OTViewIt logfile created on: 8/26/2008 8:59:18 AM - Run 2
OTViewIt by OldTimer - Version 1.0.0.12 Folder = C:\Documents and Settings\copeterson\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.14 Gb Available Physical Memory | 57.23% Memory free
3.35 Gb Paging File | 2.45 Gb Available in Paging File | 73.31% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.30 Gb Total Space | 2.33 Gb Free Space | 7.96% Space Free | Partition Type: NTFS
Drive D: | 45.15 Gb Total Space | 41.49 Gb Free Space | 91.88% Space Free | Partition Type: NTFS
Drive E: | 388.19 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: D9CRS2C1
Current User Name: copeterson
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
===== Processes - Non-Microsoft Only =====
[12/18/2007 07:03 PM | 02,569,600 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
[11/09/2007 03:15 PM | 00,108,392 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
[11/01/2006 09:48 PM | 00,020,480 | ---- | M] () - C:\WINDOWS\system32\WLTRYSVC.EXE
[11/01/2006 09:48 PM | 01,253,376 | ---- | M] (Dell Inc.) - C:\WINDOWS\system32\BCMWLTRY.EXE
[04/04/2005 06:58 PM | 00,163,840 | ---- | M] (Adobe Systems Incorporated) - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
[08/07/2008 06:40 PM | 00,079,360 | ---- | M] (Autodesk) - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
[03/25/2006 05:24 PM | 00,315,392 | ---- | M] (Wave Systems Corp.) - C:\Program Files\Wave Systems Corp\common\DataServer.exe
[03/10/2008 12:04 AM | 00,065,536 | ---- | M] () - C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe
[04/06/2006 02:57 PM | 00,380,928 | ---- | M] (Dell Inc.) - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
[01/19/2006 08:14 AM | 00,143,428 | ---- | M] (NVIDIA Corporation) - C:\WINDOWS\system32\nvsvc32.exe
[03/01/2006 03:37 PM | 00,031,232 | ---- | M] () - C:\WINDOWS\system32\rpcnet.exe
[12/18/2007 09:08 PM | 02,189,240 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
[04/04/2005 06:58 PM | 03,502,080 | ---- | M] () - C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
[11/30/2005 01:33 PM | 00,180,224 | ---- | M] () - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.7\bin\tcsd_win32.exe
[12/18/2007 07:03 PM | 01,643,904 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
[07/02/2008 01:26 PM | 00,353,672 | ---- | M] (Webroot Software Inc (www.webroot.com)) - C:\Program Files\Webroot\Webroot Desktop Firewall\wdfsvc.exe
[01/04/2008 08:56 PM | 03,572,592 | ---- | M] (Webroot Software, Inc.) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
[10/07/2005 12:13 PM | 00,176,128 | R--- | M] (Alps Electric Co., Ltd.) - C:\Program Files\Apoint\Apoint.exe
[06/28/2004 09:56 PM | 00,045,056 | R--- | M] (Alps Electric Co., Ltd.) - C:\Program Files\Apoint\hidfind.exe
[07/27/2005 02:41 PM | 00,045,056 | R--- | M] (Alps Electric Co., Ltd.) - C:\Program Files\Apoint\ApntEx.exe
[06/10/2008 04:27 AM | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) - C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[11/01/2006 09:48 PM | 01,392,640 | ---- | M] (Dell Inc.) - C:\WINDOWS\system32\WLTRAY.EXE
[03/24/2006 04:30 PM | 00,282,624 | ---- | M] (SigmaTel, Inc.) - C:\WINDOWS\stsystra.exe
[03/09/2006 12:26 PM | 00,098,304 | ---- | M] (Wave Systems Corp.) - C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
[12/09/2005 08:29 PM | 00,049,152 | ---- | M] (CyberLink Corp.) - C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[04/06/2006 02:58 PM | 01,032,192 | ---- | M] (Dell Inc) - C:\Program Files\Dell\QuickSet\quickset.exe
[09/08/2005 05:20 AM | 00,122,940 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\DLA\DLACTRLW.EXE
[07/27/2004 04:50 PM | 00,081,920 | ---- | M] (InstallShield Software Corporation) - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[11/09/2007 03:15 PM | 00,115,560 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[08/07/2008 05:46 PM | 00,185,896 | ---- | M] (RealNetworks, Inc.) - C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[04/04/2005 06:58 PM | 00,856,064 | ---- | M] (Adobe Sytems Incorporated) - C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
[12/14/2004 02:12 AM | 00,483,328 | ---- | M] (Adobe Systems Inc.) - C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe
[01/04/2008 08:56 PM | 05,367,664 | ---- | M] (Webroot Software, Inc.) - C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
[09/10/2003 02:24 AM | 00,020,480 | ---- | M] () - C:\Program Files\NetWaiting\netwaiting.exe
[08/06/2008 10:21 AM | 00,050,472 | ---- | M] (AOL LLC) - C:\Program Files\AIM6\aim6.exe
[10/29/2003 02:06 AM | 00,024,576 | ---- | M] (BVRP Software) - C:\Program Files\Digital Line Detect\DLG.exe
[08/05/2008 07:26 PM | 03,065,168 | ---- | M] (Xfire Inc.) - C:\Program Files\Xfire\xfire.exe
[10/08/2007 04:50 PM | 00,041,824 | ---- | M] (AOL LLC) - C:\Program Files\AIM6\aolsoftware.exe
[07/02/2008 08:52 PM | 00,307,712 | ---- | M] (Mozilla Corporation) - C:\Program Files\Mozilla Firefox\firefox.exe
[01/04/2008 08:34 PM | 00,214,384 | ---- | M] () - C:\Program Files\Webroot\Spy Sweeper\ssu.exe
[08/26/2008 08:57 AM | 01,299,968 | ---- | M] (OldTimer Tools) - C:\Documents and Settings\copeterson\Desktop\OTViewIt.exe
===== Win32 Services - Non-Microsoft Only =====
(Adobe LM Service) Adobe LM Service [On_Demand | Stopped]
[08/07/2008 06:50 PM | 00,072,704 | ---- | M] (Adobe Systems) - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
(Adobe Version Cue CS2) Adobe Version Cue CS2 [Auto | Running]
[04/04/2005 06:58 PM | 00,163,840 | ---- | M] (Adobe Systems Incorporated) - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
(Autodesk Licensing Service) Autodesk Licensing Service [Auto | Running]
[08/07/2008 06:40 PM | 00,079,360 | ---- | M] (Autodesk) - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
(ccEvtMgr) Symantec Event Manager [Auto | Running]
[11/09/2007 03:15 PM | 00,108,392 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
(ccSetMgr) Symantec Settings Manager [Auto | Running]
[11/09/2007 03:15 PM | 00,108,392 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
(DataSvr2) DataSvr2 [Auto | Running]
[03/25/2006 05:24 PM | 00,315,392 | ---- | M] (Wave Systems Corp.) - C:\Program Files\Wave Systems Corp\common\DataServer.exe
(dmadmin) Logical Disk Manager Administrative Service [On_Demand | Stopped]
[04/13/2008 07:12 PM | 00,224,768 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\dmadmin.exe
(LiveUpdate) LiveUpdate [On_Demand | Stopped]
[08/11/2007 08:05 PM | 03,093,872 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE
(mi-raysat_3dsMax2009_32) mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit [Auto | Running]
[03/10/2008 12:04 AM | 00,065,536 | ---- | M] () - C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe
(NICCONFIGSVC) NICCONFIGSVC [Auto | Running]
[04/06/2006 02:57 PM | 00,380,928 | ---- | M] (Dell Inc.) - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
(NVSvc) NVIDIA Display Driver Service [Auto | Running]
[01/19/2006 08:14 AM | 00,143,428 | ---- | M] (NVIDIA Corporation) - C:\WINDOWS\system32\nvsvc32.exe
(Rpcnet) Remote Procedure Call (RPC) Net [Auto | Running]
[03/01/2006 03:37 PM | 00,031,232 | ---- | M] () - C:\WINDOWS\system32\rpcnet.exe
(SmcService) Symantec Management Client [Auto | Running]
[12/18/2007 07:03 PM | 02,569,600 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
(SNAC) Symantec Network Access Control [On_Demand | Stopped]
[12/18/2007 07:04 PM | 00,234,888 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
(Symantec AntiVirus) Symantec Endpoint Protection [Auto | Running]
[12/18/2007 09:08 PM | 02,189,240 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
(tcsd_win32.exe) NTRU Hybrid TSS v2.0.7 TCS [Auto | Running]
[11/30/2005 01:33 PM | 00,180,224 | ---- | M] () - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.7\bin\tcsd_win32.exe
(WDFNet) Webroot Desktop Firewall network service [Auto | Running]
[07/02/2008 01:26 PM | 00,353,672 | ---- | M] (Webroot Software Inc (www.webroot.com)) - C:\Program Files\Webroot\Webroot Desktop Firewall\wdfsvc.exe
(WebrootSpySweeperService) Webroot Spy Sweeper Engine [Auto | Running]
[01/04/2008 08:56 PM | 03,572,592 | ---- | M] (Webroot Software, Inc.) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
(wltrysvc) Dell Wireless WLAN Tray Service [Auto | Running]
[11/01/2006 09:48 PM | 00,020,480 | ---- | M] () - C:\WINDOWS\system32\WLTRYSVC.EXE
===== Driver Services - Non-Microsoft Only =====
(AliIde) AliIde [Disabled | Stopped]
[08/17/2001 01:51 PM | 00,005,248 | ---- | M] (Acer Laboratories Inc.) - C:\WINDOWS\system32\drivers\aliide.sys
(amdagp) AMD AGP Bus Filter Driver [Disabled | Stopped]
[04/13/2008 01:36 PM | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) - C:\WINDOWS\system32\drivers\amdagp.sys
(ApfiltrService) Alps Touch Pad Filter Driver for Windows 2000/XP [On_Demand | Running]
[09/28/2005 06:57 PM | 00,113,847 | R--- | M] (Alps Electric Co., Ltd.) - C:\WINDOWS\system32\drivers\Apfiltr.sys
(APPDRV) APPDRV [System | Running]
[08/12/2005 05:50 PM | 00,016,128 | ---- | M] (Dell Inc) - C:\WINDOWS\system32\drivers\APPDRV.SYS
(asc) asc [Disabled | Stopped]
[08/17/2001 01:52 PM | 00,026,496 | ---- | M] (Advanced System Products, Inc.) - C:\WINDOWS\system32\drivers\asc.sys
(asc3550) asc3550 [Disabled | Stopped]
[08/17/2001 01:51 PM | 00,014,848 | ---- | M] (Advanced System Products, Inc.) - C:\WINDOWS\system32\drivers\asc3550.sys
(b57w2k) Broadcom NetXtreme Gigabit Ethernet [On_Demand | Running]
[11/10/2005 09:25 AM | 00,142,720 | ---- | M] (Broadcom Corporation) - C:\WINDOWS\system32\drivers\b57xp32.sys
(BCM43XX) Dell Wireless WLAN Card Driver [On_Demand | Running]
[10/13/2006 12:28 AM | 00,604,928 | ---- | M] (Broadcom Corporation) - C:\WINDOWS\system32\drivers\BCMWL5.SYS
(CmdIde) CmdIde [Disabled | Stopped]
[08/17/2001 01:51 PM | 00,006,656 | ---- | M] (CMD Technology, Inc.) - C:\WINDOWS\system32\drivers\cmdide.sys
(dac2w2k) dac2w2k [Disabled | Stopped]
[08/17/2001 01:52 PM | 00,179,584 | ---- | M] (Mylex Corporation) - C:\WINDOWS\system32\drivers\dac2w2k.sys
(DLABOIOM) DLABOIOM [Auto | Running]
[09/08/2005 05:20 AM | 00,025,628 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\DLA\DLABOIOM.SYS
(DLACDBHM) DLACDBHM [System | Running]
[08/25/2005 12:16 PM | 00,005,628 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\drivers\DLACDBHM.SYS
(DLADResN) DLADResN [Auto | Running]
[09/08/2005 05:20 AM | 00,002,496 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\DLA\DLADResN.SYS
(DLAIFS_M) DLAIFS_M [Auto | Running]
[09/08/2005 05:20 AM | 00,086,524 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\DLA\DLAIFS_M.SYS
(DLAOPIOM) DLAOPIOM [Auto | Running]
[09/08/2005 05:20 AM | 00,014,684 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\DLA\DLAOPIOM.SYS
(DLAPoolM) DLAPoolM [Auto | Running]
[09/08/2005 05:20 AM | 00,006,364 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\DLA\DLAPoolM.SYS
(DLARTL_N) DLARTL_N [System | Running]
[08/25/2005 12:16 PM | 00,022,684 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\drivers\DLARTL_N.SYS
(DLAUDFAM) DLAUDFAM [Auto | Running]
[09/08/2005 05:20 AM | 00,094,332 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\DLA\DLAUDFAM.SYS
(DLAUDF_M) DLAUDF_M [Auto | Running]
[09/08/2005 05:20 AM | 00,087,036 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\DLA\DLAUDF_M.SYS
(dmboot) dmboot [Disabled | Stopped]
[04/13/2008 01:44 PM | 00,799,744 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\drivers\dmboot.sys
(dmio) Logical Disk Manager Driver [Boot | Running]
[04/13/2008 01:44 PM | 00,153,344 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\drivers\dmio.sys
(dmload) dmload [Disabled | Stopped]
[08/04/2004 05:00 AM | 00,005,888 | ---- | M] (Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\drivers\dmload.sys
(DRVMCDB) DRVMCDB [Boot | Running]
[09/12/2005 03:30 AM | 00,089,264 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\drivers\DRVMCDB.SYS
(DRVNDDM) DRVNDDM [Auto | Running]
[08/12/2005 05:20 AM | 00,040,544 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\drivers\DRVNDDM.SYS
(DS1410D) DS1410D [Auto | Stopped]
File not found - C:\WINDOWS\system32\drivers\ds1410d.sys
(E100B) Intel® PRO Adapter Driver [On_Demand | Stopped]
[08/17/2001 12:12 PM | 00,117,760 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\drivers\e100b325.sys
(eeCtrl) Symantec Eraser Control driver [System | Running]
[08/18/2008 03:00 AM | 00,371,248 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
(EraserUtilRebootDrv) EraserUtilRebootDrv [On_Demand | Running]
[08/18/2008 03:00 AM | 00,099,376 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
(guardian2) guardian2 [On_Demand | Running]
[01/31/2007 02:37 AM | 00,056,320 | ---- | M] (O2Micro) - C:\WINDOWS\system32\drivers\oz776.sys
(Hardlock) Hardlock [Auto | Running]
[07/28/2005 08:18 AM | 00,685,056 | ---- | M] (Aladdin Knowledge Systems Ltd.) - C:\WINDOWS\system32\drivers\hardlock.sys
(Haspnt) Haspnt [Auto | Running]
[08/07/2008 08:23 PM | 00,047,616 | ---- | M] (Aladdin Knowledge Systems) - C:\WINDOWS\system32\drivers\Haspnt.sys
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [On_Demand | Running]
[04/13/2008 11:36 AM | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) - C:\WINDOWS\system32\drivers\hdaudbus.sys
(HSF_DPV) HSF_DPV [On_Demand | Running]
[12/01/2005 12:40 AM | 00,936,960 | ---- | M] (Conexant Systems, Inc.) - C:\WINDOWS\system32\drivers\HSX_DPV.sys
(HSXHWAZL) HSXHWAZL [On_Demand | Running]
[12/01/2005 12:40 AM | 00,192,512 | ---- | M] (Conexant Systems, Inc.) - C:\WINDOWS\system32\drivers\HSXHWAZL.sys
(mdmxsdk) mdmxsdk [Auto | Running]
[10/04/2005 09:57 PM | 00,012,544 | ---- | M] (Conexant) - C:\WINDOWS\system32\drivers\mdmxsdk.sys
(mraid35x) mraid35x [Disabled | Stopped]
[08/17/2001 01:52 PM | 00,017,280 | ---- | M] (American Megatrends Inc.) - C:\WINDOWS\system32\drivers\mraid35x.sys
(NAVENG) NAVENG [On_Demand | Running]
[08/21/2008 03:00 AM | 00,089,104 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080825.034\NAVENG.SYS
(NAVEX15) NAVEX15 [On_Demand | Running]
[08/21/2008 03:00 AM | 00,873,552 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080825.034\NAVEX15.SYS
(nv) nv [On_Demand | Running]
[01/19/2006 08:14 AM | 03,595,296 | ---- | M] (NVIDIA Corporation) - C:\WINDOWS\system32\drivers\nv4_mini.sys
(PBADRV) PBADRV [Boot | Running]
[12/09/2005 03:35 PM | 00,018,816 | ---- | M] (Dell Inc) - C:\WINDOWS\system32\drivers\PBADRV.sys
(Ptilink) Direct Parallel Link Driver [On_Demand | Running]
[08/04/2004 05:00 AM | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) - C:\WINDOWS\system32\drivers\ptilink.sys
(pwipf6) pwipf6 [System | Running]
[07/02/2008 01:26 PM | 00,103,304 | ---- | M] (Webroot Software Inc (www.webroot.com)) - C:\WINDOWS\system32\drivers\pwipf6.sys
(PxHelp20) PxHelp20 [Boot | Running]
[01/26/2005 02:03 AM | 00,020,576 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\drivers\pxhelp20.sys
(ql1080) ql1080 [Disabled | Stopped]
[08/17/2001 01:52 PM | 00,040,320 | ---- | M] (QLogic Corporation) - C:\WINDOWS\system32\drivers\ql1080.sys
(ql12160) ql12160 [Disabled | Stopped]
[08/17/2001 01:52 PM | 00,045,312 | ---- | M] (QLogic Corporation) - C:\WINDOWS\system32\drivers\ql12160.sys
(ql1280) ql1280 [Disabled | Stopped]
[08/17/2001 01:52 PM | 00,049,024 | ---- | M] (QLogic Corporation) - C:\WINDOWS\system32\drivers\ql1280.sys
(Secdrv) Secdrv [On_Demand | Stopped]
[11/13/2007 05:25 AM | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) - C:\WINDOWS\system32\drivers\secdrv.sys
(Sentinel) Sentinel [Auto | Running]
[06/21/2001 09:39 PM | 00,073,728 | ---- | M] (Rainbow Technologies, Inc.) - C:\WINDOWS\system32\drivers\SENTINEL.SYS
(sisagp) SIS AGP Bus Filter [Disabled | Stopped]
[04/13/2008 01:36 PM | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) - C:\WINDOWS\system32\drivers\sisagp.sys
(SMCIRDA) SMC IrCC Miniport Device Driver [On_Demand | Stopped]
[08/17/2001 01:10 PM | 00,035,913 | ---- | M] (SMC) - C:\WINDOWS\system32\drivers\smcirda.sys
(Sntnlusb) Rainbow USB SuperPro [On_Demand | Stopped]
[06/21/2001 09:39 PM | 00,020,032 | R--- | M] (Rainbow Technologies Inc.) - C:\WINDOWS\system32\drivers\SNTNLUSB.SYS
(Sparrow) Sparrow [Disabled | Stopped]
[08/17/2001 02:07 PM | 00,019,072 | ---- | M] (Adaptec, Inc.) - C:\WINDOWS\system32\drivers\sparrow.sys
(SPBBCDrv) SPBBCDrv [System | Running]
[07/31/2007 02:17 AM | 00,418,864 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
(SRTSP) SRTSP [System | Running]
[11/30/2007 11:57 PM | 00,279,088 | ---- | M] (Symantec Corporation) - C:\WINDOWS\system32\drivers\srtsp.sys
(SRTSPL) SRTSPL [On_Demand | Stopped]
[11/30/2007 11:57 PM | 00,317,616 | ---- | M] (Symantec Corporation) - C:\WINDOWS\system32\drivers\srtspl.sys
(SRTSPX) SRTSPX [System | Running]
[11/30/2007 11:57 PM | 00,043,696 | ---- | M] (Symantec Corporation) - C:\WINDOWS\system32\drivers\srtspx.sys
(SSFS0BB9) Spy Sweeper File System Filer Driver: 0BB9 [Boot | Running]
[01/04/2008 08:34 PM | 00,020,336 | ---- | M] (Webroot Software Inc (www.webroot.com)) - C:\WINDOWS\system32\drivers\SSFS0BB9.sys
(SSHRMD) Spy Sweeper Hookrack MiniDriver [Boot | Running]
[01/04/2008 08:34 PM | 00,021,872 | ---- | M] (Webroot Software Inc (www.webroot.com)) - C:\WINDOWS\system32\drivers\sshrmd.sys
(SSIDRV) Spy Sweeper Interdiction Driver [Boot | Running]
[01/04/2008 08:34 PM | 00,163,696 | ---- | M] (Webroot Software Inc (www.webroot.com)) - C:\WINDOWS\system32\drivers\ssidrv.sys
(SSKBFD) Webroot Spy Sweeper Keylogger Shield Keyboard Filter [On_Demand | Running]
[01/04/2008 08:34 PM | 00,023,920 | ---- | M] (Webroot Software Inc (www.webroot.com)) - C:\WINDOWS\system32\drivers\sskbfd.sys
(STHDA) SigmaTel High Definition Audio CODEC [On_Demand | Running]
[03/24/2006 04:34 PM | 01,156,648 | ---- | M] (SigmaTel, Inc.) - C:\WINDOWS\system32\drivers\sthda.sys
(symc810) symc810 [Disabled | Stopped]
[08/17/2001 02:07 PM | 00,016,256 | ---- | M] (Symbios Logic Inc.) - C:\WINDOWS\system32\drivers\symc810.sys
(symc8xx) symc8xx [Disabled | Stopped]
[08/17/2001 02:07 PM | 00,032,640 | ---- | M] (LSI Logic) - C:\WINDOWS\system32\drivers\symc8xx.sys
(SymEvent) SymEvent [On_Demand | Running]
[06/19/2008 12:15 PM | 00,136,496 | ---- | M] (Symantec Corporation) - C:\WINDOWS\system32\drivers\SYMEVENT.SYS
(symlcbrd) symlcbrd [Auto | Running]
[07/06/2006 02:27 PM | 00,010,344 | ---- | M] (Symantec Corporation) - C:\WINDOWS\system32\drivers\symlcbrd.sys
(SYMREDRV) SYMREDRV [On_Demand | Running]
[01/09/2007 04:46 PM | 00,027,576 | ---- | M] (Symantec Corporation) - C:\WINDOWS\system32\drivers\symredrv.sys
(SYMTDI) SYMTDI [System | Running]
[01/09/2007 04:46 PM | 00,191,544 | ---- | M] (Symantec Corporation) - C:\WINDOWS\system32\drivers\symtdi.sys
(sym_hi) sym_hi [Disabled | Stopped]
[08/17/2001 02:07 PM | 00,028,384 | ---- | M] (LSI Logic) - C:\WINDOWS\system32\drivers\sym_hi.sys
(sym_u3) sym_u3 [Disabled | Stopped]
[08/17/2001 02:07 PM | 00,030,688 | ---- | M] (LSI Logic) - C:\WINDOWS\system32\drivers\sym_u3.sys
(ultra) ultra [Disabled | Stopped]
[08/17/2001 01:52 PM | 00,036,736 | ---- | M] (Promise Technology, Inc.) - C:\WINDOWS\system32\drivers\ultra.sys
(vsdatant) vsdatant [Disabled | Stopped]
File not found - a
(winachsf) winachsf [On_Demand | Running]
[12/01/2005 12:40 AM | 00,669,696 | ---- | M] (Conexant Systems, Inc.) - C:\WINDOWS\system32\drivers\HSX_CNXT.sys
===== Run Keys =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"" = File not found
"Acrobat Assistant 7.0" = "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [12/14/2004 02:12 AM | 00,483,328 | ---- | M] (Adobe Systems Inc.)
"Adobe Version Cue CS2" = "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [04/04/2005 06:58 PM | 00,856,064 | ---- | M] (Adobe Sytems Incorporated)
"Apoint" = "C:\Program Files\Apoint\Apoint.exe" [10/07/2005 12:13 PM | 00,176,128 | R--- | M] (Alps Electric Co., Ltd.)
"Broadcom Wireless Manager UI" = C:\WINDOWS\system32\WLTRAY.exe [11/01/2006 09:48 PM | 01,392,640 | ---- | M] (Dell Inc.)
"ccApp" = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [11/09/2007 03:15 PM | 00,115,560 | ---- | M] (Symantec Corporation)
"Dell QuickSet" = "C:\Program Files\Dell\QuickSet\quickset.exe" [04/06/2006 02:58 PM | 01,032,192 | ---- | M] (Dell Inc)
"DLA" = C:\WINDOWS\System32\DLA\DLACTRLW.EXE [09/08/2005 05:20 AM | 00,122,940 | ---- | M] (Sonic Solutions)
"Document Manager" = "C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe" [03/09/2006 12:26 PM | 00,098,304 | ---- | M] (Wave Systems Corp.)
"DVDLauncher" = "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [12/09/2005 08:29 PM | 00,049,152 | ---- | M] (CyberLink Corp.)
"Explorer-" = c:\windows\explorer-.exe File not found
"InitDataWin64" = c:\windows\explorer-.exe File not found
"ISUSPM Startup" = "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup [07/27/2004 04:50 PM | 00,221,184 | ---- | M] (InstallShield Software Corporation)
"ISUSScheduler" = "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start [07/27/2004 04:50 PM | 00,081,920 | ---- | M] (InstallShield Software Corporation)
"NvCplDaemon" = "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup [01/19/2006 08:14 AM | 07,401,472 | ---- | M] (NVIDIA Corporation)
"NVHotkey" = "rundll32.exe" nvHotkey.dll,Start [01/19/2006 08:14 AM | 00,073,728 | ---- | M] (NVIDIA Corporation)
"nwiz" = "nwiz.exe" /installquiet [01/19/2006 08:14 AM | 01,519,616 | ---- | M] ()
"SigmatelSysTrayApp" = stsystra.exe [03/24/2006 04:30 PM | 00,282,624 | ---- | M] (SigmaTel, Inc.)
"SpySweeper" = C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray [01/04/2008 08:56 PM | 05,367,664 | ---- | M] (Webroot Software, Inc.)
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM | 00,144,784 | ---- | M] (Sun Microsystems, Inc.)
"TkBellExe" = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot [08/07/2008 05:46 PM | 00,185,896 | ---- | M] (RealNetworks, Inc.)
"Webroot Desktop Firewall" = "C:\Program Files\Webroot\Webroot Desktop Firewall\WDF.exe" [07/02/2008 01:26 PM | 02,401,672 | ---- | M] (Webroot Software Inc (www.webroot.com))
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6" = "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp [08/06/2008 10:21 AM | 00,050,472 | ---- | M] (AOL LLC)
"ModemOnHold" = "C:\Program Files\NetWaiting\netWaiting.exe" [09/10/2003 02:24 AM | 00,020,480 | ---- | M] ()
"Steam" = "C:\Program Files\Steam\Steam.exe" -silent [08/21/2008 08:33 PM | 01,271,032 | ---- | M] (Valve Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-21-1665011553-906448321-1714775081-21989\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6" = "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp [08/06/2008 10:21 AM | 00,050,472 | ---- | M] (AOL LLC)
"ModemOnHold" = "C:\Program Files\NetWaiting\netWaiting.exe" [09/10/2003 02:24 AM | 00,020,480 | ---- | M] ()
"Steam" = "C:\Program Files\Steam\Steam.exe" -silent [08/21/2008 08:33 PM | 01,271,032 | ---- | M] (Valve Corporation)
[HKEY_USERS\S-1-5-21-1665011553-906448321-1714775081-21989\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
===== Startup Folders =====
[Administrator Startup Folder - C:\Documents and Settings\Administrator\Start Menu\Programs\Startup]
[All Users Startup Folder - C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
[08/07/2008 07:15 PM | 00,025,214 | R--- | M] () - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe
[03/16/2005 07:16 PM | 00,113,664 | ---- | M] (Adobe Systems, Inc.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[10/29/2003 02:06 AM | 00,024,576 | ---- | M] (BVRP Software) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
[Computer User Startup Folder - C:\Documents and Settings\Computer User\Start Menu\Programs\Startup]
[copeterson Startup Folder - C:\Documents and Settings\copeterson\Start Menu\Programs\Startup]
[08/05/2008 07:26 PM | 03,065,168 | ---- | M] (Xfire Inc.) - C:\Documents and Settings\copeterson\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\xfire.exe
[Default User Startup Folder - C:\Documents and Settings\Default User\Start Menu\Programs\Startup]
===== BHO's =====
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
HKLM CLSID: (&Yahoo! Toolbar Helper) - [05/15/2008 02:40 PM | 00,817,936 | ---- | M] (Yahoo! Inc.) C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
HKLM CLSID: (AcroIEHlprObj Class) - [12/14/2004 01:56 AM | 00,063,136 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
HKLM CLSID: (Yahoo! IE Services Button) - [12/12/2007 05:09 PM | 00,222,448 | ---- | M] (Yahoo! Inc.) C:\Program Files\Yahoo!\Common\yiesrvc.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
HKLM CLSID: (DriveLetterAccess) - [09/08/2005 05:20 AM | 00,110,652 | ---- | M] (Sonic Solutions) C:\WINDOWS\system32\DLA\DLASHX_W.DLL
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
HKLM CLSID: (SSVHelper Class) - [06/10/2008 04:27 AM | 00,509,328 | ---- | M] (Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
HKLM CLSID: (AcroIEToolbarHelper Class) - [12/14/2004 02:13 AM | 00,225,280 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
HKLM CLSID: (CBrowserHelperObject Object) - [02/17/2006 10:28 AM | 00,094,208 | ---- | M] (Dell Inc.) c:\Program Files\BAE\BAE.dll
===== Toolbars =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"
HKLM CLSID: (Adobe PDF) - [12/14/2004 02:13 AM | 00,225,280 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
HKLM CLSID: (Yahoo! Toolbar) - [05/15/2008 02:40 PM | 00,817,936 | ---- | M] (Yahoo! Inc.) C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"
HKLM CLSID: (Adobe PDF) - [12/14/2004 02:13 AM | 00,225,280 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
[HKEY_USERS\S-1-5-21-1665011553-906448321-1714775081-21989\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"
HKLM CLSID: (Adobe PDF) - [12/14/2004 02:13 AM | 00,225,280 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
===== Policies =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoCDBurning" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername" = 0
"legalnoticecaption" =
"legalnoticetext" =
"shutdownwithoutlogon" = 1
"undockwithoutlogon" = 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-21-1665011553-906448321-1714775081-21989\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-21-1665011553-906448321-1714775081-21989\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
===== Desktop Components =====
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"FriendlyName" = "My Current Home Page"
"Source" = "About:Home"
"SubscribedURL" = "About:Home"
===== Shared Task Scheduler =====
===== AppInit_Dlls =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls]
"wxvault.dll" - [03/09/2006 12:25 PM | 00,286,720 | ---- | M] () C:\WINDOWS\system32\wxvault.dll
===== Lsa Authentication Packages =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages]
"wvauth" - [03/24/2006 03:19 PM | 00,360,448 | ---- | M] (Wave Systems Corp.) C:\WINDOWS\system32\wvauth.dll
===== Lsa Security Packages =====
===== Authorized Applications List =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe [04/13/2008 07:12 PM | 00,141,312 | ---- | M] (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = C:\WINDOWS\network diagnostic\xpnetdiag.exe [04/13/2008 01:53 PM | 00,558,080 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe [10/18/2007 11:34 AM | 05,724,184 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe [10/02/2007 05:18 PM | 00,304,488 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [08/30/2007 05:43 PM | 04,670,704 | ---- | M] (Yahoo! Inc.)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe [08/06/2008 10:21 AM | 00,050,472 | ---- | M] (AOL LLC)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe [08/21/2008 08:33 PM | 01,271,032 | ---- | M] (Valve Corporation)
"C:\Program Files\Xfire\xfire.exe" = C:\Program Files\Xfire\xfire.exe [08/05/2008 07:26 PM | 03,065,168 | ---- | M] (Xfire Inc.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe [04/13/2008 07:12 PM | 00,141,312 | ---- | M] (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = C:\WINDOWS\network diagnostic\xpnetdiag.exe [04/13/2008 01:53 PM | 00,558,080 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe" = C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe [12/18/2007 07:03 PM | 02,569,600 | ---- | M] (Symantec Corporation)
"C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE" = C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE [12/18/2007 07:04 PM | 00,234,888 | ---- | M] (Symantec Corporation)
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" = C:\Program Files\Common Files\Symantec Shared\ccApp.exe [11/09/2007 03:15 PM | 00,115,560 | ---- | M] (Symantec Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [08/30/2007 05:43 PM | 04,670,704 | ---- | M] (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe [08/30/2007 05:43 PM | 00,091,376 | ---- | M] (Yahoo! Inc.)
"C:\Program Files\Autodesk\Backburner\monitor.exe" = C:\Program Files\Autodesk\Backburner\monitor.exe [02/20/2008 03:26 PM | 00,425,984 | ---- | M] (Autodesk, Inc.)
"C:\Program Files\Autodesk\Backburner\manager.exe" = C:\Program Files\Autodesk\Backburner\manager.exe [02/20/2008 03:26 PM | 00,532,480 | ---- | M] (Autodesk, Inc.)
"C:\Program Files\Autodesk\Backburner\server.exe" = C:\Program Files\Autodesk\Backburner\server.exe [02/20/2008 03:26 PM | 00,110,592 | ---- | M] (Autodesk, Inc.)
"C:\Program Files\Autodesk\3ds Max 2009\3dsmax.exe" = C:\Program Files\Autodesk\3ds Max 2009\3dsmax.exe [03/10/2008 01:22 AM | 07,299,072 | ---- | M] (Autodesk, Inc.)
"C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" = C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe [04/04/2005 06:58 PM | 00,163,840 | ---- | M] (Adobe Systems Incorporated)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe [04/13/2008 07:12 PM | 01,695,232 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe [10/18/2007 11:34 AM | 05,724,184 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe [10/02/2007 05:18 PM | 00,304,488 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe [11/03/2006 02:17 AM | 00,010,800 | ---- | M] (AOL LLC)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe [08/06/2008 10:21 AM | 00,050,472 | ---- | M] (AOL LLC)
"C:\Program Files\Xfire\xfire.exe" = C:\Program Files\Xfire\xfire.exe [08/05/2008 07:26 PM | 03,065,168 | ---- | M] (Xfire Inc.)
===== HKLM Winlogon Settings =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
"Explorer.exe" - [04/13/2008 07:12 PM | 01,033,728 | ---- | M] (Microsoft Corporation) C:\WINDOWS\explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit]
"C:\WINDOWS\system32\userinit.exe" - [04/13/2008 07:12 PM | 00,026,112 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost]
"logonui.exe" - [04/13/2008 07:12 PM | 00,514,560 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\logonui.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet]
"rundll32 shell32" - [04/13/2008 07:12 PM | 08,461,312 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
"Control_RunDLL "sysdm.cpl"" - [04/13/2008 07:12 PM | 00,300,544 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
===== User's Winlogon Settings =====
===== Winlogon Notify Settings =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier]
"DllName" = C:\WINDOWS\system32\WRLogonNtf.dll [01/04/2008 08:34 PM | 00,219,504 | ---- | M] (Webroot Software, Inc.)
===== Safeboot Options =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell" = cmd.exe
===== Disabled MsConfig Items =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Yahoo! Pager]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = YahooMessenger
"hkey" = HKCU
"command" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [08/30/2007 05:43 PM | 04,670,704 | ---- | M] (Yahoo! Inc.)
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state]
"system.ini" = 0
"win.ini" = 0
"bootini" = 0
"services" = 0
"startup" = 2
===== DNS Name Servers =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{25E78321-B6C7-4032-877F-9AB260B8EEF0}]
Servers: | Description: 1394 Net Adapter
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{4FA47D39-444D-40D3-AE8D-3C5F1F914F64}]
Servers: | Description: 1394 Net Adapter
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{5223089D-ECC5-479D-A7EB-EF96799B462B}]
Servers: | Description: 1394 Net Adapter
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{95427291-79D6-4FA1-985B-7166CE25EE69}]
Servers: | Description: 1394 Net Adapter
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{E168A95F-EBD3-4657-BCB6-B2A65D5C8FB4}]
Servers: | Description: Broadcom NetXtreme 57xx Gigabit Controller
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{F317AC1C-0D7A-4CF2-99FC-31B7551204D0}]
Servers: | Description: Dell Wireless 1390 WLAN Mini-Card
===== CDRom AutoRun Settings =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
===== Autorun Files on Drives =====
AUTOEXEC.BAT []
[08/11/2004 05:15 PM | 00,000,000 | ---- | M] () C:\AUTOEXEC.BAT [ NTFS ]
autorun.inf [[autorun] | open=GPGTCDLauncher.exe | icon=torque.ico | ]
[02/03/2006 03:45 PM | 00,000,051 | R--- | M] () E:\autorun.inf [ CDFS ]
===== MountPoints2 =====
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9c891beb-64d1-11dd-8f9e-0015c5bc1566}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9c891beb-64d1-11dd-8f9e-0015c5bc1566}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [04/13/2008 07:12 PM | 08,461,312 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9c891beb-64d1-11dd-8f9e-0015c5bc1566}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9c891c00-64d1-11dd-8f9e-0015c5bc1566}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9c891c00-64d1-11dd-8f9e-0015c5bc1566}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [04/13/2008 07:12 PM | 08,461,312 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9c891c00-64d1-11dd-8f9e-0015c5bc1566}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c88d133b-6ed5-11dd-8fa3-0015c5bc1566}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c88d133b-6ed5-11dd-8fa3-0015c5bc1566}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [04/13/2008 07:12 PM | 08,461,312 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c88d133b-6ed5-11dd-8fa3-0015c5bc1566}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
===== Hosts File =====
HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
[Files/Folders - Created Within 60 days]
[08/07/2008 03:04 PM | ---D | C] - C:\Printers
[08/07/2008 04:20 PM | 00,000,164 | ---- | C] () - C:\install.dat
[08/07/2008 07:53 PM | ---D | C] - C:\Torque
[08/15/2008 10:10 PM | 00,000,730 | -H-- | C] () - C:\IPH.PH
[08/21/2008 08:43 PM | -HSD | C] - C:\Config.Msi
[01/04/2008 08:34 PM | 00,020,336 | ---- | C] (Webroot Software Inc (www.webroot.com)) - C:\WINDOWS\System32\drivers\SSFS0BB9.sys
[01/04/2008 08:34 PM | 00,021,872 | ---- | C] (Webroot Software Inc (www.webroot.com)) - C:\WINDOWS\System32\drivers\sshrmd.sys
[01/04/2008 08:34 PM | 00,023,920 | ---- | C] (Webroot Software Inc (www.webroot.com)) - C:\WINDOWS\System32\drivers\sskbfd.sys
[01/04/2008 08:34 PM | 00,163,696 | ---- | C] (Webroot Software Inc (www.webroot.com)) - C:\WINDOWS\System32\drivers\ssidrv.sys
[06/21/2001 09:39 PM | 00,020,032 | R--- | C] (Rainbow Technologies Inc.) - C:\WINDOWS\System32\drivers\SNTNLUSB.SYS
[06/21/2001 09:39 PM | 00,073,728 | ---- | C] (Rainbow Technologies, Inc.) - C:\WINDOWS\System32\drivers\SENTINEL.SYS
[07/02/2008 01:26 PM | 00,103,304 | ---- | C] (Webroot Software Inc (www.webroot.com)) - C:\WINDOWS\System32\drivers\pwipf6.sys
[07/28/2005 08:18 AM | 00,685,056 | ---- | C] (Aladdin Knowledge Systems Ltd.) - C:\WINDOWS\System32\drivers\hardlock.sys
[08/07/2008 08:23 PM | 00,047,616 | ---- | C] (Aladdin Knowledge Systems) - C:\WINDOWS\System32\drivers\Haspnt.sys
[1 C:\WINDOWS\System32\*.tmp files]
[01/04/2008 08:34 PM | 00,016,240 | ---- | C] (Webroot Software Inc (www.webroot.com)) - C:\WINDOWS\System32\ssiefr.EXE
[01/04/2008 08:34 PM | 00,026,480 | ---- | C] () - C:\WINDOWS\System32\wrlzma.dll
[01/04/2008 08:34 PM | 00,219,504 | ---- | C] (Webroot Software, Inc.) - C:\WINDOWS\System32\WRLogonNtf.dll
[06/08/2002 08:00 PM | 00,466,944 | ---- | C] (InterVideo Inc.) - C:\WINDOWS\System32\iviaudio.ax
[06/10/2008 01:21 AM | 00,135,168 | ---- | C] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\java.exe
[06/10/2008 01:21 AM | 00,135,168 | ---- | C] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaw.exe
[06/10/2008 02:32 AM | 00,139,264 | ---- | C] (Sun Microsystems, Inc.) - C:\WINDOWS\System32\javaws.exe
[06/20/2006 03:56 AM | 00,225,280 | ---- | C] (Propellerhead Software AB) - C:\WINDOWS\System32\rewire.dll
[06/21/2001 09:39 PM | 00,009,949 | ---- | C] () - C:\WINDOWS\System32\SENTINEL.HLP
[06/21/2001 09:39 PM | 00,018,432 | ---- | C] (Rainbow Technologies, Inc.) - C:\WINDOWS\System32\RNBOVDD.DLL
[06/21/2001 09:39 PM | 00,049,664 | ---- | C] (Rainbow Technologies, Inc.) - C:\WINDOWS\System32\SNTI386.DLL
[07/02/2008 01:26 PM | 00,173,448 | ---- | C] (Webroot Software Inc (www.webroot.com)) - C:\WINDOWS\System32\wdfproc.dll
[07/07/2002 05:14 PM | 01,294,336 | ---- | C] (HMS
http://hp.vector.co....hors/VA012897/) - C:\WINDOWS\System32\vorbis.acm
[07/10/2008 07:28 PM | 00,026,292 | ---- | C] () - C:\WINDOWS\System32\SQLServerManager10.msc
[08/05/2008 07:26 PM | 00,042,320 | ---- | C] () - C:\WINDOWS\System32\xfcodec.dll
[08/07/2008 05:46 PM | 00,005,632 | ---- | C] (RealNetworks, Inc.) - C:\WINDOWS\System32\pndx5032.dll
[08/07/2008 05:46 PM | 00,006,656 | ---- | C] (RealNetworks, Inc.) - C:\WINDOWS\System32\pndx5016.dll
[08/07/2008 05:46 PM | 00,185,944 | ---- | C] (RealNetworks, Inc.) - C:\WINDOWS\System32\rmoc3260.dll
[08/07/2008 05:46 PM | 00,278,528 | ---- | C] (Real Networks, Inc) - C:\WINDOWS\System32\pncrt.dll
[08/07/2008 07:05 PM | ---D | C] - C:\WINDOWS\System32\Adobe
[08/07/2008 08:20 PM | ---D | C] - C:\WINDOWS\System32\RNBOSENT
[08/07/2008 08:21 PM | 00,002,624 | ---- | C] () - C:\WINDOWS\System32\config.hsp
[08/07/2008 08:23 PM | 00,000,383 | ---- | C] () - C:\WINDOWS\System32\haspdos.sys
[08/07/2008 08:23 PM | 00,006,656 | ---- | C] (Aladdin Knowledge Systems.) - C:\WINDOWS\System32\haspvdd.dll
[08/07/2008 11:22 PM | ---D | C] - C:\WINDOWS\System32\DRVSTORE
[08/13/2008 01:13 PM | ---D | C] - C:\WINDOWS\System32\appmgmt
[08/16/2004 07:40 PM | 00,016,384 | ---- | C] () - C:\WINDOWS\System32\FileOps.exe
[08/18/2008 03:26 PM | ---D | C] - C:\WINDOWS\System32\RsFx
[08/18/2008 12:53 PM | ---D | C] - C:\WINDOWS\System32\XPSViewer
[08/25/2008 07:53 PM | ---D | C] - C:\WINDOWS\System32\Kaspersky Lab
[1 C:\WINDOWS\*.tmp files]
[01/04/2008 08:56 PM | 01,526,640 | ---- | C] (Webroot Software, Inc.) - C:\WINDOWS\WRSetup.dll
[03/16/2003 12:15 AM | 00,090,112 | ---- | C] (MindVision Software) - C:\WINDOWS\unvise32.exe
[08/07/2008 03:07 PM | ---D | C] - C:\WINDOWS\SchCache
[08/07/2008 03:09 PM | -HSD | C] - C:\WINDOWS\CSC
[08/07/2008 03:46 PM | 00,000,000 | ---- | C] () - C:\WINDOWS\nsreg.dat
[08/07/2008 05:48 PM | 00,000,025 | ---- | C] () - C:\WINDOWS\cdplayer.ini
[08/07/2008 05:57 PM | ---D | C] - C:\WINDOWS\pss
[08/07/2008 07:56 PM | 00,004,096 | ---- | C] () - C:\WINDOWS\d3dx.dat
[08/13/2008 02:48 PM | ---D | C] - C:\WINDOWS\Sun
[08/18/2008 03:15 PM | ---D | C] - C:\WINDOWS\SxsCaPendDel
[08/18/2008 09:54 AM | ---D | C] - C:\WINDOWS\Logs
[08/26/2008 08:50 AM | 00,000,000 | ---- | C] () - C:\WINDOWS\TempFile
[08/26/2008 08:55 AM | 00,000,274 | ---- | C] () - C:\WINDOWS\tasks\Symantec NetDetect.job
[08/07/2008 04:32 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Webroot
[08/07/2008 06:02 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[08/07/2008 06:51 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Autodesk
[08/07/2008 06:54 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Adobe Systems
[08/07/2008 11:12 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\WLInstaller
[08/08/2008 01:33 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Yahoo!
[08/12/2008 12:16 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\AOL
[08/12/2008 12:18 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\AOL OCP
[08/15/2008 10:09 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\acccore
[08/18/2008 03:09 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Microsoft Help
[08/18/2008 10:30 AM | 00,000,044 | ---- | C] () - C:\Documents and Settings\All Users\Application Data\{5E70RQU4-N865-6307-D5423453040Q}
[08/25/2008 06:11 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Viewpoint
[08/25/2008 06:17 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Malwarebytes
[06/28/2006 08:05 PM | ---D | C] - C:\Documents and Settings\copeterson\Application Data\Sun
[06/28/2006 08:14 PM | ---D | C] - C:\Documents and Settings\copeterson\Application Data\Google
[08/07/2008 03:46 PM | ---D | C] - C:\Documents and Settings\copeterson\Application Data\Mozilla
[08/07/2008 04:17 PM | ---D | C] - C:\Documents and Settings\copeterson\Application Data\Macromedia
[08/07/2008 04:25 PM | ---D | C] - C:\Documents and Settings\copeterson\Application Data\Webroot
[08/07/2008 06:04 PM | ---D | C] - C:\Documents and Settings\copeterson\Application Data\Real
[08/07/2008 06:38 PM | ---D | C] - C:\Documents and Settings\copeterson\Application Data\Yahoo!
[08/07/2008 06:52 PM | ---D | C] - C:\Documents and Settings\copeterson\Application Data\Autodesk
[08/10/2008 01:14 AM | ---D | C] - C:\Documents and Settings\copeterson\Application Data\Help
[08/11/2004 05:07 PM | 00,000,062 | -HS- | C] () - C:\Documents and Settings\copeterson\Application Data\desktop.ini
[08/11/2004 05:20 PM | ---D | C] - C:\Documents and Settings\copeterson\Application Data\Identities
[08/13/2008 02:22 PM | ---D | C] - C:\Documents and Settings\copeterson\Application Data\AdobeUM
[08/15/2008 10:11 PM | ---D | C] - C:\Documents and Setting