5\index.dat -> [2008/12/01 07:15:00 | 00,016,384 | —- | M] ()
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ -> [2006/12/26 00:34:18 | 00,000,000 | -HSD | M]
index.dat -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2008/12/01 07:15:00 | 00,032,768 | —- | M] ()
ponihiti -> %SystemRoot%\System32\ponihiti -> [2008/12/01 09:56:14 | 00,008,812 | -H– | M] ()
rYFffMoq.ini -> %SystemRoot%\System32\rYFffMoq.ini -> [2008/12/01 09:56:04 | 00,901,656 | -HS- | M] ()
rYFffMoq.ini2 -> %SystemRoot%\System32\rYFffMoq.ini2 -> [2008/12/01 09:54:46 | 00,901,656 | -HS- | M] ()
wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2008/12/01 09:37:38 | 00,001,158 | —- | M] ()
eRLog.ini -> %SystemRoot%\System32\eRLog.ini -> [2008/12/01 09:37:24 | 00,000,454 | —- | M] ()
nvapps.xml -> %SystemRoot%\System32\nvapps.xml -> [2008/12/01 09:36:32 | 00,051,048 | —- | M] ()
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2008/12/01 09:35:54 | 00,000,006 | -H– | M] ()
bootstat.dat -> %SystemRoot%\bootstat.dat -> [2008/12/01 09:35:46 | 00,002,048 | –S- | M] ()
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2008/12/01 09:35:38 | 21,455,05280 | -HS- | M] ()
Config.MPF -> %SystemRoot%\System32\Config.MPF -> [2008/12/01 09:15:42 | 00,004,069 | —- | M] ()
bthservsdp.dat -> %SystemRoot%\bthservsdp.dat -> [2008/12/01 09:15:42 | 00,000,012 | —- | M] ()
examuy.dll -> %SystemRoot%\System32\examuy.dll -> [2008/11/30 22:30:20 | 00,129,024 | —- | M] ()
bsghddwu.dll -> %SystemRoot%\System32\bsghddwu.dll -> [2008/11/30 22:30:20 | 00,129,024 | —- | M] ()
ujnjymct.dll -> %SystemRoot%\System32\ujnjymct.dll -> [2008/11/30 22:30:04 | 00,129,024 | —- | M] ()
wthvwwmy.dll -> %SystemRoot%\System32\wthvwwmy.dll -> [2008/11/30 22:30:02 | 00,075,776 | —- | M] ()
veglaf.dll -> %SystemRoot%\System32\veglaf.dll -> [2008/11/30 22:30:02 | 00,075,776 | —- | M] ()
dicoejye.ini -> %SystemRoot%\System32\dicoejye.ini -> [2008/11/30 22:29:46 | 01,691,436 | -HS- | M] ()
eyjeocid.dll -> %SystemRoot%\System32\eyjeocid.dll -> [2008/11/30 22:29:36 | 00,072,704 | —- | M] ()
OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/11/30 19:00:22 | 00,536,920 | —- | M] ()
nphnrvrs.ini -> %SystemRoot%\System32\nphnrvrs.ini -> [2008/11/30 16:48:54 | 01,691,436 | -HS- | M] ()
yvzcxo.dll -> %SystemRoot%\System32\yvzcxo.dll -> [2008/11/30 16:46:40 | 00,075,776 | —- | M] ()
ofmnnjam.dll -> %SystemRoot%\System32\ofmnnjam.dll -> [2008/11/30 16:46:40 | 00,075,776 | —- | M] ()
lecbjl.dll -> %SystemRoot%\System32\lecbjl.dll -> [2008/11/30 16:46:38 | 00,129,024 | —- | M] ()
lbwtoaac.dll -> %SystemRoot%\System32\lbwtoaac.dll -> [2008/11/30 16:46:38 | 00,129,024 | —- | M] ()
LopSD.exe -> %UserProfile%\Desktop\LopSD.exe -> [2008/11/30 15:44:02 | 00,529,069 | —- | M] ()
NTREGOPT.lnk -> %UserProfile%\Desktop\NTREGOPT.lnk -> [2008/11/29 19:43:30 | 00,000,519 | —- | M] ()
ERUNT.lnk -> %UserProfile%\Desktop\ERUNT.lnk -> [2008/11/29 19:43:30 | 00,000,500 | —- | M] ()
erunt_setup.exe -> %UserProfile%\Desktop\erunt_setup.exe -> [2008/11/29 19:42:34 | 00,791,393 | —- | M] (Lars Hederer												)
HJTInstall.exe -> %UserProfile%\Desktop\HJTInstall.exe -> [2008/11/29 19:32:16 | 00,812,344 | —- | M] (Trend Micro Inc.)
uvegyt.dll -> %SystemRoot%\System32\uvegyt.dll -> [2008/11/29 16:45:18 | 00,129,024 | —- | M] ()
snghoxvm.dll -> %SystemRoot%\System32\snghoxvm.dll -> [2008/11/29 16:45:18 | 00,129,024 | —- | M] ()
rmirseiq.ini -> %SystemRoot%\System32\rmirseiq.ini -> [2008/11/29 16:45:08 | 01,691,436 | -HS- | M] ()
sxnbkwiy.dll -> %SystemRoot%\System32\sxnbkwiy.dll -> [2008/11/29 16:44:32 | 00,075,776 | —- | M] ()
jxmjgz.dll -> %SystemRoot%\System32\jxmjgz.dll -> [2008/11/29 16:44:32 | 00,075,776 | —- | M] ()
uwnnvtfw.ini -> %SystemRoot%\System32\uwnnvtfw.ini -> [2008/11/29 16:43:54 | 01,691,436 | -HS- | M] ()
Gift lists.xlsx -> %UserProfile%\My Documents\Gift lists.xlsx -> [2008/11/29 00:01:48 | 00,020,492 | —- | M] ()
~.exe -> %SystemRoot%\System32\~.exe -> [2008/11/28 21:17:24 | 00,061,952 | —- | M] ()
qomdne.dll -> %SystemRoot%\System32\qomdne.dll -> [2008/11/28 16:04:02 | 00,075,776 | —- | M] ()
hpuvxyhp.dll -> %SystemRoot%\System32\hpuvxyhp.dll -> [2008/11/28 16:04:02 | 00,075,776 | —- | M] ()
mfftix.dll -> %SystemRoot%\System32\mfftix.dll -> [2008/11/28 16:01:02 | 00,129,024 | —- | M] ()
aujmlggl.dll -> %SystemRoot%\System32\aujmlggl.dll -> [2008/11/28 16:01:02 | 00,129,024 | —- | M] ()
durgjtqm.ini -> %SystemRoot%\System32\durgjtqm.ini -> [2008/11/28 15:59:32 | 01,691,436 | -HS- | M] ()
sisbqrnt.dll -> %SystemRoot%\System32\sisbqrnt.dll -> [2008/11/27 14:26:28 | 00,129,024 | —- | M] ()
llwdna.dll -> %SystemRoot%\System32\llwdna.dll -> [2008/11/27 14:26:28 | 00,129,024 | —- | M] ()
uqveuyne.dll -> %SystemRoot%\System32\uqveuyne.dll -> [2008/11/27 14:21:26 | 00,075,776 | —- | M] ()
azpfhp.dll -> %SystemRoot%\System32\azpfhp.dll -> [2008/11/27 14:21:26 | 00,075,776 | —- | M] ()
zjstnc.dll -> %SystemRoot%\System32\zjstnc.dll -> [2008/11/27 14:11:12 | 00,075,776 | —- | M] ()
eskmtlpl.dll -> %SystemRoot%\System32\eskmtlpl.dll -> [2008/11/27 14:11:12 | 00,075,776 | —- | M] ()
McAfee Security Center.lnk -> %AllUsersProfile%\Desktop\McAfee Security Center.lnk -> [2008/11/26 15:43:50 | 00,000,579 | —- | M] ()
McDefragTask.job -> %SystemRoot%\tasks\McDefragTask.job -> [2008/11/26 15:38:26 | 00,000,344 | —- | M] ()
McQcTask.job -> %SystemRoot%\tasks\McQcTask.job -> [2008/11/26 15:38:24 | 00,000,336 | —- | M] ()
DMSetup-Serial.exe -> %UserProfile%\Desktop\DMSetup-Serial.exe -> [2008/11/26 15:16:16 | 01,226,248 | —- | M] (McAfee, Inc.)
txrjmu.dll -> %SystemRoot%\System32\txrjmu.dll -> [2008/11/26 11:36:52 | 00,075,776 | —- | M] ()
thqwcnrr.dll -> %SystemRoot%\System32\thqwcnrr.dll -> [2008/11/26 11:36:52 | 00,075,776 | —- | M] ()
qmlsajge.dll -> %SystemRoot%\System32\qmlsajge.dll -> [2008/11/26 11:36:22 | 00,075,776 | —- | M] ()
atrfes.dll -> %SystemRoot%\System32\atrfes.dll -> [2008/11/26 11:36:22 | 00,075,776 | —- | M] ()
vvufqhjy.dll -> %SystemRoot%\System32\vvufqhjy.dll -> [2008/11/26 11:15:42 | 00,129,024 | —- | M] ()
ezwjpw.dll -> %SystemRoot%\System32\ezwjpw.dll -> [2008/11/26 11:15:42 | 00,129,024 | —- | M] ()
qoMffFYr.dll -> %SystemRoot%\System32\qoMffFYr.dll -> [2008/11/26 11:12:36 | 00,318,464 | —- | M] ()
MSINET.OCX -> %SystemRoot%\System32\MSINET.OCX -> [2008/11/25 23:29:40 | 00,115,016 | —- | M] (Microsoft Corporation)
MSINET.oca -> %SystemRoot%\System32\MSINET.oca -> [2008/11/25 23:29:40 | 00,029,184 | —- | M] ()
MSINET.DEP -> %SystemRoot%\System32\MSINET.DEP -> [2008/11/25 23:29:40 | 00,002,407 | —- | M] ()
iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [2008/11/25 17:17:14 | 00,002,137 | —- | M] ()
Oct-Dec2008.docx -> %UserProfile%\Desktop\Oct-Dec2008.docx -> [2008/11/23 19:28:00 | 00,017,099 | —- | M] ()
2008-09-Faith Formation calendar.pdf -> %UserProfile%\Desktop\2008-09-Faith Formation calendar.pdf -> [2008/11/23 19:27:02 | 00,277,116 | —- | M] ()
Christmas lists.docx -> %UserProfile%\My Documents\Christmas lists.docx -> [2008/11/23 19:20:40 | 00,013,677 | —- | M] ()
~$ristmas lists.docx -> %UserProfile%\My Documents\~$ristmas lists.docx -> [2008/11/23 13:43:46 | 00,000,162 | -H– | M] ()
OneNote 2007 Screen Clipper and Launcher.lnk -> %UserProfile%\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk -> [2008/11/23 13:06:04 | 00,000,855 | —- | M] ()
imsins.BAK -> %SystemRoot%\imsins.BAK -> [2008/11/11 23:24:16 | 00,001,393 | —- | M] ()
110908_bento_closeup.JPG -> %UserProfile%\Desktop\110908_bento_closeup.JPG -> [2008/11/09 22:32:02 | 00,306,112 | —- | M] ()
110908_bento.JPG -> %UserProfile%\Desktop\110908_bento.JPG -> [2008/11/09 22:30:50 | 00,938,713 | —- | M] ()
Reading Log.docx -> %UserProfile%\My Documents\Reading Log.docx -> [2008/11/09 18:57:28 | 00,011,382 | —- | M] ()
~$ading Log.docx -> %UserProfile%\My Documents\~$ading Log.docx -> [2008/11/09 18:50:24 | 00,000,162 | -H– | M] ()
my-neighbor-totoro-tonari-no-totoro-piano-duet[1].pdf -> %UserProfile%\My Documents\my-neighbor-totoro-tonari-no-totoro-piano-duet[1].pdf -> [2008/11/08 22:36:06 | 00,377,436 | —- | M] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2008/11/02 19:18:34 | 00,020,992 | —- | M] ()
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2008/11/02 08:34:18 | 01,662,432 | —- | M] ()
Virtual Earth.lnk -> %AllUsersProfile%\Desktop\Virtual Earth.lnk -> [2008/11/01 17:08:58 | 00,001,809 | —- | M] ()
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2008/11/01 16:14:14 | 04,843,052 | -H– | M] ()
CURRENT EVENTS worksheet.doc -> %UserProfile%\My Documents\CURRENT EVENTS worksheet.doc -> [2008/10/29 21:29:56 | 00,025,088 | —- | M] ()
mrxsmb.sys -> %SystemRoot%\System32\drivers\mrxsmb.sys -> [2008/10/24 05:10:42 | 00,453,632 | —- | M] (Microsoft Corporation)
mrxsmb.sys -> %SystemRoot%\System32\dllcache\mrxsmb.sys -> [2008/10/24 05:10:42 | 00,453,632 | —- | M] (Microsoft Corporation)
2009 calendar.docx -> %UserProfile%\Desktop\2009 calendar.docx -> [2008/10/22 19:20:12 | 00,035,851 | —- | M] ()
wuaueng.dll -> %SystemRoot%\System32\wuaueng.dll -> [2008/10/16 14:13:40 | 01,809,944 | —- | M] (Microsoft Corporation)
wuaueng.dll -> %SystemRoot%\System32\dllcache\wuaueng.dll -> [2008/10/16 14:13:40 | 01,809,944 | —- | M] (Microsoft Corporation)
wuweb.dll -> %SystemRoot%\System32\wuweb.dll -> [2008/10/16 14:13:40 | 00,202,776 | —- | M] (Microsoft Corporation)
wuweb.dll -> %SystemRoot%\System32\dllcache\wuweb.dll -> [2008/10/16 14:13:40 | 00,202,776 | —- | M] (Microsoft Corporation)
wucltui.dll -> %SystemRoot%\System32\wucltui.dll -> [2008/10/16 14:12:22 | 00,323,608 | —- | M] (Microsoft Corporation)
wucltui.dll -> %SystemRoot%\System32\dllcache\wucltui.dll -> [2008/10/16 14:12:22 | 00,323,608 | —- | M] (Microsoft Corporation)
wuapi.dll -> %SystemRoot%\System32\wuapi.dll -> [2008/10/16 14:12:20 | 00,561,688 | —- | M] (Microsoft Corporation)
wuapi.dll -> %SystemRoot%\System32\dllcache\wuapi.dll -> [2008/10/16 14:12:20 | 00,561,688 | —- | M] (Microsoft Corporation)
wuaucpl.cpl -> %SystemRoot%\System32\wuaucpl.cpl -> [2008/10/16 14:12:20 | 00,213,528 | —- | M] (Microsoft Corporation)
wuaucpl.cpl -> %SystemRoot%\System32\dllcache\wuaucpl.cpl -> [2008/10/16 14:12:20 | 00,213,528 | —- | M] (Microsoft Corporation)
cdm.dll -> %SystemRoot%\System32\dllcache\cdm.dll -> [2008/10/16 14:09:44 | 00,092,696 | —- | M] (Microsoft Corporation)
cdm.dll -> %SystemRoot%\System32\cdm.dll -> [2008/10/16 14:09:44 | 00,092,696 | —- | M] (Microsoft Corporation)
wuauclt.exe -> %SystemRoot%\System32\wuauclt.exe -> [2008/10/16 14:09:44 | 00,051,224 | —- | M] (Microsoft Corporation)
wuauclt.exe -> %SystemRoot%\System32\dllcache\wuauclt.exe -> [2008/10/16 14:09:44 | 00,051,224 | —- | M] (Microsoft Corporation)
wups2.dll -> %SystemRoot%\System32\wups2.dll -> [2008/10/16 14:09:44 | 00,043,544 | —- | M] (Microsoft Corporation)
wucltui.dll.mui -> %SystemRoot%\System32\wucltui.dll.mui -> [2008/10/16 14:09:40 | 00,031,768 | —- | M] (Microsoft Corporation)
wups.dll -> %SystemRoot%\System32\wups.dll -> [2008/10/16 14:08:58 | 00,034,328 | —- | M] (Microsoft Corporation)
wups.dll -> %SystemRoot%\System32\dllcache\wups.dll -> [2008/10/16 14:08:58 | 00,034,328 | —- | M] (Microsoft Corporation)
wuaucpl.cpl.mui -> %SystemRoot%\System32\wuaucpl.cpl.mui -> [2008/10/16 14:07:46 | 00,023,576 | —- | M] (Microsoft Corporation)
wuapi.dll.mui -> %SystemRoot%\System32\wuapi.dll.mui -> [2008/10/16 14:07:44 | 00,023,576 | —- | M] (Microsoft Corporation)
wuaueng.dll.mui -> %SystemRoot%\System32\wuaueng.dll.mui -> [2008/10/16 14:07:14 | 00,018,456 | —- | M] (Microsoft Corporation)
mucltui.dll -> %SystemRoot%\System32\mucltui.dll -> [2008/10/16 14:06:48 | 00,268,648 | —- | M] (Microsoft Corporation)
muweb.dll -> %SystemRoot%\System32\muweb.dll -> [2008/10/16 14:06:48 | 00,208,744 | —- | M] (Microsoft Corporation)
mucltui.dll.mui -> %SystemRoot%\System32\mucltui.dll.mui -> [2008/10/16 14:06:48 | 00,027,496 | —- | M] (Microsoft Corporation)
netapi32.dll -> %SystemRoot%\System32\netapi32.dll -> [2008/10/15 11:57:56 | 00,332,800 | —- | M] (Microsoft Corporation)
netapi32.dll -> %SystemRoot%\System32\dllcache\netapi32.dll -> [2008/10/15 11:57:56 | 00,332,800 | —- | M] (Microsoft Corporation)
christmas2.JPG -> %UserProfile%\My Documents\christmas2.JPG -> [2008/10/12 21:52:00 | 00,779,018 | —- | M] ()
christmas2.JPG -> %UserProfile%\Desktop\christmas2.JPG -> [2008/10/12 21:52:00 | 00,779,018 | —- | M] ()
Amelia.jpg -> %UserProfile%\Desktop\Amelia.jpg -> [2008/10/12 21:52:00 | 00,098,782 | —- | M] ()
Metformin_IV_Contrast_Sept_2008_lisa[1].doc -> %UserProfile%\Desktop\Metformin_IV_Contrast_Sept_2008_lisa[1].doc -> [2008/10/08 19:15:44 | 00,058,880 | —- | M] ()
d3d9caps.dat -> %SystemRoot%\System32\d3d9caps.dat -> [2008/10/06 23:27:50 | 00,000,664 | —- | M] ()
Trader Joes shopping list sorted.doc -> %UserProfile%\Desktop\Trader Joes shopping list sorted.doc -> [2008/10/05 12:51:20 | 00,027,648 | —- | M] ()
cruises.doc -> %UserProfile%\Desktop\cruises.doc -> [2008/10/04 19:25:02 | 00,019,968 | —- | M] ()
Smarter_than_a_5th_grader%281%29(1).xls -> %UserProfile%\Desktop\Smarter_than_a_5th_grader%281%29(1).xls -> [2008/10/03 14:14:40 | 00,152,576 | —- | M] ()
ieframe.dll -> %SystemRoot%\System32\ieframe.dll -> [2008/10/03 12:41:16 | 06,066,176 | —- | M] (Microsoft Corporation)
ieframe.dll -> %SystemRoot%\System32\dllcache\ieframe.dll -> [2008/10/03 12:41:16 | 06,066,176 | —- | M] (Microsoft Corporation)
msxml4.dll -> %SystemRoot%\System32\msxml4.dll -> [2008/09/30 16:43:34 | 01,286,152 | —- | M] (Microsoft Corporation)
clip_image001.jpg -> %UserProfile%\My Documents\clip_image001.jpg -> [2008/09/24 19:43:02 | 00,200,640 | —- | M] ()
marscam.ini -> %SystemRoot%\marscam.ini -> [2008/09/20 15:20:42 | 00,000,037 | —- | M] ()
Bug chart.docx -> %AllUsersProfile%\Documents\Bug chart.docx -> [2008/09/20 13:45:20 | 00,011,106 | —- | M] ()
~$g chart.docx -> %AllUsersProfile%\Documents\~$g chart.docx -> [2008/09/20 13:45:20 | 00,000,162 | -H– | M] ()
win32k.sys -> %SystemRoot%\System32\win32k.sys -> [2008/09/15 06:57:42 | 01,846,016 | —- | M] (Microsoft Corporation)
win32k.sys -> %SystemRoot%\System32\dllcache\win32k.sys -> [2008/09/15 06:57:42 | 01,846,016 | —- | M] (Microsoft Corporation)
Sept 12 LArts.pdf -> %AllUsersProfile%\Documents\Sept 12 LArts.pdf -> [2008/09/13 16:42:58 | 00,124,655 | —- | M] ()
Life Science Assignments.doc -> %AllUsersProfile%\Documents\Life Science Assignments.doc -> [2008/09/13 16:39:24 | 00,062,464 | —- | M] ()
WgaLogon.dll -> %SystemRoot%\System32\WgaLogon.dll -> [2008/09/05 23:30:42 | 00,241,704 | —- | M] (Microsoft Corporation)
wgaLogon.dll -> %SystemRoot%\System32\dllcache\wgaLogon.dll -> [2008/09/05 23:30:42 | 00,241,704 | —- | M] (Microsoft Corporation)
LegitCheckControl.dll -> %SystemRoot%\System32\LegitCheckControl.dll -> [2008/09/05 23:30:06 | 01,480,232 | —- | M] (Microsoft Corporation)
WgaTray.exe -> %SystemRoot%\System32\WgaTray.exe -> [2008/09/05 23:29:58 | 00,917,032 | —- | M] (Microsoft Corporation)
WgaTray.exe -> %SystemRoot%\System32\dllcache\WgaTray.exe -> [2008/09/05 23:29:58 | 00,917,032 | —- | M] (Microsoft Corporation)
msxml3.dll -> %SystemRoot%\System32\msxml3.dll -> [2008/09/04 10:42:02 | 01,106,944 | —- | M] (Microsoft Corporation)
msxml3.dll -> %SystemRoot%\System32\dllcache\msxml3.dll -> [2008/09/04 10:42:02 | 01,106,944 | —- | M] (Microsoft Corporation)
[File - Lop Check]
36 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> 
Application Data -> C:\Documents and Settings\All Users\Application Data -> [2006/08/23 02:29:04 | 00,000,000 | RH-D | M]
{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> [2008/10/17 14:50:28 | 00,000,000 | —D | M]
Acer -> C:\Documents and Settings\All Users\Application Data\Acer -> [2006/08/23 03:06:58 | 00,000,000 | —D | M]
CyberLink -> C:\Documents and Settings\All Users\Application Data\CyberLink -> [2006/12/26 02:41:50 | 00,000,000 | —D | M]
FLEXnet -> C:\Documents and Settings\All Users\Application Data\FLEXnet -> [2008/03/13 20:23:36 | 00,000,000 | —D | M]
Intel -> C:\Documents and Settings\All Users\Application Data\Intel -> [2006/12/26 02:44:58 | 00,000,000 | —D | M]
PopCap -> C:\Documents and Settings\All Users\Application Data\PopCap -> [2007/02/09 17:18:44 | 00,000,000 | —D | M]
Quark -> C:\Documents and Settings\All Users\Application Data\Quark -> [2007/01/19 19:30:38 | 00,000,000 | —D | M]
TEMP -> C:\Documents and Settings\All Users\Application Data\TEMP -> [2008/08/13 11:54:06 | 00,000,000 | —D | M]
Trymedia -> C:\Documents and Settings\All Users\Application Data\Trymedia -> [2007/02/10 10:12:38 | 00,000,000 | —D | M]
WholeSecurity -> C:\Documents and Settings\All Users\Application Data\WholeSecurity -> [2007/02/17 09:55:04 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\Maryann\Application Data -> [2006/08/23 02:29:04 | 00,000,000 | RH-D | M]
Acer -> C:\Documents and Settings\Maryann\Application Data\Acer -> [2006/08/23 03:09:44 | 00,000,000 | —D | M]
CyberLink -> C:\Documents and Settings\Maryann\Application Data\CyberLink -> [2006/12/26 03:26:26 | 00,000,000 | —D | M]
ICAClient -> C:\Documents and Settings\Maryann\Application Data\ICAClient -> [2007/02/28 22:55:38 | 00,000,000 | —D | M]
Leadertech -> C:\Documents and Settings\Maryann\Application Data\Leadertech -> [2007/07/07 23:37:40 | 00,000,000 | —D | M]
Move Networks -> C:\Documents and Settings\Maryann\Application Data\Move Networks -> [2007/09/23 22:03:28 | 00,000,000 | —D | M]
mypoints -> C:\Documents and Settings\Maryann\Application Data\mypoints -> [2008/03/01 18:08:08 | 00,000,000 | —D | M]
Quark -> C:\Documents and Settings\Maryann\Application Data\Quark -> [2007/01/19 19:30:58 | 00,000,000 | —D | M]
C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2006/08/23 02:38:34 | 00,000,000 | –SD | M]
desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2004/08/04 05:00:00 | 00,000,065 | RH– | M] ()
SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2008/12/01 09:35:54 | 00,000,006 | -H– | M] ()
McQcTask.job -> C:\WINDOWS\Tasks\McQcTask.job -> [2008/11/26 15:38:24 | 00,000,336 | —- | M] ()
McDefragTask.job -> C:\WINDOWS\Tasks\McDefragTask.job -> [2008/11/26 15:38:26 | 00,000,344 | —- | M] ()
[File - Purity Scan]
 
[File - Signature Check]
< Cached Copy > -> < OS Copy > -> < MD5's >
C:\WINDOWS\system32\dllcache\explorer.exe [2007/06/13 05:23:08 | 01,033,216 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\explorer.exe [2007/06/13 05:23:08 | 01,033,216 | —- | M] (Microsoft Corporation) -> Cached Copy = 97BD6515465659FF8F3B7BE375B2EA87 \ OS Copy = 97BD6515465659FF8F3B7BE375B2EA87
C:\WINDOWS\system32\dllcache\csrss.exe [2004/08/03 22:00:00 | 00,006,144 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\csrss.exe [2004/08/04 05:00:00 | 00,006,144 | —- | M] (Microsoft Corporation) -> Cached Copy = F12B178B1678D778CFD3FF1FC38C71FB \ OS Copy = F12B178B1678D778CFD3FF1FC38C71FB
C:\WINDOWS\system32\dllcache\lsass.exe [2004/08/03 22:00:00 | 00,013,312 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\lsass.exe [2004/08/04 05:00:00 | 00,013,312 | —- | M] (Microsoft Corporation) -> Cached Copy = 84885F9B82F4D55C6146EBF6065D75D2 \ OS Copy = 84885F9B82F4D55C6146EBF6065D75D2
C:\WINDOWS\system32\dllcache\rundll32.exe [2004/08/04 05:00:00 | 00,033,280 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\rundll32.exe [2004/08/04 05:00:00 | 00,033,280 | —- | M] (Microsoft Corporation) -> Cached Copy = DA285490BBD8A1D0CE6623577D5BA1FF \ OS Copy = DA285490BBD8A1D0CE6623577D5BA1FF
C:\WINDOWS\system32\dllcache\services.exe [2004/08/03 22:00:00 | 00,108,032 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\services.exe [2004/08/04 05:00:00 | 00,108,032 | —- | M] (Microsoft Corporation) -> Cached Copy = C6CE6EEC82F187615D1002BB3BB50ED4 \ OS Copy = C6CE6EEC82F187615D1002BB3BB50ED4
C:\WINDOWS\system32\dllcache\smss.exe [2004/08/03 22:00:00 | 00,050,688 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\smss.exe [2004/08/04 05:00:00 | 00,050,688 | —- | M] (Microsoft Corporation) -> Cached Copy = BD7FB0957C716F1A60333AEE04DE2178 \ OS Copy = BD7FB0957C716F1A60333AEE04DE2178
C:\WINDOWS\system32\dllcache\spoolsv.exe [2005/06/10 17:53:32 | 00,057,856 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\spoolsv.exe [2005/06/10 17:53:32 | 00,057,856 | —- | M] (Microsoft Corporation) -> Cached Copy = DA81EC57ACD4CDC3D4C51CF3D409AF9F \ OS Copy = DA81EC57ACD4CDC3D4C51CF3D409AF9F
C:\WINDOWS\system32\dllcache\svchost.exe [2004/08/03 22:00:00 | 00,014,336 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\svchost.exe [2004/08/04 05:00:00 | 00,014,336 | —- | M] (Microsoft Corporation) -> Cached Copy = 8F078AE4ED187AAABC0A305146DE6716 \ OS Copy = 8F078AE4ED187AAABC0A305146DE6716
C:\WINDOWS\system32\dllcache\taskmgr.exe [2004/08/04 05:00:00 | 00,135,680 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\taskmgr.exe [2004/08/04 05:00:00 | 00,135,680 | —- | M] (Microsoft Corporation) -> Cached Copy = FC160ACE21C81837692B339D230DD4BE \ OS Copy = FC160ACE21C81837692B339D230DD4BE
C:\WINDOWS\system32\dllcache\userinit.exe [2004/08/04 05:00:00 | 00,024,576 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\userinit.exe [2004/08/04 05:00:00 | 00,024,576 | —- | M] (Microsoft Corporation) -> Cached Copy = 39B1FFB03C2296323832ACBAE50D2AFF \ OS Copy = 39B1FFB03C2296323832ACBAE50D2AFF
C:\WINDOWS\system32\dllcache\winlogon.exe [2004/08/03 22:00:00 | 00,502,272 | —- | M] (Microsoft Corporation) -> C:\WINDOWS\system32\winlogon.exe [2004/08/04 05:00:00 | 00,502,272 | —- | M] (Microsoft Corporation) -> Cached Copy = 01C3346C241652F43AED8E2149881BFE \ OS Copy = 01C3346C241652F43AED8E2149881BFE
 
[CatchMe Rootkit Scan by GMER]
< Windows folder & sub-folders >
scanning hidden services …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  McAfee Backup = C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
< Document and Settings folder & sub folders >
scanning hidden services …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  McAfee Backup = C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
 
[Custom Scans]
< C:\Windows\Prefetch\*.* /s >
C:\Windows\Prefetch\ -> C:\Windows\Prefetch -> [2006/08/23 02:45:32 | 00,000,000 | —D | M]
RUNDLL32.EXE-71AB9752.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 18:53:40 | 00,035,378 | —- | M] ()
INSTALLHELPER.EXE-34E4A3DB.pf -> C:\Windows\Prefetch\INSTALLHELPER.EXE -> [2008/12/01 09:37:08 | 00,021,066 | —- | M] ()
LOGONUI.EXE-312BE1BF.pf -> C:\Windows\Prefetch\LOGONUI.EXE -> [2008/12/01 12:37:28 | 00,056,898 | —- | M] ()
RUNDLL32.EXE-6E8D4657.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 18:55:02 | 00,027,692 | —- | M] ()
GOOGLETOOLBARNOTIFIER.EXE-0047A1C5.pf -> C:\Windows\Prefetch\GOOGLETOOLBARNOTIFIER.EXE -> [2008/12/01 09:38:00 | 00,064,704 | —- | M] ()
OUTLOOK.EXE-326CF986.pf -> C:\Windows\Prefetch\OUTLOOK.EXE -> [2008/12/01 07:05:36 | 00,107,008 | —- | M] ()
MONITOR.EXE-0693E15D.pf -> C:\Windows\Prefetch\MONITOR.EXE -> [2008/12/01 09:37:08 | 00,027,666 | —- | M] ()
NAVW32.EXE-32139521.pf -> C:\Windows\Prefetch\NAVW32.EXE -> [2008/11/26 14:55:06 | 00,073,710 | —- | M] ()
RUNDLL32.EXE-4FF9832D.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 18:55:58 | 00,026,002 | —- | M] ()
E_FPREAJA.EXE-1AD749DD.pf -> C:\Windows\Prefetch\E_FPREAJA.EXE -> [2008/11/30 18:56:12 | 00,036,548 | —- | M] ()
E_FAMTAJA.EXE-259013E3.pf -> C:\Windows\Prefetch\E_FAMTAJA.EXE -> [2008/11/30 18:56:18 | 00,029,998 | —- | M] ()
E_FARNAJA.EXE-0F851086.pf -> C:\Windows\Prefetch\E_FARNAJA.EXE -> [2008/11/30 18:56:18 | 00,029,484 | —- | M] ()
NOTEPAD.EXE-2F2D61E1.pf -> C:\Windows\Prefetch\NOTEPAD.EXE -> [2008/12/01 09:41:04 | 00,029,262 | —- | M] ()
RUNDLL32.EXE-41C4C933.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 09:37:08 | 00,034,598 | —- | M] ()
MCSHELL.EXE-0086A5A5.pf -> C:\Windows\Prefetch\MCSHELL.EXE -> [2008/12/01 09:37:56 | 00,060,352 | —- | M] ()
OTSCANIT2.EXE-38B52C6F.pf -> C:\Windows\Prefetch\OTSCANIT2.EXE -> [2008/11/30 19:02:08 | 00,026,218 | —- | M] ()
OTSCANIT2.EXE-292E33A5.pf -> C:\Windows\Prefetch\OTSCANIT2.EXE -> [2008/12/01 09:52:56 | 00,033,780 | —- | M] ()
CATCHME.EXE-372FD807.pf -> C:\Windows\Prefetch\CATCHME.EXE -> [2008/12/01 12:38:00 | 00,015,682 | —- | M] ()
VPNGUI.EXE-1D86AE14.pf -> C:\Windows\Prefetch\VPNGUI.EXE -> [2008/12/01 09:38:18 | 00,031,902 | —- | M] ()
DUMPREP.EXE-0AF2BF67.pf -> C:\Windows\Prefetch\DUMPREP.EXE -> [2008/12/01 08:11:26 | 00,200,330 | —- | M] ()
DWWIN.EXE-2C373FB7.pf -> C:\Windows\Prefetch\DWWIN.EXE -> [2008/12/01 08:11:32 | 00,034,168 | —- | M] ()
MCSVRCNT.EXE-082353A7.pf -> C:\Windows\Prefetch\MCSVRCNT.EXE -> [2008/12/01 11:53:32 | 00,046,470 | —- | M] ()
MCVSMAP.EXE-068969FB.pf -> C:\Windows\Prefetch\MCVSMAP.EXE -> [2008/12/01 11:53:34 | 00,029,274 | —- | M] ()
MCINFO.EXE-079FCA72.pf -> C:\Windows\Prefetch\MCINFO.EXE -> [2008/12/01 11:53:36 | 00,048,986 | —- | M] ()
MCSYNC.EXE-0369EAA9.pf -> C:\Windows\Prefetch\MCSYNC.EXE -> [2008/12/01 11:53:36 | 00,036,560 | —- | M] ()
ACER EPOWER MANAGEMENT.EXE-269102ED.pf -> C:\Windows\Prefetch\ACER EPOWER MANAGEMENT.EXE -> [2008/12/01 09:37:08 | 00,023,120 | —- | M] ()
MCUPDATE.EXE-32479339.pf -> C:\Windows\Prefetch\MCUPDATE.EXE -> [2008/12/01 11:53:36 | 00,053,838 | —- | M] ()
LMANAGER.EXE-38229E59.pf -> C:\Windows\Prefetch\LMANAGER.EXE -> [2008/12/01 09:37:08 | 00,023,556 | —- | M] ()
CAMERAASSISTANT.EXE-0C1735AF.pf -> C:\Windows\Prefetch\CAMERAASSISTANT.EXE -> [2008/12/01 09:37:16 | 00,030,518 | —- | M] ()
LVCOMSX.EXE-30FB8DC0.pf -> C:\Windows\Prefetch\LVCOMSX.EXE -> [2008/12/01 09:37:12 | 00,043,968 | —- | M] ()
UNSECAPP.EXE-16EB9856.pf -> C:\Windows\Prefetch\UNSECAPP.EXE -> [2008/12/01 09:37:50 | 00,027,324 | —- | M] ()
MCUPDMGR.EXE-2AB0177A.pf -> C:\Windows\Prefetch\MCUPDMGR.EXE -> [2008/12/01 11:53:42 | 00,062,338 | —- | M] ()
IEXPLORE.EXE-2D97EBE6.pf -> C:\Windows\Prefetch\IEXPLORE.EXE -> [2008/12/01 11:42:02 | 00,104,042 | —- | M] ()
HWUPDCHK.EXE-2CCE7F93.pf -> C:\Windows\Prefetch\HWUPDCHK.EXE -> [2008/12/01 11:53:36 | 00,037,170 | —- | M] ()
MCSYSMON.EXE-3AA753B8.pf -> C:\Windows\Prefetch\MCSYSMON.EXE -> [2008/12/01 07:06:14 | 00,040,298 | —- | M] ()
NTOSBOOT-B00DFAAD.pf -> C:\Windows\Prefetch\NTOSBOOT-B00DFAAD.pf -> [2008/12/01 09:37:08 | 00,704,692 | —- | M] ()
RUNDLL32.EXE-4D15288E.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 20:16:20 | 00,040,626 | —- | M] ()
MBKLAU~1.EXE-1942AFB4.pf -> C:\Windows\Prefetch\MBKLAU~1.EXE -> [2008/11/30 20:27:18 | 00,058,516 | —- | M] ()
GOOGLEDESKTOP.EXE-16DAD850.pf -> C:\Windows\Prefetch\GOOGLEDESKTOP.EXE -> [2008/12/01 09:37:38 | 00,025,354 | —- | M] ()
EXPLORER.EXE-02121B1A.pf -> C:\Windows\Prefetch\EXPLORER.EXE -> [2008/12/01 09:51:44 | 00,071,126 | —- | M] ()
SNDVOL32.EXE-0EC6FD20.pf -> C:\Windows\Prefetch\SNDVOL32.EXE -> [2008/11/30 22:46:08 | 00,030,014 | —- | M] ()
ALAUNCH.EXE-145B15F4.pf -> C:\Windows\Prefetch\ALAUNCH.EXE -> [2008/12/01 07:05:02 | 00,019,134 | —- | M] ()
AZMIXERSEL.EXE-0057985F.pf -> C:\Windows\Prefetch\AZMIXERSEL.EXE -> [2008/12/01 07:05:00 | 00,018,782 | —- | M] ()
IGFXSRVC.EXE-1D88F978.pf -> C:\Windows\Prefetch\IGFXSRVC.EXE -> [2008/12/01 07:05:02 | 00,016,980 | —- | M] ()
SYNTPENH.EXE-2B70B91C.pf -> C:\Windows\Prefetch\SYNTPENH.EXE -> [2008/11/30 22:27:58 | 00,017,030 | —- | M] ()
NTIMUI.EXE-2D0A7662.pf -> C:\Windows\Prefetch\NTIMUI.EXE -> [2008/12/01 07:05:02 | 00,030,494 | —- | M] ()
IPODSERVICE.EXE-37043579.pf -> C:\Windows\Prefetch\IPODSERVICE.EXE -> [2008/12/01 09:38:18 | 00,081,846 | —- | M] ()
ELKCTRL.EXE-0C71F1E7.pf -> C:\Windows\Prefetch\ELKCTRL.EXE -> [2008/12/01 09:37:20 | 00,022,974 | —- | M] ()
ADMTRAY.EXE-261081D2.pf -> C:\Windows\Prefetch\ADMTRAY.EXE -> [2008/12/01 07:05:02 | 00,022,544 | —- | M] ()
EDSLOADER.EXE-2A914953.pf -> C:\Windows\Prefetch\EDSLOADER.EXE -> [2008/12/01 07:05:02 | 00,033,412 | —- | M] ()
RUNDLL32.EXE-3B866543.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 07:05:02 | 00,022,522 | —- | M] ()
RUNDLL32.EXE-5ACE91DC.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 07:14:44 | 00,030,828 | —- | M] ()
EPOWER_DMC.EXE-0838B86A.pf -> C:\Windows\Prefetch\EPOWER_DMC.EXE -> [2008/12/01 07:05:04 | 00,008,222 | —- | M] ()
LOGON.SCR-24ADF392.pf -> C:\Windows\Prefetch\LOGON.SCR -> [2008/12/01 10:17:24 | 00,011,336 | —- | M] ()
JUSCHED.EXE-0C11AB3F.pf -> C:\Windows\Prefetch\JUSCHED.EXE -> [2008/12/01 09:37:20 | 00,017,092 | —- | M] ()
E_FATIAJA.EXE-1E181673.pf -> C:\Windows\Prefetch\E_FATIAJA.EXE -> [2008/12/01 09:37:26 | 00,015,226 | —- | M] ()
ALCMTR.EXE-01A7139B.pf -> C:\Windows\Prefetch\ALCMTR.EXE -> [2008/12/01 09:37:26 | 00,016,922 | —- | M] ()
RTHDCPL.EXE-005A6E31.pf -> C:\Windows\Prefetch\RTHDCPL.EXE -> [2008/12/01 09:37:34 | 00,025,486 | —- | M] ()
ALG.EXE-275708CF.pf -> C:\Windows\Prefetch\ALG.EXE -> [2008/12/01 09:37:38 | 00,020,518 | —- | M] ()
GROOVEMONITOR.EXE-23AE9D0A.pf -> C:\Windows\Prefetch\GROOVEMONITOR.EXE -> [2008/12/01 09:37:36 | 00,030,918 | —- | M] ()
MCUIMGR.EXE-232A5ACA.pf -> C:\Windows\Prefetch\MCUIMGR.EXE -> [2008/12/01 09:38:22 | 00,029,830 | —- | M] ()
APDPROXY.EXE-1570C10E.pf -> C:\Windows\Prefetch\APDPROXY.EXE -> [2008/12/01 09:37:38 | 00,028,338 | —- | M] ()
READER_SL.EXE-02E193BD.pf -> C:\Windows\Prefetch\READER_SL.EXE -> [2008/12/01 09:37:40 | 00,021,200 | —- | M] ()
APPLESYNCNOTIFIER.EXE-118555EB.pf -> C:\Windows\Prefetch\APPLESYNCNOTIFIER.EXE -> [2008/12/01 07:05:54 | 00,018,104 | —- | M] ()
MCAGENT.EXE-0AA61076.pf -> C:\Windows\Prefetch\MCAGENT.EXE -> [2008/12/01 09:37:40 | 00,019,522 | —- | M] ()
ITUNESHELPER.EXE-0A1B0F2C.pf -> C:\Windows\Prefetch\ITUNESHELPER.EXE -> [2008/12/01 09:37:46 | 00,023,074 | —- | M] ()
MCAFEEDATABACKUP.EXE-0F64DECB.pf -> C:\Windows\Prefetch\MCAFEEDATABACKUP.EXE -> [2008/12/01 09:37:52 | 00,034,142 | —- | M] ()
LOGONHOOK.EXE-0165E737.pf -> C:\Windows\Prefetch\LOGONHOOK.EXE -> [2008/12/01 09:37:50 | 00,021,588 | —- | M] ()
RUNDLL32.EXE-5CBEC4AF.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 09:37:50 | 00,021,942 | —- | M] ()
RUNDLL32.EXE-43401C69.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 22:28:36 | 00,007,164 | —- | M] ()
ONENOTEM.EXE-14CC9B1E.pf -> C:\Windows\Prefetch\ONENOTEM.EXE -> [2008/12/01 09:38:06 | 00,030,204 | —- | M] ()
CVTRES.EXE-16681F8A.pf -> C:\Windows\Prefetch\CVTRES.EXE -> [2008/12/01 09:38:30 | 00,017,056 | —- | M] ()
CSC.EXE-22F6101C.pf -> C:\Windows\Prefetch\CSC.EXE -> [2008/12/01 09:38:30 | 00,050,720 | —- | M] ()
RUNDLL32.EXE-58320A10.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 22:29:48 | 00,025,502 | —- | M] ()
RUNDLL32.EXE-757ED321.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 22:30:04 | 00,029,980 | —- | M] ()
RUNDLL32.EXE-3B4320EE.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/11/30 22:30:26 | 00,027,222 | —- | M] ()
IGFXPERS.EXE-19DA7B04.pf -> C:\Windows\Prefetch\IGFXPERS.EXE -> [2008/12/01 07:05:00 | 00,016,786 | —- | M] ()
HKCMD.EXE-0F06AE14.pf -> C:\Windows\Prefetch\HKCMD.EXE -> [2008/12/01 07:05:00 | 00,017,012 | —- | M] ()
IGFXTRAY.EXE-0A23D403.pf -> C:\Windows\Prefetch\IGFXTRAY.EXE -> [2008/12/01 07:05:00 | 00,017,742 | —- | M] ()
TINTSETP.EXE-2DD83AEF.pf -> C:\Windows\Prefetch\TINTSETP.EXE -> [2008/12/01 09:37:08 | 00,011,808 | —- | M] ()
IMSCINST.EXE-2B626103.pf -> C:\Windows\Prefetch\IMSCINST.EXE -> [2008/12/01 09:37:08 | 00,016,026 | —- | M] ()
IMJPMIG.EXE-32ABEE9A.pf -> C:\Windows\Prefetch\IMJPMIG.EXE -> [2008/12/01 07:05:02 | 00,017,486 | —- | M] ()
NWIZ.EXE-2D374245.pf -> C:\Windows\Prefetch\NWIZ.EXE -> [2008/12/01 09:37:08 | 00,017,960 | —- | M] ()
RUNDLL32.EXE-7316AB2B.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 09:37:52 | 00,014,708 | —- | M] ()
TASKMGR.EXE-06144C13.pf -> C:\Windows\Prefetch\TASKMGR.EXE -> [2008/12/01 08:09:54 | 00,029,822 | —- | M] ()
FXSSVC.EXE-140862E7.pf -> C:\Windows\Prefetch\FXSSVC.EXE -> [2008/12/01 09:37:08 | 00,016,022 | —- | M] ()
RUNDLL32.EXE-6ACD0C83.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 09:37:08 | 00,028,394 | —- | M] ()
RUNDLL32.EXE-3CAE7316.pf -> C:\Windows\Prefetch\RUNDLL32.EXE -> [2008/12/01 09:37:08 | 00,017,952 | —- | M] ()
PCMSERVICE.EXE-384B5F7A.pf -> C:\Windows\Prefetch\PCMSERVICE.EXE -> [2008/12/01 09:37:08 | 00,004,784 | —- | M] ()
ICWCONN1.EXE-01D53BFC.pf -> C:\Windows\Prefetch\ICWCONN1.EXE -> [2008/12/01 11:42:18 | 00,023,142 | —- | M] ()
Layout.ini -> C:\Windows\Prefetch\Layout.ini -> [2008/12/01 10:21:42 | 00,236,944 | —- | M] ()
REGSVR32.EXE-396DEA2C.pf -> C:\Windows\Prefetch\REGSVR32.EXE -> [2008/12/01 09:37:16 | 00,020,778 | —- | M] ()
IMAPI.EXE-201490BB.pf -> C:\Windows\Prefetch\IMAPI.EXE -> [2008/12/01 09:51:56 | 00,078,052 | —- | M] ()
RTKBTMNT.EXE-219E8D85.pf -> C:\Windows\Prefetch\RTKBTMNT.EXE -> [2008/12/01 09:37:44 | 00,078,252 | —- | M] ()
QTTASK.EXE-1876A1A1.pf -> C:\Windows\Prefetch\QTTASK.EXE -> [2008/12/01 07:05:50 | 00,015,738 | —- | M] ()
MSMSGS.EXE-0620E8B3.pf -> C:\Windows\Prefetch\MSMSGS.EXE -> [2008/11/26 15:28:44 | 00,027,584 | —- | M] ()
CTFMON.EXE-05E57A5E.pf -> C:\Windows\Prefetch\CTFMON.EXE -> [2008/12/01 09:37:52 | 00,021,908 | —- | M] ()
WMIPRVSE.EXE-0D449B4F.pf -> C:\Windows\Prefetch\WMIPRVSE.EXE -> [2008/12/01 09:37:42 | 00,041,650 | —- | M] ()
WUAUCLT.EXE-1360D60A.pf -> C:\Windows\Prefetch\WUAUCLT.EXE -> [2008/11/27 22:51:30 | 00,041,952 | —- | M] ()
NSCSRVCE.EXE-24B30AFD.pf -> C:\Windows\Prefetch\NSCSRVCE.EXE -> [2008/11/26 14:54:26 | 00,042,926 | —- | M] ()
LUCOMS~1.EXE-1610F181.pf -> C:\Windows\Prefetch\LUCOMS~1.EXE -> [2008/11/27 01:03:34 | 00,055,528 | —- | M] ()
VERCLSID.EXE-28F52AD2.pf -> C:\Windows\Prefetch\VERCLSID.EXE -> [2008/12/01 10:41:54 | 00,029,376 | —- | M] ()
LUCALLBACKPROXY.EXE-29128DB6.pf -> C:\Windows\Prefetch\LUCALLBACKPROXY.EXE -> [2008/11/26 14:58:10 | 00,054,174 | —- | M] ()
AUPDATE.EXE-223E3682.pf -> C:\Windows\Prefetch\AUPDATE.EXE -> [2008/11/26 23:40:42 | 00,045,410 | —- | M] ()
< %systemroot%\system32\drivers\*.dat >
< C:\WINDOWS\Temp\bca4e2da.$$$ >
< C:\WINDOWS\Temp\ed47fa.$ >
< C:\WINDOWS\Temp\fa56d7ec.$$$ >
< C:\Windows\System32\antiwpa.dll >
< c:\windows\system32\drivers\winfilse.exe >
< c:\windows\system32\drivers\srosa2.sys >
< c:\windows\system32\drivers\srosa.sys >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services|{FBE1D620-5418-4AAE-A0F0-316D590663A1} /rs >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services|tds /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 ->  -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\\DisplayString -> NTDS -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock2 - Google Desktop Search Backup Before First Install\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 ->  -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock2 - Google Desktop Search Backup Before First Install\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\\DisplayString -> NTDS -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock2 - Google Desktop Search Backup Before Last Install\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 ->  -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock2 - Google Desktop Search Backup Before Last Install\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\\DisplayString -> NTDS -> 
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services|SROSA /rs >
< C:\Program Files\*crack*.  >
Program Files -> C:\Program Files -> [2006/08/23 02:39:18 | 00,000,000 | R–D | M]
< C:\Program Files\*keygen*.  >
Program Files -> C:\Program Files -> [2006/08/23 02:39:18 | 00,000,000 | R–D | M]
< C:\*crack*.  >
OTScanIt2 -> C: -> [2008/11/30 19:02:18 | 00,000,000 | —D | M]
< C:\*keygen*.  >
OTScanIt2 -> C: -> [2008/11/30 19:02:18 | 00,000,000 | —D | M]
< C:\*.zip >
< C:\*.rar >
< C:\*.exe >
< C:\Program Files\*.zip >
< C:\Program Files\*.rar >
< C:\Program Files\*.exe >
< C:\Program Files\Common Files\*bak*. >
Common Files -> C:\Program Files\Common Files -> [2006/08/23 02:29:22 | 00,000,000 | —D | M]
< C:\WINDOWS\SYSTEM32\*bak*. >
3 C:\WINDOWS\SYSTEM32\*.tmp files -> C:\WINDOWS\SYSTEM32\*.tmp -> 
system32 -> C:\WINDOWS\SYSTEM32 -> [2006/08/10 13:27:22 | 00,000,000 | —D | M]
CatRoot_bak -> C:\WINDOWS\SYSTEM32\CatRoot_bak -> [2008/08/04 20:45:32 | 00,000,000 | —D | M]
< C:\Program Files\*bak*. >
Program Files -> C:\Program Files -> [2006/08/23 02:39:18 | 00,000,000 | R–D | M]
< End of report >
Hello

Start OTScanIt2. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YY -> {4e5ffa00-4f7f-43c2-874d-43b84ce07067} [HKLM] -> %SystemRoot%\system32\examuy.dll [Reg Error: Value does not exist or could not be read.]
YY -> {7274C06D-C70A-4DEF-876E-BBE9F9E6E1E1} [HKLM] -> %SystemRoot%\system32\qoMffFYr.dll [Reg Error: Value does not exist or could not be read.]
YY -> {8bc485fd-d543-44f0-8a1d-9c6e90fc088f} [HKLM] -> %SystemRoot%\system32\veglaf.dll [Reg Error: Value does not exist or could not be read.]
YY -> {fba9acc7-9a24-4a1f-972c-807dde81eceb} [HKLM] -> %SystemRoot%\system32\heyehita.dll [Reg Error: Value does not exist or could not be read.]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> ShellBrowser\\"{C4069E3A-68F1-403E-B40E-20066696354B}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\"{5BED3930-2E9E-76D8-BACC-80DF2188D455}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "" -> []
YY -> "320d18a1" -> %SystemRoot%\system32\eyjeocid.DLL [rundll32.exe "C:\WINDOWS\system32\eyjeocid.dll",b]
YN -> "Alcmtr" -> %SystemRoot%\ALCMTR.EXE [ALCMTR.EXE]
YN -> "Google Desktop Search" -> ["C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup]
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls
YY -> C:\WINDOWS\system32\pazodoga.dll examuy.dll -> %SystemRoot%\system32\pazodoga.dll examuy.dll
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
YY -> C:\WINDOWS\system32\qoMffFYr -> %SystemRoot%\system32\qoMffFYr.dll
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
[Files/Folders - Created Within 90 Days]
NY -> 3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> 36 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp
NY -> examuy.dll -> %SystemRoot%\System32\examuy.dll
NY -> bsghddwu.dll -> %SystemRoot%\System32\bsghddwu.dll
NY -> ujnjymct.dll -> %SystemRoot%\System32\ujnjymct.dll
NY -> wthvwwmy.dll -> %SystemRoot%\System32\wthvwwmy.dll
NY -> veglaf.dll -> %SystemRoot%\System32\veglaf.dll
NY -> dicoejye.ini -> %SystemRoot%\System32\dicoejye.ini
NY -> eyjeocid.dll -> %SystemRoot%\System32\eyjeocid.dll
NY -> yvzcxo.dll -> %SystemRoot%\System32\yvzcxo.dll
NY -> ofmnnjam.dll -> %SystemRoot%\System32\ofmnnjam.dll
NY -> lecbjl.dll -> %SystemRoot%\System32\lecbjl.dll
NY -> lbwtoaac.dll -> %SystemRoot%\System32\lbwtoaac.dll
NY -> LopSD.exe -> %UserProfile%\Desktop\LopSD.exe
NY -> Lop SD -> %SystemDrive%\Lop SD
NY -> NTREGOPT.lnk -> %UserProfile%\Desktop\NTREGOPT.lnk
NY -> ERUNT.lnk -> %UserProfile%\Desktop\ERUNT.lnk
NY -> erunt_setup.exe -> %UserProfile%\Desktop\erunt_setup.exe
NY -> HJTInstall.exe -> %UserProfile%\Desktop\HJTInstall.exe
NY -> nphnrvrs.ini -> %SystemRoot%\System32\nphnrvrs.ini
NY -> uvegyt.dll -> %SystemRoot%\System32\uvegyt.dll
NY -> snghoxvm.dll -> %SystemRoot%\System32\snghoxvm.dll
NY -> rmirseiq.ini -> %SystemRoot%\System32\rmirseiq.ini
NY -> jxmjgz.dll -> %SystemRoot%\System32\jxmjgz.dll
NY -> sxnbkwiy.dll -> %SystemRoot%\System32\sxnbkwiy.dll
NY -> ~.exe -> %SystemRoot%\System32\~.exe
NY -> qomdne.dll -> %SystemRoot%\System32\qomdne.dll
NY -> hpuvxyhp.dll -> %SystemRoot%\System32\hpuvxyhp.dll
NY -> mfftix.dll -> %SystemRoot%\System32\mfftix.dll
NY -> aujmlggl.dll -> %SystemRoot%\System32\aujmlggl.dll
NY -> uwnnvtfw.ini -> %SystemRoot%\System32\uwnnvtfw.ini
NY -> llwdna.dll -> %SystemRoot%\System32\llwdna.dll
NY -> sisbqrnt.dll -> %SystemRoot%\System32\sisbqrnt.dll
NY -> durgjtqm.ini -> %SystemRoot%\System32\durgjtqm.ini
NY -> uqveuyne.dll -> %SystemRoot%\System32\uqveuyne.dll
NY -> azpfhp.dll -> %SystemRoot%\System32\azpfhp.dll
NY -> zjstnc.dll -> %SystemRoot%\System32\zjstnc.dll
NY -> eskmtlpl.dll -> %SystemRoot%\System32\eskmtlpl.dll
NY -> txrjmu.dll -> %SystemRoot%\System32\txrjmu.dll
NY -> thqwcnrr.dll -> %SystemRoot%\System32\thqwcnrr.dll
NY -> atrfes.dll -> %SystemRoot%\System32\atrfes.dll
NY -> qmlsajge.dll -> %SystemRoot%\System32\qmlsajge.dll
NY -> ezwjpw.dll -> %SystemRoot%\System32\ezwjpw.dll
NY -> vvufqhjy.dll -> %SystemRoot%\System32\vvufqhjy.dll
NY -> rYFffMoq.ini2 -> %SystemRoot%\System32\rYFffMoq.ini2
NY -> rYFffMoq.ini -> %SystemRoot%\System32\rYFffMoq.ini
NY -> qoMffFYr.dll -> %SystemRoot%\System32\qoMffFYr.dll
NY -> FOUND.020 -> %SystemDrive%\FOUND.020
NY -> FOUND.019 -> %SystemDrive%\FOUND.019
NY -> FOUND.015 -> %SystemDrive%\FOUND.015
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.
Here's the fix logfile… Process Explorer.EXE killed successfully! [Registry - Safe List] Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e5ffa00-4f7f-43c2-874d-43b84ce07067}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4e5ffa00-4f7f-43c2-874d-43b84ce07067}\ not found. File C:\WINDOWS\system32\examuy.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7274C06D-C70A-4DEF-876E-BBE9F9E6E1E1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7274C06D-C70A-4DEF-876E-BBE9F9E6E1E1}\ not found. File C:\WINDOWS\system32\qoMffFYr.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8bc485fd-d543-44f0-8a1d-9c6e90fc088f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8bc485fd-d543-44f0-8a1d-9c6e90fc088f}\ not found. File C:\WINDOWS\system32\veglaf.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fba9acc7-9a24-4a1f-972c-807dde81eceb}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fba9acc7-9a24-4a1f-972c-807dde81eceb}\ deleted successfully. File C:\WINDOWS\system32\heyehita.dll not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5BED3930-2E9E-76D8-BACC-80DF2188D455} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\320d18a1 not found. File C:\WINDOWS\system32\eyjeocid.DLL not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Alcmtr not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Google Desktop Search not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\WINDOWS\system32\pazodoga.dll examuy.dll scheduled to be deleted on reboot. File C:\WINDOWS\system32\pazodoga.dll examuy.dll not found. Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\qoMffFYr scheduled to be deleted on reboot. File C:\WINDOWS\system32\qoMffFYr.dll not found. [Files/Folders - Created Within 90 Days] File C:\WINDOWS\System32\examuy.dll not found! File C:\WINDOWS\System32\bsghddwu.dll not found! File C:\WINDOWS\System32\ujnjymct.dll not found! File C:\WINDOWS\System32\wthvwwmy.dll not found! File C:\WINDOWS\System32\veglaf.dll not found! File C:\WINDOWS\System32\dicoejye.ini not found! File C:\WINDOWS\System32\eyjeocid.dll not found! File C:\WINDOWS\System32\yvzcxo.dll not found! File C:\WINDOWS\System32\ofmnnjam.dll not found! File C:\WINDOWS\System32\lecbjl.dll not found! File C:\WINDOWS\System32\lbwtoaac.dll not found! File C:\Documents and Settings\Maryann\Desktop\LopSD.exe not found! File C:\Lop SD not found! File C:\Documents and Settings\Maryann\Desktop\NTREGOPT.lnk not found! File C:\Documents and Settings\Maryann\Desktop\ERUNT.lnk not found! File C:\Documents and Settings\Maryann\Desktop\erunt_setup.exe not found! File C:\Documents and Settings\Maryann\Desktop\HJTInstall.exe not found! File C:\WINDOWS\System32\nphnrvrs.ini not found! File C:\WINDOWS\System32\uvegyt.dll not found! File C:\WINDOWS\System32\snghoxvm.dll not found! File C:\WINDOWS\System32\rmirseiq.ini not found! File C:\WINDOWS\System32\jxmjgz.dll not found! File C:\WINDOWS\System32\sxnbkwiy.dll not found! File C:\WINDOWS\System32\~.exe not found! File C:\WINDOWS\System32\qomdne.dll not found! File C:\WINDOWS\System32\hpuvxyhp.dll not found! File C:\WINDOWS\System32\mfftix.dll not found! File C:\WINDOWS\System32\aujmlggl.dll not found! File C:\WINDOWS\System32\uwnnvtfw.ini not found! File C:\WINDOWS\System32\llwdna.dll not found! File C:\WINDOWS\System32\sisbqrnt.dll not found! File C:\WINDOWS\System32\durgjtqm.ini not found! File C:\WINDOWS\System32\uqveuyne.dll not found! File C:\WINDOWS\System32\azpfhp.dll not found! File C:\WINDOWS\System32\zjstnc.dll not found! File C:\WINDOWS\System32\eskmtlpl.dll not found! File C:\WINDOWS\System32\txrjmu.dll not found! File C:\WINDOWS\System32\thqwcnrr.dll not found! File C:\WINDOWS\System32\atrfes.dll not found! File C:\WINDOWS\System32\qmlsajge.dll not found! DllUnregisterServer procedure not found in C:\WINDOWS\System32\ezwjpw.dll C:\WINDOWS\System32\ezwjpw.dll NOT unregistered. C:\WINDOWS\System32\ezwjpw.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\vvufqhjy.dll C:\WINDOWS\System32\vvufqhjy.dll NOT unregistered. C:\WINDOWS\System32\vvufqhjy.dll moved successfully. C:\WINDOWS\System32\rYFffMoq.ini2 moved successfully. C:\WINDOWS\System32\rYFffMoq.ini moved successfully. File C:\WINDOWS\System32\qoMffFYr.dll not found! C:\FOUND.020 folder moved successfully. C:\FOUND.019 folder moved successfully. C:\FOUND.015 folder moved successfully. [Empty Temp Folders] File delete failed. C:\Documents and Settings\Maryann\Local Settings\Temp\RtkBtMnt.exe scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Maryann\Local Settings\Temp\~DFB050.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Maryann\Local Settings\Temp\fb_712.lck scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\CLML_AGENT_LOG1.txt scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\mcmsc_BlUXx4N0cQLpxmn scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_klukMM83C39ADdR scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\WFV1.tmp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\fb_1232.lck scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. RecycleBin -> emptied. Explorer started successfully < End of fix log > OTScanIt2 by OldTimer - Version 1.0.2.0 fix logfile created on 12012008_215225 Files moved on Reboot… C:\Documents and Settings\Maryann\Local Settings\Temp\RtkBtMnt.exe moved successfully. C:\Documents and Settings\Maryann\Local Settings\Temp\~DFB050.tmp moved successfully. File C:\Documents and Settings\Maryann\Local Settings\Temp\fb_712.lck not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\CLML_AGENT_LOG1.txt scheduled to be moved on reboot. File C:\WINDOWS\temp\mcmsc_BlUXx4N0cQLpxmn not found! File C:\WINDOWS\temp\sqlite_klukMM83C39ADdR not found! File move failed. C:\WINDOWS\temp\WFV1.tmp scheduled to be moved on reboot. File C:\WINDOWS\temp\fb_1232.lck not found! Registry entries deleted on Reboot… Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\WINDOWS\system32\pazodoga.dll examuy.dll scheduled to be deleted on reboot. Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\qoMffFYr scheduled to be deleted on reboot.
Hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Ok, here we go….

MBAM report:

Malwarebytes' Anti-Malware 1.30
Database version: 1450
Windows 5.1.2600 Service Pack 2

12/2/2008 8:26:06 PM
mbam-log-2008-12-02 (20-26-06).txt

Scan type: Quick Scan
Objects scanned: 68197
Time elapsed: 4 minute(s), 0 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 17
Registry Values Infected: 4
Registry Data Items Infected: 2
Folders Infected: 17
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\WINDOWS\system32\funugipi.dll (Trojan.Vundo) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fba9acc7-9a24-4a1f-972c-807dde81eceb} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{fba9acc7-9a24-4a1f-972c-807dde81eceb} (Trojan.BHO.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{62960d20-6d0d-1ab4-4bf1-95b0b5b8783a} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{73259091-9574-4ed8-a40f-7f65afc28634} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm313e2b3d (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rirawapola (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: c:\windows\system32\funugipi.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: system32\funugipi.dll -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\3.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\4.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\5.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\6.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\7.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\SrchAstt (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\SrchAstt\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\SrchAstt\2.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\SrchAstt\3.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\SrchAstt\4.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\SrchAstt\5.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\SrchAstt\6.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\SrchAstt\7.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\roloropo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\oporolor.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kabujupe.dll (Trojan.BHO.H) -> Delete on reboot.
c:\WINDOWS\system32\funugipi.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\pofokago.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\kusitozo.dll (Trojan.Agent) -> Delete on reboot.


Kaspersky report:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, December 2, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, December 02, 2008 20:35:17
Records in database: 1432531
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 82245
Threat name: 6
Infected objects: 7
Suspicious objects: 0
Duration of the scan: 01:11:50


File name / Threat name / Threats count
C:\System Volume Information\_restore{81E770B2-87AC-4F99-8343-5B3206A00881}\RP228\A0154375.ocx Infected: not-a-virus:AdWare.Win32.Coupons.h 1
C:\System Volume Information\_restore{81E770B2-87AC-4F99-8343-5B3206A00881}\RP228\A0154410.exe Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.bc 1
C:\System Volume Information\_restore{81E770B2-87AC-4F99-8343-5B3206A00881}\RP229\A0157379.dll Infected: not-a-virus:AdWare.Win32.Coupons 1
C:\System Volume Information\_restore{81E770B2-87AC-4F99-8343-5B3206A00881}\RP231\A0159526.dll Infected: Trojan.Win32.Monder.aann 1
C:\System Volume Information\_restore{81E770B2-87AC-4F99-8343-5B3206A00881}\RP234\A0162343.scr Infected: not-a-virus:WebToolbar.Win32.MyWebSearch 1
C:\_OTScanIt\MovedFiles\12012008_214500\C_WINDOWS\System32\llwdna.dll Infected: Backdoor.Win32.Aimbot.jn 1
C:\_OTScanIt\MovedFiles\12012008_214500\C_WINDOWS\System32\sisbqrnt.dll Infected: Backdoor.Win32.Aimbot.jn 1

The selected area was scanned.
Hello

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Thanks. Here are the two log files…. FYI (I don't know if this matters or not) but Internet Explorer is giving me error reports when I try to open it. I'm having to use Firefox for my browser now. When I ran the ATF Cleaner the other day, I did it for both IE and Firefox knowing that I occasionally use Firefox.

Log:

Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-12-03 20:20:28
Microsoft Windows XP Professional Service Pack 2
System drive C: has 32 GB (44%) free of 74 GB
Total RAM: 2046 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:20:35 PM, on 12/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\admtray.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\DOCUME~1\Maryann\LOCALS~1\Temp\RtkBtMnt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Documents and Settings\Maryann\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Maryann.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: (no name) - {C5828AA8-4FCA-44C8-984C-D444BE6B1318} - C:\WINDOWS\system32\qoMffFYr.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: (no name) - {fba9acc7-9a24-4a1f-972c-807dde81eceb} - C:\WINDOWS\system32\ziniguhe.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Acer\OrbiCam\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O5 "LPT1:" /M "Stylus Photo R340"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [rirawapola] Rundll32.exe "C:\WINDOWS\system32\hepoyaba.dll",s
O4 - HKLM\..\Run: [CPM313e2b3d] Rundll32.exe "c:\windows\system32\bajibuli.dll",a
O4 - HKLM\..\Run: [320d18a1] rundll32.exe "C:\WINDOWS\system32\jikotato.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jd…ows-i586-jc.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL c:\windows\system32\bajibuli.dll,C:\WINDOWS\system32\naruhoku.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bajibuli.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bajibuli.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe (file missing)
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Maryann/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg

–
End of file - 15661 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\McQcTask.job
C:\WINDOWS\tasks\McDefragTask.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2007-09-05 816400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-CEC4-75A487FD6484}]
MYPOINTS - C:\PROGRA~1\mypoints\mypoints.dll [2008-10-29 1909248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar3.dll [2007-01-19 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2008-10-30 737776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C5828AA8-4FCA-44C8-984C-D444BE6B1318}]
C:\WINDOWS\system32\qoMffFYr.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
EpsonToolBandKicker Class - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fba9acc7-9a24-4a1f-972c-807dde81eceb}]
C:\WINDOWS\system32\ziniguhe.dll [2008-09-03 64565]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\WINDOWS\system32\eDStoolbar.dll [2006-02-22 106496]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2007-09-05 816400]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar3.dll [2007-01-19 2403392]
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
{A057A204-BACC-4D26-CEC4-75A487FD6484} - MYPOINTS - C:\PROGRA~1\mypoints\mypoints.dll [2008-10-29 1909248]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe [2006-03-23 94208]
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe [2006-03-23 77824]
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe [2006-03-23 118784]
"LaunchApp"=Alaunch []
"AzMixerSel"=C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [2005-12-21 53248]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-03-03 761946]
"ntiMUI"=C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe [2006-05-15 45056]
"ADMTray.exe"=C:\Acer\Empowering Technology\admtray.exe [2005-10-24 2462208]
"eDataSecurity Loader"=C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe [2005-12-27 69632]
"BluetoothAuthenticationAgent"=C:\WINDOWS\system32\bthprops.cpl [2004-08-04 110592]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-04 59392]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-07-20 7581696]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-07-20 86016]
"PCMService"=C:\Program Files\Acer\Acer Arcade\PCMService.exe [2006-08-09 151552]
"ePower_DMC"=C:\Acer\Empowering Technology\ePower\ePower_DMC.exe [2006-08-10 352256]
"Acer ePower Management"=C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe [2006-05-22 3080704]
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2006-07-20 593920]
"eRecoveryService"=C:\Acer\Empowering Technology\eRecovery\Monitor.exe [2006-01-24 397312]
"LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2006-06-23 225280]
"LogitechCameraAssistant"=C:\Program Files\Acer\OrbiCam\CameraAssistant.exe [2006-06-26 331776]
"LogitechVideo[inspector]"=C:\Program Files\Acer\OrbiCam\InstallHelper.exe [2006-06-26 73728]
"LogitechCameraService(E)"=C:\WINDOWS\system32\ElkCtrl.exe [2004-11-01 262144]
"WinVNC"=C:\Program Files\TightVNC\WinVNC.exe -servicehelper []
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"EPSON Stylus Photo R340 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE [2005-04-26 98304]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-03-21 16126464]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2007-08-24 33648]
"Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe [2007-03-09 63712]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-09-03 111936]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2007-11-01 582992]
"McAfee Backup"=C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe [2007-01-16 4838952]
"MBkLogOnHook"=C:\Program Files\McAfee\MBK\LogOnHook.exe [2007-01-08 20480]
"rirawapola"=C:\WINDOWS\system32\hepoyaba.dll [2008-09-03 64565]
"CPM313e2b3d"=c:\windows\system32\bajibuli.dll [2008-12-03 94261]
"320d18a1"=C:\WINDOWS\system32\jikotato.dll [2008-12-03 85557]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-06-26 68856]
"updateMgr"=c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe

C:\Documents and Settings\Maryann\Start Menu\Programs\Startup
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL c:\windows\system32\bajibuli.dll,C:\WINDOWS\system32\naruhoku.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2006-03-23 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bajibuli.dll [2008-12-03 94261]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bajibuli.dll [2008-12-03 94261]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\WINDOWS\system32\naruhoku.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoBandCustomize"=0
"NoMovingBands"=0
"NoCloseDragDropBands"=0
"NoActiveDesktop"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Acer\Acer Arcade\PCMService.exe"="C:\Program Files\Acer\Acer Arcade\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\WINDOWS\Explorer.EXE"="C:\WINDOWS\Explorer.EXE:*:Enabled:Explorer"
"C:\WINDOWS\System32\logonui.exe"="C:\WINDOWS\System32\logonui.exe:*:Enabled:logonui"
"C:\WINDOWS\System32\WINLOGON.EXE"="C:\WINDOWS\System32\WINLOGON.EXE:*:Enabled:winlogon"
"C:\WINDOWS\System32\SERVICES.EXE"="C:\WINDOWS\System32\SERVICES.EXE:*:Enabled:services"
"C:\WINDOWS\System32\LSASS.EXE"="C:\WINDOWS\System32\LSASS.EXE:*:Enabled:lsass"
"C:\WINDOWS\System32\ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe:*:Enabled:ctfmon"
"C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe:*:Enabled:McAfeeDataBackup"
"C:\Program Files\McAfee\MBK\LogonHook.exe"="C:\Program Files\McAfee\MBK\LogonHook.exe:*:Enabled:LogOnHook"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2008-12-03 20:20:28 —-D—- C:\rsit
2008-12-03 20:10:52 —-SH—- C:\WINDOWS\system32\otatokij.ini
2008-12-02 20:20:17 —-D—- C:\Documents and Settings\Maryann\Application Data\Malwarebytes
2008-12-02 20:20:09 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-12-02 20:20:09 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-01 21:20:41 —-D—- C:\_OTScanIt
2008-11-29 19:44:00 —-D—- C:\WINDOWS\ERDNT
2008-11-29 19:43:28 —-D—- C:\Program Files\ERUNT
2008-11-29 19:32:31 —-D—- C:\Program Files\Trend Micro
2008-11-29 19:18:05 —-D—- C:\Program Files\Hijackthis
2008-11-28 11:28:01 —-D—- C:\Documents and Settings\Maryann\Application Data\McAfee
2008-11-27 01:03:27 —-D—- C:\WINDOWS\system32\appmgmt
2008-11-26 23:03:40 —-D—- C:\WINDOWS\pss
2008-11-26 15:43:10 —-A—- C:\WINDOWS\system32\dunzip32.dll
2008-11-26 15:37:50 —-D—- C:\Program Files\McAfee.com
2008-11-26 15:37:36 —-D—- C:\Program Files\Common Files\McAfee
2008-11-26 15:37:19 —-D—- C:\Program Files\McAfee
2008-11-26 15:16:45 —-D—- C:\Documents and Settings\All Users\Application Data\McAfee
2008-11-26 08:06:17 —-A—- C:\WINDOWS\system32\392edcdf-.txt
2008-11-11 23:24:17 —-HD—- C:\WINDOWS\$NtUninstallKB957097$
2008-11-11 23:24:01 —-HD—- C:\WINDOWS\$NtUninstallKB955069$

======List of files/folders modified in the last 1 months======

2008-12-03 20:10:42 —-A—- C:\WINDOWS\system32\eRLog.ini
2008-12-03 20:10:20 —-ASH—- C:\WINDOWS\system32\biwifasi.dll
2008-12-03 20:10:20 —-ASH—- C:\WINDOWS\system32\bajibuli.dll
2008-12-03 20:10:18 —-ASH—- C:\WINDOWS\system32\jikotato.dll
2008-12-03 20:09:46 —-A—- C:\WINDOWS\ModemLog_HDAUDIO Soft Data Fax Modem with SmartCP.txt
2008-12-03 07:07:16 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-12-02 07:08:12 —-ASH—- C:\WINDOWS\system32\ledanozo.dll
2008-11-11 23:24:16 —-A—- C:\WINDOWS\imsins.BAK

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2007-11-22 201320]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2007-07-13 113952]
R1 OsaFsLoc;OsaFsLoc; \??\C:\WINDOWS\system32\drivers\OsaFsLoc.sys []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-03 8832]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.9.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2006-12-26 21275]
R2 CVPNDRVA;Cisco Systems IPsec Driver; \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys []
R2 EpmPsd;Acer EPM Power Scheme Driver; \??\C:\WINDOWS\system32\drivers\epm-psd.sys []
R2 EpmShd;Acer EPM System Hardware Driver; \??\C:\WINDOWS\system32\drivers\epm-shd.sys []
R2 int15.sys;int15.sys; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys []
R2 irda;IrDA Protocol; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-03 87424]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2005-10-05 12544]
R2 osaio;osaio; \??\C:\WINDOWS\system32\drivers\osaio.sys []
R2 osanbm;osanbm; \??\C:\WINDOWS\system32\drivers\osanbm.sys []
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2005-11-28 13568]
R2 symlcbrd;symlcbrd; \??\C:\WINDOWS\system32\drivers\symlcbrd.sys []
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2005-10-31 45312]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-03 14080]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\WINDOWS\system32\DRIVERS\DKbFltr.sys [2004-12-08 16896]
R3 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2003-07-24 139604]
R3 EMSCR;EMSCR; C:\WINDOWS\system32\DRIVERS\EMS7SK.sys [2006-06-16 61056]
R3 ESDCR;ESDCR; C:\WINDOWS\system32\DRIVERS\ESD7SK.sys [2006-06-16 40064]
R3 ESMCR;ESMCR; C:\WINDOWS\system32\DRIVERS\ESM7SK.sys [2006-06-16 74752]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-10-18 998656]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2005-10-24 218496]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-03-26 4395008]
R3 lv321av;Logitech USB PC Camera (VC0321); C:\WINDOWS\system32\DRIVERS\lv321av.sys [2006-06-19 1097728]
R3 lvmvdrv;Logitech Machine Vision Engine Loader; \??\C:\WINDOWS\system32\drivers\lvmvdrv.sys []
R3 LVPrcMon;Logitech LVPrcMon Driver; \??\C:\WINDOWS\system32\drivers\LVPrcMon.sys []
R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2006-06-19 39424]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2007-11-22 79304]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2007-11-22 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2007-12-02 40488]
R3 NdisFilt;OSA NdisFilter Protocol; C:\WINDOWS\System32\Drivers\NdisFilt.sys [2005-09-13 4392]
R3 NTIDrvr;Upper Class Filter Driver; C:\WINDOWS\system32\DRIVERS\NTIDrvr.sys [2006-08-23 6144]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-07-20 3685152]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-04 67584]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2006-03-03 192672]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2006-04-19 30080]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-04-19 20608]
R3 w39n51;Intel® PRO/Wireless 3945ABG Adapter Driver; C:\WINDOWS\system32\DRIVERS\w39n51.sys [2006-04-03 1429632]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-10-18 721280]
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
S3 BthEnum;Bluetooth Request Block Driver; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2004-08-04 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2004-08-04 100992]
S3 BTHPORT;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-13 272128]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2004-08-04 18944]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 CVirtA;Cisco Systems VPN Adapter; C:\WINDOWS\system32\DRIVERS\CVirtA.sys [2003-05-01 5220]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-04 9600]
S3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2006-03-23 1166972]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2007-11-22 33832]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NETMNT;Acer NetMonitor Protocol; C:\WINDOWS\system32\DRIVERS\NETMNT.sys [2005-05-02 9600]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2006-01-23 32512]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2004-08-04 59648]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 SMCIRDA;SMSC IrCC Miniport Device Driver; C:\WINDOWS\system32\DRIVERS\smcirda.sys [2005-10-31 46080]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 vsdatant;vsdatant; \??\C:\WINDOWS\system32\vsdatant.sys []
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
R2 AWService;AdminWorks Agent X6; C:\Acer\Empowering Technology\admServ.exe [2005-10-24 1314816]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 CLCapSvc;CyberLink Background Capture Service (CBCS); C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe [2006-08-09 254050]
R2 CLSched;CyberLink Task Scheduler (CTS); C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe [2006-08-09 114784]
R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [2004-12-06 1437712]
R2 CyberLink Media Library Service;CyberLink Media Library Service; C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe [2006-08-09 61440]
R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2005-11-28 114753]
R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-05-18 49152]
R2 LVPrcSrv;Logitech Process Monitor; c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe [2006-06-23 86016]
R2 MBackMonitor;MBackMonitor; C:\Program Files\McAfee\MBK\MBackMonitor.exe [2007-01-16 71208]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-01-09 767976]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-01-25 2458128]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2007-08-15 359248]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2007-07-24 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2007-07-18 856864]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-07-20 143426]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2005-11-28 217164]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2005-01-21 143360]
R2 S24EventMonitor;Intel® PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2005-11-28 540745]
R2 Symantec Core LC;Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [2008-06-11 1251720]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2007-12-05 695624]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-04 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-02 29744]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-31 138168]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2007-11-07 378184]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2006-01-23 86016]
S3 winvnc;VNC Server; C:\Program Files\TightVNC\WinVNC.exe -service []

—————–EOF—————–


Info:

info.txt logfile of random's system information tool 1.04 2008-12-03 20:20:38

======Uninstall list======

–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Acer Inc.\Acer English Online Help Creator\Uninst.isu"
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{13E613EF-BB55-11D9-9D77-000129760D75}\setup.exe" -uninstall
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC4F90EC-B1DA-11D9-9D77-000129760D75}\setup.exe" -uninstall
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-00BA-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0114-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
Acer Arcade–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\setup.exe" -uninstall
Acer eDataSecurity Management 1.00.26–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E431C518-2EE2-471E-9234-BE995C36D513}\setup.exe" -l0x9 -removeonly
Acer eLock Management–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{6CA897D0-67F5-4F75-8261-DC8BFCA6DA42}
Acer Empowering Technology framework–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{15B70821-7893-4607-805A-BB80F3EA8279}
Acer eNet Management–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C06554A1-2C1E-4D20-B613-EE62C79927CC}\Setup.exe" -l0x9
Acer ePerformance Management–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{DEE08946-40F0-4890-853E-60A6C3306041}
Acer ePower Management–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{58E5844B-7CE2-413D-83D1-99294BF6C74F}\Setup.exe" -l0x9
Acer ePresentation Management–>C:\WINDOWS\UnInst32.exe AcerePrj.UNI
Acer eSettings Management–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{E38BC648-883B-4EE5-966C-94C4B7AB3E0B}
Acer GridVista–>C:\WINDOWS\UnInst32.exe GridV.UNI
Acer OrbiCam Driver–>"C:\Program Files\Common Files\Acer\OrbiCam\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT -l0409
Acer OrbiCam Software–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{76AC1AEB-1167-4ABC-8861-4E58392A5B7F}\setup.exe" -l0x9
Acer Screensaver–>MsiExec.exe /I{D458BBDC-0363-42E0-8FF9-4736E3CB3CA2}
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)–>MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe Flash Player 10 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.2–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe® Photoshop® Album Starter Edition 3.2–>MsiExec.exe /I{A654A805-41D9-40C7-AA46-4AF04F044D61}
Apple Mobile Device Support–>MsiExec.exe /I{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}
Apple Software Update–>MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
Bonjour–>MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
Camera Driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D1B3874F-3057-11D6-B2EA-0050BA18806B}\Setup.exe"
Citrix Web Client–>C:\WINDOWS\system32\ctxsetup.exe /uninst C:\PROGRA~1\Citrix\icaweb32\uninst.inf
EPSON Printer Software–>C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON Web-To-Page–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\Setup.exe" -l0x9 -anything
ERUNT 1.1j–>"C:\Program Files\ERUNT\unins000.exe"
Galapago–>"C:\Program Files\Oberon Media\Galapago\unins000.exe"
Google Desktop–>C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Earth–>MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
Google SketchUp 6–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98736A65-3C79-49EC-B7E9-A3C77774B0E6}\setup.exe" -l0x9 -removeonly
Google SketchUp 6–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}\setup.exe" -l0x9 -removeonly
Google Toolbar for Internet Explorer–>regsvr32 /u /s "c:\program files\google\googletoolbar3.dll"
HDAUDIO Soft Data Fax Modem with SmartCP–>C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_1025007F\HXFSETUP.EXE -U -IWstAzlK.inf
High Definition Audio Driver Package - KB888111–>"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)–>"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows XP (KB896256)–>"C:\WINDOWS\$NtUninstallKB896256$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB909667)–>"C:\WINDOWS\$NtUninstallKB909667$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB914440)–>"C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB915865)–>"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB918005)–>"C:\WINDOWS\$NtUninstallKB918005$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB935448)–>"C:\WINDOWS\$NtUninstallKB935448$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Intel® PROSet/Wireless Software–>C:\WINDOWS\Installer\iProInst.exe
InterActual Player–>C:\Program Files\InterActual\InterActual Player\inuninst.exe
iTunes–>MsiExec.exe /I{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}
J2SE Runtime Environment 5.0 Update 11–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
Java™ 6 Update 2–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Java™ SE Runtime Environment 6 Update 1–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
Launch Manager–>C:\WINDOWS\UnInst32.exe LManager.UNI
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee SecurityCenter–>C:\Program Files\McAfee\MSC\mcuninst.exe
mCore–>MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Access MUI (English) 2007–>MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007–>MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007–>MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007–>MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007–>MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007–>MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007–>MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007–>MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007–>MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007–>MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007–>MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007–>MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007–>MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007–>MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007–>MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007–>MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Ultimate 2007–>"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ULTIMATER /dll OSETUP.DLL
Microsoft Office Ultimate 2007–>MsiExec.exe /X{91120000-002E-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007–>MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Silverlight–>MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
mMHouse–>MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
MobileMe Control Panel–>MsiExec.exe /I{6DA9102E-199F-43A0-A36B-6EF48081A658}
Mozilla Firefox (2.0.0.4)–>C:\Program Files\Mozilla Firefox\uninstall\helper.exe
mPfMgr–>MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
mProSafe–>MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
MSXML 4.0 SP2 (KB927978)–>MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
mWlsSafe–>MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
mXML–>MsiExec.exe /I{9CC89556-3578-48DD-8408-04E66EBEF401}
MyPoints Toolbar–>C:\Program Files\mypoints\uninstall.exe
Netflix Movie Viewer–>MsiExec.exe /X{178FDCAC-0CC9-433B-8E1C-96251615DCBE}
NTI Backup NOW! 4.5–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B06B842F-2450-494F-BBDE-217CDC151A37}\setup.exe" -l0x9 -uninst -removeonly
NTI CD & DVD-Maker–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1033 CDM7
NVIDIA Drivers–>C:\WINDOWS\system32\nvudisp.exe UninstallGUI
OpenOffice.org Installer 1.0–>MsiExec.exe /X{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}
PowerProducer–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
PuTTY version 0.60–>"C:\Program Files\PuTTY\unins000.exe"
QuarkXPress 6.5–>MsiExec.exe /I{FF0B0792-F6E7-4627-B820-EA50617E223B}
QuickTime–>MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
Realtek High Definition Audio Driver–>RtlUpd.exe -r -m
Safari–>MsiExec.exe /I{0AFC9710-5DD6-4C6A-BA52-91AE992B2C9D}
Security Update for 2007 Microsoft Office System (KB951550)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
Security Update for 2007 Microsoft Office System (KB951944)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
Security Update for 2007 Microsoft Office System (KB955936)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {1D94099C-2BBA-440E-BD5E-093BBDF8F028}
Security Update for CAPICOM (KB931906)–>MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)–>MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Microsoft Office Excel 2007 (KB955470)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {6E8637D8-10D6-4568-AA06-E2706F31685E}
Security Update for Microsoft Office OneNote 2007 (KB950130)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
Security Update for Microsoft Office PowerPoint 2007 (KB951338)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
Security Update for Microsoft Office Publisher 2007 (KB950114)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
Security Update for Microsoft Office system 2007 (KB951808)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}
Security Update for Microsoft Office system 2007 (KB954326)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
Security Update for Microsoft Office Word 2007 (KB950113)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}
Security Update for Visio 2007 (KB947590)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
Security Update for Windows Internet Explorer 7 (KB928090)–>"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB929969)–>"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB931768)–>"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB933566)–>"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)–>"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)–>"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)–>"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)–>"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)–>"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB911564)–>"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
Security Update for Windows Media Player 6.4 (KB925398)–>"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB917734)–>"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB893756)–>"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896358)–>"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896423)–>"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896424)–>"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896428)–>"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899587)–>"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899591)–>"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
Security Update for Windows XP (KB900725)–>"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901017)–>"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901190)–>"C:\WINDOWS\$NtUninstallKB901190$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901214)–>"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
Security Update for Windows XP (KB902400)–>"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Security Update for Windows XP (KB904706)–>"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905414)–>"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905749)–>"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB908519)–>"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911562)–>"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911927)–>"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
Security Update for Windows XP (KB912919)–>"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
Security Update for Windows XP (KB913580)–>"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914388)–>"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914389)–>"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917344)–>"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917422)–>"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
Security Update for Windows XP (KB917953)–>"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918118)–>"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918439)–>"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
Security Update for Windows XP (KB919007)–>"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920213)–>"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920670)–>"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920683)–>"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920685)–>"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
Security Update for Windows XP (KB921398)–>"C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
Security Update for Windows XP (KB921503)–>"C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
Security Update for Windows XP (KB922616)–>"C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
Security Update for Windows XP (KB922819)–>"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923191)–>"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923414)–>"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923689)–>"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923694)–>"C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923980)–>"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924191)–>"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924270)–>"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924496)–>"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924667)–>"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
Security Update for Windows XP (KB925454)–>"C:\WINDOWS\$NtUninstallKB925454$\spuninst\spuninst.exe"
Security Update for Windows XP (KB925486)–>"C:\WINDOWS\$NtUninstallKB925486$\spuninst\spuninst.exe"
Security Update for Windows XP (KB925902)–>"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926255)–>"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926436)–>"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927779)–>"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927802)–>"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928255)–>"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928843)–>"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
Security Update for Windows XP (KB929123)–>"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
Security Update for Windows XP (KB930178)–>"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931261)–>"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931784)–>"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
Security Update for Windows XP (KB932168)–>"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
Security Update for Windows XP (KB933729)–>"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935839)–>"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935840)–>"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
Security Update for Windows XP (KB936021)–>"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
Security Update for Windows XP (KB937894)–>"C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938829)–>"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941202)–>"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941568)–>"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941644)–>"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941693)–>"C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943055)–>"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943460)–>"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943485)–>"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944653)–>"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
Security Update for Windows XP (KB945553)–>"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946026)–>"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB948590)–>"C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
Security Update for Windows XP (KB948881)–>"C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950749)–>"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)–>"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Symantec KB-DocID:2003093015493306–>MsiExec.exe /I{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}
Synaptics Pointing Device Driver–>rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Update for Microsoft Office Outlook 2007 (KB952142)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
Update for Office 2007 (KB946691)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Outlook 2007 Junk Email Filter (kb957829)–>msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {07A1F6B6-4F1C-418C-A605-755A121C4A16}
Update for Windows XP (KB894391)–>"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
Update for Windows XP (KB898461)–>"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB900485)–>"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
Update for Windows XP (KB904942)–>"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
Update for Windows XP (KB908531)–>"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
Update for Windows XP (KB910437)–>"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
Update for Windows XP (KB911280)–>"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
Update for Windows XP (KB912945)–>"C:\WINDOWS\$NtUninstallKB912945$\spuninst\spuninst.exe"
Update for Windows XP (KB916595)–>"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
Update for Windows XP (KB920872)–>"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
Update for Windows XP (KB922582)–>"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
Update for Windows XP (KB927891)–>"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
Update for Windows XP (KB929338)–>"C:\WINDOWS\$NtUninstallKB929338$\spuninst\spuninst.exe"
Update for Windows XP (KB930916)–>"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
Update for Windows XP (KB931836)–>"C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe"
Update for Windows XP (KB932823-v3)–>"C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
Update for Windows XP (KB933360)–>"C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
Update for Windows XP (KB936357)–>"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
Update for Windows XP (KB938828)–>"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
Update for Windows XP (KB942763)–>"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Virtual Earth 3D (Beta)–>MsiExec.exe /I{3CCB26F5-E2A7-4C91-8340-9149D7B7C2BE}
VPN Client–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5624C000-B109-11D4-9DB4-00E0290FCAC5}\Setup.exe" -l0x9 VpnUninstall
Windows Imaging Component–>"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Installer 3.1 (KB893803)–>"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Internet Explorer 7–>"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows XP Hotfix - KB873339–>C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Windows XP Hotfix - KB885835–>C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Windows XP Hotfix - KB885836–>C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Windows XP Hotfix - KB885855–>C:\WINDOWS\$NtUninstallKB885855$\spuninst\spuninst.exe
Windows XP Hotfix - KB886185–>C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Windows XP Hotfix - KB887472–>C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
Windows XP Hotfix - KB888302–>C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Windows XP Hotfix - KB890859–>"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Windows XP Hotfix - KB891781–>C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
Yahoo! Install Manager–>C:\WINDOWS\system32\regsvr32 /u C:\WINDOWS\cache\YINSTH~1.DLL
Yahoo! Toolbar–>C:\PROGRA~1\Yahoo!\Common\unyt.exe

======Security center information======

AV: McAfee VirusScan
FW: McAfee Personal Firewall (disabled)

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Intel\Wireless\Bin\;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=0f06
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

—————–EOF—————–

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI