the rest of the logs.
--- System information ---
Unknown Windows version 6.1 (Build: 7600) (6.1.7600)
--- Startup entries list ---
Located: HK_LM:Run, Adobe ARM
command: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
file: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
size: 976832
MD5: 0B232C77D822983397674AEEC9AB59DC
Located: HK_LM:Run, Adobe Reader Speed Launcher
command: "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
file: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
size: 35760
MD5: A32B25970003B6ABA027EFF8EEDA12A3
Located: HK_LM:Run, AVG9_TRAY
command: C:\PROGRA~2\AVG\AVG9\avgtray.exe
file: C:\PROGRA~2\AVG\AVG9\avgtray.exe
size: 2065760
MD5: E9B04FD2921ACE22CA17FA7D5131F491
Located: HK_LM:Run, BDRegion
command: c:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
file: c:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
size: 75048
MD5: BD1D3356384529CE03D3D7155091EB6D
Located: HK_LM:Run, DivXUpdate
command: "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
file: C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
size: 1164584
MD5: 6AE5C5807E47FA41CAE4FBC25B1A012E
Located: HK_LM:Run, FAStartup
command:
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_LM:Run, FATrayAlert
command: C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
file: C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
size: 95496
MD5: B14619122371547E226DFAC829E53FE0
Located: HK_LM:Run, jsafesurf
command: C:\Windows\SysWOW64\drivers\safesurf.exe
file: C:\Windows\SysWOW64\drivers\safesurf.exe
size: 211968
MD5: CC412B13CB3080B58ED81EB91F672F5B
Located: HK_LM:Run, OSD_LAUNCH
command: c:\Program Files (x86)\OSD\Launch_OSD.exe
file: c:\Program Files (x86)\OSD\Launch_OSD.exe
size: 32768
MD5: BBB34DDD6359AE157B77645CAF0359E2
Located: HK_LM:Run, PDVD8LanguageShortcut
command: "c:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"
file: c:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe
size: 50472
MD5: F8270CFD51F9D6BF42140FA4071C83FE
Located: HK_LM:Run, RemoteControl8
command: "c:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"
file: c:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
size: 91432
MD5: 28FD28A29C637C9AFEFE0A26E27C6DFE
Located: HK_LM:Run, StartCCC
command: "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
file: C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
size: 102400
MD5: 9AC78D384CE632BF4B5C73D5231CE17E
Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
file: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
size: 248552
MD5: 93DB1FF92B03D24738A71E6E4992DFD3
Located: HK_LM:Run, UCam_Menu
command: "c:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
file: c:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe
size: 218408
MD5: 5C5D40DDDE89190B2B3A19EDAC1CCF55
Located: HK_CU:Run, DelayShred
where: .DEFAULT...
command: c:\progra~2\mcafee\mshr\ShrCL.EXE /P7 /q c:\users\ILEAND~1\appdata\local\temp\divDEE9.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\MOZ6L4AS\CLB994~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\P7LDHRRH\VITALI~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\MOZ6L4AS\CLEC03~1.SH! c:\users\ILEAND~1\appdata\local\temp\Low\HSPERF~1.SH! c:\users\ILEAND~1\appdata\local\temp\HSPERF~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\MOZ6L4AS\CLA788~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\IO9UL2VC\VITALI~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\1NHEO8WV\CL30F6~1.SH! c:\users\ILEAND~1\appdata\local\temp\divAFBE.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\MOZ6L4AS\CL3CE2~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\P7LDHRRH\CLAACF~1.SH! c:\users\ILEAND~1\appdata\local\temp\div98C5.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\UI9ZTR9Q\SLAP_P~1.SH! c:\users\ILEAND~1\appdata\local\temp\divF0D3.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\Q3B1KCG6\SLAP_P~2.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\VHI4F51D\CL5B84~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\1O2LK7S1\CL90D8~1.SH! c:\users\ILEAND~1\appdata\local\temp\TEMPOR~1\Content.SH! c:\users\ILEAND~1\appdata\local\temp\TEMPOR~1.SH! c:\users\ILEAND~1\appdata\local\temp\History\History.SH! c:\users\ILEAND~1\appdata\local\temp\History.SH! c:\users\ILEAND~1\appdata\local\temp\div2DF2.SH! c:\users\ILEAND~1\appdata\local\temp\Cookies.SH!
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: HK_CU:Run, DAEMON Tools Lite
where: S-1-5-21-3114459104-3109507807-2530587415-1001...
command: "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
file: C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
size: 357696
MD5: F34E7705751BB413283434697BF8E55D
Located: HK_CU:Run, HKCU
where: S-1-5-21-3114459104-3109507807-2530587415-1001...
command: C:\Users\ileandover\AppData\Roaming\install\server.exe
file: C:\Users\ileandover\AppData\Roaming\install\server.exe
size: 602112
MD5: 8CAD97C369A14CB7E8E2B2515A73A303
Located: HK_CU:Run, DelayShred
where: S-1-5-18...
command: c:\progra~2\mcafee\mshr\ShrCL.EXE /P7 /q c:\users\ILEAND~1\appdata\local\temp\divDEE9.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\MOZ6L4AS\CLB994~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\P7LDHRRH\VITALI~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\MOZ6L4AS\CLEC03~1.SH! c:\users\ILEAND~1\appdata\local\temp\Low\HSPERF~1.SH! c:\users\ILEAND~1\appdata\local\temp\HSPERF~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\MOZ6L4AS\CLA788~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\IO9UL2VC\VITALI~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\1NHEO8WV\CL30F6~1.SH! c:\users\ILEAND~1\appdata\local\temp\divAFBE.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\MOZ6L4AS\CL3CE2~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\P7LDHRRH\CLAACF~1.SH! c:\users\ILEAND~1\appdata\local\temp\div98C5.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\UI9ZTR9Q\SLAP_P~1.SH! c:\users\ILEAND~1\appdata\local\temp\divF0D3.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\Q3B1KCG6\SLAP_P~2.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\VHI4F51D\CL5B84~1.SH! C:\Users\ILEAND~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\1O2LK7S1\CL90D8~1.SH! c:\users\ILEAND~1\appdata\local\temp\TEMPOR~1\Content.SH! c:\users\ILEAND~1\appdata\local\temp\TEMPOR~1.SH! c:\users\ILEAND~1\appdata\local\temp\History\History.SH! c:\users\ILEAND~1\appdata\local\temp\History.SH! c:\users\ILEAND~1\appdata\local\temp\div2DF2.SH! c:\users\ILEAND~1\appdata\local\temp\Cookies.SH!
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: Startup (common), Bluetooth.lnk
where: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup...
command: C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
file: C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, FastAccess
command: C:\Program Files\Alienware\Command Center\AlienSense\FALogNot.dll
file: C:\Program Files\Alienware\Command Center\AlienSense\FALogNot.dll
size: 140552
MD5: 1C019F6D4CCFE15A7BCE63BA3F867245
--- Browser helper object list ---
{02478D38-C3F9-4efb-9B51-7695ECA05670} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:
description: Yahoo Companion!
classification: Legitimate
known filename: Ycomp*_*_*_*.dll
info link:
http://companion.yahoo.com/
info source: TonyKlein
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: AcroIEHelperStub
CLSID name: Adobe PDF Link Helper
Path: C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\
Long name: AcroIEHelperShim.dll
Short name: ACROIE~2.DLL
Date (created): 6/19/2010 3:29:34 PM
Date (last access): 7/2/2010 8:08:26 PM
Date (last write): 6/19/2010 3:29:34 PM
Filesize: 75200
Attributes: archive
MD5: 6D9042F1443A601DA8DC24D991EDDD0A
CRC32: 10990AC8
Version: 9.3.3.177
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (WormRadar.com IESiteBlocker.NavFilter)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: WormRadar.com IESiteBlocker.NavFilter
CLSID name: AVG Safe Search
Path: C:\Program Files (x86)\AVG\AVG9\
Long name: avgssie.dll
Short name:
Date (created): 7/16/2010 9:30:46 AM
Date (last access): 7/21/2010 11:09:34 AM
Date (last write): 7/21/2010 11:09:34 AM
Filesize: 1619296
Attributes: archive
MD5: 9709500432501607C7DD32B9F2B07E1F
CRC32: DD3F49C2
Version: 9.0.0.845
{53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Spybot-S&D IE Protection
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDhelper.dll
info link:
http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\PROGRA~2\SPYBOT~1\
Long name: SDHelper.dll
Short name:
Date (created): 6/25/2010 10:36:52 PM
Date (last access): 6/25/2010 10:36:52 PM
Date (last write): 1/26/2009 3:31:02 PM
Filesize: 1879896
Attributes: archive
MD5: 022C2F6DCCDFA0AD73024D254E62AFAC
CRC32: 5BA24007
Version: 1.6.2.14
{5C255C8A-E604-49b4-9D64-90988571CECB} ()
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name:
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Groove GFS Browser Helper
Path: C:\Program Files (x86)\Microsoft Office\Office12\
Long name: GrooveShellExtensions.dll
Short name: GR469A~1.DLL
Date (created): 2/12/2009 3:19:32 PM
Date (last access): 6/3/2010 3:04:10 PM
Date (last write): 2/12/2009 3:19:32 PM
Filesize: 2217848
Attributes: archive
MD5: A6B5A41C0ED007AB6C43CAD899E533D8
CRC32: BA078F79
Version: 12.0.6421.1000
{9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Windows Live Sign-in Helper
Path: C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\
Long name: WindowsLiveLogin.dll
Short name: WINDOW~1.DLL
Date (created): 1/22/2009 3:41:30 PM
Date (last access): 5/2/2010 9:52:00 AM
Date (last write): 1/22/2009 3:41:30 PM
Filesize: 408448
Attributes: archive
MD5: B7899C3E21B299D7A3C0DA96CAE340BD
CRC32: 288935F8
Version: 5.0.818.5
{A2F122DA-055F-4df7-8F24-7354DBDBA85B} (FAIESSO Helper Object)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: FAIESSO Helper Object
CLSID name: FAIESSOHelper Class
Path: C:\Program Files\Alienware\Command Center\AlienSense\
Long name: FAIESSO.dll
Short name:
Date (created): 6/24/2009 7:31:16 PM
Date (last access): 4/23/2010 9:44:46 AM
Date (last write): 6/24/2009 7:31:16 PM
Filesize: 206088
Attributes: archive
MD5: 7F053719146602A00350F8F2F69523F4
CRC32: 9A0B05E1
Version: 2.4.7.1
{A3BC75A2-1F87-4686-AA43-5347D756017C} (AVG Security Toolbar BHO)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: AVG Security Toolbar BHO
Path: C:\Program Files (x86)\AVG\AVG9\Toolbar\
Long name: IEToolbar.dll
Short name: IETOOL~1.DLL
Date (created): 5/24/2010 6:54:54 PM
Date (last access): 5/24/2010 6:54:54 PM
Date (last write): 4/19/2010 10:25:32 AM
Filesize: 2117704
Attributes: archive
MD5: 88E16E108B71F904F53DCDB75F453C9C
CRC32: EA0A78F2
Version: 4.504.19.2
{DBC80044-A445-435b-BC74-9C25C1C588A9} (Java(tm) Plug-In 2 SSV Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Java(tm) Plug-In 2 SSV Helper
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: jp2ssv.dll
Short name:
Date (created): 8/4/2010 3:37:18 PM
Date (last access): 8/11/2010 12:11:08 PM
Date (last write): 8/4/2010 3:37:18 PM
Filesize: 41760
Attributes: archive
MD5: 6D5ADB1C823BFE21F9431D0995C7B185
CRC32: 71F413A1
Version: 6.0.210.7
--- ActiveX list ---
{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
DPF name:
CLSID name: Shockwave ActiveX Control
Installer: C:\Windows\Downloaded Program Files\swdir.inf
Codebase:
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
description: Macromedia ShockWave Flash Player 7
classification: Legitimate
known filename: SWDIR.DLL
info link:
info source: Patrick M. Kolla
Path: C:\Windows\SysWow64\Adobe\Director\
Long name: SwDir.dll
Short name:
Date (created): 5/5/2010 10:37:26 AM
Date (last access): 5/18/2010 9:21:14 PM
Date (last write): 5/5/2010 10:37:26 AM
Filesize: 213272
Attributes: archive
MD5: 1697C92A56774FA33F4DA3D4561FB4C7
CRC32: C2719B78
Version: 11.5.7.609
{17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool)
DPF name:
CLSID name: Windows Genuine Advantage Validation Tool
Installer: C:\Windows\Downloaded Program Files\LegitCheckControl.inf
Codebase:
http://download.microsoft.com/downl...-4117-8430-A67417AA88CD/LegitCheckControl.cab
description:
classification: Legitimate
known filename: LegitCheckControl.DLL
info link:
info source: Safer Networking Ltd.
Path: C:\Windows\SysWow64\
Long name: LegitCheckControl.DLL
Short name: LEGITC~1.DLL
Date (created): 6/25/2009 1:20:28 PM
Date (last access): 6/25/2009 1:20:28 PM
Date (last write): 6/25/2009 1:20:28 PM
Filesize: 1485176
Attributes: archive
MD5: 3307A07B81206F354F0D4BEFEE922437
CRC32: 58E4DC38
Version: 1.9.42.0
{67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object)
DPF name:
CLSID name: DivXBrowserPlugin Object
Installer: C:\Windows\Downloaded Program Files\DivXPlugin.inf
Codebase:
http://download.divx.com/player/DivXBrowserPlugin.cab
description:
classification: Legitimate
known filename: npdivx32.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files (x86)\DivX\DivX Plus Web Player\
Long name: npdivx32.dll
Short name:
Date (created): 8/24/2010 8:47:58 PM
Date (last access): 8/27/2010 6:16:52 PM
Date (last write): 8/24/2010 8:47:58 PM
Filesize: 2405688
Attributes: archive
MD5: 6827CA29D7AD3595660271F3F05C79B5
CRC32: 84248F6A
Version: 2.0.3.4
{8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control)
DPF name:
CLSID name: Facebook Photo Uploader 5 Control
Installer: C:\Windows\Downloaded Program Files\PhotoUploader55.inf
Codebase:
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
Path: C:\Windows\Downloaded Program Files\
Long name: PhotoUploader55.ocx
Short name: PHOTOU~1.OCX
Date (created): 7/29/2009 9:21:24 PM
Date (last access): 7/29/2009 9:21:24 PM
Date (last write): 7/29/2009 9:21:24 PM
Filesize: 3540488
Attributes: archive
MD5: B36353934BB8B0E7CC8557AC5143EF41
CRC32: 3AC3C312
Version: 5.5.8.1
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_21
Installer:
Codebase:
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: jp2iexp.dll
Short name:
Date (created): 4/23/2010 9:34:52 AM
Date (last access): 7/17/2010 5:01:04 AM
Date (last write): 7/17/2010 5:00:08 AM
Filesize: 108320
Attributes: archive
MD5: 25F044BAA126064EB0284FB6C115BAB9
CRC32: 9CD13605
Version: 6.0.210.7
{8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} (ZPA_WheelOfFortune Object)
DPF name:
CLSID name: ZPA_WheelOfFortune Object
Installer:
Codebase:
http://zone.msn.com/bingame/zpagames/zpa_wof.cab55579.cab
Path: C:\Windows\Downloaded Program Files\
Long name: zpa_wof.ocx
Short name:
Date (created): 1/26/2007 11:01:28 AM
Date (last access): 1/26/2007 11:01:28 AM
Date (last write): 1/26/2007 11:01:28 AM
Filesize: 2544040
Attributes: archive
MD5: 73B3EB02DA4C7E9C3826AC547BDA25DC
CRC32: 7EA1B4C3
Version: 9.5.5579.1
{B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer)
DPF name:
CLSID name: MSN Games - Installer
Installer: C:\Windows\Downloaded Program Files\ZPAFramework.inf
Codebase:
http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
description:
classification: Legitimate
known filename: ZIntro.ocx
info link:
info source: Safer Networking Ltd.
Path: C:\Windows\Downloaded Program Files\
Long name: Zintro.ocx
Short name:
Date (created): 5/7/2009 1:48:20 PM
Date (last access): 5/7/2009 1:48:20 PM
Date (last write): 5/7/2009 1:48:20 PM
Filesize: 155488
Attributes: archive
MD5: B3BAB5F5E17ECF29EFF38FB3B8B4DB53
CRC32: 464D4848
Version: 9.10.2118.1
{BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner)
DPF name:
CLSID name: a-squared Scanner
Installer:
Codebase:
http://ax.emsisoft.com/asquared.cab
description:
classification: Legitimate
known filename: axscan.ocx
info link:
info source: Safer Networking Ltd.
Path: C:\Windows\DOWNLO~1\
Long name: asquared.ocx
Short name:
Date (created): 6/17/2010 10:22:16 AM
Date (last access): 6/17/2010 10:22:16 AM
Date (last write): 6/17/2010 10:22:16 AM
Filesize: 1031072
Attributes: archive
MD5: 19C413E3F34BC7F7CEFE7D9BE927D90F
CRC32: CA5E057E
Version: 4.0.0.11
{C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} (DellSystemLite.Scanner)
DPF name:
CLSID name: DellSystemLite.Scanner
Installer: C:\Windows\Downloaded Program Files\DellSystemLite.INF
Codebase:
http://support.dell.com/systemprofiler/DellSystemLite.CAB
Path: C:\Windows\Downloaded Program Files\
Long name: DellSystemLite.ocx
Short name: DELLSY~1.OCX
Date (created): 12/14/2009 11:04:18 AM
Date (last access): 12/14/2009 11:04:18 AM
Date (last write): 12/14/2009 11:04:18 AM
Filesize: 51120
Attributes: archive
MD5: 492016673352550A7D4D10B9B1424771
CRC32: A4C7E2E6
Version: 1.0.0.0
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_21
Installer:
Codebase:
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: jp2iexp.dll
Short name:
Date (created): 4/23/2010 9:34:52 AM
Date (last access): 7/17/2010 5:01:04 AM
Date (last write): 7/17/2010 5:00:08 AM
Filesize: 108320
Attributes: archive
MD5: 25F044BAA126064EB0284FB6C115BAB9
CRC32: 9CD13605
Version: 6.0.210.7
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_21
Installer:
Codebase:
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
description:
classification: Legitimate
known filename: npjpi150_06.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files (x86)\Java\jre6\bin\
Long name: npjpi160_21.dll
Short name: NPJPI1~1.DLL
Date (created): 7/17/2010 2:42:32 AM
Date (last access): 7/17/2010 5:01:16 AM
Date (last write): 7/17/2010 5:00:06 AM
Filesize: 141088
Attributes: archive
MD5: 0B3AC6C55A8F57FFEB18A9FC35A5E9CF
CRC32: 1D07915B
Version: 6.0.210.7
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} ()
DPF name:
CLSID name:
Installer: C:\Windows\Downloaded Program Files\gp.inf
Codebase:
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
--- Process list ---
PID: 0 ( 0) [System]
PID: 4124 (2316) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
size: 16704
MD5: 8DE45D4D906D600AFE47E4BADB95A6F8
PID: 2084 (2656) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
size: 58696
MD5: 5F819346DAFCC145966985A25100A002
PID: 4660 (2656) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
size: 186904
MD5: D1930CA970D4250D891F432419E3D6C9
PID: 5440 (2656) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
size: 357696
MD5: F34E7705751BB413283434697BF8E55D
PID: 5612 (5500) C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
size: 95496
MD5: B14619122371547E226DFAC829E53FE0
PID: 5700 (5500) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
size: 91432
MD5: 28FD28A29C637C9AFEFE0A26E27C6DFE
PID: 5768 (5500) C:\Program Files (x86)\CyberLink\Shared Files\brs.exe
size: 75048
MD5: BD1D3356384529CE03D3D7155091EB6D
PID: 5836 (5612) C:\Program Files\Alienware\Command Center\AlienSense\FATrayAlert.exe
size: 1942792
MD5: 5712588FBA79DFBC39A933ECFD61FAB8
PID: 5872 (5580) C:\Windows\SysWOW64\explorer.exe
size: 2614272
MD5: 2626FC9755BE22F805D3CFA0CE3EE727
PID: 5648 (5500) C:\Program Files (x86)\AVG\AVG9\avgtray.exe
size: 2065760
MD5: E9B04FD2921ACE22CA17FA7D5131F491
PID: 5944 (5500) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
size: 248552
MD5: 93DB1FF92B03D24738A71E6E4992DFD3
PID: 6020 (5580) C:\Users\ileandover\AppData\Roaming\install\server.exe
size: 602112
MD5: 8CAD97C369A14CB7E8E2B2515A73A303
PID: 6220 (5500) C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
size: 1164584
MD5: 6AE5C5807E47FA41CAE4FBC25B1A012E
PID: 6140 (6272) c:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
size: 13600
MD5: 69388C3D3DBD3D92C475B58AE4BF508B
PID: 7580 (2084) C:\Program Files\Alienware\Command Center\AlienFXHook32Mngr.exe
size: 13624
MD5: 0E962A62AB25DDBDF83A7CE641A99B12
PID: 2472 (5648) C:\Program Files (x86)\Internet Explorer\iexplore.exe
size: 673048
MD5: 2C32E3E596CFE660353753EABEFB0540
PID: 4700 (2472) C:\Program Files (x86)\Internet Explorer\iexplore.exe
size: 673048
MD5: 2C32E3E596CFE660353753EABEFB0540
PID: 7568 (1204) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10i_ActiveX.exe
size: 232912
MD5: A51D1C449E9CA956F477F9BFBE67A5C8
PID: 4288 (2656) C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
size: 5365592
MD5: 0477C2F9171599CA5BC3307FDFBA8D89
PID: 4 ( 0) System
PID: 368 ( 4) smss.exe
PID: 516 ( 508) csrss.exe
PID: 604 ( 596) csrss.exe
PID: 612 ( 508) wininit.exe
size: 96256
PID: 632 ( 612) avgchsva.exe
PID: 640 ( 612) avgrsa.exe
PID: 676 ( 596) winlogon.exe
PID: 744 ( 640) avgcsrva.exe
PID: 784 ( 612) services.exe
PID: 792 ( 612) lsass.exe
PID: 808 ( 612) lsm.exe
PID: 1204 ( 784) svchost.exe
size: 20992
PID: 1296 ( 784) svchost.exe
size: 20992
PID: 1376 ( 784) atiesrxx.exe
PID: 1420 ( 784) svchost.exe
size: 20992
PID: 1452 ( 784) svchost.exe
size: 20992
PID: 1524 ( 784) FAService.exe
PID: 1604 ( 784) svchost.exe
size: 20992
PID: 1640 ( 784) stacsv64.exe
PID: 1684 (1420) audiodg.exe
PID: 1936 ( 784) svchost.exe
size: 20992
PID: 1996 ( 784) MSI15BF.tmp
PID: 2008 (1376) atieclxx.exe
PID: 1816 ( 784) svchost.exe
size: 20992
PID: 1164 (1452) wlanext.exe
size: 77312
PID: 1276 ( 516) conhost.exe
PID: 2112 ( 784) spoolsv.exe
PID: 2164 ( 784) svchost.exe
size: 20992
PID: 2268 ( 784) AESTSr64.exe
PID: 2296 ( 784) svchost.exe
size: 20992
PID: 2316 ( 784) AlienFusionService.exe
PID: 2524 ( 784) C:\Windows\System32\taskhost.exe
PID: 2608 (1452) C:\Windows\System32\dwm.exe
PID: 2656 (2600) C:\Windows\explorer.exe
size: 2870272
MD5: 9AAAEC8DAC27AA17B053E6352AD233AE
PID: 2968 ( 784) avgwdsvc.exe
PID: 2992 ( 784) btwdins.exe
PID: 3040 ( 784) EvtEng.exe
PID: 2364 ( 784) svchost.exe
size: 20992
PID: 2840 ( 784) OSD_Service.exe
PID: 2976 ( 784) NBService.exe
PID: 3164 (2968) avgnsa.exe
PID: 3184 ( 784) RegSrvc.exe
PID: 3252 ( 784) svchost.exe
size: 20992
PID: 3360 ( 784) TomTomHOMEService.exe
PID: 3392 ( 784) svchost.exe
size: 20992
PID: 3512 ( 784) svchost.exe
size: 20992
PID: 3736 ( 784) YahooAUService.exe
PID: 3824 ( 784) IAANTmon.exe
PID: 3920 ( 784) SDWinSec.exe
PID: 3208 (1204) unsecapp.exe
PID: 3068 (1204) WmiPrvSE.exe
PID: 3488 (1204) WmiPrvSE.exe
PID: 4552 ( 784) svchost.exe
size: 20992
PID: 4576 ( 784) svchost.exe
size: 20992
PID: 4868 (1452) WUDFHost.exe
PID: 3436 (2656) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
size: 1881384
MD5: F96EB8AB2AD7D14052004E29AE1182FB
PID: 2804 (2656) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
size: 1926928
MD5: CAFC14FD383035C97C846706E2FCFD0C
PID: 4404 (2656) C:\Program Files\IDT\WDM\sttray64.exe
size: 487424
MD5: 06C2C34EA4C666835C6AB492976C0BA1
PID: 4968 (2656) C:\Windows\WindowsMobile\wmdc.exe
size: 660360
MD5: 233A10D4B3F6897899112E4EC60F1906
PID: 5172 (3436) SynTPHelper.exe
PID: 5180 ( 784) svchost.exe
size: 20992
PID: 5388 (1204) C:\Windows\System32\wbem\unsecapp.exe
PID: 5568 (2656) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
size: 1080096
MD5: C40894A0E9031191674FEE74D4C7C473
PID: 5672 (2840) OSD.exe
PID: 5996 ( 784) SearchIndexer.exe
size: 428032
PID: 6012 (5932) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
size: 65536
MD5: E7704CBF568815C1CAA6E513387BD3F2
PID: 6272 (1204) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
size: 3062560
MD5: 50093278F90AB4843A65C6114DCB3773
PID: 6396 ( 784) wmpnetwk.exe
PID: 6636 (6012) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
size: 65536
MD5: 74EF310FAC89341CE2897B7F2C4A7B0F
PID: 6432 (5188) surfguard.exe
PID: 7260 ( 784) svchost.exe
size: 20992
PID: 7588 ( 604) C:\Windows\System32\conhost.exe
PID: 7628 (2084) C:\Program Files\Alienware\Command Center\AlienFXHook64Mngr.exe
size: 13112
MD5: 94ED1551B0A691663C20373478D62B90
PID: 7636 ( 604) C:\Windows\System32\conhost.exe
PID: 3428 (1604) C:\Windows\System32\taskeng.exe
size: 190464
MD5: DE5DACEBD4C89834EC6D2C41C8643CDA
PID: 2600 (3428) C:\Windows\System32\jusched.exe
PID: 3388 (3512) safesurf.exe
PID: 6316 ( 784) taskhost.exe
PID: 8124 (8036) MpCmdRun.exe
PID: 4104 (5996) SearchProtocolHost.exe
size: 164352
PID: 3136 (5996) SearchFilterHost.exe
size: 86528
--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 9/15/2010 1:46:19 PM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\Windows\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.facebook.com/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.alienware.com/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
C:\Windows\SysWOW64\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://go.microsoft.com/fwlink/?LinkId=54896
--- Winsock Layered Service Provider list ---
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 3: MSAFD Tcpip [TCP/IPv6]
GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IPv6 protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 4: MSAFD Tcpip [UDP/IPv6]
GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IPv6 protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 5: MSAFD Tcpip [RAW/IPv6]
GUID: {F9EAB0C0-26D4-11D0-BBBF-00AA006C34E4}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IPv6 protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 6: RSVP TCPv6 Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 7: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 8: RSVP UDPv6 Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 9: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 10: MSAFD RfComm [Bluetooth]
GUID: {9FC48064-7298-43E4-B7BD-181F2089792A}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Bluetooth
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD RfComm [Bluetooth]
Namespace Provider 0: Network Location Awareness Legacy (NLAv1) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename:
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace
Namespace Provider 1: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename:
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP
Namespace Provider 2: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS
Namespace Provider 3: E-mail Naming Shim Provider
GUID: {964ACBA2-B2BC-40EB-8C6A-A6DB40161CAE}
Filename:
Namespace Provider 4: PNRP Cloud Namespace Provider
GUID: {03FE89CE-766D-4976-B9C1-BB9BC42C7B4D}
Filename:
Namespace Provider 5: PNRP Name Namespace Provider
GUID: {03FE89CD-766D-4976-B9C1-BB9BC42C7B4D}
Filename:
Namespace Provider 6: Bluetooth Namespace
GUID: {06AA63E0-7D60-41FF-AFB2-3EE6D2D9392D}
Filename: %SystemRoot%\system32\wshbth.dll
Description: Bluetooth
DB filename: %SystemRoot%\system32\wshbth.dll
DB protocol: Bluetooth-Namespace
--- System Services ---
Service (registry key): .NET CLR Data
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET CLR Networking
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET CLR Networking 4.0.0.0
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET Data Provider for Oracle
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NET Data Provider for SqlServer
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): .NETFramework
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): 1394ohci
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: 1394 OHCI Compliant Host Controller
Image path: system32\DRIVERS\1394ohci.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Acceler
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Accelerometer Service
Image path: system32\DRIVERS\Acceler.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): ACPI
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Microsoft ACPI Driver
Image path: system32\DRIVERS\ACPI.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 3
Service (registry key): AcpiPmi
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ACPI Power Meter Driver
Image path: \SystemRoot\system32\DRIVERS\acpipmi.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): adp94xx
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\adp94xx.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): adpahci
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\adpahci.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): adpu320
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\adpu320.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): adsi
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): AeLookupSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\aelupsvc.dll,-1
Description: @%SystemRoot%\system32\aelupsvc.dll,-2
Object name: localSystem
Image path: %systemroot%\system32\svchost.exe -k netsvcs
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Service (registry key): AESTFilters
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Andrea ST Filters Service
Object name: LocalSystem
Image path: C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7984240545aadb84\AESTSr64.exe
Image size: 89600
Image MD5: A6FB9DB8F1A86861D955FD6975977AE0
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Service (registry key): AFD
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%systemroot%\system32\drivers\afd.sys,-1000
Description: @%systemroot%\system32\drivers\afd.sys,-1000
Image path: \SystemRoot\system32\drivers\afd.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): agp440
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Intel AGP Bus Filter
Image path: \SystemRoot\system32\DRIVERS\agp440.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): Akamai
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Akamai NetSession Interface
Description: Provides networking protocol and file transfer technologies. If the service is stopped, those applications that depend on the service may fail to transfer files or otherwise function properly.
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k Akamai
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 2
Type: 272
Error Control: 0
Service (registry key): ALG
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\Alg.exe,-112
Description: @%SystemRoot%\system32\Alg.exe,-113
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\alg.exe
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): AlienFusionService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Alienware Fusion Service
Description: Allows to control Alienware custom power settings
Object name: LocalSystem
Image path: "C:\Program Files\Alienware\Command Center\AlienFusionService.exe"
Image size: 13624
Image MD5: F8D67C4A69D9448F687AB1401FF29720
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Service (registry key): aliide
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\aliide.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 3
Service (registry key): AMD External Events Utility
Registry path: \SYSTEM\CurrentControlSet\Services\
Object name: LocalSystem
Image path: %SystemRoot%\system32\atiesrxx.exe
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Service (registry key): amdide
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\amdide.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 3
Service (registry key): AmdK8
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AMD K8 Processor Driver
Image path: \SystemRoot\system32\DRIVERS\amdk8.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): amdkmdag
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\atikmdag.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): amdkmdap
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\atikmpag.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): AmdPPM
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AMD Processor Driver
Image path: \SystemRoot\system32\DRIVERS\amdppm.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): amdsata
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\amdsata.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): amdsbs
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\amdsbs.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): amdxata
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\amdxata.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 0
Type: 1
Error Control: 1
Service (registry key): AppID
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%systemroot%\system32\appidsvc.dll,-102
Description: @%systemroot%\system32\appidsvc.dll,-103
Image path: \SystemRoot\system32\drivers\appid.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Depends On services: FltMgr,DisCache
Service (registry key): AppIDSvc
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%systemroot%\system32\appidsvc.dll,-100
Description: @%systemroot%\system32\appidsvc.dll,-101
Object name: NT Authority\LocalService
Image path: %SystemRoot%\system32\svchost.exe -k LocalServiceAndNoImpersonation
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs,AppID,CryptSvc
Service (registry key): Appinfo
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%systemroot%\system32\appinfo.dll,-100
Description: @%systemroot%\system32\appinfo.dll,-101
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k netsvcs
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: RpcSs,ProfSvc
Service (registry key): arc
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\arc.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): arcsas
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\arcsas.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): AsyncMac
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%systemroot%\system32\rascfg.dll,-32000
Description: @%systemroot%\system32\rascfg.dll,-32000
Image path: system32\DRIVERS\asyncmac.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): atapi
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: \SystemRoot\system32\DRIVERS\atapi.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 3
Service (registry key): Atierecord
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): AtiHdmiService
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: ATI Function Driver for High Definition Audio Service
Image path: system32\drivers\AtiHdmi.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): atikmdag
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\atikmdag.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 0
Service (registry key): atksgt
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: atksgt
Image path: system32\DRIVERS\atksgt.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 2
Type: 1
Error Control: 1
Service (registry key): AudioEndpointBuilder
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\audiosrv.dll,-204
Description: @%SystemRoot%\System32\audiosrv.dll,-205
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: PlugPlay
Service (registry key): AudioSrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\audiosrv.dll,-200
Description: @%SystemRoot%\System32\audiosrv.dll,-201
Object name: NT AUTHORITY\LocalService
Image path: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: AudioEndpointBuilder,RpcSs,MMCSS
Service (registry key): AVG
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): AVG Security Toolbar Service
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVG Security Toolbar Service
Object name: LocalSystem
Image path: C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe
Image size: 430152
Image MD5: 8C4CC2389BF37403E9CA0BCA511A71AA
Control Set: CurrentControlSet
Start: 3
Type: 16
Error Control: 1
Service (registry key): avg9wd
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVG Free WatchDog
Object name: LocalSystem
Image path: "C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe"
Image size: 308136
Image MD5: C4D15594DB5BE042D3346EA58DF87D89
Control Set: CurrentControlSet
Start: 2
Type: 16
Error Control: 1
Service (registry key): AvgLdx64
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVG Free AVI Loader Driver x64
Image path: System32\Drivers\avgldx64.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): AvgMfx64
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVG Free On-access Scanner Minifilter Driver x64
Image path: System32\Drivers\avgmfx64.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 2
Error Control: 1
Service (registry key): AvgTdiA
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: AVG Free Network Redirector x64
Image path: System32\Drivers\avgtdia.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): AxInstSV
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\AxInstSV.dll,-103
Description: @%SystemRoot%\system32\AxInstSV.dll,-104
Object name: LocalSystem
Image path: %SystemRoot%\system32\svchost.exe -k AxInstSVGroup
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Depends On services: rpcss
Service (registry key): b06bdrv
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Broadcom NetXtreme II VBD
Image path: \SystemRoot\system32\DRIVERS\bxvbda.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): b57nd60a
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
Image path: system32\DRIVERS\b57nd60a.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 3
Type: 1
Error Control: 1
Service (registry key): BattC
Registry path: \SYSTEM\CurrentControlSet\Services\
Control Set: CurrentControlSet
Start: 0
Type: 0
Error Control: 0
Service (registry key): BDESVC
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\bdesvc.dll,-100
Description: @%SystemRoot%\system32\bdesvc.dll,-101
Object name: localSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 3
Type: 32
Error Control: 1
Service (registry key): Beep
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: Beep
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1
Service (registry key): BFE
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\bfe.dll,-1001
Description: @%SystemRoot%\system32\bfe.dll,-1002
Object name: NT AUTHORITY\LocalService
Image path: %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs
Service (registry key): BITS
Registry path: \SYSTEM\CurrentControlSet\Services\
Display name: @%SystemRoot%\system32\qmgr.dll,-1000
Description: @%SystemRoot%\system32\qmgr.dll,-1001
Object name: LocalSystem
Image path: %SystemRoot%\System32\svchost.exe -k netsvcs
Image size: 20992
Image MD5: 54A47F6B5E09A77E61649109C6A08866
Control Set: CurrentControlSet
Start: 2
Type: 32
Error Control: 1
Depends On services: RpcSs,EventSystem
Service (registry key): blbdrive
Registry path: \SYSTEM\CurrentControlSet\Services\
Image path: system32\DRIVERS\blbdrive.sys
Image size: 0
Image MD5: D41D8CD98F00B204E9800998ECF8427E
Control Set: CurrentControlSet
Start: 1
Type: 1
Error Control: 1