This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Win32Delf.uc virus and others

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

PC keeps freezing. Running very slowly. Virus picked up by Norton and spyblaster but keeps reappearing. Spybot search and destroy has also not cured problem. Error messages include closing down of Vs Tsk Mgr.exe and recurrence of virus Win32.Delf.uc. Also hav Trojan - rc[1].htm AND RC[2].HTM - JA/Generic Exploit.j, Whcih have 'Move failed (Clean failed because the file isn't cleanable), posted next to them.
Unable to view some icons on desktop. One icon appears to be off screen to left and unable to access this irrespective is I install and reinstall the programme.

Logfile of HijackThis v1.99.1
Scan saved at 20:30:57, on 06/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\lxdjcoms.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\Sony\WiseWan\NOVATE~1\NWAppService.exe
C:\PROGRA~1\Sony\WiseWan\NOVATE~1\NwAppLauncher.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Protector Suite QL\menusw.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\T-Mobile\Communication Center\AutoUpdateSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = server1:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [Biomenu] "C:\Program Files\Protector Suite QL\menusw.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [lxdjmon.exe] "C:\Program Files\Lexmark 1400 Series\lxdjmon.exe"
O4 - HKLM\..\Run: [lxdjamon] "C:\Program Files\Lexmark 1400 Series\lxdjamon.exe"
O4 - HKLM\..\Run: [LXDJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDJtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [VAIO Update 4] "C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe" /Stationary
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Alice Automatic Updates Agent.lnk = ?
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: Add RSS Support Site to VAIO Information FLOW - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'bmnet.dll' missing
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ncgst.nhs.uk
O17 - HKLM\Software\..\Telephony: DomainName = ncgst.nhs.uk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ncgst.nhs.uk
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: t-mobile - {C6D89159-3467-4C2F-9918-3362DA57BCD2} - C:\PROGRA~1\T-Mobile\HOTSPO~1\TMOBIL~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: psfus - C:\WINDOWS\SYSTEM32\fusstub.dll
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: lxdj_device - - C:\WINDOWS\system32\lxdjcoms.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NWAppService - Unknown owner - C:\PROGRA~1\Sony\WiseWan\NOVATE~1\NWAppService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\Avlib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Cooporated Initialisation (VCI) - Unknown owner - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe (file missing)
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
Hello and welcome to Posted Image

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your HJT log now, I will post back shortly with instructions.
Thank you for your help I have McAfee running (pre-installed) and have also added Norton Antivirus to software which I have on my desktop. Both are running simultaneously and I am not sure this is wise, but at least Norton appears to have cleared something. Will I need to post a new HJT log now?
Hello thedoce123,

Nothing is showing up on your HJT log, so lets get a deeper analysis.


  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Thanks again
On boot up still have error stating problem with VsTskMgr.exe and windows closes this down. SpyBot continually picks up and cleans Win32Delf.uc but it keeps reappearing. Spyware Doctor is moving rc[1].htm AND RC[2].HTM - JA/Generic Exploit.j but obviously not clearing them. I think Norton has sorted out one of the problems. Best to mention I have a VPN connection to pick up mail. This is where the problem first manifest as I could not load software for 3g card to make connection.

Here are the logs:
OTListIt logfile created on: 08/02/2009 10:57:33 - Run
OTListIt2 by OldTimer - Version 2.0.0.9 Folder = C:\Documents and Settings\janderson\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 0.96 Gb Available Physical Memory | 47.96% Memory free
3.85 Gb Paging File | 2.89 Gb Available in Paging File | 75.05% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 46.57 Gb Total Space | 11.67 Gb Free Space | 25.06% Space Free | Partition Type: NTFS
Drive D: | 38.67 Gb Total Space | 34.00 Gb Free Space | 87.93% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NET-VTAILOR
Current User Name: janderson
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe ()
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\WINDOWS\system32\lxdjcoms.exe ( )
PRC - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (Network Associates, Inc.)
PRC - C:\Program Files\Network Associates\VirusScan\Mcshield.exe (Network Associates, Inc.)
PRC - C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe (Network Associates, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
PRC - C:\WINDOWS\system32\searchindexer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\system32\ico.exe (Primax Electronics Ltd.)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe (Intel Corporation)
PRC - C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
PRC - C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
PRC - C:\Program Files\Protector Suite QL\menusw.exe (UPEK Inc.)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Network Associates\VirusScan\shstat.exe (Network Associates, Inc.)
PRC - C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe (Network Associates, Inc.)
PRC - C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe (Network Associates, Inc.)
PRC - C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe (HP)
PRC - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
PRC - C:\Program Files\Kontiki\KHost.exe (Kontiki Inc.)
PRC - C:\Program Files\TomTom HOME 2\HOMERunner.exe (TomTom)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files\Nokia\Nokia PC Suite 7\PcSync2.exe (Time Information Services Ltd.)
PRC - C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe ()
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe ()
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclToBTSrv.exe ()
PRC - C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe (Nokia Corporation)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe (TOSHIBA CORPORATION.)
PRC - C:\WINDOWS\system32\searchprotocolhost.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\searchfilterhost.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Documents and Settings\janderson\Desktop\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AdobeActiveFileMonitor4.0 [Auto | Running]) – C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe ()
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Automatic LiveUpdate Scheduler [Auto | Running]) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CLTNetCnService [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
SRV - (comHost [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (CVPND [Auto | Running]) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (EvtEng [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment [On_Demand | Stopped]) – C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)
SRV - (KService [Auto | Running]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (LiveUpdate [On_Demand | Stopped]) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (LiveUpdate Notice [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
SRV - (lxdj_device [Auto | Running]) – C:\WINDOWS\system32\lxdjcoms.exe ( )
SRV - (McAfeeFramework [Auto | Running]) – C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (Network Associates, Inc.)
SRV - (McShield [Auto | Running]) – C:\Program Files\Network Associates\VirusScan\Mcshield.exe (Network Associates, Inc.)
SRV - (McTaskManager [Auto | Stopped]) – C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe (Network Associates, Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service [On_Demand | Stopped]) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (MSCSPTISRV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\Avlib\MSCSPTISRV.exe (Sony Corporation)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (NWCWorkstation [Auto | Running]) – C:\WINDOWS\system32\nwwks.dll (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PACSPTISVR [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\Avlib\PACSPTISVR.exe (Sony Corporation)
SRV - (RegSrvc [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (S24EventMonitor [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (sdAuxService [Auto | Running]) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (sdCoreService [Auto | Running]) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (ServiceLayer [On_Demand | Running]) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (SSScsiSV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\Avlib\SSScsiSV.exe (Sony Corporation)
SRV - (Symantec Core LC [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (VAIO Event Service [Auto | Running]) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (VCI [Auto | Stopped]) – File not found
SRV - (Vcsw [On_Demand | Running]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (VzCdbSvc [Auto | Running]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (VzFw [Auto | Running]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WSearch [Auto | Running]) – C:\WINDOWS\system32\searchindexer.exe (Microsoft Corporation)
SRV - (WudfSvc [Auto | Running]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AegisP [Auto | Running]) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
DRV - (ApfiltrService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (COH_Mon [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (CO_Mon [Auto | Running]) – C:\WINDOWS\system32\drivers\CO_Mon.sys (Symantec Corporation)
DRV - (CVirtA [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (CVPNDRVA [Auto | Running]) – C:\WINDOWS\system32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (DMICall [System | Running]) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (DNE [On_Demand | Running]) – C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (FdRedir [Auto | Running]) – C:\Program Files\Common Files\Protector Suite QL\Drivers\FdRedir.sys (UPEK Inc.)
DRV - (FileDisk2 [Auto | Running]) – C:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys (UPEK Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWAZL [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (IFXTPM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
DRV - (IKFileSec [Boot | Running]) – C:\WINDOWS\system32\drivers\ikfilesec.sys (PCTools Research Pty Ltd.)
DRV - (IkSysFlt [System | Running]) – C:\WINDOWS\system32\drivers\iksysflt.sys (PCTools Research Pty Ltd.)
DRV - (IKSysSec [System | Running]) – C:\WINDOWS\system32\drivers\iksyssec.sys (PCTools Research Pty Ltd.)
DRV - (kbdhid [System | Stopped]) – C:\WINDOWS\system32\drivers\kbdhid.sys (Microsoft Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (Mvc25U870_VID_1262&PID_25FD [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Mvc25U870.sys (Micro Vision Co.,Ltd)
DRV - (NaiAvFilter1 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\naiavf5x.sys (Network Associates, Inc.)
DRV - (NaiAvTdi1 [System | Running]) – C:\WINDOWS\system32\drivers\mvstdi5x.sys (Network Associates, Inc.)
DRV - (NAVENG [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090206.057\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090206.057\NAVEX15.SYS (Symantec Corporation)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (NWADI [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NwlnkIpx [Auto | Running]) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (NwlnkNb [Auto | Running]) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx [Auto | Running]) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (NWRDR [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nwrdr.sys (Microsoft Corporation)
DRV - (NWUSBModem [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (odysseyIM4 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\odysseyIM4.sys (Funk Software, Inc.)
DRV - (pccsmcfd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
DRV - (RimSerPort [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RimSerial.sys (Research in Motion Ltd)
DRV - (ROOTMODEM [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\rootmdm.sys (Microsoft Corporation)
DRV - (s24trans [Auto | Running]) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (shpf [Boot | Running]) – C:\WINDOWS\system32\drivers\shpf.sys (Sony Corporation)
DRV - (SNC [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)
DRV - (SonyImgF [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SonyImgF.sys (Sony Corporation)
DRV - (SPBBCDrv [System | Running]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SPI [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SonyPI.sys (Sony Corporation)
DRV - (SRTSP [System | Running]) – C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPL [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSPX [System | Running]) – C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (STHDA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (SYMDNS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symdns.sys (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symfw.sys (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symids.sys (Symantec Corporation)
DRV - (SYMIDSCO [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20090129.001\SymIDSCo.sys (Symantec Corporation)
DRV - (SymIM [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\SymIM.sys (Symantec Corporation)
DRV - (SymIMMP [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SymIM.sys (Symantec Corporation)
DRV - (symlcbrd [Auto | Running]) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symndis.sys (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SYMTDI [System | Running]) – C:\WINDOWS\system32\drivers\symtdi.sys (Symantec Corporation)
DRV - (TcUsb [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tcusb.sys (UPEK Inc.)
DRV - (ti21sony [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ti21sony.sys (Texas Instruments)
DRV - (toshidpt [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\toshidpt.sys (TOSHIBA Corporation.)
DRV - (tosporte [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfbd [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (Tosrfbnp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfcom [System | Running]) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (Tosrfhid [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (tosrfnds [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (TosRfSnd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfsnd.sys (TOSHIBA Corporation)
DRV - (Tosrfusb [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (vsdatant [On_Demand | Stopped]) – C:\WINDOWS\system32\vsdatant.sys (Zone Labs Inc.)
DRV - (w39n51 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (WS2IFSL [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)
DRV - (yukonwxp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (EntDrv51 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\EntDrv51.sys (Network Associates, Inc)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (291996 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10056 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google BAE\BAE.dll (Sony Corp.)
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Biomenu] "C:\Program Files\Protector Suite QL\menusw.exe" (UPEK Inc.)
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" (Intel Corporation)
O4 - HKLM..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe (HP)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe" (PC Tools)
O4 - HKLM..\Run: [lxdjamon] "C:\Program Files\Lexmark 1400 Series\lxdjamon.exe" (Lexmark)
O4 - HKLM..\Run: [LXDJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDJtime.dll,_RunDLLEntry@16 (Lexmark International, Inc.)
O4 - HKLM..\Run: [lxdjmon.exe] "C:\Program Files\Lexmark 1400 Series\lxdjmon.exe" File not found
O4 - HKLM..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey (Network Associates, Inc.)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] ICO.EXE (Primax Electronics Ltd.)
O4 - HKLM..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" (Network Associates, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe" (Symantec Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE (Network Associates, Inc.)
O4 - HKLM..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" (Sony Corporation)
O4 - HKLM..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
O4 - HKLM..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon (Microsoft Corporation)
O4 - HKLM..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary (Sony Corporation)
O4 - HKLM..\Run: [VAIO Update 4] "C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe" /Stationary (Sony Corporation)
O4 - HKLM..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" (Sony Corporation)
O4 - HKCU..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all (Kontiki Inc.)
O4 - HKCU..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog (Time Information Services Ltd.)
O4 - HKCU..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray (Nokia)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" (TomTom)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe (Cisco Systems, Inc.)
O4 - Startup: C:\Documents and Settings\janderson\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add RSS Support Site to VAIO Information FLOW - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: sony-europe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Sites: sonystyle-europe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Sites: vaio-link.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\t-mobile {C6D89159-3467-4C2F-9918-3362DA57BCD2} - C:\Program Files\T-Mobile\HotSpot Locator\TMobileExplorerPlugin.dll ()
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (PSLogon.dll) - C:\WINDOWS\system32\PSLogon.dll (UPEK Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\psfus: DllName - fusstub.dll - C:\WINDOWS\system32\fusstub.dll (UPEK Inc.)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\system32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{b97d6e22-937a-11dd-b98c-0016fe96704a}\Shell - "" = AutoRun
O33 - MountPoints2\{b97d6e22-937a-11dd-b98c-0016fe96704a}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b97d6e22-937a-11dd-b98c-0016fe96704a}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O33 - MountPoints2\{ede5bced-9121-11dd-b987-0016fe96704a}\Shell - "" = AutoRun
O33 - MountPoints2\{ede5bced-9121-11dd-b987-0016fe96704a}\Shell\Auto\command - "" = G:\Song.exe – File not found
O33 - MountPoints2\{ede5bced-9121-11dd-b987-0016fe96704a}\Shell\AutoRun - "" = Auto&Play

========== Files/Folders - Created Within 30 Days ==========

[2009/02/08 10:56:50 | 00,487,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\janderson\Desktop\OTListIt22.exe
[2009/02/08 10:42:54 | 00,000,000 | R-SD | C] – C:\Documents and Settings\janderson\My Documents\My Safe
[2009/02/07 11:20:00 | 00,025,313 | —- | C] () – C:\Documents and Settings\janderson\My Documents\writeup.jsp.htm
[2009/02/06 23:13:46 | 00,000,630 | —- | C] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - janderson.job
[2009/02/06 22:19:01 | 00,002,011 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton Internet Security.lnk
[2009/02/06 22:17:20 | 00,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2009/02/06 22:16:16 | 00,000,000 | —D | C] – C:\Program Files\Norton Internet Security
[2009/02/06 22:14:28 | 00,124,464 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009/02/06 22:14:28 | 00,060,808 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2009/02/06 22:14:28 | 00,010,635 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2009/02/06 22:14:28 | 00,000,806 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2009/02/06 22:14:17 | 00,000,000 | —D | C] – C:\Program Files\Symantec
[2009/02/06 22:08:01 | 00,000,000 | —D | C] – C:\Documents and Settings\janderson\Application Data\Symantec
[2009/02/06 20:29:51 | 00,000,654 | —- | C] () – C:\Documents and Settings\janderson\Desktop\Hijackthis.lnk
[2009/02/06 20:28:54 | 00,000,000 | —D | C] – C:\Program Files\Hijackthis
[2009/02/02 22:06:25 | 00,000,000 | —D | C] – C:\quarantine
[2009/02/02 21:36:08 | 00,023,040 | —- | C] () – C:\WINDOWS\kernel32.exe
[2009/02/02 21:33:53 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd
[2009/02/02 21:01:40 | 00,000,937 | —- | C] () – C:\Documents and Settings\janderson\Desktop\Spybot - Search & Destroy.lnk
[2009/02/02 19:24:09 | 00,028,160 | —- | C] () – C:\Documents and Settings\janderson\My Documents\Jim.doc
[2009/02/02 18:38:00 | 00,042,496 | —- | C] () – C:\Documents and Settings\janderson\My Documents\surgical curriculum extracts.doc
[2009/02/02 17:54:16 | 00,273,920 | —- | C] () – C:\Documents and Settings\janderson\My Documents\Copy of bsg_programme_FINAL_09.xls
[2009/02/02 17:52:10 | 00,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2009/02/02 17:52:10 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/30 07:08:21 | 00,307,719 | —- | C] () – C:\Documents and Settings\janderson\My Documents\standard-tube-map.pdf
[2009/01/30 06:28:33 | 00,000,000 | —D | C] – C:\Documents and Settings\janderson\My Documents\Proctor and Gamble project
[2009/01/29 09:09:06 | 00,080,695 | —- | C] () – C:\Documents and Settings\janderson\My Documents\Tutorials_Certificate.pdf
[2009/01/20 18:15:33 | 00,000,000 | —D | C] – C:\Documents and Settings\janderson\My Documents\e-Endoscopy
[2009/01/19 20:36:24 | 00,080,384 | —- | C] () – C:\Documents and Settings\janderson\My Documents\TC contacts JAN 2009.doc
[2009/01/09 11:25:18 | 00,011,795 | —- | C] () – C:\Documents and Settings\janderson\Desktop\Today.docx

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/02/08 10:52:58 | 00,487,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\janderson\Desktop\OTListIt22.exe
[2009/02/08 10:42:38 | 00,050,868 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/02/08 10:42:10 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/08 10:39:20 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/08 10:38:58 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/08 10:38:38 | 21,454,39744 | -HS- | M] () – C:\hiberfil.sys
[2009/02/07 17:51:53 | 00,000,512 | —- | M] () – C:\WINDOWS\randseed.rnd
[2009/02/07 13:34:07 | 00,220,672 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\logon.scr
[2009/02/07 13:34:05 | 00,009,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\scrnsave.scr
[2009/02/07 13:33:59 | 00,019,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ssbezier.scr
[2009/02/07 13:33:50 | 00,014,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ssstars.scr
[2009/02/07 13:33:48 | 00,610,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\sspipes.scr
[2009/02/07 13:33:45 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ssmyst.scr
[2009/02/07 13:33:43 | 00,047,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ssmypics.scr
[2009/02/07 13:33:41 | 00,020,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ssmarque.scr
[2009/02/07 13:33:40 | 00,393,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ssflwbox.scr
[2009/02/07 13:33:38 | 00,704,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ss3dfo.scr
[2009/02/07 12:50:37 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieudinit.exe
[2009/02/07 12:50:34 | 00,070,656 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2009/02/07 12:50:32 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshta.exe
[2009/02/07 11:20:07 | 00,025,313 | —- | M] () – C:\Documents and Settings\janderson\My Documents\writeup.jsp.htm
[2009/02/07 11:13:54 | 00,124,464 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009/02/07 11:13:54 | 00,060,808 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2009/02/07 11:13:54 | 00,010,635 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2009/02/07 11:13:54 | 00,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2009/02/07 10:37:14 | 01,414,656 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mmc.exe
[2009/02/07 10:36:37 | 01,200,640 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ntbackup.exe
[2009/02/07 10:36:36 | 00,514,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\logonui.exe
[2009/02/07 10:36:35 | 01,298,432 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxdiag.exe
[2009/02/07 10:36:23 | 00,065,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wextract.exe
[2009/02/07 10:36:23 | 00,008,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wdfmgr.exe
[2009/02/07 10:36:22 | 00,049,664 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\w32tm.exe
[2009/02/07 10:36:22 | 00,033,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\vssadmin.exe
[2009/02/07 10:36:22 | 00,005,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\winver.exe
[2009/02/07 10:36:21 | 00,008,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\uwdf.exe
[2009/02/07 10:36:20 | 00,050,176 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\utilman.exe
[2009/02/07 10:36:20 | 00,004,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\unlodctr.exe
[2009/02/07 10:36:19 | 00,062,976 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tzchange.exe
[2009/02/07 10:36:19 | 00,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tscupgrd.exe
[2009/02/07 10:36:19 | 00,036,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\typeperf.exe
[2009/02/07 10:36:18 | 00,259,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tracerpt.exe
[2009/02/07 10:36:17 | 00,061,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tlntadmn.exe
[2009/02/07 10:36:16 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\systeminfo.exe
[2009/02/07 10:36:15 | 00,293,376 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WISPTIS.EXE
[2009/02/07 10:36:14 | 00,024,576 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\sort.exe
[2009/02/07 10:36:14 | 00,007,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\spdwnwxp.exe
[2009/02/07 10:36:13 | 00,131,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\sndrec32.exe
[2009/02/07 10:36:12 | 00,026,112 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\skeys.exe
[2009/02/07 10:36:12 | 00,008,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\smbinst.exe
[2009/02/07 10:36:11 | 00,433,664 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wiaacmgr.exe
[2009/02/07 10:36:11 | 00,070,144 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\sigverif.exe
[2009/02/07 10:36:10 | 00,032,768 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2009/02/07 10:36:09 | 00,062,976 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rsopprov.exe
[2009/02/07 10:36:09 | 00,031,232 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\sethc.exe
[2009/02/07 10:36:09 | 00,031,232 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\sc.exe
[2009/02/07 10:36:07 | 00,032,768 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\relog.exe
[2009/02/07 10:36:07 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\routemon.exe
[2009/02/07 10:36:07 | 00,004,608 | —- | M] (Microsoft) – C:\WINDOWS\System32\regwiz.exe
[2009/02/07 10:36:06 | 00,050,176 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\reg.exe
[2009/02/07 10:36:06 | 00,033,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\regini.exe
[2009/02/07 10:36:06 | 00,007,168 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\recover.exe
[2009/02/07 10:36:06 | 00,003,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\regedt32.exe
[2009/02/07 10:36:05 | 00,067,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rdshost.exe
[2009/02/07 10:36:04 | 00,062,976 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rdpclip.exe
[2009/02/07 10:36:04 | 00,056,832 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rasphone.exe
[2009/02/07 10:36:04 | 00,050,176 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\proquota.exe
[2009/02/07 10:36:03 | 00,049,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\powercfg.exe
[2009/02/07 10:36:02 | 00,172,032 | —- | M] (Primax Electronics Ltd.) – C:\WINDOWS\System32\PMUNINST.EXE
[2009/02/07 10:36:01 | 00,058,368 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\packager.exe
[2009/02/07 10:36:00 | 00,215,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\osk.exe
[2009/02/07 10:36:00 | 00,040,448 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\osuninst.exe
[2009/02/07 10:35:59 | 00,067,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\openfiles.exe
[2009/02/07 10:35:58 | 00,044,168 | —- | M] () – C:\WINDOWS\System32\oem_setup.exe
[2009/02/07 10:35:58 | 00,032,768 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\odbcad32.exe
[2009/02/07 10:35:57 | 00,126,464 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\nwscript.exe
[2009/02/07 10:35:57 | 00,066,560 | —- | M] (UPEK Inc.) – C:\WINDOWS\System32\nwhlp.exe
[2009/02/07 10:35:56 | 00,206,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WinFXDocObj.exe
[2009/02/07 10:35:54 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\netstat.exe
[2009/02/07 10:35:54 | 00,032,256 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wpabaln.exe
[2009/02/07 10:35:53 | 00,331,776 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\netsetup.exe
[2009/02/07 10:35:52 | 00,124,928 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\net1.exe
[2009/02/07 10:35:52 | 00,042,496 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\net.exe
[2009/02/07 10:35:51 | 00,176,640 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2009/02/07 10:35:51 | 00,004,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\nddeapir.exe
[2009/02/07 10:35:49 | 00,006,656 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msswchx.exe
[2009/02/07 10:35:49 | 00,005,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\write.exe
[2009/02/07 10:35:48 | 00,123,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mplay32.exe
[2009/02/07 10:35:48 | 00,008,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mountvol.exe
[2009/02/07 10:35:48 | 00,004,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mqsvc.exe
[2009/02/07 10:35:47 | 00,057,344 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\makecab.exe
[2009/02/07 10:35:47 | 00,051,712 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\migpwd.exe
[2009/02/07 10:35:47 | 00,033,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2009/02/07 10:35:46 | 00,059,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\logman.exe
[2009/02/07 10:35:46 | 00,008,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\lpr.exe
[2009/02/07 10:35:46 | 00,006,144 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\lpq.exe
[2009/02/07 10:35:46 | 00,005,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\lodctr.exe
[2009/02/07 10:35:45 | 00,029,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\lights.exe
[2009/02/07 10:35:45 | 00,025,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\lnkstub.exe
[2009/02/07 10:35:44 | 00,044,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ipsec6.exe
[2009/02/07 10:35:41 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ipconfig.exe
[2009/02/07 10:35:38 | 00,045,056 | —- | M] (Primax Electronics Ltd.) – C:\WINDOWS\System32\ICONSPY.EXE
[2009/02/07 10:35:37 | 00,193,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\fsquirt.exe
[2009/02/07 10:35:37 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\getmac.exe
[2009/02/07 10:35:37 | 00,039,424 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\grpconv.exe
[2009/02/07 10:35:36 | 00,027,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\findstr.exe
[2009/02/07 10:35:36 | 00,024,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\extrac32.exe
[2009/02/07 10:35:36 | 00,007,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\forcedos.exe
[2009/02/07 10:35:36 | 00,003,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\fixmapi.exe
[2009/02/07 10:35:35 | 00,193,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\eudcedit.exe
[2009/02/07 10:35:35 | 00,050,688 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\eventcreate.exe
[2009/02/07 10:35:35 | 00,008,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\eventvwr.exe
[2009/02/07 10:35:34 | 00,249,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drmupgds.exe
[2009/02/07 10:35:33 | 00,062,976 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\driverquery.exe
[2009/02/07 10:35:33 | 00,029,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dplaysvr.exe
[2009/02/07 10:35:32 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\diskpart.exe
[2009/02/07 10:35:32 | 00,004,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllhst3g.exe
[2009/02/07 10:35:31 | 00,025,088 | —- | M] (Microsoft Corp. and Executive Software International, Inc.) – C:\WINDOWS\System32\defrag.exe
[2009/02/07 10:35:30 | 00,030,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ddeshare.exe
[2009/02/07 10:35:29 | 00,063,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cmstp.exe
[2009/02/07 10:35:29 | 00,039,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cmmon32.exe
[2009/02/07 10:35:29 | 00,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\conime.exe
[2009/02/07 10:35:29 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cmdl32.exe
[2009/02/07 10:35:29 | 00,008,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\control.exe
[2009/02/07 10:35:28 | 00,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cmd.exe
[2009/02/07 10:35:28 | 00,064,000 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cleanmgr.exe
[2009/02/07 10:35:27 | 00,007,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ckcnv.exe
[2009/02/07 10:35:26 | 00,056,832 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cipher.exe
[2009/02/07 10:35:26 | 00,008,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cidaemon.exe
[2009/02/07 10:35:26 | 00,005,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\bootvrfy.exe
[2009/02/07 10:35:25 | 00,142,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\bootcfg.exe
[2009/02/07 10:35:25 | 00,004,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\bootok.exe
[2009/02/07 10:35:24 | 00,142,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WudfHost.exe
[2009/02/07 10:35:24 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\blastcln.exe
[2009/02/07 10:35:24 | 00,032,256 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wupdmgr.exe
[2009/02/07 10:35:23 | 00,030,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\xcopy.exe
[2009/02/07 10:35:23 | 00,025,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\at.exe
[2009/02/07 10:35:22 | 00,032,768 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\asr_pfu.exe
[2009/02/07 10:35:22 | 00,032,256 | —- | M] (Microsoft Corp.) – C:\WINDOWS\System32\asr_ldm.exe
[2009/02/07 10:35:21 | 00,030,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\asr_fmt.exe
[2009/02/07 10:35:21 | 00,004,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\actmovie.exe
[2009/02/07 10:35:16 | 00,023,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\setup.exe
[2009/02/07 10:35:16 | 00,023,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\fltmc.exe
[2009/02/07 10:35:15 | 00,023,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ipxroute.exe
[2009/02/07 10:35:15 | 00,022,016 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\qwinsta.exe
[2009/02/07 10:35:15 | 00,021,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rcp.exe
[2009/02/07 10:35:15 | 00,021,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pathping.exe
[2009/02/07 10:35:15 | 00,020,480 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cliconfg.exe
[2009/02/07 10:35:05 | 00,015,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\taskman.exe
[2009/02/07 10:35:05 | 00,015,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pentnt.exe
[2009/02/07 10:35:04 | 00,016,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\upnpcont.exe
[2009/02/07 10:35:04 | 00,016,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tsshutdn.exe
[2009/02/07 10:35:04 | 00,015,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\logoff.exe
[2009/02/07 10:35:03 | 00,016,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tskill.exe
[2009/02/07 10:35:03 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\comp.exe
[2009/02/07 10:35:02 | 00,019,456 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tcpsvcs.exe
[2009/02/07 10:35:02 | 00,017,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\diskperf.exe
[2009/02/07 10:35:02 | 00,017,408 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\compact.exe
[2009/02/07 10:35:02 | 00,016,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tftp.exe
[2009/02/07 10:35:01 | 00,020,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\spupdwxp.exe
[2009/02/07 10:35:01 | 00,019,456 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\shutdown.exe
[2009/02/07 10:35:01 | 00,017,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dvdupgrd.exe
[2009/02/07 10:35:01 | 00,017,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dpnsvr.exe
[2009/02/07 10:35:01 | 00,015,872 | —- | M] (Microsoft Corp.) – C:\WINDOWS\System32\dmremote.exe
[2009/02/07 10:35:00 | 00,020,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\faxpatch.exe
[2009/02/07 10:35:00 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\secedit.exe
[2009/02/07 10:35:00 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rwinsta.exe
[2009/02/07 10:35:00 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\expand.exe
[2009/02/07 10:34:59 | 00,020,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\fontview.exe
[2009/02/07 10:34:59 | 00,016,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\qappsrv.exe
[2009/02/07 10:34:59 | 00,016,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\runas.exe
[2009/02/07 10:34:59 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\help.exe
[2009/02/07 10:34:58 | 00,019,456 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\arp.exe
[2009/02/07 10:34:58 | 00,017,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ping.exe
[2009/02/07 10:34:58 | 00,017,408 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wpdshextautoplay.exe
[2009/02/07 10:34:57 | 00,020,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msg.exe
[2009/02/07 10:34:57 | 00,020,480 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\nbtstat.exe
[2009/02/07 10:34:57 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\perfmon.exe
[2009/02/07 10:34:56 | 00,014,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\stimon.exe
[2009/02/07 10:34:56 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\convert.exe
[2009/02/07 10:34:56 | 00,011,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\spnpinst.exe
[2009/02/07 10:34:56 | 00,009,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\comsdupd.exe
[2009/02/07 10:34:55 | 00,014,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tsdiscon.exe
[2009/02/07 10:34:55 | 00,014,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tscon.exe
[2009/02/07 10:34:55 | 00,014,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\shadow.exe
[2009/02/07 10:34:55 | 00,014,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rsh.exe
[2009/02/07 10:34:55 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\savedump.exe
[2009/02/07 10:34:55 | 00,012,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\spiisupd.exe
[2009/02/07 10:34:55 | 00,012,288 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tracert.exe
[2009/02/07 10:34:55 | 00,012,288 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tcmsetup.exe
[2009/02/07 10:34:55 | 00,009,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\sfc.exe
[2009/02/07 10:34:55 | 00,009,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\subst.exe
[2009/02/07 10:34:54 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rexec.exe
[2009/02/07 10:34:54 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rdsaddin.exe
[2009/02/07 10:34:54 | 00,012,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\replace.exe
[2009/02/07 10:34:54 | 00,011,776 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rasautou.exe
[2009/02/07 10:34:54 | 00,011,776 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\chkdsk.exe
[2009/02/07 10:34:54 | 00,011,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rasdial.exe
[2009/02/07 10:34:54 | 00,011,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\chkntfs.exe
[2009/02/07 10:34:54 | 00,010,752 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\doskey.exe
[2009/02/07 10:34:54 | 00,009,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\reset.exe
[2009/02/07 10:34:53 | 00,014,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\auditusr.exe
[2009/02/07 10:34:53 | 00,012,288 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\attrib.exe
[2009/02/07 10:34:53 | 00,011,776 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\winmsd.exe
[2009/02/07 10:34:53 | 00,011,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\atmadm.exe
[2009/02/07 10:34:53 | 00,009,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\print.exe
[2009/02/07 10:34:52 | 00,014,848 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\fc.exe
[2009/02/07 10:34:52 | 00,012,288 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstinit.exe
[2009/02/07 10:34:52 | 00,009,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\finger.exe
[2009/02/07 10:34:52 | 00,009,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\find.exe
[2009/02/07 10:34:51 | 00,538,624 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\spider.exe
[2009/02/07 10:34:51 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wscntfy.exe
[2009/02/07 10:34:51 | 00,011,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wpnpinst.exe
[2009/02/07 10:34:51 | 00,009,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\label.exe
[2009/02/07 10:34:37 | 00,025,600 | —- | M] (Twain Working Group) – C:\WINDOWS\twunk_32.exe
[2009/02/07 10:34:35 | 00,347,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tourstart.exe
[2009/02/07 10:34:35 | 00,315,392 | —- | M] (Sony Electronics, Inc) – C:\WINDOWS\Reminder.exe
[2009/02/07 10:34:33 | 00,146,432 | —- | M] (Microsoft Corporation) – C:\WINDOWS\regedit.exe
[2009/02/07 10:34:30 | 00,023,040 | —- | M] () – C:\WINDOWS\kernel32.exe
[2009/02/07 10:34:12 | 00,010,752 | —- | M] (Microsoft Corporation) – C:\WINDOWS\hh.exe
[2009/02/07 10:34:00 | 00,019,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cacls.exe
[2009/02/07 10:33:59 | 00,019,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\qprocess.exe
[2009/02/07 10:33:59 | 00,019,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mqbkup.exe
[2009/02/07 10:33:41 | 00,033,280 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\clipsrv.exe
[2009/02/07 10:33:29 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\notepad.exe
[2009/02/07 10:33:27 | 00,055,296 | —- | M] () – C:\WINDOWS\System32\dvdplay.exe
[2009/02/07 10:33:26 | 00,053,760 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\narrator.exe
[2009/02/07 10:33:26 | 00,053,248 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ipv6.exe
[2009/02/07 10:33:17 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\clipbrd.exe
[2009/02/07 10:33:16 | 00,105,472 | —- | M] (Microsoft Corp. and Executive Software International, Inc.) – C:\WINDOWS\System32\dfrgntfs.exe
[2009/02/07 10:33:15 | 00,120,832 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\gpresult.exe
[2009/02/07 10:33:15 | 00,114,688 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\calc.exe
[2009/02/07 10:33:14 | 00,114,688 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iexpress.exe
[2009/02/07 10:33:13 | 00,119,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\winmine.exe
[2009/02/07 10:33:12 | 00,117,248 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mqtgsvc.exe
[2009/02/07 10:33:11 | 00,111,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\netdde.exe
[2009/02/07 10:33:10 | 00,109,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\progman.exe
[2009/02/07 10:33:09 | 00,121,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\schtasks.exe
[2009/02/07 10:33:09 | 00,107,520 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rsnotify.exe
[2009/02/07 10:33:08 | 00,106,496 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\sysocmgr.exe
[2009/02/07 10:33:07 | 00,087,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\diantz.exe
[2009/02/07 10:33:07 | 00,082,944 | —- | M] (Microsoft Corp. and Executive Software International, Inc.) – C:\WINDOWS\System32\dfrgfat.exe
[2009/02/07 10:33:06 | 00,083,456 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dpvsetup.exe
[2009/02/07 10:33:06 | 00,082,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\eventtriggers.exe
[2009/02/07 10:33:05 | 00,098,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\verifier.exe
[2009/02/07 10:33:03 | 00,080,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\charmap.exe
[2009/02/07 10:33:03 | 00,069,632 | —- | M] ( U.S. Robotics Corporation) – C:\WINDOWS\System32\usrshuta.exe
[2009/02/07 10:33:01 | 00,077,824 | —- | M] (U.S. Robotics Corporation) – C:\WINDOWS\System32\usrmlnka.exe
[2009/02/07 10:33:00 | 00,086,016 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\netsh.exe
[2009/02/07 10:33:00 | 00,076,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\nslookup.exe
[2009/02/07 10:33:00 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\magnify.exe
[2009/02/07 10:32:59 | 00,184,320 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\accwiz.exe
[2009/02/07 10:32:59 | 00,078,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tlntsess.exe
[2009/02/07 10:32:59 | 00,075,776 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\telnet.exe
[2009/02/07 10:32:58 | 00,086,016 | —- | M] (Primax Electronics Ltd.) – C:\WINDOWS\System32\PELMICED.EXE
[2009/02/07 10:32:58 | 00,077,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tasklist.exe
[2009/02/07 10:32:58 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\odbcconf.exe
[2009/02/07 10:32:57 | 00,076,288 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\taskkill.exe
[2009/02/07 10:32:56 | 00,077,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\sdbinst.exe
[2009/02/07 10:32:56 | 00,077,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rtcshare.exe
[2009/02/07 10:32:55 | 00,098,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ahui.exe
[2009/02/07 10:32:55 | 00,077,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\shrpubw.exe
[2009/02/07 10:32:37 | 00,073,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tlntsvr.exe
[2009/02/07 10:30:54 | 00,135,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\taskmgr.exe
[2009/02/07 10:09:05 | 00,042,496 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ftp.exe
[2009/02/07 09:57:20 | 00,737,280 | —- | M] (Indigo Rose Corporation) – C:\WINDOWS\iun6002.exe
[2009/02/07 09:36:38 | 00,035,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rcimlby.exe
[2009/02/07 09:34:19 | 00,100,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\logagent.exe
[2009/02/07 09:34:18 | 00,135,168 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cscript.exe
[2009/02/07 09:34:16 | 00,155,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wscript.exe
[2009/02/07 09:34:08 | 00,100,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\logagent.exe
[2009/02/07 09:34:05 | 00,135,168 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cscript.exe
[2009/02/07 09:34:04 | 00,155,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wscript.exe
[2009/02/07 09:29:41 | 00,420,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ntvdm.exe
[2009/02/07 09:24:23 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drwtsn32.exe
[2009/02/07 09:24:00 | 00,343,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mspaint.exe
[2009/02/07 09:21:28 | 00,010,752 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dumprep.exe
[2009/02/07 09:19:54 | 00,180,224 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dwwin.exe
[2009/02/07 09:17:42 | 00,031,744 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ntsd.exe
[2009/02/07 09:17:36 | 00,070,656 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2009/02/07 09:17:27 | 00,011,776 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\regsvr32.exe
[2009/02/07 09:17:24 | 00,045,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\shmgrate.exe
[2009/02/07 09:17:16 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieudinit.exe
[2009/02/07 09:17:14 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe
[2009/02/07 09:16:03 | 00,018,432 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ups.exe
[2009/02/07 09:14:52 | 00,005,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllhost.exe
[2009/02/07 09:14:50 | 00,224,768 | —- | M] (Microsoft Corp., Veritas Software) – C:\WINDOWS\System32\dmadmin.exe
[2009/02/07 09:14:44 | 00,005,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cisvc.exe
[2009/02/07 09:14:35 | 00,075,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\locator.exe
[2009/02/07 09:14:13 | 00,283,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\winhlp32.exe
[2009/02/07 09:14:01 | 00,089,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\smlogsvc.exe
[2009/02/07 09:13:46 | 00,032,768 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mnmsrvc.exe
[2009/02/07 09:13:45 | 00,141,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\sessmgr.exe
[2009/02/07 09:13:43 | 00,132,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rsvp.exe
[2009/02/07 09:13:37 | 00,289,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\vssvc.exe
[2009/02/07 09:13:31 | 00,006,144 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msdtc.exe
[2009/02/07 09:13:00 | 00,677,888 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstsc.exe
[2009/02/07 09:12:50 | 00,150,528 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\imapi.exe
[2009/02/07 09:12:40 | 00,028,672 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\verclsid.exe
[2009/02/07 09:11:45 | 00,457,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\searchindexer.exe
[2009/02/07 09:11:07 | 00,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\alg.exe
[2009/02/07 09:03:30 | 00,032,768 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ctfmon.exe
[2009/02/07 09:01:46 | 01,051,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
[2009/02/07 09:00:38 | 00,065,536 | —- | M] (Primax Electronics Ltd.) – C:\WINDOWS\System32\ico.exe
[2009/02/07 08:58:11 | 00,026,112 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\userinit.exe
[2009/02/07 00:23:25 | 00,143,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mobsync.exe
[2009/02/07 00:09:01 | 00,096,256 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msiexec.exe
[2009/02/07 00:08:29 | 00,033,280 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\rundll32.exe
[2009/02/07 00:06:54 | 00,087,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\searchfilterhost.exe
[2009/02/07 00:05:51 | 00,184,832 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\searchprotocolhost.exe
[2009/02/06 23:13:47 | 00,000,630 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - janderson.job
[2009/02/06 22:19:01 | 00,002,011 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton Internet Security.lnk
[2009/02/06 20:30:32 | 00,000,654 | —- | M] () – C:\Documents and Settings\janderson\Desktop\Hijackthis.lnk
[2009/02/06 15:05:32 | 00,000,410 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan for janderson.job
[2009/02/06 14:05:13 | 00,000,078 | —- | M] () – C:\WINDOWS\info.ini
[2009/02/06 09:09:59 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/02/05 19:28:55 | 00,091,520 | —- | M] () – C:\WINDOWS\OptionPCCardInstallerUninstall.exe
[2009/02/05 18:45:02 | 00,065,973 | —- | M] () – C:\WINDOWS\sem_GCXXUninstall.exe
[2009/02/05 18:45:00 | 00,072,967 | —- | M] () – C:\WINDOWS\OptionPluss_PCCardInstallerUninstall.exe
[2009/02/03 13:32:24 | 00,000,250 | —- | M] () – C:\WINDOWS\system.ini
[2009/02/02 23:56:15 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/02/02 21:53:36 | 00,000,182 | —- | M] () – C:\WINDOWS\WININIT.INI
[2009/02/02 21:01:40 | 00,000,937 | —- | M] () – C:\Documents and Settings\janderson\Desktop\Spybot - Search & Destroy.lnk
[2009/02/02 20:45:00 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090202-235615.backup
[2009/02/02 20:43:57 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090202-204500.backup
[2009/02/02 20:32:02 | 00,011,795 | —- | M] () – C:\Documents and Settings\janderson\Desktop\Today.docx
[2009/02/02 20:19:27 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/02/02 19:24:09 | 00,028,160 | —- | M] () – C:\Documents and Settings\janderson\My Documents\Jim.doc
[2009/02/02 18:38:01 | 00,042,496 | —- | M] () – C:\Documents and Settings\janderson\My Documents\surgical curriculum extracts.doc
[2009/02/02 18:02:28 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090202-204357.backup
[2009/02/02 17:56:40 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090202-180228.backup
[2009/02/02 17:54:18 | 00,273,920 | —- | M] () – C:\Documents and Settings\janderson\My Documents\Copy of bsg_programme_FINAL_09.xls
[2009/01/30 16:10:13 | 00,000,026 | —- | M] () – C:\WINDOWS\NwtGatewayConfig.ini
[2009/01/30 07:08:21 | 00,307,719 | —- | M] () – C:\Documents and Settings\janderson\My Documents\standard-tube-map.pdf
[2009/01/29 09:09:06 | 00,080,695 | —- | M] () – C:\Documents and Settings\janderson\My Documents\Tutorials_Certificate.pdf
[2009/01/27 13:40:24 | 00,010,240 | -HS- | M] () – C:\Documents and Settings\janderson\My Documents\Thumbs.db
[2009/01/19 20:36:25 | 00,080,384 | —- | M] () – C:\Documents and Settings\janderson\My Documents\TC contacts JAN 2009.doc
[2009/01/10 01:35:28 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe

========== LOP Check ==========

[2009/02/02 21:33:53 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2007/08/02 20:17:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/09/12 08:09:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/09/12 08:09:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/10/28 17:53:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2009/02/02 21:40:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd
[2007/07/20 09:00:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GlobeTrotter Mobility Manager
[2008/10/19 21:30:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2008/12/01 15:38:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2006/08/21 10:31:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intel
[2009/02/08 11:00:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/12/09 11:58:02 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/12/04 07:49:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2007/08/02 08:43:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Mozilla
[2007/05/15 14:31:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Network Associates
[2008/12/01 15:41:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nokia
[2008/12/09 11:55:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2006/08/21 09:15:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2007/08/02 17:48:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Skype
[2006/12/25 13:55:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony Corporation
[2009/02/02 23:44:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/02/07 17:32:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/02/08 10:43:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/07/10 10:47:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2008/11/30 15:49:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2006/12/25 13:54:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VAIO Media Platform
[2007/05/15 15:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/10/28 19:29:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/02/06 22:08:01 | 00,000,000 | RH-D | M] – C:\Documents and Settings\janderson\Application Data
[2007/08/03 16:34:44 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Adobe
[2007/08/02 09:15:53 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\AdobeUM
[2009/02/07 09:57:39 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Alice Systems
[2008/12/01 15:18:04 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Any Video Converter
[2007/09/12 09:18:35 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Apple Computer
[2008/10/28 18:31:12 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\AVS4YOU
[2008/09/25 17:06:35 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Bytemobile
[2006/08/21 13:14:19 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Google
[2007/10/25 17:16:46 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Help
[2006/08/18 15:47:10 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Identities
[2006/08/21 10:31:42 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Intel
[2007/09/11 17:23:20 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\InterVideo
[2007/07/06 12:44:06 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Macromedia
[2008/12/02 08:16:54 | 00,000,000 | –SD | M] – C:\Documents and Settings\janderson\Application Data\Microsoft
[2008/07/10 10:46:56 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Mozilla
[2007/07/06 02:56:59 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\MSNInstaller
[2008/01/22 14:18:11 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Nokia
[2008/01/22 14:18:25 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\PC Suite
[2007/08/02 08:44:41 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\PC Tools
[2006/12/25 14:07:42 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Protector Suite
[2008/03/31 07:33:41 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Real
[2009/01/01 22:41:58 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Skype
[2009/01/01 16:39:39 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\skypePM
[2007/07/13 13:40:01 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\sony
[2008/11/02 00:36:02 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Sony Corporation
[2009/02/06 23:15:28 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Symantec
[2007/08/02 08:46:52 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Talkback
[2008/07/10 10:46:52 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\TomTom
[2008/01/22 10:16:31 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Toshiba
[2008/11/12 12:22:38 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\U3
[2008/10/18 14:06:37 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Windows Desktop Search
[2008/10/27 01:33:42 | 00,000,000 | —D | M] – C:\Documents and Settings\janderson\Application Data\Windows Search
[2009/02/06 09:09:59 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 12:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/06 23:13:47 | 00,000,630 | —- | M] () – C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - janderson.job
[2009/02/06 15:05:32 | 00,000,410 | —- | M] () – C:\WINDOWS\Tasks\Norton Security Scan for janderson.job
[2009/02/08 10:39:20 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 98 bytes -> %AllUsersProfile%\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable
< End of report >


OTListIt Extras logfile created on: 08/02/2009 10:57:33 - Run
OTListIt2 by OldTimer - Version 2.0.0.9 Folder = C:\Documents and Settings\janderson\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 0.96 Gb Available Physical Memory | 47.96% Memory free
3.85 Gb Paging File | 2.89 Gb Available in Paging File | 75.05% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 46.57 Gb Total Space | 11.67 Gb Free Space | 25.06% Space Free | Partition Type: NTFS
Drive D: | 38.67 Gb Total Space | 34.00 Gb Free Space | 87.93% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NET-VTAILOR
Current User Name: janderson
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\WINDOWS\System32\winhlp32.exe File not found
.hta [@ = htafile] – C:\WINDOWS\system32\mshta.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.inf [@ = inffile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.ini [@ = inifile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.js [@ = JSFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\WINDOWS\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) File not found
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)
C:\Program Files\T-Mobile\Communication Center\AutoUpdateSrv.exe:*:Disabled:AutoUpdateSrv Application File not found
C:\WINDOWS\system32\lxdjcoms.exe:*:Enabled:Lexmark Communications System ( )
C:\Program Files\Lexmark 1400 Series\lxdjamon.exe:*:Enabled:Lexmark Device Monitor (Lexmark)
C:\Program Files\Lexmark 1400 Series\app4r.exe:*:Enabled:BorgListener ()
C:\Program Files\Lexmark 1400 Series\Wireless\lxdjwpss.exe:*:Enabled: (Lexmark International, Inc.)
C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdjtime.exe:*:Enabled: (Lexmark International, Inc.)
C:\Program Files\TVAnts\Tvants.exe:*:Enabled:TVAnts File not found
C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdjpswx.exe:*:Enabled: ()
C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process (Nokia Corporation)
C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater (Nokia Corporation)
C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdjwbgw.exe:*:Enabled: (Copyright 2006-2007 Lexmark International, Inc. All rights reserved.)
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook (Microsoft Corporation)
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype (Skype Technologies S.A.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) File not found
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)
C:\Program Files\T-Mobile\Communication Center\AutoUpdateSrv.exe:*:Enabled:AutoUpdateSrv Application File not found
C:\Program Files\Common Files\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process (Nokia Corporation)
C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater (Nokia Corporation)
C:\Documents and Settings\janderson\Local Settings\Temp\lxdj\wireless\ENGLISH\lxdjwpss.exe:*:Enabled: File not found
C:\WINDOWS\system32\lxdjcfg.exe:*:Enabled: ( )
C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdjjswx.exe:*:Enabled: ()
C:\Program Files\Lexmark 1400 Series\lxdjamon.exe:*:Enabled:Device Monitor Application (Lexmark)
C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service (Kontiki Inc.)
C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdjpswx.exe:*:Enabled: ()
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook (Microsoft Corporation)
C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove (Microsoft Corporation)
C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote (Microsoft Corporation)
C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox (Mozilla Corporation)
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype (Skype Technologies S.A.)
C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdjwbgw.exe:*:Enabled: (Copyright 2006-2007 Lexmark International, Inc. All rights reserved.)
C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdjtime.exe:*:Enabled: (Lexmark International, Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00F8608F-BA6A-4B32-843A-1A568ACD1198}" = VAIO Sea Wallpaper
"{013E1BA8-C815-4E27-BCB9-D6B1B2E24094}" = SonicStage Mastering Studio Audio Filter Custom Preset
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony Video Shared Library
"{0332234E-09D1-4B74-A5F3-73E34BA29F5B}" = Nokia Software Updater
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio DigitalMedia Data
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306
"{0C846973-F9D7-4F05-92E1-81068EA267EE}" = Symantec Real Time Storage Protection Component
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Toolbar
"{1417F599-1DBD-4499-9375-B2813E9F890C}" = VAIO Camera Utility
"{1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C}" = PC Connectivity Solution
"{1BEF9285-5530-426B-A5F1-5836B95C7EB1}" = VAIO Original Screen Saver
"{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{23BE930B-6AC4-4D0D-B5C3-03062A2BF2A3}" = OpenMG AAC Add-on Module 1.0.00
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{24960AC2-C413-4A86-B1C1-E4CCADCA44D3}" = VAIO Information FLOW
"{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter
"{2A0A6470-FD0F-4F45-9B11-85F3167DB943}" = Nokia Flashing Cable Driver
"{2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5}" = Wireless Switch Setting Utility
"{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}" = SymNet
"{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}" = Component Framework
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3633BA28-67CE-4AC8-A677-3406CA84C3D8}" = OpenMG Secure Module 4.5.01
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector
"{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}" = Google Earth
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{55A6283C-638A-4EE0-B491-51118554BDA2}" = Norton Confidential Core
"{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 5.0
"{5624C000-B109-11D4-9DB4-00E0290FCAC5}" = VPN Client
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 5.0
"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series
"{5958CAC6-373E-402F-84FE-0A699AA920B9}" = LAN Setting Utility
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{5DF3D1BB-894E-4DCD-8275-159AC9829B43}" = McAfee VirusScan Enterprise
"{61D6E4FB-1A62-4EB1-BE56-929B00C155CF}" = Wireless LAN Starter
"{62120008-8E1E-4807-860D-A8B48F8552DB}" = Norton Protection Center
"{63B8FB69-A1B6-425D-B67D-5257B7A1F663}" = Image Converter 2 Plus
"{668B1BD6-4593-4959-970E-249AFFE6F35C}" = VOR
"{685BCC47-B8EC-45EC-BBCE-77DF2451502C}" = DVgate Plus
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74EC78BC-B379-4E29-9006-8F161DCAABA6}" = Apple Software Update
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit
"{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}" = Norton AntiVirus
"{785EB1D4-ECEC-4195-99B4-73C47E187721}" = VAIO Media Integrated Server 5.0
"{795AF20A-51C5-4BAF-9EF5-AA38105C6141}" = Norton Security Scan
"{83CDA18E-0BF3-4ACA-872C-B4CDABF2360E}" = VAIO Update 4
"{8696ED8F-F797-40F0-A52A-CF6552E338E1}" = Novatel Wireless Mobile Broadband Generic Drivers
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{8DF4C627-4AF3-4245-9F13-3518FC8584DC}" = Protector Suite QL 5.3
"{8FFC924C-ED06-44CB-8867-3CA778ECE903}" = Adobe Help Center 2.0
"{900A92BA-19EF-4A34-86CF-7B6C85BDD971}" = VC_MergeModuleToMSI
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{9080C5D2-82FA-452A-87FA-CBB4B05D67A5}" = VPS
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for VAIO
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}" = QuickTime
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9E319E96-ED8E-4B01-9775-C521A1869A25}" = VAIO Power Management
"{9E407618-D9CD-4F39-9490-9ED45294073D}" = Click to DVD 2.0.03 Menu Data
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 4.0
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A52415E5-CA1E-44DE-9EDC-D412F31D271C}" = Google Photos Screensaver
"{A6C38A49-367A-443D-BBEA-403A3BF8C877}" = GlobeTrotter Mobility Manager
"{A947C2B3-7445-42C4-9063-EE704CACCB22}" = VAIO Hardware Diagnostics
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio DigitalMedia Audio
"{ABBD2A2E-2424-4078-966F-F319A88D5F21}" = VAIO Starfish Wallpaper
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.1
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}" = VAIO Media Registration Tool 5.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio DigitalMedia Copy
"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B502B428-3386-40A9-98DB-079AAB72E64F}" = mEoU
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{BBFFB027-7D53-4E1B-95BC-35A2216D1D60}" = VAIO Long Battery Life Wallpaper
"{BF3B304B-8A18-452D-A19F-6012CA8418D7}" = SonicStage Mastering Studio 2.2
"{C1C185CA-C531-49F5-A6FA-B838405A049D}" = Norton Internet Security
"{C27BF761-C499-488D-A964-A3718BC6EC3E}" = DSD Direct
"{C518C7BF-A345-4019-815B-FFDF32EBCAD9}" = VAIO HDD Protection
"{C5B2E36F-802E-4A6C-9251-18574BEFDDA2}" = SymNet
"{C89EB8CD-675F-44F4-9729-4C9A8FAC2D4F}" = DSD Playback Plug-in 1.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBDE9C7D-CF52-4558-B23E-B66359CB586A}" = Nokia Connectivity Cable Driver
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D466F3D9-510C-4729-B7D4-2E70490E4CDF}" = BBC iPlayer Download Manager
"{D5577624-0626-4C4B-87AA-D966DA1739D6}" = Nokia PC Suite
"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}" = Norton AntiVirus Help
"{E5E6E687-1033-0000-0000-000000000002}" = Adobe Acrobat 7.0 Elements
"{E809063C-51A3-4269-8984-D1EB742F2151}" = Click to DVD 2.5.30
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{E9AE9A91-AB45-4321-87BD-AD34855D944F}" = Chessmaster 10th Edition
"{EBB7C1C1-D439-4D9B-9FDC-954C10F266B0}" = Adobe Photoshop Elements 4.0
"{EC54CAFB-9467-4A05-9209-898E7DD58EA7}" = BlackBerry Desktop Software 4.0.1
"{EE7EB179-5AA2-4B28-AC92-5CBAAF82BA7F}" = SonicStage Mastering Studio Plugins
"{EF3D45BB-2260-4008-88EA-492E7744A9DF}" = Sony Utilities DLL
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}" = VAIO Event Service
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FB714F13-10C9-48DB-91C9-DDBCCCBF9370}" = VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents
"{FC37C108-821D-4EDE-8F40-D5B497586805}" = VAIO Control Center
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0)
"6A630DCEC5EEC912115F2FF59D8C2C769798D930" = Windows Driver Package - Nokia Modem (10/12/2007 3.6)
"819D45A9F73817F5B6D7C71A33ADAB88C5DA1765" = Windows Driver Package - Nokia Modem (08/03/2007 6.84.0.2)
"9CD348AE9C64C4B939B624E8E24F3903EFDFC82B" = Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1)
"Adobe Acrobat 7.0 Elements" = Adobe Acrobat 7.0 Elements
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 4" = Adobe Photoshop Elements 4.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"BBC iPlayer Download Manager" = BBC iPlayer Download Manager
"BlackBerry_{EC54CAFB-9467-4A05-9209-898E7DD58EA7}" = BlackBerry Desktop Software 4.0.1
"C5A76DC11BABDA0A881E7BE8DDEB641365A77FFD" = Windows Driver Package - Nokia Modem (05/22/2008 3.8)
"CBF192A85B624E32B8D19ADEEF2DCFC5BC3AA73A" = Windows Driver Package - Nokia Modem (03/05/2008 3.7)
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_20030003" = HDAUDIO SoftV92 Data Fax Modem with SmartCP
"DocuCabinet V2_is1" = DocuCabinet Version 2.2
"ENTERPRISER" = Microsoft Office Enterprise 2007
"F1CB0AC2D40DDCFCA6933082B115073476C155DE" = Windows Driver Package - Nokia Modem (08/03/2007 3.2)
"HijackThis" = HijackThis 1.99.1
"Hijackthis_is1" = Hijackthis 1.99.1
"hp deskjet 3320 series" = hp deskjet 3320 series (Remove only)
"Huawei E620 PC Card" = Huawei E620 PC Card
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{23BE930B-6AC4-4D0D-B5C3-03062A2BF2A3}" = OpenMG AAC Add-on Module 1.0.00
"InstallShield_{3633BA28-67CE-4AC8-A677-3406CA84C3D8}" = OpenMG Secure Module 4.5.01
"InstallShield_{668B1BD6-4593-4959-970E-249AFFE6F35C}" = VAIO Online Registration (English)
"InstallShield_{9080C5D2-82FA-452A-87FA-CBB4B05D67A5}" = VAIO Product Survey
"InstallShield_{E9AE9A91-AB45-4321-87BD-AD34855D944F}" = Chessmaster 10th Edition
"Lexmark 1400 Series" = Lexmark 1400 Series
"McAfee Anti-Spyware Enterprise Module" = McAfee Anti-Spyware Enterprise Module
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MouseSuite98" = Sony USB Mouse
"Mozilla Firefox (3.0.4)" = Mozilla Firefox (3.0.4)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Nokia PC Suite" = Nokia PC Suite
"Novatel_700_800_PCCardInstaller" = Novatel 700/800 driver
"NSSSetup.{795AF20A-51C5-4BAF-9EF5-AA38105C6141}" = Norton Security Scan (Symantec Corporation)
"NVIDIA Drivers" = NVIDIA Drivers
"OpenMG HotFix4.5-06-05-10-01" = OpenMG Limited Patch 4.5-06-05-12-01
"OptionPCCardInstaller" = Option PC Cards driver package
"OptionPluss_PCCardInstaller" = Option GT HSDPA driver suite
"Picasa2" = Picasa 2
"ProInst" = Intel® PROSet/Wireless Software
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"RealPlayer 6.0" = RealPlayer
"sem_GCXX" = Sony Ericsson GCXX (75/79/82/83/85/89)
"Shockwave" = Shockwave
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SmartSync Pro" = SmartSync Pro
"Spyware Doctor" = Spyware Doctor 5.5
"SymSetup.{C1C185CA-C531-49F5-A6FA-B838405A049D}" = Norton Internet Security (Symantec Corporation)
"TomTom HOME" = TomTom HOME
"WGA" = Windows Genuine Advantage Validation Tool
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01005" = Microsoft User-Mode Driver Framework Feature Pack 1.5

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 07/02/2009 18:39:50 | Computer Name = NET-VTAILOR | Source = Alert Manager Event Interface | ID = 257
Description = VirusScan Enterprise: The file C:\quarantine\rc[1].htm.Vir.1 is infected
with the JS/Generic Exploit.j Trojan. No cleaner available, quarantined successfully
. Detected using Scan engine version 5300 DAT version 5514.(from NET-VTAILOR IP
192.168.0.5 user NT AUTHORITY\SYSTEM running VirusScan Enter 8.0 OAS)

Error - 07/02/2009 18:39:50 | Computer Name = NET-VTAILOR | Source = Alert Manager Event Interface | ID = 257
Description = VirusScan Enterprise: The file C:\quarantine\rc[2].htm.Vir is infected
with the JS/Generic Exploit.j Trojan. No cleaner available, quarantined successfully
. Detected using Scan engine version 5300 DAT version 5514.(from NET-VTAILOR IP
192.168.0.5 user NT AUTHORITY\SYSTEM running VirusScan Enter 8.0 OAS)

Error - 07/02/2009 18:47:45 | Computer Name = NET-VTAILOR | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error Initialization of the COM subsystem failed.
Error code: 0x8007041D.

Error - 08/02/2009 06:39:33 | Computer Name = NET-VTAILOR | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 08/02/2009 06:39:34 | Computer Name = NET-VTAILOR | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.

Error - 08/02/2009 06:39:39 | Computer Name = NET-VTAILOR | Source = Application Error | ID = 1000
Description = Faulting application VsTskMgr.exe, version 8.0.0.912, faulting module
unknown, version 0.0.0.0, fault address 0x6362c99b.

Error - 08/02/2009 06:42:05 | Computer Name = NET-VTAILOR | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.

Error - 08/02/2009 06:43:00 | Computer Name = NET-VTAILOR | Source = Application Error | ID = 1004
Description = Faulting application VsTskMgr.exe, version 8.0.0.912, faulting module
unknown, version 0.0.0.0, fault address 0x6362c99b.

Error - 08/02/2009 06:45:24 | Computer Name = NET-VTAILOR | Source = Application Error | ID = 1001
Description = Fault bucket 1133418613.

Error - 08/02/2009 06:54:58 | Computer Name = NET-VTAILOR | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error Initialization of the COM subsystem failed.
Error code: 0x8007041D.

[ OSession Events ]
Error - 28/11/2008 16:46:10 | Computer Name = NET-VTAILOR | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6211.1000, Microsoft Office Version: 12.0.6215.1000. This session lasted 2075
seconds with 2040 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 08/02/2009 06:40:09 | Computer Name = NET-VTAILOR | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 08/02/2009 06:40:32 | Computer Name = NET-VTAILOR | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Network Associates Task
Manager service to connect.

Error - 08/02/2009 06:40:32 | Computer Name = NET-VTAILOR | Source = Service Control Manager | ID = 7000
Description = The Network Associates Task Manager service failed to start due to
the following error: %%1053

Error - 08/02/2009 06:40:32 | Computer Name = NET-VTAILOR | Source = Service Control Manager | ID = 7023
Description = The KService service terminated with the following error: %%2147500037

Error - 08/02/2009 06:40:32 | Computer Name = NET-VTAILOR | Source = Service Control Manager | ID = 7000
Description = The VAIO Cooporated Initialisation service failed to start due to
the following error: %%2

Error - 08/02/2009 06:54:58 | Computer Name = NET-VTAILOR | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service LiveUpdate
with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}

Error - 08/02/2009 06:54:58 | Computer Name = NET-VTAILOR | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LiveUpdate service to
connect.

Error - 08/02/2009 06:55:14 | Computer Name = NET-VTAILOR | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.

Error - 08/02/2009 06:55:32 | Computer Name = NET-VTAILOR | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service LiveUpdate
with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}

Error - 08/02/2009 06:55:32 | Computer Name = NET-VTAILOR | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LiveUpdate service to
connect.


< End of report >


Thanks again
Hello thedoce123

First there are a couple of unidentified files on the system that I would like to get analyzed.

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • One at a time - Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:

    • C:\WINDOWS\info.ini
    • C:\WINDOWS\QTFont.qfn
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Next:

I need you to disable Spybot's Teatimer before we begin, as it will interfere with the fix.
To do this can you start Spybot and go to the Mode button and select Advanced. Go to Tools > Resident and uncheck the box next to Tea-Timer.
Make sure that the icon in the system tray is no longer there. If it is, just right click on it and select "Exit".

Next:

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please click OTMoveIt3 and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Services

:Reg

:Files
C:\WINDOWS\kernel32.exe

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot
  • Return to OTMoveIt3, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Next:

Download avz4.zip from here
  • Unzip it to your desktop to a folder named avz4
  • Double click on AVZ.exe to run it.
  • Run an update by clicking the Auto Update button on the Right of the Log window: [external image: Posted Image]
  • Click Start to begin the update
Note: If you recieve an error message, chose a different source, then click Start again
  • After the update, from the "File" menu, choose "Standard Scripts"
  • Put a check next to item 2: Advanced System Investigation
  • Click Execute selected scripts
  • At the next prompt, click the OK button
  • Let the scan run and click "OK" when the completion prompt pops up
  • Now Close out of the Standard Scripts window, and exit AVZ
  • Navigate to the avz4 folder and locate the folder LOG
  • Inside the LOG folder you will find virusinfo_syscheck.htm and virusinfo_syscheck.zip
  • Attach virusinfo_syscheck.htm to your next reply.


In your next response I need:


  • OTMoveIt log
  • VirScan analysis for both files (please identify which is which)
  • virusinfo_syscheck.htm
Also, please advise how your computer is running now.
CatByte Thanks for the advice. I have done as requested. Needed a reboot after OTMoveIt3. Still having error message and close down of Vs Tsk Mgr.exe on bootup. A little slow but much better. Icons eventually load after closedown of Vs Tsk Mgr.exe and background appears. Closedown of boxes very slow after running AVZ. I have not tried loading any new software until this is sorted. Many thanks:C:\WINDOWS\info.ini scan result:
VirSCAN.org Scanned Report :
Scanned time : 2009/02/08 15:54:30 (GMT)
Scanner results: All Scanners reported not find malware!
File Name : info.ini
File Size : 78 byte
File Type : ASCII text, with CRLF line terminators
MD5 : d191a4a98ba90e788421cb3f94bf99e1
SHA1 : 7232cf18f1fed4ca665c001f2707ae03c7986c81
Online report : http://virscan.org/report/40df27362104ca1d…5f6cde92ab.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.29 20090208203155 2009-02-08 3.22 -
AhnLab V3 2009.02.08.00 2009.02.08 2009-02-08 2.00 -
AntiVir 7.9.0.76 7.1.1.241 2009-02-07 1.89 -
Antiy 2.0.18 20090206.2159922 2009-02-06 0.02 -
Authentium 5.1.1 200902071429 2009-02-07 1.09 -
AVAST! 3.0.1 090207-0 2009-02-07 0.81 -
AVG 7.5.52.442 270.10.19/1939 2009-02-07 1.88 -
BitDefender 7.81008.2640088 7.23559 2009-02-08 2.45 -
CA (VET) 9.0.0.143 31.6.6346 2009-02-07 4.54 -
ClamAV 0.94.2 8965 2009-02-08 0.00 -
Comodo 3.0 971 2009-02-08 1.12 -
CP Secure 1.1.0.715 2009.02.07 2009-02-07 7.01 -
Dr.Web 4.44.0.9170 2009.02.08 2009-02-08 3.94 -
F-Prot 4.4.4.56 20090207 2009-02-07 1.07 -
F-Secure 5.51.6100 2009.02.08.02 2009-02-08 0.04 -
Fortinet 2.81-3.117 10.12 2009-02-07 0.19 -
GData 19.2915/19.216 20090208 2009-02-08 3.54 -
ViRobot 20090206 2009.02.06 2009-02-06 0.57 -
Ikarus T3.1.01.45 2009.02.08.72273 2009-02-08 3.64 -
JiangMin 11.0.706 2009.02.08 2009-02-08 2.11 -
Kaspersky 5.5.10 2009.02.08 2009-02-08 0.02 -
KingSoft 2008.9.8.18 2009.2.8.20 2009-02-08 0.74 -
McAfee 5.3.00 5519 2009-02-07 3.14 -
Microsoft 1.4306 2009.02.08 2009-02-08 4.54 -
mks_vir 2.01 2009.02.07 2009-02-07 2.57 -
Norman 6.00.02 6.00.00 2009-02-06 8.01 -
Panda 9.05.01 2009.02.08 2009-02-08 1.52 -
Trend Micro 8.700-1004 5.822.40 2009-02-08 0.02 -
Quick Heal 10.00 2009.02.07 2009-02-07 0.88 -
Rising 20.0 21.15.50.00 2009-02-07 0.25 -
Sophos 2.83.3 4.38 2009-02-08 2.33 -
Sunbelt 4804 4804 2009-02-06 0.85 -
Symantec 1.3.0.24 20090207.003 2009-02-07 0.20 -
nProtect 20090208.01 3115293 2009-02-08 4.02 -
The Hacker [removed] v00249 2009-02-08 0.47 -
VBA32 3.12.8.12 20090207.1057 2009-02-07 1.59 -
VirusBuster 4.5.11.10 10.101.6/894383 2009-02-08 0.00 -
C:\WINDOWS\QTFont.qfn scan report
VirSCAN.org Scanned Report :
Scanned time : 2009/02/08 15:57:42 (GMT)
Scanner results: All Scanners reported not find malware!
File Name : QTFont.qfn
File Size : 54156 byte
File Type : TrueType font data
MD5 : dba91cd5a3a68302967c03213e52bde8
SHA1 : 8188a5832590c810b08ee3a2f1567afcdd094108
Online report : http://virscan.org/report/dba91cd5a3a68302…213e52bde8.html





Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared [removed] 20090208203155 2009-02-08 2.26 -
AhnLab V3 2009.02.08.00 2009.02.08 2009-02-08 1.14 -
AntiVir 7.9.0.76 7.1.1.241 2009-02-07 1.93 -
Antiy 2.0.18 20090206.2159922 2009-02-06 0.02 -
Authentium 5.1.1 200902071429 2009-02-07 1.09 -
AVAST! 3.0.1 090207-0 2009-02-07 0.81 -
AVG 7.5.52.442 270.10.19/1939 2009-02-07 1.88 -
BitDefender 7.81008.2640088 7.23559 2009-02-08 2.47 -
CA (VET) 9.0.0.143 31.6.6346 2009-02-07 4.14 -
ClamAV 0.94.2 8965 2009-02-08 0.00 -
Comodo 3.0 971 2009-02-08 0.91 -
CP Secure 1.1.0.715 2009.02.07 2009-02-07 7.00 -
Dr.Web 4.44.0.9170 2009.02.08 2009-02-08 3.96 -
F-Prot 4.4.4.56 20090207 2009-02-07 1.07 -
F-Secure 5.51.6100 2009.02.08.02 2009-02-08 0.04 -
Fortinet 2.81-3.117 10.12 2009-02-07 0.20 -
GData 19.2915/19.216 20090208 2009-02-08 3.17 -
ViRobot 20090206 2009.02.06 2009-02-06 0.41 -
Ikarus T3.1.01.45 2009.02.08.72273 2009-02-08 3.66 -
JiangMin 11.0.706 2009.02.08 2009-02-08 1.44 -
Kaspersky 5.5.10 2009.02.08 2009-02-08 0.02 -
KingSoft 2008.9.8.18 2009.2.8.20 2009-02-08 0.63 -
McAfee 5.3.00 5519 2009-02-07 3.12 -
Microsoft 1.4306 2009.02.08 2009-02-08 7.20 -
mks_vir 2.01 2009.02.07 2009-02-07 2.61 -
Norman 6.00.02 6.00.00 2009-02-06 8.01 -
Panda 9.05.01 2009.02.08 2009-02-08 1.58 -
Trend Micro 8.700-1004 5.822.40 2009-02-08 0.03 -
Quick Heal 10.00 2009.02.07 2009-02-07 0.91 -
Rising 20.0 21.15.50.00 2009-02-07 0.26 -
Sophos 2.83.3 4.38 2009-02-08 2.32 -
Sunbelt 4804 4804 2009-02-06 0.92 -
Symantec 1.3.0.24 20090207.003 2009-02-07 0.18 -
nProtect 20090208.01 3115293 2009-02-08 4.05 -
The Hacker [removed] v00249 2009-02-08 0.51 -
VBA32 3.12.8.12 20090207.1057 2009-02-07 1.49 -
VirusBuster 4.5.11.10 10.101.6/894383 2009-02-08 1.11 -

MOVE IT LOG:
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\WINDOWS\kernel32.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\JANDER~1\LOCALS~1\Temp\NGLALog.txt scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\inf1clrg.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\JET35BC.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\JET3A64.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\JET3A8E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_12b4.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\WFV49.tmp scheduled to be deleted on reboot.
Windows Temp folder emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
Error: Unable to interpret <[Reboot> in the current context!

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02082009_160808

Files moved on Reboot…
C:\DOCUME~1\JANDER~1\LOCALS~1\Temp\NGLALog.txt moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\WINDOWS\temp\inf1clrg.tmp moved successfully.
File C:\WINDOWS\temp\JET35BC.tmp not found!
File C:\WINDOWS\temp\JET3A64.tmp not found!
File C:\WINDOWS\temp\JET3A8E.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_12b4.dat not found!
File C:\WINDOWS\temp\WFV49.tmp not found!


My file size was too large to upload. I will try this again with a seperate post below

Thanks again
CatByte still getting error message Upload failed. The file was larger than the available space. File size is 1000KB. What next?
Hi thedoce123,

Things are looking better but we still have more work to do, so stay with me

First

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Next

Download Dr.Web CureIt to the desktop:
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.

In your next post I need
  • MBAM log
  • Dr.Web log (note Dr.Web.csv may have to be named to Dr.Web.txt to upload here)
Hello CatByte I thought I would give you a quick update. I have downloaded the software. When I run the Malwarebytes programme, if I open any other application on the PC whilst this is running, the computer just grinds to a halt, screen freezes and I am unable to shut down any of the programmes properly as they don't respond to anything. The Malwarebytes also stops responding and I am forced to switch off and reboot. After 3 attempts to run the programme this has now dawned on me and so once I have posted this I will dedicated the PC only to this programme in the hope it will finish the run and I can make the post as requested. Sorry!
Hi thedoce123,

We need to make sure the virut infection found by Dr.Web is completely gone, or this can be devastating for your computer. Please delete the old copy of Dr.Web in case it became infected and download and run a fresh copy.

Download Dr.Web CureIt to the desktop:
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.


Next, download and run a fresh copy of OTListIt

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.


Post both Dr.Web.txt and OTListIt logs into your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI