Onecattoo
Topic Starter
Trying to help my daughter with her very slow laptop while she is home for Thanksgiving. Here are the requested logs:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/25 16:19
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
Address: 0x8B529000 Size: 32768 File Visible: No Signed: -
Status: -
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x8B51E000 Size: 45056 File Visible: No Signed: -
Status: -
Name: mchInjDrv.sys
Image Path: C:\Windows\system32\Drivers\mchInjDrv.sys
Address: 0x97B49000 Size: 2560 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x8AA00000 Size: 49152 File Visible: No Signed: -
Status: -
Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1164 Status: Locked to the Windows API!
SSDT
——————-
#: 072 Function Name: NtCreateProcess
Status: Hooked by "C:\Windows\system32\drivers\PCTCore.sys" at address 0x807bf9a6
#: 073 Function Name: NtCreateProcessEx
Status: Hooked by "C:\Windows\system32\drivers\PCTCore.sys" at address 0x807bfb98
#: 334 Function Name: NtTerminateProcess
Status: Hooked by "C:\Windows\system32\drivers\PCTCore.sys" at address 0x807bf656
#: 383 Function Name: NtCreateUserProcess
Status: Hooked by "C:\Windows\system32\drivers\PCTCore.sys" at address 0x807bfda0
==EOF==
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/25 16:19
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
Address: 0x8B529000 Size: 32768 File Visible: No Signed: -
Status: -
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x8B51E000 Size: 45056 File Visible: No Signed: -
Status: -
Name: mchInjDrv.sys
Image Path: C:\Windows\system32\Drivers\mchInjDrv.sys
Address: 0x97B49000 Size: 2560 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x8AA00000 Size: 49152 File Visible: No Signed: -
Status: -
Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1164 Status: Locked to the Windows API!
SSDT
——————-
#: 072 Function Name: NtCreateProcess
Status: Hooked by "C:\Windows\system32\drivers\PCTCore.sys" at address 0x807bf9a6
#: 073 Function Name: NtCreateProcessEx
Status: Hooked by "C:\Windows\system32\drivers\PCTCore.sys" at address 0x807bfb98
#: 334 Function Name: NtTerminateProcess
Status: Hooked by "C:\Windows\system32\drivers\PCTCore.sys" at address 0x807bf656
#: 383 Function Name: NtCreateUserProcess
Status: Hooked by "C:\Windows\system32\drivers\PCTCore.sys" at address 0x807bfda0
==EOF==
Internet Explorer: 8.0.6001.18828
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.893.159 [GMT -8:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MsMpEng.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Microsoft Forefront\Client Security\Client\SSA\FcsSas.exe
C:\Program Files\Common Files\Iconix\IconixService.exe
C:\Windows\system32\lxdccoms.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Napster\napster.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\AOL\1180300995\ee\aolsoftware.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MpCmdRun.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Windows\system32\rundll32.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VirusScan\mcsysmon.exe
C:\PROGRA~1\McAfee\VirusScan\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\McAfee\MSC\mcshell.exe
C:\Program Files\Common Files\McAfee\Core\mchost.exe
C:\PROGRA~1\McAfee\VirusScan\mcods.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\explorer.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
C:\Users\Elena Lampman\Desktop\dds.scr
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = about:blank
uWindow Title = Internet Explorer provided by BlueFrog Internet
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MT6458
mDefault_Page_URL = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MT6458
mWindow Title = Internet Explorer provided by BlueFrog Internet
uInternet Settings,ProxyOverride = ;*.local
mSearchAssistant = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MT6458
uURLSearchHooks: P2P Energy Toolbar: {2bae58c2-79f9-45d1-a286-81f911301c3a} - c:\program files\p2p_energy\tbP2P1.dll
mURLSearchHooks: P2P Energy Toolbar: {2bae58c2-79f9-45d1-a286-81f911301c3a} - c:\program files\p2p_energy\tbP2P1.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: P2P Energy Toolbar: {2bae58c2-79f9-45d1-a286-81f911301c3a} - c:\program files\p2p_energy\tbP2P1.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: IconixBHOClass Class: {761233b6-f228-49e4-8f6b-668499d4e55a} - c:\program files\iconix\ieaddon\IconixBHO_41.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\siteadvisor\mcieplg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\google\BAE.dll
TB: P2P Energy Toolbar: {2bae58c2-79f9-45d1-a286-81f911301c3a} - c:\program files\p2p_energy\tbP2P1.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\siteadvisor\mcieplg.dll
uRun: []
uRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background
uRun: [ares vista] "c:\program files\ares vista\AresVista.exe" -h
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [Desktop Software] "c:\program files\common files\supportsoft\bin\bcont.exe" /ini "c:\program files\comcastui\desktop software\uinstaller.ini" /fromrun /starthidden
uRun: [17765430] c:\programdata\17765430\17765430.exe
uRun: [UniblueSpeedUpMyPC] c:\windows\system32\Launcher.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe
mRun: [NapsterShell] c:\program files\napster\napster.exe /systray
mRun: [BigFix] c:\program files\bigfix\bigfix.exe /atstartup
mRun: [HostManager] c:\program files\common files\aol\1180300995\ee\AOLSoftware.exe
mRun: [lxdcmon.exe] "c:\program files\lexmark 1300 series\lxdcmon.exe"
mRun: [lxdcamon] "c:\program files\lexmark 1300 series\lxdcamon.exe"
mRun: [LXDCCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXDCtime.dll,_RunDLLEntry@16
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Microsoft Forefront Client Security Antimalware Service] "c:\program files\microsoft forefront\client security\client\antimalware\MSASCui.exe" -hide
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [ddoctorv2] "c:\program files\comcast\desktop doctor\bin\sprtcmd.exe" /P ddoctorv2
mRun: []
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [17765430] c:\progra~2\17765430\17765430.exe
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
StartupFolder: c:\users\elenal~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\cleana~1.lnk - c:\program files\cisco systems\clean access agent\CCAAgent.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\1.0.150\SSScheduler.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - {44E212AB-13EA-4CA4-BE65-197FBA170412} - c:\program files\iconix\ieaddon\IconixBHO_41.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {BC3F6B6D-2E49-4603-B028-7411655713F3} - {0CC2F28D-D415-4FC6-A2E4-54B4D983609A} - c:\program files\iconix\ieaddon\IconixBHO_41.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\siteadvisor\McIEPlg.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\elenal~1\appdata\roaming\mozilla\firefox\profiles\je3cs45s.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1269415&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - P2P Energy Customized Web Search
FF - prefs.js: browser.startup.homepage - www.facebook.com
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1269415&SearchSource=2&q=
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - component: c:\program files\mozilla firefox\extensions\{6133daa7-c343-9318-6da3-48218cde28e2}\components\FFProxy35.dll
FF - component: c:\users\elena lampman\appdata\roaming\mozilla\firefox\profiles\je3cs45s.default\extensions\{2bae58c2-79f9-45d1-a286-81f911301c3a}\components\FFExternalAlert.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npIconixProxy35.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\users\elena lampman\appdata\roaming\move networks\plugins\npqmp071503000010.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2009-11-25 15:07 7,600 a——- c:\windows\system32\Config.MPF
2009-11-25 15:05 –d—– c:\programdata\SiteAdvisor
2009-11-25 14:57 40,552 a——- c:\windows\system32\drivers\mfesmfk.sys
2009-11-25 14:57 35,272 a——- c:\windows\system32\drivers\mfebopk.sys
2009-11-25 14:57 79,816 a——- c:\windows\system32\drivers\mfeavfk.sys
2009-11-25 14:57 130,424 a——- c:\windows\system32\drivers\Mpfp.sys
2009-11-25 14:54 –d—– c:\program files\common files\McAfee
2009-11-25 14:54 –d—– c:\program files\McAfee.com
2009-11-25 14:54 –d—– c:\program files\McAfee
2009-11-25 14:27 34,248 a——- c:\windows\system32\drivers\mferkdk.sys
2009-11-25 11:50 2,048 a——- c:\windows\system32\tzres.dll
2009-11-24 17:33 1,401,856 a——- c:\windows\system32\msxml6.dll
2009-11-24 17:33 1,248,768 a——- c:\windows\system32\msxml3.dll
2009-11-24 17:33 714,240 a——- c:\windows\system32\timedate.cpl
2009-11-22 18:43 709 a——- c:\windows\system32\CommandDispatchers.xml
2009-11-22 18:43 1,349 a——- c:\windows\system32\cleaner-config.xml
2009-11-22 18:42 –d—– c:\windows\system32\ErrorLogs
2009-11-22 15:34 6,375,988 a——- c:\users\elena lampman\ApexDC++_1.2.2_setup.exe
2009-11-18 14:48 –d—– C:\fbf2309febf98775b9ae771e
2009-11-18 14:39 –d—– c:\users\elenal~1\appdata\roaming\Iconix
2009-11-18 14:39 –d—– c:\programdata\Iconix
2009-11-18 14:39 –d—– c:\progra~2\Iconix
2009-11-18 14:39 –d—– c:\program files\common files\Iconix
2009-11-18 14:38 –d—– c:\program files\Iconix
2009-11-18 14:29 –d—– c:\program files\Uniblue
2009-11-18 14:28 -cd-h— c:\programdata\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2009-11-18 14:28 -cd-h— c:\progra~2\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2009-11-17 03:25 –d—– c:\program files\Windows Portable Devices
2009-11-17 03:25 0 a—h— c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-17 03:24 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-17 03:07 92,672 a——- c:\windows\system32\UIAnimation.dll
2009-11-17 03:07 1,164,800 a——- c:\windows\system32\UIRibbonRes.dll
2009-11-17 03:07 3,023,360 a——- c:\windows\system32\UIRibbon.dll
2009-11-17 03:06 369,664 a——- c:\windows\system32\WMPhoto.dll
2009-11-17 03:06 258,048 a——- c:\windows\system32\winspool.drv
2009-11-17 03:06 634,880 a——- c:\windows\system32\drivers\dxgkrnl.sys
2009-11-17 03:06 37,888 a——- c:\windows\system32\cdd.dll
2009-11-17 03:04 30,208 a——- c:\windows\system32\WPDShextAutoplay.exe
2009-11-17 03:01 4,096 a——- c:\windows\system32\oleaccrc.dll
2009-11-17 03:01 555,520 a——- c:\windows\system32\UIAutomationCore.dll
2009-11-17 03:01 234,496 a——- c:\windows\system32\oleacc.dll
2009-11-16 03:15 159,600 a——- c:\windows\system32\drivers\pctgntdi.sys
2009-11-16 03:14 206,256 a——- c:\windows\system32\drivers\PCTCore.sys
2009-11-16 03:14 86,888 a——- c:\windows\system32\drivers\PCTAppEvent.sys
2009-11-16 03:14 7,396 a——- c:\windows\system32\drivers\pctcore.cat
2009-11-16 03:14 –d—– c:\program files\common files\PC Tools
2009-11-16 03:13 64,392 a——- c:\windows\system32\drivers\pctplsg.sys
2009-11-16 03:11 –d—– c:\users\elenal~1\appdata\roaming\PC Tools
2009-11-16 03:11 –d—– c:\programdata\PC Tools
2009-11-16 03:11 –d—– c:\program files\Spyware Doctor
2009-11-16 03:11 –d—– c:\progra~2\PC Tools
2009-11-16 03:10 a-d—– c:\programdata\TEMP
2009-11-16 02:28 –d—– c:\programdata\17765430
2009-11-16 02:28 –d—– c:\progra~2\17765430
2009-11-11 23:21 2,036,736 a——- c:\windows\system32\win32k.sys
2009-11-11 23:18 355,328 a——- c:\windows\system32\WSDApi.dll
2009-11-06 22:53 –d—– c:\program files\iPod
2009-11-06 22:53 –d—– c:\program files\iTunes
2009-11-04 16:54 214,664 a——- c:\windows\system32\drivers\mfehidk.sys
2009-11-03 21:59 1,638,912 a——- c:\windows\system32\mshtml.tlb
2009-11-02 15:42 –d-h— c:\programdata\CanonBJ
2009-11-02 15:40 223,744 a——- c:\windows\system32\CNMLM97.DLL
2009-10-31 22:55 –d—– c:\program files\common files\PX Storage Engine
2009-10-31 22:50 –d—– c:\program files\DivX
2009-10-27 10:45 310,784 a——- c:\windows\system32\unregmp2.exe
2009-10-27 10:45 8,147,456 a——- c:\windows\system32\wmploc.DLL
2009-10-27 07:16 2,421,760 a——- c:\windows\system32\wucltux.dll
2009-10-27 07:15 87,552 a——- c:\windows\system32\wudriver.dll
2009-10-27 07:15 171,608 a——- c:\windows\system32\wuwebv.dll
2009-10-27 07:15 33,792 a——- c:\windows\system32\wuapp.exe
==================== Find3M ====================
2009-11-17 03:25 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-17 03:25 143,360 a——- c:\windows\inf\infstrng.dat
2009-11-17 03:25 86,016 a——- c:\windows\inf\infstor.dat
2009-11-17 03:25 51,200 a——- c:\windows\inf\infpub.dat
2009-11-02 20:42 195,456 ——– c:\windows\system32\MpSigStub.exe
2009-09-30 17:02 2,537,472 a——- c:\windows\system32\wpdshext.dll
2009-09-30 17:02 334,848 a——- c:\windows\system32\PortableDeviceApi.dll
2009-09-30 17:02 87,552 a——- c:\windows\system32\WPDShServiceObj.dll
2009-09-30 17:02 31,232 a——- c:\windows\system32\BthMtpContextHandler.dll
2009-09-30 17:01 546,816 a——- c:\windows\system32\wpd_ci.dll
2009-09-30 17:01 160,256 a——- c:\windows\system32\PortableDeviceTypes.dll
2009-09-30 17:01 350,208 a——- c:\windows\system32\WPDSp.dll
2009-09-30 17:01 196,608 a——- c:\windows\system32\PortableDeviceWMDRM.dll
2009-09-30 17:01 100,864 a——- c:\windows\system32\PortableDeviceClassExtension.dll
2009-09-30 17:01 60,928 a——- c:\windows\system32\PortableDeviceConnectApi.dll
2009-09-30 17:01 81,920 a——- c:\windows\system32\wpdbusenum.dll
2009-09-30 17:01 40,448 a——- c:\windows\system32\drivers\WpdUsb.sys
2009-09-30 17:01 226,816 a——- c:\windows\system32\WpdMtp.dll
2009-09-30 17:01 61,952 a——- c:\windows\system32\WpdMtpUS.dll
2009-09-30 17:01 33,280 a——- c:\windows\system32\WpdConns.dll
2009-09-24 18:10 974,848 a——- c:\windows\system32\WindowsCodecs.dll
2009-09-24 18:07 189,440 a——- c:\windows\system32\WindowsCodecsExt.dll
2009-09-24 18:04 321,024 a——- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-24 17:49 1,554,432 a——- c:\windows\system32\xpsservices.dll
2009-09-24 17:48 351,232 a——- c:\windows\system32\XpsPrint.dll
2009-09-24 17:38 847,360 a——- c:\windows\system32\OpcServices.dll
2009-09-24 17:36 280,064 a——- c:\windows\system32\XpsGdiConverter.dll
2009-09-24 17:35 135,680 a——- c:\windows\system32\XpsRasterService.dll
2009-09-24 17:33 195,584 a——- c:\windows\system32\dxdiagn.dll
2009-09-24 17:33 829,440 a——- c:\windows\system32\d3d10warp.dll
2009-09-24 17:32 252,928 a——- c:\windows\system32\dxdiag.exe
2009-09-24 17:31 519,680 a——- c:\windows\system32\d3d11.dll
2009-09-24 17:31 486,912 a——- c:\windows\system32\d3d10level9.dll
2009-09-24 17:31 161,280 a——- c:\windows\system32\d3d10_1.dll
2009-09-24 17:31 218,112 a——- c:\windows\system32\d3d10_1core.dll
2009-09-24 17:31 1,030,144 a——- c:\windows\system32\d3d10.dll
2009-09-24 17:31 828,928 a——- c:\windows\system32\d2d1.dll
2009-09-24 17:30 481,792 a——- c:\windows\system32\dxgi.dll
2009-09-24 17:30 190,464 a——- c:\windows\system32\d3d10core.dll
2009-09-24 17:27 1,064,448 a——- c:\windows\system32\DWrite.dll
2009-09-24 17:27 793,088 a——- c:\windows\system32\FntCache.dll
2009-09-24 14:54 667,648 a——- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 14:54 26,112 a——- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-10 08:48 218,624 a——- c:\windows\system32\msv1_0.dll
2009-09-04 15:56 56 a—h— c:\programdata\ezsidmv.dat
2009-09-04 15:56 56 a—h— c:\progra~2\ezsidmv.dat
2009-09-04 03:41 60,928 a——- c:\windows\system32\msasn1.dll
2009-08-28 18:42 2,065,696 a——- c:\windows\system32\usbaaplrc.dll
2009-08-28 18:30 173,056 a——- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 18:30 458,752 a——- c:\windows\apppatch\AcSpecfc.dll
2009-08-28 18:30 2,159,616 a——- c:\windows\apppatch\AcGenral.dll
2009-08-28 18:30 542,720 a——- c:\windows\apppatch\AcLayers.dll
2009-08-28 16:27 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-28 16:14 28,672 a——- c:\windows\system32\Apphlpdm.dll
2009-06-30 02:32 174 a–sh— c:\program files\desktop.ini
2007-08-22 09:23 342 a——- c:\users\elenal~1\appdata\roaming\wklnhst.dat
2006-11-02 04:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 04:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 04:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 04:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 01:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 01:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 01:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 01:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 16:13:00.70 ===============