Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
May 13 2008, 01:17 PM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 13-May 08 Member No.: 208,737 |
Scan saved at 2:15:08 PM, on 5/12/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe c:\Program Files\Common Files\Symantec Shared\ccProxy.exe c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\windows\system\hpsysdrv.exe C:\HP\KBD\KBD.EXE C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\AGRSMMSG.exe C:\WINDOWS\system32\svchost.exe c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\BroadJump\Client Foundation\CFD.exe C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\system32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...=EN_US&c=Q4 04&bd=presario&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...e=EN_US&c=Q 404&bd=presario&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...e=EN_US&c=Q 404&bd=presario&pf=desktop R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user') O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk.disabled O4 - Global Startup: SBC Self Support Tool.lnk.disabled O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2DEF4530-8CE6-41C9-84B6-A54536C90213} (Crystal Report Viewer Control 9) - http://www.ugaais.com/viewer9/activeXViewe...tivexviewer.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} - http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - http://aolcc.aol.com/computercheckup/qdiagcc.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...ols/en/x86/clie nt/muweb_site.cab?1210477749796 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E9552735-0D73-4652-B82E-8A0C2C8 713D2}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe -- End of file - 10349 bytes |
|
|
|
![]() |
May 13 2008, 02:00 PM
Post
#2
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 15,582 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you.
Please go to this page and scroll down to step 6. http://www.bleepingcomputer.com/forums/topic34773.html Follow the directions there to run DSS and then post those logs back here in your next reply. -------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it! ======================================================== |
|
|
|
May 13 2008, 08:52 PM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 13-May 08 Member No.: 208,737 |
Sam,
Thank you so much for your speedy replay!!! You rock! Please instruct me what to do next and I will comply Deckard's System Scanner v20071014.68 Run by Compaq_Owner on 2008-05-12 21:44:40 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 110: 2008-05-13 03:44:49 UTC - RP761 - Deckard's System Scanner Restore Point 109: 2008-05-12 20:19:08 UTC - RP760 - Spybot-S&D Spyware removal 108: 2008-05-12 09:39:40 UTC - RP759 - System Checkpoint 107: 2008-05-11 09:00:21 UTC - RP758 - Software Distribution Service 3.0 106: 2008-05-11 04:10:27 UTC - RP757 - Software Distribution Service 3.0 -- First Restore Point -- 1: 2008-02-13 20:58:35 UTC - RP652 - System Checkpoint Backed up registry hives. Performed disk cleanup. Total Physical Memory: 504 MiB (512 MiB recommended). -- HijackThis (run as Compaq_Owner.exe) ---------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:46:15 PM, on 5/12/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe c:\Program Files\Common Files\Symantec Shared\ccProxy.exe c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\WINDOWS\Explorer.EXE c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\windows\system\hpsysdrv.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\BroadJump\Client Foundation\CFD.exe C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Compaq_Owner\Desktop\dss.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\PROGRA~1\TRENDM~1\HIJACK~1\Compaq_Owner.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user') O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk.disabled O4 - Global Startup: SBC Self Support Tool.lnk.disabled O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2DEF4530-8CE6-41C9-84B6-A54536C90213} (Crystal Report Viewer Control 9) - http://www.ugaais.com/viewer9/activeXViewe...tivexviewer.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} - http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - http://aolcc.aol.com/computercheckup/qdiagcc.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1210477749796 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E9552735-0D73-4652-B82E-8A0C2C8713D2}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe -- End of file - 10283 bytes -- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) ----------- backup-20080512-140209-448 O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe backup-20080512-140251-806 O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing) -- File Associations ----------------------------------------------------------- .cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%* .cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%* -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver> -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- All services whitelisted. -- Device Manager: Disabled ---------------------------------------------------- No disabled devices found. -- Scheduled Tasks ------------------------------------------------------------- 2008-05-12 20:56:39 378 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job 2008-05-12 17:25:34 406 --ah----- C:\WINDOWS\Tasks\User_Feed_Synchronization-{B762FE03-A8B1-48EF-A136-ACA43880C8C5}.job 2008-05-12 15:00:49 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job 2008-05-12 12:35:25 426 --a------ C:\WINDOWS\Tasks\ParetoLogic Update.job 2008-05-10 20:35:38 420 --a------ C:\WINDOWS\Tasks\Pareto UNS.job 2008-05-10 20:35:36 462 --a------ C:\WINDOWS\Tasks\ParetoLogic Anti-Spyware.job 2006-03-07 23:26:17 314 --a------ C:\WINDOWS\Tasks\XoftSpy.job -- Files created between 2008-04-12 and 2008-05-12 ----------------------------- 2008-05-12 17:58:38 967 --a------ C:\WINDOWS\ScUnin.pif 2008-05-12 17:58:38 94208 --a------ C:\WINDOWS\ScUnin.exe <Not Verified; Blizzard Entertainment; Starcraft Uninstaller> 2008-05-12 17:58:38 13044 --a------ C:\WINDOWS\scunin.dat 2008-05-12 13:44:31 0 d-------- C:\Program Files\Trend Micro 2008-05-11 03:00:39 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2 2008-05-10 22:31:14 0 d-------- C:\WINDOWS\Prefetch 2008-05-10 22:23:07 0 d-------- C:\WINDOWS\system32\scripting 2008-05-10 22:23:06 0 d-------- C:\WINDOWS\l2schemas 2008-05-10 22:23:05 0 d-------- C:\WINDOWS\system32\en 2008-05-10 22:23:05 0 d-------- C:\WINDOWS\system32\bits 2008-05-10 22:20:45 0 d-------- C:\WINDOWS\ServicePackFiles 2008-05-10 22:14:06 0 d-------- C:\WINDOWS\EHome 2008-05-10 20:35:34 0 d-------- C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware 2008-05-10 20:35:28 0 d-------- C:\Program Files\ParetoLogic 2008-05-10 20:35:27 0 d-------- C:\Program Files\Common Files\ParetoLogic 2008-05-10 00:34:03 0 d-------- C:\ie-spyad_zo 2008-05-09 23:01:05 0 d-------- C:\Program Files\Panda Security 2008-05-09 23:01:04 0 --a------ C:\WINDOWS\mozver.dat 2008-05-09 21:40:02 0 d-------- C:\kav 2008-05-09 20:30:24 0 d-------- C:\Program Files\Common Files\Blizzard Entertainment -- Find3M Report --------------------------------------------------------------- 2008-05-12 21:45:44 0 d-------- C:\Program Files\Common Files\Symantec Shared 2008-05-12 18:09:46 0 d-------- C:\Program Files\Starcraft 2008-05-12 15:03:13 0 d-------- C:\Program Files\Recovery for Works 2008-05-12 14:58:00 0 d-------- C:\Program Files\Common Files 2008-05-12 13:23:00 0 d-------- C:\Program Files\Microsoft Works 2008-05-12 12:49:39 0 d-------- C:\Program Files\PokerStars 2008-05-10 22:30:35 0 d-------- C:\Program Files\Messenger 2008-05-10 22:23:04 0 d-------- C:\Program Files\Movie Maker 2008-05-10 22:20:32 0 d-------- C:\Program Files\Windows NT 2008-02-29 23:50:37 2557 --a------ C:\WINDOWS\unins000.dat 2008-02-29 23:46:00 691545 --a------ C:\WINDOWS\unins000.exe -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [05/07/1998 05:04 PM] "KBD"="C:\HP\KBD\KBD.EXE" [02/11/2003 09:02 PM] "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [04/14/2004 09:43 PM] "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [08/20/2004 05:51 PM] "AGRSMMSG"="AGRSMMSG.exe" [03/04/2005 01:01 PM C:\WINDOWS\AGRSMMSG.exe] "PS2"="C:\WINDOWS\system32\ps2.exe" [09/12/2003 09:13 PM] "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [03/08/2006 12:08 AM] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [12/21/2005 01:54 PM] "BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [09/10/2002 10:26 PM] "Motive SmartBridge"="C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [12/10/2003 05:52 AM] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [12/15/2005 12:18 PM] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [11/03/2006 07:20 PM] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [10/10/2007 08:51 PM] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [01/25/2007 12:06 AM] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [04/13/2008 06:12 PM] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/13/2008 06:12 PM] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 12:43 PM] [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce] "RunNarrator"=Narrator.exe C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Compaq Connections.lnk - C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe [8/9/2004 2:59:58 AM] HP Digital Imaging Monitor.lnk.disabled [5/22/2006 1:49:26 PM] SBC Self Support Tool.lnk.disabled [4/10/2006 11:48:35 PM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{51C55F9E-C308-4c95-89AB-8858D8AFD819}"= C:\Program Files\ParetoLogic\Anti-Spyware\PASShlExt.dll [05/06/2008 03:16 PM 98304] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "System"="kdvsn.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy] C:\WINDOWS\System32\dimsntfy.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] @="Volume shadow copy" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background "Yahoo! Pager"=1 "MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe "IgfxTray"=C:\WINDOWS\system32\igfxtray.exe "AlcxMonitor"=ALCXMNTR.EXE "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe "RealTray"=C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER "UserFaultCheck"=%systemroot%\system32\dumprep 0 -u [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] eapsvcs eaphost dot3svc dot3svc HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs napagent hkmsvc [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5513f4d4-1ad0-11d9-a996-806d6172696f}] AutoRun\command- E:\SETUP.EXE -- Hosts ----------------------------------------------------------------------- 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 8396 more entries in hosts file. -- End of Deckard's System Scanner: finished at 2008-05-12 21:49:20 ------------ |
|
|
|
May 13 2008, 10:59 PM
Post
#4
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 15,582 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
Download and scan with SUPERAntiSpyware Free for Home Users
-------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it! ======================================================== |
|
|
|
May 13 2008, 11:37 PM
Post
#5
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 13-May 08 Member No.: 208,737 |
I ran the scan and it identified no items. What next?
|
|
|
|
May 13 2008, 11:43 PM
Post
#6
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 13-May 08 Member No.: 208,737 |
SUPERAntiSpyware Scan Log
http://www.superantispyware.com Generated 05/13/2008 at 00:36 AM Application Version : 4.0.1154 Core Rules Database Version : 3460 Trace Rules Database Version: 1451 Scan type : Complete Scan Total Scan Time : 00:27:00 Memory items scanned : 458 |
|
|
|
May 13 2008, 11:59 PM
Post
#7
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 13-May 08 Member No.: 208,737 |
Application Version : 4.0.1154
Core Rules Database Version : 3460 Trace Rules Database Version: 1451 Scan type : Complete Scan Total Scan Time : 00:27:00 Memory items scanned : 458 Memory threats detected : 0 Registry items scanned : 5352 Registry threats detected : 0 File items scanned : 60475 File threats detected : 0 |
|
|
|
May 14 2008, 04:40 PM
Post
#8
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 15,582 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
I want to check out a suspicious file that shows up in your log.
Can you post the info from Spybot that is showing the infected items? -------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it! ======================================================== |
|
|
|
May 14 2008, 08:42 PM
Post
#9
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 13-May 08 Member No.: 208,737 |
Hi Sam,
Here is the virusscan report... The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file Next I will run my Spybot report again and submit results. |
|
|
|
May 14 2008, 09:13 PM
Post
#10
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 13-May 08 Member No.: 208,737 |
Here is the full report from my last Spybot scan
--- Search result list --- Zlob.DNSChanger.Rtk: [SBI $FE3023DF] Settings (Registry value, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System=...KDVSN.EXE... Common Dialogs: History (12 files) (Registry key, nothing done) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU Log: Activity: SchedLgU.Txt (Backup file, nothing done) C:\WINDOWS\SchedLgU.Txt Log: Activity: imsins.log (Backup file, nothing done) C:\WINDOWS\imsins.log Log: Activity: OEWABLog.txt (Backup file, nothing done) C:\WINDOWS\OEWABLog.txt Log: Install: comsetup.log (Backup file, nothing done) C:\WINDOWS\comsetup.log Log: Install: ocgen.log (Backup file, nothing done) C:\WINDOWS\ocgen.log Log: Install: setupact.log (Backup file, nothing done) C:\WINDOWS\setupact.log Log: Install: setupapi.log (Backup file, nothing done) C:\WINDOWS\setupapi.log Log: Install: setuplog.txt (Backup file, nothing done) C:\WINDOWS\setuplog.txt Log: Install: svcpack.log (Backup file, nothing done) C:\WINDOWS\svcpack.log Log: Install: wmsetup.log (Backup file, nothing done) C:\WINDOWS\wmsetup.log Log: Install: DtcInstall.log (Backup file, nothing done) C:\WINDOWS\DtcInstall.log Log: Shutdown: System32\wbem\logs\mofcomp.log (Backup file, nothing done) C:\WINDOWS\System32\wbem\logs\mofcomp.log Log: Shutdown: System32\wbem\logs\setup.log (Backup file, nothing done) C:\WINDOWS\System32\wbem\logs\setup.log Log: Shutdown: System32\wbem\logs\wbemcore.log (Backup file, nothing done) C:\WINDOWS\System32\wbem\logs\wbemcore.log Log: Shutdown: System32\wbem\logs\wbemess.lo_ (Backup file, nothing done) C:\WINDOWS\System32\wbem\logs\wbemess.lo_ Log: Shutdown: System32\wbem\logs\wbemess.log (Backup file, nothing done) C:\WINDOWS\System32\wbem\logs\wbemess.log Log: Shutdown: System32\wbem\logs\wmiprov.log (Backup file, nothing done) C:\WINDOWS\System32\wbem\logs\wmiprov.log MS Media Player: [SBI $5C51E349] Client ID (Registry change, nothing done) HKEY_USERS\.DEFAULT\Software\Microsoft\MediaPlayer\Player\Settings\Client ID MS Media Player: [SBI $5C51E349] Client ID (Registry change, nothing done) HKEY_USERS\S-1-5-18\Software\Microsoft\MediaPlayer\Player\Settings\Client ID MS Direct3D: [SBI $7FB7B83F] Most recent application (Registry change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name MS DirectDraw: [SBI $EB49D5AF] Most recent application (Registry change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name MS Search Assistant: [SBI $AE0C4647] Typed search terms history (Registry key, nothing done) HKEY_USERS\S-1-5-21-3341656437-3043363843-2328747555-1009\Software\Microsoft\Search Assistant\ACMru Windows Explorer: [SBI $AA0766B5] Stream history (2 files) (Registry key, nothing done) HKEY_USERS\S-1-5-21-3341656437-3043363843-2328747555-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU Windows Explorer: [SBI $2026AFB6] User Assistant history IE (6 files) (Registry key, nothing done) HKEY_USERS\S-1-5-21-3341656437-3043363843-2328747555-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count Windows Explorer: [SBI $6107D172] User Assistant history files (61 files) (Registry key, nothing done) HKEY_USERS\S-1-5-21-3341656437-3043363843-2328747555-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count Windows Explorer: [SBI $B7EBA926] Last visited history (5 files) (Registry key, nothing done) HKEY_USERS\S-1-5-21-3341656437-3043363843-2328747555-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU Windows Explorer: [SBI $D20DA0AD] Recent file global history (Registry key, nothing done) HKEY_USERS\S-1-5-21-3341656437-3043363843-2328747555-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs Cookie: Cookie (3) (Cookie, nothing done) Cache: Cache (78) (Cache, nothing done) History: History (20) (History, nothing done) Cookie: Cookie (18) (Cookie, nothing done) --- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) --- 2008-01-28 blindman.exe (1.0.0.7) 2008-01-28 SDDelFile.exe (1.0.2.4) 2008-01-28 SDMain.exe (1.0.0.5) 2007-10-07 SDShred.exe (1.0.1.2) 2008-01-28 SDUpdate.exe (1.0.8.8) 2008-01-28 SDWinSec.exe (1.0.0.11) 2008-01-28 SpybotSD.exe (1.5.2.20) 2008-01-28 TeaTimer.exe (1.5.2.16) 2004-04-27 unins000.exe (51.13.0.0) 2008-02-29 unins001.exe (51.49.0.0) 2008-01-28 Update.exe (1.4.0.6) 2008-01-28 advcheck.dll (1.5.4.5) 2007-04-02 aports.dll (2.1.0.0) 2004-05-12 borlndmm.dll (7.0.4.453) 2004-05-12 delphimm.dll (7.0.4.453) 2007-11-17 DelZip179.dll (1.79.7.4) 2008-01-28 SDFiles.dll (1.5.1.19) 2008-01-28 SDHelper.dll (1.5.0.11) 2006-02-20 Tools.dll (2.0.0.2) 2004-05-12 UnzDll.dll (1.73.1.1) 2004-05-12 ZipDll.dll (1.73.2.0) 2008-04-16 Includes\Adware.sbi (*) 2008-05-07 Includes\AdwareC.sbi (*) 2008-05-07 Includes\Cookies.sbi (*) 2007-12-26 Includes\Dialer.sbi (*) 2008-05-07 Includes\DialerC.sbi (*) 2008-05-07 Includes\HeavyDuty.sbi (*) 2008-04-30 Includes\Hijackers.sbi (*) 2008-05-07 Includes\HijackersC.sbi (*) 2008-04-30 Includes\Keyloggers.sbi (*) 2008-05-07 Includes\KeyloggersC.sbi (*) 2004-11-29 Includes\LSP.sbi (*) 2008-04-22 Includes\Malware.sbi (*) 2008-05-07 Includes\MalwareC.sbi (*) 2008-03-26 Includes\PUPS.sbi (*) 2008-05-07 Includes\PUPSC.sbi (*) 2008-05-07 Includes\Revision.sbi (*) 2008-01-09 Includes\Security.sbi (*) 2008-05-07 Includes\SecurityC.sbi (*) 2008-04-16 Includes\Spybots.sbi (*) 2008-05-07 Includes\SpybotsC.sbi (*) 2008-04-16 Includes\Spyware.sbi (*) 2008-05-07 Includes\SpywareC.sbi (*) 2007-11-06 Includes\Tracks.uti (*) 2008-04-30 Includes\Trojans.sbi (*) 2008-05-07 Includes\TrojansC.sbi (*) 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-06-06 Plugins\TCPIPAddress.dll --- System information --- Windows XP (Build: 2600) Service Pack 3 (5.1.2600) / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366) / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) / MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2 / MSXML4SP2: Security update for MSXML4 SP2 (KB936181) / Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB898458) / Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB923723) / Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs / Windows / SP1: Microsoft National Language Support Downlevel APIs / Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399) / Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782) / Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683) / Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398) / Windows Media Player 9: Security Update for Windows Media Player 9 (KB917734) / Windows XP: Security Update for Windows XP (KB923689) / Windows XP: Security Update for Windows XP (KB941569) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB928090) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB929969) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB931768) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB933566) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB937143) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB939653) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB942615) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB944533) / Windows XP / SP0: Hotfix for Windows Internet Explorer 7 (KB947864) / Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP / Windows XP / SP3: Windows XP Service Pack 3 / Windows XP OOB / SP10: High Definition Audio Driver Package - KB835221 --- Startup entries list --- Located: HK_LM:Run, Adobe Reader Speed Launcher command: "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" file: C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe size: 39792 MD5: E28D00EC675F5F5A5A0555E7A4523A6E Located: HK_LM:Run, AGRSMMSG command: AGRSMMSG.exe file: C:\WINDOWS\AGRSMMSG.exe size: 88209 MD5: 230EA041666125B6812FE3FF964B2DF3 Located: HK_LM:Run, BJCFD command: C:\Program Files\BroadJump\Client Foundation\CFD.exe file: C:\Program Files\BroadJump\Client Foundation\CFD.exe size: 368706 MD5: BA9AF06103549A96F77036861FDE357B Located: HK_LM:Run, ccApp command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe size: 71328 MD5: F1F54205EAAD3E37CA2C5A13437BB947 Located: HK_LM:Run, HotKeysCmds command: C:\WINDOWS\system32\hkcmd.exe file: C:\WINDOWS\system32\hkcmd.exe size: 118784 MD5: EA5DD164296F66241BEAD39E12FA69F2 Located: HK_LM:Run, HP Software Update command: C:\Program Files\HP\HP Software Update\HPWuSchd2.exe file: C:\Program Files\HP\HP Software Update\HPWuSchd2.exe size: 49152 MD5: 65ED174C0B836D4CFA489712278CEF7B Located: HK_LM:Run, hpsysdrv command: c:\windows\system\hpsysdrv.exe file: c:\windows\system\hpsysdrv.exe size: 52736 MD5: 06A1ECB63DF139EC639E084D4AB3C9D7 Located: HK_LM:Run, KBD command: C:\HP\KBD\KBD.EXE file: C:\HP\KBD\KBD.EXE size: 61440 MD5: 4A95F15B706B8FD9EC8715B6401EAB7B Located: HK_LM:Run, Motive SmartBridge command: C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe file: C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe size: 380928 MD5: F055034225687B9F9D176985F0108145 Located: HK_LM:Run, PS2 command: C:\WINDOWS\system32\ps2.exe file: C:\WINDOWS\system32\ps2.exe size: 98304 MD5: 8B3D67651581347878CD7D8FBF016A64 Located: HK_LM:Run, Recguard command: C:\WINDOWS\SMINST\RECGUARD.EXE file: C:\WINDOWS\SMINST\RECGUARD.EXE size: 233472 MD5: 310F1E8A0781887BA1C217448C0E4D48 Located: HK_LM:Run, Symantec NetDriver Monitor command: C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer file: C:\PROGRA~1\SYMNET~1\SNDMon.exe size: 100056 MD5: F9418981EE4D7E995D359833ADAB59D5 Located: HK_LM:Run, Windows Defender command: "C:\Program Files\Windows Defender\MSASCui.exe" -hide file: C:\Program Files\Windows Defender\MSASCui.exe size: 866584 MD5: 77C03BF23AE56B0A31AE4D5BB4B3D0AC Located: HK_LM:Run, AlcxMonitor (DISABLED) command: ALCXMNTR.EXE file: C:\WINDOWS\ALCXMNTR.EXE size: 57344 MD5: 7B8875A5B04932AC73AFD8079864DB68 Located: HK_LM:Run, IgfxTray (DISABLED) command: C:\WINDOWS\system32\igfxtray.exe file: C:\WINDOWS\system32\igfxtray.exe size: 155648 MD5: 8BBBADA96FFE1449EDD39256EDA99CD8 Located: HK_LM:Run, iTunesHelper (DISABLED) command: C:\Program Files\iTunes\iTunesHelper.exe file: C:\Program Files\iTunes\iTunesHelper.exe size: 286720 MD5: 3062C3DBF757D4029B8965BC04A4C218 Located: HK_LM:Run, RealTray (DISABLED) command: C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER file: C:\Program Files\Real\RealPlayer\RealPlay.exe size: 26112 MD5: 849D97FE4CC09CFC2772D10F641E1BAF Located: HK_LM:Run, SunJavaUpdateSched (DISABLED) command: C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe file: C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe size: 36975 MD5: 61A3A9D5D98BF0331DF5B716144A8100 Located: HK_LM:Run, UserFaultCheck (DISABLED) command: %systemroot%\system32\dumprep 0 -u file: C:\WINDOWS\system32\dumprep.exe size: 10752 MD5: 8E16BF5600797E678EA97051CF93E6BF Located: HK_CU:RunOnce, RunNarrator where: .DEFAULT... command: Narrator.exe file: C:\WINDOWS\system32\Narrator.exe size: 53760 MD5: 21F839F2281473642AC2060F30E19DC7 Located: HK_CU:Run, ctfmon.exe where: S-1-5-21-3341656437-3043363843-2328747555-1009... command: C:\WINDOWS\system32\ctfmon.exe file: C:\WINDOWS\system32\ctfmon.exe size: 15360 MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3 Located: HK_CU:Run, MSMSGS where: S-1-5-21-3341656437-3043363843-2328747555-1009... command: "C:\Program Files\Messenger\msmsgs.exe" /background file: C:\Program Files\Messenger\msmsgs.exe size: 1695232 MD5: 3E930C641079443D4DE036167A69CAA2 Located: HK_CU:Run, SpybotSD TeaTimer where: S-1-5-21-3341656437-3043363843-2328747555-1009... command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe size: 2097488 MD5: A9A5DB6AC3721BE698B996913693D73F Located: HK_CU:Run, SUPERAntiSpyware where: S-1-5-21-3341656437-3043363843-2328747555-1009... command: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe file: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe size: 1481968 MD5: 658A81BD5930FB5A67F874E6E6C31DF8 Located: HK_CU:Run, swg where: S-1-5-21-3341656437-3043363843-2328747555-1009... command: C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe file: C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe size: 171448 MD5: 0FA44EA8B03ABA3E1D240B5A333D8E6A Located: HK_CU:Run, MSMSGS (DISABLED) where: S-1-5-21-3341656437-3043363843-2328747555-1009... command: "C:\Program Files\Messenger\msmsgs.exe" /background file: C:\Program Files\Messenger\msmsgs.exe size: 1695232 MD5: 3E930C641079443D4DE036167A69CAA2 Located: HK_CU:Run, MsnMsgr (DISABLED) where: S-1-5-21-3341656437-3043363843-2328747555-1009... command: "C:\Program Files\MSN Messenger\msnmsgr.exe" /background file: C:\Program Files\MSN Messenger\msnmsgr.exe size: 7086080 MD5: 55406C4B910C174CDF36F66AFCA1A18C Located: HK_CU:Run, Yahoo! Pager (DISABLED) where: S-1-5-21-3341656437-3043363843-2328747555-1009... command: 1 file: size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: HK_CU:RunOnce, RunNarrator where: S-1-5-18... command: Narrator.exe file: C:\WINDOWS\system32\Narrator.exe size: 53760 MD5: 21F839F2281473642AC2060F30E19DC7 Located: Startup (common), Compaq Connections.lnk where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup... command: C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe file: C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe size: 16423 MD5: DB9012564169875F5B2AA7F5FC4905E4 Located: Startup (common), HP Digital Imaging Monitor.lnk (DISABLED) where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup... command: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe file: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe size: 282624 MD5: A9D65CEEEC7844C9A0C6B445BCBE7823 Located: Startup (common), SBC Self Support Tool.lnk (DISABLED) where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup... command: C:\Program Files\SBC Self Support Tool\bin\matcli.exe file: C:\Program Files\SBC Self Support Tool\bin\matcli.exe size: 217088 MD5: 96610108433EC2F885672AB0F32A0466 Located: WinLogon, !SASWinLogon command: C:\Program Files\SUPERAntiSpyware\SASWINLO.dll file: C:\Program Files\SUPERAntiSpyware\SASWINLO.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, crypt32chain command: crypt32.dll file: crypt32.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, cryptnet command: cryptnet.dll file: cryptnet.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, cscdll command: cscdll.dll file: cscdll.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, dimsntfy command: %SystemRoot%\System32\dimsntfy.dll file: %SystemRoot%\System32\dimsntfy.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, igfxcui command: igfxsrvc.dll file: igfxsrvc.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, ScCertProp command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, Schedule command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, sclgntfy command: sclgntfy.dll file: sclgntfy.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, SensLogn command: WlNotify.dll file: WlNotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, termsrv command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, WgaLogon command: WgaLogon.dll file: WgaLogon.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, wlballoon command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! --- Browser helper object list --- {9394EDE7-C8B5-483E-8773-474BF36AF6E4} (ST) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: ST Path: C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\ Long name: stmain.dll Short name: Date (created): 2/6/2006 1:38:54 AM Date (last access): 5/13/2008 9:54:14 PM Date (last write): 8/13/2004 7:42:00 PM Filesize: 155648 Attributes: archive MD5: 0DA1349495955CB41A5899047C5A1267 CRC32: C050EECD Version: 1.2.3000.1001 {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: Google Toolbar Helper description: Google toolbar classification: Open for discussion known filename: googletoolbar.dll<br>googletoolbar*.dll<br>(* = number)<br>googletoolbar_en_*.**-big.dll<br>Googletoolbar_en_*.*.**-deleon.dll info link: http://toolbar.google.com/ info source: TonyKlein Path: c:\program files\google\ Long name: GoogleToolbar3.dll Short name: GOOGLE~3.DLL Date (created): 1/25/2007 12:06:06 AM Date (last access): 5/13/2008 2:09:24 AM Date (last write): 1/20/2007 1:55:32 AM Filesize: 2403392 Attributes: readonly archive MD5: 6319F2D4708DBCAE37CFA03DA10782C0 CRC32: D51D8296 Version: 4.0.1601.4978 {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (MSNToolBandBHO) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: MSNToolBandBHO Path: C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\ Long name: msntb.dll Short name: Date (created): 2/9/2006 11:49:42 PM Date (last access): 5/13/2008 9:54:14 PM Date (last write): 1/17/2006 6:04:16 PM Filesize: 282624 Attributes: archive MD5: 6B3B0C6657B3DFEAD7ABC5BFEE45B347 CRC32: 1DF31317 Version: 1.2.5000.1021 --- ActiveX list --- Microsoft XML Parser for Java (Microsoft XML Parser for Java) DPF name: Microsoft XML Parser for Java CLSID name: Installer: Codebase: file://C:\WINDOWS\Java\classes\xmldso.cab description: classification: Legitimate known filename: %WINDIR%\Java\classes\xmldso.cab info link: info source: Patrick M. Kolla {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) DPF name: CLSID name: Windows Genuine Advantage Validation Tool Installer: C:\WINDOWS\Downloaded Program Files\LegitCheckControl.inf Codebase: http://go.microsoft.com/fwlink/?linkid=39204 description: classification: Legitimate known filename: LegitCheckControl.DLL info link: info source: Safer Networking Ltd. Path: C:\WINDOWS\system32\ Long name: LegitCheckControl.dll Short name: LEGITC~1.DLL Date (created): 7/12/2005 7:04:22 PM Date (last access): 5/13/2008 9:56:16 PM Date (last write): 3/20/2008 6:06:36 PM Filesize: 1480232 Attributes: MD5: E058C4821D48E0A67F6069CB50818D44 CRC32: 3513AE02 Version: 1.7.69.2 {2DEF4530-8CE6-41C9-84B6-A54536C90213} (Crystal Report Viewer Control 9) DPF name: CLSID name: Crystal Report Viewer Control 9 Installer: C:\WINDOWS\Downloaded Program Files\crviewer9.inf Codebase: http://www.ugaais.com/viewer9/activeXViewe...tivexviewer.cab description: classification: Legitimate known filename: CRViewer9.dll info link: info source: Safer Networking Ltd. Path: C:\WINDOWS\Downloaded Program Files\ Long name: CRViewer9.dll {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) DPF name: CLSID name: YInstStarter Class Installer: C:\Program Files\Yahoo!\common\yinst.inf Codebase: C:\Program Files\Yahoo!\common\yinsthelper.dll description: Yahoo! Installation helper classification: Legitimate known filename: %SystemRoot%\Downloaded Program Files\yinsthelper.dll info link: info source: Patrick M. Kolla Path: C:\Program Files\Yahoo!\common\ Long name: yinsthelper.dll Short name: YINSTH~1.DLL Date (created): 4/10/2006 11:27:54 PM Date (last access): 5/13/2008 2:09:26 AM Date (last write): 11/7/2004 5:29:46 PM Filesize: 173168 Attributes: archive MD5: 4C0658E518FA9D08E884DB717A7087AE CRC32: FFDA1549 Version: 2004.11.7.1 {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} () DPF name: CLSID name: Installer: C:\WINDOWS\Downloaded Program Files\aolcoach_core.inf Codebase: http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab description: classification: Legitimate known filename: info link: info source: Safer Networking Ltd. {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} () DPF name: CLSID name: Installer: C:\WINDOWS\Downloaded Program Files\qdiagcc.inf Codebase: http://aolcc.aol.com/computercheckup/qdiagcc.cab description: classification: Legitimate known filename: qdiagcc.ocx info link: info source: Safer Networking Ltd. {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) DPF name: CLSID name: MUWebControl Class Installer: C:\WINDOWS\Downloaded Program Files\muweb.inf Codebase: http://www.update.microsoft.com/microsoftu...b?1210477749796 description: classification: Legitimate known filename: muweb.dll info link: info source: Safer Networking Ltd. Path: C:\WINDOWS\system32\ Long name: muweb.dll Short name: Date (created): 7/30/2007 7:18:34 PM Date (last access): 5/13/2008 9:49:48 PM Date (last write): 7/30/2007 7:18:34 PM Filesize: 207736 Attributes: archive MD5: 8038B166CE79E58E193566150CE26465 CRC32: 9137D395 Version: 7.0.6000.381 {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) DPF name: Java Runtime Environment 1.5.0 CLSID name: Java Plug-in 1.5.0_06 Installer: Codebase: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab description: Sun Java classification: Legitimate known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll info link: info source: Patrick M. Kolla Path: C:\Program Files\Java\jre1.5.0_06\bin\ Long name: NPJPI150_06.dll Short name: NPJPI1~1.DLL Date (created): 11/10/2005 3:03:56 PM Date (last access): 5/13/2008 2:09:28 AM Date (last write): 11/10/2005 3:22:10 PM Filesize: 69746 Attributes: archive MD5: D2CF6BB5E9020E6707B62575F8083954 CRC32: 7F39DC54 Version: 5.0.60.5 {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) DPF name: CLSID name: MsnMessengerSetupDownloadControl Class Installer: C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.inf Codebase: http://messenger.msn.com/download/MsnMesse...pDownloader.cab description: classification: Legitimate known filename: MsnMessengerSetupDownloader.ocx info link: info source: Safer Networking Ltd. Path: C:\WINDOWS\Downloaded Program Files\ Long name: MsnMessengerSetupDownloader.ocx {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0) DPF name: Java Runtime Environment 1.5.0 CLSID name: Java Plug-in 1.5.0_06 Installer: Codebase: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab description: classification: Legitimate known filename: npjpi150_06.dll info link: info source: Safer Networking Ltd. Path: C:\Program Files\Java\jre1.5.0_06\bin\ Long name: NPJPI150_06.dll Short name: NPJPI1~1.DLL Date (created): 11/10/2005 3:03:56 PM Date (last access): 5/13/2008 10:11:06 PM Date (last write): 11/10/2005 3:22:10 PM Filesize: 69746 Attributes: archive MD5: D2CF6BB5E9020E6707B62575F8083954 CRC32: 7F39DC54 Version: 5.0.60.5 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0) DPF name: Java Runtime Environment 1.5.0 CLSID name: Java Plug-in 1.5.0_06 Installer: Codebase: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab description: classification: Legitimate known filename: npjpi150_06.dll info link: info source: Safer Networking Ltd. Path: C:\Program Files\Java\jre1.5.0_06\bin\ Long name: NPJPI150_06.dll Short name: NPJPI1~1.DLL Date (created): 11/10/2005 3:03:56 PM Date (last access): 5/13/2008 10:11:06 PM Date (last write): 11/10/2005 3:22:10 PM Filesize: 69746 Attributes: archive MD5: D2CF6BB5E9020E6707B62575F8083954 CRC32: 7F39DC54 Version: 5.0.60.5 {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) DPF name: CLSID name: Shockwave Flash Object Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf Codebase: http://fpdownload.macromedia.com/get/flash...ent/swflash.cab description: Macromedia Shockwave Flash Player classification: Legitimate known filename: info link: info source: Patrick M. Kolla Path: C:\WINDOWS\system32\Macromed\Flash\ Long name: Flash9b.ocx Short name: Date (created): 11/9/2006 4:46:26 PM Date (last access): 5/13/2008 2:09:32 AM Date (last write): 11/9/2006 4:46:26 PM Filesize: 2262648 Attributes: readonly archive MD5: F3B3EE66CA76C94510555ABE9D00A353 CRC32: A51F3CB4 Version: 9.0.28.0 --- Process list --- PID: 0 ( 0) [System] PID: 444 ( 4) \SystemRoot\System32\smss.exe size: 50688 PID: 500 ( 444) \??\C:\WINDOWS\system32\csrss.exe size: 6144 PID: 524 ( 444) \??\C:\WINDOWS\system32\winlogon.exe size: 507904 PID: 568 ( 524) C:\WINDOWS\system32\services.exe size: 108544 MD5: 0E776ED5F7CC9F94299E70461B7B8185 PID: 580 ( 524) C:\WINDOWS\system32\lsass.exe size: 13312 MD5: BF2466B3E18E970D8A976FB95FC1CA85 PID: 768 ( 568) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 828 ( 568) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 892 ( 568) C:\Program Files\Windows Defender\MsMpEng.exe size: 13592 MD5: F45DD1E1365D857DD08BC23563370D0E PID: 936 ( 568) C:\WINDOWS\System32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 980 ( 568) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 1044 ( 568) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 1280 ( 568) c:\Program Files\Common Files\Symantec Shared\ccProxy.exe size: 218736 MD5: 35AD77BDC4EE11E7FA111E4CE4026E8C PID: 1368 ( 568) c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe size: 235168 MD5: 4F46BD842DB5C1A0E4381B47C117EBBE PID: 1384 ( 568) C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe size: 206552 MD5: 443E397643965E08C5AB6A6CAA732B97 PID: 1412 (1328) C:\WINDOWS\Explorer.EXE size: 1033728 MD5: 12896823FB95BFB3DC9B46BCAEDC9923 PID: 1424 ( 568) c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe size: 255648 MD5: 9761D4E304074F156AE9B7C3DFF1A229 PID: 1736 ( 568) C:\WINDOWS\system32\spoolsv.exe size: 57856 MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B PID: 652 ( 568) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE size: 322120 MD5: 11F714F85530A2BD134074DC30E99FCA PID: 732 ( 568) C:\WINDOWS\system32\HPZipm12.exe size: 69632 MD5: A38B3CE68E7F126190CDE4AA3FDF050F PID: 1156 ( 568) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 1244 ( 568) c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe size: 316544 MD5: 67C5AF84809468061121FBCBECB19285 PID: 1336 (1412) C:\windows\system\hpsysdrv.exe size: 52736 MD5: 06A1ECB63DF139EC639E084D4AB3C9D7 PID: 584 (1412) C:\HP\KBD\KBD.EXE size: 61440 MD5: 4A95F15B706B8FD9EC8715B6401EAB7B PID: 1228 (1412) C:\WINDOWS\system32\hkcmd.exe size: 118784 MD5: EA5DD164296F66241BEAD39E12FA69F2 PID: 1960 (1412) C:\WINDOWS\AGRSMMSG.exe size: 88209 MD5: 230EA041666125B6812FE3FF964B2DF3 PID: 2112 (1412) C:\Program Files\Common Files\Symantec Shared\ccApp.exe size: 71328 MD5: F1F54205EAAD3E37CA2C5A13437BB947 PID: 2124 (1412) C:\Program Files\BroadJump\Client Foundation\CFD.exe size: 368706 MD5: BA9AF06103549A96F77036861FDE357B PID: 2152 (1412) C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe size: 380928 MD5: F055034225687B9F9D176985F0108145 PID: 2200 (1412) C:\Program Files\HP\HP Software Update\HPWuSchd2.exe size: 49152 MD5: 65ED174C0B836D4CFA489712278CEF7B PID: 2232 (1412) C:\Program Files\Windows Defender\MSASCui.exe size: 866584 MD5: 77C03BF23AE56B0A31AE4D5BB4B3D0AC PID: 2316 (1412) C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe size: 171448 MD5: 0FA44EA8B03ABA3E1D240B5A333D8E6A PID: 2368 (1412) C:\Program Files\Messenger\msmsgs.exe size: 1695232 MD5: 3E930C641079443D4DE036167A69CAA2 PID: 2428 ( 568) C:\WINDOWS\System32\alg.exe size: 44544 MD5: 8C515081584A38AA007909CD02020B3D PID: 2536 (1412) C:\WINDOWS\system32\ctfmon.exe size: 15360 MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3 PID: 2940 (2712) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe size: 1481968 MD5: 658A81BD5930FB5A67F874E6E6C31DF8 PID: 2148 (1412) C:\Program Files\Mozilla Firefox\firefox.exe size: 7660656 MD5: B366BB8334CDCFB5C2A58DCF5121B6BC PID: 660 (1412) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe size: 5146448 MD5: 2ECA8CDEED7C82F879E766DA92A3561A PID: 4 ( 0) System --- Browser start & search pages list --- Spybot - Search & Destroy browser pages report, 5/13/2008 10:11:05 PM HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page C:\WINDOWS\system32\blank.htm HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page http://www.google.com HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar http://www.google.com/ie HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page http://yahoo.sbc.com/dsl HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Page_URL http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Search_URL http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\SearchAssistant http://www.google.com/ie HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@ http://www.google.com/search?q=%s HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page %SystemRoot%\system32\blank.htm HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page http://www.google.com HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page http://yahoo.sbc.com/dsl HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL http://go.microsoft.com/fwlink/?LinkId=69157 HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL http://go.microsoft.com/fwlink/?LinkId=54896 HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant http://www.google.com/ie HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm --- Winsock Layered Service Provider list --- --- Uninstall list --- -BMWWilliamsF1Team (-BMWWilliamsF1Team) uninstall cmd: C:\WINDOWS\system32\-BMWWI~1.SCR /UNINSTALL "C:\WINDOWS\system32\-BMWWilliamsF1Team.log" 4Diskclean Freeware 1.0 (4Diskclean Freeware_is1) uninstall cmd: "C:\Program Files\4DiskcleanF\unins000.exe" Panda ActiveScan 2.0 01.00.00.0000 (ActiveScan 2.0) estimated size: 4000 install location: C:\Program Files\Panda Security\ActiveScan 2.0 uninstall cmd: C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe publisher: Panda Security help link: http://www.pandasecurity.com/activescan/help/ (AddressBook) Adobe Flash Player Plugin 9.0.115.0 (Adobe Flash Player Plugin) uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe publisher: Adobe Systems Incorporated Agere Systems PCI Soft Modem (Agere Systems Soft Modem) uninstall cmd: agrsmdel Compaq Connections (BackWeb-6750491 Uninstaller) uninstall cmd: C:\WINDOWS\BWUnin-6.3.2.62.exe -AppId 6750491 BroadJump Client Foundation (BroadJump Client Foundation) uninstall cmd: C:\WINDOWS\IsUninst.exe -f"C:\Program Files\BroadJump\Client Foundation\Uninst.isu" -c"C:\Program Files\BroadJump\Client Foundation\RmvBJCFD.dll" -b"CFD" -h"CFD" -a (Connection Manager) (DirectAnimation) (DirectDrawEx) (DXM_Runtime) (Fontcore) Handy Recovery 2.0 (Handy Recovery 2.0) uninstall cmd: C:\PROGRA~1\SOFTLO~1\HANDYR~1.0\UNWISE.EXE C:\PROGRA~1\SOFTLO~1\HANDYR~1.0\INSTALL.LOG Help and Support Additions (Help and Support Additions) uninstall cmd: C:\PROGRA~1\HELPAN~1\UNWISE.EXE C:\PROGRA~1\HELPAN~1\INSTALL.LOG HijackThis 2.0.2 2.0.2 (HijackThis) uninstall cmd: "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall publisher: TrendMicro HP Imaging Device Functions 6.1 6.1 (HP Imaging Device Functions) uninstall cmd: C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat publisher: HP help link: http://www.hp.com/support HP Solution Center and Imaging Support Tools 6.1 6.1 (HP Solution Center & Imaging Support Tools) uninstall cmd: C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat publisher: HP help link: http://www.hp.com/support HP Extended Capabilities 6.1 6.1 (HPExtendedCapabilities) uninstall cmd: C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat publisher: HP help link: http://www.hp.com/support (ICW) Microsoft Internationalized Domain Names Mitigation APIs (IDNMitigationAPIs) install date: 20061121 uninstall cmd: "C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe" publisher: Microsoft Corporation (IE40) (IE4Data) (IE5BAKEX) Windows Internet Explorer 7 20061107.210142 (ie7) install date: 20061121 publisher: Microsoft Corporation help link: http://www.microsoft.com/ie (IEData) (InstallShield Uninstall Information) iTunes 4.5.0.31 (InstallShield_{35AFD495-EC2E-4B2B-B9DB-30EEBC74049D}) version: 67436544 version (major): 4 version (minor): 5 estimated size: 11971 install date: 20040808 install location: C:\Program Files\iTunes\ install source: C:\WINDOWS\Downloaded Installations\{833D9BE4-D960-4A19-8FB8-1E8FC9656D65}\ uninstall cmd: C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{35AFD495-EC2E-4B2B-B9DB-30EEBC74049D} publisher: Apple Computer, Inc. contact: AppleCare Support help link: http://www.info.apple.com/ help telephone: 1-800-275-2273 (InstallShield_{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}) High Definition Audio Driver Package - KB835221 20040219.000000 (KB835221WXP) uninstall cmd: C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=KB835221 (KB884016) (KB884267) (KB885353) (KB886612) (KB887078) (KB887626) (KB888656) (KB889858) (KB891122) Windows Genuine Advantage Validation Tool (KB892130) (KB892130) install date: 20080511 publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=892130 (KB892313) (KB893240) (KB893241) (KB895181) (KB895316) (KB895572) (KB897586) Security Update for Step By Step Interactive Training (KB898458) 20050502.101010 (KB898458) install date: 20050619 uninstall cmd: "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com/kb/898458 (KB898549) (KB900399) (KB902344) (KB907658) Security Update for Windows Media Player (KB911564) (KB911564) install date: 20060219 publisher: Microsoft Corporation help link: http://support.microsoft.com/?kbid=911564 Security Update for Windows Media Player 9 (KB911565) (KB911565) install date: 20060219 uninstall cmd: "C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com/?kbid=911565 (KB911854) Security Update for Windows Media Player 9 (KB917734) (KB917734_WMP9) install date: 20060617 uninstall cmd: "C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com/?kbid=917734 Security Update for Windows XP (KB923689) (KB923689) install date: 20061215 publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=923689 Security Update for Step By Step Interactive Training (KB923723) 20050502.101010 (KB923723) install date: 20070213 uninstall cmd: "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com/kb/923723 Security Update for Windows Media Player 6.4 (KB925398) (KB925398_WMP64) install date: 20061215 publisher: Microsoft Corporation help link: http://support.microsoft.com/?kbid=925398 Security Update for Windows Internet Explorer 7 (KB928090) 20070117.120000 (KB928090-IE7) install date: 20070213 uninstall cmd: "C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=928090 Hotfix for Windows Media Format 11 SDK (KB929399) (KB929399) install date: 20070404 uninstall cmd: "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com/?kbid=929399 Security Update for Windows Internet Explorer 7 (KB929969) 20061222.120000 (KB929969) install date: 20070110 uninstall cmd: "C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=929969 Security Update for Windows Internet Explorer 7 (KB931768) 1 (KB931768-IE7) install date: 20070508 uninstall cmd: "C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=931768 Security Update for CAPICOM (KB931906) 2.1.0.2 (KB931906) uninstall cmd: MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=931906 Security Update for Windows Internet Explorer 7 (KB933566) 1 (KB933566-IE7) install date: 20070612 uninstall cmd: "C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=933566 Security Update for Windows Media Player 11 (KB936782) (KB936782_WMP11) install date: 20070816 uninstall cmd: "C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com/?kbid=936782 Security Update for Windows Internet Explorer 7 (KB937143) 1 (KB937143-IE7) install date: 20070816 uninstall cmd: "C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=937143 Security Update for Windows Internet Explorer 7 (KB938127) 1 (KB938127-IE7) install date: 20070816 uninstall cmd: "C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=938127 Security Update for Windows Internet Explorer 7 (KB939653) 1 (KB939653-IE7) install date: 20071010 uninstall cmd: "C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=939653 Hotfix for Windows Media Player 11 (KB939683) (KB939683) install date: 20070831 uninstall cmd: "C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com/?kbid=939683 Security Update for Windows XP (KB941569) (KB941569) install date: 20071212 uninstall cmd: "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=941569 Security Update for Windows Internet Explorer 7 (KB942615) 1 (KB942615-IE7) install date: 20071212 uninstall cmd: "C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=942615 Security Update for Windows Internet Explorer 7 (KB944533) 1 (KB944533-IE7) install date: 20080214 uninstall cmd: "C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=944533 Hotfix for Windows Internet Explorer 7 (KB947864) 1 (KB947864-IE7) install date: 20080408 uninstall cmd: "C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=947864 KBD (KBD) uninstall cmd: C:\HP\KBD\KBD.EXE uninstalled LiveReg (Symantec Corporation) 2.4.2.2295 (LiveReg) install location: C:\Program Files\Common Files\Symantec Shared\LiveReg uninstall cmd: C:\Program Files\Common Files\Symantec Shared\LiveReg\VcSetup.exe /REMOVE publisher: Symantec Corporation LiveUpdate 2.6 (Symantec Corporation) 2.6.14.0 (LiveUpdate) install location: C:\Program Files\Symantec\LiveUpdate uninstall cmd: C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U publisher: Symantec Corporation Microsoft .NET Framework 1.1 Hotfix (KB928366) (M928366) uninstall cmd: "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp" Microsoft .NET Framework 1.1 (Microsoft .NET Framework 1.1 (1033)) uninstall cmd: msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} readme: file://C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\RepairRedist.htm (Microsoft Interactive Training) uninstall cmd: C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu (MobileOptionPack) Mozilla Firefox (2.0.0.14) 2.0.0.14 (en-US) (Mozilla Firefox (2.0.0.14)) install location: C:\PROGRA~1\Mozilla Firefox uninstall cmd: C:\PROGRA~1\Mozilla Firefox\uninstall\helper.exe publisher: Mozilla comments: Mozilla Firefox MP3Rocket (MP3Rocket) uninstall cmd: C:\Program Files\MP3Rocket\Uninstall.exe (MPlayer2) Microsoft Compression Client Pack 1.0 for Windows XP 1 (MSCompPackV1) install date: 20070403 uninstall cmd: "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://go.microsoft.com/fwlink/?LinkId=74087 (MSI30-Beta1) (MSI30-Beta2) (MSI30-KB884016) (MSI30-RC1) (MSI30-RC2) (MSI30a-KB884016) (MSI31-Beta) (MSI31-RC1) (MsJavaVM) MSN Toolbar (MSN Toolbar) uninstall cmd: C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\mtbs.exe c Microsoft Text-to-Speech Engine 4.0 (English) (MSTTS) uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msTTS.inf, Uninstall (NetMeeting) Microsoft National Language Support Downlevel APIs (NLSDownlevelMapping) install date: 20061121 uninstall cmd: "C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe" publisher: Microsoft Corporation (OutlookExpress) ParetoLogic Anti-Spyware 5.7.0.10 (ParetoLogic Anti-Spyware) uninstall cmd: C:\Program Files\ParetoLogic\Anti-Spyware\Uninst_Pareto_AS.exe publisher: ParetoLogic Inc. help link: http://support.paretologic.com (PCHealth) uninstall cmd: rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf PokerStars 1.803 (PokerStars) version (major): 1 version (minor): 803 install date: 3/21/06 6:04:47p install location: C:\Program Files\PokerStars install source: C:\Documents and Settings\Compaq_Owner\Desktop\PokerStarsInstall.exe uninstall cmd: C:\Program Files\PokerStars\Uninstall.EXE /u:"PokerStars" publisher: PokerStars.com PS2 (PS2) uninstall cmd: C:\WINDOWS\system32\ps2.exe uninstall QuickTime (QuickTime) uninstall cmd: C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log RealPlayer Basic (RealPlayer 6.0) uninstall cmd: C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0 (RecordNow.exe) uninstall cmd: c:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19} 5.6.0.asst_classic.asst_install (SBC Self Support Tool) uninstall cmd: C:\PROGRA~1\SBCSEL~1\CustomUninstall.exe SBC publisher: Motive Communications, Inc. SBC Self Support Tool (SBC.MCCInstall) uninstall cmd: C:\WINDOWS\Motive\SBC\MCCUninst.exe (SchedulingAgent) (Sevinst) Adobe Flash Player 9 ActiveX 9 (ShockwaveFlash) uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete publisher: Adobe Systems Incorporated help link: http://www.adobe.com/go/flashplayer_support/ Spybot - Search & Destroy 1.5.2.20 (Spybot - Search & Destroy_is1) install date: 20080229 uninstall cmd: "C:\WINDOWS\unins000.exe" publisher: Safer Networking Ltd. help link: http://www.safer-networking.org/ Starcraft (Starcraft) uninstall cmd: C:\WINDOWS\scunin.exe C:\WINDOWS\scunin.dat Learn2 Player (Uninstall Only) (StreetPlugin) uninstall cmd: C:\Program Files\Learn2.com\StRunner\stuninst.exe Norton Personal Firewall (Symantec Corporation) 7.0.3.8 (SymSetup.{3BD0196C-6553-460c-A0C4-90D8AE5D60D2}) install location: C:\Program Files\Norton Personal Firewall install source: c:\hp\tmp\src uninstall cmd: C:\Program Files\Common Files\Symantec Shared\SymSetup\{3BD0196C-6553-460c-A0C4-90D8AE5D60D2}.exe /X publisher: Symantec Corporation Lernout & Hauspie TruVoice American English TTS Engine (tv_enua) uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\tv_enua.inf, Uninstall (ViewpointMediaPlayer) Windows Genuine Advantage Validation Tool (KB892130) 1.7.0069.2 (WGA) publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=892130 Windows Genuine Advantage Notifications (KB905474) 1.7.0018.5 (WgaNotify) install date: 20060701 publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=905474 (WIC) Windows Media Format 11 runtime (Windows Media Format Runtime) uninstall cmd: "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll help link: http://go.microsoft.com/fwlink/?LinkId=62768 Windows Media Player 11 (Windows Media Player) uninstall cmd: "C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall Windows XP Service Pack 3 20080414.031525 (Windows XP Service Pack) install date: 20080511 uninstall cmd: "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http://support.microsoft.com?kbid=936929 (WMCSetup) Windows Media Format 11 runtime (WMFDist11) install date: 20070403 uninstall cmd: "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http: Windows Media Player 11 (wmp11) install date: 20070403 uninstall cmd: "C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe" publisher: Microsoft Corporation help link: http: Microsoft User-Mode Driver Framework Feature Pack 1.0 (Wudf01000) install date: 20070403 uninstall cmd: "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe" publisher: Microsoft Corporation comments: Build Number 5716 XoftSpy (XoftSpy) uninstall cmd: C:\Program Files\XoftSpy\uninstall.exe Yahoo! Toolbar (Yahoo! Companion) uninstall cmd: C:\PROGRA~1\Yahoo!\common\unyt.exe Yahoo! Toolbar (Yahoo! Toolbar) Yahoo! Install Manager (YInstHelper) uninstall cmd: C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\common\YINSTH~1.DLL TrayApp 61.0.163.000 ({0BF5FBE7-3907-4A1F-9E48-8B66E52850D6}) version: 1023410339 version (major): 61 estimated size: 691 install date: 20060522 install source: E:\setup\TrayApp\ publisher: Hewlett-Packard Microsoft Plus! Photo Story 2 LE 1.1.0.3463 ({0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}) version: 16842752 version (major): 1 version (minor): 1 estimated size: 17337 install date: 20040808 install source: c:\hp\tmp\src\Plus! Photo Story 2 LE\ uninstall cmd: MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B} publisher: Microsoft Corporation readme: c:\Program Files\Microsoft Plus! Photo Story 2 LE\Readme.htm Security Update for CAPICOM (KB931906) 2.1.0.2 ({0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}) version: 33619968 version (major): 2 version (minor): 1 estimated size: 770 install date: 20080511 install source: C:\WINDOWS\TEMP\IXP000.TMP\ uninstall cmd: MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} publisher: Microsoft Corporation Norton Internet Security 7.0.3.8 ({12E2B9E9-05B1-407d-B0FD-B5F350535125}) version: 117440515 version (major): 7 estimated size: 4735 install date: 20040810 install source: c:\hp\tmp\src\Setup\ uninstall cmd: MsiExec.exe /I{12E2B9E9-05B1-407d-B0FD-B5F350535125} publisher: Symantec Corporation Norton WMI Update 2005.1.0.111 ({1526D87C-A955-4FAB-BF18-697BA457E352}) version (major): 2005 version (minor): 1 estimated size: 1984 install date: 20040810 install source: c:\hp\tmp\src\tax\ uninstall cmd: MsiExec.exe /X{1526D87C-A955-4FAB-BF18-697BA457E352} publisher: Symantec Corporation Status 61.0.163.000 ({1E1F1E70-14D8-4380-8652-BD1A895A7D65}) version: 1023410339 version (major): 61 estimated size: 2689 install date: 20060522 install source: E:\setup\Status\ publisher: Hewlett-Packard PC-Doctor for Windows ({1F7CCFA3-D926-4882-B2A5-A0217ED25597}) uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\Setup.exe" Google Toolbar for Internet Explorer ({2318C2B1-4965-11d4-9B18-009027A5CD4F}) uninstall cmd: regsvr32 /u /s "c:\program files\google\googletoolbar3.dll" CP_Package_Variety2 61.0.163.000 ({23B35809-5E4A-4F14-8332-1CDEDDFAC089}) version: 1023410339 version (major): 61 estimated size: 8617 install date: 20060522 install source: E:\setup\CP_Package_Variety2\ publisher: Hewlett-Packard Destinations 61.0.163.000 ({24BEBF2E-73F3-4599-840B-EDC612CCDD0D}) version: 1023410339 version (major): 61 estimated size: 17007 install date: 20060522 install source: E:\setup\Destinations\ publisher: Hewlett-Packard ScannerCopy 6.0.0.0 ({31263605-FC84-4787-B847-BA445B147E24}) version: 100663296 version (major): 6 estimated size: 5058 install date: 20060522 install source: E:\setup\ScannerCopy\ publisher: Hewlett-Packard comments: 0 contact: 0 help link: 0 help telephone: 0 readme: 0 J2SE Runtime Environment 5.0 Update 6 1.5.0.60 ({3248F0A8-6813-11D6-A77B-00B0D0150060}) version: 17104896 version (major): 1 version (minor): 5 estimated size: 122273 install date: 20051227 install source: http://jdl.sun.com/webapps/download/GetFil.../windows-i586// uninstall cmd: MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060} publisher: Sun Microsystems, Inc. contact: http://java.com help link: http://java.com readme: C:\Program Files\Java\jre1.5.0_06\README.txt Unload 6.0.0 ({34F3FCF1-817B-4D61-B6AF-19D9486AFEA0}) version: 100663296 version (major): 6 estimated size: 8873 install date: 20060522 install source: E:\setup\UnloadIntent\ publisher: Hewlett-Packard comments: 0 contact: 0 help link: 0 help telephone: 0 readme: 0 WebFldrs XP 9.50.7523 ({350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}) version: 154279267 version (major): 9 version (minor): 50 estimated size: 2456 install date: 20040808 install source: C:\WINDOWS\system32\ publisher: Microsoft Corporation help link: http://www.microsoft.com/windows iTunes 4.5.0.31 ({35AFD495-EC2E-4B2B-B9DB-30EEBC74049D}) version: 67436544 version (major): 4 version (minor): 5 estimated size: 11971 install date: 20040808 install location: C:\Program Files\iTunes\ install source: C:\WINDOWS\Downloaded Installations\{833D9BE4-D960-4A19-8FB8-1E8FC9656D65}\ publisher: Apple Computer, Inc. contact: AppleCare Support help link: http://www.info.apple.com/ help telephone: 1-800-275-2273 MSXML 4.0 SP2 (KB927978) 4.20.9841.0 ({37477865-A3F1-4772-AD43-AAFC6BCFF99F}) version: 68429425 version (major): 4 version (minor): 20 estimated size: 2625 install date: 20061114 install source: c:\ddbf65568f0129f7b39bcb8a68ab\ uninstall cmd: MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F} publisher: Microsoft Corporation help link: http://support.microsoft.com/kb/927978 ({39DA87A1-0B26-4562-A70C-2A6147366E47}) uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\Setup.exe" Norton Personal Firewall 7.0.3.8 ({3BD0196C-6553-460c-A0C4-90D8AE5D60D2}) version: 117440515 version (major): 7 estimated size: 4078 install date: 20040810 install source: c:\hp\tmp\src\Setup\ uninstall cmd: MsiExec.exe /I{3BD0196C-6553-460c-A0C4-90D8AE5D60D2} publisher: Symantec Corporation CC_ccStart 2.1.1.700 ({400A95F9-5B90-421E-BA7F-8BBB3405ABE4}) version: 33619969 version (major): 2 version (minor): 1 install date: 20040810 install source: C:\DOCUME~1\Owner\LOCALS~1\Temp\ uninstall cmd: MsiExec.exe /I{400A95F9-5B90-421E-BA7F-8BBB3405ABE4} publisher: Symantec Corporation BufferChm 61.0.163.000 ({4041C245-7099-4C96-9738-5EBC23827B3C}) version: 1023410339 version (major): 61 estimated size: 4797 install date: 20060522 install source: E:\setup\BufferChm\ publisher: Hewlett-Packard Norton Internet Security 7.0.3.8 ({48185814-A224-447a-81DA-71BD20580E1B}) version: 117440515 version (major): 7 estimated size: 370 install date: 20040810 install source: c:\hp\tmp\src\Setup\ uninstall cmd: MsiExec.exe /I{48185814-A224-447a-81DA-71BD20580E1B} publisher: Symantec Corporation SolutionCenter 61.0.163.000 ({4BE53DB2-C1F2-44D1-A9AB-1630BA7F2AF1}) version: 1023410339 version (major): 61 estimated size: 8384 install date: 20060522 install source: E:\setup\SolutionCenter\ publisher: Hewlett-Packard ({503AA035-41E2-4858-B31F-1E49AC66C309}) CP_Package_Variety1 61.0.163.000 ({522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}) version: 1023410339 version (major): 61 estimated size: 7401 install date: 20060522 install source: E:\setup\CP_Package_Variety1\ publisher: Hewlett-Packard Norton Internet Security 7.0.3.8 ({526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F}) version: 117440515 version (major): 7 estimated size: 1651 install date: 20040810 install source: c:\hp\tmp\src\Setup\ uninstall cmd: MsiExec.exe /I{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F} publisher: Symantec Corporation Norton Internet Security 5.2.1.207 ({58FF85B0-5C76-4ED1-9C07-719C54CF0178}) version: 84017153 version (major): 5 version (minor): 2 estimated size: 2168 install date: 20040810 install source: C:\DOCUME~1\Owner\LOCALS~1\Temp\ uninstall cmd: MsiExec.exe /I{58FF85B0-5C76-4ED1-9C07-719C54CF0178} publisher: Symantec Corporation ccCommon 2.1.1.700 ({59390E3C-62F5-4467-84C1-51A565D36853}) version: 33619969 version (major): 2 version (minor): 1 estimated size: 5129 install date: 20040810 install source: C:\DOCUME~1\Owner\LOCALS~1\Temp\ uninstall cmd: MsiExec.exe /I{59390E3C-62F5-4467-84C1-51A565D36853} publisher: Symantec 4300 51.0.230.000 ({61B1A9C8-B2AD-4F54-B916-388FFD07BDE7}) version: 855638246 version (major): 51 estimated size: 263 install date: 20060522 install source: C:\Program Files\HP\Digital Imaging\{E5A8DDAB-AE80-48C6-A75B-D0FAB83B299D}\Product\ publisher: Hewlett-Packard Windows Genuine Advantage v1.3.0254.0 1.3.0254.0 ({63569CE9-FA00-469C-AF5C-E5D4D93ACF91}) version: 16974078 version (major): 1 version (minor): 3 estimated size: 519 install date: 20050826 install source: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IXP000.TMP\ uninstall cmd: MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91} publisher: Microsoft comments: Your Comments contact: Customer Support Department help link: http://www.microsoft.com/genuine/downloads...idate.aspx/help help telephone: 1-425.882.8080 eSupportQFolder 1.00.0000 ({66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}) version: 16777216 version (major): 1 estimated size: 124 install date: 20060522 install source: E:\setup\QFolder\ publisher: Hewlett-Packard AiOSoftwareNPI 51.0.230.000 ({68763C27-235D-4165-A961-FDEA228CE504}) version: 855638246 version (major): 51 estimated size: 4546 install date: 20060522 install source: E:\setup\AiOSoftwarenpi\ publisher: Hewlett-Packard Microsoft Plus! Digital Media Edition Installer 1.1.0.3500 ({6E45BA47-383C-4C1E-8ED0-0D4845C293D7}) version: 16842752 version (major): 1 version (minor): 1 estimated size: 49259 install date: 20040808 install source: c:\hp\tmp\src\Plus! Digital Media Setup Program\ uninstall cmd: MsiExec.exe /X{6E45BA47-383C-4C1E-8ED0-0D4845C293D7} publisher: Microsoft Corporation CustomerResearchQFolder 1.00.0000 ({6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}) version: 16777216 version (major): 1 estimated size: 124 install date: 20060522 install source: E:\setup\QFolder\ publisher: Hewlett-Packard Java 2 Runtime Environment, SE v1.4.2_03 1.4.2_03 ({7148F0A8-6813-11D6-A77B-00B0D0142030}) version (major): 1 version (minor): 4 estimated size: 138404 install date: 20040808 install source: C:\Documents and Settings\Owner\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}\ uninstall cmd: MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030} publisher: Sun Microsystems, Inc. comments: http://www.java.com contact: http://www.java.com help link: http://www.java.com help telephone: http://www.java.com readme: Readme.txt Readme 51.0.230.000 ({736C803C-DD3B-4015-BC51-AFB9E67B9076}) version: 855638246 version (major): 51 estimated size: 36 install date: 20060522 install source: E:\setup\readme\ publisher: Hewlett-Packard Microsoft Works 7.0 07.02.0808 ({764D06D8-D8DE-411E-A1C8-D9E9380F8A84}) version: 117572392 version (major): 7 version (minor): 2 estimated size: 279542 install date: 20080512 install source: E:\MSWorks\ uninstall cmd: MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84} publisher: Microsoft Corporation comments: Microsoft Works 7.0 installation. help link: http://support.microsoft.com/support/works help telephone: ProductContextNPI 51.0.230.000 ({7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}) version: 855638246 version (major): 51 estimated size: 264 install date: 20060522 install source: C:\Program Files\HP\Digital Imaging\{E5A8DDAB-AE80-48C6-A75B-D0FAB83B299D}\ publisher: Hewlett-Packard Intel® Extreme Graphics Driver ({8A708DD8-A5E6-11D4-A706-000629E95E20}) uninstall cmd: RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562 InterVideo WinDVD Player 5.0-B11.422 ({91810AFC-A4F8-4EBA-A5AA-B198BBC81144}) version (major): 5 install location: C:\Program Files\InterVideo\WinDVD uninstall cmd: "C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL publisher: InterVideo Inc. contact: support@intervideo.com help link: http://www.intervideo.com/jsp/Support.jsp Norton Internet Security 7.0.3.8 ({91AA4B1F-B918-4e0b-A304-F8D4EC5D7726}) version: 117440515 version (major): 7 estimated size: 88 install date: 20040810 install source: c:\hp\tmp\src\Setup\ uninstall cmd: MsiExec.exe /I{91AA4B1F-B918-4e0b-A304-F8D4EC5D7726} publisher: Symantec Corporation Sonic RecordNow! 7.22 ({9541FED0-327F-4DF0-8B96-EF57EF622F19}) version: 118882304 version (major): 7 version (minor): 22 estimated size: 36611 install date: 20040808 install source: c:\hp\tmp\src\ uninstall cmd: MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19} publisher: Hewlett-Packard help link: http://support.sonic.com/ ({9F765BD0-B900-4EDE-A90B-61C8A9E95C42}) uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\Setup.exe" Windows Defender 1.1.1593.14 ({A06275F4-324B-4E85-95E6-87B2CD729401}) version: 16844345 version (major): 1 version (minor): 1 estimated size: 9778 install date: 20070408 install source: C:\Documents and Settings\Compaq_Owner\My Documents\ uninstall cmd: MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401} publisher: Microsoft Corporation help link: http://go.microsoft.com/fwlink/?LinkId=55273 CC_ccProxyMSI 2.1.1.700 ({A398F2DC-D706-4bb2-AC38-5532CD229D08}) version: 33619969 version (major): 2 version (minor): 1 estimated size: 1677 install date: 20040810 install source: c:\hp\tmp\src\Support\Proxy\ uninstall cmd: MsiExec.exe /I{A398F2DC-D706-4bb2-AC38-5532CD229D08} publisher: Symantec 4300Trb 51.0.230.000 ({A744C7C3-76F5-42F5-9E15-497A3DFBC709}) version: 855638246 version (major): 51 estimated size: 249 install date: 20060522 install source: E:\Setup\AiOHelp\ publisher: Hewlett-Packard MarketResearch 61.0.163.000 ({AAA11090-6E99-4655-AAF5-57EB5F677D0C}) version: 1023410339 version (major): 61 estimated size: 3389 install date: 20060522 install source: E:\setup\MarketResearch\ publisher: Hewlett-Packard DeviceManagementQFolder 1.00.0000 ({AB5D51AE-EBC3-438D-872C-705C7C2084B0}) version: 16777216 version (major): 1 estimated size: 124 install date: 20060522 install source: E:\setup\QFolder\ publisher: Hewlett-Packard Adobe Reader 8.1.1 8.1.1 ({AC76BA86-7AD7-1033-7B44-A81100000003}) version: 134283265 version (major): 8 version (minor): 1 estimated size: 131308 install date: 20071230 install location: C:\Program Files\Adobe\Reader 8.0\Reader\ install source: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\Adobe Reader 8\ uninstall cmd: MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81100000003} publisher: Adobe Systems Incorporated comments: contact: Customer Support help link: http://www.adobe.com/support/main.html readme: C:\Program Files\Adobe\Reader 8.0\Reader\Readme.htm Spybot - Search & Destroy 1.5.2 ({B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) install date: 20080229 install location: C:\Program Files\Spybot - Search & Destroy\ uninstall cmd: "C:\Program Files\Spybot - Search & Destroy\unins001.exe" publisher: Safer Networking Limited help link: http://www.safer-networking.org/index.php?page=support CP_Package_Variety3 61.0.163.000 ({B57F2FF0-5A25-4332-B503-4592B370C02F}) version: 1023410339 version (major): 61 estimated size: 8617 install date: 20060522 install source: E:\setup\CP_Package_Variety3\ publisher: Hewlett-Packard ({BAD59025-5B73-4E12-B789-0028C5A573C2}) uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\Setup.exe" DocProc 6.0.0.0 ({BF4E9ED0-EF26-4A4C-A123-6A6A1ABEE411}) version: 100663296 version (major): 6 estimated size: 76210 install date: 20060522 install source: E:\setup\DocProc\ publisher: Hewlett-Packard comments: 0 contact: 0 help link: 0 help telephone: 0 readme: 0 MSXML 4.0 SP2 (KB936181) 4.20.9848.0 ({C04E32E0-0416-434D-AFB9-6969D703A9EF}) version: 68429432 version (major): 4 version (minor): 20 estimated size: 2680 install date: 20070816 install source: c:\29b115e17fe92e6c2538\ uninstall cmd: MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} publisher: Microsoft Corporation help link: http://support.microsoft.com/kb/936181 Scan 6.0.0.0 ({C6812939-B117-48E6-A3BA-1709C14A3C8C}) version: 100663296 version (major): 6 estimated size: 9472 install date: 20060522 install source: E:\setup\Scan\ publisher: Hewlett-Packard comments: 0 contact: 0 help link: 0 help telephone: 0 readme: 0 AiO_Scan_CDA 51.0.230.000 ({C8753E28-2680-49BF-BD48-DD38FD086EFE}) version: 855638246 version (major): 51 estimated size: 586 install date: 20060522 install source: E:\setup\AiO_Scan\ publisher: Hewlett-Packard Toolbox 61.0.163.000 ({C98E8D9D-21DE-4F87-A9B7-142BB89840FC}) version: 1023410339 version (major): 61 estimated size: 5409 install date: 20060522 install source: E:\setup\Toolbox\ publisher: Hewlett-Packard Norton Internet Security 7.0.3.8 ({C9D599E1-6B68-4a1f-8A4F-A1DB433DB1BF}) version: 117440515 version (major): 7 install date: 20040810 install source: c:\hp\tmp\src\Setup\ uninstall cmd: MsiExec.exe /I{C9D599E1-6B68-4a1f-8A4F-A1DB433DB1BF} publisher: Symantec Corporation Symantec Network Drivers Update 5.5.1.6 ({CA0A1E54-CE0F-4366-B09C-A87B61DC5633}) version: 84213761 version (major): 5 version (minor): 5 estimated size: 2754 install date: 20060307 install source: C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.4_E\ publisher: Symantec Corporation Microsoft .NET Framework 1.1 1.1.4322 ({CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) version: 16847074 version (major): 1 version (minor): 1 estimated size: 75259 install date: 20070710 install source: C:\DOCUME~1\Owner\LOCALS~1\Temp\IXP000.TMP\ uninstall cmd: MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} publisher: Microsoft readme: file://C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\RepairRedist.htm SUPERAntiSpyware Free Edition 4.0.0.1154 ({CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) version: 67108864 version (major): 4 estimated size: 14725 install date: 20080513 install source: C:\Program Files\Common Files\Wise Installation Wizard\ uninstall cmd: MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA} publisher: SUPERAntiSpyware.com help link: http://www.superantispyware.com/support.html MSN Messenger 7.5 7.5.0311.0 ({CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}) version: 117768503 version (major): 7 version (minor): 5 estimated size: 15714 install date: 20060202 install source: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IXP000.TMP\ uninstall cmd: MsiExec.exe /I{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5} publisher: Microsoft Corporation Full Tilt Poker 4.10.3.WIN.FullTilt.Real ({D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}) version: 67764227 install date: 20070906 install location: C:\Program Files\Full Tilt Poker install source: C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\AEOYHZXX\FullTiltSetup[1].exe uninstall cmd: "C:\Program Files\InstallShield Installation Information\{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}\setup.exe" -runfromtemp -l0x0009 -removeonly publisher: Full Tilt Poker HP Photosmart Essential 1.8.0.26 ({D7CAE58E-26DE-49B7-A75D-EAEDF76726BE}) version: 17301504 version (major): 1 version (minor): 8 estimated size: 8910 install date: 20060522 install location: C:\Program Files\HP\Photosmart Essential\ install source: E:\setup\ImageZoneExpress\ uninstall cmd: MsiExec.exe /X{D7CAE58E-26DE-49B7-A75D-EAEDF76726BE} publisher: HP HpSdpAppCoreApp 3.00.0000 ({DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}) version: 50331648 version (major): 3 estimated size: 2814 install date: 20040808 install source: C:\hp\tmp\src\ publisher: Hewlett-Packard HPProductAssistant 61.0.163.000 ({DEBB2986-15B0-4D28-95FA-5C966A396589}) version: 1023410339 version (major): 61 estimated size: 3115 install date: 20060522 install source: E:\setup\hpproductassistant\ publisher: Hewlett-Packard HP PSC & OfficeJet 6.1.A ({E5A8DDAB-AE80-48C6-A75B-D0FAB83B299D}) uninstall cmd: "C:\Program Files\HP\Digital Imaging\{E5A8DDAB-AE80-48C6-A75B-D0FAB83B299D}\setup\hpzscr01.exe" -datfile hposcr08.dat publisher: HP help link: http://www.hp.com/support 4300_Help 51.0.230.000 ({E769999E-D0D9-4D51-AEFE-1BD44289E550}) version: 855638246 version (major): 51 estimated size: 5405 install date: 20060522 install source: E:\Setup\AiOHelp\ publisher: Hewlett-Packard WebReg 61.0.163.000 ({EC2715CE-C182-483C-84CC-81D7D914CF14}) version: 1023410339 version (major): 61 estimated size: 517 install date: 20060522 install source: E:\setup\WebReg\ publisher: Hewlett-Packard HP Software Update 3.0.6.003 ({ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}) version: 50331654 version (major): 3 estimated size: 3430 install date: 20060522 install source: E:\setup\HPSoftwareUpdate\ uninstall cmd: MsiExec.exe /X{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93} publisher: HEWLET~1|Hewlett-Packard contact: http://www.hp.com/support Fax_CDA 51.0.230.000 ({F6076EF9-08E1-442F-B6A2-BFB61B295A14}) version: 855638246 version (major): 51 estimated size: 21354 install date: 20060522 install source: E:\setup\fax\ publisher: Hewlett-Packard NewCopy_CDA 51.0.230.000 ({FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}) version: 855638246 version (major): 51 estimated size: 2493 install date: 20060522 install source: E:\setup\newcopy\ publisher: Hewlett-Packard Norton Internet Security 7.0.3.8 ({FC2C0536-583C-46c0-844A-62CECAE01F22}) version: 117440515 version (major): 7 estimated size: 616 install date: 20040810 install source: c:\hp\tmp\src\Setup\ uninstall cmd: MsiExec.exe /I{FC2C0536-583C-46c0-844A-62CECAE01F22} publisher: Symantec Corporation MSRedist 1.0.0.0 ({FC37ABD0-2108-4beb-B010-1254E0662B5A}) version: 16777216 version (major): 1 estimated size: 3266 install date: 20040810 install source: c:\hp\tmp\src\Support\MSRedist\ uninstall cmd: MsiExec.exe /I{FC37ABD0-2108-4beb-B010-1254E0662B5A} publisher: Symantec Corporation --- System Services --- Service (registry key): .NET CLR Data Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): .NET CLR Networking Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): .NETFramework Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Abiosdsk Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 0 Service (registry key): abp480n5 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): ACPI Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft ACPI Driver Image path: system32\DRIVERS\ACPI.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): ACPIEC Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): adpu160m Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): aec Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel Acoustic Echo Canceller Image path: system32\drivers\aec.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): AFD Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: AFD Description: AFD Networking Support Environment Image path: \SystemRoot\System32\drivers\afd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): AgereSoftModem Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Agere Systems Soft Modem Image path: system32\DRIVERS\AGRSM.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Aha154x Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): aic78u2 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): aic78xx Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): ALCXSENS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Service for WDM 3D Audio Driver Image path: system32\drivers\ALCXSENS.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ALCXWDM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Service for Realtek AC97 Audio (WDM) Image path: system32\drivers\ALCXWDM.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Alerter Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Alerter Description: Notifies selected users and computers of administrative alerts. If the service is stopped, programs that use administrative alerts will not receive them. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation Service (registry key): ALG Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Application Layer Gateway Service Description: Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Windows Firewall. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\alg.exe Image size: 44544 Image MD5: 8C515081584A38AA007909CD02020B3D Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): AliIde Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): amsint Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): AppMgmt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Application Management Description: Provides software installation services such as Assign, Publish, and Remove. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): Arp1394 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: 1394 ARP Client Protocol Description: 1394 ARP Client Protocol Image path: system32\DRIVERS\arp1394.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): asc Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): asc3350p Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): asc3550 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): ASCTRM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: ASCTRM Control Set: CurrentControlSet Start: 2 Type: 1 Error Control: 1 Service (registry key): ASP.NET Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): ASP.NET_1.1.4322 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): aspnet_state Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: ASP.NET State Service Description: Provides support for out-of-process session states for ASP.NET. If this service is stopped, out-of-process requests will not be processed. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe Image size: 32768 Image MD5: E1A1206A4FB19B675E947B29CCD25FBA Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): AsyncMac Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: RAS Asynchronous Media Driver Description: RAS Asynchronous Media Driver Image path: system32\DRIVERS\asyncmac.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): atapi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Standard IDE/ESDI Hard Disk Controller Image path: system32\DRIVERS\atapi.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): Atdisk Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 0 Service (registry key): Atmarpc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: ATM ARP Client Protocol Description: ATM ARP Client Protocol Image path: system32\DRIVERS\atmarpc.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): AudioSrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Audio Description: Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: PlugPlay,RpcSs Service (registry key): audstub Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Audio Stub Driver Image path: system32\DRIVERS\audstub.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): BattC Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Beep Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): BITS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Background Intelligent Transfer Service Description: Transfers files in the background using idle network bandwidth. If the service is stopped, features such as Windows Update, and MSN Explorer will be unable to automatically download programs and other information. If this service is disabled, any services that explicitly depend on it may fail to transfer files if they do not have a fail safe mechanism to transfer files directly through IE in case BITS has been disabled. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: Rpcss Service (registry key): Browser Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Computer Browser Description: Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation,LanmanServer Service (registry key): cbidf2k Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): ccEvtMgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Symantec Event Manager Description: Symantec Event Manager Object name: LocalSystem Image path: "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" Image size: 255648 Image MD5: 9761D4E304074F156AE9B7C3DFF1A229 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 0 Depends On services: RPCSS,ccSetMgr Service (registry key): ccProxy Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Symantec Network Proxy Description: Symantec Network Proxy Service Object name: LocalSystem Image path: "c:\Program Files\Common Files\Symantec Shared\ccProxy.exe" Image size: 218736 Image MD5: 35AD77BDC4EE11E7FA111E4CE4026E8C Control Set: CurrentControlSet Start: 2 Type: 272 Error Control: 0 Service (registry key): ccPwdSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Symantec Password Validation Description: Symantec Password Validation Service Object name: LocalSystem Image path: "c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe" Image size: 87712 Image MD5: 1613F71CC6BC9D386C4C7A712F75069D Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 0 Service (registry key): ccSetMgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Symantec Settings Manager Description: Symantec Settings Manager Object name: LocalSystem Image path: "c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" Image size: 235168 Image MD5: 4F46BD842DB5C1A0E4381B47C117EBBE Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 0 Depends On services: RPCSS Service (registry key): cd20xrnt Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): Cdaudio Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): Cdfs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 2 Error Control: 1 Depends On group: "SCSI CDROM Class" Service (registry key): Cdrom Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: CD-ROM Driver Image path: system32\DRIVERS\cdrom.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Depends On group: "SCSI miniport" Service (registry key): Changer Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): CiSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Indexing Service Description: Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language. Object name: LocalSystem Image path: %SystemRoot%\system32\cisvc.exe Image size: 5632 Image MD5: 1CFE720EB8D93A7158A4EBC3AB178BDE Control Set: CurrentControlSet Start: 3 Type: 288 Error Control: 1 Depends On services: RPCSS Service (registry key): ClipSrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: ClipBook Description: Enables ClipBook Viewer to store information and share it with remote computers. If the service is stopped, ClipBook Viewer will not be able to share information with remote computers. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\clipsrv.exe Image size: 33280 Image MD5: 34CBE729F38138217F9C80212A2A0C82 Control Set: CurrentControlSet Start: 4 Type: 16 Error Control: 1 Depends On services: NetDDE Service (registry key): CmdIde Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): COMSysApp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: COM+ System Application Description: Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} Image size: 5120 Image MD5: 0A9BA6AF531AFE7FA5E4FB973852D863 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: rpcss Service (registry key): ContentFilter Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): ContentIndex Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Cpqarray Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): CryptSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Cryptographic Services Description: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): dac2w2k Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 0 Service (registry key): dac960nt Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): DcomLaunch Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: DCOM Server Process Launcher Description: Provides launch functionality for DCOM services. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost -k DcomLaunch Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): Dhcp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: DHCP Client Description: Manages network configuration by registering and updating IP addresses and DNS names. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: Tcpip,Afd,NetBT Service (registry key): Disk Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Disk Driver Image path: system32\DRIVERS\disk.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Depends On group: "SCSI miniport" Service (registry key): dmadmin Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Logical Disk Manager Administrative Service Description: Configures hard disk drives and volumes. The service only runs for configuration processes and then stops. Object name: LocalSystem Image path: %SystemRoot%\System32\dmadmin.exe /com Image size: 224768 Image MD5: E46050330BD42F33609117F861E32D3C Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs,PlugPlay,DmServer Service (registry key): dmboot Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: System32\drivers\dmboot.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): dmio Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: System32\drivers\dmio.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): dmload Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: System32\drivers\dmload.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): dmserver Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Logical Disk Manager Description: Detects and monitors new hard disk drives and sends disk volume information to Logical Disk Manager Administrative Service for configuration. If this service is stopped, dynamic disk status and configuration information may become out of date. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs,PlugPlay Service (registry key): DMusic Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel DLS Syntheiszer Image path: system32\drivers\DMusic.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Dnscache Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: DNS Client Description: Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\system32\svchost.exe -k NetworkService Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: Tcpip Service (registry key): Dot3svc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Wired AutoConfig Description: This service performs IEEE 802.1X authentication on Ethernet interfaces Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k dot3svc Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: Ndisuio,eaphost Service (registry key): dpti2o Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): drmkaud Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel DRM Audio Descrambler Image path: system32\drivers\drmkaud.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): EapHost Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Extensible Authentication Protocol Service Description: Provides windows clients Extensible Authentication Protocol Service Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k eapsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): ERSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Error Reporting Service Description: Allows error reporting for services and applictions running in non-standard environments. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 0 Depends On services: RpcSs Service (registry key): Eventlog Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Event Log Description: Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped. Object name: LocalSystem Image path: %SystemRoot%\system32\services.exe Image size: 108544 Image MD5: 0E776ED5F7CC9F94299E70461B7B8185 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): EventSystem Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: COM+ Event System Description: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): Fastfat Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 2 Error Control: 1 Service (registry key): FastUserSwitchingCompatibility Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Fast User Switching Compatibility Description: Provides management for applications that require assistance in a multiple user environment. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: TermService Service (registry key): Fax Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Fax Description: Enables you to send and receive faxes, utilizing fax resources available on this computer or on the network. Object name: LocalSystem Image path: %systemroot%\system32\fxssvc.exe Image size: 267776 Image MD5: E97D6A8684466DF94FF3BC24FB787A07 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: TapiSrv,RpcSs,PlugPlay,Spooler Service (registry key): Fdc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Floppy Disk Controller Driver Image path: system32\DRIVERS\fdc.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Fips Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): Flpydisk Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Floppy Disk Driver Image path: system32\DRIVERS\flpydisk.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): FltMgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: FltMgr Description: File System Filter Manager Driver Image path: system32\drivers\fltmgr.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 2 Error Control: 1 Service (registry key): Fs_Rec Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 8 Error Control: 0 Service (registry key): Ftdisk Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Volume Manager Driver Image path: system32\DRIVERS\ftdisk.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): GEARAspiWDM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: GEAR CDRom Filter Image path: SYSTEM32\DRIVERS\GEARAspiWDM.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Gpc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Generic Packet Classifier Description: Generic Packet Classifier Image path: system32\DRIVERS\msgpc.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): gusvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Google Updater Service Object name: LocalSystem Image path: "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" Image size: 138168 Image MD5: 751C1D2CA2ABF4A9F5A6B8D7D45B907C Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 0 Depends On services: RPCSS Service (registry key): helpsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Help and Support Description: Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): HidServ Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Human Interface Device Access Description: Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): hkmsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Health Key and Certificate Management Service Description: Manages health certificates and keys (used by NAP) Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): hpn Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): HPZid412 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IEEE-1284.4 Driver HPZid412 Image path: system32\DRIVERS\HPZid412.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): HPZipr12 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Print Class Driver for IEEE-1284.4 HPZipr12 Image path: system32\DRIVERS\HPZipr12.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): HPZius12 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: USB to IEEE-1284.4 Translation Driver HPZius12 Image path: system32\DRIVERS\HPZius12.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): HTTP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: HTTP Description: This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start. Image path: System32\Drivers\HTTP.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): HTTPFilter Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: HTTP SSL Description: This service implements the secure hypertext transfer protocol (HTTPS) for the HTTP service, using the Secure Socket Layer (SSL). If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k HTTPFilter Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: HTTP Service (registry key): i2omgmt Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): i2omp Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): i8042prt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: i8042 Keyboard and PS/2 Mouse Port Driver Image path: system32\DRIVERS\i8042prt.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): ialm Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\DRIVERS\ialmnt5.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): Imapi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: CD-Burning Filter Driver Image path: system32\DRIVERS\imapi.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): ImapiService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IMAPI CD-Burning COM Service Description: Manages CD recording using Image Mastering Applications Programming Interface (IMAPI). If this service is stopped, this computer will be unable to record CDs. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\system32\imapi.exe Image size: 150528 Image MD5: 30DEAF54A9755BB8546168CFE8A6B5E1 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): inetaccs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): ini910u Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): Inport Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): IntelIde Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: system32\DRIVERS\intelide.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): intelppm Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Intel Processor Driver Image path: system32\DRIVERS\intelppm.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Ip6Fw Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IPv6 Windows Firewall Driver Description: Provides intrusion prevention service for a home or small office network. Image path: system32\drivers\ip6fw.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): IpFilterDriver Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IP Traffic Filter Driver Description: IP Traffic Filter Driver Image path: system32\DRIVERS\ipfltdrv.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): IpInIp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IP in IP Tunnel Driver Description: IP in IP Tunnel Driver Image path: system32\DRIVERS\ipinip.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): IpNat Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IP Network Address Translator Description: IP Network Address Translator Image path: system32\DRIVERS\ipnat.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): iPodService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: iPod Service Description: iPod hardware management services Object name: LocalSystem Image path: "C:\Program Files\iPod\bin\iPodService.exe" Image size: 401408 Image MD5: 1158F9A8799B64378BDEB8BBD6B40462 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 0 Service (registry key): IPSec Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IPSEC driver Description: IPSEC driver Image path: system32\DRIVERS\ipsec.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): IRENUM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IR Enumerator Service Image path: system32\DRIVERS\irenum.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ISAPISearch Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): isapnp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: PnP ISA/EISA Bus Driver Image path: system32\DRIVERS\isapnp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): Kbdclass Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Keyboard Class Driver Image path: system32\DRIVERS\kbdclass.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): kmixer Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel Wave Audio Mixer Image path: system32\drivers\kmixer.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): KSecDD Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): lanmanserver Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Server Description: Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): lanmanworkstation Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Workstation Description: Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): lbrtfdc Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): ldap Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): LicenseService Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): LmHosts Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: TCP/IP NetBIOS Helper Description: Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: NetBT,Afd Service (registry key): MDM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Machine Debug Manager Description: Supports local and remote debugging for Visual Studio and script debuggers. If this service is stopped, the debuggers will not function properly. Object name: LocalSystem Image path: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" Image size: 322120 Image MD5: 11F714F85530A2BD134074DC30E99FCA Control Set: CurrentControlSet Start: 2 Type: 272 Error Control: 1 Depends On services: RPCSS Service (registry key): Messenger Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Messenger Description: Transmits net send and Alerter service messages between clients and servers. This service is not related to Windows Messenger. If this service is stopped, Alerter messages will not be transmitted. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation,NetBIOS,PlugPlay,RpcSS Service (registry key): mnmdd Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): mnmsrvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NetMeeting Remote Desktop Sharing Description: Enables an authorized user to access this computer remotely by using NetMeeting over a corporate intranet. If this service is stopped, remote desktop sharing will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\system32\mnmsrvc.exe Image size: 32768 Image MD5: D18F1F0C101D06A1C1ADF26EED16FCDD Control Set: CurrentControlSet Start: 3 Type: 272 Error Control: 1 Service (registry key): Modem Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): Mouclass Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Mouse Class Driver Image path: system32\DRIVERS\mouclass.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): MountMgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Mount Point Manager Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): mraid35x Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): MRxDAV Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WebDav Client Redirector Description: WebDav Client Redirector Image path: system32\DRIVERS\mrxdav.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Service (registry key): MRxSmb Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: MRXSMB Description: MRXSMB Image path: system32\DRIVERS\mrxsmb.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Service (registry key): MSDTC Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Distributed Transaction Coordinator Description: Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\NetworkService Image path: C:\WINDOWS\system32\msdtc.exe Image size: 6144 Image MD5: A137F1470499A205ABBB9AAFB3B6F2B1 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS,SamSS Service (registry key): Msfs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Service (registry key): MSIServer Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Installer Description: Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\system32\msiexec.exe /V Image size: 78848 Image MD5: 5879D691E842574A20FE63817CB76DF9 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): MSKSSRV Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Streaming Service Proxy Image path: system32\drivers\MSKSSRV.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MSPCLOCK Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Streaming Clock Proxy Image path: system32\drivers\MSPCLOCK.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): MSPQM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Streaming Quality Manager Proxy Image path: system32\drivers\MSPQM.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): mssmbios Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft System Management BIOS Driver Image path: system32\DRIVERS\mssmbios.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Mup Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Mup Control Set: CurrentControlSet Start: 0 Type: 2 Error Control: 1 Service (registry key): napagent Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Network Access Protection Agent Description: Allows windows clients to participate in Network Access Protection Object name: localSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): NDIS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NDIS System Driver Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): NdisTapi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access NDIS TAPI Driver Description: Remote Access NDIS TAPI Driver Image path: system32\DRIVERS\ndistapi.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Ndisuio Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NDIS Usermode I/O Protocol Description: NDIS Usermode I/O Protocol Image path: system32\DRIVERS\ndisuio.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NdisWan Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access NDIS WAN Driver Description: Remote Access NDIS WAN Driver Image path: system32\DRIVERS\ndiswan.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NDProxy Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): NetBIOS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NetBIOS Interface Description: NetBIOS Interface Image path: system32\DRIVERS\netbios.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Service (registry key): NetBT Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NetBT Description: NetBios over Tcpip Image path: system32\DRIVERS\netbt.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): NetDDE Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Network DDE Description: Provides network transport and security for Dynamic Data Exchange (DDE) for programs running on the same computer or on different computers. If this service is stopped, DDE transport and security will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\netdde.exe Image size: 111104 Image MD5: B857BA82860D7FF85AE29B095645563B Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Depends On services: NetDDEDSDM Service (registry key): NetDDEdsdm Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Network DDE DSDM Description: Manages Dynamic Data Exchange (DDE) network shares. If this service is stopped, DDE network shares will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\system32\netdde.exe Image size: 111104 Image MD5: B857BA82860D7FF85AE29B095645563B Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Service (registry key): Netlogon Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Net Logon Description: Supports pass-through authentication of account logon events for computers in a domain. Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 13312 Image MD5: BF2466B3E18E970D8A976FB95FC1CA85 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: LanmanWorkstation Service (registry key): Netman Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Network Connections Description: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 288 Error Control: 1 Depends On services: RpcSs Service (registry key): NIC1394 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: 1394 Net Driver Image path: system32\DRIVERS\nic1394.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Nla Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Network Location Awareness (NLA) Description: Collects and stores network configuration and location information, and notifies applications when this information changes. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: Tcpip,Afd Service (registry key): Npfs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Service (registry key): Ntfs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 2 Error Control: 1 Service (registry key): NtLmSsp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NT LM Security Support Provider Description: Provides security to remote procedure call (RPC) programs that use transports other than named pipes. Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 13312 Image MD5: BF2466B3E18E970D8A976FB95FC1CA85 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): NtmsSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Removable Storage Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): Null Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): NwlnkFlt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IPX Traffic Filter Driver Description: IPX Traffic Filter Driver Image path: system32\DRIVERS\nwlnkflt.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: NwlnkFwd Service (registry key): NwlnkFwd Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IPX Traffic Forwarder Driver Description: IPX Traffic Forwarder Driver Image path: system32\DRIVERS\nwlnkfwd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ohci1394 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: NEC FireWarden OHCI Compliant IEEE 1394 Host Controller Image path: system32\DRIVERS\ohci1394.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): Parport Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Parallel port driver Image path: system32\DRIVERS\parport.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): PartMgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Partition Manager Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): ParVdm Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 0 Depends On services: Parport Depends On group: "Parallel arbitrator" Service (registry key): PCI Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: PCI Bus Driver Image path: system32\DRIVERS\pci.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 3 Service (registry key): PCIDump Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): PCIIde Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: PCIIde Image path: \SystemRoot\system32\DRIVERS\pciide.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): Pcmcia Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): PDCOMP Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): PDFRAME Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): PDRELI Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): PDRFRAME Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): perc2 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): perc2hib Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): PerfDisk Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): PerfNet Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): PerfOS Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): PerfProc Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): PlugPlay Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Plug and Play Description: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability. Object name: LocalSystem Image path: %SystemRoot%\system32\services.exe Image size: 108544 Image MD5: 0E776ED5F7CC9F94299E70461B7B8185 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): Pml Driver HPZ12 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Pml Driver HPZ12 Object name: LocalSystem Image path: C:\WINDOWS\system32\HPZipm12.exe Image size: 69632 Image MD5: A38B3CE68E7F126190CDE4AA3FDF050F Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Service (registry key): PolicyAgent Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: IPSEC Services Description: Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver. Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 13312 Image MD5: BF2466B3E18E970D8A976FB95FC1CA85 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RPCSS,Tcpip,IPSec Service (registry key): PptpMiniport Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WAN Miniport (PPTP) Description: WAN Miniport (PPTP) Image path: system32\DRIVERS\raspptp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): ProtectedStorage Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Protected Storage Description: Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users. Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 13312 Image MD5: BF2466B3E18E970D8A976FB95FC1CA85 Control Set: CurrentControlSet Start: 2 Type: 288 Error Control: 1 Depends On services: RpcSs Service (registry key): Ps2 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: PS2 Image path: system32\DRIVERS\PS2.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): PSched Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: QoS Packet Scheduler Description: QoS Packet Scheduler Image path: system32\DRIVERS\psched.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Depends On services: Gpc Service (registry key): Ptilink Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Direct Parallel Link Driver Description: Direct Parallel Link Driver Image path: system32\DRIVERS\ptilink.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): PxHelp20 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: PxHelp20 Image path: System32\Drivers\PxHelp20.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): ql1080 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): Ql10wnt Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): ql12160 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): ql1240 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): ql1280 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): RasAcd Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access Auto Connection Driver Description: Remote Access Auto Connection Driver Image path: system32\DRIVERS\rasacd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): RasAuto Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access Auto Connection Manager Description: Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RasMan,Tapisrv Service (registry key): Rasl2tp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WAN Miniport (L2TP) Description: WAN Miniport (L2TP) Image path: system32\DRIVERS\rasl2tp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): RasMan Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access Connection Manager Description: Creates a network connection. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: Tapisrv Service (registry key): RasPppoe Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access PPPOE Driver Description: Remote Access PPPOE Driver Image path: system32\DRIVERS\raspppoe.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Raspti Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Direct Parallel Description: Direct Parallel Image path: system32\DRIVERS\raspti.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Rdbss Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Rdbss Description: Rdbss Image path: system32\DRIVERS\rdbss.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 2 Error Control: 1 Service (registry key): RDPCDD Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: System32\DRIVERS\RDPCDD.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): RDPDD Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): RDPNP Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): RDPWD Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): RDSessMgr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Desktop Help Session Manager Description: Manages and controls Remote Assistance. If this service is stopped, Remote Assistance will be unavailable. Before stopping this service, see the Dependencies tab of the Properties dialog box. Object name: LocalSystem Image path: C:\WINDOWS\system32\sessmgr.exe Image size: 141312 Image MD5: 3C37BF86641BDA977C3BF8A840F3B7FA Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): redbook Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Digital CD Audio Playback Filter Driver Image path: system32\DRIVERS\redbook.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): RemoteAccess Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Routing and Remote Access Description: Offers routing services to businesses in local area and wide area network environments. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 4 Type: 32 Error Control: 1 Depends On services: RpcSS Depends On group: NetBIOSGroup Service (registry key): RpcLocator Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Procedure Call (RPC) Locator Description: Manages the RPC name service database. Object name: NT AUTHORITY\NetworkService Image path: %SystemRoot%\system32\locator.exe Image size: 75264 Image MD5: AAED593F84AFA419BBAE8572AF87CF6A Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: LanmanWorkstation Service (registry key): RpcSs Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Procedure Call (RPC) Description: Provides the endpoint mapper and other miscellaneous RPC services. Object name: NT Authority\NetworkService Image path: %SystemRoot%\system32\svchost -k rpcss Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): RSVP Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: QoS RSVP Description: Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets. Object name: LocalSystem Image path: %SystemRoot%\system32\rsvp.exe Image size: 132608 Image MD5: 471B3F9741D762ABE75E9DEEA4787E47 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: TcpIp,Afd,RpcSs Service (registry key): RTL8023xp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver Image path: System32\DRIVERS\Rtlnicxp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): rtl8139 Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver Image path: system32\DRIVERS\RTL8139.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SamSs Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Security Accounts Manager Description: Stores security information for local user accounts. Object name: LocalSystem Image path: %SystemRoot%\system32\lsass.exe Image size: 13312 Image MD5: BF2466B3E18E970D8A976FB95FC1CA85 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): SASDIFSV Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SASDIFSV Image path: \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): SASENUM Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SASENUM Image path: \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SASKUTIL Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SASKUTIL Image path: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): SCardSvr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Smart Card Description: Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\SCardSvr.exe Image size: 95744 Image MD5: 86D007E7A654B9A71D1D7D856B104353 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 0 Depends On services: PlugPlay Service (registry key): Schedule Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Task Scheduler Description: Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): ScsiPort Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: %SystemRoot%\system32\drivers\scsiport.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Secdrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Secdrv Description: SafeDisc driver Image path: system32\DRIVERS\secdrv.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): seclogon Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Secondary Logon Description: Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 288 Error Control: 0 Service (registry key): SENS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: System Event Notification Description: Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: EventSystem Service (registry key): serenum Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Serenum Filter Driver Image path: system32\DRIVERS\serenum.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Serial Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Serial port driver Image path: system32\DRIVERS\serial.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): Sfloppy Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Depends On group: "SCSI miniport" Service (registry key): SharedAccess Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Firewall/Internet Connection Sharing (ICS) Description: Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: Netman,WinMgmt Service (registry key): ShellHWDetection Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Shell Hardware Detection Description: Provides notifications for AutoPlay hardware events. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 0 Depends On services: RpcSs Service (registry key): Simbad Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): SNDSrvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Symantec Network Drivers Service Description: Symantec Network Drivers Service Object name: LocalSystem Image path: "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe" Image size: 206552 Image MD5: 443E397643965E08C5AB6A6CAA732B97 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 0 Service (registry key): Sparrow Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): splitter Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel Audio Splitter Image path: system32\drivers\splitter.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): Spooler Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Print Spooler Description: Loads files to memory for later printing. Object name: LocalSystem Image path: %SystemRoot%\system32\spoolsv.exe Image size: 57856 Image MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B Control Set: CurrentControlSet Start: 2 Type: 272 Error Control: 1 Depends On services: RPCSS Service (registry key): sr Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: System Restore Filter Driver Image path: system32\DRIVERS\sr.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 0 Type: 2 Error Control: 1 Service (registry key): srservice Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: System Restore Service Description: Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): Srv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Srv Description: Srv Image path: system32\DRIVERS\srv.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 2 Error Control: 1 Service (registry key): SSDPSRV Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SSDP Discovery Service Description: Enables discovery of UPnP devices on your home network. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: HTTP Service (registry key): stisvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Image Acquisition (WIA) Description: Provides image acquisition services for scanners and cameras. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k imgsvc Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): swenum Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Software Bus Driver Image path: system32\DRIVERS\swenum.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): swmidi Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel GS Wavetable Synthesizer Image path: system32\drivers\swmidi.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SwPrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: MS Software Shadow Copy Provider Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: C:\WINDOWS\system32\dllhost.exe /Processid:{2BC1C3F8-EEF4-40D5-8324-86DA2793EDB7} Image size: 5120 Image MD5: 0A9BA6AF531AFE7FA5E4FB973852D863 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 0 Depends On services: rpcss Service (registry key): swwd Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): symc810 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): symc8xx Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): SYMDNS Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\System32\Drivers\SYMDNS.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): SymEvent Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \??\C:\Program Files\Symantec\SYMEVENT.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SYMFW Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\System32\Drivers\SYMFW.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): SYMIDS Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\System32\Drivers\SYMIDS.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): SYMIDSCO Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\idsdefs\20080513.001\symidsco.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): SYMNDIS Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\System32\Drivers\SYMNDIS.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): SYMREDRV Registry path: \SYSTEM\CurrentControlSet\Services\ Image path: \SystemRoot\System32\Drivers\SYMREDRV.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): SYMTDI Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SYMTDI Image path: \SystemRoot\System32\Drivers\SYMTDI.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Depends On services: Tcpip Service (registry key): SymWSC Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: SymWMI Service Description: Symantec WMI Service Object name: LocalSystem Image path: "c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe" Image size: 316544 Image MD5: 67C5AF84809468061121FBCBECB19285 Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 0 Depends On services: winmgmt Service (registry key): sym_hi Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): sym_u3 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): sysaudio Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft Kernel System Audio Device Image path: system32\drivers\sysaudio.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): SysmonLog Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Performance Logs and Alerts Description: Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT Authority\NetworkService Image path: %SystemRoot%\system32\smlogsvc.exe Image size: 89600 Image MD5: C7ABBC59B43274B1109DF6B24D617051 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): TapiSrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Telephony Description: Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: PlugPlay,RpcSs Service (registry key): Tcpip Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: TCP/IP Protocol Driver Description: TCP/IP Protocol Driver Image path: system32\DRIVERS\tcpip.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Depends On services: IPSec Service (registry key): TDPIPE Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): TDTCP Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): TermDD Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Terminal Device Driver Image path: system32\DRIVERS\termdd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 1 Service (registry key): TermService Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Terminal Services Description: Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost -k DComLaunch Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RPCSS Service (registry key): Themes Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Themes Description: Provides user experience theme management. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): TosIde Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): TrkWks Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Distributed Link Tracking Client Description: Maintains links between NTFS files within a computer or across computers in a network domain. Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): TSDDD Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Udfs Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 2 Error Control: 1 Service (registry key): ultra Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): Update Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microcode Update Driver Image path: system32\DRIVERS\update.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): upnphost Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Universal Plug and Play Device Host Description: Provides support to host Universal Plug and Play devices. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: SSDPSRV,HTTP Service (registry key): UPS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Uninterruptible Power Supply Description: Manages an uninterruptible power supply (UPS) connected to the computer. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\System32\ups.exe Image size: 18432 Image MD5: 05365FB38FCA1E98F7A566AAAF5D1815 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Service (registry key): usb Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): usbccgp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB Generic Parent Driver Image path: system32\DRIVERS\usbccgp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbehci Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB 2.0 Enhanced Host Controller Miniport Driver Image path: system32\DRIVERS\usbehci.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbhub Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: USB2 Enabled Hub Image path: system32\DRIVERS\usbhub.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbprint Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB PRINTER Class Image path: system32\DRIVERS\usbprint.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbscan Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: USB Scanner Driver Image path: system32\DRIVERS\usbscan.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): USBSTOR Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: USB Mass Storage Driver Image path: system32\DRIVERS\USBSTOR.SYS Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): usbuhci Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft USB Universal Host Controller Miniport Driver Image path: system32\DRIVERS\usbuhci.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): VgaSave Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: VGA Display Controller. Description: Controls the VGA display adapter to provide basic display capabilities. Image path: \SystemRoot\System32\drivers\vga.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 1 Type: 1 Error Control: 0 Service (registry key): ViaIde Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: ViaIde Image path: \SystemRoot\system32\DRIVERS\viaide.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 4 Type: 1 Error Control: 1 Service (registry key): VolSnap Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 1 Error Control: 1 Service (registry key): VSS Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Volume Shadow Copy Description: Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\vssvc.exe Image size: 289792 Image MD5: 7A9DB3A67C333BF0BD42E42B8596854B Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): VXD Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): W32Time Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Time Description: Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): W3SVC Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): Wanarp Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Remote Access IP ARP Driver Description: Remote Access IP ARP Driver Image path: system32\DRIVERS\wanarp.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): wanatw Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WAN Miniport (ATW) Image path: system32\DRIVERS\wanatw4.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): WDICA Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 0 Service (registry key): wdmaud Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Microsoft WINMM WDM Audio Compatibility Driver Image path: system32\drivers\wdmaud.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): WebClient Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WebClient Description: Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: NT AUTHORITY\LocalService Image path: %SystemRoot%\system32\svchost.exe -k LocalService Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: MRxDAV Service (registry key): WinDefend Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Defender Description: Helps protect users from malicious software, spyware, and other potentially unwanted software Object name: LocalSystem Image path: "C:\Program Files\Windows Defender\MsMpEng.exe" Image size: 13592 Image MD5: F45DD1E1365D857DD08BC23563370D0E Control Set: CurrentControlSet Start: 2 Type: 16 Error Control: 1 Depends On services: RpcSs Service (registry key): winmgmt Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Management Instrumentation Description: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Object name: LocalSystem Image path: %systemroot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 0 Depends On services: RPCSS Service (registry key): Winsock Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 3 Type: 4 Error Control: 1 Service (registry key): WinSock2 Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): WinTrust Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): WmdmPmSN Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Portable Media Serial Number Service Description: Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Service (registry key): Wmi Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): WmiApRpl Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 Service (registry key): WmiApSrv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: WMI Performance Adapter Description: Provides performance library information from WMI HiPerf providers. Object name: LocalSystem Image path: C:\WINDOWS\system32\wbem\wmiapsrv.exe Image size: 126464 Image MD5: E0673F1106E62A68D2257E376079F821 Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: RPCSS Service (registry key): WMPNetworkSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Media Player Network Sharing Service Description: Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play Object name: NT AUTHORITY\NetworkService Image path: "C:\Program Files\Windows Media Player\WMPNetwk.exe" Image size: 913408 Image MD5: F74E3D9A7FA9556C3BBB14D4E5E63D3B Control Set: CurrentControlSet Start: 3 Type: 16 Error Control: 1 Depends On services: upnphost,http,HTTPFilter Service (registry key): WS2IFSL Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 1 Type: 0 Error Control: 0 Service (registry key): wscsvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Security Center Description: Monitors system security settings and configurations. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs,winmgmt Service (registry key): wuauserv Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Automatic Updates Description: Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. Object name: LocalSystem Image path: %systemroot%\system32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Service (registry key): WudfPf Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Driver Foundation - User-mode Driver Framework Platform Driver Description: Provide communciation services for UMDF components. Image path: system32\DRIVERS\WudfPf.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): WudfRd Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Driver Foundation - User-mode Driver Framework Reflector Description: Reflect device requests to user-mode driver drivers Image path: system32\DRIVERS\wudfrd.sys Image size: 0 Image MD5: D41D8CD98F00B204E9800998ECF8427E Control Set: CurrentControlSet Start: 3 Type: 1 Error Control: 1 Service (registry key): WudfSvc Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Windows Driver Foundation - User-mode Driver Framework Description: Manages user-mode driver host processes Object name: LocalSystem Image path: %SystemRoot%\system32\svchost.exe -k WudfServiceGroup Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: PlugPlay Service (registry key): WZCSVC Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Wireless Zero Configuration Description: Provides automatic configuration for the 802.11 adapters Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 2 Type: 32 Error Control: 1 Depends On services: RpcSs,Ndisuio Service (registry key): xmlprov Registry path: \SYSTEM\CurrentControlSet\Services\ Display name: Network Provisioning Service Description: Manages XML configuration files on a domain basis for automatic network provisioning. Object name: LocalSystem Image path: %SystemRoot%\System32\svchost.exe -k netsvcs Image size: 14336 Image MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 Control Set: CurrentControlSet Start: 3 Type: 32 Error Control: 1 Depends On services: RpcSs Service (registry key): {E9552735-0D73-4652-B82E-8A0C2C8713D2} Registry path: \SYSTEM\CurrentControlSet\Services\ Control Set: CurrentControlSet Start: 0 Type: 0 Error Control: 0 |
|
|
|
May 14 2008, 09:16 PM
Post
#11
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 13-May 08 Member No.: 208,737 |
Zlob.DNSChanger.Rtk: [SBI $FE3023DF] Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System=...KDVSN.EXE... Common Dialogs: History (12 files) (Registry key, nothing done) HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU Log: Activity: SchedLgU.Txt (Backup file, nothing done) C:\WINDOWS\SchedLgU.Txt Log: Activity: imsins.log (Backup file, nothing done) C:\WINDOWS\imsins.log Log: Activity: OEWABLog.txt (Backup file, nothing done) C:\WINDOWS\OEWABLog.txt Log: Install: comsetup.log (Backup file, nothing done) C:\WINDOWS\comsetup.log Log: Install: ocgen.log (Backup file, nothing done) C:\WINDOWS\ocgen.log Log: Install: setupact.log (Backup file, nothing done) C:\WINDOWS\setupact.log Log: Install: setupapi.log (Backup file, nothing done) C:\WINDOWS\setupapi.log Log: Install: setuplog.txt (Backup file, nothing done) C:\WINDOWS\setuplog.txt Log: Install: svcpack.log (Backup file, nothing done) C:\WINDOWS\svcpack.log Log: Install: wmsetup.log (Backup file, nothing done) C:\WINDOWS\wmsetup.log Log: Install: DtcInstall.log (Backup file, nothing done) C:\WINDOWS\DtcInstall.log Log: Shutdown: System32\wbem\logs\mofcomp.log (Backup file, nothing done) C:\WINDOWS\System32\wbem\logs\mofcomp.log Log: Shutdown: System32\wbem\logs\setup.log (Backup file, nothing done) C:\WINDOWS\System32\wbem\logs\setup.log Log: Shutdown: System32\wbem\logs\wbemcore.log (Backup file, nothing done) C:\WINDOWS\System32\wbem\logs\wbemcore.log Log: Shutdown: System32\wbem\logs\wbemess.lo_ (Backup file, nothing done) C:\WINDOWS\System32\wbem\logs\wbemess.lo_ Log: Shutdown: System32\wbem\logs\wbemess.log (Backup file, nothing done) C:\WINDOWS\System32\wbem\logs\wbemess.log Log: Shutdown: System32\wbem\logs\wmiprov.log (Backup file, nothing done) C:\WINDOWS\System32\wbem\logs\wmiprov.log MS Media Player: [SBI $5C51E349] Client ID (Registry change, nothing done) HKEY_USERS\.DEFAULT\Software\Microsoft\MediaPlayer\Player\Settings\Client ID MS Media Player: [SBI $5C51E349] Client ID (Registry change, nothing done) HKEY_USERS\S-1-5-18\Software\Microsoft\MediaPlayer\Player\Settings\Client ID MS Direct3D: [SBI $7FB7B83F] Most recent application (Registry change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name MS DirectDraw: [SBI $EB49D5AF] Most recent application (Registry change, nothing done) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name MS Search Assistant: [SBI $AE0C4647] Typed search terms history (Registry key, nothing done) HKEY_USERS\S-1-5-21-3341656437-3043363843-2328747555-1009\Software\Microsoft\Search Assistant\ACMru Windows Explorer: [SBI $AA0766B5] Stream history (2 files) (Registry key, nothing done) HKEY_USERS\S-1-5-21-3341656437-3043363843-2328747555-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU Windows Explorer: [SBI $2026AFB6] User Assistant history IE (6 files) (Registry key, nothing done) HKEY_USERS\S-1-5-21-3341656437-3043363843-2328747555-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count Windows Explorer: [SBI $6107D172] User Assistant history files (61 files) (Registry key, nothing done) HKEY_USERS\S-1-5-21-3341656437-3043363843-2328747555-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count Windows Explorer: [SBI $B7EBA926] Last visited history (5 files) (Registry key, nothing done) HKEY_USERS\S-1-5-21-3341656437-3043363843-2328747555-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU Windows Explorer: [SBI $D20DA0AD] Recent file global history (Registry key, nothing done) HKEY_USERS\S-1-5-21-3341656437-3043363843-2328747555-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs Cookie: Cookie (3) (Cookie, nothing done) Cache: Cache (78) (Cache, nothing done) History: History (20) (History, nothing done) Cookie: Cookie (18) (Cookie, nothing done) --- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) --- 2008-01-28 blindman.exe (1.0.0.7) 2008-01-28 SDDelFile.exe (1.0.2.4) 2008-01-28 SDMain.exe (1.0.0.5) 2007-10-07 SDShred.exe (1.0.1.2) 2008-01-28 SDUpdate.exe (1.0.8.8) 2008-01-28 SDWinSec.exe (1.0.0.11) 2008-01-28 SpybotSD.exe (1.5.2.20) 2008-01-28 TeaTimer.exe (1.5.2.16) 2004-04-27 unins000.exe (51.13.0.0) 2008-02-29 unins001.exe (51.49.0.0) 2008-01-28 Update.exe (1.4.0.6) 2008-01-28 advcheck.dll (1.5.4.5) 2007-04-02 aports.dll (2.1.0.0) 2004-05-12 borlndmm.dll (7.0.4.453) 2004-05-12 delphimm.dll (7.0.4.453) 2007-11-17 DelZip179.dll (1.79.7.4) 2008-01-28 SDFiles.dll (1.5.1.19) 2008-01-28 SDHelper.dll (1.5.0.11) 2006-02-20 Tools.dll (2.0.0.2) 2004-05-12 UnzDll.dll (1.73.1.1) 2004-05-12 ZipDll.dll (1.73.2.0) 2008-04-16 Includes\Adware.sbi (*) 2008-05-07 Includes\AdwareC.sbi (*) 2008-05-07 Includes\Cookies.sbi (*) 2007-12-26 Includes\Dialer.sbi (*) 2008-05-07 Includes\DialerC.sbi (*) 2008-05-07 Includes\HeavyDuty.sbi (*) 2008-04-30 Includes\Hijackers.sbi (*) 2008-05-07 Includes\HijackersC.sbi (*) 2008-04-30 Includes\Keyloggers.sbi (*) 2008-05-07 Includes\KeyloggersC.sbi (*) 2004-11-29 Includes\LSP.sbi (*) 2008-04-22 Includes\Malware.sbi (*) here is the results report 2008-05-07 Includes\MalwareC.sbi (*) 2008-03-26 Includes\PUPS.sbi (*) 2008-05-07 Includes\PUPSC.sbi (*) 2008-05-07 Includes\Revision.sbi (*) 2008-01-09 Includes\Security.sbi (*) 2008-05-07 Includes\SecurityC.sbi (*) 2008-04-16 Includes\Spybots.sbi (*) 2008-05-07 Includes\SpybotsC.sbi (*) 2008-04-16 Includes\Spyware.sbi (*) 2008-05-07 Includes\SpywareC.sbi (*) 2007-11-06 Includes\Tracks.uti (*) 2008-04-30 Includes\Trojans.sbi (*) 2008-05-07 Includes\TrojansC.sbi (*) 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-06-06 Plugins\TCPIPAddress.dll |
|
|
|
May 15 2008, 07:39 AM
Post
#12
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 15,582 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
That's a little more info than I really needed, but I do see the problem.
Please download the OTMoveIt2 by OldTimer.
Also post a new log from DSS. -------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it! ======================================================== |
|
|
|
May 15 2008, 09:55 PM
Post
#13
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 13-May 08 Member No.: 208,737 |
I was prompted to reboot and this is what the log read...
File move failed. C:\WINDOWS\system32\KDVSN.EXE scheduled to be moved on reboot. < HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\\System > Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\\System deleted successfully. OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 05142008_224841 Files moved on Reboot... File move failed. C:\WINDOWS\system32\KDVSN.EXE scheduled to be moved on reboot. |
|
|
|
May 15 2008, 10:03 PM
Post
#14
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 13-May 08 Member No.: 208,737 |
and the dss report requested....man this is complicated stuff. Good news though! I didn't send you a PM this time LOL. You should work for NASA or be a doctor. I hope we can diagnose this problem.
Deckard's System Scanner v20071014.68 Run by Compaq_Owner on 2008-05-14 22:57:07 Computer is in Normal Mode. -------------------------------------------------------------------------------- Total Physical Memory: 504 MiB (512 MiB recommended). -- HijackThis (run as Compaq_Owner.exe) ---------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:57:29 PM, on 5/14/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe c:\Program Files\Common Files\Symantec Shared\ccProxy.exe c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\WINDOWS\Explorer.EXE c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\windows\system\hpsysdrv.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\BroadJump\Client Foundation\CFD.exe C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\System32\alg.exe C:\Documents and Settings\Compaq_Owner\Desktop\dss(2).exe C:\PROGRA~1\TRENDM~1\HIJACK~1\COMPAQ~1.EXE C:\WINDOWS\system32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user') O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk.disabled O4 - Global Startup: SBC Self Support Tool.lnk.disabled O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2DEF4530-8CE6-41C9-84B6-A54536C90213} (Crystal Report Viewer Control 9) - http://www.ugaais.com/viewer9/activeXViewe...tivexviewer.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} - http://esupport.aol.com/help/acp2/engine/aolcoach_core_1.cab O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - http://aolcc.aol.com/computercheckup/qdiagcc.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1210477749796 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E9552735-0D73-4652-B82E-8A0C2C8713D2}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe -- End of file - 10529 bytes -- Files created between 2008-04-14 and 2008-05-14 ----------------------------- 2008-05-13 01:08:23 967 --a------ C:\WINDOWS\ScUnin.pif 2008-05-13 01:08:23 13044 --a------ C:\WINDOWS\scunin.dat 2008-05-13 01:08:22 94208 --a------ C:\WINDOWS\ScUnin.exe <Not Verified; Blizzard Entertainment; Starcraft Uninstaller> 2008-05-13 00:04:28 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2008-05-13 00:04:22 0 d-------- C:\Program Files\SUPERAntiSpyware 2008-05-13 00:04:22 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\SUPERAntiSpyware.com 2008-05-13 00:03:17 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-05-12 13:44:31 0 d-------- C:\Program Files\Trend Micro 2008-05-11 03:00:39 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2 2008-05-10 22:31:14 0 d-------- C:\WINDOWS\Prefetch 2008-05-10 22:23:07 0 d-------- C:\WINDOWS\system32\scripting 2008-05-10 22:23:06 0 d-------- C:\WINDOWS\l2schemas 2008-05-10 22:23:05 0 d-------- C:\WINDOWS\system32\en 2008-05-10 22:23:05 0 d-------- C:\WINDOWS\system32\bits 2008-05-10 22:20:45 0 d-------- C:\WINDOWS\ServicePackFiles 2008-05-10 22:14:06 0 d-------- C:\WINDOWS\EHome 2008-05-10 20:35:34 0 d-------- C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware 2008-05-10 20:35:28 0 d-------- C:\Program Files\ParetoLogic 2008-05-10 20:35:27 0 d-------- C:\Program Files\Common Files\ParetoLogic 2008-05-10 00:34:03 0 d-------- C:\ie-spyad_zo 2008-05-09 23:01:05 0 d-------- C:\Program Files\Panda Security 2008-05-09 23:01:04 0 --a------ C:\WINDOWS\mozver.dat 2008-05-09 21:40:02 0 d-------- C:\kav 2008-05-09 20:30:24 0 d-------- C:\Program Files\Common Files\Blizzard Entertainment -- Find3M Report --------------------------------------------------------------- 2008-05-14 22:57:41 0 d-------- C:\Program Files\Common Files\Symantec Shared 2008-05-14 22:50:32 0 d-------- C:\Program Files\Common Files 2008-05-13 23:20:22 0 d-------- C:\Program Files\Starcraft 2008-05-13 01:00:59 0 d-------- C:\Program Files\PokerStars 2008-05-12 15:03:13 0 d-------- C:\Program Files\Recovery for Works 2008-05-12 13:23:00 0 d-------- C:\Program Files\Microsoft Works 2008-05-10 22:30:35 0 d-------- C:\Program Files\Messenger 2008-05-10 22:23:04 0 d-------- C:\Program Files\Movie Maker 2008-05-10 22:20:32 0 d-------- C:\Program Files\Windows NT 2008-02-29 23:50:37 2557 --a------ C:\WINDOWS\unins000.dat 2008-02-29 23:46:00 691545 --a------ C:\WINDOWS\unins000.exe -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [05/07/1998 05:04 PM] "KBD"="C:\HP\KBD\KBD.EXE" [02/11/2003 09:02 PM] "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [04/14/2004 09:43 PM] "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [08/20/2004 05:51 PM] "AGRSMMSG"="AGRSMMSG.exe" [03/04/2005 01:01 PM C:\WINDOWS\AGRSMMSG.exe] "PS2"="C:\WINDOWS\system32\ps2.exe" [09/12/2003 09:13 PM] "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [03/08/2006 12:08 AM] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [12/21/2005 01:54 PM] "BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [09/10/2002 10:26 PM] "Motive SmartBridge"="C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [12/10/2003 05:52 AM] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [12/15/2005 12:18 PM] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [11/03/2006 07:20 PM] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [10/10/2007 08:51 PM] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [01/25/2007 12:06 AM] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [04/13/2008 06:12 PM] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/13/2008 06:12 PM] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 12:43 PM] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [02/29/2008 04:03 PM] [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce] "RunNarrator"=Narrator.exe C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Compaq Connections.lnk - C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe [8/9/2004 2:59:58 AM] HP Digital Imaging Monitor.lnk.disabled [5/22/2006 1:49:26 PM] SBC Self Support Tool.lnk.disabled [4/10/2006 11:48:35 PM] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"=0 (0x0) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{51C55F9E-C308-4c95-89AB-8858D8AFD819}"= C:\Program Files\ParetoLogic\Anti-Spyware\PASShlExt.dll [05/06/2008 03:16 PM 98304] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "System"="kdvsn.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy] C:\WINDOWS\System32\dimsntfy.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] @="Volume shadow copy" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background "Yahoo! Pager"=1 "MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe "IgfxTray"=C:\WINDOWS\system32\igfxtray.exe "AlcxMonitor"=ALCXMNTR.EXE "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe "RealTray"=C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER "UserFaultCheck"=%systemroot%\system32\dumprep 0 -u [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] eapsvcs eaphost dot3svc dot3svc HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs napagent hkmsvc *Newly Created Service* - SASDIFSV -- End of Deckard's System Scanner: finished at 2008-05-14 23:00:13 ------------ |
|
|
|
May 16 2008, 08:31 AM
Post
#15
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 15,582 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
Please download ComboFix and save it to your desktop.
Prior to running Combofix.exe you should disable your antivirus program and disconnect from the internet. Double click combofix.exe and follow the prompts. When it's done running it will produce a log for you. Please post that log in your next reply. Important Note - Do not mouseclick combofix's window whilst it's running. That may cause it to stall. -------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it! ======================================================== |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 21st November 2009 - 03:10 AM |