OK, I've
- run combofix with the text you've provided and pasted the log file
- run MBAM and pasted the log file
- run ESET and pasted the log file
- run OTL and pasted the contents of OTL.txt and Extra.txt
Let me know if you need anything else.
Combofix-
ComboFix 10-06-30.03 - jonathan 07/06/2010 16:27:58.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3536.2825 [GMT -4:00]
Running from: c:\documents and settings\jonathan\Desktop\schrauber.exe
Command switches used :: c:\documents and settings\jonathan\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\jonathan\Local Settings\Application Data\kdfwsy
.
((((((((((((((((((((((((( Files Created from 2010-06-06 to 2010-07-06 )))))))))))))))))))))))))))))))
.
2010-06-17 04:41 . 2010-06-17 04:41 0 ----a-w- c:\windows\nsreg.dat
2010-06-17 04:41 . 2010-06-17 04:41 -------- d-----w- c:\documents and settings\jonathan\Local Settings\Application Data\Mozilla
2010-06-14 11:53 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-06 20:26 . 2010-03-23 12:03 -------- d-----w- c:\program files\Symantec AntiVirus
2010-07-06 20:11 . 2010-03-22 20:32 0 ----a-w- c:\documents and settings\jonathan\Local Settings\Application Data\WavXMapDrive.bat
2010-07-06 19:18 . 2010-05-27 17:39 256 ----a-w- c:\windows\system32\pool.bin
2010-06-17 04:49 . 2010-04-02 10:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-17 03:34 . 2010-06-01 13:20 -------- d-----w- c:\program files\QuickTime
2010-06-04 21:36 . 2010-03-17 12:17 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-04 15:00 . 2010-06-04 15:00 -------- d-----w- c:\documents and settings\jonathan\Application Data\webex
2010-06-01 13:21 . 2010-06-01 13:21 -------- d-----w- c:\documents and settings\jonathan\Application Data\Apple Computer
2010-05-29 01:44 . 2010-05-29 01:43 -------- d-----w- c:\program files\Rhapsody
2010-05-27 17:59 . 2010-05-27 17:59 -------- d-----w- c:\documents and settings\jonathan\Application Data\Blackberry Desktop
2010-05-27 17:53 . 2010-05-27 17:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Research In Motion
2010-05-27 17:39 . 2010-05-27 17:39 -------- d-----w- c:\documents and settings\jonathan\Application Data\Research In Motion
2010-05-27 17:38 . 2010-05-27 17:37 -------- d-----w- c:\program files\Common Files\Research In Motion
2010-05-27 17:38 . 2010-03-17 12:13 -------- d-----w- c:\program files\Common Files\Roxio Shared
2010-05-27 17:37 . 2010-05-27 17:37 -------- d-----w- c:\program files\Research In Motion
2010-05-26 02:56 . 2010-05-26 02:56 503808 ----a-w- c:\documents and settings\jonathan\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-1da40877-n\msvcp71.dll
2010-05-26 02:56 . 2010-05-26 02:56 499712 ----a-w- c:\documents and settings\jonathan\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-1da40877-n\jmc.dll
2010-05-26 02:56 . 2010-05-26 02:56 348160 ----a-w- c:\documents and settings\jonathan\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-1da40877-n\msvcr71.dll
2010-05-10 04:21 . 2010-05-10 04:21 -------- d-----w- c:\program files\Windows Media Connect 2
2010-05-06 10:41 . 2008-04-25 16:16 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 06:34 . 2008-04-25 16:16 1860352 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2010-04-02 10:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-04-02 10:46 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 05:30 . 2008-04-25 16:16 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-11 18:20 . 2010-04-11 18:20 13696 ----a-w- c:\windows\system32\drivers\wpsnuio.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]
@="{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}"
[HKEY_CLASSES_ROOT\CLSID\{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}]
2009-11-24 20:48 62832 ----a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}"
[HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}]
2009-11-24 20:48 62832 ----a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-06-19 249856]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-03-17 483420]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2009-03-17 729088]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-26 134656]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-26 166912]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-26 134656]
"OA001Mon"="c:\windows\OA001Mon.exe" [2009-03-30 24576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-03-17 149280]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-02-11 186904]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2009-10-07 2498560]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2009-11-02 657920]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2010-01-05 158592]
"USCService"="c:\program files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe" [2010-01-06 34232]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-07-08 413827]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-06-24 53096]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2008-09-30 125368]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"Boingo Wi-Fi"="c:\program files\Boingo\Boingo Wi-Fi\Boingo.lnk" [2010-07-06 2179]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2010-03-11 648536]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dell ControlPoint System Manager.lnk - c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe [2009-12-10 1338144]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
TdmNotify.lnk - c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe [2009-11-24 132456]
VPN Client.lnk - c:\windows\Installer\{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}\Icon3E5562ED7.ico [2010-3-23 6144]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1919096210-140139084-965413785-500\Scripts\Logoff\0\0]
"Script"=logoff.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1919096210-140139084-965413785-500\Scripts\Logon\0\0]
"Script"=logon.cmd
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [4/19/2007 6:56 AM 133968]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [11/20/2009 6:42 PM 278304]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [12/17/2009 11:45 AM 812448]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [12/17/2009 11:45 AM 27040]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe [12/10/2009 2:09 PM 376608]
R2 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/30/2008 5:41 PM 116664]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [3/17/2010 9:55 AM 112512]
R3 CtAudDrv;Provides advanced audio effects for audio devices.;c:\windows\system32\drivers\CtAudDrv.sys [3/17/2010 8:17 AM 134144]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [3/17/2010 8:17 AM 143968]
R3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [3/17/2010 9:56 AM 33832]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [3/17/2010 9:55 AM 240344]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/28/2010 8:15 AM 102448]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [3/17/2010 9:56 AM 109568]
R3 OA001Afx;Provides a software interface to control audio effects of OA001 camera.;c:\windows\system32\drivers\OA001Afx.sys [3/17/2010 9:56 AM 148056]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [3/17/2010 9:56 AM 133632]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [3/17/2010 9:56 AM 280096]
R3 SRS_PremiumSound_Service;SRS Labs Premium Sound;c:\windows\system32\drivers\SRS_PremiumSound_i386.sys [3/17/2010 8:11 AM 232744]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/25/2008 12:16 PM 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\jonathan\Application Data\Mozilla\Firefox\Profiles\0fenrrmm.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-06 16:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1404)
c:\windows\system32\wvauth.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(1588)
c:\windows\system32\WININET.dll
c:\windows\system32\igfxdo.dll
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-07-06 16:33:16
ComboFix-quarantined-files.txt 2010-07-06 20:33
ComboFix2.txt 2010-07-01 20:51
ComboFix3.txt 2010-06-17 05:44
ComboFix4.txt 2010-06-17 04:32
Pre-Run: 228,827,799,552 bytes free
Post-Run: 228,834,840,576 bytes free
- - End Of File - - 47CE375F6174F2E62EE739C50A8979A7
Here's the MBAM file-
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4284
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/6/2010 4:52:49 PM
mbam-log-2010-07-06 (16-52-49).txt
Scan type: Quick scan
Objects scanned: 160354
Time elapsed: 3 minute(s), 48 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
...and here's the ESET file
C:\Documents and Settings\jonathan\Application Data\Sun\Java\Deployment\cache\6.0\11\31a7d00b-18195695 multiple threats deleted - quarantined
C:\Documents and Settings\jonathan\Application Data\Sun\Java\Deployment\cache\6.0\25\3768c619-2b010948 a variant of Java/Exploit.Agent.NAC trojan deleted - quarantined
...and here's the OTL file
OTL logfile created on: 7/6/2010 5:57:10 PM - Run 1
OTL by OldTimer - Version 3.2.7.1 Folder = C:\Documents and Settings\jonathan\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 73.00% Memory free
5.00 Gb Paging File | 5.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.85 Gb Total Space | 213.04 Gb Free Space | 91.49% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 232.85 Gb Total Space | 213.04 Gb Free Space | 91.49% Space Free | Partition Type: *NT5CSC
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JON-XPLP
Current User Name: jonathan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010/07/06 17:56:09 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\jonathan\Desktop\OTL.exe
PRC - [2010/03/10 22:32:26 | 000,648,536 | ---- | M] (Research In Motion Limited) -- C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
PRC - [2010/01/05 21:23:58 | 000,034,232 | ---- | M] (Broadcom Corporation) -- C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe
PRC - [2010/01/05 15:04:00 | 000,158,592 | ---- | M] (Wave Systems Corp.) -- C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe
PRC - [2009/12/17 11:45:18 | 000,812,448 | ---- | M] (Broadcom Corporation) -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
PRC - [2009/12/17 11:45:18 | 000,027,040 | ---- | M] (Broadcom Corporation) -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
PRC - [2009/12/10 14:12:38 | 001,338,144 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
PRC - [2009/12/10 14:09:28 | 000,376,608 | ---- | M] (Dell Inc.) -- c:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
PRC - [2009/11/24 16:48:36 | 001,148,264 | ---- | M] (Wave Systems Corp.) -- C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
PRC - [2009/11/20 18:42:48 | 000,278,304 | ---- | M] (Dell Inc.) -- c:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
PRC - [2009/11/02 12:40:54 | 000,657,920 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
PRC - [2009/07/08 20:28:42 | 000,365,872 | ---- | M] (Boingo Wireless, Inc.) -- C:\Program Files\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
PRC - [2009/07/08 18:08:30 | 000,413,827 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
PRC - [2009/06/19 09:57:40 | 000,249,856 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/03/29 20:28:54 | 000,024,576 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\OA001Mon.exe
PRC - [2009/03/16 21:57:38 | 000,483,420 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
PRC - [2009/03/16 21:57:26 | 000,254,034 | ---- | M] (IDT, Inc.) -- c:\drivers\audio\R213367\stacsv.exe
PRC - [2009/03/16 21:57:14 | 000,729,088 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\AESTFltr.exe
PRC - [2009/02/26 17:08:20 | 000,165,888 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\igfxext.exe
PRC - [2009/02/11 18:38:40 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009/02/11 18:38:38 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/02/04 22:26:38 | 000,128,232 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2009/01/31 20:15:38 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2009/01/31 18:43:30 | 000,049,250 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2008/11/24 09:56:46 | 000,054,568 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2008/09/30 17:41:14 | 000,125,368 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\VPTray.exe
PRC - [2008/09/30 17:41:08 | 000,116,664 | ---- | M] (symantec) -- C:\Program Files\Symantec AntiVirus\SavRoam.exe
PRC - [2008/09/30 17:41:04 | 001,956,792 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe
PRC - [2008/09/30 17:40:56 | 000,031,160 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe
PRC - [2008/06/24 18:17:38 | 000,169,320 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PRC - [2008/06/24 18:17:36 | 000,191,848 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PRC - [2008/06/24 18:17:34 | 000,053,096 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2008/05/26 23:19:14 | 000,123,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe
PRC - [2008/04/14 08:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/07/26 19:25:20 | 001,181,016 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
PRC - [2007/04/19 06:56:36 | 000,133,968 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\ASF Agent\ASFAgent.exe
PRC - [2004/04/14 10:31:40 | 001,425,424 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
========== Modules (SafeList) ========== MOD - [2010/07/06 17:56:09 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\jonathan\Desktop\OTL.exe
MOD - [2009/02/26 17:08:20 | 000,130,048 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\igfxdo.dll
MOD - [2008/04/14 08:00:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - [2009/12/17 11:45:18 | 000,812,448 | ---- | M] (Broadcom Corporation) [Auto | Running] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe -- (Credential Vault Host Control Service)
SRV - [2009/12/17 11:45:18 | 000,027,040 | ---- | M] (Broadcom Corporation) [Auto | Running] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe -- (Credential Vault Host Storage)
SRV - [2009/12/10 14:09:28 | 000,376,608 | ---- | M] (Dell Inc.) [Auto | Running] -- c:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe -- (dcpsysmgrsvc)
SRV - [2009/11/24 16:48:36 | 001,148,264 | ---- | M] (Wave Systems Corp.) [Auto | Running] -- C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe -- (TdmService)
SRV - [2009/11/20 18:42:48 | 000,278,304 | ---- | M] (Dell Inc.) [Auto | Running] -- c:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe -- (buttonsvc32)
SRV - [2009/11/18 17:35:48 | 001,032,192 | ---- | M] (Wave Systems Corp.) [On_Demand | Stopped] -- C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe -- (SecureStorageService)
SRV - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2009/03/16 21:57:26 | 000,254,034 | ---- | M] (IDT, Inc.) [Auto | Running] -- c:\drivers\audio\R213367\stacsv.exe -- (STacSV)
SRV - [2009/02/11 18:38:40 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®
SRV - [2008/11/12 14:25:48 | 001,273,856 | ---- | M] () [Auto | Stopped] -- C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe -- (tcsd_win32.exe)
SRV - [2008/09/30 17:41:08 | 000,116,664 | ---- | M] (symantec) [Auto | Running] -- C:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam)
SRV - [2008/09/30 17:41:04 | 001,956,792 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2008/09/30 17:40:56 | 000,031,160 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch)
SRV - [2008/08/20 15:50:30 | 000,214,408 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc)
SRV - [2008/06/24 18:17:38 | 000,169,320 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr)
SRV - [2008/06/24 18:17:36 | 000,191,848 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr)
SRV - [2007/09/12 18:27:24 | 002,999,664 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate)
SRV - [2007/07/26 19:25:20 | 001,181,016 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc)
SRV - [2007/04/19 06:56:36 | 000,133,968 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\ASF Agent\ASFAgent.exe -- (ASFAgent)
SRV - [2004/04/14 10:31:40 | 001,425,424 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Running] -- C:\DOCUME~1\jonathan\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010/05/21 18:41:04 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010/05/21 18:41:01 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2010/05/05 02:40:35 | 001,347,504 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100705.002\NAVEX15.SYS -- (NAVEX15)
DRV - [2010/05/05 02:40:26 | 000,085,552 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100705.002\NAVENG.SYS -- (NAVENG)
DRV - [2010/04/11 14:20:34 | 000,013,696 | ---- | M] (Skyhook Wireless) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wpsnuio.sys -- (Wpsnuio)
DRV - [2010/03/23 08:03:36 | 000,123,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2010/01/05 15:03:56 | 000,214,656 | ---- | M] (Wave Systems Corp.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\WavxDMgr.sys -- (WavxDMgr)
DRV - [2009/11/24 11:30:34 | 000,217,136 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2009/11/03 17:40:42 | 000,033,832 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cvusbdrv.sys -- (cvusbdrv)
DRV - [2009/10/07 09:01:32 | 002,649,216 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2009/09/21 15:20:26 | 000,028,632 | ---- | M] (Intel Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\iqvw32.sys -- (NAL)
DRV - [2009/08/04 09:56:28 | 000,240,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1y5132.sys -- (e1yexpress) Intel®
DRV - [2009/06/15 14:05:16 | 000,143,968 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV - [2009/05/28 11:48:20 | 000,134,144 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CtAudDrv.sys -- (CtAudDrv)
DRV - [2009/05/21 05:48:10 | 000,029,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbccid.sys -- (USBCCID)
DRV - [2009/04/27 18:05:58 | 000,329,752 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\iaStor.sys -- (iaStor)
DRV - [2009/04/03 00:25:50 | 000,048,128 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2009/03/29 20:28:44 | 000,133,632 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OA001Ufd.sys -- (OA001Ufd)
DRV - [2009/03/29 20:28:42 | 000,280,096 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OA001Vid.sys -- (OA001Vid)
DRV - [2009/03/29 20:28:40 | 000,148,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OA001Afx.sys -- (OA001Afx)
DRV - [2009/03/24 16:33:38 | 000,232,744 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SRS_PremiumSound_i386.sys -- (SRS_PremiumSound_Service)
DRV - [2009/03/16 21:57:30 | 001,545,795 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2009/03/16 21:57:12 | 000,112,512 | ---- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AESTAud.sys -- (AESTAud)
DRV - [2009/02/26 17:08:52 | 000,109,568 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel®
DRV - [2009/02/26 17:08:34 | 006,278,560 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
DRV - [2008/08/20 15:50:02 | 000,188,808 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2008/08/20 15:49:56 | 000,023,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2008/06/04 14:14:00 | 000,026,608 | ---- | M] (Dell Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\PBADRV.sys -- (PBADRV)
DRV - [2008/05/28 11:31:24 | 000,337,280 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Symantec AntiVirus\savrt.sys -- (SAVRT)
DRV - [2008/05/28 11:31:24 | 000,054,656 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL)
DRV - [2008/04/24 09:56:22 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PCASp50.sys -- (PCASp50)
DRV - [2008/04/14 08:06:40 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/14 08:06:40 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/14 08:00:00 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/07/26 19:25:18 | 000,400,216 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2007/02/22 17:26:46 | 000,071,168 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\swmx00.sys -- (SWMX00) Sierra Wireless USB MUX Driver (#00)
DRV - [2007/01/12 14:26:42 | 000,102,144 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SWNC5E00.sys -- (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00)
DRV - [2004/04/14 10:30:56 | 000,268,874 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys -- (CVPNDRVA)
DRV - [2004/02/02 12:29:00 | 000,139,604 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dne2000.sys -- (DNE)
DRV - [2003/08/28 21:40:26 | 000,189,792 | ---- | M] (Zone Labs Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
DRV - [2003/05/01 13:26:34 | 000,005,220 | R--- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CVirtA.sys -- (CVirtA)
DRV - [2001/08/17 22:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 22:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 22:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 22:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 22:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 21:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 21:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 21:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 21:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 21:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 21:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 21:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 21:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 21:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 21:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Help_Page =
http://support.dell.com/support/index.aspx...;l=en&s=genIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL =
http://g.msn.com/USREL/1IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page =
http://g.msn.com/USREL/1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 1038
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/17 00:41:15 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/17 01:34:25 | 000,000,000 | ---D | M]
[2010/06/17 00:41:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jonathan\Application Data\Mozilla\Extensions
[2010/06/29 13:41:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jonathan\Application Data\Mozilla\Firefox\Profiles\0fenrrmm.default\extensions
[2010/06/17 00:48:04 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\jonathan\Application Data\Mozilla\Firefox\Profiles\0fenrrmm.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/17 00:40:26 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/06/17 00:31:41 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AESTFltr] C:\WINDOWS\System32\AESTFltr.exe (Andrea Electronics Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [Boingo Wi-Fi] C:\Program Files\Boingo\Boingo Wi-Fi\Boingo.lnk ()
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DellControlPoint] C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [OA001Mon] C:\WINDOWS\OA001Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [USCService] C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe (Broadcom Corporation)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell ControlPoint System Manager.lnk = C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe (Dell Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TdmNotify.lnk = C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe (Wave Systems Corp.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk = C:\WINDOWS\Installer\{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}\Icon3E5562ED7.ico ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/...b?1269349572454 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu...b?1269349664319 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://assetinternational.webex.com/client...ent/ieatgpc.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 66.73.20.40 206.141.193.55
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = parkwd.com
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (wvauth) - C:\WINDOWS\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 17:29:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)
========== Files/Folders - Created Within 90 Days ========== [2099/01/01 12:00:00 | 000,000,000 | R--D | C] -- G:\Jonathan\My Videos
[2099/01/01 12:00:00 | 000,000,000 | R--D | C] -- G:\Jonathan\My Pictures
[2099/01/01 12:00:00 | 000,000,000 | R--D | C] -- G:\Jonathan\My Music
[2099/01/01 12:00:00 | 000,000,000 | -HSD | C] -- G:\Jonathan\cache
[2099/01/01 12:00:00 | 000,000,000 | ---D | C] -- G:\Jonathan\Trading Desk
[2099/01/01 12:00:00 | 000,000,000 | ---D | C] -- G:\Jonathan\Tomo
[2099/01/01 12:00:00 | 000,000,000 | ---D | C] -- G:\Jonathan\SDCERA
[2099/01/01 12:00:00 | 000,000,000 | ---D | C] -- G:\Jonathan\Portfolio
[2099/01/01 12:00:00 | 000,000,000 | ---D | C] -- G:\Jonathan\Parkwood Forms
[2099/01/01 12:00:00 | 000,000,000 | ---D | C] -- G:\Jonathan\Mort Communication
[2099/01/01 12:00:00 | 000,000,000 | ---D | C] -- G:\Jonathan\Keepers
[2099/01/01 12:00:00 | 000,000,000 | ---D | C] -- G:\Jonathan\Downloads
[2099/01/01 12:00:00 | 000,000,000 | ---D | C] -- G:\Jonathan\Dell WebCam Central
[2099/01/01 12:00:00 | 000,000,000 | ---D | C] -- G:\Jonathan\DE
[2010/07/06 17:56:05 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\jonathan\Desktop\OTL.exe
[2010/07/06 16:58:26 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/06/30 20:25:08 | 001,013,584 | ---- | C] (Kaspersky Lab) -- C:\Documents and Settings\jonathan\Desktop\TDSSKiller.exe
[2010/06/17 01:39:50 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/06/17 00:41:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Local Settings\Application Data\Mozilla
[2010/06/17 00:41:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Application Data\Mozilla
[2010/06/17 00:40:25 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2010/06/17 00:21:24 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/06/17 00:21:24 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/06/17 00:21:24 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/06/17 00:14:43 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/06/17 00:14:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/06/04 11:00:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Application Data\webex
[2010/06/02 09:17:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Local Settings\Application Data\CutePDF Writer
[2010/06/01 09:21:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Application Data\Apple Computer
[2010/06/01 09:20:50 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/06/01 09:20:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Local Settings\Application Data\Apple
[2010/06/01 09:20:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Local Settings\Application Data\Apple Computer
[2010/05/28 21:43:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Application Data\Real
[2010/05/28 21:43:27 | 000,000,000 | ---D | C] -- C:\Program Files\Rhapsody
[2010/05/28 17:27:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Wave Systems Corp
[2010/05/27 13:59:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Application Data\Blackberry Desktop
[2010/05/27 13:53:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2010/05/27 13:39:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Application Data\Research In Motion
[2010/05/27 13:37:55 | 000,000,000 | ---D | C] -- C:\Program Files\Research In Motion
[2010/05/27 13:37:55 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Research In Motion
[2010/05/10 00:21:44 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2
[2010/05/10 00:20:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2010/05/10 00:20:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2010/05/05 10:52:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Local Settings\Application Data\Learn2.com
[2010/05/05 10:52:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Application Data\Learn2.com
[2010/04/30 00:39:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Local Settings\Application Data\WMTools Downloaded Files
[2010/04/13 09:50:43 | 000,000,000 | ---D | C] -- C:\Tomo
[2010/04/11 16:31:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Local Settings\Application Data\Wave Systems Corp
[2010/04/11 14:20:34 | 000,013,696 | ---- | C] (Skyhook Wireless) -- C:\WINDOWS\System32\drivers\wpsnuio.sys
[2010/04/11 14:20:34 | 000,000,000 | ---D | C] -- C:\Program Files\Skyhook Wireless
[2010/04/11 14:20:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\jonathan\Local Settings\Application Data\Skyhook Wireless
[2010/04/11 14:20:33 | 000,000,000 | ---D | C] -- C:\Program Files\Boingo
[2010/04/11 14:20:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\GoBoingo
[4 G:\Jonathan\*.tmp files -> G:\Jonathan\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 90 Days ========== [2010/07/06 17:56:09 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\jonathan\Desktop\OTL.exe
[2010/07/06 16:33:16 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/07/06 16:32:11 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/07/06 16:18:51 | 000,557,242 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/06 16:18:51 | 000,466,982 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/07/06 16:18:51 | 000,080,032 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/07/06 16:11:42 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
[2010/07/06 16:11:32 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\jonathan\Local Settings\Application Data\WavXMapDrive.bat
[2010/07/06 16:11:23 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/07/06 16:11:00 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/07/06 16:10:55 | 3707,658,240 | -HS- | M] () -- C:\hiberfil.sys
[2010/07/06 15:45:30 | 005,242,880 | -H-- | M] () -- C:\Documents and Settings\jonathan\NTUSER.DAT
[2010/07/06 15:45:30 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\jonathan\ntuser.ini
[2010/07/06 15:45:21 | 004,802,264 | -H-- | M] () -- C:\Documents and Settings\jonathan\Local Settings\Application Data\IconCache.db
[2010/07/06 15:18:57 | 000,000,256 | ---- | M] () -- C:\WINDOWS\System32\pool.bin
[2010/07/06 15:13:55 | 000,000,567 | ---- | M] () -- C:\WINDOWS\hpbafd.ini
[2010/07/06 14:32:30 | 000,002,501 | ---- | M] () -- C:\Documents and Settings\jonathan\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word.lnk
[2010/07/06 13:56:59 | 000,014,848 | ---- | M] () -- G:\Jonathan\Candidates.xls
[2010/07/06 10:57:00 | 000,002,499 | ---- | M] () -- C:\Documents and Settings\jonathan\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Excel.lnk
[2010/07/05 15:34:55 | 000,139,186 | ---- | M] () -- G:\Jonathan\JRF's May General Commentary.pdf
[2010/07/05 15:33:52 | 000,580,013 | ---- | M] () -- G:\Jonathan\Quarterly Client Allocation Process.pdf
[2010/07/04 20:30:06 | 000,524,800 | ---- | M] () -- G:\Jonathan\Deep Immersion- Portfolio Reviewv4.doc
[2010/07/01 16:40:26 | 003,725,156 | R--- | M] () -- C:\Documents and Settings\jonathan\Desktop\schrauber.exe
[2010/07/01 16:33:51 | 000,981,780 | ---- | M] () -- C:\Documents and Settings\jonathan\Desktop\tdsskiller.zip
[2010/07/01 14:55:10 | 000,024,064 | ---- | M] () -- G:\Jonathan\Bleeping.doc
[2010/07/01 00:49:41 | 000,044,544 | ---- | M] () -- G:\Jonathan\Hedged Equity.doc
[2010/06/30 23:20:09 | 000,048,640 | ---- | M] () -- G:\Jonathan\Chris- May General Commentary Monthly Reviews 10625.doc
[2010/06/30 23:16:55 | 000,070,656 | ---- | M] () -- G:\Jonathan\Lynn- May Monthly Reviews General Commentary 100625.doc
[2010/06/30 23:15:49 | 000,048,640 | ---- | M] () -- G:\Jonathan\May General Commentary Monthly Reviews 10625.doc
[2010/06/30 23:15:32 | 000,047,104 | ---- | M] () -- G:\Jonathan\May General Commentary Monthly Reviews 100625.doc
[2010/06/30 20:25:08 | 001,013,584 | ---- | M] (Kaspersky Lab) -- C:\Documents and Settings\jonathan\Desktop\TDSSKiller.exe
[2010/06/26 16:19:07 | 000,024,064 | ---- | M] () -- G:\Jonathan\Read.doc
[2010/06/22 22:39:12 | 000,113,152 | ---- | M] () -- G:\Jonathan\Performance calculationv4.doc
[2010/06/21 15:14:39 | 000,102,912 | ---- | M] () -- G:\Jonathan\Performance calculationv2.doc
[2010/06/19 00:22:30 | 000,284,915 | ---- | M] () -- C:\Documents and Settings\jonathan\Desktop\gmer.zip
[2010/06/19 00:18:47 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\jonathan\defogger_reenable
[2010/06/17 01:39:53 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/06/17 00:48:02 | 000,001,604 | ---- | M] () -- C:\Documents and Settings\jonathan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox (2).lnk
[2010/06/17 00:41:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2010/06/17 00:40:27 | 000,001,622 | ---- | M] () -- C:\Documents and Settings\jonathan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/06/17 00:40:27 | 000,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/06/17 00:33:05 | 000,002,469 | ---- | M] () -- C:\Documents and Settings\jonathan\Desktop\Microsoft PowerPoint.lnk
[2010/06/17 00:31:41 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/06/15 07:52:11 | 000,000,794 | ---- | M] () -- C:\Documents and Settings\jonathan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2010/06/14 20:40:37 | 000,140,440 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/14 19:18:02 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/06/14 15:57:50 | 000,075,264 | ---- | M] () -- G:\Jonathan\Performance calculation.doc
[2010/06/14 15:49:07 | 000,203,264 | ---- | M] () -- C:\Plan of Attackv2.xls
[2010/06/14 12:50:44 | 000,000,162 | -H-- | M] () -- G:\Jonathan\~$rformance calculation.doc
[2010/06/14 07:45:55 | 000,827,392 | ---- | M] () -- G:\Jonathan\Proposed Commuting Schedule_ McCloskey 3.29.10.xls
[2010/06/12 17:40:45 | 000,228,352 | ---- | M] () -- G:\Jonathan\Deep Immersion- Due Diligence and Risk Management.doc
[2010/06/10 17:12:57 | 000,026,624 | ---- | M] () -- G:\Jonathan\Schedule.doc
[2010/06/10 13:47:18 | 000,058,880 | ---- | M] () -- G:\Jonathan\Yorktown Recommendation Fund IX 100608.doc
[2010/06/08 17:25:18 | 000,212,480 | ---- | M] () -- C:\Deep Immersion- Due Diligence and Risk Managementv2.doc
[2010/06/04 12:27:19 | 000,067,072 | ---- | M] () -- G:\Jonathan\Qual2.doc
[2010/06/04 08:59:16 | 000,000,156 | ---- | M] () -- C:\Documents and Settings\jonathan\Desktop\Shortcut to Offline Files.LNK
[2010/06/04 00:41:49 | 000,071,168 | ---- | M] () -- G:\Jonathan\Qual.doc
[2010/06/03 22:44:40 | 000,384,512 | ---- | M] () -- G:\Jonathan\ElliottAsset Manager Reviews 081215.doc
[2010/06/03 22:42:18 | 000,177,664 | ---- | M] () -- G:\Jonathan\King Street Recommendation 100402.doc
[2010/06/03 16:53:27 | 000,023,040 | ---- | M] () -- G:\Jonathan\legal.xls
[2010/05/30 10:57:25 | 000,020,992 | ---- | M] () -- G:\Jonathan\Hi Mort1.doc
[2010/05/29 16:30:14 | 001,299,968 | ---- | M] () -- G:\Jonathan\Geographic target allocation.doc
[2010/05/28 21:43:46 | 000,000,632 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Rhapsody.lnk
[2010/05/28 17:25:09 | 000,020,992 | ---- | M] () -- G:\Jonathan\The simple act of having a desk and trading in various markets brings a market awareness that can.doc
[2010/05/28 14:43:14 | 000,032,768 | ---- | M] () -- G:\Jonathan\Based on the substantial decline in Yalev2.doc
[2010/05/28 12:52:38 | 000,030,208 | ---- | M] () -- G:\Jonathan\Based on the substantial decline in Yale.doc
[2010/05/27 14:59:53 | 000,000,687 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/05/27 13:53:28 | 000,001,731 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Desktop Manager.lnk
[2010/05/25 10:13:14 | 000,027,648 | ---- | M] () -- G:\Jonathan\Hi Mort.doc
[2010/05/25 09:15:51 | 000,000,162 | -H-- | M] () -- G:\Jonathan\~$i Mort.doc
[2010/05/25 08:04:39 | 000,005,632 | ---- | M] () -- C:\Documents and Settings\jonathan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/24 13:59:31 | 000,029,696 | ---- | M] () -- G:\Jonathan\On a related note.doc
[2010/05/24 12:49:10 | 000,038,486 | ---- | M] () -- C:\Documents and Settings\jonathan\Application Data\Comma Separated Values (Windows).ADR
[2010/05/24 12:47:30 | 000,108,964 | ---- | M] () -- G:\Jonathan\jm contacts.CSV
[2010/05/24 05:00:20 | 000,177,664 | ---- | M] () -- C:\Articulation of purposev2.doc
[2010/05/20 18:58:12 | 000,027,648 | ---- | M] () -- G:\Jonathan\Public- Lee.doc
[2010/05/19 22:52:55 | 000,089,600 | ---- | M] () -- G:\Jonathan\Articulation of purpose.doc
[2010/05/18 19:54:29 | 000,369,664 | ---- | M] () -- G:\Jonathan\proposed template.xls
[2010/05/10 13:41:14 | 000,024,576 | ---- | M] () -- G:\Jonathan\Manager Specific.doc
[2010/05/10 07:50:33 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2010/05/10 07:50:33 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2010/05/10 00:34:50 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\jonathan\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/05/10 00:34:50 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\jonathan\Desktop\Windows Media Player.lnk
[2010/05/10 00:20:53 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010/05/08 13:39:03 | 000,105,472 | ---- | M] () -- G:\Jonathan\Outline Desk v4.doc
[2010/05/05 10:52:18 | 000,000,026 | ---- | M] () -- C:\WINDOWS\GPU.ini
[2010/05/03 16:54:01 | 000,053,760 | ---- | M] () -- G:\Jonathan\McCloskey Project List 5 3 10.doc
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/26 15:58:12 | 000,256,512 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2010/04/22 17:56:30 | 000,025,088 | ---- | M] () -- C:\Hi Mort.doc
[2010/04/19 23:25:17 | 000,035,328 | ---- | M] () -- C:\DE Notes.doc
[2010/04/18 11:05:33 | 002,443,069 | ---- | M] () -- C:\3683 Cedarbrae-Deak.pdf
[2010/04/16 10:47:12 | 000,020,894 | ---- | M] () -- C:\McCloskey Receipt.tif
[2010/04/15 17:02:26 | 000,025,088 | ---- | M] () -- C:\EM.doc
[2010/04/15 16:56:20 | 002,590,986 | ---- | M] () -- C:\bb_04_15_10.pdf
[2010/04/15 13:28:06 | 000,251,649 | ---- | M] () -- C:\2009TaxReturn.pdf
[2010/04/14 17:47:21 | 000,022,528 | ---- | M] () -- C:\Plan of Attack.xls
[2010/04/13 08:34:51 | 000,067,584 | ---- | M] () -- C:\McCloskey Deep Immersion Plan 4.12.10.doc
[2010/04/12 18:03:18 | 000,029,696 | ---- | M] () -- C:\KSC1.doc
[2010/04/12 17:18:46 | 000,034,816 | ---- | M] () -- C:\KSC.doc
[2010/04/11 17:03:41 | 000,001,818 | ---- | M] () -- C:\Documents and Settings\jonathan\Desktop\Boingo Wi-Fi.lnk
[2010/04/11 14:20:34 | 000,013,696 | ---- | M] (Skyhook Wireless) -- C:\WINDOWS\System32\drivers\wpsnuio.sys
[2010/04/09 13:29:02 | 000,020,992 | ---- | M] () -- G:\Jonathan\Hi Micth.doc
[2010/04/09 00:44:17 | 000,064,000 | ---- | M] () -- G:\Jonathan\Gurtin Site Visit Report 100407.doc
[2010/04/07 21:54:32 | 000,460,560 | ---- | M] () -- C:\IIC Tab 4.pdf
[2010/04/07 20:23:54 | 000,550,812 | ---- | M] () -- C:\Samson.California.McCloskey 6.11.09.pdf
[4 G:\Jonathan\*.tmp files -> G:\Jonathan\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2099/01/01 12:00:00 | 001,299,968 | ---- | C] () -- G:\Jonathan\Geographic target allocation.doc
[2099/01/01 12:00:00 | 001,063,976 | ---- | C] () -- G:\Jonathan\Lee Partridge contract.pdf
[2099/01/01 12:00:00 | 000,827,392 | ---- | C] () -- G:\Jonathan\Proposed Commuting Schedule_ McCloskey 3.29.10.xls
[2099/01/01 12:00:00 | 000,580,013 | ---- | C] () -- G:\Jonathan\Quarterly Client Allocation Process.pdf
[2099/01/01 12:00:00 | 000,524,800 | ---- | C] () -- G:\Jonathan\Deep Immersion- Portfolio Reviewv4.doc
[2099/01/01 12:00:00 | 000,384,512 | ---- | C] () -- G:\Jonathan\ElliottAsset Manager Reviews 081215.doc
[2099/01/01 12:00:00 | 000,369,664 | ---- | C] () -- G:\Jonathan\proposed template.xls
[2099/01/01 12:00:00 | 000,228,352 | ---- | C] () -- G:\Jonathan\Deep Immersion- Due Diligence and Risk Management.doc
[2099/01/01 12:00:00 | 000,177,664 | ---- | C] () -- G:\Jonathan\King Street Recommendation 100402.doc
[2099/01/01 12:00:00 | 000,139,186 | ---- | C] () -- G:\Jonathan\JRF's May General Commentary.pdf
[2099/01/01 12:00:00 | 000,113,152 | ---- | C] () -- G:\Jonathan\Performance calculationv4.doc
[2099/01/01 12:00:00 | 000,108,964 | ---- | C] () -- G:\Jonathan\jm contacts.CSV
[2099/01/01 12:00:00 | 000,105,472 | ---- | C] () -- G:\Jonathan\Outline Desk v4.doc
[2099/01/01 12:00:00 | 000,102,912 | ---- | C] () -- G:\Jonathan\Performance calculationv2.doc
[2099/01/01 12:00:00 | 000,089,600 | ---- | C] () -- G:\Jonathan\Articulation of purpose.doc
[2099/01/01 12:00:00 | 000,075,264 | ---- | C] () -- G:\Jonathan\Performance calculation.doc
[2099/01/01 12:00:00 | 000,071,168 | ---- | C] () -- G:\Jonathan\Qual.doc
[2099/01/01 12:00:00 | 000,070,656 | ---- | C] () -- G:\Jonathan\Lynn- May Monthly Reviews General Commentary 100625.doc
[2099/01/01 12:00:00 | 000,067,072 | ---- | C] () -- G:\Jonathan\Qual2.doc
[2099/01/01 12:00:00 | 000,064,000 | ---- | C] () -- G:\Jonathan\Gurtin Site Visit Report 100407.doc
[2099/01/01 12:00:00 | 000,058,880 | ---- | C] () -- G:\Jonathan\Yorktown Recommendation Fund IX 100608.doc
[2099/01/01 12:00:00 | 000,053,760 | ---- | C] () -- G:\Jonathan\McCloskey Project List 5 3 10.doc
[2099/01/01 12:00:00 | 000,048,640 | ---- | C] () -- G:\Jonathan\May General Commentary Monthly Reviews 10625.doc
[2099/01/01 12:00:00 | 000,048,640 | ---- | C] () -- G:\Jonathan\Chris- May General Commentary Monthly Reviews 10625.doc
[2099/01/01 12:00:00 | 000,047,104 | ---- | C] () -- G:\Jonathan\May General Commentary Monthly Reviews 100625.doc
[2099/01/01 12:00:00 | 000,044,544 | ---- | C] () -- G:\Jonathan\Hedged Equity.doc
[2099/01/01 12:00:00 | 000,032,768 | ---- | C] () -- G:\Jonathan\Based on the substantial decline in Yalev2.doc
[2099/01/01 12:00:00 | 000,030,208 | ---- | C] () -- G:\Jonathan\Based on the substantial decline in Yale.doc
[2099/01/01 12:00:00 | 000,029,696 | ---- | C] () -- G:\Jonathan\On a related note.doc
[2099/01/01 12:00:00 | 000,027,648 | ---- | C] () -- G:\Jonathan\Public- Lee.doc
[2099/01/01 12:00:00 | 000,027,648 | ---- | C] () -- G:\Jonathan\Hi Mort.doc
[2099/01/01 12:00:00 | 000,026,624 | ---- | C] () -- G:\Jonathan\Schedule.doc
[2099/01/01 12:00:00 | 000,024,576 | ---- | C] () -- G:\Jonathan\Manager Specific.doc
[2099/01/01 12:00:00 | 000,024,576 | ---- | C] () -- G:\Jonathan\Hey Skip.doc
[2099/01/01 12:00:00 | 000,024,064 | ---- | C] () -- G:\Jonathan\Read.doc
[2099/01/01 12:00:00 | 000,024,064 | ---- | C] () -- G:\Jonathan\Calls.doc
[2099/01/01 12:00:00 | 000,024,064 | ---- | C] () -- G:\Jonathan\Bleeping.doc
[2099/01/01 12:00:00 | 000,023,040 | ---- | C] () -- G:\Jonathan\legal.xls
[2099/01/01 12:00:00 | 000,020,992 | ---- | C] () -- G:\Jonathan\The simple act of having a desk and trading in various markets brings a market awareness that can.doc
[2099/01/01 12:00:00 | 000,020,992 | ---- | C] () -- G:\Jonathan\Hi Mort1.doc
[2099/01/01 12:00:00 | 000,020,992 | ---- | C] () -- G:\Jonathan\Hi Micth.doc
[2099/01/01 12:00:00 | 000,014,848 | ---- | C] () -- G:\Jonathan\Candidates.xls
[2099/01/01 12:00:00 | 000,000,162 | -H-- | C] () -- G:\Jonathan\~$rformance calculation.doc
[2099/01/01 12:00:00 | 000,000,162 | -H-- | C] () -- G:\Jonathan\~$i Mort.doc
[2010/07/01 16:40:27 | 003,725,156 | R--- | C] () -- C:\Documents and Settings\jonathan\Desktop\schrauber.exe
[2010/07/01 16:33:51 | 000,981,780 | ---- | C] () -- C:\Documents and Settings\jonathan\Desktop\tdsskiller.zip
[2010/06/19 00:24:03 | 000,284,915 | ---- | C] () -- C:\Documents and Settings\jonathan\Desktop\gmer.zip
[2010/06/19 00:18:47 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\jonathan\defogger_reenable
[2010/06/17 14:02:08 | 3707,658,240 | -HS- | C] () -- C:\hiberfil.sys
[2010/06/17 01:39:53 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/06/17 01:39:51 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/06/17 00:48:02 | 000,001,604 | ---- | C] () -- C:\Documents and Settings\jonathan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox (2).lnk
[2010/06/17 00:41:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/06/17 00:40:27 | 000,001,622 | ---- | C] () -- C:\Documents and Settings\jonathan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/06/17 00:40:27 | 000,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/06/17 00:21:25 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/06/17 00:21:24 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/06/17 00:21:24 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/06/17 00:21:24 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/06/17 00:21:24 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/06/08 13:17:16 | 000,212,480 | ---- | C] () -- C:\Deep Immersion- Due Diligence and Risk Managementv2.doc
[2010/06/04 08:59:16 | 000,000,156 | ---- | C] () -- C:\Documents and Settings\jonathan\Desktop\Shortcut to Offline Files.LNK
[2010/05/28 21:43:46 | 000,000,632 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Rhapsody.lnk
[2010/05/27 13:53:28 | 000,001,731 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Desktop Manager.lnk
[2010/05/27 13:39:41 | 000,000,256 | ---- | C] () -- C:\WINDOWS\System32\pool.bin
[2010/05/24 17:48:48 | 000,005,632 | ---- | C] () -- C:\Documents and Settings\jonathan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/24 12:49:10 | 000,038,486 | ---- | C] () -- C:\Documents and Settings\jonathan\Application Data\Comma Separated Values (Windows).ADR
[2010/05/23 14:54:26 | 000,203,264 | ---- | C] () -- C:\Plan of Attackv2.xls
[2010/05/23 14:54:12 | 000,177,664 | ---- | C] () -- C:\Articulation of purposev2.doc
[2010/05/11 14:53:48 | 000,002,469 | ---- | C] () -- C:\Documents and Settings\jonathan\Desktop\Microsoft PowerPoint.lnk
[2010/05/10 00:20:53 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010/05/05 10:52:18 | 000,000,026 | ---- | C] () -- C:\WINDOWS\GPU.ini
[2010/04/21 17:09:19 | 000,025,088 | ---- | C] () -- C:\Hi Mort.doc
[2010/04/18 11:05:33 | 002,443,069 | ---- | C] () -- C:\3683 Cedarbrae-Deak.pdf
[2010/04/16 10:47:11 | 000,020,894 | ---- | C] () -- C:\McCloskey Receipt.tif
[2010/04/15 17:02:25 | 000,025,088 | ---- | C] () -- C:\EM.doc
[2010/04/15 16:56:13 | 002,590,986 | ---- | C] () -- C:\bb_04_15_10.pdf
[2010/04/15 13:28:03 | 000,251,649 | ---- | C] () -- C:\2009TaxReturn.pdf
[2010/04/14 17:47:20 | 000,022,528 | ---- | C] () -- C:\Plan of Attack.xls
[2010/04/12 17:55:01 | 000,029,696 | ---- | C] () -- C:\KSC1.doc
[2010/04/12 15:43:00 | 000,034,816 | ---- | C] () -- C:\KSC.doc
[2010/04/12 11:52:30 | 000,067,584 | ---- | C] () -- C:\McCloskey Deep Immersion Plan 4.12.10.doc
[2010/04/12 11:52:02 | 000,035,328 | ---- | C] () -- C:\DE Notes.doc
[2010/04/11 17:03:41 | 000,001,818 | ---- | C] () -- C:\Documents and Settings\jonathan\Desktop\Boingo Wi-Fi.lnk
[2010/04/07 21:54:25 | 000,460,560 | ---- | C] () -- C:\IIC Tab 4.pdf
[2010/04/07 20:23:52 | 000,550,812 | ---- | C] () -- C:\Samson.California.McCloskey 6.11.09.pdf
[2010/03/23 09:00:48 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2010/03/23 08:23:11 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\BeCubed.dll
[2010/03/23 08:23:10 | 001,128,448 | ---- | C] () -- C:\WINDOWS\System32\Sbl.dll
[2010/03/23 08:11:37 | 000,000,022 | ---- | C] () -- C:\WINDOWS\System32\RPCS.ini
[2010/03/23 08:10:41 | 000,000,567 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2010/03/23 08:05:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2010/03/23 07:30:38 | 000,000,548 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/03/17 09:53:02 | 000,001,156 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2010/03/17 08:20:33 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2010/03/17 08:11:08 | 000,232,744 | R--- | C] () -- C:\WINDOWS\System32\drivers\SRS_PremiumSound_i386.sys
[2010/03/17 08:10:45 | 000,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2010/03/17 08:10:45 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2010/03/17 08:09:09 | 000,308,624 | ---- | C] () -- C:\WINDOWS\System32\brcmbsp.dll
[2010/03/17 08:09:09 | 000,206,216 | ---- | C] () -- C:\WINDOWS\System32\bipbsp.dll
[2010/03/17 08:09:02 | 000,080,368 | ---- | C] () -- C:\WINDOWS\System32\pbadrvdll.dll
[2009/11/19 16:47:10 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\wxvault.dll
[2009/11/18 16:21:08 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_zh-HK.dll
[2009/11/18 16:21:06 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_sl.dll
[2009/11/18 16:21:06 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_th.dll
[2009/11/18 16:21:04 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_sk.dll
[2009/11/18 16:21:02 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_hr.dll
[2009/11/18 16:20:56 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_ro.dll
[2009/11/18 16:20:56 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_tr.dll
[2009/11/18 16:20:54 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_pt-BR.dll
[2009/11/18 16:20:52 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_hu.dll
[2009/11/18 16:20:52 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_he.dll
[2009/11/18 16:20:50 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_fi.dll
[2009/11/18 16:20:48 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_el.dll
[2009/11/18 16:20:48 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_cs.dll
[2009/11/18 16:20:46 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_ar.dll
[2009/11/18 16:20:44 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_zh-CHT.dll
[2009/11/18 16:20:44 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_zh-CHS.dll
[2009/11/18 16:20:42 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_sv.dll
[2009/11/18 16:20:40 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_pt.dll
[2009/11/18 16:20:40 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_ru.dll
[2009/11/18 16:20:38 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_pl.dll
[2009/11/18 16:20:36 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_nl.dll
[2009/11/18 16:20:36 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_no.dll
[2009/11/18 16:20:34 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_ko.dll
[2009/11/18 16:20:32 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_ja.dll
[2009/11/18 16:20:30 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_it.dll
[2009/11/18 16:20:30 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_fr.dll
[2009/11/18 16:20:28 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_es.dll
[2009/11/18 16:20:26 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_de.dll
[2009/11/18 16:20:24 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\Internationalization_da.dll
[2009/11/13 09:17:00 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\Wavx_ESC_Logging.dll
[2009/11/06 16:27:22 | 000,839,680 | ---- | C] () -- C:\WINDOWS\System32\DemoLicense.dll
[2009/08/26 17:25:08 | 000,917,504 | ---- | C] () -- C:\WINDOWS\System32\lmgr10.dll
[2008/04/25 17:26:32 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2008/03/25 10:46:00 | 000,077,536 | ---- | C] () -- C:\WINDOWS\System32\xltZlib.dll
[2007/09/27 11:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/04/19 06:52:16 | 000,080,720 | ---- | C] () -- C:\WINDOWS\System32\AsfBios.dll
[2007/04/19 06:28:10 | 000,025,424 | ---- | C] () -- C:\WINDOWS\System32\drivers\netamsg.dll
[2006/06/30 13:58:44 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\bioapi_mds300.dll
[2006/06/30 13:58:44 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\bioapi100.dll
[2006/06/12 09:01:16 | 000,348,160 | ---- | C] () -- C:\WINDOWS\tsp.dll
[2004/04/14 10:31:38 | 000,139,288 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/02/27 10:41:28 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\nsldappr32v50.dll
[2002/02/27 10:41:26 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\nsldap32v50.dll
[2002/02/27 10:41:26 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\nsldapssl32v50.dll
========== LOP Check ========== [2010/03/23 14:25:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Acronis
[2010/03/17 08:09:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Broadcom
[2010/04/11 14:20:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GoBoingo
[2010/03/17 08:11:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NTRU Cryptosystems
[2010/05/27 13:53:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2010/03/17 08:14:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Uninstall
[2010/03/17 08:11:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Wave Systems Corp
[2010/05/27 13:59:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jonathan\Application Data\Blackberry Desktop
[2010/03/17 08:18:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jonathan\Application Data\Broadcom
[2010/05/05 10:52:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jonathan\Application Data\Learn2.com
[2010/05/27 13:39:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jonathan\Application Data\Research In Motion
[2010/03/23 11:39:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jonathan\Application Data\Smith Micro
[2010/03/17 08:11:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jonathan\Application Data\Wave Systems Corp
[2010/06/04 11:00:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jonathan\Application Data\webex
[2010/03/17 08:07:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jonathan\Application Data\Windows Desktop Search
[2010/03/22 16:35:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\jonathan\Application Data\Windows Search
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS >[2008/04/14 08:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\I386\sp3.cab:AGP440.sys
[2008/04/14 05:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\Program Files\Dell\DBRM\osmedia\I386\sp3.cab:AGP440.sys
[2008/04/14 08:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/04/14 08:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\AGP440.SYS
[2008/04/14 08:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\AGP440.SYS
< MD5 for: AHCIX86.SYS >[2008/10/13 14:14:18 | 000,184,848 | ---- | M] (Advanced Micro Devices, Inc) MD5=1ED718CA8A8B3F5AB77416A873C2BF9D -- C:\Program Files\Dell\DBRM\osmedia\I386\AHCIX86.SYS
< MD5 for: ATAPI.SYS >[2008/04/14 08:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\I386\sp3.cab:atapi.sys
[2008/04/14 05:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\Program Files\Dell\DBRM\osmedia\I386\sp3.cab:atapi.sys
[2008/04/14 08:00:00 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 08:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/14 08:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >[2008/04/14 08:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/14 08:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: IASTOR.SYS >[2009/02/11 18:26:18 | 000,407,576 | ---- | M] (Intel Corporation) MD5=1ADAA4F16073FD0C7270F451FD024E97 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2009/04/27 18:05:58 | 000,329,752 | ---- | M] (Intel Corporation) MD5=71ECC07BC7C5E24C3DD01D8A29A24054 -- C:\drivers\storage\R213316\IaStor.sys
[2009/02/11 18:11:50 | 000,329,752 | ---- | M] (Intel Corporation) MD5=71ECC07BC7C5E24C3DD01D8A29A24054 -- C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2009/04/27 18:05:58 | 000,329,752 | ---- | M] (Intel Corporation) MD5=71ECC07BC7C5E24C3DD01D8A29A24054 -- C:\WINDOWS\system32\drivers\iaStor.sys
[2009/06/04 17:43:16 | 000,330,264 | ---- | M] (Intel Corporation) MD5=D483687EACE0C065EE772481A96E05F5 -- C:\Program Files\Dell\DBRM\osmedia\I386\IASTOR.SYS
< MD5 for: NETLOGON.DLL >[2008/04/14 08:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/14 08:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: NVGTS.SYS >[2008/01/21 11:15:22 | 000,102,400 | ---- | M] (NVIDIA Corporation) MD5=A0B3F3A5049931657164F0FFCF0B208E -- C:\Program Files\Dell\DBRM\osmedia\I386\NVGTS.SYS
< MD5 for: NVRD32.SYS >[2008/01/21 11:15:22 | 000,128,000 | ---- | M] (NVIDIA Corporation) MD5=C9128FE14E5C1E55710781B5C276F2ED -- C:\Program Files\Dell\DBRM\osmedia\I386\NVRD32.SYS
< MD5 for: SCECLI.DLL >[2008/04/14 08:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/14 08:00:00 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: SYMMPI.SYS >[2007/02/09 23:06:00 | 000,100,096 | ---- | M] (LSI Logic) MD5=A42F863305943869BA00A613C8EE8C7E -- C:\Program Files\Dell\DBRM\osmedia\I386\SYMMPI.SYS
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[2009/03/08 04:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 04:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
[2010/05/06 06:41:50 | 000,184,320 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\iepeers.dll
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav >[2008/04/25 05:21:09 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2008/04/25 05:21:09 | 001,089,536 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2008/04/25 05:21:09 | 000,905,216 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemdrive%\*.sys /90 /md5 >[2010/07/06 16:10:55 | 3707,658,240 | -HS- | M] ()
Unable to obtain MD5 -- C:\hiberfil.sys
[2010/07/06 16:10:54 | 2145,386,496 | -HS- | M] ()
Unable to obtain MD5 -- C:\pagefile.sys
< End of report >
...and here's the Extra.txt file
OTL Extras logfile created on: 7/6/2010 5:57:10 PM - Run 1
OTL by OldTimer - Version 3.2.7.1 Folder = C:\Documents and Settings\jonathan\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 73.00% Memory free
5.00 Gb Paging File | 5.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.85 Gb Total Space | 213.04 Gb Free Space | 91.49% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 232.85 Gb Total Space | 213.04 Gb Free Space | 91.49% Space Free | Partition Type: *NT5CSC
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JON-XPLP
Current User Name: jonathan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0003C1E0-E0E7-49BB-A0F6-4AE6D2B09202}" = UPEK TouchChip Fingerprint Reader
"{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"{083CE5FA-E750-4594-B8D1-13994B297A02}" = Wave Infrastructure Installer
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE 10.3
"{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{235C31BC-BBAE-4932-9F17-15395C65907B}" = Boingo Wi-Fi
"{24A494F3-5B5F-4183-9F7D-9CE82812C1FC}" = tsp patch
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java 6 Update 17
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{314E5785-BD81-47FD-9D6B-5C3CD31B351B}" = Dell ControlPoint System Manager
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{39A6407B-DD99-410D-8EA2-280788F8423B}" = Dell Control Point
"{3A6BE9F4-5FC8-44BB-BE7B-32A29607FEF6}" = Preboot Manager
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}" = Cisco Systems VPN Client 4.0.4 (Rel)
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6A7F4379-B2EE-444F-AC4A-C5379B1CF95E}" = Dell ControlVault Host Components Installer
"{6EA8A52B-8EA1-4A59-85AB-48132299061A}" = Intel® PRO Alerting Agent
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8A94281C-8C6C-42FA-9A47-16F789089C58}" = Microsoft Dynamics SL 7.0 Feature Pack 1 Client
"{8EB29D71-DE8D-4B49-8833-F508ECF0BE59}" = DCP32MMWrapper
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90E00409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Outlook 2003
"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{91490409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Primary Interop Assemblies
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9C875FEA-B49E-49F7-AE62-0F9B91F90982}" = SRS Premium Sound
"{9D59AC32-B0FA-4CD7-A2EC-4B57C06CD9D9}" = Dell Backup and Recovery Manager
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{ABBA2EA4-740E-4052-902B-9CA70B081E3F}" = Dell Embassy Trust Suite by Wave Systems
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AD8A1013-4E46-4E02-85C2-3168C3328432}" = Symantec AntiVirus
"{AF7E4468-E364-4991-BC2A-6E8293E1055B}" = BioAPI Framework
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{BA609BE1-FD0F-41D9-9F1C-CEC0D9272941}" = VZAccess Manager for AC595
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB93D30B-B395-44BB-A9ED-A0E057F07E53}" = NTRU TCG Software Stack
"{BC52E419-B185-488F-9973-049A88E5DCBE}" = Gemalto
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCC68887-6E07-4438-A035-7C22EFBDC15E}" = Intel® Network Connections 14.6.7.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"{D657DFB4-5DD9-4A2B-AEC9-3BBE25541EE7}" = SO32MMWrapper
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DBA80D58-51A2-43A4-8C39-65F39C5B56AD}" = Parkwood IMS Add-in for Outlook
"{DDD6BE8C-9AFA-48F1-A6AE-3BD596E2EB0B}" = Trusted Drive Manager
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE 10.3
"{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F4487649-7368-4217-AEA3-1E04DB3E2C5C}" = Dell ControlPoint Security Manager
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FF1DDCF4-3A28-4F7F-96D8-E3F4BD1C1702}" = Dell Security Device Driver Pack
"9512AA21B791B05A54E27065C45BBC417AB282DF" = Windows Driver Package - Dell Inc. PBADRV System (09/11/2009 1.0.1.6)
"ActiveTouchMeetingClient" = WebEx
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"BlackBerry_{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"Creative OA001" = Integrated Webcam Driver (1.06.03.0309)
"CutePDF Writer Installation" = CutePDF Writer 2.7
"Dell Webcam Central" = Dell Webcam Central
"DW WLAN Card Utility" = DW WLAN Card Utility
"ESET Online Scanner" = ESET Online Scanner v3
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie8" = Windows Internet Explorer 8
"InstallShield_{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"InstallShield_{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"InstallShield_{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"InstallShield_{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"InstallShield_{8A94281C-8C6C-42FA-9A47-16F789089C58}" = Microsoft Dynamics SL 7.0 Feature Pack 1 Client
"InstallShield_{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"InstallShield_{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"InstallShield_{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Rhapsody" = Rhapsody
"Skyhook Wireless Wi-Fi Service" = Skyhook Wireless Wi-Fi Service
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 7/6/2010 4:11:07 PM | Computer Name = JON-XPLP | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 7/6/2010 4:11:17 PM | Computer Name = JON-XPLP | Source = Userenv | ID = 1054
Description = Windows cannot obtain the domain controller name for your computer
network. (The specified domain either does not exist or could not be contacted.
). Group Policy processing aborted.
Error - 7/6/2010 4:56:46 PM | Computer Name = JON-XPLP | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.
Error - 7/6/2010 5:50:49 PM | Computer Name = JON-XPLP | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Risk: Trojan.FakeAV in File: C:\Qoobox\Quarantine\C\Documents
and Settings\jonathan\Local Settings\Application Data\kdfwsy\dsdwua.exe.vir by:
Auto-Protect scan. Action: Cleaned by Deletion. Action Description:
Error - 7/6/2010 5:51:12 PM | Computer Name = JON-XPLP | Source = Symantec AntiVirus | ID = 16711685
Description = Risk Found!Risk: Trojan.FakeAV in File: C:\Qoobox\Quarantine\C\Documents
and Settings\jonathan\Local Settings\Application Data\kdfwsy\dsdwua.exe.vir by:
Auto-Protect scan. Action: Cleaned by Deletion. Action Description:
Error - 7/6/2010 5:51:21 PM | Computer Name = JON-XPLP | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Risk: Trojan.FakeAV in File: C:\Qoobox\Quarantine\C\Documents
and Settings\jonathan\Local Settings\Application Data\kdfwsy\dsdwua.exe.vir by:
Auto-Protect scan. Action: Cleaned by Deletion. Action Description:
Error - 7/6/2010 5:51:34 PM | Computer Name = JON-XPLP | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Risk: Backdoor.Tidserv!inf in File: C:\System
Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP69\A0049969.sys
by: Auto-Protect scan. Action: Clean failed : Quarantine failed. Action Description:
The file was left unchanged.
Error - 7/6/2010 5:51:34 PM | Computer Name = JON-XPLP | Source = Symantec AntiVirus | ID = 16711685
Description = Risk Found!Risk: Backdoor.Tidserv!inf in File: C:\System Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP69\A0049969.sys
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied.
Action Description: The file was left unchanged.
Error - 7/6/2010 5:51:34 PM | Computer Name = JON-XPLP | Source = Symantec AntiVirus | ID = 16711685
Description = Risk Found!Risk: Backdoor.Tidserv!inf in File: c:\system volume information\_restore{45b5e8b9-949a-471e-999d-f381da56a2d3}\RP69\A0049969.sys
by: Auto-Protect scan. Action: Clean failed : Quarantine failed. Action Description:
The file was left unchanged.
Error - 7/6/2010 5:51:35 PM | Computer Name = JON-XPLP | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Risk: Backdoor.Tidserv!inf in File: C:\System
Volume Information\_restore{45B5E8B9-949A-471E-999D-F381DA56A2D3}\RP69\A0049969.sys
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Access denied.
Action Description: Risk was partially removed.
[ System Events ]
Error - 7/6/2010 4:39:47 PM | Computer Name = JON-XPLP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.
Error - 7/6/2010 4:39:47 PM | Computer Name = JON-XPLP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.
Error - 7/6/2010 4:40:06 PM | Computer Name = JON-XPLP | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.197 for the Network Card with network
address F07BCB15F9D6 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).
Error - 7/6/2010 4:40:15 PM | Computer Name = JON-XPLP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.
Error - 7/6/2010 4:41:06 PM | Computer Name = JON-XPLP | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.108 for the Network Card with network
address F07BCB15F9D6 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).
Error - 7/6/2010 4:42:14 PM | Computer Name = JON-XPLP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.
Error - 7/6/2010 4:42:23 PM | Computer Name = JON-XPLP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.
Error - 7/6/2010 4:42:24 PM | Computer Name = JON-XPLP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 7/6/2010 4:57:29 PM | Computer Name = JON-XPLP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.
Error - 7/6/2010 5:27:33 PM | Computer Name = JON-XPLP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 59 minutes. NtpClient has no source of accurate
time.
< End of report >
Thanks Schrauber. Please let me know if you need anything else.