Thanks for taking a look. In the interests of saving time, I probably overwhelmed you with information. I acknowledge that my computer's problems can span several forums. Please respond to what you are comfortable helping with and, if you would be so kind as to direct me I'll be happy to explore solutions in other forums as well. I am new to bleeping computer (and new to many of the things I'm having to learn), so I'm feeling a little baffled.
Yes, I realize there are lots of things that could cause the symptoms my computer is having besides malware. however, I have to tell you that my (admittedly inexperienced) gut reaction is my computer is being beseiged and regularly attacked via the Internet. It seems to be fine when working offline. The surging and stalling starts shortly after I plug into the Internet, not necessarily at start up, although start up is slow. There are many IP addresses which try to connect to my computer, but I'm noticing that one in particular is intercepted doing port scans right before an "attack." I don't know if there is any correlation or if I'm just getting paranoid. I suppose either is possible.
I don't know if I remembered to tell you that I'm constantly having to clean to open up low memory reserves as well. Another thing I forgot to mention is that Spyware Sweeper found "Maxifiles" on my computer, but I couldn't locate the files it listed.
I uninstalled both Spyware Sweeper and Spyware Doctor. I've been scanning with whatever reputable programs I could find through another forum in bleeping computer as well as a Security article in the April 2007 issue of PC Magazine. I actually only have purchased Zone Alarm Suite, which does have both a resident spyware and antivirus program, and System Mechanic (which has a System Guard feature enabled). It is my intention to offload all other programs as I've not found anything I like better. Currently I have Primary Response Safe Connect on a trial that's got about 6 days left. I like that program for the way it monitors behavior, but Zone Alarm rated high enough (in PC Magazine) for threat removal for me to feel comfortable relying on it alone. Another program installed right now is Spy Eraser, which I've kept simply because it found something and I wanted the log. Now I've saved the log, it can go too. I also tried out Registry Booster, but I've decided not to purchase it as System Mechanic, which I already own, manages the registry. That's it as far as resident guard programs. Primary Response is fairly passive, just monitoring, and if there is a question, asking me what action to take. System Mechanic should be compatible with Zone Alarm, since it was offered to me by CheckPoint as an add-on when I purchased my firewall, I believe it was last month. I have the current version of Zone Alarm Security Suite (7.0.337.000) running with TrueVector security engine version 7.0.337.000. Anti-virus engine version 3, DAT file version; Anti-spyware engine version 5.0.162.0 DAT file version 01.200703.1225 The problem I encountered with updating it was when I tried to update it from a setup program saved to my desktop. It was looking for a Temp file I had deleted. I got around that by updating it by using the online automated technician.
I uninstalled AVG Anti-Virus as I think it is probably overkill (and to avoid conflicts) since my Zone Alarm already handles AV and has a resident guard.
I hope I've answered all your questions about versions, etc? If not, let me know. As far as the Anti-Rootkit goes, I scanned both ways and it came up clean. I couldn't get it to update from the update button, though (no window came up with an update page as it instructed). And, do you know if it scanned what the Kaspersky scanner identified as locked files? Thanks again for your help, and the logs you requested follow below.
Nalyn
Deckard's System Scanner v20070318.32
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel Pentium III processor
Percentage of Memory in Use: 73%
Physical Memory (total/avail): 254.3 MiB / 67.27 MiB
Pagefile Memory (total/avail): 625.24 MiB / 267.38 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1993.52 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 18.64 GiB total, 10.72 GiB free.
D: is CDROM (No Media)
-- Security Center -------------------------------------------------------------
AUOptions is set to notify before download.
Windows Internal Firewall is disabled.
AntivirusOverride is set.
FW: ZoneAlarm Security Suite Firewall v7.0.337.000 (Check Point, LTD.)
AV: ZoneAlarm Security Suite Antivirus v7.0.337.000 (Check Point, LTD.)
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Administrator\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=BAINDT003
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Administrator
LOGONSERVER=\\BAINDT003
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;\\kitobey.com\netlogon\tools;"C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier"
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 8 Stepping 10, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=080a
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
tvdumpflags=8
USERDOMAIN=BAINDT003
USERNAME=Administrator
USERPROFILE=C:\Documents and Settings\Administrator
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
jm
jhg
(admin, profile directory not found)kit employee
(new local, admin)jm.BAINDT003
(admin)jm.BAINDT003.000
(admin)jmain
Administrator
(admin)Guest
-- Add/Remove Programs ---------------------------------------------------------
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\System32\Uninst.isu
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Reader 8 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A80000000002}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
APC PowerChute Personal Edition --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5A0C892E-FD1C-4203-941E-0956AED20A6A}\Setup.exe" -l0x9
Burpee 3D Garden Designer --> C:\Burpee\UNWISE.EXE C:\Burpee\INSTALL.LOG
Confidence Online for Web Applications --> C:\Documents and Settings\Administrator\Application Data\WholeSecurity\CAT\WSUIEE.exe
Digital Developer --> MsiExec.exe /I{C55254E3-BD39-4EA8-A71D-A41DB0E857B1}
HijackThis 1.99.1 --> C:\hijackthis\HijackThis.exe /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
iolo technologies' System Mechanic 7 --> "C:\Program Files\iolo\System Mechanic 7\unins000.exe"
Java SE Runtime Environment 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
Kaspersky Online Scanner --> C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
Learn2.com Multimedia Training --> C:\WINDOWS\Uninvia2.exe
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Move Networks Player for Firefox --> "C:\Program Files\Mozilla Firefox\plugins\unins000.exe"
Mozilla Firefox (2.0.0.3) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 6.0 Parser (KB927977) --> MsiExec.exe /I{5A710547-B58E-488B-828D-CA9A25A0533C}
Panda ActiveScan --> C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan
PhotoParade Player --> "C:\Program Files\PhotoParade\Uninstall PhotoParade Player.exe" "PhotoParade.exe"
Primary Response SafeConnect --> C:\Program Files\InstallShield Installation Information\{AF18BF2A-255B-4A7A-8325-F545BB8CC751}\setup.exe -runfromtemp -l0x0409
QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log
Sesame Street Baby --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5E8374D9-600F-49A6-8EF9-A6BA42FDCF3D}\setup.exe"
Symnet Redirector Updater --> MsiExec.exe /X{CACE0C9D-9EF7-4F3B-9C64-88FBA245BA9C}
TurboTax Home & Business 2006 --> C:\Program Files\TurboTax\Home & Business 2006\TaxUnst.EXE "C:\Program Files\TurboTax\Home & Business 2006\Uninstall.log" -NoGui
TurboTax ItsDeductible 2006 --> MsiExec.exe /X{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}
Uniblue Registry Booster --> "C:\Program Files\Uniblue\Registry Booster\unins000.exe"
Uniblue SpyEraser --> "C:\Program Files\Uniblue\SpyEraser\unins000.exe"
URGE --> MsiExec.exe /I{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}
WexTech AnswerWorks --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}\SETUP.EXE" -l0x9 -eliminate
Windows Communication Foundation --> MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Workflow Foundation --> MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
Zinio Reader --> C:\Program Files\Zinio\uninstall.exe
ZoneAlarm Security Suite --> C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe
-- End of Deckard's System Scanner: finished at 2007-03-23 at 15:01:12 ---------
Deckard's System Scanner v20070318.32
Run by Administrator on 2007-03-23 at 14:57:10
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
10: 2007-03-23 21:57:55 UTC - RP10 - Deckard's System Scanner Restore Point
9: 2007-03-23 21:43:17 UTC - RP9 - Deckard's System Scanner Restore Point
8: 2007-03-23 15:45:31 UTC - RP8 - System Checkpoint
7: 2007-03-22 02:37:49 UTC - RP7 - System Checkpoint
6: 2007-03-20 21:30:56 UTC - RP6 - Software Distribution Service 2.0
-- First Restore Point --
1: 2007-03-20 19:15:04 UTC - RP1 - System Checkpoint
Performed disk cleanup.
Adobe Flash Player 9 ActiveX
Adobe Reader 8
Adobe Shockwave Player
APC PowerChute Personal Edition
Burpee 3D Garden Designer
Digital Developer
HijackThis 1.99.1
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
iolo technologies' System Mechanic 7
Java SE Runtime Environment 6
Kaspersky Online Scanner
Learn2.com Multimedia Training
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Move Networks Player for Firefox
Mozilla Firefox (2.0.0.3)
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB927977)
Panda ActiveScan
PhotoParade Player
Primary Response SafeConnect
QuickTime
Security Update for Microsoft .NET Framework 2.0 (KB917283)
Security Update for Microsoft .NET Framework 2.0 (KB922770)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Sesame Street Baby
Symnet Redirector Updater
TurboTax Home & Business 2006
TurboTax ItsDeductible 2006
Uniblue Registry Booster
Uniblue SpyEraser
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB914882)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB929338)
Update for Windows XP (KB931836)
URGE
WexTech AnswerWorks
Windows Communication Foundation
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Media Player 9 Hotfix [See KB885492 for more information]
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
Zinio Reader
ZoneAlarm Security Suite
-- HijackThis (run as Administrator.exe) ---------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 2:58:19 PM, on 3/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Photomax Digital Developer\DDStub.exe
C:\Program Files\iolo\System Mechanic 7\SMSystemAnalyzer.exe
C:\Program Files\iolo\System Mechanic 7\SystemGuardAlerter.exe
C:\Program Files\Sana Security\Primary Response SafeConnect\agent\bin\SanaSafeConnect.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\Program Files\Zinio\ZinioDeliveryManager.exe
C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exe
C:\Program Files\iolo\System Mechanic 7\IoloSGCtrl.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sana Security\Primary Response SafeConnect\agent\bin\SanaAgent.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Sana Security\Primary Response SafeConnect\agent\bin\SanaMonitor.exe
C:\WINDOWS\System32\alg.exe
C:\Documents and Settings\Administrator\Desktop\dss.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
C:\HIJACK~1\ADMINI~1.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [Synchronization Manager] "C:\WINDOWS\system32\mobsync.exe" /logon
O4 - HKLM\..\Run: [DigitalDeveloper] "C:\Program Files\Photomax Digital Developer\DDStub.exe"
O4 - HKLM\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 7\SMSystemAnalyzer.exe"
O4 - HKLM\..\Run: [SystemGuardAlerter] "C:\Program Files\iolo\System Mechanic 7\SystemGuardAlerter.exe"
O4 - HKLM\..\Run: [SanaSafeConnect] "C:\Program Files\Sana Security\Primary Response SafeConnect\agent\bin\SanaSafeConnect.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O4 - HKCU\..\Run: [Zinio DLM] C:\Program Files\Zinio\ZinioDeliveryManager.exe /autostart
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/english/kavwebscan_unicode.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1171005507397O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exe
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic 7\IoloSGCtrl.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SanaSafeConnectAgent - Unknown owner - C:\Program Files\Sana Security\Primary Response SafeConnect\agent\bin\SanaAgent.exe" SanaSafeConnectAgent (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
-- HijackThis Fixed Entries (C:\HIJACK~1\backups\) -----------------------------
backup-20070221-185243-185 O2 - BHO: (no name) - {BD257DCB-B5D0-459F-9F7D-42E27AC55266} - C:\WINDOWS\System32\kdphtdpf.dll (file missing)
backup-20070221-185243-326 O4 - HKLM\..\Run: [NI.UWAS5LP_0001_0811] "C:\Documents and Settings\jm.BAINDT003.000\Local Settings\Temporary Internet Files\Content.IE5\IWJEITG0\WAS5Scan[1].exe"
backup-20070221-185243-387 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
backup-20070221-185243-409 O2 - BHO: (no name) - {60DF53E6-41F2-481D-9916-0B1115E42A08} - C:\WINDOWS\System32\kdphtdpf.dll (file missing)
backup-20070221-185243-433 O2 - BHO: (no name) - {C3611AF4-EF36-4167-94C1-B204F2D526F9} - C:\WINDOWS\java\mwsawve.dll (file missing)
backup-20070221-185243-909 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
backup-20070225-135209-887 O4 - HKLM\..\Run: [NI.UWAS5LP_0001_0811] "C:\Documents and Settings\jm.BAINDT003.000\Local Settings\Temporary Internet Files\Content.IE5\IWJEITG0\WAS5Scan[1].exe"
backup-20070225-183337-898 O4 - HKLM\..\Run: [NI.UWAS5LP_0001_0811] "C:\Documents and Settings\jm.BAINDT003.000\Local Settings\Temporary Internet Files\Content.IE5\IWJEITG0\WAS5Scan[1].exe"
backup-20070305-152011-226 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20070305-152011-673 O4 - HKLM\..\Run: [NI.UWAS5LP_0001_0811] "C:\Documents and Settings\jm.BAINDT003.000\Local Settings\Temporary Internet Files\Content.IE5\IWJEITG0\WAS5Scan[1].exe"
backup-20070305-152011-883 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
backup-20070305-152011-893 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20070306-160944-970 O4 - HKLM\..\Run: [NI.UWAS5LP_0001_0811] "C:\Documents and Settings\jm.BAINDT003.000\Local Settings\Temporary Internet Files\Content.IE5\IWJEITG0\WAS5Scan[1].exe"
backup-20070308-065003-556 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20070308-065003-945 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20070308-081950-426 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20070308-081950-986 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20070312-081015-867 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20070312-081015-981 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20070313-114229-297 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20070313-114229-339 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20070313-121815-188 O17 - HKLM\System\CS1\Services\Tcpip\..\{755BF88C-460B-4D04-826A-A67BCE20A0CE}: NameServer = 4.2.2.2,4.2.2.3
backup-20070313-121815-233 O17 - HKLM\System\CS2\Services\Tcpip\..\{755BF88C-460B-4D04-826A-A67BCE20A0CE}: NameServer = 4.2.2.2,4.2.2.3
backup-20070313-121815-989 O17 - HKLM\System\CCS\Services\Tcpip\..\{755BF88C-460B-4D04-826A-A67BCE20A0CE}: NameServer = 4.2.2.2,4.2.2.3
backup-20070315-102339-192 O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cabbackup-20070315-102339-646 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20070315-102339-653 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20070315-102346-411 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab-- File Associations -----------------------------------------------------------
.js - JSFile - NOTEPAD.EXE %1.reg - regfile - NOTEPAD.EXE %1.scr - scrfile - NOTEPAD.EXE %1.vbs - VBSFile - NOTEPAD.EXE %1-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 ac97intc (Intel® 82801 Audio Driver Install Service (WDM)) - c:\windows\system32\drivers\ac97intc.sys
R3 i81x - c:\windows\system32\drivers\i81xnt5.sys
R3 SanaSafeConnectDriver - c:\program files\sana security\primary response safeconnect\agent\driver\platform_xp\safeconnectdriver.sys
R3 SanaSafeConnectShim - c:\program files\sana security\primary response safeconnect\agent\driver\platform_xp\safeconnectshim.sys
S0 kl1 - c:\windows\system32\drivers\kl1.sys (file missing)
S3 HidBatt (HID UPS Battery Driver) - c:\windows\system32\drivers\hidbatt.sys
S3 iAimFP0 - c:\windows\system32\drivers\wadv01nt.sys
S3 iAimFP1 - c:\windows\system32\drivers\wadv02nt.sys
S3 iAimFP2 - c:\windows\system32\drivers\wadv05nt.sys
S3 iAimFP3 - c:\windows\system32\drivers\wsiintxx.sys
S3 iAimFP4 - c:\windows\system32\drivers\wvchntxx.sys
S3 iAimFP5 - c:\windows\system32\drivers\wadv07nt.sys
S3 iAimFP6 - c:\windows\system32\drivers\wadv08nt.sys
S3 iAimFP7 - c:\windows\system32\drivers\wadv09nt.sys
S3 iAimTV0 - c:\windows\system32\drivers\watv01nt.sys
S3 iAimTV1 - c:\windows\system32\drivers\watv02nt.sys
S3 iAimTV2 - c:\windows\system32\drivers\watv03nt.sys (file missing)
S3 iAimTV3 - c:\windows\system32\drivers\watv04nt.sys
S3 iAimTV4 - c:\windows\system32\drivers\wch7xxnt.sys
S3 iAimTV5 - c:\windows\system32\drivers\watv10nt.sys
S3 iAimTV6 - c:\windows\system32\drivers\watv06nt.sys
S3 TSP - c:\windows\system32\drivers\klif.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 IOLO_SRV (iolo System Guard) - c:\program files\iolo\system mechanic 7\iolosgctrl.exe
R2 ioloDMV (iolo DMV Service) - c:\program files\iolo\common\lib\iolodmvsvc.exe
R2 SanaSafeConnectAgent - "c:\program files\sana security\primary response safeconnect\agent\bin\sanaagent.exe" sanasafeconnectagent
-- Scheduled Tasks -------------------------------------------------------------
2007-03-17 17:01:49 354 --a------ C:\WINDOWS\Tasks\Uniblue SpyEraser.job<UNIBLU~1.JOB>
2007-03-11 18:47:23 402 --ah----- C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job<MPSCHE~2.JOB>
-- Files created between 2007-02-23 and 2007-03-23 -----------------------------
2007-03-23 09:45:39 0 d--h----- C:\Documents and Settings\Administrator\Application Data\Move Networks<MOVENE~1>
2007-03-21 08:33:10 0 d-------- C:\Documents and Settings\Administrator\Application Data\ContentGuard<CONTEN~1>
2007-03-21 08:31:39 0 d-------- C:\Program Files\Common Files\Zinio
2007-03-21 08:31:29 0 d-------- C:\Program Files\Zinio
2007-03-20 14:46:33 0 d-------- C:\Documents and Settings\jmain\Application Data\MailFrontier<MAILFR~1>
2007-03-20 14:12:32 0 d-------- C:\Documents and Settings\Administrator\Application Data\MailFrontier<MAILFR~1>
2007-03-20 13:50:36 1087216 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-03-19 16:02:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab<KASPER~1>
2007-03-19 16:01:49 0 d-------- C:\WINDOWS\system32\Kaspersky Lab<KASPER~1>
2007-03-17 22:57:02 0 d-------- C:\Program Files\a-squared Anti-Dialer<A-SQUA~2>
2007-03-17 22:17:09 0 d-------- C:\Program Files\a-squared Free<A-SQUA~1>
2007-03-17 22:01:15 0 d-------- C:\Documents and Settings\Administrator\.housecall6.6<HOUSEC~1.6>
2007-03-17 16:01:41 0 d-------- C:\Documents and Settings\Administrator\Application Data\Uniblue
2007-03-17 16:00:42 0 d-------- C:\Program Files\Uniblue
2007-03-17 12:47:31 0 d-------- C:\Program Files\Learn2.com
2007-03-17 12:45:43 214528 --a------ C:\WINDOWS\Uninvia2.exe
2007-03-17 12:45:40 368640 --a------ C:\WINDOWS\struntme.dll
2007-03-17 12:45:40 34816 --a------ C:\WINDOWS\_Setup.dll
2007-03-17 12:45:39 254005 --a------ C:\WINDOWS\MSVCRT.DLL
2007-03-17 12:45:37 1334032 --a------ C:\WINDOWS\MSVBVM50.DLL
2007-03-17 12:45:36 995383 --a------ C:\WINDOWS\MFC42.DLL
2007-03-16 08:31:35 0 d-------- C:\Program Files\ScanSpyware v3.8.0.4<SCANSP~1.4>
2007-03-16 04:26:39 164 --a------ C:\install.dat
2007-03-15 17:27:59 626688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-03-15 17:14:01 0 d-------- C:\Program Files\Sana Security<SANASE~1>
2007-03-15 13:05:09 0 d-------- C:\Documents and Settings\jmain\Application Data\Lavasoft
2007-03-15 09:22:23 0 d-------- C:\Program Files\Lavasoft
2007-03-14 13:42:07 0 d-------- C:\Documents and Settings\jmain\Application Data\Sun
2007-03-14 11:24:03 0 d-------- C:\Program Files\MTV Networks<MTVNET~1>
2007-03-14 11:09:09 0 d-------- C:\Program Files\Windows Media Connect 2<WI4DF6~1>
2007-03-14 11:04:03 0 d-------- C:\WINDOWS\system32\LogFiles
2007-03-14 11:04:03 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2007-03-14 08:17:29 0 d-------- C:\Program Files\Common Files\Java
2007-03-14 08:12:47 370312 --a------ C:\jre-6-windows-i586-iftw.exe<JRE-6-~1.EXE>
2007-03-12 21:51:01 0 d-------- C:\Documents and Settings\Administrator\Application Data\WholeSecurity<WHOLES~1>
2007-03-12 20:48:48 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<SPYBOT~1>
2007-03-12 12:41:11 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
2007-03-12 10:54:10 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2007-03-12 10:53:37 0 d-------- C:\Documents and Settings\Administrator\Application Data\iolo
2007-03-12 07:54:01 0 d-------- C:\Program Files\SpywareGuard<SPYWAR~1>
2007-03-11 19:03:19 0 d-------- C:\WINDOWS\SxsCaPendDel<SXSCAP~1>
2007-03-10 21:31:55 0 d-------- C:\Program Files\MSBuild
2007-03-10 21:11:15 0 d-------- C:\WINDOWS\system32\XPSViewer<XPSVIE~1>
2007-03-10 21:06:49 0 d-------- C:\Program Files\Reference Assemblies<REFERE~1>
2007-03-10 20:48:24 14048 -----n--- C:\WINDOWS\system32\spmsg2.dll
2007-03-10 16:30:49 0 d-------- C:\Documents and Settings\jmain\Application Data\Intuit
2007-03-08 20:27:41 0 d-------- C:\Documents and Settings\Guest\Application Data\SUPERAntiSpyware.com<SUPERA~1.COM>
2007-03-08 17:17:36 0 d-------- C:\Documents and Settings\Guest\Application Data\Sun
2007-03-07 21:29:47 0 d-------- C:\Documents and Settings\Guest\Application Data\Adobe
2007-03-07 21:28:51 0 d-------- C:\Documents and Settings\Guest\Application Data\iolo
2007-03-07 21:25:49 1048576 --ah----- C:\Documents and Settings\Guest\NTUSER.DAT
2007-03-07 16:44:51 0 d-------- C:\Documents and Settings\jmain\Application Data\SUPERAntiSpyware.com<SUPERA~1.COM>
2007-03-07 16:15:57 0 d-------- C:\Documents and Settings\jmain\Application Data\Adobe
2007-03-07 16:14:59 0 d-------- C:\Documents and Settings\jmain\Application Data\iolo
2007-03-05 17:18:18 0 --a------ C:\WINDOWS\system32\CMMGR32.EXE
2007-03-05 17:01:15 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com<SUPERA~1.COM>
2007-03-05 17:00:25 0 d-------- C:\Documents and Settings\jm.BAINDT003.000\Application Data\SUPERAntiSpyware.com<SUPERA~1.COM>
2007-02-28 13:05:36 155648 --a------ C:\WINDOWS\system32\ssleay32.dll
2007-02-28 13:05:35 696320 --a------ C:\WINDOWS\system32\libeay32.dll
2007-02-28 13:05:34 0 d-------- C:\Documents and Settings\LocalService\Application Data\iolo
2007-02-28 13:02:29 25264 --a------ C:\WINDOWS\system32\smrgdf.exe
2007-02-28 13:02:29 41472 --a------ C:\WINDOWS\system32\iolobtdfg.exe<IOLOBT~1.EXE>
2007-02-28 13:02:23 436840 --a------ C:\WINDOWS\system32\Incinerator.dll<INCINE~1.DLL>
2007-02-28 13:01:39 0 d-------- C:\Program Files\iolo
2007-02-28 12:54:46 0 d-------- C:\Documents and Settings\jm.BAINDT003.000\Application Data\iolo
2007-02-28 12:54:46 0 d-------- C:\Documents and Settings\All Users\Application Data\iolo
2007-02-25 17:08:19 0 d-------- C:\Documents and Settings\jm.BAINDT003.000\Application Data\Help
2007-02-25 17:03:35 348160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-02-25 17:03:35 499712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-02-25 15:02:02 0 d-------- C:\!KillBox
-- Find3M Report ---------------------------------------------------------------
2007-03-23 14:35:21 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-03-23 10:00:25 512 --a------ C:\ScanSectorLog.dat<SCANSE~1.DAT>
2007-03-19 19:20:44 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft<MICROS~1>
2007-03-15 17:16:12 0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>
2007-03-14 11:54:45 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia<MACROM~1>
2007-03-14 08:17:40 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2007-03-14 08:17:27 0 d-------- C:\Program Files\Java
2007-03-12 19:39:39 0 d-------- C:\Program Files\Photomax Digital Developer<PHOTOM~1>
2007-03-12 19:37:14 0 d-------- C:\Program Files\Messenger<MESSEN~1>
2007-03-09 00:02:00 75512 --a------ C:\WINDOWS\zllsputility.exe<ZLLSPU~1.EXE>
2007-03-07 13:06:42 23552 --a------ C:\WINDOWS\xobglu32.dll
2007-03-07 13:06:42 63488 --a------ C:\WINDOWS\xobglu16.dll
2007-02-19 19:35:55 0 d-------- C:\Program Files\ItsDeductible2006<ITSDED~1>
2007-02-19 19:34:55 0 d-------- C:\Program Files\Common Files\AnswerWorks 4.0<ANSWER~1.0>
2007-02-19 19:34:18 0 d-------- C:\Program Files\Common Files\InstallShield<INSTAL~1>
2007-02-19 19:28:54 0 d-------- C:\Program Files\Common Files\Intuit
2007-02-19 19:26:03 0 d-------- C:\Program Files\TurboTax
2007-02-14 17:16:11 0 d-------- C:\Program Files\Google
2007-02-09 10:51:57 0 d--h----- C:\Program Files\WindowsUpdate<WINDOW~2>
2007-02-08 10:47:03 0 d-------- C:\Program Files\MSXML 4.0<MSXML4~1.0>
2007-02-07 10:08:27 0 d-------- C:\Program Files\Common Files\Adobe
2007-02-06 19:27:29 0 d-------- C:\Program Files\Movie Maker<MOVIEM~1>
2007-02-06 19:20:40 0 d-------- C:\Program Files\Windows NT<WINDOW~1>
2007-02-06 19:17:33 250032 -rahs---- C:\ntldr
2007-02-02 16:24:35 201 --a------ C:\WINDOWS\PowerReg.dat
2007-01-30 10:25:43 0 d-------- C:\Program Files\SesameWorkshop<SESAME~1>
2007-01-08 19:01:14 17408 --a------ C:\WINDOWS\system32\corpol.dll
-- Registry Dump ---------------------------------------------------------------
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Uniblue SpyEraser"="\"C:\\Program Files\\Uniblue\\SpyEraser\\SpyEraser.exe\" -m"
"Zinio DLM"="C:\\Program Files\\Zinio\\ZinioDeliveryManager.exe /autostart"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Synchronization Manager"="\"C:\\WINDOWS\\system32\\mobsync.exe\" /logon"
"DigitalDeveloper"="\"C:\\Program Files\\Photomax Digital Developer\\DDStub.exe\""
"SMSystemAnalyzer"="\"C:\\Program Files\\iolo\\System Mechanic 7\\SMSystemAnalyzer.exe\""
"SystemGuardAlerter"="\"C:\\Program Files\\iolo\\System Mechanic 7\\SystemGuardAlerter.exe\""
"SanaSafeConnect"="\"C:\\Program Files\\Sana Security\\Primary Response SafeConnect\\agent\\bin\\SanaSafeConnect.exe\""
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
-- End of Deckard's System Scanner: finished at 2007-03-23 at 15:01:12 ---------