One thing I failed to mention at the beginning was I did try deleting the usp10hlp.dll but it always repopulated itself.
KAPERSKY REPORT:
KASPERSKY ONLINE SCANNER 7.0 REPORT
Friday, July 3, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Friday, July 03, 2009 21:29:36
Records in database: 2422099
Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes
Scan area My Computer
C:\
D:\
Scan statistics
Files scanned 194922
Threat name 4
Infected objects 42
Suspicious objects 8
Duration of the scan 03:35:36
File name Threat name Threats count
C:\WINDOWS\system32\usp10up.dll/C:\WINDOWS\system32\usp10up.dll Infected: Trojan-Downloader.Win32.Agent.cgui 31
C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{B1373666-81B2-4C18-9E4D-1E6C37297039}\Microsoft\Outlook Express\Inbox.dbx Infected: Trojan-Spy.HTML.Pcard.c 1
C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{B1373666-81B2-4C18-9E4D-1E6C37297039}\Microsoft\Outlook Express\lms1.clarkson.edu - Inbox.dbx Infected: Virus.MSWord.Class.d 1
C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{B1373666-81B2-4C18-9E4D-1E6C37297039}\Microsoft\Outlook Express\lms1.clarkson.edu - Inbox.dbx Infected: Trojan-Spy.HTML.Pcard.c 1
C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{B1373666-81B2-4C18-9E4D-1E6C37297039}\Microsoft\Outlook Express\lms1.clarkson.edu - Sent Items.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 2
C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{B1373666-81B2-4C18-9E4D-1E6C37297039}\Microsoft\Outlook Express\Sent Items.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 2
C:\Documents and Settings\Administrator\My Documents\bugga_mail\bugga_mail\Inbox Infected: Trojan-Spy.HTML.Pcard.c 1
C:\Documents and Settings\Administrator\My Documents\bugga_mail\bugga_mail\Sent Suspicious: Trojan-Spy.HTML.Fraud.gen 2
C:\Documents and Settings\Administrator\My Documents\bugga_mail.tar.gz Suspicious: Trojan-Spy.HTML.Fraud.gen 2
C:\Documents and Settings\Administrator\My Documents\bugga_mail.tar.gz Infected: Virus.MSWord.Class.d 1
C:\Documents and Settings\Administrator\My Documents\bugga_mail.tar.gz Infected: Trojan-Spy.HTML.Pcard.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D3C0000.VBN Infected: Virus.MSWord.Class.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D3C0000.VBN Infected: Trojan-Spy.HTML.Pcard.c 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\14D80001.VBN Infected: Virus.MSWord.Class.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\14D80001.VBN Infected: Trojan-Spy.HTML.Pcard.c 1
C:\WINDOWS\system32\usp10up.dll Infected: Trojan-Downloader.Win32.Agent.cgui 1
The selected area was scanned.
OTL.TXT
OTL logfile created on: 7/3/2009 11:46:55 PM - Run 1
OTL by OldTimer - Version 3.0.6.4 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.98 Gb Total Physical Memory | 0.76 Gb Available Physical Memory | 38.27% Memory free
3.83 Gb Paging File | 2.23 Gb Available in Paging File | 58.14% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.15 Gb Total Space | 54.02 Gb Free Space | 57.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: IBM-07C4C807FC1
Current User Name: chianese
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2008/03/31 20:00:00 | 00,036,640 | ---- | M] (Lenovo) -- C:\WINDOWS\System32\ibmpmsvc.exe
PRC - [2007/11/19 10:40:08 | 01,183,744 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2006/07/19 15:26:12 | 00,169,632 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PRC - [2006/07/19 15:26:06 | 00,192,160 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PRC - [2006/07/19 15:26:10 | 00,202,400 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
PRC - [2006/09/27 10:14:44 | 00,087,728 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
PRC - [2006/08/07 12:03:02 | 00,214,720 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
PRC - [2006/04/11 13:13:38 | 01,160,848 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
PRC - [2007/11/02 00:09:34 | 00,032,768 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\Drivers\trcboot.exe
PRC - [2007/11/02 00:09:34 | 00,036,864 | ---- | M] (IBM Corporation) -- C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE
PRC - [2007/07/05 11:05:04 | 00,065,536 | ---- | M] (Lenovo ) -- C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
PRC - [2009/06/05 11:48:14 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/12/12 12:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/04/07 12:22:26 | 00,038,688 | ---- | M] (International Business Machines Corporation) -- C:\Program Files\IBM\SQLLIB\BIN\db2mgmtsvc.exe
PRC - [2008/07/08 10:53:21 | 00,053,248 | ---- | M] () -- C:\Program Files\IBM\tivoli\dcd\client\ISSI\cds\CDSWinSrv.exe
PRC - [2006/09/27 16:33:22 | 00,031,472 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
PRC - [2007/11/19 11:00:38 | 00,794,624 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2004/08/04 01:00:00 | 00,388,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\cmd.exe
PRC - [2009/06/11 11:06:28 | 00,433,392 | ---- | M] (IBM Corp.) -- C:\Program Files\c4ebreg\c4ebreg.exe
PRC - [2009/06/01 09:40:00 | 00,242,928 | ---- | M] (IBM Corp.) -- c:\sdwork\issimsvc.exe
PRC - [2009/07/03 19:01:36 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2005/08/15 01:40:28 | 00,053,248 | ---- | M] (IBM Corp) -- C:\notes\ntmulti.exe
PRC - [2007/01/13 04:00:00 | 00,323,584 | ---- | M] (AT&T) -- C:\Program Files\AT&T Network Client\NetCfgSv.EXE
PRC - [2008/03/20 20:00:00 | 00,155,716 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe
PRC - [2006/11/24 05:29:56 | 00,043,752 | ---- | M] (IBM) -- C:\Program Files\IBM\tivoli\dcd\client\ISSI\_jvm\jre\bin\java.exe
PRC - [2007/11/19 10:35:46 | 00,483,328 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2006/09/27 16:33:38 | 00,116,464 | ---- | M] (symantec) -- c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
PRC - [2006/09/27 16:33:32 | 01,813,232 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
PRC - [2006/09/27 10:15:56 | 00,173,744 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
PRC - [2008/05/14 12:21:16 | 00,037,416 | ---- | M] (Lenovo.) -- C:\WINDOWS\System32\TPHDEXLG.exe
PRC - [2006/06/29 17:57:50 | 00,032,768 | ---- | M] () -- C:\WINDOWS\System32\TpKmpSVC.exe
PRC - [2005/01/28 14:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe
PRC - [2008/07/29 04:43:00 | 00,094,208 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
PRC - [2007/07/05 11:03:32 | 00,184,320 | ---- | M] (Lenovo ) -- C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
PRC - [2007/11/02 00:09:34 | 00,028,672 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\Drivers\ldlcserv.exe
PRC - [2007/11/02 00:09:34 | 00,040,960 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\Drivers\ldlcserv6.exe
PRC - [2007/07/05 11:04:18 | 00,114,688 | ---- | M] (Lenovo ) -- C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
PRC - [2004/08/04 01:00:00 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wscntfy.exe
PRC - [2007/06/13 06:23:07 | 01,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2004/08/04 01:00:00 | 00,455,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE
PRC - [2006/07/19 15:26:04 | 00,052,896 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2006/09/27 16:33:44 | 00,125,168 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec Client Security\Symantec AntiVirus\VPTray.exe
PRC - [2007/11/02 00:09:34 | 00,028,672 | ---- | M] () -- C:\Program Files\IBM\Personal Communications\tpam.exe
PRC - [2007/04/08 20:00:00 | 01,015,808 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
PRC - [2007/07/05 10:58:40 | 00,413,696 | ---- | M] (Lenovo ) -- C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
PRC - [2007/07/05 10:51:48 | 00,126,976 | ---- | M] (Lenovo ) -- C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
PRC - [2008/06/06 14:21:04 | 00,181,536 | ---- | M] (Lenovo.) -- C:\WINDOWS\System32\TpShocks.exe
PRC - [2007/08/10 14:30:40 | 00,110,592 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2007/08/10 14:30:12 | 00,512,000 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2008/07/31 07:01:00 | 00,060,192 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe
PRC - [2008/03/24 06:15:04 | 00,068,464 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
PRC - [2009/03/13 05:00:40 | 00,184,371 | ---- | M] () -- C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.4.19\pmonmh.exe
PRC - [2004/11/15 21:05:00 | 00,127,035 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfswctrl.exe
PRC - [2009/06/11 11:06:53 | 00,281,840 | ---- | M] (IBM Corp.) -- C:\Program Files\c4ebreg\isamtray.exe
PRC - [2009/06/05 13:39:22 | 00,292,136 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/07/03 19:01:36 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008/11/17 18:49:13 | 00,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/03/24 10:41:22 | 00,067,432 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
PRC - [2008/04/25 12:38:34 | 00,128,368 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Zoom\TpScrex.exe
PRC - [2008/05/28 19:23:02 | 00,596,584 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
PRC - [2008/03/17 18:44:22 | 03,874,816 | ---- | M] (World Community Grid) -- C:\Program Files\BOINC\boincmgr.exe
PRC - [2008/05/28 19:23:02 | 01,448,576 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\BTStackServer.exe
PRC - [2008/03/17 18:38:28 | 00,430,080 | ---- | M] (World Community Grid) -- C:\Program Files\BOINC\boinc.exe
PRC - [2007/11/19 10:42:48 | 00,659,456 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2004/08/04 01:00:00 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2009/06/05 13:39:14 | 00,541,992 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2008/10/15 03:06:26 | 00,633,632 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009/07/03 19:01:36 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\java.exe
PRC - [2009/07/03 19:11:23 | 00,139,264 | ---- | M] (Kaspersky Lab.) -- C:\Documents and Settings\Administrator\Local Settings\Temp\jkos-chianese\binaries\ScanningProcess.exe
PRC - [2009/07/03 19:11:23 | 00,139,264 | ---- | M] (Kaspersky Lab.) -- C:\Documents and Settings\Administrator\Local Settings\Temp\jkos-chianese\binaries\ScanningProcess.exe
PRC - [2009/06/28 15:45:08 | 00,045,091 | ---- | M] (The Pidgin developer community) -- C:\Program Files\Pidgin\pidgin.exe
PRC - [2008/10/15 03:06:26 | 00,633,632 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009/07/03 19:01:36 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\java.exe
PRC - [2004/08/04 01:00:00 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2009/07/03 23:46:37 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - [2007/07/05 11:05:04 | 00,065,536 | ---- | M] (Lenovo ) -- C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe -- (AcPrfMgrSvc [Auto | Running])
SRV - [2007/07/05 11:03:32 | 00,184,320 | ---- | M] (Lenovo ) -- C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe -- (AcSvc [Auto | Running])
SRV - [2009/06/05 11:48:14 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2007/11/02 00:09:34 | 00,032,768 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\Drivers\appnnode.exe -- (AppnNode [On_Demand | Stopped])
SRV - [2007/10/23 21:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008/12/12 12:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/05/28 19:23:00 | 00,342,624 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe -- (btwdins [On_Demand | Stopped])
SRV - [2006/07/19 15:26:06 | 00,192,160 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr [Auto | Running])
SRV - [2006/07/19 15:26:10 | 00,202,400 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccProxy.exe -- (ccProxy [Auto | Running])
SRV - [2006/07/19 15:26:12 | 00,169,632 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr [Auto | Running])
SRV - [2007/10/23 21:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2007/11/02 00:09:34 | 00,049,152 | ---- | M] (IBM Corporation) -- C:\Program Files\IBM\Personal Communications\csrcmds.exe -- (csrcmds [On_Demand | Stopped])
SRV - [2007/11/02 00:09:34 | 00,036,864 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\cstrcser.exe -- (cstrcser [On_Demand | Stopped])
SRV - [2008/04/07 12:22:26 | 00,038,688 | ---- | M] (International Business Machines Corporation) -- C:\Program Files\IBM\SQLLIB\BIN\db2mgmtsvc.exe -- (DB2MGMTSVC_DB2COPY1 [Auto | Running])
SRV - [2008/07/08 10:53:21 | 00,053,248 | ---- | M] () -- C:\Program Files\IBM\tivoli\dcd\client\ISSI\cds\CDSWinSrv.exe -- (DCDClient-ISSI [Auto | Running])
SRV - [2006/09/27 16:33:22 | 00,031,472 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe -- (DefWatch [Auto | Running])
SRV - [2007/11/19 11:00:38 | 00,794,624 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng [Auto | Running])
SRV - [2007/10/09 08:58:12 | 00,036,864 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/11/17 18:49:12 | 00,137,200 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2004/08/04 01:00:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2008/03/31 20:00:00 | 00,036,640 | ---- | M] (Lenovo) -- C:\WINDOWS\System32\ibmpmsvc.exe -- (IBMPMSVC [Auto | Running])
SRV - [2005/11/13 21:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2007/10/11 05:55:10 | 00,864,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2009/06/05 13:39:14 | 00,541,992 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - File not found -- -- (ISAMsmt [Auto | Stopped])
SRV - [2009/06/11 11:06:28 | 00,433,392 | ---- | M] (IBM Corp.) -- C:\Program Files\c4ebreg\c4ebreg.exe -- (ISAMSvc [Auto | Running])
SRV - [2009/06/01 09:40:00 | 00,242,928 | ---- | M] (IBM Corp.) -- c:\sdwork\issimsvc.exe -- (ISSIMon [Auto | Running])
SRV - [2006/09/27 10:14:44 | 00,087,728 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe -- (ISSVC [Auto | Running])
SRV - [2009/07/03 19:01:36 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2007/11/02 00:09:34 | 00,028,672 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\Drivers\ldlcserv.exe -- (ldlcserv [Auto | Running])
SRV - [2007/11/02 00:09:34 | 00,040,960 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\Drivers\ldlcserv6.exe -- (ldlcserv6 [Auto | Running])
SRV - [2006/08/25 08:00:38 | 02,528,960 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE -- (LiveUpdate [On_Demand | Stopped])
SRV - [2005/08/15 01:40:28 | 00,053,248 | ---- | M] (IBM Corp) -- C:\notes\ntmulti.exe -- (Multi-user Cleanup Service [Auto | Running])
SRV - [2007/01/13 04:00:00 | 00,323,584 | ---- | M] (AT&T) -- C:\Program Files\AT&T Network Client\NetCfgSv.EXE -- (NetCfgSvr [Auto | Running])
SRV - [2007/10/11 05:55:14 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/03/20 20:00:00 | 00,155,716 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2000/10/19 12:55:50 | 00,411,244 | ---- | M] () -- C:\oracle\ora81\BIN\ONRSD.EXE -- (OracleOraHome81ClientCache [On_Demand | Stopped])
SRV - [2003/07/28 07:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2008/07/29 04:43:00 | 00,094,208 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE -- (Power Manager DBC Service [Auto | Running])
SRV - [2007/11/19 10:35:46 | 00,483,328 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc [Auto | Running])
SRV - [2007/11/19 10:40:08 | 01,183,744 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor [Auto | Running])
SRV - [2006/09/27 16:33:38 | 00,116,464 | ---- | M] (symantec) -- c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe -- (SavRoam [Auto | Running])
SRV - [2006/08/07 12:03:02 | 00,214,720 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc [Auto | Running])
SRV - [2006/04/11 13:13:38 | 01,160,848 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc [Auto | Running])
SRV - [2006/09/27 16:33:32 | 01,813,232 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus [Auto | Running])
SRV - [2006/09/27 10:15:56 | 00,173,744 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe -- (SymSecurePort [Auto | Running])
SRV - [2008/05/14 12:21:16 | 00,037,416 | ---- | M] (Lenovo.) -- C:\WINDOWS\System32\TPHDEXLG.exe -- (TPHDEXLGSVC [Auto | Running])
SRV - [2006/06/29 17:57:50 | 00,032,768 | ---- | M] () -- C:\WINDOWS\System32\TpKmpSVC.exe -- (TpKmpSVC [Auto | Running])
SRV - [2007/11/02 00:09:34 | 00,032,768 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\Drivers\trcboot.exe -- (TrcBoot [Auto | Running])
SRV - [2005/01/28 14:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running])
========== Driver Services (SafeList) ==========
DRV - [2007/04/12 20:00:00 | 00,306,176 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\System32\drivers\ADIHdAud.sys -- (ADIHdAudAddService [On_Demand | Running])
DRV - [2007/03/22 20:00:00 | 00,094,848 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\System32\drivers\AEAudio.sys -- (AEAudio [On_Demand | Running])
DRV - [2008/11/02 23:41:56 | 00,021,361 | ---- | M] (Cisco Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\AegisP.sys -- (AegisP [Auto | Running])
DRV - [2006/05/19 05:46:14 | 00,180,864 | ---- | M] (AT&T) -- C:\WINDOWS\System32\DRIVERS\agnfilt.sys -- (agnfilt [On_Demand | Running])
DRV - [2004/04/29 13:19:18 | 00,019,328 | ---- | M] (AT&T) -- C:\WINDOWS\System32\DRIVERS\agnwifi.sys -- (agnwifi [Disabled | Stopped])
DRV - [2001/08/17 09:51:56 | 00,005,248 | ---- | M] (Acer Laboratories Inc.) -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde [Disabled | Stopped])
DRV - [2004/08/03 19:07:44 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp [Disabled | Stopped])
DRV - [2005/11/08 05:27:20 | 00,011,520 | ---- | M] (IBM Corp.) -- C:\WINDOWS\System32\drivers\ANC.SYS -- (ANC [System | Running])
DRV - [2007/11/02 00:09:34 | 00,038,280 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\anydlc.sys -- (Anydlc [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 01,315,392 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\appn.sys -- (Appn [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,120,256 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\appnapi.sys -- (AppnApi [Auto | Running])
DRV - [2007/11/02 00:09:34 | 00,208,896 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\AppnBase.sys -- (AppnBase [On_Demand | Running])
DRV - [2001/08/17 09:52:00 | 00,026,496 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc [Disabled | Stopped])
DRV - [2001/08/17 09:51:58 | 00,014,848 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550 [Disabled | Stopped])
DRV - [2005/05/16 20:00:00 | 00,015,872 | ---- | M] (Atmel, Inc.) -- C:\WINDOWS\System32\DRIVERS\atmeltpm.sys -- (atmeltpm [On_Demand | Running])
DRV - [2003/04/04 08:48:06 | 00,013,952 | ---- | M] (AT&T) -- C:\WINDOWS\System32\DRIVERS\avpnnic.sys -- (avpnnic [On_Demand | Stopped])
DRV - [2004/05/06 12:12:10 | 00,114,688 | R--- | M] (Broadcom Corporation) -- C:\WINDOWS\System32\DRIVERS\b57xp32.sys -- (b57w2k [On_Demand | Stopped])
DRV - [2008/06/09 15:55:00 | 00,991,144 | ---- | M] (Broadcom Corporation.) -- C:\WINDOWS\System32\DRIVERS\btkrnl.sys -- (BTKRNL [On_Demand | Running])
DRV - [2008/06/09 15:55:00 | 00,047,272 | ---- | M] (Broadcom Corporation.) -- C:\WINDOWS\System32\Drivers\btwusb.sys -- (BTWUSB [On_Demand | Running])
DRV - [2001/08/17 09:51:54 | 00,006,656 | ---- | M] (CMD Technology, Inc.) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde [Disabled | Stopped])
DRV - [2001/08/17 09:52:16 | 00,179,584 | ---- | M] (Mylex Corporation) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k [Disabled | Stopped])
DRV - [2004/11/30 23:22:00 | 00,087,488 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\drvmcdb.sys -- (drvmcdb [Boot | Running])
DRV - [2004/11/22 22:56:00 | 00,040,480 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\drvnddm.sys -- (drvnddm [Auto | Running])
DRV - [2007/10/11 20:00:00 | 00,252,048 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\DRIVERS\e1e5132.sys -- (e1express [On_Demand | Running])
DRV - [2009/02/25 05:00:00 | 00,371,248 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl [System | Running])
DRV - [2005/04/27 05:16:46 | 00,005,427 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\EGATHDRV.SYS -- (EGATHDRV [Auto | Running])
DRV - [2009/02/25 05:00:00 | 00,101,936 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv [On_Demand | Running])
DRV - [2009/03/19 16:32:48 | 00,023,400 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV - [2005/01/07 13:07:18 | 00,138,752 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2007/10/31 20:00:00 | 00,211,456 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys -- (HSFHWAZL [On_Demand | Running])
DRV - [2007/10/31 20:00:00 | 00,989,696 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys -- (HSF_DPV [On_Demand | Running])
DRV - [2007/02/11 20:00:00 | 00,277,784 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\Drivers\iaStor.sys -- (iastor [Boot | Running])
DRV - [2008/03/31 20:00:00 | 00,023,720 | ---- | M] (Lenovo.) -- C:\WINDOWS\System32\DRIVERS\ibmpmdrv.sys -- (IBMPMDRV [On_Demand | Running])
DRV - [2007/04/02 07:24:08 | 00,004,224 | ---- | M] () -- C:\WINDOWS\System32\Drivers\IBMBLDID.sys -- (IBMTPCHK [System | Running])
DRV - [2007/11/02 00:09:34 | 00,101,696 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\DRIVERS\llc2.sys -- (IBM_LLC2 [Auto | Running])
DRV - [2007/11/02 00:09:34 | 00,024,588 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\klognt.sys -- (KLOGNT [On_Demand | Running])
DRV - [2007/06/07 20:00:00 | 00,081,280 | ---- | M] (Lenovo) -- C:\WINDOWS\System32\Drivers\LenovoRd.sys -- (LenovoRd [On_Demand | Running])
DRV - [2006/06/18 20:00:00 | 00,012,672 | ---- | M] (Conexant) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys -- (mdmxsdk [Auto | Running])
DRV - [2001/08/17 09:52:12 | 00,017,280 | ---- | M] (American Megatrends Inc.) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x [Disabled | Stopped])
DRV - [2009/02/20 05:00:00 | 00,089,104 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090703.004\NAVENG.SYS -- (NAVENG [On_Demand | Running])
DRV - [2009/02/20 05:00:00 | 00,876,144 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090703.004\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running])
DRV - [2007/11/26 19:37:00 | 02,236,544 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\DRIVERS\NETw4x32.sys -- (NETw4x32 [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,012,028 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\nstrcnt.sys -- (NsTrcNT [Auto | Running])
DRV - [2008/03/20 20:00:00 | 06,547,936 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,075,200 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnacom.sys -- (pdlnacom [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,036,048 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnafac.sys -- (pdlnafac [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,020,480 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnatcm.sys -- (pdlnatcm [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,018,432 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnatdl.sys -- (pdlnatdl [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,006,784 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlncbas.sys -- (pdlncbas [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,160,288 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlncfwk.sys -- (pdlncfwk [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,012,288 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnctdl.sys -- (pdlnctdl [Auto | Running])
DRV - [2007/11/02 00:09:34 | 00,012,800 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlndint.sys -- (pdlndint [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,064,512 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlndldl.sys -- (pdlndldl [Auto | Running])
DRV - [2007/11/02 00:09:34 | 00,070,656 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlndldl6.sys -- (pdlndldl6 [Auto | Running])
DRV - [2007/11/02 00:09:34 | 00,070,144 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlndlpb.sys -- (pdlndlpb [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,018,944 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlndoem.sys -- (pdlndoem [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,053,248 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlndqll.sys -- (pdlndqll [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,067,072 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlndsdl.sys -- (pdlndsdl [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,051,712 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlndtdl.sys -- (pdlndtdl [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,008,608 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnebas.sys -- (pdlnebas [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,050,336 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnecfg.sys -- (pdlnecfg [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,067,184 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnemap.sys -- (pdlnemap [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,012,768 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnemsg.sys -- (pdlnemsg [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,019,984 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnepkt.sys -- (pdlnepkt [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,059,504 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnshay.sys -- (pdlnshay [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,022,384 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnslea.sys -- (pdlnslea [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,054,416 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnsv25.sys -- (pdlnsv25 [On_Demand | Running])
DRV - [2007/11/02 00:09:34 | 00,058,432 | ---- | M] (IBM Corporation) -- C:\WINDOWS\System32\drivers\pdlnsx25.sys -- (pdlnsx25 [On_Demand | Running])
DRV - [2003/09/18 21:47:00 | 00,010,368 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\System32\drivers\pfc.sys -- (Pfc [On_Demand | Running])
DRV - [2008/10/10 15:30:58 | 00,007,012 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\PMEMNT.SYS -- (PMEM [Auto | Running])
DRV - [2004/08/04 01:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2007/03/07 19:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2001/08/17 09:52:20 | 00,040,320 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080 [Disabled | Stopped])
DRV - [2001/08/17 09:52:20 | 00,045,312 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160 [Disabled | Stopped])
DRV - [2001/08/17 09:52:18 | 00,049,024 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280 [Disabled | Stopped])
DRV - [2008/02/15 20:00:00 | 00,046,592 | ---- | M] (REDC) -- C:\WINDOWS\System32\DRIVERS\rimmptsk.sys -- (rimmptsk [Auto | Running])
DRV - [2007/07/29 20:00:00 | 00,043,008 | ---- | M] (REDC) -- C:\WINDOWS\System32\DRIVERS\rimsptsk.sys -- (rimsptsk [Auto | Running])
DRV - [2007/03/11 20:00:00 | 00,027,904 | ---- | M] (REDC) -- C:\WINDOWS\system32\DRIVERS\risdptsk.sys -- (risdptsk [Boot | Running])
DRV - [2007/07/29 20:00:00 | 00,038,400 | ---- | M] (REDC) -- C:\WINDOWS\System32\DRIVERS\rixdptsk.sys -- (rismxdp [Auto | Running])
DRV - [2007/11/20 12:39:56 | 00,012,288 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\DRIVERS\s24trans.sys -- (s24trans [Auto | Running])
DRV - [2006/09/06 10:41:20 | 00,337,592 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec Client Security\Symantec AntiVirus\savrt.sys -- (SAVRT [System | Running])
DRV - [2006/09/06 10:41:20 | 00,054,968 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL [System | Running])
DRV - [2007/11/13 06:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2008/05/14 12:21:16 | 00,114,728 | ---- | M] (Lenovo.) -- C:\WINDOWS\System32\DRIVERS\Apsx86.sys -- (Shockprf [Boot | Running])
DRV - [2004/08/03 19:07:44 | 00,041,088 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp [Disabled | Stopped])
DRV - [2001/08/17 10:07:44 | 00,019,072 | ---- | M] (Adaptec, Inc.) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow [Disabled | Stopped])
DRV - [2006/04/11 13:13:34 | 00,389,776 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv [System | Running])
DRV - [2004/07/14 07:29:04 | 00,005,627 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\sscdbhk5.sys -- (sscdbhk5 [System | Running])
DRV - [2004/07/14 07:28:50 | 00,023,545 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\ssrtln.sys -- (ssrtln [System | Running])
DRV - [2001/08/17 10:07:34 | 00,016,256 | ---- | M] (Symbios Logic Inc.) -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810 [Disabled | Stopped])
DRV - [2001/08/17 10:07:36 | 00,032,640 | ---- | M] (LSI Logic) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx [Disabled | Stopped])
DRV - [2006/08/07 12:01:56 | 00,012,992 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\SYMDNS.SYS -- (SYMDNS [On_Demand | Running])
DRV - [2006/09/18 13:55:28 | 00,109,744 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent [On_Demand | Running])
DRV - [2006/08/07 12:02:02 | 00,110,784 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\SYMFW.SYS -- (SYMFW [On_Demand | Running])
DRV - [2006/08/07 12:02:18 | 00,031,936 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\SYMIDS.SYS -- (SYMIDS [On_Demand | Running])
DRV - [2009/04/20 22:44:14 | 00,251,768 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SymcData\scfidsdefs\20090625.001\SymIDSCo.sys -- (SYMIDSCO [On_Demand | Running])
DRV - [2006/08/07 12:02:14 | 00,028,352 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\SYMNDIS.SYS -- (SYMNDIS [On_Demand | Running])
DRV - [2006/08/07 12:02:22 | 00,024,768 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV [On_Demand | Running])
DRV - [2006/08/07 12:02:26 | 00,195,776 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI [System | Running])
DRV - [2001/08/17 10:07:40 | 00,028,384 | ---- | M] (LSI Logic) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi [Disabled | Stopped])
DRV - [2001/08/17 10:07:42 | 00,030,688 | ---- | M] (LSI Logic) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3 [Disabled | Stopped])
DRV - [2007/08/10 14:25:28 | 00,177,664 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\System32\DRIVERS\SynTP.sys -- (SynTP [On_Demand | Running])
DRV - [2004/11/15 21:05:00 | 00,025,883 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsnboio.sys -- (tfsnboio [Auto | Running])
DRV - [2004/11/15 21:05:00 | 00,034,843 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsncofs.sys -- (tfsncofs [Auto | Running])
DRV - [2004/11/15 21:05:00 | 00,004,123 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsndrct.sys -- (tfsndrct [Auto | Running])
DRV - [2004/11/15 21:05:00 | 00,002,239 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsndres.sys -- (tfsndres [Auto | Running])
DRV - [2004/11/15 21:05:00 | 00,086,554 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsnifs.sys -- (tfsnifs [Auto | Running])
DRV - [2004/11/15 21:05:00 | 00,015,227 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsnopio.sys -- (tfsnopio [Auto | Running])
DRV - [2004/11/15 21:05:00 | 00,006,363 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsnpool.sys -- (tfsnpool [Auto | Running])
DRV - [2004/11/15 21:05:00 | 00,098,714 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsnudf.sys -- (tfsnudf [Auto | Running])
DRV - [2004/11/15 21:05:00 | 00,100,603 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\dla\tfsnudfa.sys -- (tfsnudfa [Auto | Running])
DRV - [2008/05/14 12:21:16 | 00,019,496 | ---- | M] (Lenovo.) -- C:\WINDOWS\System32\DRIVERS\ApsHM86.sys -- (TPDIGIMN [Boot | Running])
DRV - [2008/05/12 18:14:16 | 00,017,844 | ---- | M] (Lenovo Group Limited) -- C:\WINDOWS\System32\DRIVERS\TPHKDRV.sys -- (TPHKDRV [System | Running])
DRV - [2008/07/29 04:43:00 | 00,004,442 | ---- | M] () -- C:\WINDOWS\System32\drivers\Tppwrif.sys -- (TPPWRIF [System | Running])
DRV - [2008/07/31 07:01:00 | 00,004,608 | ---- | M] () -- C:\WINDOWS\System32\drivers\TSMAPIP.SYS -- (TSMAPIP [System | Running])
DRV - [2001/08/17 09:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra [Disabled | Stopped])
DRV - [2007/10/31 20:00:00 | 00,731,520 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys -- (winachsf [On_Demand | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://w3.ibm.com
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://w3.ibm.com
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://w3.ibm.com
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://w3.ibm.com
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm...tf8&oe=utf8
IE - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\S-1-5-21-2517262794-1839522478-3631906055-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\S-1-5-21-2517262794-1839522478-3631906055-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/03 19:01:38 | 00,000,000 | ---D | M]
[2009/02/12 15:52:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\mozilla\eclipse\extensions
[2008/11/17 15:06:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\mozilla\eclipse1\extensions
[2009/07/03 19:06:49 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/07/03 19:01:50 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/07/03 19:01:37 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2008/10/14 22:33:30 | 00,095,600 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009/06/03 22:08:11 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/06/03 22:08:11 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/06/03 22:08:11 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/06/03 22:08:11 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/06/03 22:08:11 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/06/03 22:08:11 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/06/03 22:08:11 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
O1 HOSTS File: (307172 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10574 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\..\Toolbar\ShellBrowser: (&Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\..\Toolbar\WebBrowser: (&Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
O4 - HKLM..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BLOG] C:\Program Files\ThinkPad\Utilities\BATLOGEX.DLL ()
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.CPL (Microsoft Corporation)
O4 - HKLM..\Run: [C4EBReg] C:\Program Files\c4ebreg\c4ebreg.exe (IBM Corp.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [dla] C:\WINDOWS\System32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ISAM SMT Service] C:\Program Files\C4ebreg\isamsmt.exe File not found
O4 - HKLM..\Run: [ISAMTray] C:\Program Files\c4ebreg\isamtray.exe (IBM Corp.)
O4 - HKLM..\Run: [ISSI Service] c:\sdwork\issimsvc.exe (IBM Corp.)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MyHelpService] C:\Program Files\IBM\My Help\workspace\service\delayStart.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] File not found
O4 - HKLM..\Run: [pmonmh] C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.4.19\pmonmh.exe ()
O4 - HKLM..\Run: [PSQLLauncher] File not found
O4 - HKLM..\Run: [PWRMGRTR] C:\Program Files\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [stgclean] c:\sdwork\w32main2.exe (IBM Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Tpam.exe] C:\Program Files\IBM\Personal Communications\tpam.exe ()
O4 - HKLM..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe (Lenovo)
O4 - HKLM..\Run: [TpShocks] C:\WINDOWS\System32\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec Client Security\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKU\S-1-5-21-2517262794-1839522478-3631906055-500..\Run: [NetSP - restore settings on power failure] C:\Program Files\AT&T Network Client\NetSP.exe (AT&T)
O4 - HKU\S-1-5-21-2517262794-1839522478-3631906055-500..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\World Community Grid - BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe (World Community Grid)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Infoprint Select Notification.lnk = C:\Program Files\IBM\Infoprint Select\ipnotify.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe (Lotus Development Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 51 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-2517262794-1839522478-3631906055-500\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebook.com/controls/2008.1...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944}
http://www-307.ibm.com/pc/support/acpir.cab (IASRunner Class)
O16 - DPF: {3C648A72-C49A-48EF-9F90-68EF13293F97}
http://www.midhudsonmls.com/XMLSearch/XMLCache.CAB (Cacher Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/windowsupd...b?1189037145890 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu...b?1194968075000 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C}
http://w3.ibm.com/bluepages/scripts/lnwebassist.cab (LNWebAssist Class)
O16 - DPF: {A4B28810-11A2-4956-82D1-B2DCBA4B2AFD}
http://w3.ibm.com/tools/print/plugin/gpwsx.cab (gpwsx.plugin)
O16 - DPF: {CAFEEFAC-0013-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.3.0/jinstall-...indows-i586.cab (Java Plug-in 1.3.0)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://mathworks.webex.com/client/T26L/webex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ACNotify: DllName - ACNotify.dll - C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll (Lenovo )
O20 - Winlogon\Notify\atmgrtok: DllName - atmgrtok.dll - C:\Program Files\IBM\Personal Communications\atmgrtok.dll (IBM Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\System32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\pcsinst: DllName - pcsinst.dll - C:\WINDOWS\System32\pcsinst.dll (IBM Corporation)
O20 - Winlogon\Notify\tpfnf2: DllName - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - C:\Program Files\Lenovo\HOTKEY\tphklock.dll - C:\Program Files\Lenovo\HOTKEY\tphklock.dll (Lenovo Group Limited)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/04/04 13:44:20 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[5 C:\WINDOWS\*.tmp files]
[2009/07/03 23:46:32 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/07/03 23:35:32 | 00,006,936 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Kaspersky.html
[2009/07/03 19:01:48 | 00,148,888 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2009/07/03 19:01:48 | 00,144,792 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2009/07/03 19:01:48 | 00,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2009/07/03 18:56:00 | 00,045,148 | ---- | C] (Sun Microsystems) -- C:\WINDOWS\System32\plugincpl131_03.cpl
[2009/07/03 18:45:16 | 00,410,984 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
[2009/07/02 15:29:57 | 00,108,032 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\amat_product_groups_July2_2009.xls
[2009/07/02 15:12:00 | 00,020,992 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\INSOZSPR12SMD.1_2SMDI.xls
[2009/07/02 12:22:37 | 00,025,600 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\May_30_meeting_rev.doc
[2009/07/02 12:15:47 | 00,025,600 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\May_30_meeting.doc
[2009/07/01 19:53:10 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2009/06/30 15:17:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2009/06/30 15:17:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/06/30 14:05:26 | 00,000,000 | ---D | C] -- C:\rsit
[2009/06/30 10:46:22 | 00,018,432 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\KR_Aleris_06-30-09.xls
[2009/06/29 09:55:15 | 00,003,860 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\newhires_06-29-09.csv
[2009/06/26 17:02:27 | 00,156,483 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\IMG00077-20090626-1544.jpg
[2009/06/26 07:45:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/06/24 16:27:53 | 00,108,032 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\amat_product_groups_June24_2009.xls
[2009/06/24 11:56:21 | 00,020,480 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\KR_Aleris_DD.xls
[2009/06/24 01:07:12 | 00,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/06/24 01:06:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/06/24 00:14:22 | 00,000,415 | ---- | C] () -- C:\WINDOWS\System32\usp10hlp.dll
[2009/06/23 14:36:11 | 00,039,936 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\windows error.doc
[2009/06/22 10:33:01 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\wowhlp.dll
[2009/06/22 10:33:01 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\usp10up.dll
[2009/06/21 11:19:55 | 00,000,000 | ---D | C] -- C:\Program Files\Pidgin
[2009/06/19 16:17:15 | 00,107,520 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\amat_product_groups_June19_2009.xls
[2009/06/17 07:57:03 | 00,018,432 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\KR_Aleris JG 061709.xls
[2009/06/15 09:21:14 | 00,006,340 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\newhires_06-15-09.csv
[2009/06/14 10:58:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\amat csv
[2009/06/09 09:51:12 | 00,107,008 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\amat_product_groups_June9_2009.xls
[2009/01/06 15:37:18 | 00,048,640 | ---- | C] () -- C:\WINDOWS\System32\libfdnvin.dll
[2008/11/17 05:23:32 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.ini
[2008/11/03 20:39:36 | 00,000,185 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/11/03 01:52:52 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2008/11/03 01:52:52 | 00,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2008/11/03 01:52:52 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2008/11/03 01:52:52 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2008/11/03 01:52:52 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2008/11/03 01:52:52 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2008/11/02 23:45:35 | 00,004,608 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSMAPIP.SYS
[2008/11/02 23:44:16 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll
[2008/11/02 23:43:42 | 00,004,442 | ---- | C] () -- C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2008/11/02 23:42:13 | 00,004,224 | ---- | C] () -- C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2008/11/02 23:24:02 | 01,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/11/02 23:24:02 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/11/02 23:24:01 | 01,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/11/02 23:24:01 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/09/16 13:31:15 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/05/28 19:18:04 | 02,854,912 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2007/10/11 20:00:00 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006/07/17 16:30:20 | 00,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2006/01/23 20:55:44 | 00,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2006/01/19 14:34:53 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2005/04/27 05:53:10 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\pwdmon.dll
[2005/04/05 15:59:19 | 00,000,000 | ---- | C] () -- C:\WINDOWS\pcsmig.INI
[2005/04/05 15:45:55 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\pdresrc.dll
[2005/04/05 15:45:51 | 00,552,960 | ---- | C] () -- C:\WINDOWS\System32\pdclntif.dll
[2005/04/05 15:45:51 | 00,151,552 | ---- | C] () -- C:\WINDOWS\System32\pdprDlg.dll
[2005/04/05 15:45:51 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\selnt.dll
[2005/04/05 15:45:51 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\IBMMenu.dll
[2005/04/04 15:42:47 | 00,000,299 | RH-- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/02/17 08:41:32 | 00,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 08:41:30 | 00,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2004/08/04 01:00:00 | 00,000,573 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/04 01:00:00 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/04/08 01:00:00 | 00,222,928 | ---- | C] () -- C:\WINDOWS\System32\lobas09.dll
[2003/04/08 01:00:00 | 00,047,104 | ---- | C] () -- C:\WINDOWS\System32\lotrn13.dll
[2003/04/08 01:00:00 | 00,031,008 | ---- | C] () -- C:\WINDOWS\System32\ivtrn09.dll
[2003/04/08 01:00:00 | 00,014,928 | ---- | C] () -- C:\WINDOWS\System32\wingen.drv
[2003/04/08 01:00:00 | 00,000,462 | ---- | C] () -- C:\WINDOWS\lodbf13.ini
[2003/04/08 01:00:00 | 00,000,058 | ---- | C] () -- C:\WINDOWS\loss613.ini
[2003/04/08 01:00:00 | 00,000,058 | ---- | C] () -- C:\WINDOWS\loss09.ini
[2003/04/08 01:00:00 | 00,000,038 | ---- | C] () -- C:\WINDOWS\loidp13.ini
[2001/11/14 09:56:00 | 01,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[1999/07/30 09:24:34 | 00,000,218 | ---- | C] () -- C:\WINDOWS\oraodbc.ini
[1998/09/30 20:00:00 | 01,708,032 | ---- | C] () -- C:\WINDOWS\System32\MSO97V.DLL
[1997/06/17 20:00:00 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1997/06/17 20:00:00 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/07/03 23:46:37 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/07/03 23:35:32 | 00,006,936 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Kaspersky.html
[2009/07/03 22:00:58 | 00,002,271 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AT&T Network Client.lnk
[2009/07/03 20:23:15 | 00,513,678 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/03 20:23:15 | 00,435,906 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/07/03 20:23:15 | 00,069,478 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/07/03 19:05:07 | 00,000,316 | ---- | M] () -- C:\WINDOWS\tasks\PMTask.job
[2009/07/03 19:04:57 | 00,152,804 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2009/07/03 19:04:56 | 00,026,296 | ---- | M] () -- C:\WINDOWS\System32\nvwsapps.xml
[2009/07/03 19:04:35 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/07/03 19:03:47 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/07/03 19:03:27 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/07/03 19:03:15 | 00,250,776 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/07/03 19:02:28 | 00,000,040 | ---- | M] () -- C:\WINDOWS\System32\profile.dat
[2009/07/03 19:01:36 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
[2009/07/03 19:01:36 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2009/07/03 19:01:36 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2009/07/03 19:01:36 | 00,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2009/07/03 19:01:36 | 00,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2009/07/03 07:40:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/07/02 16:38:02 | 00,152,804 | ---- | M] () -- C:\WINDOWS\System32\nvModes.dat
[2009/07/02 16:23:02 | 00,011,935 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\amat_families.csv
[2009/07/02 15:36:20 | 00,108,032 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\amat_product_groups_July2_2009.xls
[2009/07/02 15:12:00 | 00,020,992 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\INSOZSPR12SMD.1_2SMDI.xls
[2009/07/02 12:28:41 | 00,025,600 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\May_30_meeting_rev.doc
[2009/07/02 12:15:47 | 00,025,600 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\May_30_meeting.doc
[2009/07/01 01:07:42 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/06/30 11:11:13 | 00,018,432 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\KR_Aleris_06-30-09.xls
[2009/06/30 10:45:12 | 00,018,432 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\KR_Aleris JG 061709.xls
[2009/06/29 12:37:22 | 00,003,860 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\newhires_06-29-09.csv
[2009/06/26 17:02:31 | 00,156,483 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\IMG00077-20090626-1544.jpg
[2009/06/25 16:08:57 | 00,020,480 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\KR_Aleris_DD.xls
[2009/06/25 11:49:11 | 00,001,784 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Default.rdp
[2009/06/24 22:01:28 | 00,039,936 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\windows error.doc
[2009/06/24 16:34:40 | 00,108,032 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\amat_product_groups_June24_2009.xls
[2009/06/24 10:18:41 | 00,307,172 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/06/24 00:15:32 | 00,000,415 | ---- | M] () -- C:\WINDOWS\System32\usp10hlp.dll
[2009/06/22 10:33:33 | 00,040,960 | ---- | M] () -- C:\WINDOWS\System32\wowhlp.dll
[2009/06/22 10:33:33 | 00,036,864 | ---- | M] () -- C:\WINDOWS\System32\usp10up.dll
[2009/06/19 16:17:15 | 00,107,520 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\amat_product_groups_June19_2009.xls
[2009/06/15 09:21:17 | 00,006,340 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\newhires_06-15-09.csv
[2009/06/11 11:06:57 | 00,064,752 | ---- | M] (IBM Corp.) -- C:\WINDOWS\isamunin.exe
[2009/06/09 09:53:30 | 00,107,008 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\amat_product_groups_June9_2009.xls
< End of report >
EXTRAS.TXT
OTL Extras logfile created on: 7/3/2009 11:46:55 PM - Run 1
OTL by OldTimer - Version 3.0.6.4 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.98 Gb Total Physical Memory | 0.76 Gb Available Physical Memory | 38.27% Memory free
3.83 Gb Paging File | 2.23 Gb Available in Paging File | 58.14% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.15 Gb Total Space | 54.02 Gb Free Space | 57.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: IBM-07C4C807FC1
Current User Name: chianese
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"IBMconfig" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2006/10/10 08:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2006/10/10 08:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/12/12 12:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
[2009/06/05 13:39:18 | 14,073,640 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0698CECB-9072-47B1-AEA1-94CA350989B8}" = Symantec Client Security
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio DigitalMedia Data
"{113EECD6-9A04-11D4-811D-00805F923B86}" = Lotus NotesSQL 3.01 driver
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = IBM DLA
"{12B6A13C-C888-4585-9BFF-59CFDD791DFA}" = Catalyst 1.3.2
"{17CBC505-D1AE-459D-B445-3D2000A85842}" = ThinkPad UltraNav Utility
"{19C69A2F-D71E-408F-81E5-808889FCA92D}" = IBM Rational Portfolio Manager
"{2111B23F-7FDA-4A41-8309-E5A1663CA296}" = ThinkPad Keyboard Customizer Utility
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java 6 Update 14
"{2BA00471-0328-3743-93BD-FA813353A783}" = Microsoft .NET Framework 3.0 Service Pack 1
"{2E21CBDA-1EDF-4C18-A561-DB53D683229F}" = AT&T Network Client
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{46A84694-59EC-48F0-964C-7E76E9F8A2ED}" = ThinkVantage Active Protection System
"{536D6172-7453-7569-7465-392E38300409}" = Lotus SmartSuite - English
"{53A93780-6073-4207-A729-A99A30AFDE40}" = AFP Workbench for Windows
"{5D601655-6D54-4384-B52C-17EC5385FBBD}" = iTunes
"{628789DC-75F8-4302-A268-27EF628E6906}" = Lotus Notes 7.0
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{65103278-85b6-498f-a9f0-e21a39103491}" = IBM Lotus Symphony
"{65706020-7B6F-41F2-8047-FC69579E386A}" = Presentation Director
"{6838B7DB-B935-4D2E-BE99-2078978194F8}" = IBM Data Server Client - DB2COPY1
"{6928A265-9EED-4F8A-8016-483A4668016A}" = IBM Infoprint Select
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7D968F83-A23F-40F7-937C-A3B5A0C44048}" = My Help - Workstation Setup Wizard
"{7EB114D8-207F-45AE-BABD-1669715F2630}" = ThinkVantage Access Connections
"{7F87DF1C-6B8F-49F4-8EEF-7600128D99AE}" = IBM Tivoli Storage Manager Client
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110246513}" = Catan - The Computer Game
"{8355F970-601D-442D-A79B-1D7DB4F24CAD}" = Apple Mobile Device Support
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = ThinkPad Bluetooth with Enhanced Data Rate Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{90840409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Excel Viewer 2003
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{95120000-0052-0409-0000-0000000FF1CE}" = Microsoft Office Visio Viewer 2007
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{97257926-3443-4DB5-93CF-2B3ADAD581CC}" = World Community Grid - BOINC Agent
"{A0E64EBA-8BF0-49FB-90C0-BB3D781A2016}" = ThinkPad Power Manager
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A2EF91BA-068C-4F6D-B6ED-52D1D272ED8F}" = IBM Lotus Sametime Connect 8.0.2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio DigitalMedia Audio
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.6
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio DigitalMedia Copy
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B6EC7388-E277-4A5B-8C8F-71067A41BA64}" = TextPad 5
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{DFF415AC-3883-4338-9365-DDCB74A0CFBA}" = IBM My Help
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EC6AF20D-4376-4070-BEE4-D3A0DFF7E140}" = Access IBM
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F7ED29C4-8FC6-48CF-BEF4-6ADE3E0165CF}" = IBM Personal Communications
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"ActiveTouchMeetingClient" = WebEx
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_10140588" = ThinkPad Modem
"FastStone Image Viewer" = FastStone Image Viewer 3.7
"fe29d7d6aaf324b1964e31be6d7ce1981815068445" = IBM Dynamic Content Delivery (DCDClient-ISSI)
"FileZilla Client" = FileZilla Client 3.2.4.1
"GTK 2.0" = GTK+ Runtime 2.14.7 rev a (remove only)
"IBM Ayudame" = IBM Ayudame
"IBM Installation Manager" = IBM Installation Manager
"IBM Printer Software Uninstall" = IBM Printer Software Uninstall
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"IM-IBM WebSphere Integration Developer" = IBM WebSphere Integration Developer
"LiveUpdate" = LiveUpdate 3.1 (Symantec Corporation)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OnScreenDisplay" = On Screen Display
"P2P GUI" = IBM ISMA Peer-To-Peer
"Pidgin" = Pidgin
"Power Management Driver" = ThinkPad Power Management Driver
"ProInst" = Intel® PROSet/Wireless Software
"PROSet" = Intel® PRO Network Connections Drivers
"Slay_is1" = Slay 5.0
"Snapshot Viewer" = Snapshot Viewer
"SynTPDeinstKey" = ThinkPad UltraNav Driver
"TclPro 1.4.1" = TclPro 1.4.1
"ThinkPad FullScreen Magnifier" = ThinkPad FullScreen Magnifier
"VLC media player" = VLC media player 0.9.8a
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format Runtime
"Workstation Security Tool_is1" = Workstation Security Tool 2.4
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/23/2009 4:14:28 PM | Computer Name = IBM-07C4C807FC1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 4/23/2009 4:14:28 PM | Computer Name = IBM-07C4C807FC1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 4/23/2009 4:14:28 PM | Computer Name = IBM-07C4C807FC1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 4/23/2009 4:14:28 PM | Computer Name = IBM-07C4C807FC1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 12175 (0x2f8f)
Error - 4/23/2009 4:14:28 PM | Computer Name = IBM-07C4C807FC1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 4/23/2009 4:14:28 PM | Computer Name = IBM-07C4C807FC1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 4/23/2009 4:14:28 PM | Computer Name = IBM-07C4C807FC1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 12175 (0x2f8f)
Error - 4/23/2009 4:14:28 PM | Computer Name = IBM-07C4C807FC1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 4/23/2009 4:14:28 PM | Computer Name = IBM-07C4C807FC1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 4/23/2009 4:14:28 PM | Computer Name = IBM-07C4C807FC1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 12175 (0x2f8f)
[ System Events ]
Error - 7/2/2009 8:36:54 AM | Computer Name = IBM-07C4C807FC1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 7/2/2009 8:37:17 AM | Computer Name = IBM-07C4C807FC1 | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 00215C8325EF. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 7/2/2009 9:46:00 AM | Computer Name = IBM-07C4C807FC1 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.101 for the Network Card with network
address 00215C8325EF has been denied by the DHCP server 9.61.5.140 (The DHCP Server
sent a DHCPNACK message).
Error - 7/2/2009 11:08:00 AM | Computer Name = IBM-07C4C807FC1 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Schedule service.
Error - 7/2/2009 11:08:00 AM | Computer Name = IBM-07C4C807FC1 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the SENS service.
Error - 7/2/2009 11:08:00 AM | Computer Name = IBM-07C4C807FC1 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the W32Time service.
Error - 7/2/2009 11:08:00 AM | Computer Name = IBM-07C4C807FC1 | Source = Dhcp | ID = 1002
Description = The IP address lease 9.62.105.112 for the Network Card with network
address 00215C8325EF has been denied by the DHCP server 9.61.5.140 (The DHCP Server
sent a DHCPNACK message).
Error - 7/2/2009 11:04:51 PM | Computer Name = IBM-07C4C807FC1 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.5.126 for the Network Card with network
address 00215C8325EF has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).
Error - 7/3/2009 9:01:13 AM | Computer Name = IBM-07C4C807FC1 | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 00215C8325EF. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 7/3/2009 2:15:44 PM | Computer Name = IBM-07C4C807FC1 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.101 for the Network Card with network
address 00215C8325EF has been denied by the DHCP server 192.168.5.1 (The DHCP Server
sent a DHCPNACK message).
< End of report >