Here are the results of the OTscanIt2:
[code]OTScanIt2 logfile created on: 3/29/2009 12:49:20 PM - Run 1
OTScanIt2 by OldTimer - Version 1.0.9.1 Folder = C:\Documents and Settings\jim.dalessandro\Desktop\OTScanIt2
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
502.36 Mb Total Physical Memory | 138.29 Mb Available Physical Memory | 27.53% Memory free
1.20 Gb Paging File | 0.88 Gb Available in Paging File | 73.51% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 51.29 Gb Total Space | 18.57 Gb Free Space | 36.20% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JIMDALESANDRO
Current User Name: jim.dalessandro
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
[Processes - Safe List]
acprfmgrsvc.exe -> %ProgramFiles%\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe -> [2007/02/19 19:15:10 | 00,053,248 | ---- | M] ()
acsvc.exe -> %ProgramFiles%\ThinkPad\ConnectUtilities\AcSvc.exe -> [2007/02/19 19:15:14 | 00,172,032 | ---- | M] (Lenovo)
avgrsx.exe -> %ProgramFiles%\AVG\AVG8\avgrsx.exe -> [2009/02/05 09:29:00 | 00,484,120 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgwdsvc.exe -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2009/02/05 09:28:57 | 00,298,264 | ---- | M] (AVG Technologies CZ, s.r.o.)
brss01a.exe -> %SystemRoot%\system32\brss01a.exe -> [2001/12/13 00:01:00 | 00,045,056 | ---- | M] (brother Industries Ltd)
brsvc01a.exe -> %SystemRoot%\system32\brsvc01a.exe -> [2001/11/23 00:00:00 | 00,057,344 | ---- | M] (brother Industries Ltd)
ctsvccda.exe -> %SystemRoot%\system32\CTsvcCDA.exe -> [1999/12/12 13:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd)
evteng.exe -> %ProgramFiles%\Intel\Wireless\Bin\EvtEng.exe -> [2006/08/02 03:39:20 | 00,434,176 | ---- | M] (Intel Corporation)
explorer.exe -> %SystemRoot%\explorer.exe -> [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
ezejmnap.exe -> %ProgramFiles%\ThinkPad\Utilities\EZEJMNAP.EXE -> [2006/02/23 13:22:00 | 00,237,568 | ---- | M] (Lenovo Group Limited)
ibmpmsvc.exe -> %SystemRoot%\system32\ibmpmsvc.exe -> [2007/02/27 22:09:06 | 00,036,400 | ---- | M] (Lenovo)
ipssvc.exe -> %SystemRoot%\system32\IPSSVC.EXE -> [2006/08/16 13:07:00 | 00,073,728 | ---- | M] (Lenovo Group Limited)
iuservice.exe -> %ProgramFiles%\Lenovo\Rescue and Recovery\ADM\IUService.exe -> [2006/07/14 18:52:48 | 00,045,056 | ---- | M] ()
jqs.exe -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2009/03/17 12:31:58 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.)
logmon.exe -> %CommonProgramFiles%\Lenovo\Logger\logmon.exe -> [2006/07/14 20:36:00 | 00,022,016 | ---- | M] ()
mdm.exe -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/20 02:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation)
mstbsvc.exe -> %ProgramFiles%\MSN\Toolbar\3.0.0988.2\mstbsvc.exe -> [2008/12/04 12:29:28 | 00,100,184 | ---- | M] (Microsoft Corp.)
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2009/03/27 10:59:42 | 00,492,544 | ---- | M] (OldTimer Tools)
regsrvc.exe -> %ProgramFiles%\Intel\Wireless\Bin\RegSrvc.exe -> [2006/08/02 03:24:22 | 00,327,680 | ---- | M] (Intel Corporation)
rrservice.exe -> %ProgramFiles%\Lenovo\Rescue and Recovery\rrservice.exe -> [2006/07/14 21:01:00 | 01,974,272 | ---- | M] (Lenovo Group Limited)
s24evmon.exe -> %ProgramFiles%\Intel\Wireless\Bin\S24EvMon.exe -> [2006/08/02 03:31:22 | 00,937,984 | ---- | M] (Intel Corporation )
smax4pnp.exe -> %ProgramFiles%\Analog Devices\Core\smax4pnp.exe -> [2005/05/19 20:11:06 | 00,925,696 | ---- | M] (Analog Devices, Inc.)
suservice.exe -> %ProgramFiles%\lenovo\system update\suservice.exe -> [2007/02/12 05:35:42 | 00,013,312 | ---- | M] (Lenovo Group Limited)
svcguihlpr.exe -> %ProgramFiles%\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe -> [2007/02/19 19:15:58 | 00,106,496 | ---- | M] ()
syntpenh.exe -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe -> [2006/02/14 01:16:28 | 00,512,000 | ---- | M] (Synaptics, Inc.)
syntplpr.exe -> %ProgramFiles%\Synaptics\SynTP\SynTPLpr.exe -> [2006/02/14 01:17:28 | 00,110,592 | ---- | M] (Synaptics, Inc.)
tphdexlg.exe -> %SystemRoot%\System32\TPHDEXLG.EXE -> [2005/06/20 15:15:00 | 00,077,824 | ---- | M] (Lenovo.)
tphkmgr.exe -> %ProgramFiles%\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe -> [2006/07/24 21:19:40 | 00,094,208 | ---- | M] ()
tpkmpsvc.exe -> %SystemRoot%\system32\TpKmpSVC.exe -> [2005/06/07 00:26:22 | 00,032,768 | ---- | M] ()
tponscr.exe -> %ProgramFiles%\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe -> [2005/07/05 01:57:12 | 00,077,824 | ---- | M] ()
tpscrex.exe -> %ProgramFiles%\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe -> [2006/05/30 02:05:42 | 00,086,016 | ---- | M] (Lenovo Group Limited)
tpshocks.exe -> %SystemRoot%\system32\TpShocks.exe -> [2006/03/15 22:04:48 | 00,106,496 | ---- | M] (Lenovo, Ltd. and IBM Corporation.)
tvt_reg_monitor_svc.exe -> %CommonProgramFiles%\Lenovo\tvt_reg_monitor_svc.exe -> [2006/07/14 20:24:52 | 00,629,504 | ---- | M] ()
tvtsched.exe -> %CommonProgramFiles%\Lenovo\Scheduler\tvtsched.exe -> [2006/12/10 22:36:22 | 01,118,208 | ---- | M] (Lenovo Group Limited)
tvttcsd.exe -> %ProgramFiles%\Lenovo\Client Security Solution\tvttcsd.exe -> [2006/07/14 20:42:22 | 00,723,712 | ---- | M] (IBM)
winvnc4.exe -> %ProgramFiles%\RealVNC\VNC4\WinVNC4.exe -> [2006/05/12 18:04:08 | 00,439,248 | ---- | M] (RealVNC Ltd.)
wmpnetwk.exe -> %ProgramFiles%\Windows Media Player\WMPNetwk.exe -> [2006/10/18 23:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation)
[Win32 Services - Safe List]
(AcPrfMgrSvc) Ac Profile Manager Service [Win32_Own | Auto | Running] -> %ProgramFiles%\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe -> [2007/02/19 19:15:10 | 00,053,248 | ---- | M] ()
(AcSvc) Access Connections Main Service [Win32_Own | Auto | Running] -> %ProgramFiles%\ThinkPad\ConnectUtilities\AcSvc.exe -> [2007/02/19 19:15:14 | 00,172,032 | ---- | M] (Lenovo)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation)
(avg8wd) AVG8 WatchDog [Win32_Own | Auto | Running] -> %ProgramFiles%\AVG\AVG8\avgwdsvc.exe -> [2009/02/05 09:28:57 | 00,298,264 | ---- | M] (AVG Technologies CZ, s.r.o.)
(Brother XP spl Service) BrSplService [Win32_Own | Auto | Running] -> %SystemRoot%\system32\brsvc01a.exe -> [2001/11/23 00:00:00 | 00,057,344 | ---- | M] (brother Industries Ltd)
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation)
(Creative Service for CDROM Access) Creative Service for CDROM Access [Win32_Own | Auto | Running] -> %SystemRoot%\system32\CTsvcCDA.exe -> [1999/12/12 13:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd)
(EvtEng) Intel(R) PROSet/Wireless Event Log [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\EvtEng.exe -> [2006/08/02 03:39:20 | 00,434,176 | ---- | M] (Intel Corporation)
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2008/02/04 23:40:02 | 00,138,168 | ---- | M] (Google)
(helpsvc) Help and Support [Win32_Shared | Auto | Running] -> %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation)
(IBMPMSVC) ThinkPad PM Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\ibmpmsvc.exe -> [2007/02/27 22:09:06 | 00,036,400 | ---- | M] (Lenovo)
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> [2005/04/04 03:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation)
(IPSSVC) IPS Core Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\IPSSVC.EXE -> [2006/08/16 13:07:00 | 00,073,728 | ---- | M] (Lenovo Group Limited)
(Irmon) Infrared Monitor [Win32_Shared | Auto | Running] -> %SystemRoot%\System32\irmon.dll -> [2008/04/13 20:11:55 | 00,028,160 | ---- | M] (Microsoft Corporation)
(JavaQuickStarterService) Java Quick Starter [Win32_Own | Auto | Running] -> %ProgramFiles%\Java\jre6\bin\jqs.exe -> [2009/03/17 12:31:58 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.)
(MDM) Machine Debug Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/20 02:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation)
(mstbsvc) MSN Toolbar Setup [Win32_Own | Auto | Running] -> %ProgramFiles%\MSN\Toolbar\3.0.0988.2\mstbsvc.exe -> [2008/12/04 12:29:28 | 00,100,184 | ---- | M] (Microsoft Corp.)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2003/07/28 15:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation)
(PsaSrv) IBM PSA Access Driver Control [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\psasrv.exe -> [2007/05/11 20:56:02 | 00,023,552 | ---- | M] ()
(RegSrvc) Intel(R) PROSet/Wireless Registry Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\RegSrvc.exe -> [2006/08/02 03:24:22 | 00,327,680 | ---- | M] (Intel Corporation)
(S24EventMonitor) Intel(R) PROSet/Wireless Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\S24EvMon.exe -> [2006/08/02 03:31:22 | 00,937,984 | ---- | M] (Intel Corporation )
(SUService) System Update [Win32_Own | Auto | Running] -> %ProgramFiles%\lenovo\system update\suservice.exe -> [2007/02/12 05:35:42 | 00,013,312 | ---- | M] (Lenovo Group Limited)
(ThinkVantage Registry Monitor Service) ThinkVantage Registry Monitor Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Lenovo\tvt_reg_monitor_svc.exe -> [2006/07/14 20:24:52 | 00,629,504 | ---- | M] ()
(TPHDEXLGSVC) ThinkPad HDD APS Logging Service [Win32_Own | Auto | Running] -> %SystemRoot%\System32\TPHDEXLG.EXE -> [2005/06/20 15:15:00 | 00,077,824 | ---- | M] (Lenovo.)
(TpKmpSVC) IBM KCU Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\TpKmpSVC.exe -> [2005/06/07 00:26:22 | 00,032,768 | ---- | M] ()
(TSSCoreService) TSS Core Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Lenovo\Client Security Solution\tvttcsd.exe -> [2006/07/14 20:42:22 | 00,723,712 | ---- | M] (IBM)
(TVT Backup Service) TVT Backup Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Lenovo\Rescue and Recovery\rrservice.exe -> [2006/07/14 21:01:00 | 01,974,272 | ---- | M] (Lenovo Group Limited)
(TVT Scheduler) TVT Scheduler [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Lenovo\Scheduler\tvtsched.exe -> [2006/12/10 22:36:22 | 01,118,208 | ---- | M] (Lenovo Group Limited)
(tvtnetwk) tvtnetwk [Win32_Own | Auto | Running] -> %ProgramFiles%\Lenovo\Rescue and Recovery\ADM\IUService.exe -> [2006/07/14 18:52:48 | 00,045,056 | ---- | M] ()
(WinVNC4) VNC Server Version 4 [Win32_Own | Auto | Running] -> %ProgramFiles%\RealVNC\VNC4\WinVNC4.exe -> [2006/05/12 18:04:08 | 00,439,248 | ---- | M] (RealVNC Ltd.)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Windows Media Player\WMPNetwk.exe -> [2006/10/18 23:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation)
[Driver Services - Safe List]
(ac97intc) Intel(r) 82801 Audio Driver Install Service (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ac97intc.sys -> [2001/08/17 08:20:04 | 00,096,256 | ---- | M] (Intel Corporation)
(ADIHdAudAddService) ADI UAA Function Driver for High Definition Audio Service [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ADIHdAud.sys -> [2006/01/30 22:19:34 | 00,176,128 | ---- | M] (Analog Devices, Inc.)
(AEAudioService) AEAudio Service [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\AEAudio.sys -> [2006/04/26 17:42:40 | 00,093,824 | ---- | M] (Andrea Electronics Corporation)
(AegisP) AEGIS Protocol (IEEE 802.1x) v3.5.3.0 [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\AegisP.sys -> [2007/05/11 20:38:10 | 00,021,419 | ---- | M] (Meetinghouse Data Communications)
(AliIde) AliIde [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\aliide.sys -> [2001/08/17 16:51:56 | 00,005,248 | ---- | M] (Acer Laboratories Inc.)
(amdagp) AMD AGP Bus Filter Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\amdagp.sys -> [2008/04/13 14:36:39 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.)
(ANC) ANC [Kernel | System | Running] -> %SystemRoot%\System32\drivers\ANC.SYS -> [2005/11/08 12:27:20 | 00,011,520 | ---- | M] (IBM Corp.)
(asc) asc [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\asc.sys -> [2001/08/17 16:52:00 | 00,026,496 | ---- | M] (Advanced System Products, Inc.)
(asc3550) asc3550 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\asc3550.sys -> [2001/08/17 16:51:58 | 00,014,848 | ---- | M] (Advanced System Products, Inc.)
(ASPI32) ASPI32 [Kernel | System | Running] -> %SystemRoot%\System32\drivers\ASPI32.SYS -> [1999/09/10 13:06:00 | 00,025,244 | ---- | M] (Adaptec)
(atmeltpm) atmeltpm [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\atmeltpm.sys -> [2005/05/17 13:20:08 | 00,015,872 | ---- | M] (Atmel, Inc.)
(AvgLdx86) AVG AVI Loader Driver x86 [Kernel | System | Running] -> %SystemRoot%\System32\Drivers\avgldx86.sys -> [2009/02/05 09:29:00 | 00,325,128 | ---- | M] (AVG Technologies CZ, s.r.o.)
(AvgMfx86) AVG On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> %SystemRoot%\System32\Drivers\avgmfx86.sys -> [2009/02/05 09:29:00 | 00,027,656 | ---- | M] (AVG Technologies CZ, s.r.o.)
(CmdIde) CmdIde [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\cmdide.sys -> [2001/08/17 16:51:54 | 00,006,656 | ---- | M] (CMD Technology, Inc.)
(dac2w2k) dac2w2k [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\dac2w2k.sys -> [2001/08/17 16:52:16 | 00,179,584 | ---- | M] (Mylex Corporation)
(DLABOIOM) DLABOIOM [File_System | Auto | Running] -> %SystemRoot%\System32\DLA\DLABOIOM.SYS -> [2006/02/02 08:20:00 | 00,025,628 | ---- | M] (Sonic Solutions)
(DLACDBHM) DLACDBHM [File_System | System | Running] -> %SystemRoot%\System32\Drivers\DLACDBHM.SYS -> [2005/11/18 15:02:50 | 00,005,660 | ---- | M] (Sonic Solutions)
(DLADResN) DLADResN [File_System | Auto | Running] -> %SystemRoot%\System32\DLA\DLADResN.SYS -> [2006/02/02 08:20:00 | 00,002,496 | ---- | M] (Sonic Solutions)
(DLAIFS_M) DLAIFS_M [File_System | Auto | Running] -> %SystemRoot%\System32\DLA\DLAIFS_M.SYS -> [2006/02/02 08:20:00 | 00,086,652 | ---- | M] (Sonic Solutions)
(DLAOPIOM) DLAOPIOM [File_System | Auto | Running] -> %SystemRoot%\System32\DLA\DLAOPIOM.SYS -> [2006/02/02 08:20:00 | 00,014,684 | ---- | M] (Sonic Solutions)
(DLAPoolM) DLAPoolM [File_System | Auto | Running] -> %SystemRoot%\System32\DLA\DLAPoolM.SYS -> [2006/02/02 08:20:00 | 00,006,364 | ---- | M] (Sonic Solutions)
(DLARTL_N) DLARTL_N [File_System | System | Running] -> %SystemRoot%\System32\Drivers\DLARTL_N.SYS -> [2005/11/18 15:02:10 | 00,022,684 | ---- | M] (Sonic Solutions)
(DLAUDFAM) DLAUDFAM [File_System | Auto | Running] -> %SystemRoot%\System32\DLA\DLAUDFAM.SYS -> [2006/02/02 08:20:00 | 00,094,332 | ---- | M] (Sonic Solutions)
(DLAUDF_M) DLAUDF_M [File_System | Auto | Running] -> %SystemRoot%\System32\DLA\DLAUDF_M.SYS -> [2006/02/02 08:20:00 | 00,087,036 | ---- | M] (Sonic Solutions)
(DRVMCDB) DRVMCDB [Kernel | Boot | Running] -> %SystemRoot%\System32\Drivers\DRVMCDB.SYS -> [2006/03/01 06:30:00 | 00,089,472 | ---- | M] (Sonic Solutions)
(DRVNDDM) DRVNDDM [File_System | Auto | Running] -> %SystemRoot%\System32\Drivers\DRVNDDM.SYS -> [2005/11/18 08:20:00 | 00,040,544 | ---- | M] (Sonic Solutions)
(E100B) Intel(R) PRO Adapter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\e100b325.sys -> [2001/08/17 08:12:10 | 00,117,760 | ---- | M] (Intel Corporation)
(e1express) Intel(R) PRO/1000 PCI Express Network Connection Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\e1e5132.sys -> [2006/04/20 02:06:50 | 00,181,760 | ---- | M] (Intel Corporation)
(EGATHDRV) IBM eGatherer [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\EGATHDRV.SYS -> [2009/03/29 00:00:00 | 00,005,427 | ---- | M] (IBM Corporation)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\HDAudBus.sys -> [2008/04/13 12:36:05 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider)
(HSF_DPV) HSF_DPV [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\hsx_dpv.sys -> [2005/12/05 22:21:32 | 00,936,448 | ---- | M] (Conexant Systems, Inc.)
(HSXHWAZL) HSXHWAZL [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\hsxhwazl.sys -> [2005/12/05 22:20:48 | 00,192,512 | ---- | M] (Conexant Systems, Inc.)
(ialm) ialm [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ialmnt5.sys -> [2006/07/25 02:44:04 | 01,170,300 | ---- | M] (Intel Corporation)
(iaStor) Intel AHCI Controller [Kernel | Boot | Running] -> %SystemRoot%\system32\DRIVERS\iaStor.sys -> [2005/10/11 20:07:12 | 00,874,240 | ---- | M] (Intel Corporation)
(IBMPMDRV) IBMPMDRV [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ibmpmdrv.sys -> [2007/02/27 22:08:32 | 00,021,040 | ---- | M] (Lenovo.)
(IBMTPCHK) IBMTPCHK [Kernel | System | Running] -> %SystemRoot%\system32\Drivers\IBMBLDID.sys -> [2006/01/13 03:33:22 | 00,006,016 | ---- | M] ()
(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\mdmxsdk.sys -> [2005/10/05 02:57:08 | 00,012,544 | ---- | M] (Conexant)
(mraid35x) mraid35x [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\mraid35x.sys -> [2001/08/17 16:52:12 | 00,017,280 | ---- | M] (American Megatrends Inc.)
(NETw3x32) Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows XP 32 Bit [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\NETw3x32.sys -> [2006/09/27 05:36:24 | 01,709,696 | ---- | M] (Intel® Corporation)
(NSCIRDA) NSC Infrared Device Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\nscirda.sys -> [2008/04/13 14:54:36 | 00,028,672 | ---- | M] (National Semiconductor Corporation)
(nv) nv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\nv4_mini.sys -> [2004/08/03 18:29:56 | 01,897,408 | ---- | M] (NVIDIA Corporation)
(PalmUSBD) PalmUSBD [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\PalmUSBD.sys -> [2007/06/08 03:01:01 | 00,016,694 | ---- | M] (PalmSource, Inc.)
(pmem) pmem [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\pmemnt.sys -> [2007/05/11 20:55:09 | 00,007,012 | ---- | M] (Microsoft Corporation)
(PrivateDisk) PrivateDisk [Kernel | Auto | Running] -> %ProgramFiles%\Lenovo\SafeGuard PrivateDisk\PrivateDiskM.sys -> [2006/03/13 19:05:54 | 00,058,368 | R--- | M] (Utimaco Safeware AG)
(PROCDD) IPS Helper Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\PROCDD.SYS -> [2006/08/16 13:07:00 | 00,005,120 | ---- | M] (Lenovo Group Limited)
(psadd) Lenovo Parties Service Access Device Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\psadd.sys -> [2006/09/13 01:42:18 | 00,028,224 | ---- | M] (Lenovo (United States) Inc.)
(PTDCBus) PANTECH PC Card Composite Device Driver (UDP) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\PTDCBus.sys -> [2007/04/01 06:45:22 | 00,027,520 | ---- | M] (DEVGURU Co,LTD.)
(PTDCMdm) PANTECH PC Card Drivers (UDP) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\PTDCMdm.sys -> [2007/04/01 06:45:26 | 00,041,728 | ---- | M] (DEVGURU Co,LTD.)
(PTDCVsp) PANTECH PC Card Diagnostic Serial Port (UDP) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\PTDCVsp.sys -> [2007/04/01 06:45:30 | 00,039,808 | ---- | M] (DEVGURU Co,LTD.)
(PTDCWWAN) PANTECH PC Card WWAN Controller device driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\PTDCWWAN.sys -> [2007/04/30 20:30:14 | 00,058,240 | ---- | M] (DEVGURU Co,LTD.)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\ptilink.sys -> [2004/08/04 08:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.)
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\System32\Drivers\PxHelp20.sys -> [2006/10/18 04:00:00 | 00,036,624 | ---- | M] (Sonic Solutions)
(ql1080) ql1080 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\ql1080.sys -> [2001/08/17 16:52:20 | 00,040,320 | ---- | M] (QLogic Corporation)
(ql12160) ql12160 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\ql12160.sys -> [2001/08/17 16:52:20 | 00,045,312 | ---- | M] (QLogic Corporation)
(ql1280) ql1280 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\ql1280.sys -> [2001/08/17 16:52:18 | 00,049,024 | ---- | M] (QLogic Corporation)
(s24trans) WLAN Transport [Kernel | Auto | Running] -> %SystemRoot%\system32\DRIVERS\s24trans.sys -> [2006/08/02 04:27:48 | 00,012,544 | ---- | M] (Intel Corporation)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\DRIVERS\secdrv.sys -> [2007/11/13 06:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(ShockMgr) ShockMgr [Kernel | System | Running] -> %SystemRoot%\System32\drivers\ShockMgr.sys -> [2005/06/20 15:18:00 | 00,004,736 | ---- | M] (Lenovo.)
(Shockprf) Shockprf [Kernel | Boot | Running] -> %SystemRoot%\System32\drivers\shockprf.sys -> [2006/03/15 20:08:00 | 00,088,576 | ---- | M] (Lenovo)
(sisagp) SIS AGP Bus Filter [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\sisagp.sys -> [2008/04/13 14:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation)
(Smapint) Smapint [Kernel | System | Running] -> %SystemRoot%\System32\drivers\Smapint.sys -> [2006/08/02 12:54:00 | 00,014,848 | ---- | M] (Microsoft Corporation)
(smi2) smi2 [Kernel | Auto | Running] -> %ProgramFiles%\SMI2\smi2.sys -> [2006/07/14 18:55:12 | 00,003,968 | ---- | M] (IBM Corp.)
(smihlp) SMI helper driver [Kernel | Auto | Running] -> %ProgramFiles%\ThinkVantage Fingerprint Software\smihlp.sys -> [2006/04/25 22:00:00 | 00,003,456 | ---- | M] (UPEK Inc.)
(SMNDIS5) SMNDIS5 NDIS Protocol Driver [Kernel | On_Demand | Stopped] -> %ProgramFiles%\Verizon Wireless\VZAccess Manager\SMNDIS5.sys -> [2002/11/26 14:54:58 | 00,016,936 | ---- | M] (Smith Micro Software, Inc.)
(Sparrow) Sparrow [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\sparrow.sys -> [2001/08/17 17:07:44 | 00,019,072 | ---- | M] (Adaptec, Inc.)
(symc810) symc810 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\symc810.sys -> [2001/08/17 17:07:34 | 00,016,256 | ---- | M] (Symbios Logic Inc.)
(symc8xx) symc8xx [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\symc8xx.sys -> [2001/08/17 17:07:36 | 00,032,640 | ---- | M] (LSI Logic)
(sym_hi) sym_hi [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\sym_hi.sys -> [2001/08/17 17:07:40 | 00,028,384 | ---- | M] (LSI Logic)
(sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\sym_u3.sys -> [2001/08/17 17:07:42 | 00,030,688 | ---- | M] (LSI Logic)
(SynTP) Synaptics TouchPad Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\SynTP.sys -> [2006/02/14 01:04:58 | 00,177,664 | ---- | M] (Synaptics, Inc.)
(TcUsb) TC USB Kernel Driver [Kernel | On_Demand | Running] -> %SystemRoot%\System32\Drivers\tcusb.sys -> [2006/04/25 22:13:20 | 00,028,800 | ---- | M] (UPEK Inc.)
(TDSMAPI) TDSMAPI [Kernel | System | Running] -> %SystemRoot%\System32\drivers\TDSMAPI.SYS -> [2006/08/02 12:54:00 | 00,009,343 | ---- | M] ()
(tpflhlp) tpflhlp [Kernel | On_Demand | Stopped] -> %ProgramFiles%\Lenovo\System Update\session\79uj20us\tpflhlp.sys -> [2007/04/23 20:10:44 | 00,013,616 | ---- | M] (Lenovo Group Limited)
(TPHKDRV) TPHKDRV [Kernel | System | Running] -> %SystemRoot%\System32\drivers\TPHKDRV.sys -> [2005/07/05 01:57:06 | 00,017,699 | ---- | M] (IBM Corporation)
(TPPWRIF) TPPWRIF [Kernel | System | Running] -> %SystemRoot%\System32\drivers\Tppwrif.sys -> [2006/05/25 12:13:00 | 00,004,442 | ---- | M] ()
(TSMAPIP) TSMAPIP [Kernel | System | Running] -> %SystemRoot%\System32\drivers\TSMAPIP.SYS -> [2006/07/20 13:54:00 | 00,007,168 | ---- | M] ()
(tvtfilter) tvtfilter [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\tvtfilter.sys -> [2006/07/14 20:27:22 | 00,012,544 | ---- | M] (Lenovo)
(TVTPktFilter) TVT Packet Filter Service [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\tvtpktfilter.sys -> [2006/07/14 20:03:04 | 00,017,664 | ---- | M] (Lenovo Group Limited)
(ultra) ultra [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\DRIVERS\ultra.sys -> [2001/08/17 16:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.)
(winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\system32\DRIVERS\hsx_cnxt.sys -> [2005/12/05 22:20:42 | 00,670,208 | ---- | M] (Conexant Systems, Inc.)
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> Reg Error: Invalid data type. ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_CURRENT_USER\: Main\\"Start Page" -> about:blank ->
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\extensions -> ->
HKLM\software\mozilla\Firefox\extensions\\
[email protected] -> %ProgramFiles%\JAVA\JRE6\LIB\DEPLOY\JQS\FF [C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF] -> [2009/03/17 12:31:59 | 00,000,000 | ---D | M]
< FireFox Extensions [User Folders] > ->
< HOSTS File > (734 bytes and 19 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
Reset Hosts
127.0.0.1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/01/12 23:38:22 | 00,063,128 | ---- | M] (Adobe Systems Incorporated)
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> %ProgramFiles%\AVG\AVG8\avgssie.dll [AVG Safe Search] -> [2009/02/05 09:28:58 | 01,078,552 | ---- | M] (AVG Technologies CZ, s.r.o.)
{5CA3D70E-1895-11CF-8E15-001234567890} [HKLM] -> %SystemRoot%\System32\DLA\DLASHX_W.DLL [DriveLetterAccess] -> [2006/02/02 08:20:00 | 00,110,652 | ---- | M] (Sonic Solutions)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre6\bin\ssv.dll [Java(tm) Plug-In SSV Helper] -> [2009/03/17 12:31:59 | 00,320,920 | ---- | M] (Sun Microsystems, Inc.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> %ProgramFiles%\Java\jre6\bin\jp2ssv.dll [Java(tm) Plug-In 2 SSV Helper] -> [2009/03/17 12:31:58 | 00,034,816 | ---- | M] (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} [HKLM] -> %ProgramFiles%\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [JQSIEStartDetectorImpl Class] -> [2009/03/17 12:31:59 | 00,073,728 | ---- | M] (Sun Microsystems, Inc.)
{F040E541-A427-4CF7-85D8-75E3E0F476C5} [HKLM] -> %ProgramFiles%\Lenovo\Client Security Solution\tvtpwm_ie_com.dll [CPwmIEBrowserHelper Object] -> [2006/07/14 21:20:42 | 00,719,616 | ---- | M] (Lenovo Group Limited)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"ACTray" -> %ProgramFiles%\ThinkPad\ConnectUtilities\ACTray.exe [C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe] -> [2007/02/19 19:10:46 | 00,409,600 | ---- | M] ()
"ACWLIcon" -> %ProgramFiles%\ThinkPad\ConnectUtilities\ACWLIcon.exe [C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe] -> [2007/02/19 19:02:32 | 00,110,592 | ---- | M] ()
"AVG8_TRAY" -> %ProgramFiles%\AVG\AVG8\avgtray.exe [C:\PROGRA~1\AVG\AVG8\avgtray.exe] -> [2009/02/05 09:28:55 | 01,601,304 | ---- | M] (AVG Technologies CZ, s.r.o.)
"AwaySch" -> %ProgramFiles%\Lenovo\AwayTask\AwaySch.EXE [C:\Program Files\Lenovo\AwayTask\AwaySch.EXE] -> [2006/08/16 13:07:00 | 00,069,632 | ---- | M] (Lenovo Group Limited)
"BLOG" -> %ProgramFiles%\ThinkPad\Utilities\BATLOGEX.DLL [rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog] -> [2006/05/25 12:13:00 | 00,208,896 | ---- | M] ()
"cssauth" -> %ProgramFiles%\Lenovo\Client Security Solution\cssauth.exe ["C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent] -> [2006/07/14 21:13:14 | 02,341,632 | ---- | M] (Lenovo Group Limited)
"DLA" -> %SystemRoot%\System32\DLA\DLACTRLW.EXE [C:\WINDOWS\System32\DLA\DLACTRLW.EXE] -> [2006/02/02 08:20:00 | 00,122,940 | ---- | M] (Sonic Solutions)
"EZEJMNAP" -> %ProgramFiles%\ThinkPad\Utilities\EZEJMNAP.EXE [C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe] -> [2006/02/23 13:22:00 | 00,237,568 | ---- | M] (Lenovo Group Limited)
"HP Component Manager" -> %ProgramFiles%\HP\hpcoretech\hpcmpmgr.exe ["C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"] -> [2003/10/23 22:51:18 | 00,233,472 | ---- | M] (Hewlett-Packard Company)
"HP Software Update" -> %ProgramFiles%\Hewlett-Packard\HP Software Update\HPWuSchd.exe ["C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"] -> [2003/06/25 14:24:48 | 00,049,152 | ---- | M] (Hewlett-Packard)
"HPDJ Taskbar Utility" -> %SystemRoot%\system32\spool\drivers\w32x86\3\hpztsb09.exe [C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe] -> [2005/07/22 22:40:43 | 00,176,128 | ---- | M] (HP)
"igfxhkcmd" -> %SystemRoot%\system32\hkcmd.exe [C:\WINDOWS\system32\hkcmd.exe] -> [2006/07/25 02:17:54 | 00,077,824 | ---- | M] (Intel Corporation)
"igfxpers" -> %SystemRoot%\system32\igfxpers.exe [C:\WINDOWS\system32\igfxpers.exe] -> [2006/07/25 02:21:50 | 00,118,784 | ---- | M] (Intel Corporation)
"igfxtray" -> %SystemRoot%\system32\igfxtray.exe [C:\WINDOWS\system32\igfxtray.exe] -> [2006/07/25 02:21:08 | 00,094,208 | ---- | M] (Intel Corporation)
"ISUSPM Startup" -> %SystemDrive%\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup] -> File not found
"ISUSScheduler" -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe ["C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start] -> File not found
"LPManager" -> %ProgramFiles%\ThinkVantage\PrdCtr\LPMGR.EXE [C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe] -> [2006/07/04 12:11:00 | 00,110,592 | ---- | M] (Lenovo Group Limited)
"PDService.exe" -> %ProgramFiles%\Lenovo\SafeGuard PrivateDisk\pdservice.exe ["C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe"] -> [2006/03/13 19:38:56 | 00,041,472 | R--- | M] (Utimaco Safeware AG)
"PWRMGRTR" -> %ProgramFiles%\ThinkPad\Utilities\PWRMGRTR.DLL [rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor] -> [2006/05/25 12:13:00 | 00,151,552 | ---- | M] (Lenovo Group Limited)
"SoundMAX" -> %ProgramFiles%\Analog Devices\SoundMAX\Smax4.exe [C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray] -> [2005/05/06 18:06:12 | 00,716,800 | ---- | M] (Analog Devices, Inc.)
"SoundMAXPnP" -> %ProgramFiles%\Analog Devices\Core\smax4pnp.exe [C:\Program Files\Analog Devices\Core\smax4pnp.exe] -> [2005/05/19 20:11:06 | 00,925,696 | ---- | M] (Analog Devices, Inc.)
"SunJavaUpdateSched" -> %ProgramFiles%\Java\jre6\bin\jusched.exe ["C:\Program Files\Java\jre6\bin\jusched.exe"] -> [2009/03/17 12:31:58 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.)
"SynTPEnh" -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [C:\Program Files\Synaptics\SynTP\SynTPEnh.exe] -> [2006/02/14 01:16:28 | 00,512,000 | ---- | M] (Synaptics, Inc.)
"SynTPLpr" -> %ProgramFiles%\Synaptics\SynTP\SynTPLpr.exe [C:\Program Files\Synaptics\SynTP\SynTPLpr.exe] -> [2006/02/14 01:17:28 | 00,110,592 | ---- | M] (Synaptics, Inc.)
"TP4EX" -> %SystemRoot%\system32\tp4ex.exe [tp4ex.exe] -> [2005/10/17 04:11:00 | 00,065,536 | ---- | M] (Lenovo Group Limited)
"TPHOTKEY" -> %ProgramFiles%\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe [C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe] -> [2006/07/24 21:19:40 | 00,094,208 | ---- | M] ()
"TPKMAPHELPER" -> %ProgramFiles%\ThinkPad\Utilities\TpKmapAp.exe [C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper] -> [2006/06/03 01:00:18 | 00,856,064 | ---- | M] (Lenovo)
"TpShocks" -> %SystemRoot%\system32\TpShocks.exe [TpShocks.exe] -> [2006/03/15 22:04:48 | 00,106,496 | ---- | M] (Lenovo, Ltd. and IBM Corporation.)
"TVT Scheduler Proxy" -> %CommonProgramFiles%\Lenovo\Scheduler\scheduler_proxy.exe [C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe] -> [2006/12/10 22:36:32 | 00,536,576 | ---- | M] (Lenovo Group Limited)
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersProfile%\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk -> %ProgramFiles%\Palm\Hotsync.exe -> [2004/06/09 17:27:34 | 00,471,040 | ---- | M] (PalmSource, Inc)
< jim.dalessandro Startup Folder > -> C:\Documents and Settings\jim.dalessandro\Start Menu\Programs\Startup ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"HonorAutoRunSetting" -> [1] -> File not found
\\"NoCDBurning" -> [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" -> [0] -> File not found
\\"legalnoticecaption" -> [] -> File not found
\\"legalnoticetext" -> [] -> File not found
\\"shutdownwithoutlogon" -> [1] -> File not found
\\"undockwithoutlogon" -> [1] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"disableregistrytools" -> [0] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport to Microsoft Excel -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000] -> [2007/04/06 16:12:52 | 10,289,496 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{0045D4BC-5189-4b67-969C-83BB1906C421}:{0FE81B52-73FA-425F-8F06-3F32451AC73F} [HKLM] -> %ProgramFiles%\Lenovo\Client Security Solution\tvtpwm_ie_com.dll [Menu: ThinkVantage Password Manager...] -> [2006/07/14 21:20:42 | 00,719,616 | ---- | M] (Lenovo Group Limited)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Button: Research] -> [2003/07/15 01:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation)
{D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5}:Exec [HKLM] -> %ProgramFiles%\Lenovo\PkgMgr\PkgMgr.exe [Button: Software Installer] -> [2006/11/13 18:18:56 | 01,668,720 | ---- | M] (Lenovo Group Limited)
{DA320635-F48C-4613-8325-D75A933C549E}:Exec [HKLM] -> %ProgramFiles%\Lenovo\System Update\sulauncher.exe [Button: System Update] -> File not found
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> %SystemRoot%\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/13 14:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} [HKLM] -> http://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab [Office Genuine Advantage Validation Tool] ->
{17492023-C23A-453E-A040-C7C580BBF700} [HKLM] -> http://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab [Windows Genuine Advantage Validation Tool] ->
{74FFE28D-2378-11D5-990C-006094235084} [HKLM] -> http://www-307.ibm.com/pc/support/IbmEgath.cab [IBM Access Support] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11] ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab [Reg Error: Key error.] ->
{AB86CE53-AC9F-449F-9399-D8ABCA09EC09} [HKLM] -> https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx [Get_ActiveX Control] ->
{C7DB51B4-BCF7-4923-8874-7F1A0DC92277} [HKLM] -> http://office.microsoft.com/officeupdate/content/opuc4.cab [Office Update Installation Engine] ->
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab [Java Plug-in 1.5.0_06] ->
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab [Java Plug-in 1.6.0_01] ->
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab [Java Plug-in 1.6.0_03] ->
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab [Java Plug-in 1.6.0_05] ->
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab [Java Plug-in 1.6.0_07] ->
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11] ->
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{1EDEE81F-F354-433F-BCE1-25B8B9934CAA} -> (Intel(R) PRO/Wireless 3945ABG Network Connection) ->
{54512FA9-3FF7-4E91-A388-25E83A1A31C8} -> (Intel(R) PRO/1000 PL Network Connection) ->
{E359824B-5D88-4958-8D69-48ED5D7A6E75} -> () ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> %SystemRoot%\Explorer.exe -> [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
*GinaDLL* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\GinaDLL ->
vrlogon.dll -> %SystemRoot%\system32\vrlogon.dll -> [2006/04/25 22:21:28 | 00,513,536 | ---- | M] (UPEK Inc.)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
ACNotify -> %ProgramFiles%\ThinkPad\ConnectUtilities\ACNotify.dll -> [2007/02/19 19:03:20 | 00,032,768 | ---- | M] ()
avgrsstarter -> %SystemRoot%\system32\avgrsstx.dll -> [2009/02/05 09:29:00 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.)
AwayNotify -> %ProgramFiles%\Lenovo\AwayTask\AwayNotify.dll -> [2006/08/16 13:07:00 | 00,049,152 | ---- | M] (Lenovo Group Limited)
igfxcui -> %SystemRoot%\system32\igfxdev.dll -> [2006/07/25 02:16:58 | 00,139,264 | ---- | M] (Intel Corporation)
NavLogon -> -> File not found
psfus -> %SystemRoot%\system32\psqlpwd.dll -> [2006/04/25 22:20:38 | 00,040,448 | ---- | M] (UPEK Inc.)
tpfnf2 -> %SystemRoot%\system32\notifyf2.dll -> [2005/07/05 10:45:08 | 00,028,672 | ---- | M] ()
tphotkey -> %SystemRoot%\system32\tphklock.dll -> [2005/11/30 07:16:02 | 00,024,576 | ---- | M] ()
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 14:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 20:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 14:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 20:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation)
"C:\Program Files\AVG\AVG8\avgupd.exe" -> C:\Program Files\AVG\AVG8\avgupd.exe [C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe] -> [2009/02/03 10:34:56 | 01,032,984 | ---- | M] (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe" -> C:\Program Files\Grisoft\AVG7\avgamsvr.exe [C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe] -> File not found
"C:\Program Files\Grisoft\AVG7\avgcc.exe" -> C:\Program Files\Grisoft\AVG7\avgcc.exe [C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe] -> File not found
"C:\Program Files\Grisoft\AVG7\avginet.exe" -> C:\Program Files\Grisoft\AVG7\avginet.exe [C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe] -> File not found
"C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe" -> C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe [C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox] -> File not found
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> %SystemRoot%\system32\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/04/13 14:40:46 | 00,062,976 | ---- | M] (Microsoft Corporation)
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2006/04/30 03:13:35 | 00,000,000 | ---- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
[Files/Folders - Created Within 30 Days]
OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2009/03/29 12:48:08 | 00,000,000 | ---D | C]
OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2009/03/29 12:45:12 | 00,663,992 | ---- | C] ()
DaonolFix.exe -> %UserProfile%\Desktop\DaonolFix.exe -> [2009/03/29 12:07:06 | 00,091,136 | ---- | C] ()
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [2009/03/29 11:51:56 | 52,683,1616 | -HS- | C] ()
32788R22FWJFW -> %SystemDrive%\32788R22FWJFW -> [2009/03/29 11:49:01 | 00,000,000 | ---D | C]
ComboFix.exe -> %UserProfile%\Desktop\ComboFix.exe -> [2009/03/28 16:16:31 | 02,936,496 | ---- | C] ()
Malwarebytes -> %AppData%\Malwarebytes -> [2009/03/28 08:11:16 | 00,000,000 | ---D | C]
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> [2009/03/28 08:11:10 | 00,015,504 | ---- | C] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Mal