Help - Search - Members - Calendar
Full Version: Infection problems... hijackers, etc.
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
tomhawk23
Infection or hijacker somewhere is causing pop-ups, email notifications, web page hijacks, etc. etc. etc.

Here is my log file. Thank you.

Logfile of HijackThis v1.99.1
Scan saved at 11:29:09 AM, on 1/29/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\hidserv.exe
C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZipToA.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFAGENT.EXE
C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
C:\WINNT\system32\pctspk.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\WINNT\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
C:\Program Files\Common Files\AOL\1116034182\ee\AOLHostManager.exe
C:\Program Files\WxEx\WxEx.exe
C:\PROGRA~1\Compaq\EASYAC~1\EAUSBKBD.EXE
C:\WINNT\system32\intell321.exe
C:\Program Files\Common Files\AOL\1116034182\ee\AOLServiceHost.exe
C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\program files\common files\aol\1116034182\ee\services\antiSpywareApp\ver2_0_7\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1116034182\ee\AOLServiceHost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\Program Files\America Online 9.0a\shellmon.exe
C:\WINNT\explorer.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINNT\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1116034182\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
O4 - HKLM\..\Run: [WxEx] C:\Program Files\WxEx\WxEx.exe
O4 - HKLM\..\Run: [intell321.exe] C:\WINNT\system32\intell321.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b
O4 - HKCU\..\Run: [Iomega Active Disk] C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_2 -reboot 1
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aol.com/molbin/shared/m...83/mcinsctl.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aol.com/molbin/shared/m...,20/mcgdmgr.cab
O16 - DPF: {D9CDEFE3-51BB-4737-A12C-53D9814A148C} (DAX Control) - https://msmail.lh.org/exchweb/controls/DAX.cab
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - C:\WINNT\system32\dcom_13.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Iomega Activity Disk2 - Iomega Corporation - C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
O23 - Service: IomegaAccess - Iomega Corporation - C:\WINNT\system32\IomegaAccess.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINNT\System32\HPHipm11.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe
O23 - Service: ZipToA - Iomega Corporation - C:\WINNT\system32\ZipToA.exe
Mosaic1
We need a sample of these two files please to better help you.

C:\WINNT\system32\dcom_13.dll
C:\WINNT\system32\intell321.exe

Please create a new folder and copy them into that folder. Zip that folder and send it as an attachment to me in email at

Katie_3232AThotmail.com

Replace the AT with an @ so the email works please.

-------------------
You will be restarting into Safe mode later. Here's help if you need it.


To use the F8 key to start Windows 2000 in Safe mode
Restart the computer.
When you see the black-and-white Starting Windows bar at the bottom of the screen, start tapping the F8 key.
In the Windows 2000 Advanced Options Menu, select Safe mode if it is not selected.
If it is not selected, use the arrow keys to select it.
Press Enter.
-----------------------


Restart into Safe Mode.

Go directly to Start >Run and type Hijackthis.
Press enter.


Select these two items and press the fix checked button.

O4 - HKLM\..\Run: [intell321.exe] C:\WINNT\system32\intell321.exe
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - C:\WINNT\system32\dcom_13.dll

---------------

Restart the system.

Download Autoruns from this page:
http://www.sysinternals.com/Utilities/Autoruns.html

Unzip to a folder and the double click on autoruns.exe

Wait until the program has finished running (the status line will show 'Ready')
Under the 'Options' menu, make sure that 'Include Empty Sections' is checked.
Wait again until ready.

Be sure the 'Everything' tab is selected.
Select 'File -> Save' and save the output file.

Copy the contents of the Autoruns text file and post its contents in your next reply here.


Run hijackthis and post the new log.

You may have to reply more than once to fit all the logs into your response. Please be sure the entire contents of all logs is showing in your reponses. Thank you.



We'll probably have more to do.
tomhawk23
I was unable to boot up under safe mode. It keeps giving me the "blue screen of death". As I said in the email intell321.exe did not exist on the system either by what I had done or whatever.
I am posting here a new hijackthis log and the autorun file.

Thanks.

Logfile of HijackThis v1.99.1
Scan saved at 3:15:31 PM, on 1/29/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\hidserv.exe
C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZipToA.exe
C:\WINNT\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFAGENT.EXE
C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
C:\WINNT\system32\pctspk.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINNT\System32\hphmon04.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINNT\system32\taskmgr.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Compaq\EASYAC~1\EAUSBKBD.EXE
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
C:\Program Files\Common Files\AOL\1116034182\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1116034182\ee\AOLServiceHost.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\program files\common files\aol\1116034182\ee\services\antiSpywareApp\ver2_0_7\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1116034182\ee\AOLServiceHost.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\America Online 9.0a\shellmon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINNT\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1116034182\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
O4 - HKLM\..\Run: [WxEx] C:\Program Files\WxEx\WxEx.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b
O4 - HKCU\..\Run: [Iomega Active Disk] C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_2 -reboot 1
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aol.com/molbin/shared/m...83/mcinsctl.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aol.com/molbin/shared/m...,20/mcgdmgr.cab
O16 - DPF: {D9CDEFE3-51BB-4737-A12C-53D9814A148C} (DAX Control) - https://msmail.lh.org/exchweb/controls/DAX.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Iomega Activity Disk2 - Iomega Corporation - C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
O23 - Service: IomegaAccess - Iomega Corporation - C:\WINNT\system32\IomegaAccess.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINNT\System32\HPHipm11.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe
O23 - Service: ZipToA - Iomega Corporation - C:\WINNT\system32\ZipToA.exe

HKCU\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Startup

HKLM\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Startup

HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon

HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Logon

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit

+ C:\WINNT\system32\userinit.exe Userinit Logon Application Microsoft Corporation c:\winnt\system32\userinit.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell

HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

+ Explorer.exe Windows Explorer Microsoft Corporation c:\winnt\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ AOLDialer AOL Connectivity Service Dialer America Online c:\program files\common files\aol\acs\aoldial.exe

+ CPQEASYACC Easy Access Software Demon Compaq Computer Corporation c:\program files\compaq\easy access button support\cpqeadm.exe

+ EACLEAN Easy Access Software System Startup Cleanup Application Compaq Computer Corporation c:\program files\compaq\easy access button support\eaclean.exe

+ HostManager AOLHostManager America Online, Inc. c:\program files\common files\aol\1116034182\ee\aolhostmanager.exe

+ HPDJ Taskbar Utility HP c:\winnt\system32\spool\drivers\w32x86\3\hpztsb07.exe

+ HPHmon04 HPHmon04 Hewlett-Packard c:\winnt\system32\hphmon04.exe

+ HPHUPD04 HPHupd04 Hewlett-Packard c:\program files\hp photosmart 11\hphinstall\unipatch\hphupd04.exe

+ Iomega Drive Icons imgicon mine c:\program files\iomega\driveicons\imgicon.exe

+ Iomega Startup Options imgstart Iomega Corporation c:\program files\iomega\common\imgstart.exe

+ Logitech Utility Logitech Launcher Application Logitech Inc. c:\winnt\logi_mwx.exe

+ MCAgentExe McAfee SecurityCenter Agent Networks Associates Technology, Inc c:\program files\mcafee.com\agent\mcagent.exe

+ MCUpdateExe McAfee SecurityCenter Update Engine Networks Associates Technology, Inc c:\program files\mcafee.com\agent\mcupdate.exe

+ MMTray mm_tray MUSICMATCH, Inc. c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe

+ MPFExe McAfee Personal Firewall Tray Monitor McAfee Security c:\program files\mcafee.com\personal firewall\mpftray.exe

+ PCTVOICE pctvoice MFC Application c:\winnt\system32\pctspk.exe

+ Pure Networks Port Magic Port Magic Application Pure Networks, Inc. c:\program files\pure networks\port magic\portaol.exe

+ QuickTime Task Apple Computer, Inc. c:\program files\quicktime\qttask.exe

+ Share-to-Web Namespace Daemon hpgs2wnd Hewlett-Packard c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe

+ Synchronization Manager Microsoft Synchronization Manager Microsoft Corporation c:\winnt\system32\mobsync.exe

+ Tweak UI User interface customization toy Microsoft Corporation c:\winnt\system32\tweakui.cpl

+ VirusScan Online McAfee VirusScan ActiveShield Resource Networks Associates Technology, Inc c:\program files\mcafee.com\vso\mcvsshld.exe

+ VSOCheckTask McAfee VirusScan Command Handler Networks Associates Technology, Inc c:\program files\mcafee.com\vso\mcmnhdlr.exe

+ WxEx Ambient, LLC c:\program files\wxex\wxex.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

C:\Documents and Settings\All Users\Start Menu\Programs\Startup

+ Adobe Gamma Loader.lnk Adobe Gamma Loader Adobe Systems, Inc. c:\program files\common files\adobe\calibration\adobe gamma loader.exe

+ Adobe Reader Speed Launch.lnk Adobe Acrobat SpeedLauncher Adobe Systems Incorporated c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe

+ Microsoft Office.lnk Microsoft Office 2000 component Microsoft Corporation c:\program files\microsoft office\office\osa9.exe

+ NkbMonitor.exe.lnk PictureProject Monitor Nikon Corporation c:\program files\nikon\pictureproject\nkbmonitor.exe

+ WinZip Quick Pick.lnk WinZip Executable WinZip Computing, Inc. c:\program files\winzip\wzqkpick.exe

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup

+ SpywareGuard.lnk SpywareGuard c:\program files\spywareguard\sgmain.exe

+ Webshots.lnk Webshots Desktop Tray Application The Webshots Corporation c:\program files\webshots\webshotstray.exe

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ AOL Fast Start America Online America Online, Inc. c:\program files\america online 9.0a\aol.exe

+ Iomega Active Disk c:\program files\iomega\autodisk\ad2kclient.exe

+ updateMgr Adobe Update Manager Adobe Systems Incorporated c:\program files\adobe\acrobat 7.0\reader\adobeupdatemanager.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components

+ Address Book 5 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe

+ Browser Customizations Microsoft Internet Explorer Customization DLL Microsoft Corporation c:\winnt\system32\iedkcs32.dll

+ CRLUpdate UPDCRL Microsoft Corporation c:\winnt\system32\updcrl.exe

+ EnableRevocation Microsoft© Register Server Microsoft Corporation c:\winnt\system32\regsvr32.exe

+ Internet Explorer 6 IE 5.0 Per-User Install Utility Microsoft Corporation c:\winnt\system32\ie4uinit.exe

+ Internet Explorer Access Windows NT User Data Migration Tool Microsoft Corporation c:\winnt\system32\shmgrate.exe

+ Microsoft Outlook Express 6 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe

+ Microsoft Windows Media Player ADVPACK Microsoft Corporation c:\winnt\system32\advpack.dll

+ NetMeeting 3.01 ADVPACK Microsoft Corporation c:\winnt\system32\advpack.dll

+ Outlook Express Access Windows NT User Data Migration Tool Microsoft Corporation c:\winnt\system32\shmgrate.exe

+ Windows Desktop Update Microsoft© Register Server Microsoft Corporation c:\winnt\system32\regsvr32.exe

+ Windows Media Player Microsoft Windows Media Player Setup Utility Microsoft Corporation c:\winnt\inf\unregmp2.exe

HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler

+ Browseui preloader Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Component Categories cache daemon Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

+ Network.ConnectionTray Network Connections Shell Microsoft Corporation c:\winnt\system32\netshell.dll

+ SysTray Systray shell service object Microsoft Corporation c:\winnt\system32\stobject.dll

+ WebCheck Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ ewido shell guard c:\program files\ewido\security suite\shellhook.dll

+ shell32.dll Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ SpywareGuard SpywareGuard Protection c:\program files\spywareguard\spywareguard.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ &Address Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ &Links Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ .CAB file viewer Cabinet File Viewer Shell Extension Microsoft Corporation c:\winnt\system32\cabview.dll

+ Accessible Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ ActiveDesktop Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ ActiveX Cache Folder Object Control Viewer Microsoft Corporation c:\winnt\system32\occache.dll

+ Add encryption item to context menus in explorer Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Address Bar Parser Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Address EditBox Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Augmented Shell Folder Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Augmented Shell Folder 2 Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ BandProxy Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Briefcase Windows Briefcase Microsoft Corporation c:\winnt\system32\syncui.dll

+ Briefcase Folder Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ CDF Extension Copy Hook Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Channel File Channel Definition File Viewer Microsoft Corporation c:\winnt\system32\cdfview.dll

+ Channel Handler Object Channel Definition File Viewer Microsoft Corporation c:\winnt\system32\cdfview.dll

+ Channel Menu Channel Definition File Viewer Microsoft Corporation c:\winnt\system32\cdfview.dll

+ Channel Properties Channel Definition File Viewer Microsoft Corporation c:\winnt\system32\cdfview.dll

+ Channel Shortcut Channel Definition File Viewer Microsoft Corporation c:\winnt\system32\cdfview.dll

+ CmdFileIcon Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Code Download Agent Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ ConnectionAgent Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ Crypto PKO Extension Crypto Shell Extensions Microsoft Corporation c:\winnt\system32\cryptext.dll

+ Crypto Sign Extension Crypto Shell Extensions Microsoft Corporation c:\winnt\system32\cryptext.dll

+ Custom MRU AutoCompleted List Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Darwin App Publisher Shell Application Manager Microsoft Corporation c:\winnt\system32\appwiz.cpl

+ Directory Context Menu Verbs Directory Service Common UI Microsoft Corporation c:\winnt\system32\dsuiext.dll

+ Directory Namespace Directory Service UI Microsoft Corporation c:\winnt\system32\dsfolder.dll

+ Directory Object Find Directory Service Find Microsoft Corporation c:\winnt\system32\dsquery.dll

+ Directory Property UI Directory Service Common UI Microsoft Corporation c:\winnt\system32\dsuiext.dll

+ Directory Query UI Directory Service Find Microsoft Corporation c:\winnt\system32\dsquery.dll

+ Directory Start/Search Find Directory Service Find Microsoft Corporation c:\winnt\system32\dsquery.dll

+ Disk Copy Extension Windows DiskCopy Microsoft Corporation c:\winnt\system32\diskcopy.dll

+ Disk Quota UI Windows Shell Disk Quota UI DLL Microsoft Corporation c:\winnt\system32\dskquoui.dll

+ Display Adapter CPL Extension Advanced display adapter properties Microsoft Corporation c:\winnt\system32\deskadp.dll

+ Display Control Panel HTML Extensions Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Display Monitor CPL Extension Advanced display monitor properties Microsoft Corporation c:\winnt\system32\deskmon.dll

+ Display Panning CPL Extension File not found: deskpan.dll

+ Display TroubleShoot CPL Extension Advanced display performance properties Microsoft Corporation c:\winnt\system32\deskperf.dll

+ Download Status Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ DS Security Page Directory Service Security UI Microsoft Corporation c:\winnt\system32\dssec.dll

+ Explorer Band Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Favorites Band Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ File Property Page Extension Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ File Types Page Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Folder Options Property Page Extension Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Folder Shortcut Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Fonts Windows Font Folder Microsoft Corporation c:\winnt\system32\fontext.dll

+ For &People... Find People Microsoft Corporation c:\program files\outlook express\wabfind.dll

+ Fusion Cache Microsoft .NET Runtime Execution Engine Microsoft Corporation c:\winnt\system32\mscoree.dll

+ Global Folder Settings Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ History Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ HTML Thumbnail Extractor Thumbnail View Extension Microsoft Corporation c:\winnt\system32\thumbvw.dll

+ HyperTerminal Icon Ext HyperTerminal Applet Library Hilgraeve, Inc. c:\winnt\system32\hticons.dll

+ ICC Profile Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\winnt\system32\icmui.dll

+ ICM Monitor Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\winnt\system32\icmui.dll

+ ICM Printer Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\winnt\system32\icmui.dll

+ ICM Scanner Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\winnt\system32\icmui.dll

+ IE4 Suite Splash Screen Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ In-pane search Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Installed Apps Enumerator Shell Application Manager Microsoft Corporation c:\winnt\system32\appwiz.cpl

+ Internet Name Space Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ InternetShortcut Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ IomegaWare Shell Extension IMGMENU Iomega Corp. c:\program files\iomega\shell\imgmenu.dll

+ IomegaWare Shell Extension IMGPROP Iomega Corp. c:\program files\iomega\shell\imgprop.dll

+ ISFBand OC Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ IShellFolderBand Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ LNK file thumbnail interface delegator Thumbnail View Extension Microsoft Corporation c:\winnt\system32\thumbvw.dll

+ Media Band Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Menu Band Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Menu Desk Bar Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Menu Shell Folder Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Menu Site Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft AutoComplete Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft Browser Architecture Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Microsoft BrowserBand Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft CopyTo Service Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Microsoft History AutoComplete List Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft Internet Toolbar Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft MoveTo Service Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Microsoft Multiple AutoComplete List Container Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft New Object Service Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Microsoft Outlook Custom Icon Handler Microsoft Outlook Shell Hook for Start/Find Microsoft Corporation c:\program files\microsoft office\office\olkfstub.dll

+ Microsoft SendTo Service Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Microsoft Shell Folder AutoComplete List Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft Url History Service Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Microsoft Url Search Hook Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ MIME File Types Hook Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ MMC Icon Handler MMC Shell Extension DLL Microsoft Corporation c:\winnt\system32\mmcshext.dll

+ Mounted Volume Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ MRU AutoComplete List Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Multimedia File Property Sheet Control Panel Drivers Applet Microsoft Corporation c:\winnt\system32\mmsys.cpl

+ My Computer Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ MyDocs Copy Hook My Documents Folder UI Microsoft Corporation c:\winnt\system32\mydocs.dll

+ MyDocs Drop Target My Documents Folder UI Microsoft Corporation c:\winnt\system32\mydocs.dll

+ MyDocs Folder My Documents Folder UI Microsoft Corporation c:\winnt\system32\mydocs.dll

+ MyDocs Properties My Documents Folder UI Microsoft Corporation c:\winnt\system32\mydocs.dll

+ Network and Dial-up Connections Network Connections Shell Microsoft Corporation c:\winnt\system32\netshell.dll

+ NTFS Security Page Security Shell Extension Microsoft Corporation c:\winnt\system32\rshx32.dll

+ Office Graphics Filters Thumbnail Extractor Thumbnail View Extension Microsoft Corporation c:\winnt\system32\thumbvw.dll

+ Offline Files Folder Client Side Caching UI Microsoft Corporation c:\winnt\system32\cscui.dll

+ Offline Files Folder Options Client Side Caching UI Microsoft Corporation c:\winnt\system32\cscui.dll

+ Offline Files Menu Client Side Caching UI Microsoft Corporation c:\winnt\system32\cscui.dll

+ OLE Docfile Property Page OLE DocFile Property Page Microsoft Corporation c:\winnt\system32\docprop.dll

+ Open With Context Menu Handler Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ PlusPack CPL Extension Effects Control Panel extension Microsoft Corporation c:\winnt\system32\plustab.dll

+ PostAgent Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ Printers Security Page Security Shell Extension Microsoft Corporation c:\winnt\system32\rshx32.dll

+ Registry Tree Options Utility Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Scheduled Tasks Task Scheduler interface DLL Microsoft Corporation c:\winnt\system32\mstask.dll

+ Search Assistant OC Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Search Band Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Sendmail service Send Mail Microsoft Corporation c:\winnt\system32\sendmail.dll

+ Sendmail service Send Mail Microsoft Corporation c:\winnt\system32\sendmail.dll

+ Share-to-Web Upload Folder S2WNSRES Hewlett-Packard c:\program files\hewlett-packard\hp share-to-web\hpgs2wns.dll

+ Shell Application Manager Shell Application Manager Microsoft Corporation c:\winnt\system32\appwiz.cpl

+ Shell Automation Folder View Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Shell Automation Inproc Service Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Shell Automation Service Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Shell Band Site Menu Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Shell DeskBar Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Shell DeskBarApp Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Shell DocObject Viewer Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Shell Drag and Drop helper Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Shell extensions for Microsoft Windows Network objects Network object shell UI Microsoft Corporation c:\winnt\system32\ntlanui2.dll

+ Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\winnt\system32\ntshrui.dll

+ Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\winnt\system32\ntshrui.dll

+ Shell extensions for Windows Script Host Microsoft ® Shell Extension for Windows Script Host Microsoft Corporation c:\winnt\system32\wshext.dll

+ Shell Favorite Folder Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Shell properties for a DS object Directory Service UI Microsoft Corporation c:\winnt\system32\dsfolder.dll

+ Shell Rebar BandSite Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Shell Scrap DataHandler Shell scrap object handler Microsoft Corporation c:\winnt\system32\shscrap.dll

+ SpywareGuard SpywareGuard Protection c:\program files\spywareguard\spywareguard.dll

+ Start Menu Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Subscription Folder Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ Subscription Mgr Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ Summary Info Thumbnail handler (DOCFILES) Thumbnail View Extension Microsoft Corporation c:\winnt\system32\thumbvw.dll

+ Tasks Folder Icon Handler Task Scheduler interface DLL Microsoft Corporation c:\winnt\system32\mstask.dll

+ Tasks Folder Shell Extension Task Scheduler interface DLL Microsoft Corporation c:\winnt\system32\mstask.dll

+ Temporary Internet Files Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Temporary Internet Files Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ The Internet Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Thumbnail Image Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Thumbnails Thumbnail View Extension Microsoft Corporation c:\winnt\system32\thumbvw.dll

+ Track Popup Bar Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Tracking Shell Menu Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ TrayAgent Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ TridentImageExtractor Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ User Assist Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Web Printer Shell Extension Print UI DLL Microsoft Corporation c:\winnt\system32\printui.dll

+ Web Search Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ WebCheck Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ WebCheck SyncMgr Handler Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ WebCheckChannelAgent Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ WebCheckWebCrawler Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ WinZip WinZip Shell Extension DLL WinZip Computing, Inc. c:\program files\winzip\wzshlstb.dll

+ WinZip WinZip Shell Extension DLL WinZip Computing, Inc. c:\program files\winzip\wzshlstb.dll

+ WinZip WinZip Shell Extension DLL WinZip Computing, Inc. c:\program files\winzip\wzshlstb.dll

+ WinZip WinZip Shell Extension DLL WinZip Computing, Inc. c:\program files\winzip\wzshlstb.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Web Folders c:\program files\common files\microsoft shared\web folders\mson-- The nicest hobby on Earth ;) --t.dll

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ Fax Tiff Data Column Provider Fax Tiff Data Column Provider Microsoft Corporation c:\winnt\system32\faxshell.dll

+ PDF Shell Extension PDF Shell Extension Adobe Systems, Inc. c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll

+ ShAVColumnProvider class DocProp2 Microsoft Corporation c:\winnt\system32\docprop2.dll

+ Version Column Provider DocProp2 Microsoft Corporation c:\winnt\system32\docprop2.dll

+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871} Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ {24F14F01-7B1C-11d1-838f-0000F80461CF} Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ {24F14F02-7B1C-11d1-838f-0000F80461CF} Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ SpywareGuardDLBLOCK.CBrowserHelper SpywareGuard Download Protection c:\program files\spywareguard\dlprotect.dll

HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks

+ shdocvw.dll Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ McAfee VirusScan McAfee VirusScan Shell Extension Module Networks Associates Technology, Inc c:\program files\mcafee.com\vso\mcvsshl.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

Task Scheduler

+ HP Usg Login.job HPHUSG04 Hewlett-Packard c:\program files\hp photosmart 11\printer\hphusg04.exe

+ McAfee.com Scan for Viruses - My Computer (LUSSIER-Administrator).job McAfee VirusScan Command Handler Networks Associates Technology, Inc c:\program files\mcafee.com\vso\mcmnhdlr.exe

+ McAfee.com Update Check (LUSSIER-Administrator).job McAfee SecurityCenter Update Engine Networks Associates Technology, Inc c:\program files\mcafee.com\agent\mcupdate.exe

HKLM\System\CurrentControlSet\Services

+ Alerter Notifies selected users and computers of administrative alerts. Microsoft Corporation c:\winnt\system32\services.exe

+ AOL ACS AOL Connectivity Service America Online c:\program files\common files\aol\acs\aolacsd.exe

+ AOL TopSpeedMonitor AOL TopSpeed™ Monitor America Online, Inc c:\program files\common files\aol\topspeed\2.0\aoltsmon.exe

+ Browser Maintains an up-to-date list of computers on your network and supplies the list to programs that request it. Microsoft Corporation c:\winnt\system32\services.exe

+ Dhcp Manages network configuration by registering and updating IP addresses and DNS names. Microsoft Corporation c:\winnt\system32\services.exe

+ dmserver Logical Disk Manager Watchdog Service Microsoft Corporation c:\winnt\system32\services.exe

+ Dnscache Resolves and caches Domain Name System (DNS) names. Microsoft Corporation c:\winnt\system32\services.exe

+ Eventlog Logs event messages issued by programs and Windows. Event Log reports contain information that can be useful in diagnosing problems. Reports are viewed in Event Viewer. Microsoft Corporation c:\winnt\system32\services.exe

+ ewido security suite control ewido control ewido networks c:\program files\ewido\security suite\ewidoctrl.exe

+ HidServ HID Audio Service Microsoft Corporation c:\winnt\system32\hidserv.exe

+ Iomega Activity Disk2 ActivityDisk Iomega Corporation c:\program files\iomega\system32\activitydisk.exe

+ IomegaAccess IomegaAccess MFC Service Application Iomega Corporation c:\winnt\system32\iomegaaccess.exe

+ lanmanserver Provides RPC support and file, print, and named pipe sharing. Microsoft Corporation c:\winnt\system32\services.exe

+ lanmanworkstation Provides network connections and communications. Microsoft Corporation c:\winnt\system32\services.exe

+ LmHosts Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Microsoft Corporation c:\winnt\system32\services.exe

+ MCVSRte McAfee VirusScan Real-time Engine Networks Associates Technology, Inc c:\program files\mcafee.com\vso\mcvsrte.exe

+ MpfService McAfee Personal Firewall Service McAfee Corporation c:\program files\mcafee.com\personal firewall\mpfservice.exe

+ NtmsSvc Manages removable media, drives, and libraries. Microsoft Corporation c:\winnt\system32\svchost.exe

+ PlugPlay Manages device installation and configuration and notifies programs of device changes. Microsoft Corporation c:\winnt\system32\services.exe

+ PolicyAgent Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver. Microsoft Corporation c:\winnt\system32\lsass.exe

+ ProtectedStorage Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users. Microsoft Corporation c:\winnt\system32\services.exe

+ RemoteRegistry Allows remote registry manipulation. Microsoft Corporation c:\winnt\system32\regsvc.exe

+ RpcSs Provides the endpoint mapper and other miscellaneous RPC services. Microsoft Corporation c:\winnt\system32\svchost.exe

+ SamSs Stores security information for local user accounts. Microsoft Corporation c:\winnt\system32\lsass.exe

+ Schedule Enables a program to run at a designated time. Microsoft Corporation c:\winnt\system32\mstask.exe

+ seclogon Enables starting processes under alternate credentials Microsoft Corporation c:\winnt\system32\services.exe

+ SENS Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events. Microsoft Corporation c:\winnt\system32\svchost.exe

+ Spooler Loads files to memory for later printing. Microsoft Corporation c:\winnt\system32\spoolsv.exe

+ TrkWks Sends notifications of files moving between NTFS volumes in a network domain. Microsoft Corporation c:\winnt\system32\services.exe

+ WANMiniportService Wan Miniport (ATW) Service America Online, Inc. c:\winnt\wanmpsvc.exe

+ WinMgmt Provides system management information. Microsoft Corporation c:\winnt\system32\wbem\winmgmt.exe

+ wuauserv Enables the download and installation of critical Windows updates. If the service is disabled, the operating system can be manually updated at the Windows Update Web site. Microsoft Corporation c:\winnt\system32\svchost.exe

+ ZipToA ZipToA Iomega Corporation c:\winnt\system32\ziptoa.exe

HKLM\System\CurrentControlSet\Services

+ ACPI ACPI Driver for NT Microsoft Corporation c:\winnt\system32\drivers\acpi.sys

+ AFD Ancillary Function Driver for WinSock Microsoft Corporation c:\winnt\system32\drivers\afd.sys

+ allegro ES1988/ES1998/ES199A Adapter Driver ESS Technology, Inc. c:\winnt\system32\drivers\es198x.sys

+ AsyncMac RAS Asynchronous Media Driver Microsoft Corporation c:\winnt\system32\drivers\asyncmac.sys

+ atapi IDE/ATAPI Port Driver Microsoft Corporation c:\winnt\system32\drivers\atapi.sys

+ Atmarpc ATM ARP Client Protocol Microsoft Corporation c:\winnt\system32\drivers\atmarpc.sys

+ audstub AudStub Driver Microsoft Corporation c:\winnt\system32\drivers\audstub.sys

+ CCDECODE WDM Closed Caption VBI Codec Microsoft Corporation c:\winnt\system32\drivers\ccdecode.sys

+ Cdrom SCSI CD-ROM Driver Microsoft Corporation c:\winnt\system32\drivers\cdrom.sys

+ Disk PnP Disk Driver Microsoft Corporation c:\winnt\system32\drivers\disk.sys

+ dmio NT Disk Manager I/O Driver VERITAS Software Corp. c:\winnt\system32\drivers\dmio.sys

+ dmload NT Disk Manager Startup Driver VERITAS Software Corp. c:\winnt\system32\drivers\dmload.sys

+ DMusic Microsoft DirectMusic Software Synthesizer (WDM) Microsoft Corporation c:\winnt\system32\drivers\dmusic.sys

+ Dot4 HPH11 IEEE-1284.4-1999 Driver (Windows 2000) HP c:\winnt\system32\drivers\hphid411.sys

+ Dot4Print HPH11 IEEE-1284.4-1999 Print Class Driver HP c:\winnt\system32\drivers\hphipr11.sys

+ Dot4Usb HPH11 1284.4<->Usb Datalink Driver (Windows 2000) HP c:\winnt\system32\drivers\hphius11.sys

+ EACMOS File not found: C:\WINNT\system32\drivers\EACMOS.SYS

+ eaps2kbd Easy Access PS/2 Keyboard Filter Driver Compaq Computer Corp. c:\winnt\system32\drivers\eaps2kbd.sys

+ EAWDMFD Compaq EAWDMFD driver Compaq Computer Corporation c:\winnt\system32\drivers\eawdmfd.sys

+ EL90BC 3Com EtherLink PCI Driver 3Com Corporation c:\winnt\system32\drivers\el90xbc5.sys

+ ewido security suite driver c:\program files\ewido\security suite\guard.sys

+ Fdc Floppy Disk Controller Driver Microsoft Corporation c:\winnt\system32\drivers\fdc.sys

+ Flpydisk Floppy Driver Microsoft Corporation c:\winnt\system32\drivers\flpydisk.sys

+ Ftdisk FT Disk Driver Microsoft Corporation c:\winnt\system32\drivers\ftdisk.sys

+ gameenum Game Port Enumerator Microsoft Corporation c:\winnt\system32\drivers\gameenum.sys

+ Gpc Generic Packet Classifier Microsoft Corporation c:\winnt\system32\drivers\msgpc.sys

+ hidusb USB Miniport Driver for Input Devices Microsoft Corporation c:\winnt\system32\drivers\hidusb.sys

+ i8042prt i8042 Port Driver Microsoft Corporation c:\winnt\system32\drivers\i8042prt.sys

+ i81x Miniport Driver for Intel® 810 Chipset Graphics Driver Intel Corporation c:\winnt\system32\drivers\i81xnt5.sys

+ IntelIde Intel PCI IDE Driver Microsoft Corporation c:\winnt\system32\drivers\intelide.sys

+ iomdisk Iomega Devices Disk Filter Driver Iomega Corporation c:\winnt\system32\drivers\iomdisk.sys

+ IpFilterDriver IP Traffic Filter Driver Microsoft Corporation c:\winnt\system32\drivers\ipfltdrv.sys

+ IpInIp IP in IP Tunnel Driver Microsoft Corporation c:\winnt\system32\drivers\ipinip.sys

+ IpNat IP Network Address Translator Microsoft Corporation c:\winnt\system32\drivers\ipnat.sys

+ IPSEC IPSEC driver Microsoft Corporation c:\winnt\system32\drivers\ipsec.sys

+ IRENUM Infra-Red Bus Enumerator Microsoft Corporation c:\winnt\system32\drivers\irenum.sys

+ isapnp PNP ISA Bus Driver Microsoft Corporation c:\winnt\system32\drivers\isapnp.sys

+ Kbdclass Keyboard Class Driver Microsoft Corporation c:\winnt\system32\drivers\kbdclass.sys

+ kbdhid HID Mouse Filter Driver Microsoft Corporation c:\winnt\system32\drivers\kbdhid.sys

+ kmixer Kernel Mode Audio Mixer Microsoft Corporation c:\winnt\system32\drivers\kmixer.sys

+ L8042pr2 Logitech PS/2 Mouse Filter Driver. Logitech, Inc. c:\winnt\system32\drivers\l8042pr2.sys

+ LMouFlt2 Logitech Filter Driver for Mouse Class. Logitech, Inc. c:\winnt\system32\drivers\lmouflt2.sys

+ Mouclass Mouse Class Driver Microsoft Corporation c:\winnt\system32\drivers\mouclass.sys

+ mouhid HID Mouse Filter Driver Microsoft Corporation c:\winnt\system32\drivers\mouhid.sys

+ MPE Microsoft MPE to IP Filter Microsoft Corporation c:\winnt\system32\drivers\mpe.sys

+ MPFIREWL McAfee Personal Firewall Plus 5.0 McAfee Security c:\winnt\system32\drivers\mpfirewall.sys

+ ms_mpu401 MPU401 Adapter Driver Microsoft Corporation c:\winnt\system32\drivers\msmpu401.sys

+ MSKSSRV MS KS Server Microsoft Corporation c:\winnt\system32\drivers\mskssrv.sys

+ MSPCLOCK MS Proxy Clock Microsoft Corporation c:\winnt\system32\drivers\mspclock.sys

+ MSPQM MS Proxy Quality Manager Microsoft Corporation c:\winnt\system32\drivers\mspqm.sys

+ MSTEE WDM Tee/Communication Transform Filter Microsoft Corporation c:\winnt\system32\drivers\mstee.sys

+ NABTSFEC WDM NABTS/FEC VBI Codec Microsoft Corporation c:\winnt\system32\drivers\nabtsfec.sys

+ NdisTapi Remote Access NDIS TAPI Driver Microsoft Corporation c:\winnt\system32\drivers\ndistapi.sys

+ Ndisuio NDIS Usermode I/O Protocol Microsoft Corporation c:\winnt\system32\drivers\ndisuio.sys

+ NdisWan Remote Access NDIS WAN Driver Microsoft Corporation c:\winnt\system32\drivers\ndiswan.sys

+ NetBT NetBios over Tcpip Microsoft Corporation c:\winnt\system32\drivers\netbt.sys

+ NetDetect Network Card Detection driver Microsoft Corporation c:\winnt\system32\drivers\netdtect.sys

+ NwlnkFlt IPX Traffic Filter Driver Microsoft Corporation c:\winnt\system32\drivers\nwlnkflt.sys

+ NwlnkFwd IPX Traffic Forwarder Driver Microsoft Corporation c:\winnt\system32\drivers\nwlnkfwd.sys

+ Parallel Parallel Printer Driver Microsoft Corporation c:\winnt\system32\drivers\parallel.sys

+ Parport Parallel Port Driver Microsoft Corporation c:\winnt\system32\drivers\parport.sys

+ PCI NT Plug and Play PCI Enumerator Microsoft Corporation c:\winnt\system32\drivers\pci.sys

+ PptpMiniport WAN Miniport (PPTP) Microsoft Corporation c:\winnt\system32\drivers\raspptp.sys

+ Ptilink Direct Parallel Link Driver Parallel Technologies, Inc. c:\winnt\system32\drivers\ptilink.sys

+ Ptserial HSP Modem Serial Device Driver for NT 5.0 PCTEL, INC. c:\winnt\system32\drivers\ptserial.sys

+ RasAcd Remote Access Auto Connection Driver Microsoft Corporation c:\winnt\system32\drivers\rasacd.sys

+ Rasl2tp WAN Miniport (L2TP) Microsoft Corporation c:\winnt\system32\drivers\rasl2tp.sys

+ Raspti Direct Parallel Microsoft Corporation c:\winnt\system32\drivers\raspti.sys

+ RCA RCA filter Microsoft Corporation c:\winnt\system32\drivers\rca.sys

+ redbook Redbook Audio Filter Driver Microsoft Corporation c:\winnt\system32\drivers\redbook.sys

+ ROOTMODEM Legacy Non-Pnp Modem Device Driver Microsoft Corporation c:\winnt\system32\drivers\rootmdm.sys

+ serenum Serial Port Enumerator Microsoft Corporation c:\winnt\system32\drivers\serenum.sys

+ Serial Serial Device Driver Microsoft Corporation c:\winnt\system32\drivers\serial.sys

+ SLIP Microsoft Slip Deframing Filter Minidriver Microsoft Corporation c:\winnt\system32\drivers\slip.sys

+ streamip Microsoft IP Driver Microsoft Corporation c:\winnt\system32\drivers\streamip.sys

+ swenum Plug and Play Software Device Enumerator Microsoft Corporation c:\winnt\system32\drivers\swenum.sys

+ swmidi Microsoft GS Wavetable Synthesizer Microsoft Corporation c:\winnt\system32\drivers\swmidi.sys

+ SymEvent Symantec Event Library Symantec Corporation c:\program files\symantec\symevent.sys

+ sysaudio System Audio WDM Filter Microsoft Corporation c:\winnt\system32\drivers\sysaudio.sys

+ Tcpip TCP/IP Protocol Driver Microsoft Corporation c:\winnt\system32\drivers\tcpip.sys

+ uhcd Universal Host Controller Driver Microsoft Corporation c:\winnt\system32\drivers\uhcd.sys

+ Update Update Driver Microsoft Corporation c:\winnt\system32\drivers\update.sys

+ usbhub Default Hub Driver for USB Microsoft Corporation c:\winnt\system32\drivers\usbhub.sys

+ USBSTOR USB Mass Storage Class Driver Microsoft Corporation c:\winnt\system32\drivers\usbstor.sys

+ VgaSave VGA/Super VGA Video Driver Microsoft Corporation c:\winnt\system32\drivers\vga.sys

+ Vmodem HSP Modem Modem Device Driver PCTEL, INC. c:\winnt\system32\drivers\vmodem.sys

+ Vpctcom Platinum V.90 Modem Controller Device Driver PCTEL, INC. c:\winnt\system32\drivers\vpctcom.sys

+ Vvoice HSP Modem device driver PCtel, Inc. c:\winnt\system32\drivers\vvoice.sys

+ Wanarp Remote Access IP ARP Driver Microsoft Corporation c:\winnt\system32\drivers\wanarp.sys

+ wanatw Wan Miniport (ATW) America Online, Inc. c:\winnt\system32\drivers\wanatw4.sys

+ wdmaud MMSYSTEM Wave/Midi API mapper Microsoft Corporation c:\winnt\system32\drivers\wdmaud.sys

+ WSTCODEC WDM WST Codec Driver Microsoft Corporation c:\winnt\system32\drivers\wstcodec.sys

HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute

+ autocheck autochk * Auto Check Utility Microsoft Corporation c:\winnt\system32\autochk.exe

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

+ Your Image File Name Here without a path Symbolic Debugger for Windows 2000 Microsoft Corporation c:\winnt\system32\ntsd.exe

HKLM\SOFTWARE\Microsoft\Command Processor\Autorun

HKCU\SOFTWARE\Microsoft\Command Processor\Autorun

HKLM\SOFTWARE\Classes\Exefile\Shell\Open\Command\(Default)

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls

HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls

+ advapi32 Advanced Windows 32 Base API Microsoft Corporation c:\winnt\system32\advapi32.dll

+ comdlg32 Common Dialogs DLL Microsoft Corporation c:\winnt\system32\comdlg32.dll

+ gdi32 GDI Client DLL Microsoft Corporation c:\winnt\system32\gdi32.dll

+ imagehlp Windows NT Image Helper Microsoft Corporation c:\winnt\system32\imagehlp.dll

+ kernel32 Windows NT BASE API Client DLL Microsoft Corporation c:\winnt\system32\kernel32.dll

+ lz32 LZ Expand/Compress API DLL Microsoft Corporation c:\winnt\system32\lz32.dll

+ ole32 Microsoft OLE for Windows Microsoft Corporation c:\winnt\system32\ole32.dll

+ oleaut32 Microsoft Corporation c:\winnt\system32\oleaut32.dll

+ olecli32 Object Linking and Embedding Client Library Microsoft Corporation c:\winnt\system32\olecli32.dll

+ olecnv32 Microsoft OLE for Windows Microsoft Corporation c:\winnt\system32\olecnv32.dll

+ olesvr32 Object Linking and Embedding Server Library Microsoft Corporation c:\winnt\system32\olesvr32.dll

+ olethk
Mosaic1
I think the last of the autoruns log was cu off. Wuld you have a look please and just post the reminder, not the entrie log again. Thanks.

It's possible the other file was hidden.

Would you please go here and follow the directions to show all files:
http://service1.symantec.com/SUPPORT/tsgen...002092715262339

Then see if you find that file.

Thanks.


How is everything behaving now?
tomhawk23
Did a system search for intell321.exe. Nothing.
Here is the Autoruns file.

HKCU\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Startup

HKLM\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Startup

HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon

HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Logon

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit

+ C:\WINNT\system32\userinit.exe Userinit Logon Application Microsoft Corporation c:\winnt\system32\userinit.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell

HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

+ Explorer.exe Windows Explorer Microsoft Corporation c:\winnt\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

+ AOLDialer AOL Connectivity Service Dialer America Online c:\program files\common files\aol\acs\aoldial.exe

+ CPQEASYACC Easy Access Software Demon Compaq Computer Corporation c:\program files\compaq\easy access button support\cpqeadm.exe

+ EACLEAN Easy Access Software System Startup Cleanup Application Compaq Computer Corporation c:\program files\compaq\easy access button support\eaclean.exe

+ HostManager AOLHostManager America Online, Inc. c:\program files\common files\aol\1116034182\ee\aolhostmanager.exe

+ HPDJ Taskbar Utility HP c:\winnt\system32\spool\drivers\w32x86\3\hpztsb07.exe

+ HPHmon04 HPHmon04 Hewlett-Packard c:\winnt\system32\hphmon04.exe

+ HPHUPD04 HPHupd04 Hewlett-Packard c:\program files\hp photosmart 11\hphinstall\unipatch\hphupd04.exe

+ Iomega Drive Icons imgicon mine c:\program files\iomega\driveicons\imgicon.exe

+ Iomega Startup Options imgstart Iomega Corporation c:\program files\iomega\common\imgstart.exe

+ Logitech Utility Logitech Launcher Application Logitech Inc. c:\winnt\logi_mwx.exe

+ MCAgentExe McAfee SecurityCenter Agent Networks Associates Technology, Inc c:\program files\mcafee.com\agent\mcagent.exe

+ MCUpdateExe McAfee SecurityCenter Update Engine Networks Associates Technology, Inc c:\program files\mcafee.com\agent\mcupdate.exe

+ MMTray mm_tray MUSICMATCH, Inc. c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe

+ MPFExe McAfee Personal Firewall Tray Monitor McAfee Security c:\program files\mcafee.com\personal firewall\mpftray.exe

+ PCTVOICE pctvoice MFC Application c:\winnt\system32\pctspk.exe

+ Pure Networks Port Magic Port Magic Application Pure Networks, Inc. c:\program files\pure networks\port magic\portaol.exe

+ QuickTime Task Apple Computer, Inc. c:\program files\quicktime\qttask.exe

+ Share-to-Web Namespace Daemon hpgs2wnd Hewlett-Packard c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe

+ Synchronization Manager Microsoft Synchronization Manager Microsoft Corporation c:\winnt\system32\mobsync.exe

+ Tweak UI User interface customization toy Microsoft Corporation c:\winnt\system32\tweakui.cpl

+ VirusScan Online McAfee VirusScan ActiveShield Resource Networks Associates Technology, Inc c:\program files\mcafee.com\vso\mcvsshld.exe

+ VSOCheckTask McAfee VirusScan Command Handler Networks Associates Technology, Inc c:\program files\mcafee.com\vso\mcmnhdlr.exe

+ WxEx Ambient, LLC c:\program files\wxex\wxex.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

C:\Documents and Settings\All Users\Start Menu\Programs\Startup

+ Adobe Gamma Loader.lnk Adobe Gamma Loader Adobe Systems, Inc. c:\program files\common files\adobe\calibration\adobe gamma loader.exe

+ Adobe Reader Speed Launch.lnk Adobe Acrobat SpeedLauncher Adobe Systems Incorporated c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe

+ Microsoft Office.lnk Microsoft Office 2000 component Microsoft Corporation c:\program files\microsoft office\office\osa9.exe

+ NkbMonitor.exe.lnk PictureProject Monitor Nikon Corporation c:\program files\nikon\pictureproject\nkbmonitor.exe

+ WinZip Quick Pick.lnk WinZip Executable WinZip Computing, Inc. c:\program files\winzip\wzqkpick.exe

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup

+ SpywareGuard.lnk SpywareGuard c:\program files\spywareguard\sgmain.exe

+ Webshots.lnk Webshots Desktop Tray Application The Webshots Corporation c:\program files\webshots\webshotstray.exe

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ AOL Fast Start America Online America Online, Inc. c:\program files\america online 9.0a\aol.exe

+ Iomega Active Disk c:\program files\iomega\autodisk\ad2kclient.exe

+ updateMgr Adobe Update Manager Adobe Systems Incorporated c:\program files\adobe\acrobat 7.0\reader\adobeupdatemanager.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components

+ Address Book 5 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe

+ Browser Customizations Microsoft Internet Explorer Customization DLL Microsoft Corporation c:\winnt\system32\iedkcs32.dll

+ CRLUpdate UPDCRL Microsoft Corporation c:\winnt\system32\updcrl.exe

+ EnableRevocation Microsoft© Register Server Microsoft Corporation c:\winnt\system32\regsvr32.exe

+ Internet Explorer 6 IE 5.0 Per-User Install Utility Microsoft Corporation c:\winnt\system32\ie4uinit.exe

+ Internet Explorer Access Windows NT User Data Migration Tool Microsoft Corporation c:\winnt\system32\shmgrate.exe

+ Microsoft Outlook Express 6 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe

+ Microsoft Windows Media Player ADVPACK Microsoft Corporation c:\winnt\system32\advpack.dll

+ NetMeeting 3.01 ADVPACK Microsoft Corporation c:\winnt\system32\advpack.dll

+ Outlook Express Access Windows NT User Data Migration Tool Microsoft Corporation c:\winnt\system32\shmgrate.exe

+ Windows Desktop Update Microsoft© Register Server Microsoft Corporation c:\winnt\system32\regsvr32.exe

+ Windows Media Player Microsoft Windows Media Player Setup Utility Microsoft Corporation c:\winnt\inf\unregmp2.exe

HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler

+ Browseui preloader Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Component Categories cache daemon Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

+ Network.ConnectionTray Network Connections Shell Microsoft Corporation c:\winnt\system32\netshell.dll

+ SysTray Systray shell service object Microsoft Corporation c:\winnt\system32\stobject.dll

+ WebCheck Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ ewido shell guard c:\program files\ewido\security suite\shellhook.dll

+ shell32.dll Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ SpywareGuard SpywareGuard Protection c:\program files\spywareguard\spywareguard.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ &Address Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ &Links Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ .CAB file viewer Cabinet File Viewer Shell Extension Microsoft Corporation c:\winnt\system32\cabview.dll

+ Accessible Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ ActiveDesktop Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ ActiveX Cache Folder Object Control Viewer Microsoft Corporation c:\winnt\system32\occache.dll

+ Add encryption item to context menus in explorer Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Address Bar Parser Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Address EditBox Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Augmented Shell Folder Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Augmented Shell Folder 2 Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ BandProxy Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Briefcase Windows Briefcase Microsoft Corporation c:\winnt\system32\syncui.dll

+ Briefcase Folder Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ CDF Extension Copy Hook Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Channel File Channel Definition File Viewer Microsoft Corporation c:\winnt\system32\cdfview.dll

+ Channel Handler Object Channel Definition File Viewer Microsoft Corporation c:\winnt\system32\cdfview.dll

+ Channel Menu Channel Definition File Viewer Microsoft Corporation c:\winnt\system32\cdfview.dll

+ Channel Properties Channel Definition File Viewer Microsoft Corporation c:\winnt\system32\cdfview.dll

+ Channel Shortcut Channel Definition File Viewer Microsoft Corporation c:\winnt\system32\cdfview.dll

+ CmdFileIcon Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Code Download Agent Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ ConnectionAgent Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ Crypto PKO Extension Crypto Shell Extensions Microsoft Corporation c:\winnt\system32\cryptext.dll

+ Crypto Sign Extension Crypto Shell Extensions Microsoft Corporation c:\winnt\system32\cryptext.dll

+ Custom MRU AutoCompleted List Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Darwin App Publisher Shell Application Manager Microsoft Corporation c:\winnt\system32\appwiz.cpl

+ Directory Context Menu Verbs Directory Service Common UI Microsoft Corporation c:\winnt\system32\dsuiext.dll

+ Directory Namespace Directory Service UI Microsoft Corporation c:\winnt\system32\dsfolder.dll

+ Directory Object Find Directory Service Find Microsoft Corporation c:\winnt\system32\dsquery.dll

+ Directory Property UI Directory Service Common UI Microsoft Corporation c:\winnt\system32\dsuiext.dll

+ Directory Query UI Directory Service Find Microsoft Corporation c:\winnt\system32\dsquery.dll

+ Directory Start/Search Find Directory Service Find Microsoft Corporation c:\winnt\system32\dsquery.dll

+ Disk Copy Extension Windows DiskCopy Microsoft Corporation c:\winnt\system32\diskcopy.dll

+ Disk Quota UI Windows Shell Disk Quota UI DLL Microsoft Corporation c:\winnt\system32\dskquoui.dll

+ Display Adapter CPL Extension Advanced display adapter properties Microsoft Corporation c:\winnt\system32\deskadp.dll

+ Display Control Panel HTML Extensions Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Display Monitor CPL Extension Advanced display monitor properties Microsoft Corporation c:\winnt\system32\deskmon.dll

+ Display Panning CPL Extension File not found: deskpan.dll

+ Display TroubleShoot CPL Extension Advanced display performance properties Microsoft Corporation c:\winnt\system32\deskperf.dll

+ Download Status Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ DS Security Page Directory Service Security UI Microsoft Corporation c:\winnt\system32\dssec.dll

+ Explorer Band Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Favorites Band Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ File Property Page Extension Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ File Types Page Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Folder Options Property Page Extension Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Folder Shortcut Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Fonts Windows Font Folder Microsoft Corporation c:\winnt\system32\fontext.dll

+ For &People... Find People Microsoft Corporation c:\program files\outlook express\wabfind.dll

+ Fusion Cache Microsoft .NET Runtime Execution Engine Microsoft Corporation c:\winnt\system32\mscoree.dll

+ Global Folder Settings Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ History Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ HTML Thumbnail Extractor Thumbnail View Extension Microsoft Corporation c:\winnt\system32\thumbvw.dll

+ HyperTerminal Icon Ext HyperTerminal Applet Library Hilgraeve, Inc. c:\winnt\system32\hticons.dll

+ ICC Profile Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\winnt\system32\icmui.dll

+ ICM Monitor Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\winnt\system32\icmui.dll

+ ICM Printer Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\winnt\system32\icmui.dll

+ ICM Scanner Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\winnt\system32\icmui.dll

+ IE4 Suite Splash Screen Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ In-pane search Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Installed Apps Enumerator Shell Application Manager Microsoft Corporation c:\winnt\system32\appwiz.cpl

+ Internet Name Space Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ InternetShortcut Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ IomegaWare Shell Extension IMGMENU Iomega Corp. c:\program files\iomega\shell\imgmenu.dll

+ IomegaWare Shell Extension IMGPROP Iomega Corp. c:\program files\iomega\shell\imgprop.dll

+ ISFBand OC Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ IShellFolderBand Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ LNK file thumbnail interface delegator Thumbnail View Extension Microsoft Corporation c:\winnt\system32\thumbvw.dll

+ Media Band Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Menu Band Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Menu Desk Bar Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Menu Shell Folder Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Menu Site Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft AutoComplete Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft Browser Architecture Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Microsoft BrowserBand Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft CopyTo Service Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Microsoft History AutoComplete List Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft Internet Toolbar Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft MoveTo Service Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Microsoft Multiple AutoComplete List Container Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft New Object Service Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Microsoft Outlook Custom Icon Handler Microsoft Outlook Shell Hook for Start/Find Microsoft Corporation c:\program files\microsoft office\office\olkfstub.dll

+ Microsoft SendTo Service Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Microsoft Shell Folder AutoComplete List Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Microsoft Url History Service Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Microsoft Url Search Hook Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ MIME File Types Hook Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ MMC Icon Handler MMC Shell Extension DLL Microsoft Corporation c:\winnt\system32\mmcshext.dll

+ Mounted Volume Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ MRU AutoComplete List Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Multimedia File Property Sheet Control Panel Drivers Applet Microsoft Corporation c:\winnt\system32\mmsys.cpl

+ My Computer Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ MyDocs Copy Hook My Documents Folder UI Microsoft Corporation c:\winnt\system32\mydocs.dll

+ MyDocs Drop Target My Documents Folder UI Microsoft Corporation c:\winnt\system32\mydocs.dll

+ MyDocs Folder My Documents Folder UI Microsoft Corporation c:\winnt\system32\mydocs.dll

+ MyDocs Properties My Documents Folder UI Microsoft Corporation c:\winnt\system32\mydocs.dll

+ Network and Dial-up Connections Network Connections Shell Microsoft Corporation c:\winnt\system32\netshell.dll

+ NTFS Security Page Security Shell Extension Microsoft Corporation c:\winnt\system32\rshx32.dll

+ Office Graphics Filters Thumbnail Extractor Thumbnail View Extension Microsoft Corporation c:\winnt\system32\thumbvw.dll

+ Offline Files Folder Client Side Caching UI Microsoft Corporation c:\winnt\system32\cscui.dll

+ Offline Files Folder Options Client Side Caching UI Microsoft Corporation c:\winnt\system32\cscui.dll

+ Offline Files Menu Client Side Caching UI Microsoft Corporation c:\winnt\system32\cscui.dll

+ OLE Docfile Property Page OLE DocFile Property Page Microsoft Corporation c:\winnt\system32\docprop.dll

+ Open With Context Menu Handler Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ PlusPack CPL Extension Effects Control Panel extension Microsoft Corporation c:\winnt\system32\plustab.dll

+ PostAgent Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ Printers Security Page Security Shell Extension Microsoft Corporation c:\winnt\system32\rshx32.dll

+ Registry Tree Options Utility Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Scheduled Tasks Task Scheduler interface DLL Microsoft Corporation c:\winnt\system32\mstask.dll

+ Search Assistant OC Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Search Band Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Sendmail service Send Mail Microsoft Corporation c:\winnt\system32\sendmail.dll

+ Sendmail service Send Mail Microsoft Corporation c:\winnt\system32\sendmail.dll

+ Share-to-Web Upload Folder S2WNSRES Hewlett-Packard c:\program files\hewlett-packard\hp share-to-web\hpgs2wns.dll

+ Shell Application Manager Shell Application Manager Microsoft Corporation c:\winnt\system32\appwiz.cpl

+ Shell Automation Folder View Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Shell Automation Inproc Service Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Shell Automation Service Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Shell Band Site Menu Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Shell DeskBar Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Shell DeskBarApp Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Shell DocObject Viewer Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Shell Drag and Drop helper Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Shell extensions for Microsoft Windows Network objects Network object shell UI Microsoft Corporation c:\winnt\system32\ntlanui2.dll

+ Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\winnt\system32\ntshrui.dll

+ Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\winnt\system32\ntshrui.dll

+ Shell extensions for Windows Script Host Microsoft ® Shell Extension for Windows Script Host Microsoft Corporation c:\winnt\system32\wshext.dll

+ Shell Favorite Folder Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Shell properties for a DS object Directory Service UI Microsoft Corporation c:\winnt\system32\dsfolder.dll

+ Shell Rebar BandSite Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Shell Scrap DataHandler Shell scrap object handler Microsoft Corporation c:\winnt\system32\shscrap.dll

+ SpywareGuard SpywareGuard Protection c:\program files\spywareguard\spywareguard.dll

+ Start Menu Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ Subscription Folder Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ Subscription Mgr Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ Summary Info Thumbnail handler (DOCFILES) Thumbnail View Extension Microsoft Corporation c:\winnt\system32\thumbvw.dll

+ Tasks Folder Icon Handler Task Scheduler interface DLL Microsoft Corporation c:\winnt\system32\mstask.dll

+ Tasks Folder Shell Extension Task Scheduler interface DLL Microsoft Corporation c:\winnt\system32\mstask.dll

+ Temporary Internet Files Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Temporary Internet Files Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ The Internet Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

+ Thumbnail Image Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Thumbnails Thumbnail View Extension Microsoft Corporation c:\winnt\system32\thumbvw.dll

+ Track Popup Bar Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Tracking Shell Menu Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ TrayAgent Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ TridentImageExtractor Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ User Assist Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ Web Printer Shell Extension Print UI DLL Microsoft Corporation c:\winnt\system32\printui.dll

+ Web Search Shell Browser UI Library Microsoft Corporation c:\winnt\system32\browseui.dll

+ WebCheck Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ WebCheck SyncMgr Handler Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ WebCheckChannelAgent Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ WebCheckWebCrawler Web Site Monitor Microsoft Corporation c:\winnt\system32\webcheck.dll

+ WinZip WinZip Shell Extension DLL WinZip Computing, Inc. c:\program files\winzip\wzshlstb.dll

+ WinZip WinZip Shell Extension DLL WinZip Computing, Inc. c:\program files\winzip\wzshlstb.dll

+ WinZip WinZip Shell Extension DLL WinZip Computing, Inc. c:\program files\winzip\wzshlstb.dll

+ WinZip WinZip Shell Extension DLL WinZip Computing, Inc. c:\program files\winzip\wzshlstb.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ Web Folders c:\program files\common files\microsoft shared\web folders\mson-- The nicest hobby on Earth ;) --t.dll

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ Fax Tiff Data Column Provider Fax Tiff Data Column Provider Microsoft Corporation c:\winnt\system32\faxshell.dll

+ PDF Shell Extension PDF Shell Extension Adobe Systems, Inc. c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll

+ ShAVColumnProvider class DocProp2 Microsoft Corporation c:\winnt\system32\docprop2.dll

+ Version Column Provider DocProp2 Microsoft Corporation c:\winnt\system32\docprop2.dll

+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871} Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ {24F14F01-7B1C-11d1-838f-0000F80461CF} Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ {24F14F02-7B1C-11d1-838f-0000F80461CF} Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

+ SpywareGuardDLBLOCK.CBrowserHelper SpywareGuard Download Protection c:\program files\spywareguard\dlprotect.dll

HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks

+ shdocvw.dll Shell Doc Object and Control Library Microsoft Corporation c:\winnt\system32\shdocvw.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

+ McAfee VirusScan McAfee VirusScan Shell Extension Module Networks Associates Technology, Inc c:\program files\mcafee.com\vso\mcvsshl.dll

HKLM\Software\Microsoft\Internet Explorer\Extensions

Task Scheduler

+ HP Usg Login.job HPHUSG04 Hewlett-Packard c:\program files\hp photosmart 11\printer\hphusg04.exe

+ McAfee.com Scan for Viruses - My Computer (LUSSIER-Administrator).job McAfee VirusScan Command Handler Networks Associates Technology, Inc c:\program files\mcafee.com\vso\mcmnhdlr.exe

+ McAfee.com Update Check (LUSSIER-Administrator).job McAfee SecurityCenter Update Engine Networks Associates Technology, Inc c:\program files\mcafee.com\agent\mcupdate.exe

HKLM\System\CurrentControlSet\Services

+ Alerter Notifies selected users and computers of administrative alerts. Microsoft Corporation c:\winnt\system32\services.exe

+ AOL ACS AOL Connectivity Service America Online c:\program files\common files\aol\acs\aolacsd.exe

+ AOL TopSpeedMonitor AOL TopSpeed™ Monitor America Online, Inc c:\program files\common files\aol\topspeed\2.0\aoltsmon.exe

+ Browser Maintains an up-to-date list of computers on your network and supplies the list to programs that request it. Microsoft Corporation c:\winnt\system32\services.exe

+ Dhcp Manages network configuration by registering and updating IP addresses and DNS names. Microsoft Corporation c:\winnt\system32\services.exe

+ dmserver Logical Disk Manager Watchdog Service Microsoft Corporation c:\winnt\system32\services.exe

+ Dnscache Resolves and caches Domain Name System (DNS) names. Microsoft Corporation c:\winnt\system32\services.exe

+ Eventlog Logs event messages issued by programs and Windows. Event Log reports contain information that can be useful in diagnosing problems. Reports are viewed in Event Viewer. Microsoft Corporation c:\winnt\system32\services.exe

+ ewido security suite control ewido control ewido networks c:\program files\ewido\security suite\ewidoctrl.exe

+ HidServ HID Audio Service Microsoft Corporation c:\winnt\system32\hidserv.exe

+ Iomega Activity Disk2 ActivityDisk Iomega Corporation c:\program files\iomega\system32\activitydisk.exe

+ IomegaAccess IomegaAccess MFC Service Application Iomega Corporation c:\winnt\system32\iomegaaccess.exe

+ lanmanserver Provides RPC support and file, print, and named pipe sharing. Microsoft Corporation c:\winnt\system32\services.exe

+ lanmanworkstation Provides network connections and communications. Microsoft Corporation c:\winnt\system32\services.exe

+ LmHosts Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Microsoft Corporation c:\winnt\system32\services.exe

+ MCVSRte McAfee VirusScan Real-time Engine Networks Associates Technology, Inc c:\program files\mcafee.com\vso\mcvsrte.exe

+ MpfService McAfee Personal Firewall Service McAfee Corporation c:\program files\mcafee.com\personal firewall\mpfservice.exe

+ NtmsSvc Manages removable media, drives, and libraries. Microsoft Corporation c:\winnt\system32\svchost.exe

+ PlugPlay Manages device installation and configuration and notifies programs of device changes. Microsoft Corporation c:\winnt\system32\services.exe

+ PolicyAgent Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver. Microsoft Corporation c:\winnt\system32\lsass.exe

+ ProtectedStorage Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users. Microsoft Corporation c:\winnt\system32\services.exe

+ RemoteRegistry Allows remote registry manipulation. Microsoft Corporation c:\winnt\system32\regsvc.exe

+ RpcSs Provides the endpoint mapper and other miscellaneous RPC services. Microsoft Corporation c:\winnt\system32\svchost.exe

+ SamSs Stores security information for local user accounts. Microsoft Corporation c:\winnt\system32\lsass.exe

+ Schedule Enables a program to run at a designated time. Microsoft Corporation c:\winnt\system32\mstask.exe

+ seclogon Enables starting processes under alternate credentials Microsoft Corporation c:\winnt\system32\services.exe

+ SENS Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events. Microsoft Corporation c:\winnt\system32\svchost.exe

+ Spooler Loads files to memory for later printing. Microsoft Corporation c:\winnt\system32\spoolsv.exe

+ TrkWks Sends notifications of files moving between NTFS volumes in a network domain. Microsoft Corporation c:\winnt\system32\services.exe

+ WANMiniportService Wan Miniport (ATW) Service America Online, Inc. c:\winnt\wanmpsvc.exe

+ WinMgmt Provides system management information. Microsoft Corporation c:\winnt\system32\wbem\winmgmt.exe

+ wuauserv Enables the download and installation of critical Windows updates. If the service is disabled, the operating system can be manually updated at the Windows Update Web site. Microsoft Corporation c:\winnt\system32\svchost.exe

+ ZipToA ZipToA Iomega Corporation c:\winnt\system32\ziptoa.exe

HKLM\System\CurrentControlSet\Services

+ ACPI ACPI Driver for NT Microsoft Corporation c:\winnt\system32\drivers\acpi.sys

+ AFD Ancillary Function Driver for WinSock Microsoft Corporation c:\winnt\system32\drivers\afd.sys

+ allegro ES1988/ES1998/ES199A Adapter Driver ESS Technology, Inc. c:\winnt\system32\drivers\es198x.sys

+ AsyncMac RAS Asynchronous Media Driver Microsoft Corporation c:\winnt\system32\drivers\asyncmac.sys

+ atapi IDE/ATAPI Port Driver Microsoft Corporation c:\winnt\system32\drivers\atapi.sys

+ Atmarpc ATM ARP Client Protocol Microsoft Corporation c:\winnt\system32\drivers\atmarpc.sys

+ audstub AudStub Driver Microsoft Corporation c:\winnt\system32\drivers\audstub.sys

+ CCDECODE WDM Closed Caption VBI Codec Microsoft Corporation c:\winnt\system32\drivers\ccdecode.sys

+ Cdrom SCSI CD-ROM Driver Microsoft Corporation c:\winnt\system32\drivers\cdrom.sys

+ Disk PnP Disk Driver Microsoft Corporation c:\winnt\system32\drivers\disk.sys

+ dmio NT Disk Manager I/O Driver VERITAS Software Corp. c:\winnt\system32\drivers\dmio.sys

+ dmload NT Disk Manager Startup Driver VERITAS Software Corp. c:\winnt\system32\drivers\dmload.sys

+ DMusic Microsoft DirectMusic Software Synthesizer (WDM) Microsoft Corporation c:\winnt\system32\drivers\dmusic.sys

+ Dot4 HPH11 IEEE-1284.4-1999 Driver (Windows 2000) HP c:\winnt\system32\drivers\hphid411.sys

+ Dot4Print HPH11 IEEE-1284.4-1999 Print Class Driver HP c:\winnt\system32\drivers\hphipr11.sys

+ Dot4Usb HPH11 1284.4<->Usb Datalink Driver (Windows 2000) HP c:\winnt\system32\drivers\hphius11.sys

+ EACMOS File not found: C:\WINNT\system32\drivers\EACMOS.SYS

+ eaps2kbd Easy Access PS/2 Keyboard Filter Driver Compaq Computer Corp. c:\winnt\system32\drivers\eaps2kbd.sys

+ EAWDMFD Compaq EAWDMFD driver Compaq Computer Corporation c:\winnt\system32\drivers\eawdmfd.sys

+ EL90BC 3Com EtherLink PCI Driver 3Com Corporation c:\winnt\system32\drivers\el90xbc5.sys

+ ewido security suite driver c:\program files\ewido\security suite\guard.sys

+ Fdc Floppy Disk Controller Driver Microsoft Corporation c:\winnt\system32\drivers\fdc.sys

+ Flpydisk Floppy Driver Microsoft Corporation c:\winnt\system32\drivers\flpydisk.sys

+ Ftdisk FT Disk Driver Microsoft Corporation c:\winnt\system32\drivers\ftdisk.sys

+ gameenum Game Port Enumerator Microsoft Corporation c:\winnt\system32\drivers\gameenum.sys

+ Gpc Generic Packet Classifier Microsoft Corporation c:\winnt\system32\drivers\msgpc.sys

+ hidusb USB Miniport Driver for Input Devices Microsoft Corporation c:\winnt\system32\drivers\hidusb.sys

+ i8042prt i8042 Port Driver Microsoft Corporation c:\winnt\system32\drivers\i8042prt.sys

+ i81x Miniport Driver for Intel® 810 Chipset Graphics Driver Intel Corporation c:\winnt\system32\drivers\i81xnt5.sys

+ IntelIde Intel PCI IDE Driver Microsoft Corporation c:\winnt\system32\drivers\intelide.sys

+ iomdisk Iomega Devices Disk Filter Driver Iomega Corporation c:\winnt\system32\drivers\iomdisk.sys

+ IpFilterDriver IP Traffic Filter Driver Microsoft Corporation c:\winnt\system32\drivers\ipfltdrv.sys

+ IpInIp IP in IP Tunnel Driver Microsoft Corporation c:\winnt\system32\drivers\ipinip.sys

+ IpNat IP Network Address Translator Microsoft Corporation c:\winnt\system32\drivers\ipnat.sys

+ IPSEC IPSEC driver Microsoft Corporation c:\winnt\system32\drivers\ipsec.sys

+ IRENUM Infra-Red Bus Enumerator Microsoft Corporation c:\winnt\system32\drivers\irenum.sys

+ isapnp PNP ISA Bus Driver Microsoft Corporation c:\winnt\system32\drivers\isapnp.sys

+ Kbdclass Keyboard Class Driver Microsoft Corporation c:\winnt\system32\drivers\kbdclass.sys

+ kbdhid HID Mouse Filter Driver Microsoft Corporation c:\winnt\system32\drivers\kbdhid.sys

+ kmixer Kernel Mode Audio Mixer Microsoft Corporation c:\winnt\system32\drivers\kmixer.sys

+ L8042pr2 Logitech PS/2 Mouse Filter Driver. Logitech, Inc. c:\winnt\system32\drivers\l8042pr2.sys

+ LMouFlt2 Logitech Filter Driver for Mouse Class. Logitech, Inc. c:\winnt\system32\drivers\lmouflt2.sys

+ Mouclass Mouse Class Driver Microsoft Corporation c:\winnt\system32\drivers\mouclass.sys

+ mouhid HID Mouse Filter Driver Microsoft Corporation c:\winnt\system32\drivers\mouhid.sys

+ MPE Microsoft MPE to IP Filter Microsoft Corporation c:\winnt\system32\drivers\mpe.sys

+ MPFIREWL McAfee Personal Firewall Plus 5.0 McAfee Security c:\winnt\system32\drivers\mpfirewall.sys

+ ms_mpu401 MPU401 Adapter Driver Microsoft Corporation c:\winnt\system32\drivers\msmpu401.sys

+ MSKSSRV MS KS Server Microsoft Corporation c:\winnt\system32\drivers\mskssrv.sys

+ MSPCLOCK MS Proxy Clock Microsoft Corporation c:\winnt\system32\drivers\mspclock.sys

+ MSPQM MS Proxy Quality Manager Microsoft Corporation c:\winnt\system32\drivers\mspqm.sys

+ MSTEE WDM Tee/Communication Transform Filter Microsoft Corporation c:\winnt\system32\drivers\mstee.sys

+ NABTSFEC WDM NABTS/FEC VBI Codec Microsoft Corporation c:\winnt\system32\drivers\nabtsfec.sys

+ NdisTapi Remote Access NDIS TAPI Driver Microsoft Corporation c:\winnt\system32\drivers\ndistapi.sys

+ Ndisuio NDIS Usermode I/O Protocol Microsoft Corporation c:\winnt\system32\drivers\ndisuio.sys

+ NdisWan Remote Access NDIS WAN Driver Microsoft Corporation c:\winnt\system32\drivers\ndiswan.sys

+ NetBT NetBios over Tcpip Microsoft Corporation c:\winnt\system32\drivers\netbt.sys

+ NetDetect Network Card Detection driver Microsoft Corporation c:\winnt\system32\drivers\netdtect.sys

+ NwlnkFlt IPX Traffic Filter Driver Microsoft Corporation c:\winnt\system32\drivers\nwlnkflt.sys

+ NwlnkFwd IPX Traffic Forwarder Driver Microsoft Corporation c:\winnt\system32\drivers\nwlnkfwd.sys

+ Parallel Parallel Printer Driver Microsoft Corporation c:\winnt\system32\drivers\parallel.sys

+ Parport Parallel Port Driver Microsoft Corporation c:\winnt\system32\drivers\parport.sys

+ PCI NT Plug and Play PCI Enumerator Microsoft Corporation c:\winnt\system32\drivers\pci.sys

+ PptpMiniport WAN Miniport (PPTP) Microsoft Corporation c:\winnt\system32\drivers\raspptp.sys

+ Ptilink Direct Parallel Link Driver Parallel Technologies, Inc. c:\winnt\system32\drivers\ptilink.sys

+ Ptserial HSP Modem Serial Device Driver for NT 5.0 PCTEL, INC. c:\winnt\system32\drivers\ptserial.sys

+ RasAcd Remote Access Auto Connection Driver Microsoft Corporation c:\winnt\system32\drivers\rasacd.sys

+ Rasl2tp WAN Miniport (L2TP) Microsoft Corporation c:\winnt\system32\drivers\rasl2tp.sys

+ Raspti Direct Parallel Microsoft Corporation c:\winnt\system32\drivers\raspti.sys

+ RCA RCA filter Microsoft Corporation c:\winnt\system32\drivers\rca.sys

+ redbook Redbook Audio Filter Driver Microsoft Corporation c:\winnt\system32\drivers\redbook.sys

+ ROOTMODEM Legacy Non-Pnp Modem Device Driver Microsoft Corporation c:\winnt\system32\drivers\rootmdm.sys

+ serenum Serial Port Enumerator Microsoft Corporation c:\winnt\system32\drivers\serenum.sys

+ Serial Serial Device Driver Microsoft Corporation c:\winnt\system32\drivers\serial.sys

+ SLIP Microsoft Slip Deframing Filter Minidriver Microsoft Corporation c:\winnt\system32\drivers\slip.sys

+ streamip Microsoft IP Driver Microsoft Corporation c:\winnt\system32\drivers\streamip.sys

+ swenum Plug and Play Software Device Enumerator Microsoft Corporation c:\winnt\system32\drivers\swenum.sys

+ swmidi Microsoft GS Wavetable Synthesizer Microsoft Corporation c:\winnt\system32\drivers\swmidi.sys

+ SymEvent Symantec Event Library Symantec Corporation c:\program files\symantec\symevent.sys

+ sysaudio System Audio WDM Filter Microsoft Corporation c:\winnt\system32\drivers\sysaudio.sys

+ Tcpip TCP/IP Protocol Driver Microsoft Corporation c:\winnt\system32\drivers\tcpip.sys

+ uhcd Universal Host Controller Driver Microsoft Corporation c:\winnt\system32\drivers\uhcd.sys

+ Update Update Driver Microsoft Corporation c:\winnt\system32\drivers\update.sys

+ usbhub Default Hub Driver for USB Microsoft Corporation c:\winnt\system32\drivers\usbhub.sys

+ USBSTOR USB Mass Storage Class Driver Microsoft Corporation c:\winnt\system32\drivers\usbstor.sys

+ VgaSave VGA/Super VGA Video Driver Microsoft Corporation c:\winnt\system32\drivers\vga.sys

+ Vmodem HSP Modem Modem Device Driver PCTEL, INC. c:\winnt\system32\drivers\vmodem.sys

+ Vpctcom Platinum V.90 Modem Controller Device Driver PCTEL, INC. c:\winnt\system32\drivers\vpctcom.sys

+ Vvoice HSP Modem device driver PCtel, Inc. c:\winnt\system32\drivers\vvoice.sys

+ Wanarp Remote Access IP ARP Driver Microsoft Corporation c:\winnt\system32\drivers\wanarp.sys

+ wanatw Wan Miniport (ATW) America Online, Inc. c:\winnt\system32\drivers\wanatw4.sys

+ wdmaud MMSYSTEM Wave/Midi API mapper Microsoft Corporation c:\winnt\system32\drivers\wdmaud.sys

+ WSTCODEC WDM WST Codec Driver Microsoft Corporation c:\winnt\system32\drivers\wstcodec.sys

HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute

+ autocheck autochk * Auto Check Utility Microsoft Corporation c:\winnt\system32\autochk.exe

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

+ Your Image File Name Here without a path Symbolic Debugger for Windows 2000 Microsoft Corporation c:\winnt\system32\ntsd.exe

HKLM\SOFTWARE\Microsoft\Command Processor\Autorun

HKCU\SOFTWARE\Microsoft\Command Processor\Autorun

HKLM\SOFTWARE\Classes\Exefile\Shell\Open\Command\(Default)

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls

HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls

+ advapi32 Advanced Windows 32 Base API Microsoft Corporation c:\winnt\system32\advapi32.dll

+ comdlg32 Common Dialogs DLL Microsoft Corporation c:\winnt\system32\comdlg32.dll

+ gdi32 GDI Client DLL Microsoft Corporation c:\winnt\system32\gdi32.dll

+ imagehlp Windows NT Image Helper Microsoft Corporation c:\winnt\system32\imagehlp.dll

+ kernel32 Windows NT BASE API Client DLL Microsoft Corporation c:\winnt\system32\kernel32.dll

+ lz32 LZ Expand/Compress API DLL Microsoft Corporation c:\winnt\system32\lz32.dll

+ ole32 Microsoft OLE for Windows Microsoft Corporation c:\winnt\system32\ole32.dll

+ oleaut32 Microsoft Corporation c:\winnt\system32\oleaut32.dll

+ olecli32 Object Linking and Embedding Client Library Microsoft Corporation c:\winnt\system32\olecli32.dll

+ olecnv32 Microsoft OLE for Windows Microsoft Corporation c:\winnt\system32\olecnv32.dll

+ olesvr32 Object Linking and Embedding Server Library Microsoft Corporation c:\winnt\system32\olesvr32.dll

+ olethk32 Microsoft OLE for Windows Microsoft Corporation c:\winnt\system32\olethk32.dll

+ rpcrt4 Remote Procedure Call Runtime Microsoft Corporation c:\winnt\system32\rpcrt4.dll

+ shell32 Windows Shell Common Dll Microsoft Corporation c:\winnt\system32\shell32.dll

+ url Internet Shortcut Shell Extension DLL Microsoft Corporation c:\winnt\system32\url.dll

+ urlmon OLE32 Extensions for Win32 Microsoft Corporation c:\winnt\system32\urlmon.dll

+ user32 Windows 2000 USER API Client DLL Microsoft Corporation c:\winnt\system32\user32.dll

+ version Version Checking and File Installation Libraries Microsoft Corporation c:\winnt\system32\version.dll

+ wininet Internet Extensions for Win32 Microsoft Corporation c:\winnt\system32\wininet.dll

+ wldap32 Win32 LDAP API DLL Microsoft Corporation c:\winnt\system32\wldap32.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ crypt32chain Crypto API32 Microsoft Corporation c:\winnt\system32\crypt32.dll

+ cryptnet Crypto Network Related API Microsoft Corporation c:\winnt\system32\cryptnet.dll

+ cscdll Offline Network Agent Microsoft Corporation c:\winnt\system32\cscdll.dll

+ sclgntfy Secondary Logon Service Notification DLL Microsoft Corporation c:\winnt\system32\sclgntfy.dll

+ SensLogn Common DLL to receive Winlogon notifications Microsoft Corporation c:\winnt\system32\wlnotify.dll

+ wzcnotif Wireless Zero Configuration Service UI Microsoft Corporation c:\winnt\system32\wzcdlg.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GinaDLL

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman

HKCU\Control Panel\Desktop\Scrnsave.exe

+ C:\WINNT\WEBSHOTS.SCR Webshots32 Auralis, Inc. c:\winnt\webshots.scr

HKLM\System\CurrentControlSet\Control\BootVerificationProgram\ImageName

HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{5E83A8ED-B5E4-43B5-8BB4-1A9BB3A00F30}] DATAGRAM 0 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{5E83A8ED-B5E4-43B5-8BB4-1A9BB3A00F30}] SEQPACKET 0 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{A8397177-C40F-4F41-A720-36D7A694C203}] DATAGRAM 1 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{A8397177-C40F-4F41-A720-36D7A694C203}] SEQPACKET 1 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{C3BCB806-5C05-4DA6-8AF4-544DD679C4EB}] DATAGRAM 2 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{C3BCB806-5C05-4DA6-8AF4-544DD679C4EB}] SEQPACKET 2 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{D1604E9A-B001-44FA-A6CB-6F28D30FCE6C}] DATAGRAM 3 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{D1604E9A-B001-44FA-A6CB-6F28D30FCE6C}] SEQPACKET 3 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E933D29B-FEEA-4056-B1F2-780BAA3F1A37}] DATAGRAM 4 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\winnt\system32\msafd.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{E933D29B-FEEA-4056-B1F2-780BAA3F1A37}] SEQPACKET 4 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\winnt\system32\msafd.dll

+ MSAFD Tcpip [RAW/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\winnt\system32\msafd.dll

+ MSAFD Tcpip [TCP/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\winnt\system32\msafd.dll

+ MSAFD Tcpip [UDP/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\winnt\system32\msafd.dll

+ RSVP TCP Service Provider Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation c:\winnt\system32\rsvpsp.dll

+ RSVP UDP Service Provider Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation c:\winnt\system32\rsvpsp.dll

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ BJ Language Monitor Langage Monitor for Canon Bubble-Jet Printer Microsoft Corporation c:\winnt\system32\cnbjmon.dll

+ Local Port Local Spooler DLL Microsoft Corporation c:\winnt\system32\localspl.dll

+ PJL Language Monitor Spooler Setup DLL Microsoft Corporation c:\winnt\system32\pjlmon.dll

+ Standard TCP/IP Port Standard TCP/IP Port Monitor DLL Microsoft Corporation c:\winnt\system32\tcpmon.dll

+ USB Monitor Standard USB printing Port Monitor DLL Microsoft Corporation c:\winnt\system32\usbmon.dll

+ Windows NT Fax Monitor Fax Print Monitor Microsoft Corporation c:\winnt\system32\msfaxmon.dll
Mosaic1
The file you sent me was a trojan and it communicates with a remote server on the internet. I am not sure if it has stolen information from your system or not.

Do not do anything sensitive on this system until we see what else is going on.

Sensitive information on your system may not be private any longer. I just don't know for sure. If you do any banking or financial transactions online :

ANY AND ALL BANKING passwords should be changed and do not do any banking online until you are clean. Get in touch with your bank immediately if you do online banking. Same for any other financial transactions or passwords to email, or sites like this etc.


---------------------------



Thanks.

This shows as a missing file.

+ EACMOS File not found: C:\WINNT\system32\drivers\EACMOS.SYS

Post a startuplist too please. In Hijackthis press the Config Button
Click Misc Tools
Check both boxes next to the Generate StartupList log and then click the generate startuplist log button.

Paste the contents into your next reply here.
=================




The other file was in your running processes in the first log. You can't find it now and that worries me. Let's do some intense hunting now.

Download Rootkitreveal
http://www.sysinternals.com/utilities/rootkitrevealer.html

Extract rootkitreveal
Double click on rootkit revealer and press scan.

It will take some time to do a complete scan. When finished press file/save and post the contents of the log please.

=============

Try this app: blacklight Beta from here:

http://www.f-secure.com/blacklight/try.shtml

click "I accept" at bottom of page which takes you to download site.
Download the app to the desktop.
Double click it, accept the agreement, make sure "scan through windows explorer IS checked then hit "scan"
It should only take at most 5 minutes.

If any results Don't rename anything yet!
Sometimes legit items are listed along with baddies.
Just hit next> finish.

Log will be created on desktop that starts with fsbl-datetime.log

Post its results here.

============

What did the Blue Screen error say when you tried to boot to Safe Mode?


=======================
tomhawk23
Here are the log files.
As far as what the Blue screen said it was basic info about check hardware/software etc. If you need the error number I could try booting to safe mode again.
Thanks.

StartupList report, 1/29/2006, 4:56:05 PM
StartupList version: 1.52.2
Started from : C:\Program Files\HijackThis\HijackThis.EXE
Detected: Windows 2000 SP4 (WinNT 5.00.2195)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\hidserv.exe
C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZipToA.exe
C:\WINNT\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFAGENT.EXE
C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
C:\WINNT\system32\pctspk.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINNT\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\PROGRA~1\Compaq\EASYAC~1\EAUSBKBD.EXE
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\Common Files\AOL\1116034182\ee\AOLHostManager.exe
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
C:\Program Files\WxEx\WxEx.exe
C:\Program Files\Common Files\AOL\1116034182\ee\AOLServiceHost.exe
C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\program files\common files\aol\1116034182\ee\services\antiSpywareApp\ver2_0_7\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1116034182\ee\AOLServiceHost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\taskmgr.exe
C:\Program Files\HijackThis\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Administrator\Start Menu\Programs\Startup]
Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINNT\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Synchronization Manager = mobsync.exe /logon
CPQEASYACC = C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
EACLEAN = C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
PCTVOICE = pctspk.exe
Tweak UI = RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
Logitech Utility = Logi_MwX.Exe
MMTray = C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
HPDJ Taskbar Utility = C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb07.exe
HPHmon04 = C:\WINNT\System32\hphmon04.exe
HPHUPD04 = "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
Share-to-Web Namespace Daemon = C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
VSOCheckTask = "C:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
VirusScan Online = "C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
MCAgentExe = c:\PROGRA~1\mcafee.com\agent\mcagent.exe
MCUpdateExe = C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
HostManager = C:\Program Files\Common Files\AOL\1116034182\ee\AOLHostManager.exe
AOLDialer = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
Pure Networks Port Magic = "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
Iomega Startup Options = C:\Program Files\Iomega\Common\ImgStart.exe
Iomega Drive Icons = C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
MPFExe = C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
WxEx = C:\Program Files\WxEx\WxEx.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Iomega Active Disk = C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
updateMgr = C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_2 -reboot 1

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
*No values found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

--------------------------------------------------

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINNT\System32\mshta.exe "%1" %*

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINNT\inf\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = "C:\WINNT\System32\shmgrate.exe" OCInstallUserConfigIE

[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = "C:\WINNT\System32\shmgrate.exe" OCInstallUserConfigOE

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{6A5110B5-E14B-4268-A065-EF89FF33C325}] *
StubPath = regsvr32.exe /s /n /i:"S 2 true 3 true 4 true 5 true 6 true 7 true" initpki.dll

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\wmp.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\System32\ie4uinit.exe

[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINNT\System32\Rundll32.exe C:\WINNT\System32\mscories.dll,Install

[{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
StubPath = %SystemRoot%\System32\updcrl.exe -e -u %SystemRoot%\System32\verisignpub1.crl

--------------------------------------------------

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

--------------------------------------------------

Load/Run keys from C:\WINNT\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=*Registry value not found*

--------------------------------------------------

Shell & screensaver key from C:\WINNT\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINNT\WEBSHOTS.SCR
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINNT\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINNT\Explorer\Explorer.exe: not present
C:\WINNT\System\Explorer.exe: not present
C:\WINNT\System32\Explorer.exe: not present
C:\WINNT\Command\Explorer.exe: not present
C:\WINNT\Fonts\Explorer.exe: not present

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINNT
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

--------------------------------------------------

Enumerating Browser Helper Objects:

SpywareGuard Download Protection - C:\Program Files\SpywareGuard\dlprotect.dll - {4A368E80-174F-4872-96B5-0B27DDD11DB2}

--------------------------------------------------

Enumerating Task Scheduler jobs:

McAfee.com Update Check (LUSSIER-Administrator).job
McAfee.com Scan for Viruses - My Computer (LUSSIER-Administrator).job
HP Usg Login.job

--------------------------------------------------

Enumerating Download Program Files:

[DirectAnimation Java Classes]
CODEBASE = file://C:\WINNT\Java\classes\dajava.cab
OSD = C:\WINNT\Downloaded Program Files\DirectAnimation Java Classes.osd

[Microsoft XML Parser for Java]
CODEBASE = file://C:\WINNT\Java\classes\xmldso.cab
OSD = C:\WINNT\Downloaded Program Files\Microsoft XML Parser for Java.osd

[Shockwave ActiveX Control]
InProcServer32 = C:\WINNT\system32\Macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa...director/sw.cab

[QDiagAOLCCUpdateObj Class]
InProcServer32 = C:\WINNT\System32\qdiagcc.ocx
CODEBASE = http://aolcc.aol.com/computercheckup/qdiagcc.cab

[McAfee.com Operating System Class]
InProcServer32 = C:\WINNT\system32\mcinsctl.dll
CODEBASE = http://download.av.aol.com/molbin/shared/m...83/mcinsctl.cab

[Webshots Photo Uploader]
InProcServer32 = C:\WINNT\DOWNLO~1\WSPHOT~1.OCX
CODEBASE = http://community.webshots.com/html/WSPhotoUploader.CAB

[IWinAmpActiveX Class]
InProcServer32 = C:\Program Files\Common Files\Nullsoft\ActiveX\2.6\AmpX.dll
CODEBASE = http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab

[DwnldGroupMgr Class]
InProcServer32 = C:\WINNT\system32\McGDMgr.dll
CODEBASE = http://download.av.aol.com/molbin/shared/m...,20/mcgdmgr.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINNT\system32\macromed\flash\Flash.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab

[DAX Control]
InProcServer32 = C:\PROGRA~1\MWARE\ATTACH~1\DAX.ocx
CODEBASE = https://msmail.lh.org/exchweb/controls/DAX.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #1: C:\WINNT\System32\rnr20.dll
NameSpace #2: C:\WINNT\System32\winrnr.dll
Protocol #1: C:\WINNT\system32\msafd.dll
Protocol #2: C:\WINNT\system32\msafd.dll
Protocol #3: C:\WINNT\system32\msafd.dll
Protocol #4: C:\WINNT\system32\rsvpsp.dll
Protocol #5: C:\WINNT\system32\rsvpsp.dll
Protocol #6: C:\WINNT\system32\msafd.dll
Protocol #7: C:\WINNT\system32\msafd.dll
Protocol #8: C:\WINNT\system32\msafd.dll
Protocol #9: C:\WINNT\system32\msafd.dll
Protocol #10: C:\WINNT\system32\msafd.dll
Protocol #11: C:\WINNT\system32\msafd.dll
Protocol #12: C:\WINNT\system32\msafd.dll
Protocol #13: C:\WINNT\system32\msafd.dll
Protocol #14: C:\WINNT\system32\msafd.dll
Protocol #15: C:\WINNT\system32\msafd.dll

--------------------------------------------------

Enumerating Windows NT/2000/XP services

Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
AFD Networking Support Environment: \SystemRoot\System32\drivers\afd.sys (autostart)
Alerter: %SystemRoot%\System32\services.exe (autostart)
ESS Allegro Audio Driver (WDM): system32\drivers\es198x.sys (manual start)
AOL Connectivity Service: "C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe" (autostart)
AOL TopSpeed Monitor: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (autostart)
Application Management: %SystemRoot%\system32\services.exe (manual start)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys (system)
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.sys (manual start)
Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
Background Intelligent Transfer Service: %SystemRoot%\System32\svchost.exe -k BITSgroup (manual start)
Computer Browser: %SystemRoot%\System32\services.exe (autostart)
Closed Caption Decoder: System32\DRIVERS\CCDECODE.sys (manual start)
CD-ROM Driver: System32\DRIVERS\cdrom.sys (system)
Indexing Service: C:\WINNT\System32\cisvc.exe (manual start)
ClipBook: %SystemRoot%\system32\clipsrv.exe (manual start)
DHCP Client: %SystemRoot%\System32\services.exe (autostart)
Disk Driver: System32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
Logical Disk Manager Driver: System32\drivers\dmio.sys (system)
dmload: System32\drivers\dmload.sys (system)
Logical Disk Manager: %SystemRoot%\System32\services.exe (autostart)
Microsoft DirectMusic SW Synth (WDM): system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\System32\services.exe (autostart)
Dot4 HPH11: System32\DRIVERS\hphid411.sys (manual start)
Print Class Driver for IEEE-1284.4 HPH11: System32\DRIVERS\hphipr11.sys (manual start)
Dot4Usb HPH11: System32\drivers\hphius11.sys (manual start)
EACMOS: \SystemRoot\system32\drivers\EACMOS.SYS (system)
Compaq Easy Access Internet Keyboard (Win2K): System32\DRIVERS\eaps2kbd.sys (manual start)
EAWDMFD: \SystemRoot\system32\drivers\EAWDMFD.sys (system)
3Com EtherLink XL B/C Adapter Driver: System32\DRIVERS\el90xbc5.sys (manual start)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINNT\System32\svchost.exe -k netsvcs (manual start)
ewido security suite control: C:\Program Files\ewido\security suite\ewidoctrl.exe (autostart)
ewido security suite driver: \??\C:\Program Files\ewido\security suite\guard.sys (system)
ewido security suite guard: C:\Program Files\ewido\security suite\ewidoguard.exe (disabled)
Fax Service: %systemroot%\system32\faxsvc.exe (manual start)
Floppy Disk Controller Driver: System32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: System32\DRIVERS\flpydisk.sys (manual start)
Volume Manager Driver: System32\DRIVERS\ftdisk.sys (system)
Game Port Enumerator: System32\DRIVERS\gameenum.sys (manual start)
Generic Packet Classifier: System32\DRIVERS\msgpc.sys (manual start)
HID Input Service: %SystemRoot%\system32\hidserv.exe (autostart)
Microsoft HID Class Driver: System32\DRIVERS\hidusb.sys (autostart)
i8042 Keyboard and PS/2 Mouse Port Driver: System32\DRIVERS\i8042prt.sys (system)
i81x: System32\DRIVERS\i81xnt5.sys (manual start)
IntelIde: System32\DRIVERS\intelide.sys (system)
Iomega Devices Disk Filter Services: System32\DRIVERS\iomdisk.sys (system)
Iomega Activity Disk2: "C:\PROGRA~1\Iomega\System32\ActivityDisk.exe" (autostart)
IomegaAccess: C:\WINNT\system32\IomegaAccess.exe /S (autostart)
IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
IPSEC driver: System32\DRIVERS\ipsec.sys (manual start)
IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: System32\DRIVERS\isapnp.sys (system)
Keyboard Class Driver: System32\DRIVERS\kbdclass.sys (system)
Keyboard HID Driver: System32\DRIVERS\kbdhid.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Logitech PS/2 Mouse Filter Driver: System32\DRIVERS\L8042pr2.Sys (manual start)
Server: %SystemRoot%\System32\services.exe (autostart)
Workstation: %SystemRoot%\System32\services.exe (autostart)
TCP/IP NetBIOS Helper Service: %SystemRoot%\System32\services.exe (autostart)
Logitech Mouse Class Filter Driver: System32\DRIVERS\LMouFlt2.Sys (manual start)
McAfee.com McShield: c:\PROGRA~1\mcafee.com\vso\mcshield.exe (manual start)
McAfee SecurityCenter Update Manager: C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (manual start)
McAfee.com VirusScan Online Realtime Engine: c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe /Embedding (autostart)
Messenger: %SystemRoot%\System32\services.exe (disabled)
NetMeeting Remote Desktop Sharing: C:\WINNT\System32\mnmsrvc.exe (manual start)
Mouse Class Driver: System32\DRIVERS\mouclass.sys (system)
Mouse HID Driver: System32\DRIVERS\mouhid.sys (manual start)
BDA MPE Filter: System32\DRIVERS\MPE.sys (manual start)
MPFIREWL: System32\Drivers\MpFirewall.sys (system)
McAfee Personal Firewall Service: C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe (autostart)
MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
Distributed Transaction Coordinator: C:\WINNT\System32\msdtc.exe (manual start)
Windows Installer: C:\WINNT\System32\MsiExec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft Streaming Tee/Sink-to-Sink Converter: system32\drivers\MSTEE.sys (manual start)
Microsoft MPU-401 MIDI UART Driver: system32\drivers\msmpu401.sys (manual start)
NABTS/FEC VBI Codec: System32\DRIVERS\NABTSFEC.sys (manual start)
NaiFiltr: \??\C:\Program Files\McAfee.com\VSO\NaiFiltr.sys (manual start)
NaiFsRec: System32\drivers\NaiFsRec.sys (system)
Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: System32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: System32\DRIVERS\netbios.sys (system)
NetBT: System32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (manual start)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (manual start)
NetDetect: \SystemRoot\system32\drivers\netdtect.sys (manual start)
Net Logon: %SystemRoot%\System32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
NT LM Security Support Provider: %SystemRoot%\System32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
Parallel class driver: System32\DRIVERS\parallel.sys (manual start)
Parallel port driver: System32\DRIVERS\parport.sys (system)
PCI Bus Driver: System32\DRIVERS\pci.sys (system)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
Pml Driver HPH11: C:\WINNT\System32\HPHipm11.exe (manual start)
IPSEC Policy Agent: %SystemRoot%\System32\lsass.exe (autostart)
WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
Protected Storage: %SystemRoot%\system32\services.exe (autostart)
Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
W2K Pctel Serial Device Driver: System32\DRIVERS\ptserial.sys (manual start)
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Direct Parallel: System32\DRIVERS\raspti.sys (manual start)
Microsoft Streaming Network Raw Channel Access: system32\drivers\RCA.sys (manual start)
Rdbss: System32\DRIVERS\rdbss.sys (system)
Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Remote Registry Service: %SystemRoot%\system32\regsvc.exe (autostart)
Microsoft Legacy Modem Driver: System32\Drivers\RootMdm.sys (manual start)
Remote Procedure Call (RPC) Locator: %SystemRoot%\System32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\System32\rsvp.exe -s (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
Smart Card Helper: %SystemRoot%\System32\SCardSvr.exe (manual start)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\system32\MSTask.exe (autostart)
RunAs Service: %SystemRoot%\system32\services.exe (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: System32\DRIVERS\serenum.sys (manual start)
Serial port driver: System32\DRIVERS\serial.sys (system)
Internet Connection Sharing: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
BDA Slip De-Framer: System32\DRIVERS\SLIP.sys (manual start)
Symantec Network Drivers Service: C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
Srv: System32\DRIVERS\srv.sys (manual start)
BDA IPSink: System32\DRIVERS\StreamIP.sys (manual start)
Software Bus Driver: System32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
SymEvent: \??\C:\Program Files\Symantec\SYMEVENT.SYS (manual start)
Microsoft System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: System32\DRIVERS\tcpip.sys (system)
Telnet: %SystemRoot%\system32\tlntsvr.exe (manual start)
Distributed Link Tracking Client: %SystemRoot%\system32\services.exe (autostart)
Microsoft USB Universal Host Controller Driver: System32\DRIVERS\uhcd.sys (manual start)
Microcode Update Driver: System32\DRIVERS\update.sys (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
Microsoft USB Standard Hub Driver: System32\DRIVERS\usbhub.sys (manual start)
USB Mass Storage Driver: System32\DRIVERS\USBSTOR.SYS (manual start)
Utility Manager: %SystemRoot%\System32\UtilMan.exe (manual start)
VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
W2K Vmodem: System32\DRIVERS\vmodem.sys (system)
W2K Vpctcom: System32\DRIVERS\vpctcom.sys (system)
W2K Vvoice: System32\DRIVERS\vvoice.sys (system)
Windows Time: %SystemRoot%\System32\services.exe (manual start)
Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
WAN Miniport (ATW): System32\DRIVERS\wanatw4.sys (manual start)
WAN Miniport (ATW) Service: "C:\WINNT\wanmpsvc.exe" (autostart)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
Windows Management Instrumentation: %SystemRoot%\System32\WBEM\WinMgmt.exe (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Windows Management Instrumentation Driver Extensions: %SystemRoot%\system32\Services.exe (manual start)
Windows Socket 2.0 Non-IFS Service Provider Support Environment: \SystemRoot\System32\drivers\ws2ifsl.sys (disabled)
World Standard Teletext Codec: System32\DRIVERS\WSTCODEC.SYS (manual start)
Automatic Updates: %systemroot%\system32\svchost.exe -k wugroup (autostart)
Wireless Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
ZipToA: C:\WINNT\system32\ZipToA.exe /S (autostart)


--------------------------------------------------

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

Network.ConnectionTray: C:\WINNT\system32\NETSHELL.dll
WebCheck: C:\WINNT\System32\webcheck.dll
SysTray: stobject.dll

--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

--------------------------------------------------

End of report, 33,610 bytes
Report generated in 0.982 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

*****************
HKLM\SOFTWARE\Classes\webcal\URL Protocol 5/13/2005 8:37 PM 13 bytes Data mismatch between Windows API and raw hive data.


****************
01/29/06 18:10:32 [Info]: BlackLight Engine 1.0.30 initialized
01/29/06 18:10:32 [Info]: OS: 5.0 build 2195 (Service Pack 4)
01/29/06 18:10:32 [Note]: 7019 4
01/29/06 18:10:32 [Note]: 7005 0
01/29/06 18:10:40 [Note]: 7006 0
01/29/06 18:10:40 [Note]: 7011 1024
01/29/06 18:10:42 [Note]: FSRAW library version 1.7.1014
01/29/06 18:11:10 [Note]: 7007 0
Mosaic1
For the BSOD, let's see if there is anything in Event Viewer.

go to Start >Run and type
Eventvwr.msc

Press enter

When event viewer opens, have a look around. See if you can spot one where the source column reads Save Dump
Double click on that to get the details if it exists.

What does it say?

If you want to copy it, look at the icon which looks like two pages and click on it.

That copies it to your clipboard. Paste that in here.

------------------
Mosaic1
We like to run this next one in Safe Mode.

If you can get there now, then run it there. Otherwise run it in regular windows mode please.

Download WinPFind here:
http://www.bleepingcomputer.com/files/winpfind.php

Read and follow the instructions on the page to download and then run WinPFind and post the results please.

------------------

Extract the contents to a convenient folder.

Double click in WinPFind.exe to run it.


Click "Start Scan"
This is going to take considerable time.

Once the Scan has finished it will generate a text file named WinPFind.txt in the WinPFind folder. Post the contents of WinPFind.txt into your next reply here too.
Mosaic1
QUOTE
Infection or hijacker somewhere is causing pop-ups, email notifications, web page hijacks, etc. etc. etc.



What kind of email notifications and pop ups please? Where are you hijacked to and what are you doing when hijacked? When you do searches?

Is the situation any better now?
tomhawk23
The situation is definitely better now. At least I can get connected now through the AOL software on the computer as opposed to going in through IE.

I still cannot bootup under safe mode. Here is the Blue Screeen error.

STOP: 0X00000050 (0XEB8AB800, 0X00000000, 0XEB896051, 0X00000000)
PAGE_FAULT_IN_UNPAGED_AREA
tomhawk23
Sorry. Here are the files requested.

Event Type: Information
Event Source: Save Dump
Event Category: None
Event ID: 1001
Date: 1/25/2006
Time: 6:29:52 PM
User: N/A
Computer: LUSSIER
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x000000b8 (0x00000000, 0x00000000, 0x00000000, 0x00000000). Microsoft Windows 2000 [v15.2195]. A dump was saved in: C:\WINNT\Minidump\Mini012506-01.dmp.


WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows 2000 Current Build: Service Pack 4 Current Build Number: 2195
Internet Explorer Version: 6.0.2800.1106

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...
UPX! 1/25/2006 5:31:06 PM 5636 C:\q73486.exe

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
UPX! 1/25/2006 5:31:40 PM 3584 C:\WINNT\uninstDsk.exe
PEC2 9/27/2004 10:13:40 PM 184535 C:\WINNT\Zfelkesg.pwt
PEC2 9/27/2004 10:14:16 PM 192875 C:\WINNT\Ckewklf.jip
PEC2 9/27/2004 10:14:42 PM 193869 C:\WINNT\Vbuawrcoj.alj
aspack 9/27/2004 10:15:58 PM 1047967 C:\WINNT\Pllqitajw.exo
PTech 9/27/2004 10:15:58 PM 1047967 C:\WINNT\Pllqitajw.exo
aspack 9/29/2004 8:29:36 AM 1343999 C:\WINNT\Cmsydyhvbi.pwt
PTech 9/29/2004 8:29:36 AM 1343999 C:\WINNT\Cmsydyhvbi.pwt
PTech 10/1/2004 10:33:22 AM 483851 C:\WINNT\Yvrmgjws.ydf
PEC2 10/2/2004 11:50:08 AM 200923 C:\WINNT\Syzsybnum.jdx

Checking %System% folder...
UPX! 8/29/2002 7:14:40 AM 18432 C:\WINNT\SYSTEM32\oleext.dll
PEC2 1/25/2006 5:31:24 PM 20992 C:\WINNT\SYSTEM32\hoceneoa.exe
winsync 12/7/1999 12:00:00 PM 1309184 C:\WINNT\SYSTEM32\wbdbase.deu
Umonitor 6/19/2003 3:05:04 PM 529168 C:\WINNT\SYSTEM32\RASDLG.DLL

Checking %System%\Drivers folder and sub-folders...

Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
1/24/2006 11:33:44 PM H 54156 C:\WINNT\QTFont.qfn
1/29/2006 7:40:56 PM H 1284786 C:\WINNT\ShellIconCache
1/29/2006 7:50:08 PM H 1024 C:\WINNT\system32\config\software.LOG
1/29/2006 7:47:48 PM H 1024 C:\WINNT\system32\config\default.LOG
1/29/2006 7:55:18 PM H 1024 C:\WINNT\system32\config\SECURITY.LOG
1/29/2006 7:45:08 PM H 1024 C:\WINNT\system32\config\SAM.LOG
1/25/2006 7:05:42 PM H 10820 C:\WINNT\Help\windows.GID
1/29/2006 7:45:04 PM H 6 C:\WINNT\Tasks\SA.DAT

Checking for CPL files...
Microsoft Corporation 6/19/2003 3:05:04 PM 301328 C:\WINNT\SYSTEM32\appwiz.cpl
Microsoft Corporation 6/18/2000 2:03:10 PM 106544 C:\WINNT\SYSTEM32\TWEAKUI.CPL
Microsoft Corporation 6/19/2003 3:05:04 PM 237328 C:\WINNT\SYSTEM32\DESK.CPL
Microsoft Corporation 12/7/1999 12:00:00 PM 31504 C:\WINNT\SYSTEM32\fax.cpl
Microsoft Corporation 12/7/1999 12:00:00 PM 128272 C:\WINNT\SYSTEM32\hdwwiz.cpl
Microsoft Corporation 12/7/1999 12:00:00 PM 118032 C:\WINNT\SYSTEM32\intl.cpl
Microsoft Corporation 12/7/1999 12:00:00 PM 36112 C:\WINNT\SYSTEM32\irprops.cpl
Compaq Computer Corporation 10/25/1999 8:27:44 PM 110592 C:\WINNT\SYSTEM32\UICONFIG.cpl
Microsoft Corporation 12/7/1999 12:00:00 PM 122128 C:\WINNT\SYSTEM32\main.cpl
Microsoft Corporation 12/7/1999 12:00:00 PM 303888 C:\WINNT\SYSTEM32\mmsys.cpl
Microsoft Corporation 12/7/1999 12:00:00 PM 17168 C:\WINNT\SYSTEM32\ncpa.cpl
Microsoft Corporation 12/7/1999 12:00:00 PM 41232 C:\WINNT\SYSTEM32\nwc.cpl
Microsoft Corporation 10/30/2001 8:10:00 AM 326144 C:\WINNT\SYSTEM32\joy.cpl
Microsoft Corporation 6/19/2003 3:05:04 PM 125712 C:\WINNT\SYSTEM32\SYSDM.CPL
Microsoft Corporation 12/7/1999 12:00:00 PM 5904 C:\WINNT\SYSTEM32\telephon.cpl
Microsoft Corporation 12/7/1999 12:00:00 PM 61200 C:\WINNT\SYSTEM32\timedate.cpl
Microsoft Corporation 6/19/2003 3:05:04 PM 54272 C:\WINNT\SYSTEM32\wuaucpl.cpl
Microsoft Corporation 12/7/1999 12:00:00 PM 67344 C:\WINNT\SYSTEM32\access.cpl
Microsoft Corporation 8/29/2002 7:14:40 AM 292352 C:\WINNT\SYSTEM32\inetcpl.cpl
Apple Computer, Inc. 1/6/2004 4:02:36 PM 323072 C:\WINNT\SYSTEM32\QuickTime.cpl
RealNetworks, Inc. 5/30/2003 9:56:10 AM 24576 C:\WINNT\SYSTEM32\prefscpl.cpl
Iomega Corp. 6/21/2001 8:52:40 AM 188416 C:\WINNT\SYSTEM32\AutoDisk.cpl
Microsoft Corporation 6/19/2003 3:05:04 PM 41232 C:\WINNT\SYSTEM32\odbccp32.cpl
Microsoft Corporation 6/19/2003 3:05:04 PM 90896 C:\WINNT\SYSTEM32\powercfg.cpl
Microsoft Corporation 6/19/2003 3:05:04 PM 83216 C:\WINNT\SYSTEM32\sticpl.cpl
Microsoft Corporation 12/7/1999 12:00:00 PM 41232 C:\WINNT\SYSTEM32\dllcache\nwc.cpl
Microsoft Corporation 8/29/2002 7:14:40 AM 292352 C:\WINNT\SYSTEM32\dllcache\inetcpl.cpl
IBM Corporation 9/23/1999 6:44:36 PM 94208 C:\WINNT\SYSTEM32\dllcache\mwcpa32.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
11/5/2005 6:46:30 PM 708 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
11/26/2005 11:49:46 AM 1500 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
11/5/2005 6:46:26 PM 1478 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
11/5/2005 6:46:34 PM 1421 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
11/5/2005 6:46:28 PM 1307 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder...

Checking files in %USERPROFILE%\Startup folder...
11/5/2005 6:46:48 PM 447 C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\SpywareGuard.lnk
1/11/2006 8:24:48 AM 485 C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Webshots.lnk

Checking files in %USERPROFILE%\Application Data folder...
5/28/2005 8:34:28 AM 877 C:\Documents and Settings\Administrator\Application Data\AdobeDLM.log
5/28/2005 8:34:28 AM 0 C:\Documents and Settings\Administrator\Application Data\dm.ini
10/2/2004 12:23:46 PM 45 C:\Documents and Settings\Administrator\Application Data\tvmcwrd.dll

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido
{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} = C:\Program Files\ewido\security suite\context.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\shell32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\shell32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{CFC7205E-2792-4378-9591-3879CC6C9022}
= c:\progra~1\mcafee.com\vso\mcvsshl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\{CFC7205E-2792-4378-9591-3879CC6C9022}
= c:\progra~1\mcafee.com\vso\mcvsshl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ewido
{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} = C:\Program Files\ewido\security suite\context.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\shell32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\shell32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\shell32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\shell32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= C:\WINNT\System32\docprop2.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{7f9609be-af9a-11d1-83e0-00c04fb6e984}
= %SystemRoot%\system32\faxshell.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{884EA37B-37C0-11d2-BE3F-00A0C9A83DA1}
= C:\WINNT\System32\docprop2.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{F9DB5320-233E-11D1-9F84-707F02C10627}
= C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4A368E80-174F-4872-96B5-0B27DDD11DB2}
SpywareGuardDLBLOCK.CBrowserHelper = C:\Program Files\SpywareGuard\dlprotect.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
Real.com = C:\WINNT\System32\Shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
{8E718888-423F-11D2-876E-00A0C9082467} = &Radio : C:\WINNT\System32\msdxm.ocx
{BA52B914-B692-46c4-B683-905236F6F655} = McAfee VirusScan : c:\progra~1\mcafee.com\vso\mcvsshl.dll
{4982D40A-C53B-4615-B15B-B5B5E98D167C} = AOL Toolbar : C:\Program Files\AOL Toolbar\toolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{4982D40A-C53B-4615-B15B-B5B5E98D167C}
ButtonText = AOL Toolbar :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
ButtonText = Real.com :

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
Media Band = %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
File and Folders Search ActiveX Control = C:\WINNT\system32\shell32.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}
History Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}
Explorer Band = %SystemRoot%\System32\shdocvw.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\System32\browseui.dll
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = :
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{28B27897-6081-4149-A67D-8A2A229FA260} = :
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\System32\browseui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Synchronization Manager mobsync.exe /logon
CPQEASYACC C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
EACLEAN C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
PCTVOICE pctspk.exe
Tweak UI RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
Logitech Utility Logi_MwX.Exe
MMTray C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
HPDJ Taskbar Utility C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb07.exe
HPHmon04 C:\WINNT\System32\hphmon04.exe
HPHUPD04 "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
Share-to-Web Namespace Daemon C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
VSOCheckTask "C:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
VirusScan Online "C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
MCAgentExe c:\PROGRA~1\mcafee.com\agent\mcagent.exe
MCUpdateExe C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
HostManager C:\Program Files\Common Files\AOL\1116034182\ee\AOLHostManager.exe
AOLDialer C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
QuickTime Task "C:\Program Files\QuickTime\qttask.exe" -atboottime
Pure Networks Port Magic "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
Iomega Startup Options C:\Program Files\Iomega\Common\ImgStart.exe
Iomega Drive Icons C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
MPFExe C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
WxEx C:\Program Files\WxEx\WxEx.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
IMAIL Installed = 1
MAPI Installed = 1
MSFS Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Iomega Active Disk C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
updateMgr C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_2 -reboot 1

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\AdminComponent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSON-- The nicest hobby on Earth ;) --T.DLL


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 149
CDRAutoRun 0

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
Network.ConnectionTray {7007ACCF-3202-11D1-AAD2-00805FC1270E} = C:\WINNT\system32\NETSHELL.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINNT\system32\userinit.exe,
Shell = Explorer.exe
System =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif
= wzcdlg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.4.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 1/29/2006 8:04:31 PM
Mosaic1
I really suspect you have or have had a smitfraud infection.

This is normally removed in Safe Mode. In your case we can't use that. And I suspect there is something else involved.

I would like you to go and have a file scanned here:
http://virusscan.jotti.org/

Enter this path into the File to upload box and then press the submit button.
C:\Winnt\System32\wininet.dll

Copy and paste the scan results into your next reply here.

Do the same for this file:
C:\WINNT\SYSTEM32\hoceneoa.exe

And there is a whole list of other files about which I am curious. We'll get to those shortly.

----------
I would also like to see a bootlog please.

Restart and bring up the boot menu. Select Bootlog.

After you are back into Windows find this file and post its contents please.

C:\Winnt\Ntbtlog.txt
Mosaic1
As for your 2 stop errors, these are hard to diagnose. One is from several days ago. Do you often have these?


The Safe mode stop error is even harder.

I am wondering about a very siper hidden driver trying to load there.

The truth is this could be hrdware but I don;t know at the moment.

Other than your Spyware infections, have you made any recent changes to your system? Any new Hardware installed or removed?


(And you are missing a file as mentioned earlier.
C:\WINNT\system32\drivers\EACMOS.SYS
But I cannot get the details on that file to find out how to replace it. We'll get to that later too. I'll ask around. )
Mosaic1
One final step please.

Download Unhackme.zip.

http://www.greatis.com/unhackme.zip

Unzip the file to your desktop.
Doubleclick the unhackme300.exe file to begin the installation.
Follow the prompts to install it.
When the installation is complete, unhackme should open.
Click the "Check Me Now" button.
Post the results of what, if anything, unhackme found.

---------------

Also, if you haven't already done this, delete dcom_13.dll too.
tomhawk23
On the scan...
wininet.dll was fine. Here is the log for hoceneoa.exe

File: hoceneoa.exe Status:
INFECTED/MALWARE MD5 63a286ae66187eaf6508bdc0b3644104 Packers detected:
PE_PATCH.PECOMPACT, PECBUNDLE, PECOMPACT
Scanner results AntiVir
Found nothing ArcaVir
Found nothing Avast
Found Win32:Prox AVG Antivirus
Found nothing BitDefender
Found BehavesLike:Trojan.ShellObject (probable variant) ClamAV
Found nothing Dr.Web
Found Trojan.MulDrop.3248 F-Prot Antivirus
Found nothing Fortinet
Found nothing Kaspersky Anti-Virus
Found Trojan-Proxy.Win32.Wopla.q NOD32
Found probably a variant of Win32/TrojanDropper.Small.ZK (probable variant) Norman Virus Control
Found nothing UNA
Found nothing VBA32
Found Trojan.MulDrop.3248


BOOTLOG FOLLOWS...


Service Pack 3 3 7 2004 10:51:59.500
Loaded driver \WINNT\System32\ntoskrnl.exe
Loaded driver \WINNT\System32\hal.dll
Loaded driver \WINNT\System32\BOOTVID.dll
Loaded driver ACPI.sys
Loaded driver \WINNT\System32\DRIVERS\WMILIB.SYS
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver intelide.sys
Loaded driver \WINNT\System32\DRIVERS\PCIIDEX.SYS
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver Diskperf.sys
Loaded driver dmload.sys
Loaded driver dmio.sys
Loaded driver PartMgr.sys
Loaded driver atapi.sys
Loaded driver disk.sys
Loaded driver \WINNT\System32\DRIVERS\CLASSPNP.SYS
Loaded driver Fastfat.sys
Loaded driver KSecDD.sys
Loaded driver NDIS.sys
Loaded driver vvoice.sys
Loaded driver vpctcom.sys
Loaded driver vmodem.sys
Loaded driver Mup.sys
Did not load driver Advanced Configuration and Power Interface (ACPI) PC
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Loaded driver \SystemRoot\System32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\System32\DRIVERS\L8042pr2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\LMouFlt2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\System32\DRIVERS\eaps2kbd.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdclass.sys
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Loaded driver \SystemRoot\System32\DRIVERS\fdc.sys
Loaded driver \SystemRoot\System32\Drivers\Cdr4_2K.SYS
Loaded driver \SystemRoot\System32\Drivers\MxlW2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\uhcd.sys
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Loaded driver \SystemRoot\System32\DRIVERS\parallel.sys
Loaded driver \SystemRoot\System32\DRIVERS\swenum.sys
Loaded driver \SystemRoot\System32\DRIVERS\update.sys
Loaded driver \SystemRoot\System32\DRIVERS\flpydisk.sys
Loaded driver \SystemRoot\System32\DRIVERS\usbhub.sys
Loaded driver \SystemRoot\System32\DRIVERS\hidusb.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdhid.sys
Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Did not load driver \SystemRoot\system32\drivers\EACMOS.SYS
Loaded driver \SystemRoot\system32\drivers\EAWDMFD.sys
Did not load driver \SystemRoot\System32\Drivers\sglfb.SYS
Did not load driver \SystemRoot\System32\Drivers\tga.SYS
Loaded driver \SystemRoot\System32\drivers\vga.sys
Did not load driver mnmdd.SYS
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Did not load driver RasAcd.SYS
Did not load driver Tcpip.SYS
Did not load driver NetBT.SYS
Did not load driver NetBIOS.SYS
Did not load driver Parport.SYS
Did not load driver Serial.SYS
Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
Did not load driver \SystemRoot\System32\DRIVERS\redbook.sys
Did not load driver Rdbss.SYS
Did not load driver MRxSmb.SYS
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Microsoft WINMM WDM Audio Compatibility Driver
Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
Service Pack 3 3 20 2004 17:47:06.500
Loaded driver \WINNT\System32\ntoskrnl.exe
Loaded driver \WINNT\System32\hal.dll
Loaded driver \WINNT\System32\BOOTVID.dll
Loaded driver ACPI.sys
Loaded driver \WINNT\System32\DRIVERS\WMILIB.SYS
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver intelide.sys
Loaded driver \WINNT\System32\DRIVERS\PCIIDEX.SYS
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver Diskperf.sys
Loaded driver dmload.sys
Loaded driver dmio.sys
Loaded driver PartMgr.sys
Loaded driver atapi.sys
Loaded driver disk.sys
Loaded driver \WINNT\System32\DRIVERS\CLASSPNP.SYS
Loaded driver Fastfat.sys
Loaded driver KSecDD.sys
Loaded driver NDIS.sys
Loaded driver vvoice.sys
Loaded driver vpctcom.sys
Loaded driver vmodem.sys
Loaded driver Mup.sys
Did not load driver Advanced Configuration and Power Interface (ACPI) PC
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Loaded driver \SystemRoot\System32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\System32\DRIVERS\L8042pr2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\LMouFlt2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\System32\DRIVERS\eaps2kbd.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdclass.sys
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Loaded driver \SystemRoot\System32\DRIVERS\fdc.sys
Loaded driver \SystemRoot\System32\Drivers\Cdr4_2K.SYS
Loaded driver \SystemRoot\System32\Drivers\MxlW2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\uhcd.sys
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Loaded driver \SystemRoot\System32\DRIVERS\parallel.sys
Loaded driver \SystemRoot\System32\DRIVERS\swenum.sys
Loaded driver \SystemRoot\System32\DRIVERS\update.sys
Loaded driver \SystemRoot\System32\DRIVERS\flpydisk.sys
Loaded driver \SystemRoot\System32\DRIVERS\usbhub.sys
Loaded driver \SystemRoot\System32\DRIVERS\hidusb.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdhid.sys
Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Did not load driver \SystemRoot\system32\drivers\EACMOS.SYS
Loaded driver \SystemRoot\system32\drivers\EAWDMFD.sys
Did not load driver \SystemRoot\System32\Drivers\sglfb.SYS
Did not load driver \SystemRoot\System32\Drivers\tga.SYS
Loaded driver \SystemRoot\System32\drivers\vga.sys
Did not load driver mnmdd.SYS
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Did not load driver RasAcd.SYS
Did not load driver Tcpip.SYS
Did not load driver NetBT.SYS
Did not load driver NetBIOS.SYS
Did not load driver Parport.SYS
Did not load driver Serial.SYS
Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
Did not load driver \SystemRoot\System32\DRIVERS\redbook.sys
Did not load driver Rdbss.SYS
Did not load driver MRxSmb.SYS
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Microsoft WINMM WDM Audio Compatibility Driver
Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
Service Pack 410 2 2004 16:40:51.500
Loaded driver \WINNT\System32\ntoskrnl.exe
Loaded driver \WINNT\System32\hal.dll
Loaded driver \WINNT\System32\BOOTVID.DLL
Loaded driver ACPI.sys
Loaded driver \WINNT\System32\DRIVERS\WMILIB.SYS
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver intelide.sys
Loaded driver \WINNT\System32\DRIVERS\PCIIDEX.SYS
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver Diskperf.sys
Loaded driver dmload.sys
Loaded driver dmio.sys
Loaded driver PartMgr.sys
Loaded driver atapi.sys
Loaded driver disk.sys
Loaded driver \WINNT\System32\DRIVERS\CLASSPNP.SYS
Loaded driver Fastfat.sys
Loaded driver KSecDD.sys
Loaded driver NDIS.sys
Loaded driver vvoice.sys
Loaded driver vpctcom.sys
Loaded driver vmodem.sys
Loaded driver Mup.sys
Did not load driver Advanced Configuration and Power Interface (ACPI) PC
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Loaded driver \SystemRoot\System32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\System32\DRIVERS\L8042pr2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\LMouFlt2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\System32\DRIVERS\eaps2kbd.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdclass.sys
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Loaded driver \SystemRoot\System32\DRIVERS\fdc.sys
Loaded driver \SystemRoot\System32\Drivers\AFS2K.SYS
Loaded driver \SystemRoot\System32\Drivers\Cdr4_2K.SYS
Loaded driver \SystemRoot\System32\Drivers\MxlW2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\uhcd.sys
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Loaded driver \SystemRoot\System32\DRIVERS\parallel.sys
Loaded driver \SystemRoot\System32\DRIVERS\swenum.sys
Loaded driver \SystemRoot\System32\DRIVERS\update.sys
Loaded driver \SystemRoot\System32\DRIVERS\flpydisk.sys
Loaded driver \SystemRoot\System32\DRIVERS\usbhub.sys
Did not load driver photosmart 7150
Loaded driver \SystemRoot\System32\DRIVERS\hidusb.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdhid.sys
Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Did not load driver \SystemRoot\system32\drivers\EACMOS.SYS
Loaded driver \SystemRoot\system32\drivers\EAWDMFD.sys
Did not load driver \SystemRoot\System32\Drivers\sglfb.SYS
Did not load driver \SystemRoot\System32\Drivers\tga.SYS
Loaded driver \SystemRoot\System32\drivers\vga.sys
Did not load driver mnmdd.SYS
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Did not load driver RasAcd.SYS
Did not load driver Tcpip.SYS
Did not load driver NetBT.SYS
Did not load driver NetBIOS.SYS
Did not load driver Parport.SYS
Did not load driver Serial.SYS
Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
Did not load driver \SystemRoot\System32\DRIVERS\redbook.sys
Did not load driver Rdbss.SYS
Did not load driver MRxSmb.SYS
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver photosmart 7150
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Microsoft WINMM WDM Audio Compatibility Driver
Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
Service Pack 4 4 14 2005 17:38:40.500
Loaded driver \WINNT\System32\ntoskrnl.exe
Loaded driver \WINNT\System32\hal.dll
Loaded driver \WINNT\System32\BOOTVID.DLL
Loaded driver ACPI.sys
Loaded driver \WINNT\System32\DRIVERS\WMILIB.SYS
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver intelide.sys
Loaded driver \WINNT\System32\DRIVERS\PCIIDEX.SYS
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver Diskperf.sys
Loaded driver dmload.sys
Loaded driver dmio.sys
Loaded driver PartMgr.sys
Loaded driver atapi.sys
Loaded driver disk.sys
Loaded driver \WINNT\System32\DRIVERS\CLASSPNP.SYS
Loaded driver TPkd.sys
Loaded driver Fastfat.sys
Loaded driver KSecDD.sys
Loaded driver NDIS.sys
Loaded driver vvoice.sys
Loaded driver vpctcom.sys
Loaded driver vmodem.sys
Loaded driver NaiFsRec.sys
Loaded driver Mup.sys
Did not load driver Advanced Configuration and Power Interface (ACPI) PC
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Loaded driver \SystemRoot\System32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\System32\DRIVERS\L8042pr2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\LMouFlt2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\System32\DRIVERS\eaps2kbd.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdclass.sys
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Loaded driver \SystemRoot\System32\DRIVERS\fdc.sys
Loaded driver \SystemRoot\System32\Drivers\Cdr4_2K.SYS
Loaded driver \SystemRoot\System32\Drivers\AFS2K.SYS
Loaded driver \SystemRoot\System32\Drivers\MxlW2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\uhcd.sys
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Loaded driver \SystemRoot\System32\DRIVERS\parallel.sys
Loaded driver \SystemRoot\System32\DRIVERS\swenum.sys
Loaded driver \SystemRoot\System32\DRIVERS\update.sys
Loaded driver \SystemRoot\System32\DRIVERS\flpydisk.sys
Loaded driver \SystemRoot\System32\DRIVERS\usbhub.sys
Did not load driver photosmart 7150
Loaded driver \SystemRoot\System32\DRIVERS\hidusb.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdhid.sys
Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Did not load driver \SystemRoot\system32\drivers\EACMOS.SYS
Loaded driver \SystemRoot\system32\drivers\EAWDMFD.sys
Did not load driver \SystemRoot\System32\Drivers\sglfb.SYS
Did not load driver \SystemRoot\System32\Drivers\tga.SYS
Loaded driver \SystemRoot\System32\drivers\vga.sys
Did not load driver mnmdd.SYS
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Did not load driver RasAcd.SYS
Did not load driver Tcpip.SYS
Did not load driver NetBT.SYS
Did not load driver NetBIOS.SYS
Did not load driver Parport.SYS
Did not load driver Serial.SYS
Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
Did not load driver \SystemRoot\System32\DRIVERS\redbook.sys
Did not load driver Rdbss.SYS
Did not load driver MRxSmb.SYS
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver photosmart 7150
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Microsoft WINMM WDM Audio Compatibility Driver
Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
Service Pack 4 4 14 2005 18:05:05.500
Loaded driver \WINNT\System32\ntoskrnl.exe
Loaded driver \WINNT\System32\hal.dll
Loaded driver \WINNT\System32\BOOTVID.DLL
Loaded driver ACPI.sys
Loaded driver \WINNT\System32\DRIVERS\WMILIB.SYS
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver intelide.sys
Loaded driver \WINNT\System32\DRIVERS\PCIIDEX.SYS
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver Diskperf.sys
Loaded driver dmload.sys
Loaded driver dmio.sys
Loaded driver PartMgr.sys
Loaded driver atapi.sys
Loaded driver disk.sys
Loaded driver \WINNT\System32\DRIVERS\CLASSPNP.SYS
Loaded driver TPkd.sys
Loaded driver Fastfat.sys
Loaded driver KSecDD.sys
Loaded driver NDIS.sys
Loaded driver vvoice.sys
Loaded driver vpctcom.sys
Loaded driver vmodem.sys
Loaded driver NaiFsRec.sys
Loaded driver Mup.sys
Did not load driver Advanced Configuration and Power Interface (ACPI) PC
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Loaded driver \SystemRoot\System32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\System32\DRIVERS\L8042pr2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\LMouFlt2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\System32\DRIVERS\eaps2kbd.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdclass.sys
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Loaded driver \SystemRoot\System32\DRIVERS\fdc.sys
Loaded driver \SystemRoot\System32\Drivers\Cdr4_2K.SYS
Loaded driver \SystemRoot\System32\Drivers\AFS2K.SYS
Loaded driver \SystemRoot\System32\Drivers\MxlW2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\uhcd.sys
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Loaded driver \SystemRoot\System32\DRIVERS\parallel.sys
Loaded driver \SystemRoot\System32\DRIVERS\swenum.sys
Loaded driver \SystemRoot\System32\DRIVERS\update.sys
Loaded driver \SystemRoot\System32\DRIVERS\flpydisk.sys
Loaded driver \SystemRoot\System32\DRIVERS\usbhub.sys
Did not load driver photosmart 7150
Loaded driver \SystemRoot\System32\DRIVERS\hidusb.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdhid.sys
Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Did not load driver \SystemRoot\system32\drivers\EACMOS.SYS
Loaded driver \SystemRoot\system32\drivers\EAWDMFD.sys
Did not load driver \SystemRoot\System32\Drivers\sglfb.SYS
Did not load driver \SystemRoot\System32\Drivers\tga.SYS
Loaded driver \SystemRoot\System32\drivers\vga.sys
Did not load driver mnmdd.SYS
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Did not load driver RasAcd.SYS
Did not load driver Tcpip.SYS
Did not load driver NetBT.SYS
Did not load driver NetBIOS.SYS
Did not load driver Parport.SYS
Did not load driver Serial.SYS
Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
Did not load driver \SystemRoot\System32\DRIVERS\redbook.sys
Did not load driver Rdbss.SYS
Did not load driver MRxSmb.SYS
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver photosmart 7150
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Microsoft WINMM WDM Audio Compatibility Driver
Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
Service Pack 4 4 14 2005 22:47:19.500
Loaded driver \WINNT\System32\ntoskrnl.exe
Loaded driver \WINNT\System32\hal.dll
Loaded driver \WINNT\System32\BOOTVID.DLL
Loaded driver ACPI.sys
Loaded driver \WINNT\System32\DRIVERS\WMILIB.SYS
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver intelide.sys
Loaded driver \WINNT\System32\DRIVERS\PCIIDEX.SYS
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver Diskperf.sys
Loaded driver dmload.sys
Loaded driver dmio.sys
Loaded driver PartMgr.sys
Loaded driver atapi.sys
Loaded driver disk.sys
Loaded driver \WINNT\System32\DRIVERS\CLASSPNP.SYS
Loaded driver TPkd.sys
Loaded driver Fastfat.sys
Loaded driver KSecDD.sys
Loaded driver NDIS.sys
Loaded driver vvoice.sys
Loaded driver vpctcom.sys
Loaded driver vmodem.sys
Loaded driver NaiFsRec.sys
Loaded driver Mup.sys
Did not load driver Advanced Configuration and Power Interface (ACPI) PC
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Loaded driver \SystemRoot\System32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\System32\DRIVERS\L8042pr2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\LMouFlt2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\System32\DRIVERS\eaps2kbd.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdclass.sys
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Loaded driver \SystemRoot\System32\DRIVERS\fdc.sys
Loaded driver \SystemRoot\System32\Drivers\Cdr4_2K.SYS
Loaded driver \SystemRoot\System32\Drivers\AFS2K.SYS
Loaded driver \SystemRoot\System32\Drivers\MxlW2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\uhcd.sys
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Loaded driver \SystemRoot\System32\DRIVERS\parallel.sys
Loaded driver \SystemRoot\System32\DRIVERS\swenum.sys
Loaded driver \SystemRoot\System32\DRIVERS\update.sys
Loaded driver \SystemRoot\System32\DRIVERS\flpydisk.sys
Loaded driver \SystemRoot\System32\DRIVERS\usbhub.sys
Did not load driver photosmart 7150
Loaded driver \SystemRoot\System32\DRIVERS\hidusb.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdhid.sys
Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Did not load driver \SystemRoot\system32\drivers\EACMOS.SYS
Loaded driver \SystemRoot\system32\drivers\EAWDMFD.sys
Did not load driver \SystemRoot\System32\Drivers\sglfb.SYS
Did not load driver \SystemRoot\System32\Drivers\tga.SYS
Loaded driver \SystemRoot\System32\drivers\vga.sys
Did not load driver mnmdd.SYS
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Did not load driver RasAcd.SYS
Did not load driver Tcpip.SYS
Did not load driver NetBT.SYS
Did not load driver NetBIOS.SYS
Did not load driver Parport.SYS
Did not load driver Serial.SYS
Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
Did not load driver \SystemRoot\System32\DRIVERS\redbook.sys
Did not load driver Rdbss.SYS
Did not load driver MRxSmb.SYS
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver photosmart 7150
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Microsoft WINMM WDM Audio Compatibility Driver
Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
Service Pack 4 4 14 2005 23:03:06.500
Loaded driver \WINNT\System32\ntoskrnl.exe
Loaded driver \WINNT\System32\hal.dll
Loaded driver \WINNT\System32\BOOTVID.DLL
Loaded driver ACPI.sys
Loaded driver \WINNT\System32\DRIVERS\WMILIB.SYS
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver intelide.sys
Loaded driver \WINNT\System32\DRIVERS\PCIIDEX.SYS
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver Diskperf.sys
Loaded driver dmload.sys
Loaded driver dmio.sys
Loaded driver PartMgr.sys
Loaded driver atapi.sys
Loaded driver disk.sys
Loaded driver \WINNT\System32\DRIVERS\CLASSPNP.SYS
Loaded driver TPkd.sys
Loaded driver Fastfat.sys
Loaded driver KSecDD.sys
Loaded driver NDIS.sys
Loaded driver vvoice.sys
Loaded driver vpctcom.sys
Loaded driver vmodem.sys
Loaded driver NaiFsRec.sys
Loaded driver Mup.sys
Did not load driver Advanced Configuration and Power Interface (ACPI) PC
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Loaded driver \SystemRoot\System32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\System32\DRIVERS\L8042pr2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\LMouFlt2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\System32\DRIVERS\eaps2kbd.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdclass.sys
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Loaded driver \SystemRoot\System32\DRIVERS\fdc.sys
Loaded driver \SystemRoot\System32\Drivers\Cdr4_2K.SYS
Loaded driver \SystemRoot\System32\Drivers\AFS2K.SYS
Loaded driver \SystemRoot\System32\Drivers\MxlW2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\uhcd.sys
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Loaded driver \SystemRoot\System32\DRIVERS\parallel.sys
Loaded driver \SystemRoot\System32\DRIVERS\swenum.sys
Loaded driver \SystemRoot\System32\DRIVERS\update.sys
Loaded driver \SystemRoot\System32\DRIVERS\flpydisk.sys
Loaded driver \SystemRoot\System32\DRIVERS\usbhub.sys
Did not load driver photosmart 7150
Loaded driver \SystemRoot\System32\DRIVERS\hidusb.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdhid.sys
Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Did not load driver \SystemRoot\system32\drivers\EACMOS.SYS
Loaded driver \SystemRoot\system32\drivers\EAWDMFD.sys
Did not load driver \SystemRoot\System32\Drivers\sglfb.SYS
Did not load driver \SystemRoot\System32\Drivers\tga.SYS
Loaded driver \SystemRoot\System32\drivers\vga.sys
Did not load driver mnmdd.SYS
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Did not load driver RasAcd.SYS
Did not load driver Tcpip.SYS
Did not load driver NetBT.SYS
Did not load driver NetBIOS.SYS
Did not load driver Parport.SYS
Did not load driver Serial.SYS
Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
Did not load driver \SystemRoot\System32\DRIVERS\redbook.sys
Did not load driver Rdbss.SYS
Did not load driver MRxSmb.SYS
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver photosmart 7150
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Microsoft WINMM WDM Audio Compatibility Driver
Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver photosmart 7150
Did not load driver Microsoft WINMM WDM Audio Compatibility Driver
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver photosmart 7150
Service Pack 4 4 15 2005 12:37:48.500
Loaded driver \WINNT\System32\ntoskrnl.exe
Loaded driver \WINNT\System32\hal.dll
Loaded driver \WINNT\System32\BOOTVID.DLL
Loaded driver ACPI.sys
Loaded driver \WINNT\System32\DRIVERS\WMILIB.SYS
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver intelide.sys
Loaded driver \WINNT\System32\DRIVERS\PCIIDEX.SYS
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver Diskperf.sys
Loaded driver dmload.sys
Loaded driver dmio.sys
Loaded driver PartMgr.sys
Loaded driver atapi.sys
Loaded driver disk.sys
Loaded driver \WINNT\System32\DRIVERS\CLASSPNP.SYS
Loaded driver TPkd.sys
Loaded driver Fastfat.sys
Loaded driver KSecDD.sys
Loaded driver NDIS.sys
Loaded driver vvoice.sys
Loaded driver vpctcom.sys
Loaded driver vmodem.sys
Loaded driver NaiFsRec.sys
Loaded driver Mup.sys
Did not load driver Advanced Configuration and Power Interface (ACPI) PC
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Did not load driver Intel Corporation 810 Graphics Controller Hub
Did not load driver ESS Allegro PCI Audio (WDM)
Did not load driver PCTEL Platinum V.92 Modem
Did not load driver 3Com EtherLink XL 10/100 PCI For Complete PC Management NIC (3C905C-TX)
Loaded driver \SystemRoot\System32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\System32\DRIVERS\L8042pr2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\LMouFlt2.Sys
Loaded driver \SystemRoot\System32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\System32\DRIVERS\eaps2kbd.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdclass.sys
Did not load driver ECP Printer Port
Did not load driver Communications Port
Did not load driver MPU-401 Compatible MIDI Device
Did not load driver Standard Game Port
Loaded driver \SystemRoot\System32\DRIVERS\fdc.sys
Loaded driver \SystemRoot\System32\Drivers\Cdr4_2K.SYS
Loaded driver \SystemRoot\System32\Drivers\AFS2K.SYS
Loaded driver \SystemRoot\System32\Drivers\MxlW2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\uhcd.sys
Did not load driver Audio Codecs
Did not load driver Legacy Audio Drivers
Did not load driver Media Control Devices
Did not load driver Legacy Video Capture Devices
Did not load driver Video Codecs
Did not load driver Standard 56000 bps K56Flex Modem
Did not load driver WAN Miniport (L2TP)
Did not load driver WAN Miniport (IP)
Did not load driver WAN Miniport (PPTP)
Did not load driver Direct Parallel
Did not load driver WAN Miniport (ATW)
Loaded driver \SystemRoot\System32\DRIVERS\parallel.sys
Loaded driver \Sy
tomhawk23
Looks like the whole bootlog file didn't make it.

No hardware/software additions that I know of. At least the family all deny doing anything.
The missing file (EACMOS.SYS) is still missing.
Unhackme didn't find anything.
Deleted dcom_13.dll

Thanks.
Mosaic1
That bootlog is old. It is added to each time there is either a successful boot into Safe mode or you enable bootlogging for a startup.

Can you find the part from that last run please? You'll notice dates in there. Do a search for 2006 as a start.

You may have to reply more than once to fit all the logs into your response. Please be sure the entire contents of all logs is showing in your reponses. Thank you.

Please also go to start >Run and type cmd.exe
Press enter

When the command opens, copy and paste this command in and press enter: (to paste in, right click inside the command window and click paste on the menu)

type %windir%\system.ini >s.txt & Start Notepad s.txt

This will create a file named s.txt

Please post the contents of s.txt into your next reply here please.


Is your system a Compaq? Do you have the install disk there?
Also, can you look in System32\dllcache to see if there is a copy of
EACMOS.SYS in there please?


Let's see what smitrem finds. We usually run it in Safe mode but let's see how this goes in regular windows mode.

Download
smitrem.zip


Save the file to your desktop.
Double click on smitRem.exe to extract the files it contains.

This will create a folder named smitrem on your desktop.
We'll use it later.
------------

Download CCleaner.

http://www.filehippo.com/download_ccleaner.html

Install CCleaner
Launch CCleaner and look in the upper right corner and click on the "Options" button.
Click "Advanced" and remove the check by "Only delete files in Windows temp folders older than 48 hours".
Click OK
Do not run CCleaner yet. You will run it later in safe mode.


Download the trial version of Ewido Security Suite:

http://www.ewido.net/en/download/

Install ewido.
During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
Launch ewido
It will prompt you to update click the OK button and it will go to the main screen
On the left side of the main screen click update
Click on Start and let it update.
DO NOT run a scan yet. You will do that later in safe mode.
--------------------------

Sign off the internet. Close all unneeded programs.


Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.


Run Ewido:
Click on scanner
Click Complete System Scan and the scan will begin.
During the scan it will prompt you to clean files, click OK
When the scan is finished, look at the bottom of the screen and click the Save report button.
Save the report to your desktop


Start Ccleaner and click Run Cleaner


Go to Control Panel > Internet Options. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.

Go to Control Panel > Display. Click on the "Desktop" tab then click the "Customize Desktop" button. Click on the "Web" tab. Under "Web Pages" you should see an entry checked called something like "Security info" or similar.If it is there, select that entry and click the "Delete" button. Click OK then Apply and OK.




Restart the system.



Go for a free online Virus scan here:

http://www.pandasoftware.com/activescan/

Allow it to clean

Panda will have the option to create a log afer the scan has finished. Click the See Report button. Then click the save Report button. It will be saved under the name activescan.txt Do that and post that log into your next reply here.


Post a new HiJackThis log along with the results from ActiveScan and the ewido scan


Open C:\smitfiles.txt and post the contents of that file
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.