That worked, but I would recommend that people bounce into safemode with networking, so they can get the recovery console install. (I was feeling lucky, so I ran without it since it seems to take 2-3 tries before the safemode window actually comes up. I finally figured out that the time to start tapping F8 is right after the SATA Raid controller says hello...)
In anycase, here is the combofix log. (I eagerly await wise counsel....)
---------------------------
ComboFix 11-03-27.02 - Ralph Wolf 03/28/2011 11:08:21.1.4 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3510.3237 [GMT -7:00]
Running from: d:\nuggets\TechSpot\ComboFix2.exe
AV: Trend Micro OfficeScan Antivirus *Disabled/Outdated* {9618DB9B-667E-4F02-9A27-C9ECD7BA6961}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\rwolf\Cookies\Index_3E227C64.dat
c:\documents and settings\rwolf\Cookies\IndexIE_3E227C64.dat
c:\documents and settings\rwolf\Cookies\IndexIE_53CB2050.dat
c:\windows\system32\raddrv.dll
.
----- BITS: Possible infected sites -----
.
hxxp://ca1appsccm03.adcorp.kla-tencor.com:80
.
((((((((((((((((((((((((( Files Created from 2011-02-28 to 2011-03-28 )))))))))))))))))))))))))))))))
.
.
2011-03-28 07:19 . 2011-03-28 07:19 -------- d-----w- c:\program files\ESET
2011-03-24 14:01 . 2011-03-24 14:01 -------- d-----w- c:\documents and settings\rwolf\Application Data\Malwarebytes
2011-03-24 14:01 . 2010-12-21 01:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-24 14:01 . 2011-03-24 14:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-03-24 14:01 . 2011-03-24 14:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-24 14:01 . 2010-12-21 01:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-24 04:10 . 2011-03-24 04:10 102400 ----a-w- c:\windows\RegBootClean.exe
2011-03-18 01:06 . 2011-03-18 01:06 -------- d-----w- c:\documents and settings\rwolf\Local Settings\Application Data\Help
2011-03-07 22:20 . 2011-03-07 22:57 -------- d-----w- c:\documents and settings\rwolf\Application Data\U3
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-09 13:53 . 2008-04-14 12:00 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2008-04-14 12:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-03 05:40 . 2010-11-17 09:18 472808 ------w- c:\windows\system32\deployJava1.dll
2011-02-03 03:19 . 2010-11-17 09:18 73728 ------w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58 . 2010-09-25 01:27 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2010-09-25 01:27 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-27 08:15 . 2011-01-27 08:14 249856 ------w- c:\windows\Setup1.exe
2011-01-27 08:15 . 2011-01-27 08:14 73216 ------w- c:\windows\ST6UNST.EXE
2011-01-21 14:44 . 2008-04-14 12:00 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2008-04-14 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:14 . 2008-04-14 12:00 1864064 ----a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2009-07-07 737280]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-27 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-27 170008]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-27 145432]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2010-07-20 1400832]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-07-20 1206544]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-06-04 292208]
"FreeFallProtection"="c:\program files\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-07-28 727664]
"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2010-02-06 849192]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
.
c:\documents and settings\Ralph Wolf\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{B0BF7057-6869-4E4B-920C-EA2A58DA07F0}\Icon3E5562ED7.ico [2010-12-7 6144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablelockworkstation"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\OrCAD\\OrCAD_16.2\\Licensing\\LicenseClientConfiguration.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cdnshelp.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cdsinfo.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cdsmps.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cdsMsgServer.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cdsNameServer.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cdsOaPathUtil.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cdsRemote.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cdsRemshClient.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cdsRunHidden.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cdsServIpc.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cdsUnzip.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cdswhich.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cdsZip.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cds_root.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\clsAdminTool.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\clsbd.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\clu.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\cmfeedback.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\consmgr.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\dregprint.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\emsChecker.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\emsMkError.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\mpsinfo.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\msgHelp.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\nmp.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\nmppath.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\switchversion.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\van.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\bin\\versionviewer.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\capture\\capture.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\capture\\comp16.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\capture\\pcadi.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\capture\\pspiceexplorersrvr.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\capture\\pstswp.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\capture\\regsvr32.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\capture\\sch2cap.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\capture\\tutorial\\Captutor.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\cdnshelp\\bin\\cdnshelp.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\cdnshelp\\bin\\cdnshelpindexer.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\cdnshelp\\bin\\indexer.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\cdnshelp\\bin\\tagtest.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\cdnshelp\\bin\\topicgen.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\cdnshelp\\bin\\_cdnshelp.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\dfII\\bin\\skill.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\dfII\\bin\\skill_g.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\bodygen.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\cpmaccess.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\libaccess.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\lrm.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\mkdefcfg.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\newgenasym.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\pcbCache.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\projmgr.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\psetup.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\purge.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\QPSetup.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\rollback.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\UniversalBrowser.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\fet\\bin\\versiontool.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\java.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\javacpl.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\javaw.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\javaws.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\jucheck.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\jusched.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\keytool.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\kinit.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\klist.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\ktab.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\orbd.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\pack200.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\policytool.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\rmid.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\rmiregistry.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\servertool.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\tnameserv.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\jre\\bin\\unpack200.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\fvupdateutil.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\gcad.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\gcam.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\gcdin.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\idfin.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\ipc356.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\layout.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\libcat.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\lsession.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\max2hyp.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxascb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxascx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxdxf.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxeco.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxfnetx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxminb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxminw.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxminx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxorcad.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxp99x.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxpadb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxpadx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxpcadb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxpcadx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxprotb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxprotx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxstrb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxstrx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxtangb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\maxtangx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\mfceco.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\orcadodb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\padb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\padx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\pcadb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\pcadx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\pcb2max.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\prcat.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\protb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\protx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\searchTool.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\setbrows.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\specin.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\strb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\strx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\tangb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\tangx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\to386.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\toidf.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\tomax.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\tospec.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\update90.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\samples\\demo\\reset.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\sroute\\batch32.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\sroute\\sroute.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\tutorial\\laytutor.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout\\vcadd\\vcadd32.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\fvupdateutil.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\gcad.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\gcam.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\gcdin.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\idfin.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\ipc356.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\layout.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\libcat.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\lsession.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\max2hyp.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxascb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxascx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxdxf.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxeco.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxfnetx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxminb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxminw.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxminx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxorcad.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxp99x.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxpadb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxpadx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxpcadb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxpcadx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxprotb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxprotx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxstrb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxstrx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxtangb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\maxtangx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\mfceco.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\orcadodb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\padb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\padx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\pcadb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\pcadx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\pcb2max.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\prcat.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\protb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\protx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\searchTool.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\setbrows.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\specin.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\strb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\strx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\tangb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\tangx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\to386.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\toidf.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\tomax.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\tospec.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\update90.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\samples\\demo\\reset.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\sroute\\batch32.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\sroute\\sroute.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\tutorial\\Laytutor.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_eng_ed\\vcadd\\vcadd32.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\fvupdateutil.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\gcad.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\gcam.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\gcdin.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\idfin.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\ipc356.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\layout.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\libcat.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\lsession.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\max2hyp.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxascb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxascx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxdxf.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxeco.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxfnetx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxminb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxminw.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxminx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxorcad.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxp99x.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxpadb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxpadx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxpcadb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxpcadx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxprotb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxprotx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxstrb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxstrx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxtangb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\maxtangx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\mfceco.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\orcadodb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\padb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\padx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\pcadb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\pcadx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\pcb2max.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\prcat.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\protb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\protx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\searchTool.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\setbrows.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\specin.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\strb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\strx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\tangb.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\tangx.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\to386.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\toidf.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\tomax.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\tospec.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\update90.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\samples\\demo\\reset.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\sroute\\batch32.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\sroute\\sroute.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\tutorial\\laytutor.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\layout_plus\\vcadd\\vcadd32.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\a2dxf.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\allegro.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\allegro_batch.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\allegro_free_viewer.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\aprepmap.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\artwork.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\ashowmap.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\batch_drc.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\bbvia.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\bem2d.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\brd2dml.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\convert_gerber.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\create_devices.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\create_sym.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dbdoctor.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dbdoctor14.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dbdoctor15.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dbdoctor_ui.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dbfix11.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dbfix12.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dbfix13.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dbstat.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\db_change_type.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dfa_dlg.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dfa_update.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dml2brd.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dmlcheck.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dmlcrypt.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\downrev14.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\downrev_library.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\draw_check.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dump_libraries.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\dxf2a.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\ems2d.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\enved.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\explot.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\extracta.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\fatten.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\flash_convert.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\fpbrowse.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\FSvia.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\FSviaSolver.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\ftsmerge.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\gate_assign.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\gbplot.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\genfeedformat.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\genrad.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\gloss.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\ibis2signoise.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\ibischk3.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\ibischk4.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\icmchk.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\idf_in.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\idf_out.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\iges_in.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\iges_out.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\il_allegro.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\ipc356_out.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\j2script.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\l2a.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\lis2buf.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\mbs2lib.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\mcm_escapes.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\mergedml.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\mkdeviceindex.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\modelintegrity.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\modelsim.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\ncroute.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\nctape.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\netin.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\netrev.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\pads_in.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\pad_designer.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\parallel.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\pcad_in.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\pe_wordpad.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\placement.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\plctxt.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\pre_check.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\productServer.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\quad2signoise.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\qvupdate.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\refresh_padstack.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\refresh_symbol.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\refresh_vs.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\reftxt.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\report.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\signoise.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\sigwave.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\sigxp.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\sigxsect.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\spc2dml.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\spc2spc.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\spif.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\spif_batch.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\swap.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\systemdump.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\sys_root.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\techfile.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\techfile13.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\techfile14.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\techfile15.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\tlsim.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\ts2dml.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\uprev.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\zrouter.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\perl5\\bin\\perl.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\perl5\\bin\\perlglob.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\perl5\\ntt\\cmd32.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\appmgr.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\IndiceFileGeneration.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\lxcwin.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\Magneticdesigner.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\modeled.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\MrkSrvr.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\msgview.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\PDesign.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\psched.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\pspice.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\pspiceaa.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\PSpiceEnc.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\pspiceexplorersrvr.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\psp_cmd.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\regsvr32.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\simmgr.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\simsrvr.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pspice\\stmed.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\specctra\\bin\\mbs2sp.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\specctra\\bin\\sp2mbs.exe"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\specctra\\bin\\specctra.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\OrCAD\\OrCAD_16.2\\tools\\pcb\\bin\\aconvmap.exe"=
"c:\\Program Files\\Measurement Computing\\DAQ\\MccSkts.exe"=
"c:\\Program Files\\Nortel\\Nortel VPN Client\\Extranet.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Trend Micro\\OfficeScan Client\\ScanMailOutLook.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"35205:TCP"= 35205:TCP:Trend Micro OfficeScan Listener
.
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\drivers\stdcfltn.sys [9/24/2010 7:23 PM 17648]
R3 Acceler;Accelerometer Service;c:\windows\system32\drivers\Accelern.sys [9/24/2010 7:23 PM 43888]
S1 CBUL32;Measurement Computing DataAcq;c:\windows\system32\drivers\CBUL32.sys [10/15/2010 12:27 AM 54048]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/4/2011 6:55 PM 136176]
S2 SSI Survey Client;SSI Survey Client;c:\program files\Scalable Software\Survey\SSI Survey Client\surveyclientnt.exe [12/11/2010 12:19 AM 90112]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [12/22/2010 12:52 AM 52304]
S2 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\tmxpflt.sys [5/2/2008 4:22 PM 249424]
S2 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\tmpreflt.sys [5/2/2008 4:21 PM 36432]
S2 TmProxy;OfficeScan NT Proxy Service;c:\program files\Trend Micro\OfficeScan Client\TmProxy.exe [7/10/2008 6:46 PM 689416]
S2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [11/15/2010 1:32 PM 592120]
S3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [9/24/2010 7:06 PM 113664]
S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [9/24/2010 7:11 PM 168616]
S3 Eacfilt;Eacfilt Miniport;c:\windows\system32\drivers\eacfilt.sys [9/13/2007 9:52 AM 26137]
S3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [9/24/2010 6:51 PM 132480]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\drivers\IntcDAud.sys [9/24/2010 7:09 PM 235520]
S3 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [9/13/2007 9:51 AM 157648]
S3 NETwNx32;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwNx32.sys [9/24/2010 7:17 PM 6650752]
S3 r_server;Remote Administrator Service;c:\windows\system32\r_server.exe [11/17/2010 7:54 PM 724992]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [1/2/2011 9:42 AM 96488]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [1/2/2011 9:42 AM 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [1/2/2011 9:42 AM 121576]
S3 SSI Client Installer;SSI Client Installer;c:\windows\system32\SCInstallerNT.exe [12/11/2010 12:19 AM 503808]
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-05 01:55]
.
2011-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-05 01:55]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 - vpnweb.cab
DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
FF - ProfilePath -
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKLM-Run-SysTrayApp - %ProgramFiles%\IDT\WDM\sttray.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-03-28 11:11
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-03-28 11:12:21
ComboFix-quarantined-files.txt 2011-03-28 18:12
.
Pre-Run: 90,651,209,728 bytes free
Post-Run: 91,162,918,912 bytes free
.
- - End Of File - - ACD810577DD61ADA705F872632B6826B