OTViewIt logfile created on: 8/29/2008 12:05:29 AM - Run 1
OTViewIt by OldTimer - Version 1.0.1.0 Folder = C:\Documents and Settings\Dvid\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.85 Gb Total Space | 54.73 Gb Free Space | 37.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DESKTOP
Current User Name: Dvid
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
===== Processes - Non-Microsoft Only =====
[10/07/2007 10:19 AM | 00,259,128 | ---- | M] (Cisco Systems, Inc.) - C:\Program Files\Cisco Systems\SSL VPN Client\Agent.exe
[02/18/2008 11:16 AM | 00,110,592 | ---- | M] (Apple, Inc.) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[08/26/2008 11:58 PM | 00,231,192 | ---- | M] (AVG Technologies CZ, s.r.o.) - C:\Program Files\AVG\AVG8\avgwdsvc.exe
[08/06/2004 03:50 AM | 00,102,463 | ---- | M] (Network Associates, Inc.) - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
[09/22/2004 08:00 PM | 00,221,191 | ---- | M] (Network Associates, Inc.) - C:\Program Files\Network Associates\VirusScan\mcshield.exe
[08/06/2004 03:50 AM | 00,237,623 | ---- | M] (Network Associates, Inc.) - C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe
[09/22/2004 08:00 PM | 00,028,672 | ---- | M] (Network Associates, Inc.) - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
[08/26/2008 11:58 PM | 00,287,000 | ---- | M] (AVG Technologies CZ, s.r.o.) - C:\Program Files\AVG\AVG8\avgrsx.exe
[11/01/2005 02:12 AM | 00,094,208 | ---- | M] () - C:\Program Files\Dell\Media Experience\DMXLauncher.exe
[09/22/2004 08:00 PM | 00,094,208 | ---- | M] (Network Associates, Inc.) - C:\Program Files\Network Associates\VirusScan\shstat.exe
[08/06/2004 03:50 AM | 00,139,320 | ---- | M] (Network Associates, Inc.) - C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
[10/07/2003 09:48 AM | 00,147,514 | ---- | M] (Network Associates, Inc.) - C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
[08/26/2008 11:58 PM | 01,232,152 | ---- | M] (AVG Technologies CZ, s.r.o.) - C:\Program Files\AVG\AVG8\avgtray.exe
===== Win32 Services - Non-Microsoft Only =====
(Apple Mobile Device) Apple Mobile Device [Auto | Running]
[02/18/2008 11:16 AM | 00,110,592 | ---- | M] (Apple, Inc.) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
(avg8wd) AVG Free8 WatchDog [Auto | Running]
[08/26/2008 11:58 PM | 00,231,192 | ---- | M] (AVG Technologies CZ, s.r.o.) - C:\Program Files\AVG\AVG8\avgwdsvc.exe
(DSBrokerService) DSBrokerService [On_Demand | Stopped]
[03/07/2007 03:47 PM | 00,076,848 | ---- | M] () - C:\Program Files\DellSupport\brkrsvc.exe
(FLEXnet Licensing Service) FLEXnet Licensing Service [On_Demand | Stopped]
[11/02/2007 08:30 AM | 00,654,848 | ---- | M] (Macrovision Europe Ltd.) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
(McAfeeFramework) McAfee Framework Service [Auto | Running]
[08/06/2004 03:50 AM | 00,102,463 | ---- | M] (Network Associates, Inc.) - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
(McShield) Network Associates McShield [Auto | Paused]
[09/22/2004 08:00 PM | 00,221,191 | ---- | M] (Network Associates, Inc.) - C:\Program Files\Network Associates\VirusScan\mcshield.exe
(McTaskManager) Network Associates Task Manager [Auto | Running]
[09/22/2004 08:00 PM | 00,028,672 | ---- | M] (Network Associates, Inc.) - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
(STCAgent) Cisco Systems, Inc. STC Agent [Auto | Running]
[10/07/2007 10:19 AM | 00,259,128 | ---- | M] (Cisco Systems, Inc.) - C:\Program Files\Cisco Systems\SSL VPN Client\Agent.exe
===== Driver Services - Non-Microsoft Only =====
(AvgLdx86) AVG Free AVI Loader Driver x86 [System | Running]
[08/26/2008 11:58 PM | 00,096,520 | ---- | M] (AVG Technologies CZ, s.r.o.) - C:\WINDOWS\system32\drivers\avgldx86.sys
(AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [System | Running]
[08/26/2008 11:58 PM | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) - C:\WINDOWS\system32\drivers\avgmfx86.sys
(catchme) catchme [On_Demand | Stopped]
File not found - C:\DOCUME~1\Dvid\LOCALS~1\Temp\catchme.sys
(cdrbsvsd) cdrbsvsd [System | Running]
[04/29/2003 05:38 AM | 00,010,940 | ---- | M] (B.H.A Corporation) - C:\WINDOWS\System32\drivers\cdrbsvsd.sys
(CSVirtA) Cisco Systems SSL VPN Adapter [On_Demand | Stopped]
[10/07/2007 10:19 AM | 00,022,136 | ---- | M] (Cisco Systems, Inc.) - C:\WINDOWS\system32\drivers\CSVirtA.sys
(E100B) Intel® PRO Network Connection Driver [On_Demand | Running]
[10/14/2004 08:30 PM | 00,155,648 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\drivers\e100b325.sys
(FilterService) UVC Filter Service [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\lvuvcflt.sys
(fixustor) fixustor [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\drivers\fixustor.sys
(lvpopflt) Logitech POP Suppression Filter [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\lvpopflt.sys
(LVUSBSta) Logitech USB Monitor Filter [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\drivers\LVUSBSta.sys
(LVUVC) QuickCam Communicate Deluxe(UVC) [On_Demand | Stopped]
[06/15/2008 06:59 PM | 00,000,000 | ---- | M] () - C:\WINDOWS\System32\drivers\lvuvc.hs
(mraid35x) mraid35x [Disabled | Stopped]
[08/17/2001 12:52 PM | 00,017,280 | ---- | M] (American Megatrends Inc.) - C:\WINDOWS\system32\drivers\mraid35x.sys
(NaiAvFilter1) NaiAvFilter1 [On_Demand | Running]
[09/22/2004 08:00 PM | 00,108,256 | ---- | M] (Network Associates, Inc.) - C:\WINDOWS\system32\drivers\naiavf5x.sys
(NaiAvTdi1) NaiAvTdi1 [System | Running]
[10/15/2004 08:00 PM | 00,058,464 | ---- | M] (Network Associates, Inc.) - C:\WINDOWS\system32\drivers\mvstdi5x.sys
(Sparrow) Sparrow [Disabled | Stopped]
[08/17/2001 01:07 PM | 00,019,072 | ---- | M] (Adaptec, Inc.) - C:\WINDOWS\system32\drivers\sparrow.sys
(wanatw) WAN Miniport (ATW) [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\wanatw4.sys
(EntDrv51) EntDrv51 [On_Demand | Running]
[10/18/2004 08:00 PM | 00,008,320 | ---- | M] (Network Associates, Inc) - C:\WINDOWS\system32\drivers\entdrv51.sys
========== Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [08/05/2005 08:05 PM | 00,344,064 | ---- | M] (ATI Technologies, Inc.)
"AVG8_TRAY" = C:\PROGRA~1\AVG\AVG8\avgtray.exe [08/26/2008 11:58 PM | 01,232,152 | ---- | M] (AVG Technologies CZ, s.r.o.)
"DLA" = C:\WINDOWS\System32\DLA\DLACTRLW.EXE [09/08/2005 04:20 AM | 00,122,940 | ---- | M] (Sonic Solutions)
"DMXLauncher" = C:\Program Files\Dell\Media Experience\DMXLauncher.exe [11/01/2005 02:12 AM | 00,094,208 | ---- | M] ()
"dscactivate" = "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [11/15/2007 10:24 AM | 00,016,384 | ---- | M] ( )
"ISUSPM" = "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler [03/20/2006 06:34 PM | 00,213,936 | ---- | M] (Macrovision Corporation)
"ISUSPM Startup" = "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup [03/20/2006 06:34 PM | 00,213,936 | ---- | M] (Macrovision Corporation)
"ISUSScheduler" = "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start [03/20/2006 06:34 PM | 00,086,960 | ---- | M] (Macrovision Corporation)
"iTunesHelper" = "C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM | 00,267,048 | ---- | M] (Apple Inc.)
"McAfeeUpdaterUI" = "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey [08/06/2004 03:50 AM | 00,139,320 | ---- | M] (Network Associates, Inc.)
"MSKDetectorExe" = C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall File not found
"Network Associates Error Reporting Service" = "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [10/07/2003 09:48 AM | 00,147,514 | ---- | M] (Network Associates, Inc.)
"OrderReminder" = C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [01/30/2006 11:00 AM | 00,098,304 | R--- | M] (Hewlett-Packard)
"QuickTime Task" = "C:\Program Files\QuickTime\QTTask.exe" -atboottime [03/28/2008 11:37 PM | 00,413,696 | ---- | M] (Apple Inc.)
"ShStatEXE" = "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE [09/22/2004 08:00 PM | 00,094,208 | ---- | M] (Network Associates, Inc.)
"SigmatelSysTrayApp" = stsystra.exe [03/22/2005 10:20 PM | 00,339,968 | ---- | M] (SigmaTel, Inc.)
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM | 00,144,784 | ---- | M] (Sun Microsystems, Inc.)
"UserFaultCheck" = %systemroot%\system32\dumprep 0 -u File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport" = "C:\Program Files\DellSupport\DSAgnt.exe" /startup [03/15/2007 11:09 AM | 00,460,784 | ---- | M] (Gteko Ltd.)
"updateMgr" = C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0 [03/30/2006 04:45 PM | 00,313,472 | R--- | M] (Adobe Systems Incorporated)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
========== Startup Folders ==========
[All Users Startup Folder - C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
[11/04/1999 04:06 PM | 00,113,664 | ---- | M] (Adobe Systems, Inc.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[04/23/2008 03:38 AM | 00,029,696 | ---- | M] (Adobe Systems Incorporated) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[10/29/2003 01:06 AM | 00,024,576 | R--- | M] (BVRP Software) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
[Dvid Startup Folder - C:\Documents and Settings\Dvid\Start Menu\Programs\Startup]
========== BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
HKLM CLSID: (Adobe PDF Reader Link Helper) - [12/18/2006 04:16 AM | 00,059,032 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
HKLM CLSID: (AVG Safe Search) - [08/26/2008 11:58 PM | 00,455,960 | ---- | M] (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG8\avgssie.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
HKLM CLSID: () - [05/31/2005 01:04 AM | 00,853,672 | ---- | M] (Safer Networking Limited) C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
HKLM CLSID: (DriveLetterAccess) - [09/08/2005 04:20 AM | 00,110,652 | ---- | M] (Sonic Solutions) C:\WINDOWS\system32\DLA\DLASHX_W.DLL
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
HKLM CLSID: (SSVHelper Class) - [06/10/2008 04:27 AM | 00,509,328 | ---- | M] (Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
HKLM CLSID: (CBrowserHelperObject Object) - [02/22/2006 06:00 PM | 00,094,208 | ---- | M] (Dell Inc.) c:\Program Files\BAE\BAE.dll
========== Toolbars ==========
========== AppInit_Dlls ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls]
"avgrsstx.dll" - [08/26/2008 11:58 PM | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgrsstx.dll
========== HKLM Security Providers ==========
========== HKLM Winlogon Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
"Explorer.exe" - [06/13/2007 05:23 AM | 01,033,216 | ---- | M] (Microsoft Corporation) C:\WINDOWS\explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit]
"C:\WINDOWS\system32\userinit.exe" - [08/04/2004 04:00 AM | 00,024,576 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost]
"logonui.exe" - [08/04/2004 04:00 AM | 00,514,560 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\logonui.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet]
"rundll32 shell32" - [10/25/2007 10:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
"Control_RunDLL "sysdm.cpl"" - [08/04/2004 04:00 AM | 00,298,496 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
========== User's Winlogon Settings ==========
========== Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c00B6F64]
"DllName" = C:\WINDOWS\system32\__c00B6F64.dat [08/28/2008 11:37 PM | 00,025,088 | ---- | M] ()
========== Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoCDBurning" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername" = 0
"legalnoticecaption" =
"legalnoticetext" =
"shutdownwithoutlogon" = 1
"undockwithoutlogon" = 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
========== Lsa Authentication Packages ==========
========== Lsa Security Packages ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe [08/04/2004 04:00 AM | 00,140,800 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe File not found
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe File not found
"%windir%\Network Diagnostic\xpnetdiag.exe" = C:\WINDOWS\network diagnostic\xpnetdiag.exe [10/10/2006 07:44 AM | 00,557,568 | ---- | M] (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe [03/30/2008 10:36 AM | 20,638,504 | ---- | M] (Apple Inc.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe File not found
"C:\Program Files\SightSpeed\SightSpeed.exe" = C:\Program Files\SightSpeed\SightSpeed.exe File not found
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe [08/28/2008 12:55 PM | 00,641,304 | ---- | M] (AVG Technologies CZ, s.r.o.)
========== Desktop Components ==========
========== Safeboot Options ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell" = cmd.exe
========== Disabled MsConfig Items ==========
Unable to open key or key not present!
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[08/11/2004 04:15 PM | 00,000,000 | ---- | M] () C:\AUTOEXEC.BAT [ NTFS ]
========== MountPoints2 ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55b93b9b-2591-11db-ab0d-001372d74ada}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55b93b9b-2591-11db-ab0d-001372d74ada}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 10:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55b93b9b-2591-11db-ab0d-001372d74ada}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6e0b9114-2822-11db-ab18-001372d74ada}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6e0b9114-2822-11db-ab18-001372d74ada}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 10:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6e0b9114-2822-11db-ab18-001372d74ada}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a7fc7034-5d0c-11dd-aef8-001372d74ada}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a7fc7034-5d0c-11dd-aef8-001372d74ada}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 10:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a7fc7034-5d0c-11dd-aef8-001372d74ada}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ffc0cca6-c4e8-11db-ac39-001372d74ada}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ffc0cca6-c4e8-11db-ac39-001372d74ada}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 10:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ffc0cca6-c4e8-11db-ac39-001372d74ada}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
========== DNS Name Servers ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{1A145E62-D403-44C5-AE10-1F8C2AA58CE7}]
Servers: | Description:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{67EB938B-5FD9-417B-B238-EF9D67E37B5E}]
Servers: | Description:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{8FF1CE27-F806-4D11-9B01-329D077D305F}]
Servers: | Description: Intel® PRO/100 VE Network Connection
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{DF51AE47-1999-4124-95BE-AAD174553B57}]
Servers: | Description: 1394 Net Adapter
========== Hosts File ==========
HOSTS File = (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
========== Files/Folders - Created Within 30 days ==========
[08/25/2008 11:23 PM | ---D | C] - C:\SDFix
[08/27/2008 12:04 AM | -H-D | C] - C:\$AVG8.VAULT$
[08/26/2008 11:58 PM | 00,075,236 | ---- | C] () - C:\WINDOWS\System32\drivers\Avg\microavi.avg
[08/26/2008 11:58 PM | 00,211,986 | ---- | C] () - C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[08/26/2008 11:58 PM | 06,061,540 | ---- | C] () - C:\WINDOWS\System32\drivers\Avg\avi7.avg
[08/26/2008 11:58 PM | 26,642,915 | ---- | C] () - C:\WINDOWS\System32\drivers\Avg\incavi.avm
[08/26/2008 11:58 PM | 00,026,824 | ---- | C] (AVG Technologies CZ, s.r.o.) - C:\WINDOWS\System32\drivers\avgmfx86.sys
[08/26/2008 11:58 PM | 00,096,520 | ---- | C] (AVG Technologies CZ, s.r.o.) - C:\WINDOWS\System32\drivers\avgldx86.sys
[08/26/2008 11:58 PM | ---D | C] - C:\WINDOWS\System32\drivers\Avg
[08/20/2008 07:15 PM | 00,025,088 | ---- | C] () - C:\WINDOWS\System32\__c00B6F64.dat
[08/26/2008 11:30 PM | 00,004,344 | ---- | C] () - C:\WINDOWS\System32\tmp.reg
[08/26/2008 11:30 PM | 00,025,600 | ---- | C] () - C:\WINDOWS\System32\WS2Fix.exe
[08/26/2008 11:30 PM | 00,040,960 | ---- | C] () - C:\WINDOWS\System32\swsc.exe
[08/26/2008 11:30 PM | 00,051,200 | ---- | C] () - C:\WINDOWS\System32\dumphive.exe
[08/26/2008 11:30 PM | 00,053,248 | ---- | C] (
http://www.beyondlogic.org) - C:\WINDOWS\System32\Process.exe
[08/26/2008 11:30 PM | 00,079,360 | ---- | C] (SteelWerX) - C:\WINDOWS\System32\swxcacls.exe
[08/26/2008 11:30 PM | 00,082,432 | ---- | C] (S!Ri.URZ) - C:\WINDOWS\System32\404Fix.exe
[08/26/2008 11:30 PM | 00,082,432 | ---- | C] (S!Ri.URZ) - C:\WINDOWS\System32\IEDFix.C.exe
[08/26/2008 11:30 PM | 00,086,528 | ---- | C] (S!Ri.URZ) - C:\WINDOWS\System32\VACFix.exe
[08/26/2008 11:30 PM | 00,088,576 | ---- | C] (S!Ri.URZ) - C:\WINDOWS\System32\AntiXPVSTFix.exe
[08/26/2008 11:30 PM | 00,135,168 | ---- | C] (SteelWerX) - C:\WINDOWS\System32\swreg.exe
[08/26/2008 11:30 PM | 00,288,417 | ---- | C] (S!Ri) - C:\WINDOWS\System32\SrchSTS.exe
[08/26/2008 11:30 PM | 00,289,144 | ---- | C] (S!Ri) - C:\WINDOWS\System32\VCCLSID.exe
[08/26/2008 11:58 PM | 00,010,520 | ---- | C] (AVG Technologies CZ, s.r.o.) - C:\WINDOWS\System32\avgrsstx.dll
[08/25/2008 11:28 PM | ---D | C] - C:\WINDOWS\ERUNT
[08/26/2008 11:58 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\avg8
[08/01/2008 12:29 AM | ---D | C] - C:\Documents and Settings\Dvid\Local Settings\Application Data\Wildtangent
[08/26/2008 11:58 PM | 00,001,507 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[08/26/2008 11:43 PM | 48,367,896 | ---- | C] (AVG Technologies) - C:\Documents and Settings\Dvid\Desktop\avg_free_stf_en_8_138a1332.exe
[08/27/2008 10:05 PM | 00,027,136 | ---- | C] () - C:\Documents and Settings\Dvid\Desktop\For Exhibit 8.doc
[08/27/2008 10:32 PM | 00,001,734 | ---- | C] () - C:\Documents and Settings\Dvid\Desktop\HijackThis.lnk
[08/26/2008 11:58 PM | ---D | C] - C:\Program Files\AVG
[08/27/2008 10:32 PM | ---D | C] - C:\Program Files\Trend Micro
========== Files/Folders - Modified Within 30 days ==========
[08/26/2008 11:58 PM | 06,061,540 | ---- | M] () - C:\WINDOWS\System32\drivers\Avg\avi7.avg
[08/27/2008 07:27 PM | 00,075,236 | ---- | M] () - C:\WINDOWS\System32\drivers\Avg\microavi.avg
[08/27/2008 07:27 PM | 26,642,915 | ---- | M] () - C:\WINDOWS\System32\drivers\Avg\incavi.avm
[08/27/2008 12:00 AM | 00,211,986 | ---- | M] () - C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[08/26/2008 11:35 PM | 00,000,686 | ---- | M] () - C:\WINDOWS\System32\drivers\etc\HOSTS
[08/26/2008 11:58 PM | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) - C:\WINDOWS\System32\drivers\avgmfx86.sys
[08/26/2008 11:58 PM | 00,096,520 | ---- | M] (AVG Technologies CZ, s.r.o.) - C:\WINDOWS\System32\drivers\avgldx86.sys
[4 C:\WINDOWS\System32\*.tmp files]
[08/14/2008 09:52 PM | 00,082,432 | ---- | M] (S!Ri.URZ) - C:\WINDOWS\System32\IEDFix.C.exe
[08/18/2008 12:19 PM | 00,082,432 | ---- | M] (S!Ri.URZ) - C:\WINDOWS\System32\404Fix.exe
[08/23/2008 08:34 PM | 00,002,206 | ---- | M] () - C:\WINDOWS\System32\wpa.dbl
[08/26/2008 08:19 PM | 00,088,576 | ---- | M] (S!Ri.URZ) - C:\WINDOWS\System32\AntiXPVSTFix.exe
[08/26/2008 11:35 PM | 00,004,344 | ---- | M] () - C:\WINDOWS\System32\tmp.reg
[08/26/2008 11:58 PM | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) - C:\WINDOWS\System32\avgrsstx.dll
[08/28/2008 11:37 PM | 00,025,088 | ---- | M] () - C:\WINDOWS\System32\__c00B6F64.dat
[08/14/2008 12:52 AM | 00,001,374 | ---- | M] () - C:\WINDOWS\imsins.BAK
[08/28/2008 10:07 PM | 00,000,512 | ---- | M] () - C:\WINDOWS\randseed.rnd
[08/28/2008 11:47 PM | 00,002,048 | --S- | M] () - C:\WINDOWS\bootstat.dat
[08/28/2008 11:48 PM | 00,054,156 | -H-- | M] () - C:\WINDOWS\QTFont.qfn
[08/11/2008 06:12 PM | 00,000,284 | ---- | M] () - C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[08/28/2008 11:47 PM | 00,000,006 | -H-- | M] () - C:\WINDOWS\tasks\SA.DAT
[08/27/2008 11:14 PM | 00,196,096 | ---- | M] () - C:\Documents and Settings\Dvid\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[08/28/2008 11:46 PM | 04,240,656 | -H-- | M] () - C:\Documents and Settings\Dvid\Local Settings\Application Data\IconCache.db
[08/21/2008 09:09 PM | 00,002,137 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[08/26/2008 11:58 PM | 00,001,507 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[08/26/2008 11:47 PM | 48,367,896 | ---- | M] (AVG Technologies) - C:\Documents and Settings\Dvid\Desktop\avg_free_stf_en_8_138a1332.exe
[08/27/2008 10:05 PM | 00,027,136 | ---- | M] () - C:\Documents and Settings\Dvid\Desktop\For Exhibit 8.doc
[08/27/2008 10:32 PM | 00,001,734 | ---- | M] () - C:\Documents and Settings\Dvid\Desktop\HijackThis.lnk
< End of report >