OTL.Txt
OTL logfile created on: 7/15/2009 11:47:18 AM - Run 1
OTL by OldTimer - Version 3.0.7.1 Folder = C:\Documents and Settings\Chan\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.98 Gb Total Physical Memory | 1.45 Gb Available Physical Memory | 73.09% Memory free
3.31 Gb Paging File | 2.95 Gb Available in Paging File | 88.99% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 60.69 Gb Total Space | 30.44 Gb Free Space | 50.16% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CHANMAC
Current User Name: Chan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Program Files\VMware\VMware Tools\vmacthlp.exe (VMware, Inc.)
PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\System32\IRW.exe (Apple Inc.)
PRC - C:\Program Files\Boot Camp\KbdMgr.exe (Apple Inc.)
PRC - C:\Program Files\UltraMon\UltraMon.exe (Realtime Soft)
PRC - C:\Program Files\Silicon Image\57xx SteelVine\SteelVineManager.exe ()
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
PRC - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\UltraMon\UltraMonTaskbar.exe (Realtime Soft)
PRC - C:\Program Files\Silicon Image\57xx SteelVine\SteelVine.exe ()
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\AppleOSSMgr.exe ()
PRC - C:\WINDOWS\System32\AppleTimeSrv.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Prevx\prevx.exe (Prevx)
PRC - C:\Program Files\IDrive\IDriveE Service.exe (Pro Softnet Corporation)
PRC - C:\Program Files\IDrive\IDrivePlugin.exe ()
PRC - C:\Program Files\IDrive\IDriveETray.exe (Pro Softnet Corp.)
PRC - C:\Program Files\IDrive\IDriveEBackground.exe (Pro Softnet Corp.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Prevx\prevx.exe (Prevx)
PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Program Files\EasyPHP 3.0\EasyPHP.exe (EasyPHP)
PRC - C:\Program Files\EasyPHP 3.0\apache\bin\apache.exe (Apache Software Foundation)
PRC - C:\Program Files\EasyPHP 3.0\apache\bin\apache.exe (Apache Software Foundation)
PRC - C:\Program Files\EasyPHP 3.0\mysql\bin\mysqld.exe ()
PRC - C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe (Adobe Systems Incorporated)
PRC - C:\Documents and Settings\Chan\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ========== SRV - (57xx SteelVine Manager [Auto | Running]) -- C:\Program Files\Silicon Image\57xx SteelVine\SteelVine.exe ()
SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AppleOSSMgr [Auto | Running]) -- C:\WINDOWS\System32\AppleOSSMgr.exe ()
SRV - (AppleTimeSrv [Auto | Running]) -- C:\WINDOWS\System32\AppleTimeSrv.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\System32\ati2sgag.exe ()
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CSIScanner [Auto | Running]) -- C:\Program Files\Prevx\prevx.exe (Prevx)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gupdate1c9888ffbf1372 [Auto | Stopped]) -- C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriveE Service [Auto | Running]) -- C:\Program Files\IDrive\IDriveE Service.exe (Pro Softnet Corporation)
SRV - (IDrivePlugin [Auto | Running]) -- C:\Program Files\IDrive\IDrivePlugin.exe ()
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Microsoft Office Groove Audit Service [On_Demand | Stopped]) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (VMTools [Auto | Stopped]) -- C:\Program Files\VMware\VMware Tools\VMwareService.exe (VMware, Inc.)
SRV - (VMware Physical Disk Helper Service [Auto | Running]) -- C:\Program Files\VMware\VMware Tools\vmacthlp.exe (VMware, Inc.)
========== Driver Services (SafeList) ========== DRV - (applebt [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\applebt.sys (Apple Inc.)
DRV - (ASPI [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ASPI32.sys (Adaptec)
DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (BCM43XX [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\bcmwl5.sys (Broadcom Corporation)
DRV - (BthKicker [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\BthKicker.sys (Apple Inc.)
DRV - (DgiVecp [Auto | Stopped]) -- C:\WINDOWS\System32\Drivers\DgiVecp.sys (Samsung Electronics Co., Ltd.)
DRV - (es1371 [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\es1371mp.sys (Creative Technology Ltd.)
DRV - (EuMusDesignVirtualAudioCableWdm_s2x [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\vacs2xkd.sys (Eugene V. Muzychenko)
DRV - (gameenum [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (hgfs [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\hgfs.sys (VMware, Inc.)
DRV - (IntcAzAudAddService [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (IRRemoteFlt [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\IRFilter.sys (Apple Inc.)
DRV - (KeyAgent [Auto | Running]) -- C:\WINDOWS\System32\drivers\KeyAgent.sys (Apple Inc.)
DRV - (KeyMagic [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\KeyMagic.sys (Apple Inc.)
DRV - (MacHALDriver [Auto | Running]) -- C:\WINDOWS\System32\drivers\MacHALDriver.sys (Apple Inc.)
DRV - (PCnet [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\pcntpci5.sys (AMD Inc.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (pxscan [Boot | Running]) -- C:\WINDOWS\System32\drivers\pxscan.sys (Prevx)
DRV - (pxsec [Boot | Running]) -- C:\WINDOWS\System32\drivers\pxsec.sys (Prevx)
DRV - (RimUsb [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\RimUsb.sys (Research In Motion Limited)
DRV - (RimVSerPort [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\RimSerial.sys (Research in Motion Ltd)
DRV - (ROOTMODEM [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (SCDEmu [System | Running]) -- C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys ()
DRV - (UltraMonMirror [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\UltraMonMirror.sys (Realtime Soft)
DRV - (UltraMonUtility [Auto | Running]) -- C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys (Realtime Soft)
DRV - (USBAAPL [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (VMMEMCTL [Auto | Running]) -- C:\Program Files\VMware\VMware Tools\Drivers\memctl\vmmemctl.sys (VMware, Inc.)
DRV - (vmmouse [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\vmmouse.sys (VMware, Inc.)
DRV - (vmscsi [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\vmscsi.sys (VMware, Inc.)
DRV - (vmxnet [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\vmxnet.sys (VMware, Inc.)
DRV - (vmx_svga [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\vmx_svga.sys (VMware, Inc.)
DRV - (yukonwxp [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\yk51x86.sys (Marvell)
========== Standard Registry (All) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn...st/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft...amp;ar=iesearchIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft...p...&ar=msnhomeIE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\System32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.update: false
FF - prefs.js..extensions.enabledItems: {135CFDA1-9F10-4731-8B12-D123A4DEB976}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}:5.0.14
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}:6.0.04
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.4
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.29.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2008/12/10 18:27:10 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2009/07/14 10:53:59 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/04/01 16:37:14 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/04/01 16:37:14 | 00,000,000 | ---D | M]
[2008/07/12 19:01:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Chan\Application Data\mozilla\Extensions
[2008/07/12 19:01:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Chan\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/01 07:51:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Chan\Application Data\mozilla\Firefox\Profiles\3fpmcklp.default\extensions
[2009/03/19 09:31:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Chan\Application Data\mozilla\Firefox\Profiles\3fpmcklp.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2009/04/19 11:32:15 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/04/19 11:32:15 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{135CFDA1-9F10-4731-8B12-D123A4DEB976}
[2009/04/01 10:10:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/02/14 00:17:16 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}
[2008/02/04 00:10:19 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
[2009/04/01 10:10:44 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/01 10:10:44 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/02/06 13:44:28 | 01,447,296 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/04/01 10:10:45 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006/10/26 21:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2007/05/10 22:52:34 | 00,095,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009/02/04 14:15:44 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/02/04 14:15:44 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/02/04 14:15:44 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/02/04 14:15:44 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/02/04 14:15:44 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/02/04 14:15:44 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/02/04 14:15:44 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2007/11/20 17:52:00 | 02,884,992 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPSWF32.dll
[2008/12/10 01:31:29 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/12/10 01:31:29 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/12/10 01:31:29 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/12/13 11:30:58 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/12/10 01:31:29 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/12/10 01:31:29 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/12/10 01:31:29 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (0 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.29.0\gears.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O4 - HKLM..\Run: [57xxSteelVine] C:\Program Files\Silicon Image\57xx SteelVine\SteelVineManager.exe ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apple_KbdMgr] C:\Program Files\Boot Camp\KbdMgr.exe (Apple Inc.)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.CPL (Microsoft Corporation)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IRW] C:\WINDOWS\System32\IRW.exe (Apple Inc.)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKLM..\Run: [UltraMon] C:\Program Files\UltraMon\UltraMon.exe (Realtime Soft)
O4 - HKLM..\Run: [VMware Tools] C:\Program Files\VMware\VMware Tools\VMwareTray.exe (VMware, Inc.)
O4 - HKLM..\Run: [VMware User Process] C:\Program Files\VMware\VMware Tools\VMwareUser.exe (VMware, Inc.)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [IDriveE Startup] C:\Program Files\IDrive\IDrvieEStartup.exe (Pro Softnet Corporation)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Chan\Start Menu\Programs\Startup\IDrive Tray.lnk = C:\Program Files\IDrive\IDriveEReg2ini.exe (Pro Softnet Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ExSearchOptions = 105433
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\npjpi160_04.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.29.0\gears.dll (Google Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9}
http://www.blackberr...re/AxLoader.cab (AxLoaderPassword Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.2_16)
O16 - DPF: {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9}
http://mobileapps.bl...re/AxLoader.cab (RIM AxLoader)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\System32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\System32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\WlNotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\System32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\System32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\System32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/02 21:47:11 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ========== [2009/07/15 11:45:18 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Chan\Desktop\OTL.exe
[2009/07/15 11:19:08 | 00,192,506 | ---- | C] () -- C:\Documents and Settings\Chan\My Documents\admob-mobile-metrics-march-09.pdf
[2009/07/15 11:18:56 | 00,249,521 | ---- | C] () -- C:\Documents and Settings\Chan\My Documents\admob-mobile-metrics-april-09.pdf
[2009/07/15 11:04:39 | 00,568,203 | ---- | C] () -- C:\Documents and Settings\Chan\My Documents\QxMD Phone Comparison.pptx
[2009/07/15 10:01:32 | 03,761,849 | ---- | C] () -- C:\Documents and Settings\Chan\Desktop\Rim Apps(2).zip
[2009/07/14 17:10:36 | 00,685,904 | ---- | C] () -- C:\Documents and Settings\Chan\My Documents\QxMD Medical Software Technical.pptx
[2009/07/14 11:30:07 | 01,182,056 | ---- | C] () -- C:\Documents and Settings\Chan\My Documents\QxMD Medical Software.pptx
[2009/07/14 10:53:52 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/07/14 10:53:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Chan\Local Settings\Application Data\Temp
[2009/07/11 16:44:12 | 00,001,445 | ---- | C] () -- C:\Documents and Settings\Chan\Desktop\backButton.png
[2009/07/11 16:42:16 | 00,001,130 | ---- | C] () -- C:\Documents and Settings\Chan\Desktop\darkCancelButton.png
[2009/07/11 16:42:07 | 00,001,080 | ---- | C] () -- C:\Documents and Settings\Chan\Desktop\lightCancelButton.png
[2009/07/11 16:39:43 | 00,001,469 | ---- | C] () -- C:\Documents and Settings\Chan\Desktop\saveButton.png
[2009/07/11 16:33:10 | 00,004,096 | ---- | C] () -- C:\Documents and Settings\Chan\Desktop\._Picture 1.png
[2009/07/11 16:32:30 | 00,022,517 | ---- | C] () -- C:\Documents and Settings\Chan\Desktop\Picture 1.png
[2009/07/08 12:44:42 | 12,296,5176 | ---- | C] (Research In Motion) -- C:\Documents and Settings\Chan\Desktop\BlackBerry_JDE_4.3.0.exe
[2009/07/08 10:48:50 | 00,000,886 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/07/08 10:48:49 | 00,000,882 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/07/08 10:39:49 | 87,215,737 | ---- | C] () -- C:\Documents and Settings\Chan\Desktop\4.7.1.40.simpackage.fledge_niagara.zip
[2009/07/08 10:32:44 | 00,004,096 | ---- | C] () -- C:\Documents and Settings\Chan\Desktop\._ECGs new July 08
[2009/07/07 21:22:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Chan\Desktop\ECGs new July 08
[2009/06/26 18:31:56 | 00,002,944 | ---- | C] () -- C:\Documents and Settings\Chan\Desktop\ParticleBlack.png
[2009/06/26 18:26:38 | 00,004,904 | ---- | C] () -- C:\Documents and Settings\Chan\Desktop\ParticleWhite.png
[2009/06/26 18:22:05 | 00,002,176 | ---- | C] () -- C:\Documents and Settings\Chan\Desktop\Particle.png
[2009/06/25 10:08:43 | 00,000,599 | ---- | C] () -- C:\Documents and Settings\Chan\Desktop\Shortcut to www.lnk
[2009/06/17 19:16:50 | 00,018,627 | ---- | C] () -- C:\Documents and Settings\Chan\My Documents\Software Development Process.docx
[2009/06/15 23:08:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Chan\Desktop\ecg guide html images
[2009/04/28 14:48:26 | 00,000,047 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/04/18 20:02:11 | 00,111,104 | ---- | C] () -- C:\WINDOWS\System32\Nviewlib.dll
[2009/04/18 20:02:11 | 00,107,008 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2009/04/18 20:02:11 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2009/04/18 20:02:11 | 00,020,992 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2009/04/18 20:02:11 | 00,018,944 | ---- | C] () -- C:\WINDOWS\System32\vcedit.dll
[2009/04/18 20:02:11 | 00,009,728 | ---- | C] () -- C:\WINDOWS\System32\vorbisfile.dll
[2009/04/18 20:02:11 | 00,000,887 | ---- | C] () -- C:\WINDOWS\CDMaster.ini
[2009/04/18 20:02:10 | 00,144,384 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2009/02/24 11:27:41 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/02/17 09:55:37 | 00,022,723 | ---- | C] () -- C:\WINDOWS\System32\ssp1ml3.dll
[2008/06/12 22:46:19 | 00,055,808 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
[2007/07/27 05:00:00 | 00,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2007/07/27 05:00:00 | 00,000,710 | ---- | C] () -- C:\WINDOWS\win.ini
[2007/07/27 05:00:00 | 00,000,325 | ---- | C] () -- C:\WINDOWS\System32\ntnet.drv
[2007/07/27 05:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ========== [1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/07/15 16:49:32 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/07/15 16:49:31 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/07/15 16:49:27 | 21,288,30464 | -HS- | M] () -- C:\hiberfil.sys
[2009/07/15 11:45:23 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Chan\Desktop\OTL.exe
[2009/07/15 11:26:16 | 00,685,904 | ---- | M] () -- C:\Documents and Settings\Chan\My Documents\QxMD Medical Software Technical.pptx
[2009/07/15 11:19:08 | 00,192,506 | ---- | M] () -- C:\Documents and Settings\Chan\My Documents\admob-mobile-metrics-march-09.pdf
[2009/07/15 11:18:56 | 00,249,521 | ---- | M] () -- C:\Documents and Settings\Chan\My Documents\admob-mobile-metrics-april-09.pdf
[2009/07/15 11:04:39 | 00,568,203 | ---- | M] () -- C:\Documents and Settings\Chan\My Documents\QxMD Phone Comparison.pptx
[2009/07/15 10:53:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/07/15 10:53:00 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/07/15 10:09:40 | 00,000,256 | ---- | M] () -- C:\WINDOWS\System32\pool.bin
[2009/07/15 10:01:35 | 03,761,849 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\Rim Apps(2).zip
[2009/07/15 09:54:12 | 00,435,590 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/07/15 09:54:12 | 00,068,360 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/07/15 09:54:11 | 00,512,960 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/14 17:11:13 | 01,182,056 | ---- | M] () -- C:\Documents and Settings\Chan\My Documents\QxMD Medical Software.pptx
[2009/07/14 17:06:21 | 00,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/07/13 13:36:34 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/13 13:36:12 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/13 10:11:25 | 00,006,148 | ---- | M] () -- C:\.DS_Store
[2009/07/11 16:44:12 | 00,001,445 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\backButton.png
[2009/07/11 16:42:16 | 00,001,130 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\darkCancelButton.png
[2009/07/11 16:42:07 | 00,001,080 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\lightCancelButton.png
[2009/07/11 16:39:43 | 00,001,469 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\saveButton.png
[2009/07/11 16:33:10 | 00,004,096 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\._Picture 1.png
[2009/07/11 16:32:30 | 00,022,517 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\Picture 1.png
[2009/07/08 12:47:50 | 12,296,5176 | ---- | M] (Research In Motion) -- C:\Documents and Settings\Chan\Desktop\BlackBerry_JDE_4.3.0.exe
[2009/07/08 10:42:03 | 87,215,737 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\4.7.1.40.simpackage.fledge_niagara.zip
[2009/07/08 10:32:47 | 00,006,148 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\.DS_Store
[2009/07/08 10:32:44 | 00,004,096 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\._ECGs new July 08
[2009/06/26 18:31:56 | 00,002,944 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\ParticleBlack.png
[2009/06/26 18:26:38 | 00,004,904 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\ParticleWhite.png
[2009/06/26 18:22:06 | 00,002,176 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\Particle.png
[2009/06/25 10:08:43 | 00,000,599 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\Shortcut to www.lnk
[2009/06/17 20:34:28 | 00,018,627 | ---- | M] () -- C:\Documents and Settings\Chan\My Documents\Software Development Process.docx
[2009/06/17 17:16:35 | 00,046,385 | ---- | M] () -- C:\Documents and Settings\Chan\Desktop\Downloads.xlsx
========== LOP Check ========== [2009/04/28 14:48:26 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/02/04 14:16:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/02/15 08:21:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ALM
[2009/04/18 20:37:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2008/02/14 00:57:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2008/04/13 10:40:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2009/07/08 13:03:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PrevxCSI
[2009/04/26 15:02:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2009/04/19 11:31:46 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Chan\Application Data
[2009/04/18 20:36:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Chan\Application Data\AVS4YOU
[2009/04/28 15:03:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Chan\Application Data\Azureus
[2008/04/05 09:18:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Chan\Application Data\MSNInstaller
[2009/03/19 10:55:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Chan\Application Data\Notepad++
[2009/07/14 13:09:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Chan\Application Data\OpenOffice.org2
[2008/10/12 10:49:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Chan\Application Data\Research In Motion
[2009/04/19 11:31:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Chan\Application Data\Softplicity
[2007/07/27 05:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/07/15 10:53:00 | 00,000,882 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2009/07/15 10:53:00 | 00,000,886 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2009/07/15 16:49:32 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ========== < End of report >
-------------------------------------------------
Extras.Txt
OTL Extras logfile created on: 7/15/2009 11:47:18 AM - Run 1
OTL by OldTimer - Version 3.0.7.1 Folder = C:\Documents and Settings\Chan\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.98 Gb Total Physical Memory | 1.45 Gb Available Physical Memory | 73.09% Memory free
3.31 Gb Paging File | 2.95 Gb Available in Paging File | 88.99% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 60.69 Gb Total Space | 30.44 Gb Free Space | 50.16% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CHANMAC
Current User Name: Chan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 (Microsoft Corporation)
C:\WINDOWS\system32\javaw.exe:*:Enabled:Java Platform SE binary (Sun Microsystems, Inc.)
C:\Program Files\Research In Motion\BlackBerry JDE 4.0\bin\fledge.exe:*:Enabled:fledge File not found
C:\Program Files\RealVNC\VNC4\winvnc4.exe:*:Enabled:VNC Server Free Edition for Win32 (RealVNC Ltd.)
C:\j2sdk1.4.2_16\bin\javaw.exe:*:Enabled:javaw File not found
C:\Program Files\Java\jdk1.6.0_04\bin\javaw.exe:*:Enabled:Java Platform SE binary (Sun Microsystems, Inc.)
C:\Program Files\Java\jdk1.5.0_14\bin\javaw.exe:*:Enabled:Java 2 Platform Standard Edition binary (Sun Microsystems, Inc.)
C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus (Azureus Inc)
C:\Program Files\Research In Motion\BlackBerry JDE 4.0.2\bin\fledge.exe:*:Enabled:BlackBerry Handheld Simulator (Research In Motion Limited)
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\Research In Motion\BlackBerry Device Simulators 4.2.2\4.2.2.163 (8310-Rogers)\fledge.exe:*:Enabled:BlackBerry Handheld Simulator (Research In Motion Limited)
C:\Program Files\Research In Motion\BlackBerry Device Simulators 4.2.1\4.2.1.96 (8100-ATT)\fledge.exe:*:Enabled:BlackBerry Handheld Simulator (Research In Motion Limited)
C:\Program Files\Research In Motion\BlackBerry JDE 4.2.0\simulator\fledge.exe:*:Enabled:BlackBerry Handheld Simulator (Research In Motion Limited)
C:\Program Files\Java\jdk1.5.0_14\bin\java.exe:*:Enabled:Java 2 Platform Standard Edition binary (Sun Microsystems, Inc.)
C:\Documents and Settings\Chan\Desktop\RIM ARCHIVE\RIM Simulators\bold\fledge.exe:*:Enabled:BlackBerry Handheld Simulator (Research In Motion Limited)
C:\Program Files\Research In Motion\BlackBerry Smartphone Simulators 4.3.0\4.3.0.124 (8330)\fledge.exe:*:Enabled:BlackBerry Handheld Simulator (Research In Motion Limited)
C:\Program Files\Research In Motion\BlackBerry Smartphone Simulators 4.7.0\4.7.0.41 (9530)\fledge.exe:*:Enabled:BlackBerry Handheld Simulator (Research In Motion Limited)
C:\Program Files\Research In Motion\BlackBerry Smartphone Simulators 4.6.0\4.6.0.190 (9000)\fledge.exe:*:Enabled:BlackBerry Handheld Simulator (Research In Motion Limited)
C:\Program Files\Research In Motion\BlackBerry JDE 4.6.1\simulator\fledge.exe:*:Enabled:BlackBerry Handheld Simulator (Research In Motion Limited)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\Research In Motion\BlackBerry Smartphone Simulators 4.7.0\4.7.0.75 (9530-Verizon)\fledge.exe:*:Enabled:BlackBerry Handheld Simulator (Research In Motion Limited)
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook (Microsoft Corporation)
C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove (Microsoft Corporation)
C:\Program Files\Research In Motion\BlackBerry JDE 4.7.0\simulator\fledge.exe:*:Enabled:BlackBerry Handheld Simulator (Research In Motion Limited)
C:\Program Files\EasyPHP 3.0\mysql\bin\mysqld.exe:*:Enabled:mysqld ()
C:\Documents and Settings\Chan\Desktop\niagra sim\fledge.exe:*:Enabled:BlackBerry Handheld Simulator File not found
C:\Program Files\Research In Motion\BlackBerry JDE 4.3.0\simulator\fledge.exe:*:Enabled:BlackBerry Handheld Simulator (Research In Motion Limited)
C:\Program Files\Research In Motion\BlackBerry JDE 4.3.0\niagra simulator\fledge.exe:*:Enabled:BlackBerry Handheld Simulator (Research In Motion Limited)
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{034E061B-B3A3-4123-842E-10C1B6B3C8C7}" = BlackBerry Desktop Software 4.7
"{03CAB33F-D1C2-48C6-8766-DAE84DFC25FE}" = Microsoft Sync Framework Services v1.0 (x86)
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{17B9371B-E0A5-4503-B3F8-227F2B71BB2D}" = BlackBerry Smartphone Simulators 4.7.0.41 (9530)
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{217B6086-F978-4C99-9FF5-F0DD9B8E9FAF}" = BlackBerry Device Simulators 4.2.2.163 (8310-Rogers)
"{24133301-751A-4B52-88AB-B7495A3763E7}" = BlackBerry Java Development Environment 4.0.2
"{255050EF-7FE6-43D8-B93C-3323C3835598}" = BlackBerry JDE 4.6.1
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2CD2C0DB-81C3-416B-9FA6-589B9235359B}" = OpenOffice.org 2.4
"{3248F0A8-6813-11D6-A77B-00B0D0150140}" = J2SE Runtime Environment 5.0 Update 14
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java 6 Update 4
"{32A3A4F4-B792-11D6-A78A-00B0D0150140}" = J2SE Development Kit 5.0 Update 14
"{32A3A4F4-B792-11D6-A78A-00B0D0160040}" = Java SE Development Kit 6 Update 4
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{359CAF94-3086-4969-A1B1-43A9F5D1D677}" = BlackBerry Device Software v4.6.1 for the BlackBerry 8520 smartphone
"{3B410500-1802-488E-9EF1-4B11992E0440}" = VMware Tools
"{43602F34-1AA3-44FB-AEB2-D08C2C73743F}" = Paint.NET v3.36
"{4B44DABB-CF3B-46EA-8E2B-23A754D02647}" = BlackBerry Smartphone Simulators 4.6.0.190 (9000)
"{4F3E17F8-F1C8-4A4B-9EB8-1EE2D190CDA9}" = Adobe Setup
"{5022AA3F-26CB-4B07-AEBD-419D6DAB002B}" = 57xx SteelVine
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6C65C8BB-B975-44D4-A8F5-61129CDDF4C3}" = BlackBerry Email and MDS Services Simulators 4.1.2
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7148F0A8-6813-11D6-A77B-00B0D0142160}" = Java 2 Runtime Environment, SE v1.4.2_16
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{81DCEC2B-E069-4985-978B-3230292AB744}" = NTI Shadow
"{83AC2F9F-495B-4119-ABB8-507BF0456EC9}" = BlackBerry Device Simulators 4.2.1.96 (8100-ATT)
"{87B0CC92-9E8E-42E1-85E5-49BCE3C1012C}" = BlackBerry JDE 4.3.0
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8BF340E6-1A28-47DD-913A-07E1B16E38AD}" = BlackBerry Device Software v4.6.1 for the BlackBerry 8900 smartphone
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{993A94A9-DCE3-4774-B35D-D8C74FC1E0BE}" = Royale Remixed Theme
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A177EBE2-10B5-440E-80EB-6D9AFEBED650}" = BlackBerry Smartphone Simulators 4.3.0.124 (8330)
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A80B8B18-D9ED-4CEC-A50F-9D390251A836}" = BlackBerry Device Software v4.5.0 for the BlackBerry 8820 smartphone
"{A8BD5A60-E843-46DC-8271-ABF20756BE0F}" = Microsoft Sync Framework Runtime v1.0 (x86)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AF2F6CF8-5A5E-3EB3-BCCC-3777D6A7A79D}" = Google Gears
"{AFDFC350-C142-4790-BE12-8357AECD028F}" = SyncToy 2.0 (x86)
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B784FE9A-B271-4A93-AD97-E0C50190AEB7}" = BlackBerry JDE 4.2.0
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BA2898D6-6270-4B00-AA32-4E82867973CF}" = BlackBerry Smartphone Simulators 4.7.0.75 (9530-Verizon)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{CD49361E-3FE6-457E-90A1-9C59E29B5D02}" = Java DB 10.3.1.4
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}" = WinZip 12.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E67FF1A2-23C1-4102-84E9-42115F77AD32}" = UltraMon
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
"{F0E45628-1218-4865-A516-8E8A54272ADC}" = Boot Camp Services
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F508F0F9-0D16-4472-A0E3-F2A4A9C81C6F}" = BlackBerry Device Software v4.6.1 for the BlackBerry 8900 smartphone
"{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}" = iTunes
"{FA38652E-98FB-4095-9ACB-44E82C965C20}" = BlackBerry JDE 4.7.0
"059BF941BA77F24DED9444B45BB0DAA5353F86EB" = Windows Driver Package - Apple Inc. System (06/21/2007 2.0.0.0)
"0936416DB5978E29D553FACF9DD6F3EFBA1929DA" = Windows Driver Package - Apple Inc. Apple Trackpad (08/28/2007 2.0.1.4)
"0EEF0136F93FA6C5AB723AADEA61FF550D8C60FB" = Windows Driver Package - Broadcom (BCM43XX) Net (01/08/2007 4.80.75.0)
"181B29655BDD6EA3FC483A7E4D1C2ED7735873F0" = Windows Driver Package - Apple Inc. Apple Keyboard (08/30/2007 2.0.1.4)
"18BB9B0552BA675902E31409A34F929D9C9AD56C" = Windows Driver Package - Intel (e1express) Net (04/03/2006 9.3.39.0)
"4Musics MP3 Bitrate Changer 5.0_is1" = 4Musics MP3 Bitrate Changer 5.0
"5F8BE32FAE3D6BC77B512F7B0624D7B6C8A26EFB" = Windows Driver Package - Apple Inc. Apple Bluetooth Enabler (06/27/2007 2.0.0.1)
"6784A318842714811EC3F8409C3C0F7983B90972" = Windows Driver Package - Apple Inc. Apple Built-in iSight (04/09/2007 1.3.0.0)
"6AB59209597E0F6B986EC8E976521FDF0A696C9D" = Windows Driver Package - Marvell (yukonwxp) Net (03/23/2007 10.12.7.3)
"6AEF368351694A266BAB82596EEA968C73E8FC87" = Windows Driver Package - Apple Inc. Apple Trackpad Enabler (08/28/2007 2.0.1.4)
"80087CDF19A4CE2FBB535E7DC99A0E50FFA25589" = Windows Driver Package - Intel (E1000) Net (01/06/2006 8.6.17.0)
"850625E38080EAF5C2644C07A2510A394019973D" = Windows Driver Package - Apple Inc. (applebt) Bluetooth (06/27/2007 2.0.0.1)
"9B19F92D5E3730EA8D0788B248741F6CC2633DBE" = Windows Driver Package - Apple Inc. Apple IR Receiver (07/16/2007 2.0.0.1)
"Active@ ISO Burner v 1.1" = Active@ ISO Burner v 1.1
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe_a04a925a57548091300ada368235fc6" = Adobe Illustrator CS3
"All ATI Software" = ATI - Software Uninstall Utility
"Alt WAV MP3 WMA OGG Converter 7.2 Shareware_is1" = Alt WAV MP3 WMA OGG Converter 7.2
"ATI Display Driver" = ATI Display Driver
"AVS Audio Converter 5.1_is1" = AVS Audio Converter version 5.1
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"Azureus Vuze" = Azureus Vuze
"BlackBerry_{034E061B-B3A3-4123-842E-10C1B6B3C8C7}" = BlackBerry Desktop Software 4.7
"Bridge Building Game" = Bridge Building Game
"CDMaster32" = CDMaster32
"CE031DF97C704035E8B6E570362ABD337ACA4BA5" = Windows Driver Package - Atheros (AR5211) Net (04/05/2007 5.3.0.35)
"D66D0ACEFE4E32CCDF30362ACBB3EAEFB97E9FDE" = Windows Driver Package - Atheros (AR5416) Net (06/26/2007 6.0.3.94)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HijackThis" = HijackThis 2.0.2
"IDrive_is1" = IDrive version 2.2.0 June 12 2008
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"MSNINST" = MSN
"Notepad++" = Notepad++
"NVIDIA Drivers" = NVIDIA Drivers
"PCSI" = Prevx 3.0
"PowerGREP 3" = JGsoft PowerGREP 3 DEMO 3.5.2
"PowerISO" = PowerISO
"RealVNC_is1" = VNC Free Edition 4.1.2
"Samsung ML-2240 Series" = Samsung ML-2240 Series
"Total Audio Converter_is1" = TotalAudioConverter
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"WinRAR archiver" = WinRAR archiver
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 4/2/2009 4:33:36 PM | Computer Name = CHANMAC | Source = Application Hang | ID = 1002
Description = Hanging application DesktopMgr.exe, version 4.7.0.32, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 4/8/2009 1:23:22 PM | Computer Name = CHANMAC | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 4/18/2009 11:34:43 PM | Computer Name = CHANMAC | Source = Application Hang | ID = 1002
Description = Hanging application mp3-mp3.exe, version 5.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 4/18/2009 11:35:00 PM | Computer Name = CHANMAC | Source = Application Hang | ID = 1002
Description = Hanging application CDMaster32.exe, version 6.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 4/19/2009 1:57:13 PM | Computer Name = CHANMAC | Source = Application Error | ID = 1000
Description = Faulting application audioenc.exe, version 2.1.69.114, faulting module
imacf.dll, version 1.1.0.1112, fault address 0x00010f80.
Error - 4/19/2009 1:59:55 PM | Computer Name = CHANMAC | Source = Application Error | ID = 1000
Description = Faulting application audioenc.exe, version 2.1.69.114, faulting module
imacf.dll, version 1.1.0.1112, fault address 0x00012577.
Error - 4/28/2009 5:53:41 PM | Computer Name = CHANMAC | Source = Application Hang | ID = 1002
Description = Hanging application Azureus.exe, version 3.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 4/30/2009 12:26:53 AM | Computer Name = CHANMAC | Source = Google Update | ID = 20
Description =
Error - 4/30/2009 1:38:34 AM | Computer Name = CHANMAC | Source = Application Hang | ID = 1002
Description = Hanging application AudioConverter.exe, version 2.6.1.6, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 7/8/2009 5:21:08 PM | Computer Name = CHANMAC | Source = Application Error | ID = 1000
Description = Faulting application bbdevmgr.exe, version 4.1.0.11, faulting module
bbdevmgr.exe, version 4.1.0.11, fault address 0x00001254.
[ System Events ]
Error - 7/11/2009 7:34:45 PM | Computer Name = CHANMAC | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2
Error - 7/11/2009 7:34:45 PM | Computer Name = CHANMAC | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the VMware Tools Service
service to connect.
Error - 7/14/2009 1:06:36 PM | Computer Name = CHANMAC | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058
Error - 7/14/2009 1:06:36 PM | Computer Name = CHANMAC | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%20
Error - 7/14/2009 1:06:36 PM | Computer Name = CHANMAC | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2
Error - 7/14/2009 1:06:36 PM | Computer Name = CHANMAC | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the VMware Tools Service
service to connect.
Error - 7/15/2009 12:49:46 PM | Computer Name = CHANMAC | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058
Error - 7/15/2009 12:49:46 PM | Computer Name = CHANMAC | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%20
Error - 7/15/2009 12:49:46 PM | Computer Name = CHANMAC | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2
Error - 7/15/2009 12:49:46 PM | Computer Name = CHANMAC | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the VMware Tools Service
service to connect.
< End of report >
-------------------------------------------------
Results.log
GMER 1.0.15.14972 -
http://www.gmer.netRootkit scan 2009-07-15 14:51:28
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
SSDT pxsec.sys (Prevx Realtime Analysis/Prevx) ZwTerminateProcess [0xBA12A680]
INT 0x01 \SystemRoot\system32\DRIVERS\ati2mtag.sys (ATI Radeon WindowsNT Miniport Driver/ATI Technologies Inc.) B953B541
INT 0x03 \SystemRoot\system32\DRIVERS\ati2mtag.sys (ATI Radeon WindowsNT Miniport Driver/ATI Technologies Inc.) B953B5E7
---- Devices - GMER 1.0.15 ----
Device \Driver\BTHUSB \Device\000000a1 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\000000a3 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\001e52eb38bc
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae@imagepath \systemroot\system32\drivers\ovfsthforluqexedqoljnlfdkvraoevlhlodvb.sys
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae@inst 0
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main@ver icv060409
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main@cid 01
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main@bid 2087390783-1993962763-1450960922-682003330
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main@aid 303617
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main@sid 203
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main@feed 0x22 0x64 0x78 0x36 ...
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main@cmddelay 28801
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\delete
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\ff
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\ff@extension \\?\C:\Program Files\Mozilla Firefox\extensions\{135CFDA1-9F10-4731-8B12-D123A4DEB976}
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\ff@version 1
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\injector
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\
[email protected] ovfsthwi.dll
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\
[email protected] ovfsthff.dll
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\tasks
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\tasks\0000000004
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\tasks\0000000004@fn (null)
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\tasks\0000000004@url
http://212.117.188.1.../lmppcsetup.exeReg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\tasks\0000000004@timeout 900
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\tasks\0000000004@type 0
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\main\tasks\0000000004@count 8
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\modules
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\
[email protected] \systemroot\system32\drivers\ovfsthforluqexedqoljnlfdkvraoevlhlodvb.sys
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\
[email protected] \systemroot\system32\ovfsthpwqbmkgmskoqbrmoyeofcxubhcnkjrxv.dll
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\
[email protected] \systemroot\system32\ovfsthkotarjiegogkpvuxqtwsrrmfshthkxlf.dat
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\
[email protected] \systemroot\system32\ovfsthamfnwapiwxjdkoishpvslxsperdjesiw.dll
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\
[email protected] \systemroot\system32\ovfsthofnypjpymtxdgpmwqsuoplwaqofgjboq.dll
Reg HKLM\SYSTEM\ControlSet002\Services\ovfsthjvrgwpfnxttohwwtuklyidfrfrxjibae\
[email protected] \systemroot\system32\ovfsthfhwbtbwwuqkdbjtjnpfvmfsaqtoposoy.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e52eb38bc
---- EOF - GMER 1.0.15 ----