Thanks for the reply. Sorry I thought I got it all but I see that I did miss a lot. I'll try again
OTL logfile created on: 8/18/2011 10:04:58 AM - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\Charles New\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.96 Gb Total Physical Memory | 0.74 Gb Available Physical Memory | 37.71% Memory free
3.81 Gb Paging File | 2.25 Gb Available in Paging File | 59.19% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.01 Gb Total Space | 70.35 Gb Free Space | 47.21% Space Free | Partition Type: NTFS
Computer Name: JCNRHIZOGEN | User Name: Charles New | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/08/18 10:01:45 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Charles New\My Documents\Downloads\OTL.exe
PRC - [2011/08/12 00:57:30 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/03/09 07:30:08 | 000,247,728 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2011/03/09 07:30:08 | 000,092,592 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2011/02/18 11:47:12 | 000,079,192 | ---- | M] (Research In Motion Limited) -- C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
PRC - [2010/12/14 11:23:18 | 000,228,352 | ---- | M] (PC Pitstop LLC) -- C:\Program Files\PCPitstop\PC MaticRT\PCPitstopRTService.exe
PRC - [2010/10/29 15:49:28 | 000,505,064 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2010/09/27 11:09:54 | 000,325,336 | ---- | M] (PC Pitstop LLC) -- C:\Program Files\PCPitstop\PC Matic\PCMatic.exe
PRC - [2010/02/25 19:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe
PRC - [2009/05/21 11:13:58 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/02/22 18:49:42 | 000,483,420 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
PRC - [2009/02/22 18:49:34 | 000,249,938 | ---- | M] (IDT, Inc.) -- c:\drivers\audio\R211990\stacsv.exe
PRC - [2009/02/22 18:49:28 | 000,729,088 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\AESTFltr.exe
PRC - [2009/02/02 20:12:00 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2009/02/02 20:11:42 | 000,208,896 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2009/02/02 20:11:40 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2009/02/02 20:11:40 | 000,046,376 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2008/05/23 14:06:08 | 000,128,296 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2008/04/14 07:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/14 07:00:00 | 000,538,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spider.exe
PRC - [2008/01/31 15:03:40 | 000,094,208 | R--- | M] (Brother Industries, Ltd.) -- C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
========== Modules (No Company Name) ========== MOD - [2011/08/12 00:57:30 | 001,846,232 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/06/28 11:49:17 | 004,379,984 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\vcore.dll
MOD - [2011/06/12 18:40:39 | 000,316,752 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\remediation.dll
MOD - [2011/05/03 12:24:19 | 000,292,176 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\libEmail.dll
MOD - [2011/03/20 18:40:32 | 000,394,576 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\libVvs.dll
MOD - [2011/03/20 18:40:32 | 000,263,504 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\libZip.dll
MOD - [2011/03/20 18:40:31 | 000,185,680 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\libtd.dll
MOD - [2011/03/20 18:40:30 | 000,300,368 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\libRar.dll
MOD - [2011/03/20 18:40:30 | 000,185,680 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\libRTF.dll
MOD - [2011/03/20 18:40:29 | 000,349,520 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\libOleA.dll
MOD - [2011/03/20 18:40:28 | 000,210,256 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\libNSIS.dll
MOD - [2011/03/20 18:40:28 | 000,185,680 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\libMsi.dll
MOD - [2011/03/20 18:40:27 | 000,443,728 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\libMsCab.dll
MOD - [2011/03/20 18:40:26 | 000,193,872 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\libMachoUniv.dll
MOD - [2011/03/20 18:40:25 | 000,210,256 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\libBase64.dll
MOD - [2011/03/20 18:40:24 | 000,202,064 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\lib7zip.dll
MOD - [2011/03/20 18:40:23 | 000,963,920 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat\datRT\lgpl.dll
MOD - [2010/10/28 11:14:32 | 000,344,216 | ---- | M] () -- C:\WINDOWS\Downloaded Program Files\DiskMD3Ctrl.dll
MOD - [2010/09/17 09:34:58 | 000,459,480 | ---- | M] () -- C:\WINDOWS\Downloaded Program Files\PCPitStop.dll
MOD - [2010/09/17 09:34:38 | 000,266,240 | ---- | M] () -- C:\WINDOWS\Downloaded Program Files\PCPitstopAntiVirus2.dll
MOD - [2010/08/16 15:37:04 | 000,407,224 | ---- | M] () -- C:\WINDOWS\Downloaded Program Files\pcpitstop2.dll
MOD - [2010/08/12 03:06:43 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\a6dbe24cbfe3ab6b318ed3095cc572d8\System.Xml.ni.dll
MOD - [2010/08/12 03:06:24 | 007,949,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\08ffa4d388d5f007869aa7651c458e7c\System.ni.dll
MOD - [2010/08/12 03:06:15 | 011,490,816 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7bffd7ff2009f421fe5d229927588496\mscorlib.ni.dll
MOD - [2010/07/09 13:52:32 | 001,310,032 | ---- | M] () -- C:\WINDOWS\Downloaded Program Files\sbte.dll
MOD - [2010/07/09 13:52:24 | 000,415,056 | ---- | M] () -- C:\WINDOWS\Downloaded Program Files\SpursDownload.dll
MOD - [2010/03/23 04:21:40 | 000,300,368 | ---- | M] () -- C:\WINDOWS\Downloaded Program Files\vipre.dll
MOD - [2010/03/23 04:21:40 | 000,300,368 | ---- | M] () -- C:\Program Files\PCPitstop\PC MaticRT\vipre.dll
MOD - [2009/11/16 14:53:56 | 003,081,400 | ---- | M] () -- C:\WINDOWS\Downloaded Program Files\PCPitstop3D.dll
MOD - [2009/11/03 16:51:42 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2009/02/14 05:04:38 | 000,756,040 | ---- | M] () -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL
MOD - [2008/12/11 20:38:02 | 000,143,360 | ---- | M] () -- C:\WINDOWS\system32\preflib.dll
MOD - [2008/12/11 20:37:28 | 000,753,664 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll
MOD - [2008/10/26 05:42:14 | 000,065,376 | ---- | M] () -- C:\Program Files\Microsoft Office\Office12\ADDINS\ColleagueImport.dll
MOD - [2007/07/23 15:04:46 | 000,068,080 | ---- | M] () -- C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\dlaapi_w.dll
MOD - [2006/10/27 15:35:18 | 000,436,512 | ---- | M] () -- C:\Program Files\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll
MOD - [2002/11/26 14:43:18 | 000,106,496 | ---- | M] () -- C:\WINDOWS\system32\BrMuSNMP.dll
========== Win32 Services (SafeList) ========== SRV - [2011/03/09 07:30:08 | 000,092,592 | ---- | M] (TomTom) [On_Demand | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2010/12/14 11:23:18 | 000,228,352 | ---- | M] (PC Pitstop LLC) [Auto | Running] -- C:\Program Files\PCPitstop\PC MaticRT\PCPitstopRTService.exe -- (PCPitstop Realtime)
SRV - [2010/09/27 11:09:52 | 000,090,864 | ---- | M] (PC Pitstop LLC) [On_Demand | Stopped] -- C:\Program Files\PCPitstop\PCPitstopScheduleService.exe -- (PCPitstop Scheduling)
SRV - [2010/02/25 19:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe -- (N360)
SRV - [2009/02/22 18:49:34 | 000,249,938 | ---- | M] (IDT, Inc.) [Auto | Running] -- c:\drivers\audio\R211990\stacsv.exe -- (STacSV)
SRV - [2009/01/21 14:10:44 | 000,072,224 | ---- | M] (O2Micro International) [On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\o2flash.exe -- (O2FLASH)
SRV - [2008/08/14 00:04:44 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [On_Demand | Stopped] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
========== Driver Services (SafeList) ========== DRV - [2011/08/03 21:11:14 | 001,576,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110817.038\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/08/03 21:11:14 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110817.038\NAVENG.SYS -- (NAVENG)
DRV - [2011/08/02 01:07:58 | 000,355,256 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110816.030\IDSXpx86.sys -- (IDSxpx86)
DRV - [2011/07/27 18:01:08 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011/07/27 18:01:08 | 000,105,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/07/22 19:27:23 | 000,815,736 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20110812.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2010/07/14 07:56:32 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2010/06/14 15:04:30 | 000,069,976 | ---- | M] (Sunbelt Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\sbapifs.sys -- (sbapifs)
DRV - [2010/06/14 15:04:30 | 000,021,464 | ---- | M] (Sunbelt Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\sbaphd.sys -- (sbaphd)
DRV - [2010/05/05 23:01:59 | 000,361,904 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS -- (SYMTDI)
DRV - [2010/04/29 00:03:51 | 000,116,784 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS -- (SymIRON)
DRV - [2010/04/21 22:02:20 | 000,173,104 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS -- (SymEFA)
DRV - [2010/04/21 21:29:50 | 000,325,680 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS -- (SRTSP)
DRV - [2010/04/21 21:29:50 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2010/02/25 19:22:57 | 000,501,888 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys -- (ccHP)
DRV - [2009/10/14 22:50:05 | 000,328,752 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS -- (SymDS)
DRV - [2009/07/28 17:55:00 | 000,143,360 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2009/02/22 18:49:38 | 001,548,339 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2009/02/22 18:49:26 | 000,112,512 | ---- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AESTAud.sys -- (AESTAud)
DRV - [2009/02/02 20:11:38 | 000,170,032 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2009/01/21 14:10:48 | 000,041,760 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\o2sdg.sys -- (O2SDGRDR)
DRV - [2009/01/21 14:10:46 | 000,051,616 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\o2mdg.sys -- (O2MDGRDR)
DRV - [2008/12/11 20:37:58 | 001,287,552 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2008/11/20 22:59:02 | 000,027,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PCASp50.sys -- (PCASp50)
DRV - [2008/08/22 12:05:40 | 000,026,760 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\swmsflt.sys -- (swmsflt)
DRV - [2008/08/20 14:36:36 | 000,142,976 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\swumx80.sys -- (SWUMX80) Sierra Wireless USB MUX Driver (UMTS80)
DRV - [2008/08/20 14:35:40 | 000,168,192 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\swnc8u80.sys -- (SWNC8U80) Sierra Wireless MUX NDIS Driver (UMTS80)
DRV - [2008/04/14 07:00:00 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/04/14 07:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2008/04/14 07:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2007/07/23 15:05:20 | 000,009,104 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLADResM.SYS -- (DLADResM)
DRV - [2007/07/23 15:04:58 | 000,037,360 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLABMFSM.SYS -- (DLABMFSM)
DRV - [2007/07/23 15:04:56 | 000,098,448 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2007/07/23 15:04:56 | 000,093,552 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2007/07/23 15:04:54 | 000,027,216 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2007/07/23 15:04:52 | 000,032,848 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2007/07/23 15:04:52 | 000,016,304 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2007/07/23 15:04:50 | 000,108,752 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2007/07/23 14:49:44 | 000,030,064 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_M.SYS -- (DLARTL_M)
DRV - [2007/07/23 14:49:44 | 000,014,576 | ---- | M] (Roxio) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2001/08/17 12:11:18 | 000,020,160 | ---- | M] (ADMtek Incorporated) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ADM8511.SYS -- (ADM8511)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL =
http://g.msn.com/USSMB/1IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://search.msn.com/sphome.aspxIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page =
http://g.msn.com/USSMB/1 IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/USSMB/1IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityrespo...er/fix_homepageIE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8074
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/USSMB/1IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityrespo...er/fix_homepageIE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8074
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityrespo...er/fix_homepage IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityrespo...er/fix_homepage IE - HKU\S-1-5-21-1119492408-994160716-3076737224-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/USSMB/1IE - HKU\S-1-5-21-1119492408-994160716-3076737224-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://search.msn.com/sphome.aspxIE - HKU\S-1-5-21-1119492408-994160716-3076737224-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.live.comIE - HKU\S-1-5-21-1119492408-994160716-3076737224-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityrespo...er/fix_homepageIE - HKU\S-1-5-21-1119492408-994160716-3076737224-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1119492408-994160716-3076737224-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/USSMB/1IE - HKU\S-1-5-21-1119492408-994160716-3076737224-1007\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
http://www.dell.comIE - HKU\S-1-5-21-1119492408-994160716-3076737224-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://search.msn.com/sphome.aspxIE - HKU\S-1-5-21-1119492408-994160716-3076737224-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.live.comIE - HKU\S-1-5-21-1119492408-994160716-3076737224-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/USSMB/1IE - HKU\S-1-5-21-1119492408-994160716-3076737224-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
http://www.google.com/" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rim.com/npappworld: C:\Program Files\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll ()
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\
[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/07/30 11:21:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2011/07/25 07:58:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn_2010_9_0_6 [2011/08/17 18:12:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/08/18 09:17:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/24 16:11:23 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/07/30 11:21:27 | 000,000,000 | ---D | M]
[2011/05/03 08:18:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Charles New\Application Data\Mozilla\Extensions
[2011/05/03 08:18:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Charles New\Application Data\Mozilla\Extensions\
[email protected][2011/08/16 14:41:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Charles New\Application Data\Mozilla\Firefox\Profiles\cjmfk3ax.default\extensions
[2010/05/13 09:28:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Charles New\Application Data\Mozilla\Firefox\Profiles\cjmfk3ax.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/12 20:35:46 | 000,000,000 | ---D | M] (IE Tab) -- C:\Documents and Settings\Charles New\Application Data\Mozilla\Firefox\Profiles\cjmfk3ax.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2010/08/17 11:56:36 | 000,000,000 | ---D | M] (WebSlingPlayer) -- C:\Documents and Settings\Charles New\Application Data\Mozilla\Firefox\Profiles\cjmfk3ax.default\extensions\{9EB34849-81D3-4841-939D-666D522B889A}
[2011/08/16 14:41:37 | 000,000,000 | ---D | M] (Cooliris) -- C:\Documents and Settings\Charles New\Application Data\Mozilla\Firefox\Profiles\cjmfk3ax.default\extensions\
[email protected][2010/11/17 10:35:27 | 000,001,820 | ---- | M] () -- C:\Documents and Settings\Charles New\Application Data\Mozilla\Firefox\Profiles\cjmfk3ax.default\searchplugins\bing.xml
[2011/08/18 09:17:07 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/03/12 17:45:32 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) --
[2011/08/12 00:57:31 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/03/12 17:45:11 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/08/11 22:16:35 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
O1 HOSTS File: ([2008/04/14 07:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEplg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-1119492408-994160716-3076737224-1006\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [AESTFltr] C:\WINDOWS\System32\AESTFltr.exe (Andrea Electronics Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [PC MaticRT] C:\Program Files\PCPitstop\PC MaticRT\PCMaticRT.exe (PC Pitstop LLC)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [ToolBoxFX] C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe (HP)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKU\S-1-5-21-1119492408-994160716-3076737224-1006..\Run: [SMAV] File not found
O4 - HKU\.DEFAULT..\RunOnce: [] File not found
O4 - HKU\S-1-5-18..\RunOnce: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [] File not found
O4 - HKU\S-1-5-20..\RunOnce: [] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\S-1-5-21-1119492408-994160716-3076737224-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-21-1119492408-994160716-3076737224-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKU\S-1-5-21-1119492408-994160716-3076737224-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: //about.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Exclude.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //FWEvent.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //LanguageSelection.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Message.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryCmd.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryNag.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyNotification.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //NOCLessUpdate.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //quarantine.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //ScanNow.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //strings.vbs/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Template.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Update.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //VirFound.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] https in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O15 - HKU\S-1-5-21-1119492408-994160716-3076737224-1006\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKU\S-1-5-21-1119492408-994160716-3076737224-1006\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-1119492408-994160716-3076737224-1006\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}
http://utilities.pcp...ols/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C}
http://www.facebook....ls/contactx.dll (ContactExtractor Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20270.www2.h...tDetection2.cab (GMNRev Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
https://secure.logme...trl.cab?lmi=100 (Performance Viewer Activex Control)
O16 - DPF: Garmin Communicator Plug-In
https://static.garmi...inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.28.186.91 68.28.178.91
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKU\.DEFAULT Winlogon: Shell - (C:\Documents and Settings\NetworkService\Application Data\hotfix.exe) - File not found
O20 - HKU\S-1-5-18 Winlogon: Shell - (C:\Documents and Settings\NetworkService\Application Data\hotfix.exe) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Charles New\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Charles New\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 16:29:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{20da1b20-a0d0-11de-9290-00225f8a4bdc}\Shell - "" = AutoRun
O33 - MountPoints2\{20da1b20-a0d0-11de-9290-00225f8a4bdc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{20da1b20-a0d0-11de-9290-00225f8a4bdc}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{3f7a8572-74bd-11e0-93b6-0014d11d5b14}\Shell\AutoRun\command - "" = E:\InstallTomTomHOME.exe
O33 - MountPoints2\{3f7a8573-74bd-11e0-93b6-0014d11d5b14}\Shell\AutoRun\command - "" = E:\InstallTomTomHOME.exe
O33 - MountPoints2\{625cae50-5e2b-11df-9302-00225f8a4bdc}\Shell - "" = AutoRun
O33 - MountPoints2\{625cae50-5e2b-11df-9302-00225f8a4bdc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{625cae50-5e2b-11df-9302-00225f8a4bdc}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{cd6d88bf-e338-11de-92cc-00225f8a4bdc}\Shell\AutoRun\command - "" = E:\slacker.synclauncher.exe
O33 - MountPoints2\{cd6d88bf-e338-11de-92cc-00225f8a4bdc}\Shell\slacker\command - "" = E:\slacker.synclauncher.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/08/14 06:43:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Charles New\Application Data\Tific
[2011/08/14 06:43:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Charles New\Local Settings\Application Data\Symantec
[2011/07/28 10:33:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Charles New\Start Menu\Programs\pdfFactory Pro
[2011/07/28 10:33:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Charles New\My Documents\PDF files
[2011/07/28 10:33:04 | 000,385,024 | ---- | C] (FinePrint Software, LLC) -- C:\WINDOWS\System32\fppmon4.dll
[2011/07/28 10:33:04 | 000,262,656 | ---- | C] (FinePrint Software, LLC) -- C:\WINDOWS\System32\fppr432.dll
[2011/07/28 10:26:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Charles New\Local Settings\Application Data\Citrix
[2010/10/17 13:42:05 | 000,004,096 | ---- | C] ( ) -- C:\WINDOWS\System32\IGFXDEVLib.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/08/18 10:11:01 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/18 09:19:19 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{B3FD3A4C-C734-4529-9D87-3AC851657ACC}.job
[2011/08/18 09:17:12 | 000,000,744 | ---- | M] () -- C:\Documents and Settings\Charles New\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/08/18 09:17:11 | 000,000,726 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/08/17 16:24:14 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/08/17 16:24:12 | 000,000,892 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/17 16:22:11 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/08/17 16:21:43 | 2106,470,400 | -HS- | M] () -- C:\hiberfil.sys
[2011/08/17 13:14:24 | 000,001,774 | -H-- | M] () -- C:\Documents and Settings\Charles New\My Documents\Default.rdp
[2011/08/16 22:15:00 | 000,312,571 | ---- | M] () -- C:\Documents and Settings\Charles New\Desktop\Distributor Price List August 1, 2011.pdf
[2011/08/13 13:05:06 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/07/28 10:26:38 | 000,103,720 | ---- | M] () -- C:\Documents and Settings\Charles New\GoToAssistDownloadHelper.exe
[2011/07/23 22:50:28 | 000,385,024 | ---- | M] (FinePrint Software, LLC) -- C:\WINDOWS\System32\fppmon4.dll
[2011/07/23 22:47:24 | 000,262,656 | ---- | M] (FinePrint Software, LLC) -- C:\WINDOWS\System32\fppr432.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/08/16 17:57:55 | 000,312,571 | ---- | C] () -- C:\Documents and Settings\Charles New\Desktop\Distributor Price List August 1, 2011.pdf
[2011/07/28 10:26:36 | 000,103,720 | ---- | C] () -- C:\Documents and Settings\Charles New\GoToAssistDownloadHelper.exe
[2011/05/12 14:09:42 | 000,001,940 | ---- | C] () -- C:\Documents and Settings\Charles New\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/03/15 17:20:22 | 000,469,306 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1119492408-994160716-3076737224-1006-0.dat
[2011/03/15 17:20:21 | 000,166,794 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/03/12 18:01:07 | 000,026,760 | ---- | C] () -- C:\WINDOWS\System32\drivers\swmsflt.sys
[2011/03/09 10:57:54 | 000,000,800 | ---- | C] () -- C:\WINDOWS\Brpfx04a.ini
[2011/03/09 10:57:54 | 000,000,153 | ---- | C] () -- C:\WINDOWS\brpcfx.ini
[2011/03/09 10:56:50 | 000,000,086 | ---- | C] () -- C:\WINDOWS\Brfaxrx.ini
[2011/03/09 10:56:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\brdfxspd.dat
[2011/03/09 10:56:48 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\BrMuSNMP.dll
[2011/03/09 09:52:34 | 000,000,426 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2011/03/09 09:52:33 | 000,000,065 | ---- | C] () -- C:\WINDOWS\System32\BD7840W.DAT
[2011/03/09 09:52:28 | 000,000,000 | ---- | C] () -- C:\Program Files\error.dat
[2011/03/09 09:52:28 | 000,000,000 | ---- | C] () -- C:\WINDOWS\brmx2001.ini
[2011/03/09 09:52:24 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\BRTCPCON.DLL
[2011/03/09 09:52:23 | 000,000,114 | ---- | C] () -- C:\WINDOWS\System32\BRLMW03A.INI
[2011/03/09 09:51:28 | 000,000,074 | ---- | C] () -- C:\WINDOWS\Brownie.ini
[2011/03/09 09:09:02 | 000,031,567 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2010/12/25 19:06:20 | 000,040,412 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/11/01 07:54:57 | 000,000,197 | ---- | C] () -- C:\Documents and Settings\NetworkService\Application Data\dkfjasdfshd.bat
[2010/10/17 13:42:04 | 000,000,151 | ---- | C] () -- C:\WINDOWS\System32\GfxUI.exe.config
[2010/09/15 06:59:47 | 001,564,656 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/26 13:34:04 | 000,000,080 | ---- | C] () -- C:\WINDOWS\ricdb.ini
[2010/08/26 13:34:02 | 000,000,031 | ---- | C] () -- C:\WINDOWS\System32\RPCS.ini
[2010/07/12 15:21:44 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/02/17 11:24:21 | 000,000,014 | ---- | C] () -- C:\WINDOWS\hpmssnpjt.ini
[2010/01/28 18:06:12 | 000,127,408 | ---- | C] () -- C:\WINDOWS\hpwins21.dat
[2010/01/28 18:06:12 | 000,000,428 | ---- | C] () -- C:\WINDOWS\hpwmdl21.dat
[2010/01/25 13:58:06 | 000,462,848 | ---- | C] () -- C:\WINDOWS\System32\ractrlkeyhook.dll
[2009/09/02 16:36:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/06 18:48:38 | 000,000,125 | ---- | C] () -- C:\WINDOWS\ka.ini
[2009/05/07 18:02:30 | 000,010,240 | ---- | C] () -- C:\Documents and Settings\Charles New\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/06 16:11:27 | 000,000,608 | -HS- | C] () -- C:\WINDOWS\System32\winzvprt5.sys
[2009/05/06 16:08:56 | 000,000,685 | R--- | C] () -- C:\WINDOWS\System32\hppapr08.dat
[2009/05/06 16:08:36 | 000,000,131 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2009/05/06 16:06:08 | 000,001,202 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2009/05/06 16:00:45 | 000,153,548 | ---- | C] () -- C:\WINDOWS\hppins08.dat
[2009/05/06 16:00:45 | 000,153,507 | ---- | C] () -- C:\WINDOWS\System32\hppins08.dat
[2009/05/06 16:00:45 | 000,001,116 | ---- | C] () -- C:\WINDOWS\hppmdl08.dat
[2009/05/03 14:34:27 | 000,165,809 | ---- | C] () -- C:\WINDOWS\hpoins31.dat
[2009/05/03 14:34:27 | 000,001,691 | ---- | C] () -- C:\WINDOWS\hpomdl31.dat
[2009/05/02 08:13:40 | 000,000,256 | ---- | C] () -- C:\WINDOWS\System32\pool.bin
[2009/04/24 12:48:17 | 000,077,824 | ---- | C] () -- C:\WINDOWS\setpwr32.exe
[2009/04/24 12:48:06 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2009/04/24 12:48:01 | 000,982,240 | ---- | C] () -- C:\WINDOWS\System32\igkrng500.bin
[2009/04/24 12:48:01 | 000,439,308 | ---- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin
[2009/04/24 12:48:01 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v5016.dll
[2009/04/24 12:47:12 | 000,001,153 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2009/04/24 10:08:36 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2009/04/24 09:58:52 | 000,000,232 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/04/24 09:57:34 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2009/04/24 09:57:33 | 000,753,664 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2009/04/24 09:57:33 | 000,024,064 | ---- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/25 16:31:41 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/04/25 16:27:18 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/04/25 16:26:32 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2008/04/25 11:16:24 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008/04/25 11:16:22 | 000,506,858 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008/04/25 11:16:22 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008/04/25 11:16:22 | 000,088,046 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008/04/25 11:16:22 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008/04/25 11:16:22 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2008/04/25 11:16:21 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2008/04/25 11:16:20 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2008/04/25 11:16:18 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008/04/25 11:16:18 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008/04/25 11:16:13 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008/04/25 11:16:11 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/04/25 04:22:39 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/04/25 04:21:52 | 000,198,552 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/03/16 17:00:00 | 000,003,403 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ========== [2009/04/24 09:56:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2010/07/12 08:12:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\23a4628
[2010/05/04 13:02:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\99306936
[2011/03/17 07:41:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
[2011/08/18 10:06:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/10/17 12:53:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCPitstopDat
[2010/08/24 10:46:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2011/03/31 09:30:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/04/24 10:00:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2011/05/03 08:20:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom
[2009/05/06 16:11:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\zvprt50
[2010/12/24 01:22:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/01/31 16:49:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/03/12 18:05:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\AT&T
[2011/03/13 01:06:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\Audacity
[2010/01/29 09:21:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\Blackberry Desktop
[2011/03/12 18:05:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\DBUpdater
[2011/07/18 15:18:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\GARMIN
[2009/06/26 16:54:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\GetRightToGo
[2011/03/09 11:11:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\PC-FAX TX
[2010/12/13 09:37:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\PCDr
[2010/09/14 07:33:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\Research In Motion
[2011/03/31 09:18:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\ScanSoft
[2011/03/12 17:50:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\Sierra Wireless
[2010/05/20 12:21:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\Sling Media
[2011/08/14 06:43:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\Tific
[2011/05/03 08:17:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\TomTom
[2009/04/24 09:56:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\Windows Desktop Search
[2009/05/01 16:16:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Charles New\Application Data\Windows Search
[2009/04/24 09:56:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\Windows Desktop Search
[2011/03/12 18:05:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Bytemobile
[2009/04/24 09:56:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LogMeInRemoteUser\Application Data\Windows Desktop Search
[2011/03/12 18:09:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Bytemobile
[2011/08/18 09:19:19 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{B3FD3A4C-C734-4529-9D87-3AC851657ACC}.job
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Charles New\Desktop\Account For Charles New.grv:SummaryInformation
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Charles New\My Documents\Super Bowl Briskets and Birds 2010.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Charles New\My Documents\Rhizogen LLC Letterhead Template 5-09.doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Charles New\My Documents\Rain.wmv:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Charles New\My Documents\Copy of Boy Scouts Contact List 2010.xls:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Charles New\My Documents\AB site report (2).doc:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Charles New\My Documents\1733821.pdf:Roxio EMC Stream
< End of report >