OTListIt logfile created on: 2/5/2009 12:15:42 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\Margaret Kenney\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
510.00 Mb Total Physical Memory | 329.18 Mb Available Physical Memory | 64.55% Memory free
1.22 Gb Paging File | 1.10 Gb Available in Paging File | 90.40% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 18.04 Gb Free Space | 24.22% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TOM-SERVO
Current User Name: Margaret Kenney
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrlS.exe (Panda Software International)
C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe (Panda Software International)
C:\WINDOWS\SYSTEM32\hkcmd.exe (Intel Corporation)
C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe (Sonic Solutions)
C:\Program Files\Dell\Media Experience\PCMService.exe (CyberLink Corp.)
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe (Dell Computer Corporation)
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe (Dell Computer Corporation)
C:\Documents and Settings\Margaret Kenney\Desktop\OTListIt22.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (6to4 [Auto | Running]) – C:\WINDOWS\SYSTEM32\6to4svc.dll (Microsoft Corporation)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (DM1Service [Auto | Stopped]) – C:\Program Files\Olympus\DeviceDetector\DM1Service.exe (OLYMPUS OPTICAL CO.,LTD)
SRV - (DomainService [Auto | Stopped]) – File not found
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (LexBceS [Auto | Stopped]) – C:\WINDOWS\SYSTEM32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (Panda Software Controller [Auto | Running]) – C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrlS.exe (Panda Software International)
SRV - (PavPrSrv [Auto | Stopped]) – C:\Program Files\Common Files\Panda Software\PavShld\PavPrSrv.exe (Panda Software)
SRV - (PAVSRV [Auto | Stopped]) – C:\Program Files\Panda Security\Panda Antivirus 2008\PAVSRV51.EXE (Panda Software International)
SRV - (PSIMSVC [Auto | Running]) – C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe (Panda Software International)
========== Driver Services (SafeList) ==========
DRV - (aeaudio [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\aeaudio.sys (Andrea Electronics Corporation)
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ALIIDE.SYS (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ASC.SYS (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ASC3550.SYS (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\CMDIDE.SYS (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\DAC2W2K.SYS (Mylex Corporation)
DRV - (drvmcdb [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm [Auto | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
DRV - (EL90XBC [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
DRV - (FileDisk [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\filedisk.sys (iolo technologies, LLC (based on original work by Bo Brantén))
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HSFHWBS2 [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (i81x [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (iAimFP3 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimFP4 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimTV0 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimTV1 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV3 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV4 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\MRAID35X.SYS (American Megatrends Inc.)
DRV - (nm [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\nmnt.sys (Microsoft Corporation)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (PavProc [Auto | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\PavProc.sys (Panda Software International)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys (Padus, Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\pxhelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\QL1080.SYS (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\QL12160.SYS (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\QL1280.SYS (QLogic Corporation)
DRV - (SCDEmu [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SECDRV.SYS ()
DRV - (ShldDrv [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ShlDrv51.sys (Panda Software)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (smwdm [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\smwdm.sys (Analog Devices, Inc.)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SONYPVU1.SYS (Sony Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SPARROW.SYS (Adaptec, Inc.)
DRV - (sscdbhk5 [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYMC810.SYS (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYMC8XX.SYS (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYM_HI.SYS (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYM_U3.SYS (LSI Logic)
DRV - (Tcpip6 [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys (Microsoft Corporation)
DRV - (tfsnboio [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsncofs [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsndrct [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
DRV - (tfsnifs [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsnopio [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsnudf [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnudfa [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tunmp [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\tunmp.sys (Microsoft Corporation)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ULTRA.SYS (Promise Technology, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (WS2IFSL [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS (Microsoft Corporation)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ialmkchw.sys (Intel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://login.yahoo.com/config/mail?.intl=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (736 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {4140C4CD-7657-359C-5711-5300CAC78BBA} - C:\WINDOWS\SYSTEM32\afrmxxot.dll ()
O2 - BHO: (no name) - {42F2CE47-25D8-6E4C-8839-51C07758D1EC} - C:\WINDOWS\SYSTEM32\xielkrog.dll ()
O2 - BHO: (no name) - {4CB8F4B4-5F66-4D9E-BC3B-184596A58824} - C:\WINDOWS\SYSTEM32\jkkljgg.dll ()
O2 - BHO: (Gordon tool) - {4D8F81B2-80C9-45B1-9F03-67B2B0D2320B} - C:\WINDOWS\SYSTEM32\gjavn.dll ()
O2 - BHO: () - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (OIN Analytics) - {6B221E01-F517-4959-8C41-81948E7F2F17} - C:\Program Files\OINAnalytics\OINAnalytics2.dll ()
O2 - BHO: (bannerstyle browser optimizer) - {81aa3b3b-45b7-e428-ed82-b7a6ef965b39} - C:\WINDOWS\SYSTEM32\rmipphlowloxuhjx.dll ( )
O2 - BHO: (no name) - {887EA37D-2348-412F-A011-37DDF88F66CE} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {89d75840-a65d-45da-bbe5-7155b13fd3d0} - C:\WINDOWS\SYSTEM32\phwavs.dll ()
O2 - BHO: (DrFlex IE Helper) - {8EEB2711-9D21-4f9c-99A1-B7FC5A8CA56A} - C:\Program Files\QdrDrive\QdrDrive20.dll ()
O2 - BHO: (no name) - {93A6AE09-42F0-4B38-8198-7972AFE25E88} - C:\WINDOWS\SYSTEM32\ssqrq.dll ()
O2 - BHO: (no name) - {A6FE4E63-F2A1-463B-92CF-7F6061A19B39} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\SYSTEM32\lwvbealv.dll ()
O2 - BHO: (no name) - SOFTWARE - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKLM\..\Toolbar: (Security Toolbar) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\SYSTEM32\lwvbealv.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\SYSTEM32\lwvbealv.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [{a6755f01-71b0-81c6-cc33-9d19a7fd3a8b}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\rmipphlowloxuhjx.dll" DllStart ( )
O4 - HKLM..\Run: [0012eed0] rundll32.exe "C:\WINDOWS\system32\pprlfqly.dll",b ()
O4 - HKLM..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE" /s (Panda Software International)
O4 - HKLM..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" (Dell Computer Corporation)
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [LanzarL2007] "C:\DOCUME~1\AARONK~1\LOCALS~1\Temp\{B5CCD7BD-0F24-4DD4-9125-E2A475002832}\{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}\..\..\L2007tmp\Setup.exe" /SETUP:"/l0x0009" File not found
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKCU..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl File not found
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [Sonic RecordNow!] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CallWave.lnk = C:\Program Files\CallWave\IAM.exe (CallWave, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key does not exist or could not be opened. File not found
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_05)
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (phwavs.dll) - C:\WINDOWS\SYSTEM32\phwavs.dll ()
O20 - Winlogon\Notify\avldr: DllName - avldr.dll - C:\WINDOWS\SYSTEM32\avldr.dll (Panda Software International)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\SYSTEM32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\jkkljgg: DllName - jkkljgg.dll - C:\WINDOWS\SYSTEM32\jkkljgg.dll ()
O20 - Winlogon\Notify\lwvbealv: DllName - lwvbealv.dll - C:\WINDOWS\SYSTEM32\lwvbealv.dll ()
O20 - Winlogon\Notify\mllmm: DllName - Reg Error: Value DLLName does not exist or could not be read. - File not found
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {4CB8F4B4-5F66-4D9E-BC3B-184596A58824} - C:\WINDOWS\SYSTEM32\jkkljgg.dll ()
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\ssqrq.dll) - C:\WINDOWS\SYSTEM32\ssqrq.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
========== Files/Folders - Created Within 30 Days ==========
[2009/02/05 12:14:34 | 00,487,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Margaret Kenney\Desktop\OTListIt22.exe
[2009/02/05 03:45:13 | 00,001,734 | —- | C] () – C:\Documents and Settings\Margaret Kenney\Desktop\HijackThis.lnk
[2009/02/05 03:45:13 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/05 03:45:04 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Margaret Kenney\Desktop\HJTInstall.exe
[2009/02/05 03:26:41 | 01,536,827 | -HS- | C] () – C:\WINDOWS\System32\ylqflrpp.ini
[2009/02/05 03:26:38 | 00,085,056 | —- | C] () – C:\WINDOWS\System32\pprlfqly.dll
[2009/02/05 03:17:03 | 00,000,000 | —D | C] – C:\Program Files\Hijackthis
[2009/02/05 03:16:47 | 00,488,144 | —- | C] (Soeperman Enterprises Ltd ) – C:\Documents and Settings\Margaret Kenney\Desktop\HJTsetup.exe
[2009/02/05 02:52:11 | 00,123,456 | —- | C] () – C:\WINDOWS\System32\phwavs.dll
[2009/02/05 02:52:10 | 00,123,456 | —- | C] () – C:\WINDOWS\System32\nsnynyvq.dll
[2009/01/30 03:57:22 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/01/30 03:57:22 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/01/30 03:04:21 | 01,483,063 | -HS- | C] () – C:\WINDOWS\System32\bjmfmpjq.ini
[2009/01/30 03:04:18 | 00,085,056 | —- | C] () – C:\WINDOWS\System32\qjpmfmjb.dll
[2009/01/30 03:04:15 | 00,122,432 | —- | C] () – C:\WINDOWS\System32\xtctyq.dll
[2009/01/30 03:04:14 | 00,122,432 | —- | C] () – C:\WINDOWS\System32\ilxpfamg.dll
========== Files - Modified Within 30 Days ==========
[2009/02/05 12:14:34 | 00,487,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Margaret Kenney\Desktop\OTListIt22.exe
[2009/02/05 12:09:35 | 00,460,344 | -HS- | M] () – C:\WINDOWS\System32\qrqss.ini2
[2009/02/05 12:09:34 | 00,460,344 | -HS- | M] () – C:\WINDOWS\System32\qrqss.ini
[2009/02/05 12:09:31 | 00,020,810 | -HS- | M] () – C:\WINDOWS\System32\lwvbealv.dllbox
[2009/02/05 05:00:19 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/05 04:59:57 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/02/05 04:59:48 | 53,484,3392 | -HS- | M] () – C:\hiberfil.sys
[2009/02/05 04:59:00 | 04,312,026 | -H– | M] () – C:\Documents and Settings\Margaret Kenney\Local Settings\Application Data\IconCache.db
[2009/02/05 04:55:49 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/02/05 03:45:13 | 00,001,734 | —- | M] () – C:\Documents and Settings\Margaret Kenney\Desktop\HijackThis.lnk
[2009/02/05 03:45:05 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Margaret Kenney\Desktop\HJTInstall.exe
[2009/02/05 03:26:52 | 01,536,827 | -HS- | M] () – C:\WINDOWS\System32\ylqflrpp.ini
[2009/02/05 03:26:39 | 00,085,056 | —- | M] () – C:\WINDOWS\System32\pprlfqly.dll
[2009/02/05 03:16:48 | 00,488,144 | —- | M] (Soeperman Enterprises Ltd ) – C:\Documents and Settings\Margaret Kenney\Desktop\HJTsetup.exe
[2009/02/05 02:52:11 | 00,123,456 | —- | M] () – C:\WINDOWS\System32\phwavs.dll
[2009/02/05 02:52:11 | 00,123,456 | —- | M] () – C:\WINDOWS\System32\nsnynyvq.dll
[2009/02/02 18:19:00 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/30 03:57:22 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/01/30 03:04:24 | 01,483,063 | -HS- | M] () – C:\WINDOWS\System32\bjmfmpjq.ini
[2009/01/30 03:04:18 | 00,085,056 | —- | M] () – C:\WINDOWS\System32\qjpmfmjb.dll
[2009/01/30 03:04:15 | 00,122,432 | —- | M] () – C:\WINDOWS\System32\xtctyq.dll
[2009/01/30 03:04:15 | 00,122,432 | —- | M] () – C:\WINDOWS\System32\ilxpfamg.dll
[2009/01/29 22:45:11 | 00,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
========== LOP Check ==========
[2008/09/03 01:39:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data
[2004/05/14 20:45:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/01/30 23:50:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2008/01/10 09:24:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/01/18 12:03:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2005/04/20 22:20:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2004/05/26 21:08:54 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Dpi
[2008/01/14 19:12:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2008/07/03 22:23:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GRETECH
[2005/04/19 23:52:36 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2008/04/19 10:44:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2008/09/03 01:39:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ludia
[2006/09/22 18:00:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2007/11/29 23:48:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2007/02/05 10:56:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
[2008/05/20 19:55:13 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2004/05/10 18:22:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2004/05/26 20:37:51 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\pcsvc
[2004/05/04 10:51:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2004/05/04 10:22:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2008/08/21 02:19:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/09/03 18:41:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2004/10/26 19:40:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2008/04/26 01:46:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/06/10 13:04:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/01/02 02:32:53 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Margaret Kenney\Application Data
[2008/04/30 13:51:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Adobe
[2008/03/21 01:45:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\AdobeUM
[2004/10/20 03:31:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Aim
[2007/02/12 16:21:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Apple Computer
[2004/05/22 21:34:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Corel
[2009/01/02 02:35:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\DVD Profiler
[2006/11/02 08:30:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Google
[2008/08/13 02:42:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\GRETECH
[2005/04/19 23:53:11 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Gtek
[2008/03/27 18:56:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Help
[2004/05/04 10:22:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Identities
[2004/05/04 10:54:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Jasc Software Inc
[2008/09/03 01:39:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Ludia
[2004/10/20 03:11:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Macromedia
[2004/05/12 14:32:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\McAfee.com Personal Firewall
[2004/11/13 11:35:19 | 00,000,000 | –SD | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Microsoft
[2007/09/20 11:46:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Mozilla
[2006/09/17 22:35:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\MSN6
[2007/02/24 04:46:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\MySpace
[2004/05/10 14:05:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Real
[2008/11/12 20:23:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Sonic
[2004/05/04 10:44:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Sun
[2009/02/02 18:19:00 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 05:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\DESKTOP.INI
[2009/02/05 05:00:19 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
[2008/01/28 19:55:02 | 00,000,000 | —D | M] – C:\Program Files\Outerinfo
[2008/01/28 19:55:02 | 00,000,000 | —D | M] – C:\Program Files\Outerinfo\FF
[2008/07/12 02:41:25 | 00,000,000 | —D | M] – C:\Program Files\ѕecurity
** - C:\Program Files\?ecurity
[2008/11/04 21:39:49 | 00,000,000 | —D | M] – C:\Program Files\ѕecurity\ѕecurity
** - C:\Program Files\?ecurity\?ecurity
========== Alternate Data Streams ==========
@Alternate Data Stream - 127 bytes -> %AllUsersProfile%\Application Data\TEMP:5B85C37B
@Alternate Data Stream - 0 bytes -> %SystemRoot%\Thumbs.db:encryptable
< End of report >
—————————————————————————————————————————————————————–
OTListIt Extras logfile created on: 2/5/2009 12:15:42 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\Margaret Kenney\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
510.00 Mb Total Physical Memory | 329.18 Mb Available Physical Memory | 64.55% Memory free
1.22 Gb Paging File | 1.10 Gb Available in Paging File | 90.40% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 18.04 Gb Free Space | 24.22% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TOM-SERVO
Current User Name: Margaret Kenney
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger (America Online, Inc.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe:*:Enabled:LimeWire: The most advanced file sharing program on the planet. File not found
C:\Program Files\Hello\Hello.exe:*:Enabled:Hello! File not found
C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealOne Player File not found
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger File not found
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server File not found
C:\Program Files\HangStan Trivia\HangStanTrivia.exe:*:Disabled:Hang Stan File not found
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire File not found
C:\WINDOWS\SYSTEM32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test (Microsoft Corporation)
C:\WINDOWS\SYSTEM32\rundll32.exe:*:Enabled:Run a DLL as an App (Microsoft Corporation)
C:\Program Files\BitSpirit\BitSpirit.exe:*:Enabled:The powerful and easy-to-use BitTorrent Client File not found
C:\Program Files\WinAntiVirus Pro 2006\Updater.exe:*:Enabled:updater.exe File not found
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger (America Online, Inc.)
C:\Program Files\Last.fm\LastFM.exe:*:Enabled:Last.fm File not found
C:\Tcl\bin\wish85.exe:*:Enabled:Wish Application File not found
C:\WINDOWS\SYSTEM32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE (Lexmark International, Inc.)
C:\Program Files\CallWave\IAM.exe:*:Enabled:CallWave (CallWave, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{04410044-9149-45C6-A806-F2BF9CFCE762}" = Microsoft Encarta Encyclopedia Standard 2004
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = Qualxserve Service Agreement
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{54F90B55-BEB3-4F0D-8802-228822FA5921}" = WordPerfect Office 11
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{7148F0A8-6813-11D6-A77B-00B0D0142050}" = Java 2 Runtime Environment, SE v1.4.2_05
"{76E6BBAA-25E6-4BFC-9613-75A5CACE2940}" = Olympus
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114767253}" = The Price is Right
"{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{BFD96B89-B769-4CD6-B11E-E79FFD46F067}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}" = Panda Antivirus 2008
"{EE7C3A14-1D20-49F6-B903-491561076F0F}" = ArcSoft Software Suite
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"Ad-aware 6 Personal" = Ad-aware 6 Personal
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AOL Instant Messenger" = AOL Instant Messenger
"bannerstyle" = Enhancement Browser Tools Bannerstyle
"CallWave" = CallWave
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_PCI_VEN_14F1&DEV_2702" = Conexant SmartHSFi V.9x 56K DF PCI Modem
"Dell AIO Printer A920" = Dell AIO Printer A920
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"GOM Player" = GOM Player
"HijackThis" = HijackThis 2.0.2
"Hijackthis_is1" = Hijackthis 1.99.1
"iCheck" = Internet Speed Monitor
"InstallShield_{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"InterActual Player" = InterActual Player
"intexp" = TopFiveSearch.com Search Assistant
"InvelosDVDProfiler_is1" = DVD Profiler Version 3.1.1
"Mozilla Firefox (3.0.3)" = Mozilla Firefox (3.0.3)
"OINAnalytics" = OIN Analytics
"Outerinfo" = Outerinfo
"PCFriendly" = PCFriendly
"Plasma Pong_is1" = Plasma Pong v1.3b
"PodUtil_is1" = PodUtil 3.0.2
"PowerISO" = PowerISO
"Shockwave" = Shockwave
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.3
"System Mechanic Professional 6_is1" = iolo technologies' System Mechanic Professional 6
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinRAR archiver" = WinRAR archiver
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 12/28/2008 3:13:18 PM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x00001010.
Error - 12/31/2008 11:55:10 PM | Computer Name = TOM-SERVO | Source = Application Hang | ID = 1002
Description = Hanging application QuickTimePlayer.exe, version 7.4.1.14, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/2/2009 3:23:34 AM | Computer Name = TOM-SERVO | Source = Application Hang | ID = 1002
Description = Hanging application dvdpro.exe, version 3.1.1.1171, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 1/2/2009 9:15:49 AM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x0003426d.
Error - 1/2/2009 9:15:56 AM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1001
Description = Fault bucket 127913559.
Error - 1/2/2009 9:22:06 AM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x0003426d.
Error - 1/15/2009 10:26:33 PM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3188, faulting module
unknown, version 0.0.0.0, fault address 0x058812c8.
Error - 1/20/2009 3:16:33 AM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3188, faulting module
ssqrq.dll, version 0.0.0.0, fault address 0x000282a0.
Error - 1/30/2009 2:10:43 AM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3188, faulting module
ssqrq.dll, version 0.0.0.0, fault address 0x000282a0.
Error - 1/31/2009 4:39:57 AM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3188, faulting module
ssqrq.dll, version 0.0.0.0, fault address 0x000282a0.
[ System Events ]
Error - 2/4/2009 3:19:33 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
vspf vspf_hk
Error - 2/5/2009 6:00:40 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7003
Description = The Panda anti-virus service service depends on the following nonexistent
service: PavDrv
Error - 2/5/2009 6:00:40 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LexBce Server service
to connect.
Error - 2/5/2009 6:00:41 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7000
Description = The LexBce Server service failed to start due to the following error:
%%1053
Error - 2/5/2009 6:00:41 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7001
Description = The Print Spooler service depends on the LexBce Server service which
failed to start because of the following error: %%1053
Error - 2/5/2009 6:00:41 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the DM1Service service to
connect.
Error - 2/5/2009 6:00:41 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7000
Description = The DM1Service service failed to start due to the following error:
%%1053
Error - 2/5/2009 6:00:41 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Panda Process Protection
Service service to connect.
Error - 2/5/2009 6:00:41 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7000
Description = The Panda Process Protection Service service failed to start due to
the following error: %%1053
Error - 2/5/2009 6:00:44 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
vspf vspf_hk
< End of report >