1
Tech Clinic / I Have "win32.p2p-Worm.Alcan.a" -- please help if you can.
« on: February 13, 2007, 11:08:49 PM »
Good advice.. I will certainly scan new files I'm unsure about in the future...
Thank You!
Thank You!
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
2007-01-08,15:40:46
System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)
Windows XP Home Edition Service Pack 2 (Build 2600)
- Administrative User - Completed Functions Allowed
Follow item(s) have been choosed:
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Runing Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<updateMgr><"C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1> [N/A]
<STYLEXP><C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide> [N/A]
<Second Copy><"C:\PROGRA~1\SecCopy\SecCopy.exe"> [Centered Systems]
<Taskbar Shuffle><C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe> [Jay Elaraj]
<DOpus><C:\Program Files\GPSoftware\Directory Opus\dopus.exe> [(Verified)GP Software]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Google Desktop Search><"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup> [Google]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
<ShowWnd><ShowWnd.exe> [N/A]
<Recguard><%WINDIR%\SMINST\RECGUARD.EXE> []
<NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe> [Ahead Software Gmbh]
<IgfxTray><C:\WINDOWS\system32\igfxtray.exe> [(Verified)Intel Corporation]
<HotKeysCmds><C:\WINDOWS\system32\hkcmd.exe> [(Verified)Intel Corporation]
<CHotkey><zHotkey.exe> []
<QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
<iTunesHelper><"C:\Program Files\iTunes\iTunesHelper.exe"> [(Verified)Apple Computer, Inc.]
<High Definition Audio Property Page Shortcut><HDAShCut.exe> [(Verified)Windows (R) Server 2003 DDK provider]
<High Definition Audio Property Page Shortcut><HDAShCut.exe> [(Verified)Windows (R) Server 2003 DDK provider]
<SoundMan><SOUNDMAN.EXE> [(Verified)Realtek Semiconductor Corp.]
<AlcWzrd><ALCWZRD.EXE> [RealTek Semicoductor Corp.]
<Alcmtr><ALCMTR.EXE> [(Verified)Realtek Semiconductor Corp.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><explorer.exe> [(Verified)Microsoft Corporation]
<Userinit><userinit.exe> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL> [Google]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><LogonUI.EXE> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{3CF9ECE0-1A9F-11D2-8C73-00C06C2005DE}><C:\Program Files\GPSoftware\Directory Opus\dopuslib.dll> [(Verified)GP Software]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
<WinlogonNotify: WgaLogon><WgaLogon.dll> [Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<Cleanup><; > [N/A]
<Gateway Extended Warranty><; > [N/A]
<msci><; > [N/A]
<SSC_UserPrompt><; > [N/A]
==================================
Startup Folders
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk --> C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [Adobe Systems, Inc.]><N>
[Adobe Reader Speed Launch]
<C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk --> C:\PROGRA~1\Adobe\ACROBA~2.0\Reader\READER~1.EXE [Adobe Systems Incorporated]><N>
[Suitcase Startup]
<C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Suitcase Startup.lnk --> C:\PROGRA~1\Extensis\SUITCA~1.2\Suitcase.exe [Extensis Products Group]><N>
[TabUserW.exe]
<C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TabUserW.exe.lnk --> C:\WINDOWS\system32\WTablet\TabUserW.exe [Wacom Technology, Corp.]><N>
==================================
Services
[Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
[Application Management / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[ATM Service / ATMsrvc][Stopped/Disabled]
<C:\WINDOWS\System32\ATMsrvc.exe><Adobe Systems Incorporated>
[Diskeeper / Diskeeper][Running/Auto Start]
<"C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe"><Diskeeper Corporation>
[Logical Disk Manager Administrative Service / dmadmin][Stopped/Manual Start]
<C:\WINDOWS\System32\dmadmin.exe /com><Microsoft Corp., Veritas Software>
[Human Interface Device Access / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"><Macrovision Corporation>
[iPod Service / iPod Service][Running/Manual Start]
<"C:\Program Files\iPod\bin\iPodService.exe"><Apple Computer, Inc.>
[Macromedia Licensing Service / Macromedia Licensing Service][Stopped/Manual Start]
<"C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"><N/A>
[Network Location Awareness (NLA) / Nla][Running/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\mswsock.dll><Microsoft Corporation>
[Removable Storage / NtmsSvc][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\ntmssvc.dll><Microsoft Corporation>
[Microsoft Office Diagnostics Service / odserv][Stopped/Manual Start]
<"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE"><Microsoft Corporation>
[PrismXL / PrismXL][Running/Auto Start]
<C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS><New Boundary Technologies, Inc.>
[Retrospect Launcher / RetroLauncher][Stopped/Disabled]
<C:\Program Files\Dantz\Retrospect\retrorun.exe><Dantz Development Corporation>
[Retrospect WD Service / RetroWDSvc][Stopped/Disabled]
<C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe><Dantz Development Corporation>
[StyleXPService / StyleXPService][Stopped/Auto Start]
<"C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe"><>
[TabletService / TabletService][Running/Auto Start]
<C:\WINDOWS\system32\Tablet.exe><Wacom Technology, Corp.>
[Telephony / TapiSrv][Running/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\tapisrv.dll><Microsoft Corporation>
[Universal Plug and Play Device Host / upnphost][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k LocalService-->%SystemRoot%\System32\upnphost.dll><Microsoft Corporation>
[Windows Management Instrumentation / winmgmt][Running/Auto Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\system32\wbem\WMIsvc.dll><Microsoft Corporation>
==================================
Drivers
[abp480n5 / abp480n5][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\ABP480N5.SYS><Microsoft Corporation>
[adpu160m / adpu160m][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\adpu160m.sys><Microsoft Corporation>
[agony / agony][Running/Manual Start]
<\??\C:\WINDOWS\system32\agony.sys><N/A>
[Aha154x / Aha154x][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\aha154x.sys><Microsoft Corporation>
[aic78u2 / aic78u2][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\aic78u2.sys><Microsoft Corporation>
[aic78xx / aic78xx][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\aic78xx.sys><Microsoft Corporation>
[AliIde / AliIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\aliide.sys><Acer Laboratories Inc.>
[AMD AGP Bus Filter Driver / amdagp][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\amdagp.sys><Advanced Micro Devices, Inc.>
[asc / asc][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\asc.sys><Advanced System Products, Inc.>
[asc3350p / asc3350p][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\asc3350p.sys><Microsoft Corporation>
[asc3550 / asc3550][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\asc3550.sys><Advanced System Products, Inc.>
[ASPI32 / ASPI32][Running/Auto Start]
<System32\drivers\aspi32.sys><Adaptec>
[Audio Stub Driver / audstub][Running/Manual Start]
<system32\DRIVERS\audstub.sys><Microsoft Corporation>
[cd20xrnt / cd20xrnt][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\cd20xrnt.sys><Microsoft Corporation>
[CmdIde / CmdIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\cmdide.sys><CMD Technology, Inc.>
[dac2w2k / dac2w2k][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\dac2w2k.sys><Mylex Corporation>
[dpti2o / dpti2o][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\dpti2o.sys><Microsoft Corporation>
[Intel(R) PRO Adapter Driver / E100B][Running/Manual Start]
<system32\DRIVERS\e100b325.sys><Intel Corporation>
[GEARAspiWDM / GEARAspiWDM][Running/Manual Start]
<System32\Drivers\GEARAspiWDM.sys><GEAR Software Inc.>
[Microsoft UAA Function Driver for High Definition Audio Service / HdAudAddService][Stopped/Manual Start]
<system32\drivers\HdAudio.sys><Windows (R) Server 2003 DDK provider>
[Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
<system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
[HSFHWBS2 / HSFHWBS2][Running/Manual Start]
<system32\DRIVERS\HSFHWBS2.sys><Conexant Systems, Inc.>
[HSF_DP / HSF_DP][Running/Manual Start]
<system32\DRIVERS\HSF_DP.sys><Conexant Systems, Inc.>
[ialm / ialm][Stopped/Manual Start]
<system32\DRIVERS\ialmnt5.sys><Intel Corporation>
[Hauppauge WinTV PVR USB2 Encoder / iComp][Stopped/Manual Start]
<system32\DRIVERS\HCWUSB2.sys><Hauppauge Computer Works, Inc.>
[ini910u / ini910u][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\ini910u.sys><Microsoft Corporation>
[WD Bridge Controller Driver / inibtmgr][Stopped/Manual Start]
<system32\DRIVERS\inibtmgr.sys><Western Digital>
[Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
<system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
[PnP ISA/EISA Bus Driver / isapnp][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\isapnp.sys><Microsoft Corporation>
[Jukebox / Jukebox][Stopped/Manual Start]
<system32\DRIVERS\ctpdusb2.sys><Creative Technology Ltd.>
[mdmxsdk / mdmxsdk][Running/Auto Start]
<system32\DRIVERS\mdmxsdk.sys><Conexant>
[Mouse HID Driver / mouhid][Running/Manual Start]
<system32\DRIVERS\mouhid.sys><Microsoft Corporation>
[mraid35x / mraid35x][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\mraid35x.sys><American Megatrends Inc.>
[MRxSmb / MRxSmb][Running/System Start]
<system32\DRIVERS\mrxsmb.sys><Microsoft Corporation>
[Macronix MX987xx Family Fast Ethernet NT Driver / mxnic][Stopped/Manual Start]
<system32\DRIVERS\mxnic.sys><Macronix International Co., Ltd.>
[Remote Access NDIS TAPI Driver / NdisTapi][Running/Manual Start]
<system32\DRIVERS\ndistapi.sys><Microsoft Corporation>
[NetBios over Tcpip / NetBT][Running/System Start]
<system32\DRIVERS\netbt.sys><Microsoft Corporation>
[nv / nv][Running/Manual Start]
<system32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
[Pen Class / PenClass][Running/Boot Start]
<\SystemRoot\system32\Drivers\PenClass.sys><Wacom Technology Corporation>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[ql1080 / ql1080][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\ql1080.sys><QLogic Corporation>
[Ql10wnt / Ql10wnt][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\ql10wnt.sys><Microsoft Corporation>
[ql12160 / ql12160][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\ql12160.sys><QLogic Corporation>
[ql1280 / ql1280][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\ql1280.sys><QLogic Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><N/A>
[SIS AGP Bus Filter / sisagp][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\sisagp.sys><Silicon Integrated Systems Corporation>
[Sony USB Filter Driver (SONYPVU1) / SONYPVU1][Stopped/Manual Start]
<system32\DRIVERS\SONYPVU1.SYS><Sony Corporation>
[Sparrow / Sparrow][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\sparrow.sys><Adaptec, Inc.>
[StyleXPHelper / StyleXPHelper][Running/System Start]
<\??\C:\Program Files\TGTSoft\StyleXP\StyleXPHelper.exe><Windows (R) 2000 DDK provider>
[Alcor Micro Corp Reader / SunkFilt][Running/Manual Start]
<\??\C:\WINDOWS\System32\Drivers\sunkfilt.sys><Alcor Micro Corp.>
[symc810 / symc810][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\symc810.sys><Symbios Logic Inc.>
[symc8xx / symc8xx][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\symc8xx.sys><LSI Logic>
[sym_hi / sym_hi][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\sym_hi.sys><LSI Logic>
[sym_u3 / sym_u3][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\sym_u3.sys><LSI Logic>
[TosIde / TosIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\toside.sys><Microsoft Corporation>
[ultra / ultra][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\ultra.sys><Promise Technology, Inc.>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[WAN Miniport (ATW) / wanatw][Stopped/Manual Start]
<system32\DRIVERS\wanatw4.sys><N/A>
[winachsf / winachsf][Running/Manual Start]
<system32\DRIVERS\HSF_CNXT.sys><Conexant Systems, Inc.>
[World Standard Teletext Codec / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
==================================
Browser Add-ons
[HelperObject Class]
{00C6482D-C502-44C8-8409-FCE54AD9C208} <C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll, TechSmith Corporation>
[&Research]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL, Microsoft Corporation>
[Real.com]
{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} <C:\WINDOWS\system32\Shdocvw.dll, Microsoft Corporation>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[SnagIt]
{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} <C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll, TechSmith Corporation>
[]
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <C:\WINDOWS\system32\macromed\download\Download.dll, Macromedia, Inc.>
[ActiveScan Installer Class]
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} <C:\WINDOWS\Downloaded Program Files\asinst.dll, Panda Software>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[ASPRO Installer Class]
{D6376DD2-C2BD-49B2-A1B1-138F869633F3} <C:\WINDOWS\Downloaded Program Files\ASPROinst.dll, Panda Software>
[HelperObject Class]
{00C6482D-C502-44C8-8409-FCE54AD9C208} <C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll, TechSmith Corporation>
[SnagIt]
{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} <C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll, TechSmith Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[Add to Windows &Live Favorites]
<http://favorites.live.com/quickadd.aspx, N/A>
[E&xport to Microsoft Excel]
<res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000, N/A>
==================================
Running Processes
[PID: 536][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 680][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 704][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\igfxsrvc.dll] [Intel Corporation, 3.0.0.3889]
[C:\WINDOWS\system32\hccutils.DLL] [Intel Corporation, 3.0.0.3889]
[PID: 748][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 760][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 916][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1028][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1120][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1220][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1356][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1504][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\CNMLM4d.DLL] [CANON INC., 1.62.2.2]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\CNMPD4d.DLL] [CANON INC., 1.62.2.2]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNMUI4d.DLL] [CANON INC., 1.62.2.2]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNMDR4d.DLL] [CANON INC., 1.62.2.2]
[PID: 1636][C:\WINDOWS\system32\msdtc.exe] [Microsoft Corporation, 2001.12.4414.258]
[PID: 1708][C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe] [Diskeeper Corporation, 10.0.608.0]
[C:\Program Files\Diskeeper Corporation\Diskeeper\DKLib.dll] [Diskeeper Corporation, 10.0.608.0]
[C:\Program Files\Diskeeper Corporation\Diskeeper\GetFATExtents.dll] [Diskeeper Corporation, 10.0.608.0]
[C:\Program Files\Diskeeper Corporation\Diskeeper\1033\DkRes.dll] [Diskeeper Corporation, 10.0.608.0]
[C:\Program Files\Diskeeper Corporation\Diskeeper\Tab.dll] [Diskeeper® Corporation., 1.0.37.0]
[C:\Program Files\Diskeeper Corporation\Diskeeper\DkTabProvider.dll] [Diskeeper Corporation, 10.0.608.0]
[C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS] [New Boundary Technologies, Inc., 6.0.3.30]
[PID: 1776][C:\WINDOWS\system32\locator.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1860][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\CNQU86.DLL] [CANON INC., 1, 0, 2, 3]
[C:\WINDOWS\system32\CNQL3203.DLL] [, 1, 0, 0, 5]
[PID: 1916][C:\WINDOWS\system32\Tablet.exe] [Wacom Technology, Corp., 4.91-2]
[PID: 448][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 396][C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe] [Google, 4.2006.1008.2039]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopResources_en.dll] [Google, 4.2006.1008.2039]
[PID: 812][C:\WINDOWS\zHotkey.exe] [, 3, 0, 0, 7]
[C:\WINDOWS\HKNTDLL.dll] [N/A, N/A]
[PID: 1144][C:\Program Files\QuickTime\qttask.exe] [Apple Computer, Inc., 7.1.3]
[PID: 824][C:\Program Files\iTunes\iTunesHelper.exe] [Apple Computer, Inc., 7.0.2.16]
[C:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.DLL] [Apple Computer, Inc., 7.0.2.16]
[C:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.DLL] [Apple Computer, Inc., 7.0.2.16]
[PID: 1736][C:\WINDOWS\SOUNDMAN.EXE] [Realtek Semiconductor Corp., 1, 0, 0, 17]
[PID: 1524][C:\WINDOWS\ALCWZRD.EXE] [RealTek Semicoductor Corp., 1.1.0.23]
[PID: 2076][C:\PROGRA~1\SecCopy\SecCopy.exe] [Centered Systems, 7.0.0.163]
[PID: 2092][C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe] [Jay Elaraj, 2.0.0.164]
[C:\Program Files\Taskbar Shuffle\tbhookin.dll] [, 2.0.0.469]
[PID: 2100][C:\Program Files\GPSoftware\Directory Opus\dopus.exe] [GP Software, 2, 0, 0, 0]
[C:\Program Files\GPSoftware\Directory Opus\dopuslib.dll] [GP Software, 2, 0, 60, 0]
[C:\Program Files\GPSoftware\Directory Opus\dopusbch.dll] [Jan van den Baard, modifications (with permission) by GP Software, 6, 0, 0, 4]
[C:\Program Files\GPSoftware\Directory Opus\exif.dll] [GP Software, 1, 0, 0, 6]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[C:\WINDOWS\HKNTDLL.dll] [N/A, N/A]
[C:\Program Files\Ace Utilities\wipext.dll] [N/A, N/A]
[C:\Program Files\Ace Utilities\WIPE.dll] [N/A, N/A]
[C:\WINDOWS\system32\amstream.dll] [N/A, N/A]
[C:\WINDOWS\system32\quartz.dll] [N/A, N/A]
[C:\WINDOWS\system32\devenum.dll] [N/A, N/A]
[C:\WINDOWS\system32\msdmo.dll] [N/A, N/A]
[C:\Program Files\K-Lite Codec Pack\filters\vsfilter.dll] [Gabest, 1, 0, 0, 9]
[C:\Program Files\K-Lite Codec Pack\filters\3ivxDSMediaSplitter.ax] [3ivx.com, 4, 5, 1, 30]
[C:\WINDOWS\system32\OpenQuicktimeLib.dll] [N/A, N/A]
[C:\Program Files\Sony\Shared Plug-Ins\File Formats\MCMPEG\mcspmpeg.ax] [MainConcept AG, 1, 0, 1, 3]
[C:\Program Files\Sony\Shared Plug-Ins\File Formats\MCMPEG\mpegin.dll] [MainConcept AG, official release build]
[C:\WINDOWS\system32\mpg2splt.ax] [N/A, N/A]
[C:\Program Files\Sony\Shared Plug-Ins\File Formats\MCMPEG\mcdsmpeg.ax] [MainConcept AG, 1, 0, 0, 73]
[C:\Program Files\Sony\Shared Plug-Ins\File Formats\MCMPEG\mcmpgdec.dll] [MainConcept AG, official release build]
[C:\WINDOWS\system32\dxmasf.dll] [N/A, N/A]
[C:\Program Files\Common Files\Ahead\DSFilter\NeVideo.ax] [Ahead Software AG, 2, 0, 1, 0]
[C:\Program Files\Common Files\Ahead\Lib\AdvrCntr.dll] [Ahead Software AG, 1,0,13, 2121]
[C:\Program Files\GPSoftware\Directory Opus\Viewers\jp2raw.dll] [http://www.PretentiousName.com, 1, 1, 0, 0]
[C:\Program Files\GPSoftware\Directory Opus\Viewers\movie.dll] [GP Software, 1, 0, 0, 4]
[C:\Program Files\GPSoftware\Directory Opus\Viewers\wma.dll] [GP Software, 1, 0, 0, 3]
[C:\Program Files\GPSoftware\Directory Opus\Viewers\textthumb.dll] [http://www.PretentiousName.com, 1, 2, 0, 0]
[C:\Program Files\GPSoftware\Directory Opus\Viewers\gifanim.dll] [http://www.PretentiousName.com, 1, 1, 0, 8]
[C:\Program Files\GPSoftware\Directory Opus\Viewers\ogg.dll] [http://www.gpsoft.com.au, 1, 0, 0, 4]
[C:\Program Files\GPSoftware\Directory Opus\Viewers\targa.dll] [GP Software, 1, 0, 0, 4]
[C:\Program Files\GPSoftware\Directory Opus\Viewers\text.dll] [GP Software, 1, 0, 0, 12]
[PID: 2108][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2184][C:\Program Files\Extensis\Suitcase 9.2\Suitcase.exe] [Extensis Products Group, 9.2]
[C:\Program Files\Extensis\Suitcase 9.2\EToolBox.dll] [Extensis, Inc., 1.0.6]
[C:\Program Files\Extensis\Suitcase 9.2\slp.dll] [N/A, N/A]
[C:\Program Files\Extensis\Suitcase 9.2\SCAfmSup.dll] [Extensis Products Group, 1, 0, 0, 1]
[C:\Program Files\Extensis\Suitcase 9.2\SCAtmSup.dll] [Extensis Products Group, 1, 0, 0, 1]
[C:\WINDOWS\system32\ATMLIB.dll] [Adobe Systems, 5.1 Build 226]
[PID: 2196][C:\WINDOWS\system32\WTablet\TabUserW.exe] [Wacom Technology, Corp., 4.91-2]
[PID: 2208][C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe] [Google, 4.2006.1008.2039]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopAPI2.dll] [Google, 4.2006.1008.2039]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopHyper.dll] [Google, 4.2006.1008.2039]
[C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL] [Google, 4.2006.1008.2039]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopResources_en.dll] [Google, 4.2006.1008.2039]
[C:\Program Files\Google\Google Desktop Search\gzlib.dll] [N/A, N/A]
[C:\WINDOWS\HKNTDLL.dll] [N/A, N/A]
[PID: 2220][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2420][C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe] [Google, 4.2006.1008.2039]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopAPI2.dll] [Google, 4.2006.1008.2039]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopResources_en.dll] [Google, 4.2006.1008.2039]
[C:\Program Files\Google\Google Desktop Search\gzlib.dll] [N/A, N/A]
[C:\WINDOWS\system32\icm32.dll] [Microsoft Corporation, 5.1.2600.2709 (xpsp_sp2_gdr.050628-1518)]
[PID: 2452][C:\Program Files\iPod\bin\iPodService.exe] [Apple Computer, Inc., 7.0.2.16]
[C:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.DLL] [Apple Computer, Inc., 7.0.2.16]
[C:\Program Files\iPod\bin\iPodService.Resources\iPodService.DLL] [Apple Computer, Inc., 7.0.2.16]
[PID: 820][C:\Program Files\Microsoft Office\Office10\WINWORD.EXE] [Microsoft Corporation, 10.0.2627]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopOffice.dll] [Google, 4.2006.1008.2039]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopResources_en.dll] [Google, 4.2006.1008.2039]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopAPI2.dll] [Google, 4.2006.1008.2039]
[C:\Program Files\TechSmith\SnagIt 8\SnagItOfficeAddin.dll] [TechSmith Corporation, 1.1.0]
[C:\Program Files\TechSmith\SnagIt 8\SnagItOfficeAddinRes.dll] [TechSmith Corporation, 1.1.0]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNMUI4d.DLL] [CANON INC., 1.62.2.2]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNMDR4d.DLL] [CANON INC., 1.62.2.2]
[PID: 184][C:\Documents and Settings\Owner\Desktop\gmer.exe] [N/A, 1, 0, 12, 12011]
[C:\WINDOWS\gmer.dll] [N/A, 1, 0, 12, 12011]
[C:\Program Files\GPSoftware\Directory Opus\dopuslib.dll] [GP Software, 2, 0, 60, 0]
[C:\WINDOWS\HKNTDLL.dll] [N/A, N/A]
[PID: 3652][C:\WINDOWS\explorer.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\GPSoftware\Directory Opus\dopuslib.dll] [GP Software, 2, 0, 60, 0]
[C:\Program Files\Taskbar Shuffle\tbhookin.dll] [, 2.0.0.469]
[C:\Program Files\SmartFTP\smarthook.dll] [SmartFTP, 1.0.2.1]
[C:\Program Files\WinSCP3\DragExt.dll] [Martin Prikryl, 1.1.5.67]
[C:\Program Files\Ashampoo\Ashampoo WinOptimizer Platinum 3\ContextHandler.dll] [N/A, N/A]
[C:\Program Files\Ace Utilities\wipext.dll] [N/A, N/A]
[C:\Program Files\Ace Utilities\WIPE.dll] [N/A, N/A]
[C:\Program Files\WinRAR\rarext.dll] [N/A, N/A]
[C:\Program Files\TextPad 4\System\shellext.dll] [Helios Software Solutions, 1.4]
[C:\Program Files\TechSmith\SnagIt 8\SnagItShellExt.dll] [TechSmith Corporation, 1.0.2.0]
[C:\Program Files\eFax Messenger 4.0\J2GShell.dll] [j2 Global Communications, Inc., 4.0.134.0]
[C:\Program Files\eFax Messenger 4.0\J2GRes_Enu.dll] [j2 Global Communications, Inc., 4.0.134.0]
[PID: 3280][C:\Program Files\Windows NT\Accessories\wordpad.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\GPSoftware\Directory Opus\dopuslib.dll] [GP Software, 2, 0, 60, 0]
[C:\WINDOWS\HKNTDLL.dll] [N/A, N/A]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNMUI4d.DLL] [CANON INC., 1.62.2.2]
[C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CNMDR4d.DLL] [CANON INC., 1.62.2.2]
[PID: 500][C:\Program Files\Mozilla Firefox\firefox.exe] [Mozilla Corporation, 1.8.1.1: 2006120418]
[C:\Program Files\Mozilla Firefox\js3250.dll] [Netscape Communications Corporation, 4.0]
[C:\Program Files\Mozilla Firefox\nspr4.dll] [Netscape Communications Corporation, 4.6.4]
[C:\Program Files\Mozilla Firefox\xpcom_core.dll] [Mozilla Foundation, 1.8.1.1: 2006120418]
[C:\Program Files\Mozilla Firefox\plc4.dll] [Netscape Communications Corporation, 4.6.4]
[C:\Program Files\Mozilla Firefox\plds4.dll] [Netscape Communications Corporation, 4.6.4]
[C:\Program Files\Mozilla Firefox\smime3.dll] [Mozilla Foundation, 3.11.4 Basic ECC]
[C:\Program Files\Mozilla Firefox\nss3.dll] [Mozilla Foundation, 3.11.4 Basic ECC]
[C:\Program Files\Mozilla Firefox\softokn3.dll] [Mozilla Foundation, 3.11.4 Basic ECC]
[C:\Program Files\Mozilla Firefox\ssl3.dll] [Mozilla Foundation, 3.11.4 Basic ECC]
[C:\Program Files\Mozilla Firefox\xpcom_compat.dll] [Mozilla Foundation, 1.8.1.1: 2006120418]
[C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL] [Google, 4.2006.1008.2039]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopResources_en.dll] [Google, 4.2006.1008.2039]
[C:\Program Files\Mozilla Firefox\components\myspell.dll] [Mozilla Foundation, 1.8.1.1: 2006120418]
[C:\Program Files\Mozilla Firefox\components\GoogleDesktopMozilla.dll] [Google, 4.2006.1008.2039]
[C:\Program Files\Mozilla Firefox\xpcom.dll] [Mozilla Foundation, 1.8.1.1: 2006120418]
[C:\Program Files\Google\Google Desktop Search\GoogleDesktopAPI2.dll] [Google, 4.2006.1008.2039]
[C:\Program Files\Mozilla Firefox\components\jar50.dll] [Mozilla Foundation, 1.8.1.1: 2006120418]
[C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ygl5nnqq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll] [N/A, N/A]
[C:\Program Files\GPSoftware\Directory Opus\dopuslib.dll] [GP Software, 2, 0, 60, 0]
[C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ygl5nnqq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll] [N/A, N/A]
[C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ygl5nnqq.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\components\FoxyTunes.dll] [N/A, N/A]
[C:\Program Files\Mozilla Firefox\freebl3.dll] [Mozilla Foundation, 3.11.4 Basic ECC]
[C:\PROGRA~1\MOZILL~1\nssckbi.dll] [Mozilla Foundation, 1.62]
[C:\Program Files\Mozilla Firefox\components\spellchk.dll] [Mozilla Foundation, 1.8.1.1: 2006120418]
[C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ygl5nnqq.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\components\ColorZilla.dll] [N/A, N/A]
[C:\Program Files\Mozilla Firefox\plugins\npmozax.dll] [, 1, 0, 0, 4]
[C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll] [N/A, N/A]
[C:\Program Files\Google\Google Desktop Search\gzlib.dll] [N/A, N/A]
[C:\WINDOWS\HKNTDLL.dll] [N/A, N/A]
[C:\Program Files\Dell\Dell DJ Explorer\CTOJBNS.DLL] [Creative Technology Ltd, 1.00.13]
[C:\Program Files\Dell\Dell DJ Explorer\CTIntrfc.dll] [Creative Technology Ltd, 1.1.1.0]
[C:\Program Files\Dell\Dell DJ Explorer\DFMHK.dll] [Creative Technology Ltd, 1.0.1.0]
[C:\Program Files\Dell\Dell DJ Explorer\CTOJBRES.DLL] [Creative Technology Ltd, 1.00.11]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0]
[PID: 3100][C:\Documents and Settings\Owner\Desktop\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\Program Files\GPSoftware\Directory Opus\dopuslib.dll] [GP Software, 2, 0, 60, 0]
==================================
File Associations
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS Error. ["C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" "%1"]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock Provider
N/A
==================================
Autorun.Inf
N/A
==================================
HOSTS File
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
:18 total references