Hi Jimmy 2012:
Here are your reports
SDFix Log
SDFix: Version 1.218 Run by judith on Fri 08/22/2008 at 07:59 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Restoring Default ScreenSaver value
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\system32\lphce9lj0e7c1.exe - Deleted
C:\WINDOWS\system32\blphce9lj0e7c1.scr - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt1.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt100.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt102.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt104.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt106.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt108.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt10A.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt10C.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt10E.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt11.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt110.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt112.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt114.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt116.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt118.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt11A.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt11C.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt120.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt122.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt124.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt126.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt128.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt12A.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt12C.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt12E.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt13.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt130.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt132.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt134.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt136.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt138.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt13A.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt13C.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt13E.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt140.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt142.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt144.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt146.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt148.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt14A.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt15.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt152.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt154.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt156.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt158.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt15A.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt15C.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt15E.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt160.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt162.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt164.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt166.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt167.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt169.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt16B.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt16D.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt16F.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt17.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt171.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt173.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt175.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt177.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt179.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt17B.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt17D.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt17F.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt181.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt183.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt185.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt187.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt189.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt18B.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt18C.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt18D.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt18F.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt19.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt190.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt192.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt194.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt196.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt198.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt19A.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt19F.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt1A1.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt1A3.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt1B.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt1D.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt1F.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt2.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt21.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt23.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt25.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt27.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt29.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt2B.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt2D.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt2F.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt3.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt31.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt33.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt35.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt37.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt39.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt3B.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt3D.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt3F.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt4.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt41.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt43.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt45.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt47.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt48.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt4A.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt4C.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt4E.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt5.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt50.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt52.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt54.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt56.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt58.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt5A.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt5C.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt5E.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt60.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt62.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt64.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt66.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt68.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt6A.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt6C.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt6E.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt7.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt70.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt72.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt74.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt76.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt78.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt7A.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt7C.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt7E.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt8.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt80.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt82.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt84.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt89.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt8B.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt8D.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt91.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt93.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt95.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt97.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt99.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt9B.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttA.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttA3.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttA6.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttB0.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttB2.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttB4.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttB6.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttB8.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttBA.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttBC.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttBE.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttC.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttC0.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttC2.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttC4.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttC6.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttC8.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttCA.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttCC.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttCE.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttD0.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttD2.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttD4.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttD6.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttD8.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttDA.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttDC.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttDE.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttE.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttE0.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttE2.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttE4.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttE6.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttE8.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttEA.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttEC.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttEE.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttF0.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttF2.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttF4.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttF6.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttF8.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttFA.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttFC.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.ttFE.tmp - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt1.tmp.vbs - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt2.tmp.vbs - Deleted
C:\DOCUME~1\judith\LOCALS~1\Temp\.tt4.tmp.vbs - Deleted
C:\WINDOWS\system32\wpx5.cpx - Deleted
C:\WINDOWS\iexplorer.exe - Deleted
C:\WINDOWS\wiaservb.log - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-22 20:08:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Sony Handheld\\HOTSYNC.EXE"="C:\\Program Files\\Sony Handheld\\HOTSYNC.EXE:*:Enabled:HotSyncr Manager Application"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Mon 26 Nov 2007 31 A..H. --- "C:\WINDOWS\uccspecc.sys"
Fri 15 Dec 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Finished!HijackThis Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:21:52 PM, on 8/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\crypserv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Citrix\GoToMyPC\g2svc.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Citrix\GoToMyPC\g2comm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Citrix\GoToMyPC\g2pre.exe
C:\Program Files\Citrix\GoToMyPC\g2tray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\devldr32.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.bulletpro...ware-98743.htmlR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [GoToMyPC] C:\Program Files\Citrix\GoToMyPC\g2svc.exe -logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://download.mac...ash/swflash.cabO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: GoToMyPC - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToMyPC\g2svc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
--
End of file - 6054 bytes
OTViewIt Log
OTViewIt logfile created on: 8/22/2008 8:17:01 PM
OTViewIt by OldTimer - Version 1.0.0.5 Folder = C:\Documents and Settings\judith\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
255.30 Mb Total Physical Memory | 126.28 Mb Available Physical Memory | 49.46% Memory free
1002.06 Mb Paging File | 761.98 Mb Available in Paging File | 76.04% Paging File free
Paging file location(s): C:\pagefile.sys 768 768;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9.54 Gb Total Space | 4.26 Gb Free Space | 44.67% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 74.53 Gb Total Space | 65.60 Gb Free Space | 88.02% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME-8CN6I20DL4
Current User Name: judith
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
===== Processes - Non-Microsoft Only =====
[01/15/2008 03:40 AM | 0,011,0592 | ---- | M] (Apple, Inc.) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[07/24/2007 04:17 PM | 0,022,9376 | ---- | M] (Apple Inc.) - C:\Program Files\Bonjour\mDNSResponder.exe
[02/28/2006 09:10 PM | 0,006,9632 | ---- | M] (CrypKey (Canada) Ltd.) - C:\WINDOWS\system32\Crypserv.exe
[10/07/2003 12:10 PM | 0,003,2768 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
[01/06/2004 11:47 AM | 0,032,7792 | ---- | M] (Executive Software International, Inc.) - C:\Program Files\Executive Software\Diskeeper\DkService.exe
[01/12/2007 06:45 PM | 0,024,9904 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) - C:\Program Files\Citrix\GoToMyPC\g2svc.exe
[10/07/2003 12:35 PM | 0,064,7168 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
[01/12/2007 06:45 PM | 0,059,0384 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) - C:\Program Files\Citrix\GoToMyPC\g2comm.exe
[01/12/2007 06:45 PM | 0,025,1440 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) - C:\Program Files\Citrix\GoToMyPC\g2pre.exe
[01/12/2007 06:45 PM | 0,089,7584 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) - C:\Program Files\Citrix\GoToMyPC\g2tray.exe
[10/07/2003 12:39 PM | 0,009,0112 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\VPTray.exe
[08/17/2001 06:36 PM | 0,002,4064 | ---- | M] (Creative Technology Ltd.) - C:\WINDOWS\system32\devldr32.exe
[05/10/2005 04:04 PM | 0,010,2400 | ---- | M] (Musicmatch, Inc.) - C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
[06/10/2008 04:27 AM | 0,014,4784 | ---- | M] (Sun Microsystems, Inc.) - C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[05/10/2005 04:04 PM | 0,040,3456 | ---- | M] (Musicmatch, Inc.) - C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
[10/24/2003 12:37 AM | 0,021,7194 | ---- | M] (Adobe Systems Inc.) - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
[08/09/2002 04:36 PM | 0,029,9008 | ---- | M] (Palm, Inc.) - C:\Program Files\Sony Handheld\HOTSYNC.EXE
[08/22/2008 08:16 PM | 0,139,7248 | ---- | M] (OldTimer Tools) - C:\Documents and Settings\judith\Desktop\OTViewIt.exe
===== Win32 Services - Non-Microsoft Only =====
(Apple Mobile Device) Apple Mobile Device [Auto | Running]
[01/15/2008 03:40 AM | 0,011,0592 | ---- | M] (Apple, Inc.) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
(Bonjour Service) Bonjour Service [Auto | Running]
[07/24/2007 04:17 PM | 0,022,9376 | ---- | M] (Apple Inc.) - C:\Program Files\Bonjour\mDNSResponder.exe
(Crypkey License) Crypkey License [Auto | Running]
[02/28/2006 09:10 PM | 0,006,9632 | ---- | M] (CrypKey (Canada) Ltd.) - C:\WINDOWS\system32\Crypserv.exe
(DefWatch) DefWatch [Auto | Running]
[10/07/2003 12:10 PM | 0,003,2768 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
(Diskeeper) Diskeeper [Auto | Running]
[01/06/2004 11:47 AM | 0,032,7792 | ---- | M] (Executive Software International, Inc.) - C:\Program Files\Executive Software\Diskeeper\DkService.exe
(dmadmin) Logical Disk Manager Administrative Service [On_Demand | Stopped]
[08/04/2004 12:56 AM | 0,022,4768 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\dmadmin.exe
(GoToMyPC) GoToMyPC [Auto | Running]
[01/12/2007 06:45 PM | 0,024,9904 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) - C:\Program Files\Citrix\GoToMyPC\g2svc.exe
(iPod Service) iPod Service [On_Demand | Stopped]
[02/04/2008 03:18 PM | 0,050,4104 | ---- | M] (Apple Inc.) - C:\Program Files\iPod\bin\iPodService.exe
(Norton AntiVirus Server) Symantec AntiVirus Client [Auto | Running]
[10/07/2003 12:35 PM | 0,064,7168 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
(sdAuxService) PC Tools Auxiliary Service [On_Demand | Stopped]
[06/25/2008 07:47 PM | 0,033,7800 | ---- | M] (PC Tools) - C:\Program Files\Spyware Doctor\pctsAuxs.exe
(sdCoreService) PC Tools Security Service [On_Demand | Stopped]
[06/25/2008 07:47 PM | 0,101,7224 | ---- | M] (PC Tools) - C:\Program Files\Spyware Doctor\pctsSvc.exe
===== Driver Services - Non-Microsoft Only =====
(74840a61) 74840a61 [System | Stopped]
[08/22/2008 07:32 AM | 0,000,0000 | ---- | M] () - C:\WINDOWS\system32\drivers\74840a61.sys
(AN983) ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter [On_Demand | Running]
[08/28/2002 06:59 PM | 0,003,6224 | ---- | M] (ADMtek Incorporated.) - C:\WINDOWS\system32\drivers\an983.sys
(ati2mtaa) ati2mtaa [On_Demand | Running]
[08/03/2004 10:29 PM | 0,032,7040 | ---- | M] (ATI Technologies Inc.) - C:\WINDOWS\system32\drivers\ati2mtaa.sys
(BrScnUsb) Brother USB Still Image driver [On_Demand | Stopped]
[10/15/2004 01:50 PM | 0,001,5295 | ---- | M] (Brother Industries Ltd.) - C:\WINDOWS\system32\drivers\BrScnUsb.sys
(BrSerIf) Brother MFC Serial Port Interface WDM Driver [On_Demand | Stopped]
[09/29/2004 04:24 AM | 0,005,1712 | ---- | M] (Brother Industries Ltd.) - C:\WINDOWS\system32\drivers\BrSerIf.sys
(BrUsbSer) Brother MFC USB Serial WDM Driver [On_Demand | Stopped]
[01/10/2004 05:28 AM | 0,001,1648 | ---- | M] (Brother Industries Ltd.) - C:\WINDOWS\system32\drivers\BrUsbSer.sys
(catchme) catchme [On_Demand | Running]
File not found - C:\DOCUME~1\judith\LOCALS~1\Temp\catchme.sys
(ctljystk) Creative SBLive! Gameport [On_Demand | Running]
[08/17/2001 08:19 AM | 0,000,3712 | ---- | M] (Creative Technology Ltd.) - C:\WINDOWS\system32\drivers\ctljystk.sys
(dmboot) dmboot [Disabled | Stopped]
[08/03/2004 11:07 PM | 0,079,9744 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\drivers\dmboot.sys
(dmio) Logical Disk Manager Driver [Boot | Running]
[08/03/2004 11:07 PM | 0,015,3344 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\drivers\dmio.sys
(dmload) dmload [Boot | Running]
[08/18/2001 08:00 AM | 0,000,5888 | ---- | M] (Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\drivers\dmload.sys
(emu10k) Creative SB Live! (WDM) [On_Demand | Running]
[08/17/2001 08:19 AM | 0,028,3904 | ---- | M] (Creative Technology Ltd.) - C:\WINDOWS\system32\drivers\emu10k1m.sys
(emu10k1) Creative Interface Manager Driver (WDM) [On_Demand | Running]
[08/17/2001 08:19 AM | 0,000,6912 | ---- | M] (Creative Technology Ltd.) - C:\WINDOWS\system32\drivers\ctlfacem.sys
(GEARAspiWDM) GEARAspiWDM [On_Demand | Running]
[09/19/2006 03:44 PM | 0,001,5664 | ---- | M] (GEAR Software Inc.) - C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
(HCF_MSFT) HCF_MSFT [On_Demand | Running]
[08/17/2001 09:28 AM | 0,090,7456 | ---- | M] (Conexant) - C:\WINDOWS\system32\drivers\HCF_MSFT.sys
(IKFileSec) File Security Driver [On_Demand | Stopped]
[02/01/2008 01:55 PM | 0,004,2376 | ---- | M] (PCTools Research Pty Ltd.) - C:\WINDOWS\system32\drivers\ikfilesec.sys
(IKSysFlt) System Filter Driver [On_Demand | Stopped]
[12/10/2007 03:53 PM | 0,006,6952 | ---- | M] (PCTools Research Pty Ltd.) - C:\WINDOWS\system32\drivers\iksysflt.sys
(IKSysSec) System Security Driver [On_Demand | Stopped]
[12/10/2007 03:53 PM | 0,008,1288 | ---- | M] (PCTools Research Pty Ltd.) - C:\WINDOWS\system32\drivers\iksyssec.sys
(NAVAP) NAVAP [On_Demand | Running]
[08/11/2003 05:39 AM | 0,022,4768 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navap.sys
(NAVAPEL) NAVAPEL [Auto | Running]
[08/11/2003 05:39 AM | 0,003,0208 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navapel.sys
(NAVENG) NAVENG [On_Demand | Running]
[08/15/2008 04:00 AM | 0,008,9936 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080815.007\NAVENG.SYS
(NAVEX15) NAVEX15 [On_Demand | Running]
[08/15/2008 04:00 AM | 0,085,6336 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080815.007\NAVEX15.SYS
(ndiscm) Motorola SurfBoard USB Cable Modem Windows 2000 Driver [On_Demand | Stopped]
[05/13/2002 08:43 PM | 0,001,5399 | R--- | M] (Motorola Inc.) - C:\WINDOWS\system32\drivers\netmotcm.sys
(NetworkX) NetworkX [System | Running]
[01/09/2006 10:47 PM | 0,003,1846 | ---- | M] () - C:\WINDOWS\system32\Ckldrv.sys
(PalmUSBD) PalmUSBD [On_Demand | Stopped]
[07/29/2003 09:11 PM | 0,001,6772 | R--- | M] (Palm, Inc.) - C:\WINDOWS\system32\drivers\PalmUSBD.sys
(Ptilink) Direct Parallel Link Driver [On_Demand | Running]
[08/18/2001 08:00 AM | 0,001,7792 | ---- | M] (Parallel Technologies, Inc.) - C:\WINDOWS\system32\drivers\ptilink.sys
(PxHelp20) PxHelp20 [Boot | Running]
[08/29/2005 08:12 PM | 0,002,0576 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\drivers\PxHelp20.sys
(Secdrv) Secdrv [On_Demand | Stopped]
[03/25/2002 08:02 PM | 0,002,7440 | ---- | M] () - C:\WINDOWS\system32\drivers\secdrv.sys
(sfman) Creative SoundFont Manager Driver (WDM) [On_Demand | Running]
[08/17/2001 08:19 AM | 0,003,6480 | ---- | M] (Creative Technology Ltd.) - C:\WINDOWS\system32\drivers\sfmanm.sys
(SymEvent) SymEvent [On_Demand | Running]
[08/13/2005 01:35 PM | 0,007,3496 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec\SYMEVENT.SYS
(USBAAPL) Apple Mobile USB Driver [On_Demand | Stopped]
[01/15/2008 03:39 AM | 0,003,0464 | ---- | M] (Apple, Inc.) - C:\WINDOWS\system32\drivers\usbaapl.sys
===== Run Keys =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoToMyPC" = C:\Program Files\Citrix\GoToMyPC\g2svc.exe -logon [01/12/2007 06:45 PM | 0,024,9904 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.)
"MimBoot" = C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe [05/10/2005 04:04 PM | 0,001,1776 | ---- | M] (Musicmatch, Inc.)
"NeroCheck" = C:\WINDOWS\system32\\NeroCheck.exe [07/09/2001 06:50 AM | 0,015,5648 | ---- | M] (Ahead Software Gmbh)
"QuickTime Task" = "C:\Program Files\QuickTime\qttask.exe" -atboottime [02/01/2008 12:13 AM | 0,038,5024 | ---- | M] (Apple Inc.)
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM | 0,014,4784 | ---- | M] (Sun Microsystems, Inc.)
"vptray" = C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe [10/07/2003 12:39 PM | 0,009,0112 | ---- | M] (Symantec Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed" = 1
"NoChange" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed" = 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
===== Startup Folders =====
[All Users Startup Folder - C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
[10/24/2003 12:37 AM | 0,021,7194 | ---- | M] (Adobe Systems Inc.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
[10/25/2003 03:44 AM | 0,072,4992 | ---- | M] (Intuit, Inc.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
[judith Startup Folder - C:\Documents and Settings\judith\Start Menu\Programs\Startup]
[08/09/2002 04:36 PM | 0,029,9008 | ---- | M] (Palm, Inc.) - C:\Documents and Settings\judith\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
[11/05/2005 01:59 PM | 0,025,6000 | ---- | M] () - C:\Documents and Settings\judith\Start Menu\Programs\Startup\PowerReg SchedulerV2.exe
===== BHO's =====
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
HKLM CLSID: (AcroIEHlprObj Class) - [11/03/2003 06:17 PM | 0,005,4248 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
HKLM CLSID: (SSVHelper Class) - [06/10/2008 04:27 AM | 0,050,9328 | ---- | M] (Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
HKLM CLSID: (AcroIEToolbarHelper Class) - [05/15/2003 02:03 AM | 0,014,7456 | ---- | M] () C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
===== Toolbars =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"
HKLM CLSID: (Adobe PDF) - [05/15/2003 02:03 AM | 0,014,7456 | ---- | M] () C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"
HKLM CLSID: (Adobe PDF) - [05/15/2003 02:03 AM | 0,014,7456 | ---- | M] () C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"
HKLM CLSID: (Adobe PDF) - [05/15/2003 02:03 AM | 0,014,7456 | ---- | M] () C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
HKLM CLSID: (Yahoo! Toolbar) - File not found Reg Error: Key does not exist or could not be opened.
===== Policies =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveAutoRun" = 67108863
"NoDriveTypeAutoRun" = 255
"NoDrives" = 0
"NoCDBurning" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum]
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}" = 1
"{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}" = 1073741857
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}" = 32
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername" = 0
"legalnoticecaption" =
"legalnoticetext" =
"shutdownwithoutlogon" = 1
"undockwithoutlogon" = 1
"HideLegacyLogonScripts" = 0
"HideLogoffScripts" = 0
"RunLogonScriptSync" = 1
"RunStartupScriptSync" = 0
"HideStartupScripts" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
"NoDriveAutoRun" = -1
"NoDrives" = 0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"HideLegacyLogonScripts" = 0
"HideLogoffScripts" = 0
"RunLogonScriptSync" = 1
"RunStartupScriptSync" = 0
"HideStartupScripts" = 0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate]
===== Desktop Components =====
===== Shared Task Scheduler =====
===== AppInit_Dlls =====
===== Lsa Authentication Packages =====
===== Lsa Security Packages =====
===== Authorized Applications List =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe [08/04/2004 12:56 AM | 0,014,0800 | ---- | M] (Microsoft Corporation)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe [08/01/2006 04:35 PM | 0,006,7112 | ---- | M] (America Online, Inc.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe [08/04/2004 12:56 AM | 0,014,0800 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe [11/30/2006 10:49 PM | 0,009,1640 | ---- | M] (Yahoo! Inc.)
"C:\Program Files\Sony Handheld\HOTSYNC.EXE" = C:\Program Files\Sony Handheld\HOTSYNC.EXE [08/09/2002 04:36 PM | 0,029,9008 | ---- | M] (Palm, Inc.)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe [08/01/2006 04:35 PM | 0,006,7112 | ---- | M] (America Online, Inc.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe [10/10/2006 01:53 PM | 0,001,0800 | ---- | M] (AOL LLC)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [11/30/2006 10:49 PM | 0,466,2776 | ---- | M] (Yahoo! Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe [07/24/2007 04:17 PM | 0,022,9376 | ---- | M] (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe [02/04/2008 03:18 PM | 1,992,6824 | ---- | M] (Apple Inc.)
===== HKLM Winlogon Settings =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
"Explorer.exe" - [08/04/2004 12:56 AM | 0,103,2192 | ---- | M] (Microsoft Corporation) C:\WINDOWS\explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit]
"C:\WINDOWS\system32\userinit.exe" - [08/04/2004 12:56 AM | 0,002,4576 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost]
"logonui.exe" - [08/04/2004 12:56 AM | 0,051,4560 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\logonui.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet]
"rundll32 shell32" - [02/28/2005 07:11 PM | 0,845,0048 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
"Control_RunDLL "sysdm.cpl"" - [08/04/2004 12:56 AM | 0,029,8496 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
===== User's Winlogon Settings =====
===== Winlogon Notify Settings =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToMyPC]
"DllName" = C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll [01/12/2007 06:45 PM | 0,001,0800 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
"DllName" = C:\WINDOWS\system32\NavLogon.dll [10/07/2003 12:30 PM | 0,004,5056 | ---- | M] ()
===== Safeboot Options =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell" = cmd.exe
===== Disabled MsConfig Items =====
Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\ not found. -> ->
===== DNS Name Servers =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{0C75E08F-6F89-47AB-B223-9027025E1B88}]
Servers: | Description: Linksys LNE100TX Fast Ethernet Adapter(LNE100TX v4)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{8B4328B1-B837-4F86-B6FE-6A610558BD59}]
Servers: | Description: Motorola SURFboard SB5121 USB Cable Modem
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{BAC3583F-E605-4F09-8FFE-E35C1737F98C}]
Servers: | Description: Motorola SurfBoard 4200 USB Cable Modem
[Files/Folders - Created Within 30 days]
[08/13/2005 01:24 PM | 0,000,0211 | ---- | M] () - C:\Boot.bak
[07/29/2008 08:02 PM | ---D | C] - C:\cmdcons
[08/03/2004 11:00 PM | 0,026,0272 | ---- | M] () - C:\cmldr
[08/22/2008 08:04 PM | 2,677,67808 | -HS- | M] () - C:\hiberfil.sys
[08/03/2008 09:31 AM | -HSD | C] - C:\RECYCLER
[08/22/2008 08:10 PM | ---D | C] - C:\SDFix
[08/22/2008 07:32 AM | 0,000,0000 | ---- | M] () - C:\WINDOWS\System32\drivers\74840a61.sys
[01/09/2006 10:47 PM | 0,003,1846 | ---- | M] () - C:\WINDOWS\System32\Ckldrv.sys
[02/28/2006 09:10 PM | 0,006,9632 | ---- | M] (CrypKey (Canada) Ltd.) - C:\WINDOWS\System32\Crypserv.exe
[08/16/2008 06:20 AM | 0,000,1680 | ---- | M] () - C:\WINDOWS\System32\esnecil.ind
[08/15/2008 11:22 PM | 0,000,1680 | ---- | M] () - C:\WINDOWS\System32\esnecil.nlp
[06/10/2008 01:21 AM | 0,013,5168 | ---- | M] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\java.exe
[06/10/2008 02:32 AM | 0,007,3728 | ---- | M] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javacpl.cpl
[06/10/2008 01:21 AM | 0,013,5168 | ---- | M] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaw.exe
[06/10/2008 02:32 AM | 0,013,9264 | ---- | M] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaws.exe
[08/22/2008 07:44 PM | 0,062,5208 | ---- | M] () - C:\WINDOWS\System32\phce9lj0e7c1.bmp
[08/20/2008 09:02 PM | 0,001,4336 | ---- | M] () - C:\WINDOWS\System32\winaux.drv
[06/18/1999 05:49 PM | 0,016,5888 | ---- | M] (Kenonic Controls) - C:\WINDOWS\Ckconfig.exe
[07/04/1995 02:33 PM | 0,001,1776 | ---- | M] () - C:\WINDOWS\Ckrfresh.exe
[08/15/2008 11:21 PM | 0,000,0071 | ---- | M] () - C:\WINDOWS\Crypkey.ini
[08/22/2008 07:56 PM | ---D | C] - C:\WINDOWS\ERUNT
[3 C:\WINDOWS\*.tmp files]
[08/16/2008 09:30 AM | -H-D | C] - C:\WINDOWS\PIF
[08/17/2008 01:58 PM | 0,000,1409 | ---- | M] () - C:\WINDOWS\QTFont.for
[08/17/2008 01:58 PM | 0,005,4156 | -H-- | M] () - C:\WINDOWS\QTFont.qfn
[05/03/1996 11:36 AM | 0,001,8432 | ---- | M] () - C:\WINDOWS\Setup_ck.dll
[05/03/1996 01:21 PM | 0,002,7648 | R--- | M] () - C:\WINDOWS\Setup_ck.exe
[08/15/2008 11:22 PM | 0,000,0004 | ---- | M] () - C:\WINDOWS\vx86036.dat
[08/17/2008 09:11 AM | 0,000,0545 | ---- | M] () - C:\Documents and Settings\judith\Desktop\EPSON Smart Panel.lnk
[08/21/2008 07:40 PM | 0,000,1734 | ---- | M] () - C:\Documents and Settings\judith\Desktop\HijackThis.lnk
[08/22/2008 08:16 PM | 0,139,7248 | ---- | M] (OldTimer Tools) - C:\Documents and Settings\judith\Desktop\OTViewIt.exe
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\OTViewIt.exe:Zone.Identifier
[08/22/2008 07:38 PM | 0,146,3521 | ---- | M] () - C:\Documents and Settings\judith\Desktop\SDFix.exe
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\SDFix.exe:Zone.Identifier
[08/14/2008 10:08 PM | ---D | C] - C:\Program Files\Common Files\Java
[08/20/2008 09:02 PM | ---D | C] - C:\Program Files\Microsoft Common
[08/21/2008 07:40 PM | ---D | C] - C:\Program Files\Trend Micro
[Files/Folders - Modified Within 30 days]
[07/29/2008 08:02 PM | 0,000,0281 | RHS- | M] () - C:\boot.ini
[07/29/2008 08:02 PM | ---D | M] - C:\cmdcons
[08/22/2008 08:04 PM | 2,677,67808 | -HS- | M] () - C:\hiberfil.sys
[08/21/2008 07:40 PM | ---D | M] - C:\Program Files
[08/03/2008 09:31 AM | -HSD | M] - C:\RECYCLER
[08/22/2008 08:10 PM | ---D | M] - C:\SDFix
[08/22/2008 07:45 PM | -HSD | M] - C:\System Volume Information
[08/22/2008 08:03 PM | ---D | M] - C:\WINDOWS
[08/22/2008 07:32 AM | 0,000,0000 | ---- | M] () - C:\WINDOWS\System32\drivers\74840a61.sys
[08/22/2008 08:00 PM | ---D | M] - C:\WINDOWS\System32\drivers\etc
[08/22/2008 08:00 PM | 0,000,0686 | ---- | M] () - C:\WINDOWS\System32\drivers\etc\HOSTS
[08/22/2008 01:04 AM | ---D | M] - C:\WINDOWS\System32\CatRoot2
[1 C:\WINDOWS\System32\*.tmp files]
[08/22/2008 07:58 PM | RHSD | M] - C:\WINDOWS\System32\dllcache
[08/22/2008 01:04 AM | ---D | M] - C:\WINDOWS\System32\drivers
[08/16/2008 06:20 AM | 0,000,1680 | ---- | M] () - C:\WINDOWS\System32\esnecil.ind
[08/15/2008 11:22 PM | 0,000,1680 | ---- | M] () - C:\WINDOWS\System32\esnecil.nlp
[08/16/2008 06:31 AM | ---D | M] - C:\WINDOWS\System32\NtmsData
[08/22/2008 07:44 PM | 0,062,5208 | ---- | M] () - C:\WINDOWS\System32\phce9lj0e7c1.bmp
[08/22/2008 07:45 PM | ---D | M] - C:\WINDOWS\System32\Restore
[08/20/2008 09:02 PM | 0,001,4336 | ---- | M] () - C:\WINDOWS\System32\winaux.drv
[08/22/2008 07:33 AM | 0,000,2262 | ---- | M] () - C:\WINDOWS\System32\wpa.dbl
[08/01/2008 09:56 AM | ---D | M] - C:\WINDOWS\AppPatch
[3 C:\WINDOWS\*.tmp files]
[08/15/2008 11:21 PM | 0,000,0071 | ---- | M] () - C:\WINDOWS\Crypkey.ini
[08/01/2008 06:25 PM | --SD | M] - C:\WINDOWS\Downloaded Program Files
[08/22/2008 07:56 PM | ---D | M] - C:\WINDOWS\ERUNT
[08/01/2008 06:25 PM | -H-D | M] - C:\WINDOWS\inf
[08/14/2008 10:09 PM | -HSD | M] - C:\WINDOWS\Installer
[08/16/2008 09:30 AM | -H-D | M] - C:\WINDOWS\PIF
[08/22/2008 08:10 PM | ---D | M] - C:\WINDOWS\Prefetch
[08/17/2008 01:58 PM | 0,000,1409 | ---- | M] () - C:\WINDOWS\QTFont.for
[08/17/2008 01:58 PM | 0,005,4156 | -H-- | M] () - C:\WINDOWS\QTFont.qfn
[08/01/2008 09:57 AM | 0,000,0227 | ---- | M] () - C:\WINDOWS\system.ini
[08/22/2008 08:03 PM | ---D | M] - C:\WINDOWS\system32
[08/22/2008 08:12 PM | ---D | M] - C:\WINDOWS\TEMP
[08/15/2008 11:22 PM | 0,000,0004 | ---- | M] () - C:\WINDOWS\vx86036.dat
[08/22/2008 08:07 PM | 0,000,0690 | ---- | M] () - C:\WINDOWS\win.ini
[08/21/2008 02:15 PM | 0,000,0284 | ---- | M] () - C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[08/22/2008 08:05 PM | 0,000,0006 | -H-- | M] () - C:\WINDOWS\tasks\SA.DAT
[08/15/2008 11:16 PM | --SD | M] - C:\Documents and Settings\All Users\Application Data\Microsoft
[08/17/2008 10:18 PM | ---D | M] - C:\Documents and Settings\All Users\Application Data\TEMP
@Alternate Data Stream - 143 bytes -> %AllUsersProfile%\Application Data\TEMP:DFC5A2B2
[08/15/2008 07:43 PM | 0,639,1568 | -H-- | M] () - C:\Documents and Settings\judith\Local Settings\Application Data\IconCache.db
[08/15/2008 11:16 PM | ---D | M] - C:\Documents and Settings\judith\Local Settings\Application Data\Microsoft
[08/22/2008 07:40 PM | ---D | M] - C:\Documents and Settings\judith\Local Settings\Application Data\SMASHER
[08/17/2008 09:11 AM | 0,000,0545 | ---- | M] () - C:\Documents and Settings\judith\Desktop\EPSON Smart Panel.lnk
[08/21/2008 07:40 PM | 0,000,1734 | ---- | M] () - C:\Documents and Settings\judith\Desktop\HijackThis.lnk
[08/21/2008 09:11 AM | 0,000,2521 | ---- | M] () - C:\Documents and Settings\judith\Desktop\Microsoft Office Outlook 2003.lnk
[08/22/2008 08:16 PM | 0,139,7248 | ---- | M] (OldTimer Tools) - C:\Documents and Settings\judith\Desktop\OTViewIt.exe
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\OTViewIt.exe:Zone.Identifier
[08/22/2008 07:38 PM | 0,146,3521 | ---- | M] () - C:\Documents and Settings\judith\Desktop\SDFix.exe
@Alternate Data Stream - 26 bytes -> %UserProf