Thank you for your response Thunderbird1988. Here are the logs.
OTListIt.Txt
OTListIt logfile created on: 1/20/2009 2:07:21 PM - Run
OTListIt2 by OldTimer - Version 1.0.3.0 Folder = C:\Documents and Settings\Chris\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.10 Gb Available Physical Memory | 54.83% Memory free
3.35 Gb Paging File | 2.62 Gb Available in Paging File | 78.32% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.50 Gb Total Space | 7.29 Gb Free Space | 10.20% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive W: | 465.23 Gb Total Space | 157.13 Gb Free Space | 33.77% Space Free | Partition Type: NTFS
Drive X: | 279.47 Gb Total Space | 230.21 Gb Free Space | 82.37% Space Free | Partition Type: NTFS
Computer Name: CHRIS-ABOD
Current User Name: Chris
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ========== C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
c:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
C:\Program Files\NavNT\defwatch.exe (Symantec Corporation)
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
C:\Program Files\LogMeIn\x86\LMIGuardian.exe (LogMeIn, Inc.)
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe (Dell Inc.)
C:\Program Files\ZyXEL\AG-225H\NICServ.exe ()
C:\Program Files\NavNT\rtvscan.exe (Symantec Corporation)
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
C:\WINDOWS\system32\TSSchBkpService.exe ()
C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\WINDOWS\system32\MSGSYS.EXE (Intel Corporation)
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
C:\Program Files\Intel\Wireless\Bin\1XConfig.exe (Intel)
C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
C:\Program Files\Dell\Media Experience\PCMService.exe (CyberLink Corp.)
C:\Program Files\Dell\QuickSet\quickset.exe ()
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
C:\Program Files\Logitech\Video\CameraAssistant.exe (Logitech Inc.)
C:\WINDOWS\system32\ElkCtrl.exe (Logitech Inc.)
C:\Program Files\Maxtor\Maxtor Quick Start\MaxBackService.exe (Maxtor Corp)
C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe (Maxtor Corp.)
C:\Program Files\Maxtor\Maxtor Quick Start\msssort.exe (Maxtor)
C:\Program Files\NavNT\vptray.exe (Symantec Corporation)
C:\Program Files\SamsungODD\Magic Speed\MagicSL.exe (SAMSUNG ELECTRONICS CO., LTD)
C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe ( )
C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe (ACD Systems)
C:\Program Files\LogMeIn\x86\LMIGuardian.exe (LogMeIn, Inc.)
C:\WINDOWS\system32\shdocvw.exe ()
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
C:\Program Files\palmOne\AlarmApp.exe (Palm, Inc.)
C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
C:\Program Files\SiteDevelopers.Com\Dynamic DNS Client .NET Edition - Desktop\ClientGUI.exe (Mike Hacker)
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
C:\Program Files\palmOne\Hotsync.exe (PalmSource, Inc)
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe (Intuit)
C:\Program Files\ZyXEL\AG-225H\AG-225Hv2.exe ()
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe (TOSHIBA CORPORATION.)
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe (TOSHIBA CORPORATION.)
C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
C:\Program Files\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
C:\Documents and Settings\Chris\Desktop\OTListIt2.exe (OldTimer Tools)
========== (O23) Win32 Services (SafeList) ========== (Adobe LM Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
(aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
(Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
(awhost32 [On_Demand | Stopped]) -- C:\Program Files\Symantec\pcAnywhere\awhost32.exe (Symantec Corporation)
(clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
(DefWatch [Auto | Running]) -- C:\Program Files\NavNT\defwatch.exe (Symantec Corporation)
(EvtEng [Auto | Running]) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
(gusvc [Auto | Running]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
(IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
(IntuitUpdateService [Auto | Running]) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
(JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
(LMIMaint [Auto | Running]) -- C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
(LogMeIn [Auto | Running]) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
(LVPrcSrv [Auto | Running]) -- c:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
(MDM [Auto | Running]) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
(NICCONFIGSVC [Auto | Running]) -- C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe (Dell Inc.)
(NICSer_AG225H [Auto | Running]) -- C:\Program Files\ZyXEL\AG-225H\NICServ.exe ()
(Norton AntiVirus Server [Auto | Running]) -- C:\Program Files\NavNT\rtvscan.exe (Symantec Corporation)
(ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
(Pml Driver HPZ12 [On_Demand | Stopped]) -- C:\WINDOWS\system32\HPZipm12.exe (HP)
(QBCFMonitorService [Disabled | Stopped]) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
(QBFCService [On_Demand | Stopped]) -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
(RegSrvc [Auto | Running]) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
(RoxLiveShare9 [Auto | Stopped]) -- File not found
(rpcapd [On_Demand | Stopped]) -- C:\Program Files\WinPcap\rpcapd.exe ()
(S24EventMonitor [Auto | Running]) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
(TOSHIBA Bluetooth Service [Auto | Running]) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
(TSScheduleBackup [Auto | Running]) -- C:\WINDOWS\system32\TSSchBkpService.exe ()
(UMWdf [On_Demand | Stopped]) -- C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
(usnjsvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
(Viewpoint Manager Service [Auto | Running]) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
(WLANKEEPER [Auto | Running]) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
(WLSetupSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
========== Driver Services (SafeList) ========== (AegisP [Auto | Running]) -- C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
(AliIde [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\aliide.sys (Acer Laboratories Inc.)
(amdagp [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\AMDAGP.SYS (Advanced Micro Devices, Inc.)
(ApfiltrService [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
(APPDRV [System | Running]) -- C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
(asc [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\asc.sys (Advanced System Products, Inc.)
(asc3550 [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\asc3550.sys (Advanced System Products, Inc.)
(ati2mtag [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
(awecho [System | Running]) -- C:\WINDOWS\system32\drivers\awechomd.sys (Symantec Corporation)
(AW_HOST [System | Running]) -- C:\WINDOWS\system32\drivers\AW_HOST5.sys (Symantec Corporation)
(bcm4sbxp [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
(BthEnum [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\BthEnum.sys (Microsoft Corporation)
(BthPan [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\bthpan.sys (Microsoft Corporation)
(BTHPORT [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\bthport.sys (Microsoft Corporation)
(BTHUSB [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\BTHUSB.SYS (Microsoft Corporation)
(CmdIde [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\cmdide.sys (CMD Technology, Inc.)
(dac2w2k [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\dac2w2k.sys (Mylex Corporation)
(Dot4 [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\Dot4.sys (Microsoft Corporation)
(Dot4Print [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\Dot4Prt.sys (Microsoft Corporation)
(dot4usb [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\Dot4usb.sys (Microsoft Corporation)
(drvmcdb [Boot | Running]) -- C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
(drvnddm [Auto | Running]) -- C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
(E100B [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
(FilterService [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
(Gernuwa [Boot | Running]) -- C:\WINDOWS\system32\drivers\GERNUWA.sys (Symantec Corporation)
(HSFHWICH [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
(HSF_DP [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
(HSF_DPV [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\HSF_DPV.SYS (Conexant Systems, Inc.)
(IWCA [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\iwca.sys (Intel Corporation)
(kbdhid [System | Running]) -- C:\WINDOWS\system32\drivers\kbdhid.sys (Microsoft Corporation)
(lgatbus [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\lgatbus.sys (MCCI)
(lgatmdm [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\lgatmdm.sys (MCCI)
(lgatserd [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\lgatserd.sys (MCCI)
(LMIInfo [Auto | Running]) -- C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
(lmimirr [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\lmimirr.sys (LogMeIn, Inc.)
(LMIRfsClientNP [Disabled | Stopped]) -- C:\WINDOWS\system32\LMIRfsClientNP.dll (LogMeIn, Inc.)
(LMIRfsDriver [Auto | Running]) -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
(Lvckap [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\Lvckap.sys ()
(lvmvdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\LVMVdrv.sys ()
(lvpopflt [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)
(LVPrcMon [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\LVPrcMon.sys ()
(LVUSBSta [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
(LVUVC [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
(mdmxsdk [Auto | Running]) -- C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
(mraid35x [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\mraid35x.sys (American Megatrends Inc.)
(NAVAP [On_Demand | Running]) -- C:\Program Files\NavNT\navap.sys ()
(NAVAPEL [Auto | Running]) -- C:\Program Files\NavNT\Navapel.sys ()
(NAVENG [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090114.017\NAVENG.SYS (Symantec Corporation)
(NAVEX15 [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090114.017\NAVEX15.SYS (Symantec Corporation)
(nv [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
(omci [System | Running]) -- C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
(PalmUSBD [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
(pcouffin [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\pcouffin.sys (VSO Software)
(Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
(PxHelp20 [Boot | Running]) -- C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
(ql1080 [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\ql1080.sys (QLogic Corporation)
(ql12160 [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\ql12160.sys (QLogic Corporation)
(ql1280 [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\ql1280.sys (QLogic Corporation)
(RFCOMM [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\rfcomm.sys (Microsoft Corporation)
(RimVSerPort [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\RimSerial.sys (Research in Motion Ltd)
(ROOTMODEM [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\rootmdm.sys (Microsoft Corporation)
(s24trans [Auto | Running]) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
(sdbus [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\sdbus.sys (Microsoft Corporation)
(Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(Ser2pl [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ser2pl.sys (Prolific Technology Inc.)
(sffdisk [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\sffdisk.sys (Microsoft Corporation)
(sffp_sd [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\sffp_sd.sys (Microsoft Corporation)
(sisagp [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\SISAGP.SYS (Silicon Integrated Systems Corporation)
(Sparrow [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\sparrow.sys (Adaptec, Inc.)
(sscdbhk5 [System | Running]) -- C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
(ssrtln [System | Running]) -- C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
(STAC97 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
(symc810 [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\symc810.sys (Symbios Logic Inc.)
(symc8xx [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\symc8xx.sys (LSI Logic)
(SymEvent [On_Demand | Running]) -- C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
(sym_hi [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\sym_hi.sys (LSI Logic)
(sym_u3 [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\sym_u3.sys (LSI Logic)
(tbhsd [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\tbhsd.sys (RapidSolution Software AG)
(Tcpip6 [System | Running]) -- C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
(tfsnboio [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
(tfsncofs [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
(tfsndrct [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
(tfsndres [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
(tfsnifs [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
(tfsnopio [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
(tfsnpool [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
(tfsnudf [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
(tfsnudfa [Auto | Running]) -- C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
(toshidpt [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\Toshidpt.sys (TOSHIBA Corporation.)
(tosporte [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
(Tosrfbd [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
(Tosrfbnp [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
(Tosrfcom [System | Running]) -- C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
(Tosrfhid [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
(tosrfnds [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
(TosRfSnd [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
(Tosrfusb [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
(tunmp [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\tunmp.sys (Microsoft Corporation)
(ultra [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\ultra.sys (Promise Technology, Inc.)
(usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
(w29n51 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
(winachsf [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
(WS2IFSL [Disabled | Stopped]) -- C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)
(ZDA211BU(ZyXEL) [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ZDA211BU.sys (ZyDAS Technology Corporation)
(ZDPSp50 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ZDPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieHKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft...p...ER}&ar=homeHKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htmHKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieHKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft...amp;ar=iesearchHKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comHKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/igHKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (291504 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 10040 more lines...
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar: (no name) - {BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe" (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" (ATI Technologies, Inc.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] "rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent (Microsoft Corporation)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [Device Detector] DevDetect.exe -autorun File not found
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (Macrovision Corporation)
O4 - HKLM..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [LogitechCameraAssistant] "C:\Program Files\Logitech\Video\CameraAssistant.exe" (Logitech Inc.)
O4 - HKLM..\Run: [LogitechCameraService(E)] "C:\WINDOWS\system32\ElkCtrl.exe" /automation (Logitech Inc.)
O4 - HKLM..\Run: [LogitechVideo[inspector]] "C:\Program Files\Logitech\Video\InstallHelper.exe" /inspect (Logitech Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" (LogMeIn, Inc.)
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [MagicSpeed] "C:\Program Files\SamsungODD\Magic Speed\MagicSL.exe" /autorun (SAMSUNG ELECTRONICS CO., LTD)
O4 - HKLM..\Run: [MaxBackSchedule] "C:\Program Files\Maxtor\Maxtor Quick Start\maxbackservice.exe" (Maxtor Corp)
O4 - HKLM..\Run: [mssSort] "C:\Program Files\Maxtor\Maxtor Quick Start\msssort.exe" (Maxtor)
O4 - HKLM..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" (Maxtor Corp.)
O4 - HKLM..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe r ( )
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [vptray] "C:\Program Files\NavNT\vptray.exe" (Symantec Corporation)
O4 - HKLM..\Run: [Windows Service Processor] shdocvw.exe ()
O4 - HKCU..\Run: [cogad] "C:\Documents and Settings\Chris\Application Data\cogad\cogad.exe" 61A847B5BBF728133B923E466188719AB689201522886B092CBD44BD8689220221DD3257 File not found
O4 - HKCU..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (Microsoft Corporation)
O4 - HKCU..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (Macrovision Corporation)
O4 - HKCU..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot (Logitech Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunServices: [Windows Service Processor] shdocvw.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Alarm Manager.LNK = C:\Program Files\palmOne\AlarmApp.exe (Palm, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dynamic DNS Client.lnk = C:\WINDOWS\Installer\{BA0DB8B7-7DCF-4F5E-AD6E-49F8DDFB9176}\_2cd672ae.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\palmOne\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Web Connector.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZyXEL AG-225H Utility.lnk = C:\Program Files\ZyXEL\AG-225H\AG-225Hv2.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Sites: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: turbotax.com (https in Trusted sites)
O15 - HKCU\..Trusted Sites: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B}
http://support.dell....iler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A}
http://downloadcente...trolLite_EN.cab (DjVuCtl Class)
O16 - DPF: {240EEE8D-91DB-4D74-A87E-671026601333}
http://www.rightnetw...eb/eolupcli.cab (EOLUP.Version)
O16 - DPF: {2D360201-FFF5-11D1-8D03-00A0C959BC0A}
http://unakrt-wm.unlb.org/DHTMLED.cab (DHTML Edit Control Safe for Scripting for IE5)
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B}
http://webiq005.webi...6-6D5536C585C9} (WebIQ Engine Application Object)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
http://office.micros...ntent/opuc2.cab (Office Update Installation Engine)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.micros...b?1120072921953 (WUWebControl Class)
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850}
http://www.rightnetw...rdp20050324.cab (Microsoft RDP Client Control (redist))
O16 - DPF: {843EE768-3A97-455C-9076-741BA3AD7B62}
https://accounting.q...156/qboax10.cab (QuickBooks Online Edition Utilities Class v10)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8CE3BAE6-AB66-40B6-9019-41E5282FF1E2}
https://accounting.q....255/qboax8.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
http://messenger.msn...pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler: - intu-help-qb1 - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll (TODO: <Company name>)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - livecall - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-itss - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msnim - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap11 - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
========== Winlogon Notify Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
AtiExtEvent: "DllName" = Ati2evxx.dll -- C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
fuldqzhh: "DllName" = fuldqzhh32.dll -- C:\WINDOWS\system32\fuldqzhh32.dll ()
IntelWireless: "DllName" = C:\Program Files\Intel\Wireless\Bin\LgNotify.dll -- C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
LMIinit: "DllName" = LMIinit.dll -- C:\WINDOWS\system32\LMIinit.dll (LogMeIn, Inc.)
NavLogon: "DllName" = C:\WINDOWS\system32\NavLogon.dll -- C:\WINDOWS\system32\NavLogon.dll ()
PCANotify: "DllName" = PCANotify.dll -- C:\WINDOWS\system32\PCANotify.dll (Symantec Corporation)
========== Shell Execute Hooks ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" (HKLM) -- C:\Program Files\SUPERAntiSpyware\SASSEH.DLL File not found
========== Safeboot Options ========== "AlternateShell" = cmd.exe
========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ========== AUTOEXEC.BAT []
C:\AUTOEXEC.BAT () -- [ NTFS ]
========== MountPoints2 ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{909b79da-bb3c-11dc-8f9d-00123fd631a9}\Shell\AutoRun\command]
"" = E:\InstallTomTomHOME.exe -- File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9b66b87b-c35a-11dd-9cbb-0010c67e438b}\Shell\AutoRun\command]
"" = E:\start.exe -- File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f212b86c-cb41-11db-9e74-00123fd631a9}\Shell\autorun]
"" = Auto&Play
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f212b86c-cb41-11db-9e74-00123fd631a9}\Shell\explore\command]
"" = system.exe
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f212b86c-cb41-11db-9e74-00123fd631a9}\Shell\open\command]
"" = system.exe
========== Files/Folders - Created Within 30 Days ========== [4 C:\WINDOWS\*.tmp files]
[2009/01/20 14:08:02 | 00,530,106 | ---- | C] () -- C:\Documents and Settings\Chris\Desktop\LopSD.exe
[2009/01/20 14:05:55 | 00,419,328 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Chris\Desktop\OTListIt2.exe
[2009/01/20 14:02:09 | 00,024,366 | ---- | C] () -- C:\Documents and Settings\Chris\My Documents\Generic host.JPG
[2009/01/20 14:01:11 | 00,018,888 | ---- | C] () -- C:\Documents and Settings\Chris\My Documents\DEP.JPG
[2009/01/20 07:37:53 | 00,000,933 | ---- | C] () -- C:\Documents and Settings\Chris\Desktop\Spybot - Search & Destroy.lnk
[2009/01/20 01:10:38 | 00,388,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmd.execf
[2009/01/20 01:06:47 | 00,388,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF4482.exe
[2009/01/20 01:06:47 | 00,388,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF4476.exe
[2009/01/20 01:06:11 | 00,000,000 | ---D | C] -- C:\32788R22FWJFW
[2009/01/20 00:54:55 | 03,043,320 | R--- | C] () -- C:\Documents and Settings\Chris\Desktop\CF.exe
[2009/01/20 00:53:41 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/20 00:05:40 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
[2009/01/19 23:43:44 | 21,468,93824 | -HS- | C] () -- C:\hiberfil.sys
[2009/01/19 23:27:03 | 01,529,241 | ---- | C] () -- C:\Documents and Settings\Chris\Desktop\SDFix.exe
[2009/01/19 22:37:34 | 00,016,896 | ---- | C] () -- C:\WINDOWS\System32\fuldqzhh32.dll
[2009/01/19 21:00:38 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/01/19 21:00:38 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/01/19 21:00:38 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/01/19 21:00:38 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/01/19 21:00:38 | 00,089,504 | ---- | C] (Smallfrogs Studio) -- C:\WINDOWS\fdsv.exe
[2009/01/19 21:00:38 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/01/19 21:00:38 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/01/19 21:00:38 | 00,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009/01/19 21:00:38 | 00,029,696 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/01/19 21:00:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/01/19 21:00:26 | 00,388,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF21786.exe
[2009/01/19 21:00:26 | 00,388,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF21776.exe
[2009/01/19 21:00:26 | 00,388,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\CF21772.exe
[2009/01/19 20:27:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Chris\Local Settings\Application Data\{27E17E67-C78F-4032-8ED3-44A2446403A2}
[2009/01/19 20:11:37 | 00,016,896 | ---- | C] () -- C:\WINDOWS\System32\fuldqzhh.dll
[2009/01/19 20:07:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Chris\Application Data\cogad
[2009/01/19 20:07:22 | 00,133,254 | ---- | C] () -- C:\WINDOWS\Promo3-Is_it_safe.png
[2009/01/19 20:07:18 | 00,289,840 | ---- | C] () -- C:\WINDOWS\Promo2-Petri.png
[2009/01/19 20:07:16 | 00,298,242 | ---- | C] () -- C:\WINDOWS\Promo1-map.png
[2009/01/18 18:02:35 | 00,000,384 | ---- | C] () -- C:\Documents and Settings\Chris\My Documents\license.dat
[2009/01/16 18:04:53 | 00,020,602 | ---- | C] () -- C:\Documents and Settings\Chris\My Documents\error.JPG
[2009/01/16 14:50:35 | 00,000,040 | ---- | C] () -- C:\WINDOWS\BO5140.INI
[2008/12/30 15:10:34 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\AnswerWorks 5.0
[2008/12/30 11:22:10 | 00,203,378 | ---- | C] () -- C:\Documents and Settings\Chris\My Documents\BestBuy.pdf
[2008/12/30 10:47:43 | 00,152,401 | ---- | C] () -- C:\WINDOWS\hpbvspst.his
[2008/12/30 10:47:43 | 00,000,395 | ---- | C] () -- C:\WINDOWS\hpbvspst.ini
[2008/12/30 10:47:38 | 00,002,010 | ---- | C] () -- C:\WINDOWS\hpbvnstp.hi1
[2008/12/30 10:47:38 | 00,000,783 | ---- | C] () -- C:\WINDOWS\hpbvnstp.bu1
[2008/12/25 08:49:55 | 00,190,232 | ---- | C] () -- C:\WINDOWS\hplj1320.hi1
[2008/12/25 08:49:55 | 00,013,266 | ---- | C] () -- C:\WINDOWS\hplj1320.bu1
[2008/12/24 15:53:09 | 00,000,782 | ---- | C] () -- C:\Documents and Settings\Chris\Desktop\ABC Amber BlackBerry Converter.lnk
[2008/12/24 15:53:04 | 00,000,000 | ---D | C] -- C:\Program Files\ABC Amber BlackBerry Converter
[2008/12/24 07:55:52 | 00,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0
[2008/12/24 07:49:06 | 00,000,256 | ---- | C] () -- C:\WINDOWS\System32\pool.bin
[2008/12/24 03:21:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sonic
[2008/12/24 03:12:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Roxio
[2008/12/24 03:12:28 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Roxio Shared
[2008/12/24 02:58:40 | 00,026,496 | R--- | C] (Research in Motion Ltd) -- C:\WINDOWS\System32\drivers\RimSerial.sys
[2008/12/24 02:45:19 | 00,000,000 | -HSD | C] -- C:\WINDOWS\ftpcache
========== Files - Modified Within 30 Days ========== [2 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/01/20 14:08:02 | 00,530,106 | ---- | M] () -- C:\Documents and Settings\Chris\Desktop\LopSD.exe
[2009/01/20 14:05:56 | 00,419,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Chris\Desktop\OTListIt2.exe
[2009/01/20 14:02:09 | 00,024,366 | ---- | M] () -- C:\Documents and Settings\Chris\My Documents\Generic host.JPG
[2009/01/20 14:01:11 | 00,018,888 | ---- | M] () -- C:\Documents and Settings\Chris\My Documents\DEP.JPG
[2009/01/20 14:01:05 | 00,000,450 | ---- | M] () -- C:\Documents and Settings\Chris\Application Data\SamsungLiveUpdateConfig.ini
[2009/01/20 13:58:28 | 00,002,593 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dynamic DNS Client.lnk
[2009/01/20 13:54:55 | 00,000,440 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2009/01/20 13:54:28 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/01/20 13:54:19 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/01/20 13:54:15 | 21,468,93824 | -HS- | M] () -- C:\hiberfil.sys
[2009/01/20 08:56:57 | 00,000,282 | RHS- | M] () -- C:\boot.ini
[2009/01/20 08:56:56 | 00,000,573 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/01/20 08:56:56 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/01/20 07:43:07 | 00,291,504 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2009/01/20 07:37:53 | 00,000,933 | ---- | M] () -- C:\Documents and Settings\Chris\Desktop\Spybot - Search & Destroy.lnk
[2009/01/20 01:10:38 | 00,388,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\cmd.execf
[2009/01/20 01:06:20 | 00,388,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF4482.exe
[2009/01/20 01:06:20 | 00,388,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF4476.exe
[2009/01/20 01:02:34 | 00,250,387 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090120-074307.backup
[2009/01/19 23:36:46 | 00,000,686 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090120-010234.backup
[2009/01/19 22:52:44 | 01,529,241 | ---- | M] () -- C:\Documents and Settings\Chris\Desktop\SDFix.exe
[2009/01/19 22:37:34 | 00,016,896 | ---- | M] () -- C:\WINDOWS\System32\fuldqzhh32.dll
[2009/01/19 22:37:34 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\svchost.exe
[2009/01/19 22:37:34 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\svchost.exe
[2009/01/19 22:16:00 | 00,016,896 | ---- | M] () -- C:\WINDOWS\System32\fuldqzhh.dll
[2009/01/19 21:00:07 | 00,388,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF21786.exe
[2009/01/19 21:00:07 | 00,388,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\CF21776.exe
[2009/01/19