This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected by Agent.Exe

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL Extras logfile created on: 3/7/2011 5:19:24 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Anti-Virus
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 44.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 3070 3070 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.86 Gb Total Space | 5.36 Gb Free Space | 5.96% Space Free | Partition Type: NTFS
Drive F: | 76.69 Gb Total Space | 5.55 Gb Free Space | 7.24% Space Free | Partition Type: NTFS
Drive H: | 931.28 Gb Total Space | 912.64 Gb Free Space | 98.00% Space Free | Partition Type: FAT32

Computer Name: MSTARNES-9200 | User Name: mstarnes | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"5900:TCP" = 5900:TCP:*:Enabled:VNC
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"4481:TCP" = 4481:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4481:UDP" = 4481:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
"4482:TCP" = 4482:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4482:UDP" = 4482:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
"9051:UDP" = 9051:UDP:LocalSubNet:Enabled:FiOS Tech Wizard
"50000:UDP" = 50000:UDP:*:Enabled:IHA_MessageCenter

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL
"C:\Program Files\Gensym\g2-8.1r1\g2\g2.exe" = C:\Program Files\Gensym\g2-8.1r1\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\g2-8.1r0\g2\g2.exe" = C:\Program Files\Gensym\g2-8.1r0\g2\g2.exe:*:Enabled:Gensym G2 – (Gensym Corporation)
"C:\jmace\g2.exe" = C:\jmace\g2.exe:*:Enabled:Gensym G2 – (Gensym Corporation)
"C:\Program Files\Gensym\g2-8.2r2\g2\g2.exe" = C:\Program Files\Gensym\g2-8.2r2\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\g2-8.2r2\jre\bin\java.exe" = C:\Program Files\Gensym\g2-8.2r2\jre\bin\java.exe:*:Enabled:java
"C:\MRSDEMO\Satellite\Satellite2\pingmgr.exe" = C:\MRSDEMO\Satellite\Satellite2\pingmgr.exe:*:Enabled:pingmgr
"C:\Program Files\Gensym\G2-8.2r0\g2\g2.exe" = C:\Program Files\Gensym\G2-8.2r0\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\rethink-5.0r1\g2\g2.exe" = C:\Program Files\Gensym\rethink-5.0r1\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\rethink-5.0r1\odbc\bin\g2-odbc.exe" = C:\Program Files\Gensym\rethink-5.0r1\odbc\bin\g2-odbc.exe:*:Enabled:Gensym G2-ODBC Bridge
"C:\Program Files\Gensym\g2-7.1r1\g2\g2.exe" = C:\Program Files\Gensym\g2-7.1r1\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\g2-8.3b0\g2\g2.exe" = C:\Program Files\Gensym\g2-8.3b0\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\g2-8.3b1\g2\g2.exe" = C:\Program Files\Gensym\g2-8.3b1\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\g2-8.3b1\nol\bin\ntnol.exe" = C:\Program Files\Gensym\g2-8.3b1\nol\bin\ntnol.exe:*:Enabled:ntnol
"E:\Program Files\Gensym\g2-6.2\g2\g2.exe" = E:\Program Files\Gensym\g2-6.2\g2\g2.exe:*:Enabled:g2
"E:\g2classic\G2-62r0\g2\g2.exe" = E:\g2classic\G2-62r0\g2\g2.exe:*:Enabled:g2
"E:\gensym\g2\G2.EXE" = E:\gensym\g2\G2.EXE:*:Enabled:G2
"C:\Program Files\Gensym\g2-8.2r4\g2\g2.exe" = C:\Program Files\Gensym\g2-8.2r4\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\g2-8.3r0\g2\g2.exe" = C:\Program Files\Gensym\g2-8.3r0\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\escor_rethink-4.0r4\g2\g2.exe" = C:\Program Files\Gensym\escor_rethink-4.0r4\g2\g2.exe:*:Enabled:g2
"C:\Program Files\Gensym\escor_rethink-4.0r4\jre\bin\javaw.exe" = C:\Program Files\Gensym\escor_rethink-4.0r4\jre\bin\javaw.exe:*:Enabled:javaw
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
"C:\C2\g2.exe" = C:\C2\g2.exe:*:Enabled:Gensym G2
"C:\WINDOWS\SYSTEM32\FTP.EXE" = C:\WINDOWS\SYSTEM32\FTP.EXE:*:Enabled:File Transfer Program – (Microsoft Corporation)
"C:\Program Files\ICQ6\ICQ.exe" = C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\Mozilla Thunderbird\thunderbird.exe" = C:\Program Files\Mozilla Thunderbird\thunderbird.exe:*:Enabled:Mozilla Thunderbird
"C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe" = C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe:*:Enabled:Live Mesh Remote Desktop – (Microsoft Corporation)
"C:\Documents and Settings\mstarnes\Local Settings\Application Data\Microsoft\Live Mesh\GacBase\Moe.exe" = C:\Documents and Settings\mstarnes\Local Settings\Application Data\Microsoft\Live Mesh\GacBase\Moe.exe:*:Enabled:Live Mesh – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\jmace\g2.exe" = C:\jmace\g2.exe:*:Enabled:Gensym G2 – (Gensym Corporation)
"C:\Program Files\Gensym\g2-8.1r0\g2\g2.exe" = C:\Program Files\Gensym\g2-8.1r0\g2\g2.exe:*:Enabled:Gensym G2 – (Gensym Corporation)
"C:\Program Files\Gensym\g2-8.1r1\g2\g2.exe" = C:\Program Files\Gensym\g2-8.1r1\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Ipswitch\WS_FTP Pro\wsftpgui.exe" = C:\Program Files\Ipswitch\WS_FTP Pro\wsftpgui.exe:*:Enabled:WS_FTP Pro Application – (Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421)
"C:\Program Files\NxView\Studio\Studio.exe" = C:\Program Files\NxView\Studio\Studio.exe:*:Enabled:OSCAR 3D Studio
"C:\Program Files\Schwab\SSPro\SSPro.exe" = C:\Program Files\Schwab\SSPro\SSPro.exe:*:Enabled:StreetSmart Pro®
"C:\Program Files\Gensym\g2-7.1r1\g2\g2.exe" = C:\Program Files\Gensym\g2-7.1r1\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\escor_rethink-4.0r4\g2\g2.exe" = C:\Program Files\Gensym\escor_rethink-4.0r4\g2\g2.exe:*:Enabled:g2
"C:\Program Files\Gensym\escor_rethink-4.0r4\jre\bin\javaw.exe" = C:\Program Files\Gensym\escor_rethink-4.0r4\jre\bin\javaw.exe:*:Enabled:javaw
"C:\Program Files\Gensym\rethink-5.0b0\g2\g2.exe" = C:\Program Files\Gensym\G2-8.2r0\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\G2-8.2r0\g2\g2.exe" = C:\Program Files\Gensym\G2-8.2r0\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\G2-8.2r0\odbc\bin\g2-odbc.exe" = C:\Program Files\Gensym\G2-8.2r0\odbc\bin\g2-odbc.exe:*:Enabled:Gensym G2-ODBC Bridge
"C:\Program Files\Gensym\g2-8.2r1\g2\g2.exe" = C:\Program Files\Gensym\g2-8.2r1\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\g2-8.1r1\odbc\bin\g2-odbc.exe" = C:\Program Files\Gensym\g2-8.1r1\odbc\bin\g2-odbc.exe:*:Enabled:Gensym G2-ODBC Bridge
"C:\Program Files\Gensym\g2-8.2r1\odbc\bin\g2-odbc.exe" = C:\Program Files\Gensym\g2-8.2r1\odbc\bin\g2-odbc.exe:*:Enabled:Gensym G2-ODBC Bridge
"C:\Program Files\Gensym\g2-8.2r2\g2\g2.exe" = C:\Program Files\Gensym\g2-8.2r2\g2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Gensym\g2-8.2r2\jre\bin\java.exe" = C:\Program Files\Gensym\g2-8.2r2\jre\bin\java.exe:*:Enabled:java
"C:\MRSDEMO\Satellite\Satellite2\pingmgr.exe" = C:\MRSDEMO\Satellite\Satellite2\pingmgr.exe:*:Enabled:pingmgr
"C:\Program Files\Gensym\g2-8.3b0\g2\g2.exe" = C:\Program Files\Gensym\g2-8.3b0\g2\g2.exe:*:Enabled:Gensym G2
"E:\gensym\g2\G2.EXE" = E:\gensym\g2\G2.EXE:*:Enabled:G2
"C:\Program Files\Gensym\g2-8.3b1\g2\g2.exe" = C:\Program Files\Gensym\g2-8.3b1\g2\g2.exe:*:Enabled:Gensym G2
"E:\gensym\Integrity32r0\g2\g2.exe" = E:\gensym\Integrity32r0\g2\g2.exe:*:Enabled:g2
"E:\g2classic\g2\g2.exe" = E:\g2classic\g2\g2.exe:*:Enabled:g2
"E:\g2classic\G2-62r0\g2\g2.exe" = E:\g2classic\G2-62r0\g2\g2.exe:*:Enabled:g2
"C:\Program Files\Gensym\g2-8.3b1\nol\bin\ntnol.exe" = C:\Program Files\Gensym\g2-8.3b1\nol\bin\ntnol.exe:*:Enabled:ntnol
"C:\Program Files\Gensym\g2-8.3r0\g2\g2.exe" = C:\Program Files\Gensym\g2-8.3r0\g2\g2.exe:*:Enabled:Gensym G2
"C:\C2\g2.exe" = C:\C2\g2.exe:*:Enabled:Gensym G2
"C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe" = C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe:*:Enabled:Live Mesh Remote Desktop – (Microsoft Corporation)
"C:\Documents and Settings\mstarnes\Local Settings\Application Data\Microsoft\Live Mesh\GacBase\Moe.exe" = C:\Documents and Settings\mstarnes\Local Settings\Application Data\Microsoft\Live Mesh\GacBase\Moe.exe:*:Enabled:Live Mesh – (Microsoft Corporation)
"C:\Program Files\Intuit\QuickBooks 2010\QBDBMgrN.exe" = C:\Program Files\Intuit\QuickBooks 2010\QBDBMgrN.exe:*:Enabled:QuickBooks 2010 Data Manager – (Intuit, Inc.)
"D:\WD Discovery Software\WD Discovery.exe" = D:\WD Discovery Software\WD Discovery.exe:*:Enabled:WD Discovery Application
"C:\Program Files\PDF Convertor\bin\PDFPlus.exe" = C:\Program Files\PDF Convertor\bin\PDFPlus.exe:*:Enabled:PDF Converter Professional – (Nuance Communications, Inc.)
"C:\Program Files\PDF Convertor\PDFRouter.exe" = C:\Program Files\PDF Convertor\PDFRouter.exe:*:Enabled:PDF Converter Assistant – (Nuance Communications, Inc.)
"C:\Program Files\PDF Convertor\bin\PDFDirect.exe" = C:\Program Files\PDF Convertor\bin\PDFDirect.exe:*:Enabled:PDF Create! Assistant – (Zeon International Investment Corp. )
"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe" = C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software – (Research In Motion)
"C:\Program Files\Verizon\VSP\ServicepointService.exe" = C:\Program Files\Verizon\VSP\ServicepointService.exe:*:Enabled:Servicepoint Service – (Radialpoint Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{045E9660-BBF8-445C-9D54-4F677C054F23}" = Gensym ReThink Online 4.0r4
"{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
"{06A9E630-DBA6-4D92-9DE7-A235AA6496C7}" = QuickBooks
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{0700E22B-A422-40A5-BD20-04BF618CA0F9}" = QuickBooks Pro 2010
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0E1847A1-52F5-49D2-A78F-C830D4F2ACC1}" = VectorVest Online
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{0F052922-4BCE-4763-A540-00857554336D}" = Redist
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{17B66E83-1BC9-11D5-A54A-0090278A1BB8}" = Microsoft FrontPage Client - English
"{17D47941-887F-48E1-86EB-7EFF3E5A9224}" = Gensym G2 Development 8.1r0
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{1A772F15-B3FE-381A-BD29-82A78096B720}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4418
"{1B16E687-98F4-478C-BB0F-D775EB0D1A46}" = Gensym G2 Development 8.2r1
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD
"{23C12370-3A82-4558-B727-F345B473AD87}" = BlackBerry Device Software Updater
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{2515BF88-E42E-4AFA-A8E7-DF272762589B}" = Microsoft Office Live Meeting 2007
"{25B052BB-7126-4412-99D9-3D9448235FE4}" = WeatherBug
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 20
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2A2EDF5F-F3C6-4919-AE34-C08A71AD034A}" = Wireless-G Notebook Adapter
"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer
"{30CCA81B-4951-4751-986D-14388D9F4FFC}" = Wireless-G Notebook Adapter with SRX400
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{34C8AA92-6E3B-3890-8312-6156FE95F9BF}" = Microsoft Visual C++ 2010 RC x86 Runtime - 10.0.30128
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3973967D-6C2A-4703-A287-BE1A50AB5A02}" = Gensym G2 Development 8.3r1
"{3E5CBADD-2E51-47C1-BBE2-B802DB6DA56A}" = Interbank FX Trader 4.00
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{44E9E746-AD21-4D0B-BAB6-F0D80E0F0E6F}" = DirListBox
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{46E1B1F2-A279-4356-9B17-029F9CC72EAE}" = Brother MFL-Pro Suite
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{4BEED434-8D57-11D4-A3B6-008048EE5CCD}" = TurboProject v.4
"{4CF8CA08-876C-4375-957A-48BB2D78BA5A}_is1" = Classic Menu 3.x for PowerPoint 2007
"{4DB7E66B-B4E4-475E-BF8B-BF7B55E6A802}" = Gensym G2 ReThink Online 5.0r1
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{536F7C74-844B-4683-B0C5-EA39E19A6FE3}" = Microsoft AntiSpyware
"{53DF5B5A-9B29-474A-A738-868FD1CAC1D3}" = Enterprise Architect 8 LITE Edition
"{5624C000-B109-11D4-9DB4-00E0290FCAC5}" = VPN Client
"{580E9BBC-A51E-4AE9-A977-7B0939BEDAD3}" = Scanner Utility for Microsoft Windows
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5DF3D1BB-894E-4DCD-8275-159AC9829B43}" = McAfee VirusScan Enterprise
"{60600409-EA9B-45E9-A468-2C68C8DE70DF}" = Visual Studio .NET Enterprise Developer 2003 - English
"{6444D9D9-CD6C-4464-B970-55C606C944DC}" = Logitech QuickCam
"{64658686-0CD4-4CF6-983D-0A6BE32007DB}" = Business Complete Care Services Agreement
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{67545F8B-1C2A-4D7D-BFFB-F7EF063DCD10}" = Gensym G2 Development 8.2r2
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.1
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{6916E491-8BBF-4E8A-AFAD-D01307C059E5}" = Vz In Home Agent
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6DE14BE4-6F04-4935-8ABD-A0A19FE2E55A}" = mCore
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{6FFFE74E-3FBD-4E2E-97F9-5E9A2A077626}" = mIWCA
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{742BD5EC-F73E-444D-A006-1F8ECB7CE75E}" = PowerPoint Add-in for PPT To Video Scout
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{7A8FF745-BBC5-482B-88E4-18D3178249A9}" = ScanSoft PaperPort 11
"{80813829-BE27-4799-8BC7-2F75A7B6CB50}" = IHA_MessageCenter
"{808FAA20-4C3A-11D4-8A57-00201853C903}" = PC-Linq
"{83073C45-3003-4671-9A86-243AAADD915A}" = Microsoft Calculator Plus
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84A78614-0E4B-4A4E-BA8C-2B0A05A08E4E}" = BlackBerry Desktop Software 6.0.1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C0B406B-DF08-49EF-8702-FA45752C135F}" = Verizon Download Manager
"{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
"{8D6AE289-7A5E-41B4-A7F0-687C2DAB1B87}" = Microsoft Location Finder
"{8E560E1F-1DAE-40D5-B658-313779E8945A}" = WebEx One-Click
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}_VISPROR_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{91120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
"{91120000-0051-0000-0000-0000000FF1CE}_VISPROR_{0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{91120000-0051-0000-0000-0000000FF1CE}_VISPROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9176251A-4CC1-4DDB-B343-B487195EB397}" = Windows Live Writer
"{92A70E71-4F0E-4C05-A777-16424E89F162}" = Garmin Communicator Plugin with myGarmin Agent
"{93F4944A-2607-4B88-A977-44EF51B0CFF9}" = Gensym G2 Development 8.3b0
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9D76A758-E820-4223-B011-9472A0A5EE2B}" = Gensym G2 Development 8.3b1
"{9E712CF9-4BA1-47EB-8C85-408F0B8BD3ED}" = VectorVest Online
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A58BF6FF-20F6-41B9-BC4A-63B6F942C98D}" = Gensym G2 Development 7.1r1
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.2
"{AD88355B-A4E0-4DA1-BAC3-EA4FEA930691}" = Ipswitch WS_FTP Professional 2006
"{AF06CAE4-C134-44B1-B699-14FBDB63BD37}" = Dell Picture Studio v3.0
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B793C461-063E-4F69-872F-8F443EEF7314}" = Screencaster Plug-in for IE
"{B8742BE5-6238-3EC0-A9B9-CD562E054A54}" = Microsoft .NET Framework 4 Client Profile
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C427735F-EAEF-48A1-9628-67F05C4DE831}" = Barracuda Networks Outlook Plug-in
"{C7793EE8-F666-4E6B-9827-76468679480E}" = Tweakui Powertoy for Windows XP
"{CA9BAADB-C262-4E05-B2E2-CEE8CE9809EC}" = mToolkit
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC7464F1-BE7D-49FD-88B8-49C0AA894233}" = Diskeeper Professional Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D4D24FE5-FAB3-4FE2-AFFC-623955F4DF3A}" = Visual Studio.NET Baseline - English
"{D5A145FC-D00C-4F1A-9119-EB4D9D659750}" = Windows Live Toolbar
"{DB696946-2D97-44C2-B5F5-7971488FCAB4}" = Gensym G2 Development 8.3r0
"{DCB4E1D9-B187-4B54-971E-1478485C9A53}" = Live Mesh
"{E0AD8FC1-1860-33CA-9CFE-5962B91DDDEB}" = Microsoft .NET Framework 4 Extended
"{E1417885-CF39-4385-8C10-3E843E35C1EC}" = Gensym G2 Development 8.1r1
"{E6DE9A54-8514-446E-9D11-530DC599C355}" = Microsoft SharedView
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0853DDA-11AA-47D5-ABE4-3342FF2EA2F8}" = Gensym G2-8.2r0
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F261C693-3514-11D9-BF03-000AF5000CE8}" = Wireless-G Notebook Adapter with SRX Utility
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{F7F0DECF-E464-43BF-8DA5-3028564A4588}" = Nuance PDF Professional 6
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FCC3A967-D7C7-4DD1-BC53-39F61AFCEFE5}" = Gensym G2 Development 8.2r4
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"ActiveTouchMeetingClient" = WebEx
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"ATI Display Driver" = ATI Display Driver
"AVS Audio Editor_is1" = AVS Audio Editor version 6.1
"AVS Image Converter_is1" = AVS Image Converter [removed]
"AVS Photo Editor_is1" = AVS Photo Editor
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS Video Editor 4_is1" = AVS Video Editor 4
"AVS Video Recorder_is1" = AVS Video Recorder 2.4
"AVS YouTube Uploader 2.1_is1" = AVS YouTube Uploader version 2.1
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.0.1
"Bluetooth User Guide" = Bluetooth User Guide
"Bytescout Lossless Video Codec_is1" = Bytescout Lossless Video Codec 1.00.187 (FREEWARE)
"Bytescout PPT To Video Scout_is1" = Bytescout PPT To Video Scout
"BytescoutLosslessCodec" = Bytescout Lossless Codec
"CDex" = CDex - Open Source Digital Audio CD Extractor
"CNXT_MODEM_PCI_VEN_8086&DEV;_24x6&SUBSYS;_542214F1" = Conexant D110 MDC V.92 Modem
"Free Download Manager_is1" = Free Download Manager 3.0
"getPlus®_ocx" = getPlus®_ocx
"Google Desktop" = Google Desktop
"Google Updater" = Google Updater
"Hardwood Solitaire III" = Hardwood Solitaire III
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
"IrfanView" = IrfanView (remove only)
"lvdrivers_11.70" = Logitech QuickCam Driver Package
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Microsoft Visual Studio 2005 Tools for Office Runtime
"Mirage Driver_is1" = Mirage Driver 1.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSGOLF30" = Microsoft Golf 3.0
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"ProInst" = Intel® PROSet/Wireless Software
"PuTTY_is1" = PuTTY version 0.60
"RadialpointClientGateway_is1" = Verizon Servicepoint 3.5.18
"RealPlayer 6.0" = RealPlayer Basic
"RealVNC_is1" = VNC Free Edition 4.1.2
"SkyCaddieDesktop" = SkyCaddie Desktop
"SLABCOMM" = CP2101 USB to UART Bridge Controller
"Software Informer_is1" = Software Informer 1.0 BETA
"Software Operation Panel" = Software Operation Panel
"TPI 3D Viewer" = TPI 3D Viewer
"Tweak UI 2.10" = Tweak UI
"Verizon Help and Support" = Verizon Help and Support Tool
"Verizon Media Manager" = Verizon Media Manager
"VISPROR" = Microsoft Office Visio Professional 2007
"Visual Studio .NET Enterprise Developer 2003 - English" = Microsoft Visual Studio .NET Enterprise Developer 2003 - English
"VLC media player" = VLC media player 1.1.4
"WeatherBug" = WeatherBug
"WGA" = Windows Genuine Advantage Validation Tool
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yugma" = Yugma

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Adobe Connect Add-in" = Adobe Connect Add-in
"EPP Installer" = EPP Installer
"GoToMeeting" = GoToMeeting 4.5.0.457
"Move Media Player" = Move Media Player
"WinDirStat" = WinDirStat 1.1.2

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/7/2011 3:37:36 PM | Computer Name = MSTARNES-9200 | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : The
DAT file versions do not match each other.

Error - 3/7/2011 3:56:49 PM | Computer Name = MSTARNES-9200 | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 3/7/2011 3:56:49 PM | Computer Name = MSTARNES-9200 | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 3/7/2011 3:56:49 PM | Computer Name = MSTARNES-9200 | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 3/7/2011 4:00:13 PM | Computer Name = MSTARNES-9200 | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks Pro 2010": Error: CreateWindow
failed. Trying to create a non-modal window of class: MauiFor

Error - 3/7/2011 4:00:13 PM | Computer Name = MSTARNES-9200 | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks Pro 2010": QuickBooks
has experienced a problem and must be shut dow

Error - 3/7/2011 4:34:44 PM | Computer Name = MSTARNES-9200 | Source = Application Hang | ID = 1002
Description = Hanging application SpybotSD.exe, version 1.6.2.46, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 3/7/2011 4:37:59 PM | Computer Name = MSTARNES-9200 | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : The
DAT file versions do not match each other.

Error - 3/7/2011 5:39:30 PM | Computer Name = MSTARNES-9200 | Source = McLogEvent | ID = 5022
Description = MCSCAN32 Engine Initialisation failed. Engine returned error : The
DAT file versions do not match each other.

Error - 3/7/2011 6:22:14 PM | Computer Name = MSTARNES-9200 | Source = Alert Manager Event Interface | ID = 257
Description = VirusScan Enterprise: The update failed; see event log.(from MSTARNES-9200
IP 192.168.1.104 user SYSTEM running VirusScan Ent. 8.0.0 UPD)

[ OSession Events ]
Error - 10/5/2007 9:19:45 AM | Computer Name = MSTARNES-9200 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1982374
seconds with 25920 seconds of active time. This session ended with a crash.

Error - 10/18/2007 9:21:44 AM | Computer Name = MSTARNES-9200 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 204
seconds with 120 seconds of active time. This session ended with a crash.

Error - 10/18/2007 11:38:58 AM | Computer Name = MSTARNES-9200 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 8223
seconds with 0 seconds of active time. This session ended with a crash.

Error - 12/17/2007 5:47:26 PM | Computer Name = MSTARNES-9200 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 25483
seconds with 10620 seconds of active time. This session ended with a crash.

Error - 1/28/2008 12:25:26 PM | Computer Name = MSTARNES-9200 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 868324
seconds with 26040 seconds of active time. This session ended with a crash.

Error - 6/11/2008 5:35:19 PM | Computer Name = MSTARNES-9200 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 3315
seconds with 2820 seconds of active time. This session ended with a crash.

Error - 6/11/2008 5:50:21 PM | Computer Name = MSTARNES-9200 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 893
seconds with 660 seconds of active time. This session ended with a crash.

Error - 7/21/2008 5:02:22 PM | Computer Name = MSTARNES-9200 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 21253
seconds with 1800 seconds of active time. This session ended with a crash.

Error - 4/23/2010 12:01:07 PM | Computer Name = MSTARNES-9200 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6524.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 779222
seconds with 15660 seconds of active time. This session ended with a crash.

Error - 5/17/2010 11:54:48 AM | Computer Name = MSTARNES-9200 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6524.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 5096
seconds with 3600 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 3/7/2011 4:19:49 PM | Computer Name = MSTARNES-9200 | Source = DCOM | ID = 10010
Description = The server {98D9A6F1-4696-4B5E-A2E8-36B3F9C1E12C} did not register
with DCOM within the required timeout.

Error - 3/7/2011 4:20:20 PM | Computer Name = MSTARNES-9200 | Source = DCOM | ID = 10010
Description = The server {98D9A6F1-4696-4B5E-A2E8-36B3F9C1E12C} did not register
with DCOM within the required timeout.

Error - 3/7/2011 4:20:50 PM | Computer Name = MSTARNES-9200 | Source = DCOM | ID = 10010
Description = The server {98D9A6F1-4696-4B5E-A2E8-36B3F9C1E12C} did not register
with DCOM within the required timeout.

Error - 3/7/2011 4:25:26 PM | Computer Name = MSTARNES-9200 | Source = DCOM | ID = 10010
Description = The server {98D9A6F1-4696-4B5E-A2E8-36B3F9C1E12C} did not register
with DCOM within the required timeout.

Error - 3/7/2011 4:36:13 PM | Computer Name = MSTARNES-9200 | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain GENSYM due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.

Error - 3/7/2011 4:37:59 PM | Computer Name = MSTARNES-9200 | Source = Service Control Manager | ID = 7024
Description = The Network Associates McShield service terminated with service-specific
error 5022 (0x139E).

Error - 3/7/2011 5:03:06 PM | Computer Name = MSTARNES-9200 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.

Error - 3/7/2011 5:39:30 PM | Computer Name = MSTARNES-9200 | Source = Service Control Manager | ID = 7024
Description = The Network Associates McShield service terminated with service-specific
error 5022 (0x139E).

Error - 3/7/2011 6:21:17 PM | Computer Name = MSTARNES-9200 | Source = Service Control Manager | ID = 7024
Description = The IIS Admin service terminated with service-specific error 2148073487
(0x8009000F).

Error - 3/7/2011 6:21:47 PM | Computer Name = MSTARNES-9200 | Source = DCOM | ID = 10010
Description = The server {A9E69610-B80D-11D0-B9B9-00A0C922E750} did not register
with DCOM within the required timeout.


< End of report >

OTL logfile created on: 3/7/2011 5:19:24 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Anti-Virus
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 44.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 3070 3070 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.86 Gb Total Space | 5.36 Gb Free Space | 5.96% Space Free | Partition Type: NTFS
Drive F: | 76.69 Gb Total Space | 5.55 Gb Free Space | 7.24% Space Free | Partition Type: NTFS
Drive H: | 931.28 Gb Total Space | 912.64 Gb Free Space | 98.00% Space Free | Partition Type: FAT32

Computer Name: MSTARNES-9200 | User Name: mstarnes | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Anti-Virus\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe ()
PRC - C:\Program Files\VERIZONDM\bin\tgsrvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\VERIZONDM\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\VERIZONDM\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
PRC - C:\Program Files\Verizon\VSP\ServicepointService.exe (Radialpoint Inc.)
PRC - C:\Program Files\Garmin\MyGarminAgent\myGarminAgent.exe ()
PRC - C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe (Skype Technologies S.A.)
PRC - C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\mstarnes\Local Settings\Application Data\Microsoft\Live Mesh\GacBase\Moe.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\mstarnes\Local Settings\Application Data\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe (Microsoft Corporation)
PRC - C:\Program Files\Intuit\QuickBooks 2010\QBDBMgr.exe (Intuit, Inc.)
PRC - C:\Program Files\PDF Convertor\PdfPro6Hook.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\PDF Convertor\PDFProFiltSrv.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (Macrovision Corporation)
PRC - C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
PRC - C:\Program Files\RealVNC\VNC4\winvnc4.exe (RealVNC Ltd.)
PRC - C:\Program Files\Cisco-Linksys LLC\Wireless-G Notebook Adapter with SRX400\WPC54GX4.exe (The Linksys Group, Inc.)
PRC - C:\Program Files\Microsoft Location Finder\LocationFinder.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\TWAIN_32\Fjscan32\SOP\FtLnSOP.exe (PFU LIMITED)
PRC - C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe (Microsoft Corporation)
PRC - C:\Program Files\Executive Software\Diskeeper\DkService.exe (Executive Software International, Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\WINDOWS\TWAIN_32\Fjscan32\FjtwSetup.exe (FUJITSU LIMITED)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Network Associates\VirusScan\shstat.exe (Network Associates, Inc.)
PRC - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe (Network Associates, Inc.)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
PRC - C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe (Network Associates, Inc.)
PRC - C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe (Network Associates, Inc.)
PRC - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (Network Associates, Inc.)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe (Network Associates, Inc.)
PRC - C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54CFG.EXE (The Linksys Group, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Anti-Virus\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\Motive\McciContextHook_DSR.dll (Alcatel-Lucent)
MOD - C:\WINDOWS\Temp\logishrd\LVPrcInj02.dll (Logitech Inc.)


========== Win32 Services (SafeList) ==========

SRV - (RoxLiveShare9) – File not found
SRV - (ODBC22043) – File not found
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (IHA_MessageCenter) – C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe ()
SRV - (tgsrvc_verizondm) SupportSoft Repair Service (verizondm) – C:\Program Files\VERIZONDM\bin\tgsrvc.exe (SupportSoft, Inc.)
SRV - (sprtsvc_verizondm) SupportSoft Sprocket Service (verizondm) – C:\Program Files\VERIZONDM\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (ServicepointService) – C:\Program Files\Verizon\VSP\ServicepointService.exe (Radialpoint Inc.)
SRV - (wlcrasvc) – C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe (Microsoft Corporation)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (PDFProFiltSrv) – C:\Program Files\PDF Convertor\PDFProFiltSrv.exe (Nuance Communications, Inc.)
SRV - (W3SVC) – C:\WINDOWS\SYSTEM32\INETSRV\inetinfo.exe (Microsoft Corporation)
SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) – C:\WINDOWS\SYSTEM32\INETSRV\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINDOWS\SYSTEM32\INETSRV\inetinfo.exe (Microsoft Corporation)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (WinVNC4) – C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)
SRV - (Diskeeper) – C:\Program Files\Executive Software\Diskeeper\DkService.exe (Executive Software International, Inc.)
SRV - (WLANKEEPER) – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (McShield) – C:\Program Files\Network Associates\VirusScan\Mcshield.exe (Network Associates, Inc.)
SRV - (McTaskManager) – C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe (Network Associates, Inc.)
SRV - (McAfeeFramework) – C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (Network Associates, Inc.)
SRV - (CVPND) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (RDPVDD) – C:\WINDOWS\SYSTEM32\DRIVERS\rdpvmp.sys (Microsoft Corporation)
DRV - (RDPDISPM) – C:\WINDOWS\SYSTEM32\DRIVERS\rdpdispm.sys (Microsoft Corporation)
DRV - (qrkis) – C:\WINDOWS\SYSTEM32\DRIVERS\qrkis.sys (Tether)
DRV - (FilterService) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech QuickCam S5500(UVC) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\SYSTEM32\DRIVERS\LVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\SYSTEM32\DRIVERS\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVcKap) – C:\WINDOWS\SYSTEM32\DRIVERS\Lvckap.sys (Logitech Inc.)
DRV - (WNIPROT5) – C:\WINDOWS\SYSTEM32\WNIPROT5.SYS (Airgo Networks, Inc.)
DRV - (dfmirage) – C:\WINDOWS\SYSTEM32\DRIVERS\dfmirage.sys (DemoForge, LLC)
DRV - (Airgo3P) – C:\WINDOWS\SYSTEM32\DRIVERS\Lssrx42.sys (Airgo Networks, Inc.)
DRV - (HSF_DPV) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (HSFHWICH) – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (vsdatant) – C:\WINDOWS\SYSTEM32\vsdatant.sys (Zone Labs Inc.)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (Airgo) – C:\WINDOWS\SYSTEM32\DRIVERS\wnihdd51.sys (Airgo Networks, Inc.)
DRV - (w29n51) Intel® – C:\WINDOWS\SYSTEM32\DRIVERS\w29n51.sys (Intel® Corporation)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (s24trans) – C:\WINDOWS\SYSTEM32\DRIVERS\s24trans.sys (Intel Corporation)
DRV - (NaiAvFilter1) – C:\WINDOWS\SYSTEM32\DRIVERS\naiavf5x.sys (Network Associates, Inc.)
DRV - (NaiAvTdi1) – C:\WINDOWS\SYSTEM32\DRIVERS\mvstdi5x.sys (Network Associates, Inc.)
DRV - (EntDrv51) – C:\WINDOWS\SYSTEM32\DRIVERS\EntDrv51.sys (Network Associates, Inc)
DRV - (STAC97) – C:\WINDOWS\SYSTEM32\DRIVERS\STAC97.sys (SigmaTel, Inc.)
DRV - (IWCA) – C:\WINDOWS\SYSTEM32\DRIVERS\iwca.sys (Intel Corporation)
DRV - (ApfiltrService) – C:\WINDOWS\SYSTEM32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (CVPNDRVA) – C:\WINDOWS\SYSTEM32\DRIVERS\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (slabbus) CP2101 USB Composite Device driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\slabbus.sys (MCCI)
DRV - (slabser) – C:\WINDOWS\SYSTEM32\DRIVERS\slabser.sys (MCCI)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Inc)
DRV - (bcm4sbxp) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (DNE) – C:\WINDOWS\SYSTEM32\DRIVERS\dne2000.sys (Deterministic Networks, Inc.)
DRV - (CVirtA) – C:\WINDOWS\SYSTEM32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)
DRV - (bt3cusb) – C:\WINDOWS\SYSTEM32\DRIVERS\bt3cusb.sys (3Com Corporation)
DRV - (BT3CSer) – C:\WINDOWS\SYSTEM32\DRIVERS\BT3CSer.sys (3Com Corporation)
DRV - (Wdm1) – C:\WINDOWS\SYSTEM32\DRIVERS\usbbc.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://netmg.dyndns.org:18180/gt/frame/index.html"
FF - prefs.js..extensions.enabledItems: [removed]:1.0


[2009/03/16 15:45:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\mstarnes\Application Data\Mozilla\Extensions
[2010/02/21 12:36:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\mstarnes\Application Data\Mozilla\Firefox\Profiles\luziu9jh.default\extensions
[2009/05/11 14:06:08 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

O1 HOSTS File: ([2005/06/08 10:44:49 | 000,000,770 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 1.0.2.86 hqmail hqmail.gensym.com
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\PDF Convertor\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (ZeonIEEventHelper Class) - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\PDF Convertor\bin\ZeonIEFavClient.dll (Zeon Corporation)
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Nuance PDF) - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\PDF Convertor\bin\ZeonIEFavClient.dll (Zeon Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DiskeeperSystray] C:\Program Files\Executive Software\Diskeeper\DkIcon.exe (Executive Software International, Inc.)
O4 - HKLM..\Run: [FJTWAIN Setup] C:\WINDOWS\Twain_32\fjscan32\FjtwSetup.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [FtLnSOP_setup] C:\WINDOWS\TWAIN_32\Fjscan32\SOP\FtLnSOP.exe (PFU LIMITED)
O4 - HKLM..\Run: [gcasServ] C:\Program Files\Microsoft AntiSpyware\gcasServ.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe (Network Associates, Inc.)
O4 - HKLM..\Run: [MyGarminAgent] C:\Program Files\Garmin\MyGarminAgent\myGarminAgent.exe ()
O4 - HKLM..\Run: [Network Associates Error Reporting Service] C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe (Network Associates, Inc.)
O4 - HKLM..\Run: [Nuance PDF Professional 6-reminder] C:\Program Files\PDF Convertor\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDF6 Registry Controller] C:\Program Files\PDF Convertor\RegistryController.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\PDF Convertor\PdfPro6Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [RunUtility] C:\Program Files\Cisco-Linksys LLC\Wireless-G Notebook Adapter with SRX400\WPC54GX4.exe (The Linksys Group, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE (Network Associates, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [VERIZONDM] C:\Program Files\VERIZONDM\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\VSP\VerizonServicepoint.exe (Verizon)
O4 - HKCU..\Run: [fsm] File not found
O4 - HKCU..\Run: [Microsoft Location Finder] C:\Program Files\Microsoft Location Finder\LocationFinder.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MoeMonitor.exe] C:\Documents and Settings\mstarnes\Local Settings\Application Data\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe (Cisco Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless-G Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54CFG.EXE (The Linksys Group, Inc.)
O4 - Startup: C:\Documents and Settings\mstarnes\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Windows; Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Append the content of the link to existing PDF file - C:\Program Files\PDF Convertor\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append the content of the selected links to existing PDF file - C:\Program Files\PDF Convertor\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append to existing PDF file - C:\Program Files\PDF Convertor\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file - C:\Program Files\PDF Convertor\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file from the content of the link - C:\Program Files\PDF Convertor\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF files from the selected links - C:\Program Files\PDF Convertor\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Open with Nuance PDF Converter 6.0 - C:\Program Files\PDF Convertor\cnvres_eng.dll ()
O8 - Extra context menu item: Open with PDF Professional 6 - C:\Program Files\PDF Convertor\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O15 - HKCU\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: vectorvest.com ([www] * in Trusted sites)
O15 - HKCU\..Trusted Domains: vectorvest.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: vectorvest.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} https://www-1.ibm.com/qp2.cab (QuickPlace Class)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://www.ipix.com/viewers/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc2.cab (Office Update Installation Engine)
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} http://www.vectorvest.com/vvonline/us/install/setup.exe (InstallShield Setup Player 2K2)
O16 - DPF: {843EE768-3A97-455C-9076-741BA3AD7B62} https://qbo.intuit.com/c27/v32.131/qboax10.cab (QuickBooks Online Edition Utilities Class v10)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8D3314D6-5914-46C1-9F3D-9F14B6A305F1} http://www.mytpi.com/mytpi05/eval/ectuploader.cab (eCTUploader Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://66.255.127.85/AxisCamControl.ocx (CamImage Class)
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} http://www.sha.state.md.us/viewer/activeXV…tivexviewer.cab (Crystal Report Viewer Control)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D1278801-B2C0-4332-BD3E-2F64D2204EDF} https://www.mesh.com/0.9.4014.13/TSWeb.cab (Windows Live Mesh Upload Tool)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://gensym.webex.com/client/v_mywebex-t…bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = gensym.com
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\IntelWireless: DllName - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O20 - Winlogon\Notify\wlcrdplauncher: DllName - C:\Program Files\Live Mesh\Remote Desktop\wlcrdplauncher.dll - C:\Program Files\Live Mesh\Remote Desktop\wlcrdplauncher.dll (Microsoft Corporation)
O21 - SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - CLSID or File not found.
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/01/20 00:14:00 | 000,000,030 | —- | M] () - H:\autorun.inf – [ FAT32 ]
O33 - MountPoints2\{218129e0-7573-11db-b722-00114369cd7c}\Shell\AutoRun\command - "" = E:\PTStart.exe index.html
O33 - MountPoints2\{f6b67d8f-a546-11df-b899-00114369cd7c}\Shell - "" = AutoRun
O33 - MountPoints2\{f6b67d8f-a546-11df-b899-00114369cd7c}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{f6b67d8f-a546-11df-b899-00114369cd7c}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL http://www.garmin.com/agent
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.BLVC - C:\WINDOWS\System32\BytescoutLosslessCodec.dll (Bytescout)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\IR41_32.DLL (Intel® Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (74323004602974208)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/07 17:17:17 | 000,000,000 | —D | C] – C:\Anti-Virus
[2011/03/07 15:14:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/03/07 10:17:15 | 000,000,000 | —D | C] – C:\Delta Zeta
[2011/03/03 08:40:16 | 000,000,000 | —D | C] – C:\stupid
[2011/02/17 08:48:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Verizon Media Manager
[2011/02/15 17:52:14 | 000,000,000 | —D | C] – C:\Documents and Settings\mstarnes\Application Data\Verizon
[2011/02/15 17:52:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Radialpoint
[2011/02/15 17:52:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Verizon Servicepoint
[2011/02/15 17:52:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Verizon
[2011/02/15 17:43:10 | 000,000,000 | —D | C] – C:\Documents and Settings\mstarnes\Local Settings\Application Data\SupportSoft
[2011/02/15 17:42:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2011/02/15 17:42:39 | 000,000,000 | —D | C] – C:\Program Files\VERIZONDM
[2011/02/15 17:42:11 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SupportSoft
[2011/02/15 14:46:48 | 000,000,000 | —D | C] – C:\Documents and Settings\mstarnes\Local Settings\Application Data\Research In Motion
[2011/02/15 12:02:16 | 000,000,000 | —D | C] – C:\Documents and Settings\mstarnes\Application Data\Motive
[2011/02/15 12:00:19 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Motive
[2011/02/15 12:00:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Motive
[2011/02/15 11:56:57 | 000,000,000 | —D | C] – C:\Program Files\Verizon
[2011/02/15 11:53:40 | 000,000,000 | —D | C] – C:\Documents and Settings\mstarnes\Application Data\TechWizard
[2009/05/15 09:18:49 | 001,719,336 | —- | C] (Yugma,Inc. ) – C:\Documents and Settings\All Users\Application Data\YugmaSE-Uninstaller.exe
[2007/10/30 10:50:31 | 005,809,216 | —- | C] (Hypnotizer) – C:\Program Files\hyplay.exe
[2006/08/18 10:34:25 | 000,212,992 | —- | C] ( ) – C:\WINDOWS\System32\Interop.ComctlLib.dll
[2006/08/18 10:34:25 | 000,114,688 | —- | C] ( ) – C:\WINDOWS\System32\AxInterop.ComctlLib.dll
[1980/01/01 01:00:00 | 000,163,840 | —- | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\mstarnes\*.tmp files -> C:\Documents and Settings\mstarnes\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/07 17:21:51 | 000,000,512 | —- | M] () – C:\WINDOWS\randseed.rnd
[2011/03/07 17:03:00 | 000,000,260 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2011/03/07 16:35:04 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/07 15:14:26 | 000,000,933 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\Spybot - Search & Destroy.lnk
[2011/03/07 15:01:45 | 000,002,453 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\HiJackThis.lnk
[2011/03/07 14:14:13 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/03/07 11:52:54 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2011/03/07 11:52:52 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[2011/03/07 11:41:48 | 000,001,037 | —- | M] () – C:\Documents and Settings\mstarnes\Local Settings\Application Data\Account.atomsvc
[2011/03/07 11:41:04 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2011/03/07 11:41:04 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2011/03/07 11:38:22 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/03/07 11:36:25 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/07 11:36:07 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2011/03/07 11:36:04 | 2146,742,272 | -HS- | M] () – C:\hiberfil.sys
[2011/03/06 05:57:36 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/03/05 12:17:46 | 000,002,459 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\Excel.lnk
[2011/03/05 12:13:51 | 000,002,501 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\Word.lnk
[2011/03/04 18:30:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (DELL-9200-FRED).job
[2011/03/04 09:19:24 | 000,000,268 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\Junkies.url
[2011/03/04 08:43:12 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2011/03/04 08:43:11 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2011/03/03 12:42:16 | 000,000,090 | —- | M] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2011/02/26 13:12:12 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2011/02/26 13:12:11 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2011/02/23 10:09:12 | 000,002,469 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\PPoint.lnk
[2011/02/22 16:05:31 | 000,110,395 | —- | M] () – C:\Documents and Settings\mstarnes\My Documents\KAP Commercial Reps Certs Jan 2011-mod[1].pdf
[2011/02/21 10:48:08 | 000,108,145 | —- | M] () – C:\Documents and Settings\mstarnes\My Documents\Eatern-Interconnection.png
[2011/02/17 11:00:40 | 000,000,656 | —- | M] () – C:\bar.emf
[2011/02/17 11:00:08 | 000,117,760 | —- | M] () – C:\Documents and Settings\mstarnes\My Documents\SmartCloud Security Flow.vsd
[2011/02/17 08:49:51 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/02/17 08:48:03 | 000,000,757 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Verizon Media Manager.lnk
[2011/02/17 08:02:12 | 000,216,582 | —- | M] () – C:\OFFICIAL VISA.pdf
[2011/02/16 09:58:56 | 000,000,190 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\Futures.url
[2011/02/16 09:57:17 | 000,002,419 | —- | M] () – C:\Documents and Settings\All Users\Desktop\VzAgent.lnk
[2011/02/15 17:52:31 | 000,001,611 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\Click for Verizon Wi-Fi Setup.lnk
[2011/02/15 17:52:28 | 000,001,845 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\Verizon Message Center.lnk
[2011/02/15 17:52:28 | 000,001,741 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\MyVzn.lnk
[2011/02/15 17:52:28 | 000,001,687 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\Search.lnk
[2011/02/15 11:56:37 | 000,002,040 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\FiOS.lnk
[2011/02/15 11:56:35 | 000,002,069 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\Install Verizon Media Manager.lnk
[2011/02/14 16:14:10 | 000,001,716 | -H– | M] () – C:\Documents and Settings\mstarnes\My Documents\Default.rdp
[2011/02/14 15:48:22 | 000,000,183 | —- | M] () – C:\Documents and Settings\mstarnes\Desktop\SC2!.url
[2011/02/12 15:51:29 | 000,049,517 | —- | M] () – C:\Documents and Settings\mstarnes\My Documents\Silver Spring Florist Hoover-Fisher Florist in Silver Spring MD.pdf
[2011/02/12 14:28:21 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2011/02/12 14:28:20 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2011/02/09 03:40:56 | 000,344,216 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/09 03:14:17 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\mstarnes\*.tmp files -> C:\Documents and Settings\mstarnes\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/07 15:14:26 | 000,000,933 | —- | C] () – C:\Documents and Settings\mstarnes\Desktop\Spybot - Search & Destroy.lnk
[2011/03/07 11:41:48 | 000,001,037 | —- | C] () – C:\Documents and Settings\mstarnes\Local Settings\Application Data\Account.atomsvc
[2011/02/22 16:05:30 | 000,110,395 | —- | C] () – C:\Documents and Settings\mstarnes\My Documents\KAP Commercial Reps Certs Jan 2011-mod[1].pdf
[2011/02/21 10:48:07 | 000,108,145 | —- | C] () – C:\Documents and Settings\mstarnes\My Documents\Eatern-Interconnection.png
[2011/02/17 11:00:07 | 000,117,760 | —- | C] () – C:\Documents and Settings\mstarnes\My Documents\SmartCloud Security Flow.vsd
[2011/02/17 08:48:03 | 000,000,757 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Verizon Media Manager.lnk
[2011/02/17 08:02:12 | 000,216,582 | —- | C] () – C:\OFFICIAL VISA.pdf
[2011/02/15 17:52:30 | 000,001,611 | —- | C] () – C:\Documents and Settings\mstarnes\Desktop\Click for Verizon Wi-Fi Setup.lnk
[2011/02/15 17:52:28 | 000,001,845 | —- | C] () – C:\Documents and Settings\mstarnes\Desktop\Verizon Message Center.lnk
[2011/02/15 17:52:28 | 000,001,687 | —- | C] () – C:\Documents and Settings\mstarnes\Desktop\Search.lnk
[2011/02/15 17:52:27 | 000,001,741 | —- | C] () – C:\Documents and Settings\mstarnes\Desktop\MyVzn.lnk
[2011/02/15 17:42:21 | 009,836,032 | —- | C] () – C:\WINDOWS\VerizonDM.msi
[2011/02/15 11:57:01 | 000,002,419 | —- | C] () – C:\Documents and Settings\All Users\Desktop\VzAgent.lnk
[2011/02/15 11:56:37 | 000,002,040 | —- | C] () – C:\Documents and Settings\mstarnes\Desktop\FiOS.lnk
[2011/02/15 11:56:35 | 000,002,069 | —- | C] () – C:\Documents and Settings\mstarnes\Desktop\Install Verizon Media Manager.lnk
[2011/02/14 15:11:33 | 000,000,183 | —- | C] () – C:\Documents and Settings\mstarnes\Desktop\SC2!.url
[2011/02/12 15:51:29 | 000,049,517 | —- | C] () – C:\Documents and Settings\mstarnes\My Documents\Silver Spring Florist Hoover-Fisher Florist in Silver Spring MD.pdf
[2010/08/03 02:21:06 | 002,254,600 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/07/21 14:00:58 | 297,947,136 | —- | C] () – C:\Program Files\en_expression_studio_4_premium_x86_dvd_537029.iso
[2010/05/11 09:18:13 | 000,020,992 | —- | C] () – C:\WINDOWS\jestertb.dll
[2010/03/01 14:16:39 | 000,000,090 | —- | C] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2010/02/21 12:18:03 | 000,091,742 | —- | C] () – C:\Program Files\Videos.htm
[2010/02/21 12:18:03 | 000,066,797 | —- | C] () – C:\Program Files\TableOfContents.htm
[2010/02/21 12:18:02 | 000,104,832 | —- | C] () – C:\Program Files\Presentations.htm
[2010/02/21 12:17:55 | 000,124,628 | —- | C] () – C:\Program Files\Labs.htm
[2010/02/21 12:17:55 | 000,004,820 | —- | C] () – C:\Program Files\Prerequisites.htm
[2010/02/21 12:13:04 | 000,086,468 | —- | C] () – C:\Program Files\Demos.htm
[2010/02/21 12:12:32 | 000,053,321 | —- | C] () – C:\Program Files\Default.htm
[2009/09/10 21:59:35 | 000,000,000 | —- | C] () – C:\WINDOWS\brdfxspd.dat
[2009/08/26 09:57:57 | 000,000,000 | —- | C] () – C:\Program Files\error.dat
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/03/16 10:23:58 | 000,001,172 | —- | C] () – C:\WINDOWS\mozver.dat
[2009/01/27 14:51:42 | 000,000,256 | —- | C] () – C:\WINDOWS\System32\pool.bin
[2009/01/22 08:41:02 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/01/22 08:40:09 | 000,001,083 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2009/01/22 08:40:09 | 000,000,153 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2009/01/22 08:40:09 | 000,000,065 | —- | C] () – C:\WINDOWS\System32\bd7840w.dat
[2009/01/22 08:37:05 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\BRTCPCON.DLL
[2009/01/22 08:37:05 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\BRLMW03A.INI
[2009/01/22 08:37:03 | 000,000,086 | —- | C] () – C:\WINDOWS\Brfaxrx.ini
[2009/01/22 08:37:02 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2009/01/21 18:03:17 | 000,031,567 | —- | C] () – C:\WINDOWS\maxlink.ini
[2008/12/10 09:23:12 | 000,000,026 | —- | C] () – C:\WINDOWS\DfrgUIEx.INI
[2008/11/07 13:50:01 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2008/11/07 13:48:37 | 000,091,648 | —- | C] () – C:\WINDOWS\gzip.exe
[2008/08/18 08:15:54 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2008/07/07 12:16:30 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2008/07/07 12:02:16 | 000,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/05/26 20:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 20:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/02/05 17:20:08 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/08/16 14:28:49 | 000,000,046 | —- | C] () – C:\WINDOWS\PowerPlugs Player.INI
[2007/08/16 13:23:25 | 000,000,025 | —- | C] () – C:\WINDOWS\System32\WinPPAddress.ini
[2007/08/16 13:22:22 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\VideoPlayer.dll
[2007/08/16 13:22:22 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\TransSaveStatus.dll
[2007/08/16 13:21:45 | 000,000,832 | —- | C] () – C:\WINDOWS\TransMusicClips.ini
[2007/06/21 15:56:53 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2006/08/18 10:34:25 | 000,000,353 | —- | C] () – C:\WINDOWS\System32\regasm.exe.config
[2006/08/18 10:34:23 | 000,338,944 | —- | C] () – C:\WINDOWS\System32\LFFPX7.DLL
[2006/08/18 10:34:23 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2006/08/18 10:20:28 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5220ex0C0A.dll
[2006/08/18 10:20:28 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5220ex0419.dll
[2006/08/18 10:20:28 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5220ex0410.dll
[2006/08/18 10:20:28 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5220ex040C.dll
[2006/08/18 10:20:28 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5220ex0409.dll
[2006/08/18 10:20:28 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5220ex0407.dll
[2006/08/18 10:20:28 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5120ex0C0A.dll
[2006/08/18 10:20:28 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5120ex0419.dll
[2006/08/18 10:20:28 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5220ex0412.dll
[2006/08/18 10:20:28 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5220ex0411.dll
[2006/08/18 10:20:28 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5120ex0412.dll
[2006/08/18 10:20:28 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5220ex0804.dll
[2006/08/18 10:20:28 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5120ex0804.dll
[2006/08/18 10:20:28 | 000,000,712 | —- | C] () – C:\WINDOWS\FJTWSTI.INI
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5530ex0C0A.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5530ex0419.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5530ex0410.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5530ex040C.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5530ex0409.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5530ex0407.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5120ex0410.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5120ex040C.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5120ex0409.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5120ex0407.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5110ex0C0A.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5110ex0410.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5110ex040C.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5110ex0407.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi4340ex0C0A.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi4340ex0410.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi4340ex040C.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi4340ex0407.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi42202ex0C0A.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi42202ex0410.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi42202ex040C.dll
[2006/08/18 10:20:27 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi42202ex0407.dll
[2006/08/18 10:20:27 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5530ex0412.dll
[2006/08/18 10:20:27 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5530ex0411.dll
[2006/08/18 10:20:27 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5120ex0411.dll
[2006/08/18 10:20:27 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5110ex0411.dll
[2006/08/18 10:20:27 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4340ex0409.dll
[2006/08/18 10:20:27 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi42202ex0409.dll
[2006/08/18 10:20:27 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5530ex0804.dll
[2006/08/18 10:20:27 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5110ex0804.dll
[2006/08/18 10:20:27 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4340ex0804.dll
[2006/08/18 10:20:27 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4340ex0411.dll
[2006/08/18 10:20:27 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi42202ex0804.dll
[2006/08/18 10:20:27 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi42202ex0411.dll
[2006/08/18 10:20:26 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\fi4530ex.dll
[2006/08/18 10:20:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5750ex0C0A.dll
[2006/08/18 10:20:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5750ex0410.dll
[2006/08/18 10:20:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5750ex040C.dll
[2006/08/18 10:20:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5750ex0407.dll
[2006/08/18 10:20:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5650ex0C0A.dll
[2006/08/18 10:20:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5650ex0410.dll
[2006/08/18 10:20:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5650ex040C.dll
[2006/08/18 10:20:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5650ex0407.dll
[2006/08/18 10:20:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi41202ex0C0A.dll
[2006/08/18 10:20:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi41202ex0410.dll
[2006/08/18 10:20:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi41202ex040C.dll
[2006/08/18 10:20:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi41202ex0407.dll
[2006/08/18 10:20:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5750ex0409.dll
[2006/08/18 10:20:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5650ex0409.dll
[2006/08/18 10:20:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4530ex0c0a.dll
[2006/08/18 10:20:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4530ex0410.dll
[2006/08/18 10:20:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4530ex040C.dll
[2006/08/18 10:20:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4530ex0409.dll
[2006/08/18 10:20:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4530ex0407.dll
[2006/08/18 10:20:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4220ex0C0A.dll
[2006/08/18 10:20:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4220ex0410.dll
[2006/08/18 10:20:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi41202ex0409.dll
[2006/08/18 10:20:26 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5750ex0804.dll
[2006/08/18 10:20:26 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5750ex0411.dll
[2006/08/18 10:20:26 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5650ex0804.dll
[2006/08/18 10:20:26 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5650ex0411.dll
[2006/08/18 10:20:26 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4530ex0804.dll
[2006/08/18 10:20:26 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4530ex0411.dll
[2006/08/18 10:20:26 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4220ex0804.dll
[2006/08/18 10:20:26 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4220ex0411.dll
[2006/08/18 10:20:26 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi41202ex0804.dll
[2006/08/18 10:20:26 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi41202ex0411.dll
[2006/08/18 10:20:25 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\fi4220ex.dll
[2006/08/18 10:20:25 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\fi4120ex.dll
[2006/08/18 10:20:25 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4220ex040C.dll
[2006/08/18 10:20:25 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4220ex0409.dll
[2006/08/18 10:20:25 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4220ex0407.dll
[2006/08/18 10:20:25 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4120ex0C0A.dll
[2006/08/18 10:20:25 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4120ex0410.dll
[2006/08/18 10:20:25 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4120ex040C.dll
[2006/08/18 10:20:25 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4120ex0409.dll
[2006/08/18 10:20:25 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4120ex0407.dll
[2006/08/18 10:20:25 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4120ex0804.dll
[2006/08/18 10:20:25 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4120ex0411.dll
[2006/04/20 09:27:47 | 000,000,075 | —- | C] () – C:\WINDOWS\USBBC.ini
[2006/04/20 09:27:47 | 000,000,000 | —- | C] () – C:\WINDOWS\MDI.INI
[2006/04/20 09:23:00 | 000,015,576 | R— | C] () – C:\WINDOWS\System32\drivers\usbbc.sys
[2006/04/20 09:23:00 | 000,003,953 | R— | C] () – C:\WINDOWS\System32\coinst.dll
[2006/04/07 14:06:22 | 000,311,296 | —- | C] () – C:\WINDOWS\System32\AegisI5.exe
[2006/04/07 14:06:22 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\ACUClose.exe
[2006/04/07 14:06:22 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\RmWlan.exe
[2006/04/07 14:06:22 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\CheckPCcardDevice.exe
[2006/04/07 14:06:07 | 000,274,432 | —- | C] () – C:\WINDOWS\System32\MagicP.exe
[2006/04/07 14:06:07 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\StopUtility.exe
[2006/04/07 14:06:07 | 000,008,914 | —- | C] () – C:\WINDOWS\System32\drivers\Lssrx4.bin
[2006/01/26 09:32:54 | 000,008,648 | —- | C] () – C:\Documents and Settings\mstarnes\Application Data\Barracuda-WhiteList.xml
[2005/12/06 16:32:31 | 000,002,560 | —- | C] () – C:\WINDOWS\_MSRSTRT.EXE
[2005/12/01 09:06:37 | 000,000,656 | —- | C] () – C:\WINDOWS\nvviewer.ini
[2005/10/27 11:26:38 | 000,000,054 | —- | C] () – C:\WINDOWS\JascCmdFile.INI
[2005/10/25 16:23:39 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\OSZLIB.dll
[2005/07/13 14:41:00 | 000,000,140 | —- | C] () – C:\WINDOWS\_delis32.ini
[2005/06/29 08:59:34 | 000,051,392 | —- | C] () – C:\WINDOWS\System32\drivers\atnt40k.sys
[2005/06/16 08:30:31 | 000,000,131 | —- | C] () – C:\Documents and Settings\mstarnes\Local Settings\Application Data\fusioncache.dat
[2005/06/13 13:34:11 | 000,000,033 | —- | C] () – C:\WINDOWS\iltwain.ini
[2005/06/02 09:05:43 | 000,105,984 | —- | C] () – C:\Documents and Settings\mstarnes\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/05/31 10:20:44 | 000,005,374 | R— | C] () – C:\WINDOWS\System32\drivers\wni6000.bin
[2005/05/19 14:05:07 | 000,000,456 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2005/05/17 13:45:39 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2005/02/07 09:54:22 | 000,139,288 | —- | C] () – C:\WINDOWS\System32\CSGina.dll
[2005/02/03 14:42:09 | 000,000,000 | —- | C] () – C:\WINDOWS\frontpg.ini
[2005/02/03 14:32:51 | 000,021,791 | —- | C] () – C:\WINDOWS\System32\smtpctrs.ini
[2005/02/03 14:32:50 | 000,001,037 | —- | C] () – C:\WINDOWS\System32\ntfsdrct.ini
[2005/02/03 14:31:17 | 000,038,576 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2005/02/03 14:31:16 | 000,010,225 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2005/02/03 14:31:14 | 000,011,435 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2005/02/03 10:00:50 | 000,000,984 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/02/03 08:52:33 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/01/24 19:54:23 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/01/24 19:50:31 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005/01/24 19:46:45 | 000,000,264 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/01/24 19:30:12 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2005/01/24 19:28:28 | 000,575,956 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2005/01/24 19:28:28 | 000,112,808 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2005/01/24 19:09:20 | 000,000,516 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/09/15 22:49:44 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/12 09:44:10 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\iwca.dll
[2004/08/11 18:25:56 | 000,000,883 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/11 18:20:10 | 000,344,216 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/11 18:14:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/11 18:12:16 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/11 11:31:24 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/11 11:31:24 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 06:00:00 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2004/08/04 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 06:00:00 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/04 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 06:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 06:00:00 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/04 06:00:00 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2004/08/04 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2004/08/04 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 06:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 06:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 06:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 17:01:02 | 000,045,056 | —- | C] () – C:\WINDOWS\SETPWRCG.EXE
[2004/04/23 14:17:02 | 000,000,061 | —- | C] () – C:\WINDOWS\System32\uninstall.ini
[1996/09/11 23:00:00 | 000,000,058 | —- | C] () – C:\WINDOWS\GLFHELP.INI
[1995/03/21 23:00:00 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\IYVU9_32.DLL
[1980/01/01 01:00:00 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\stac97co.dll

========== LOP Check ==========

[2009/05/21 10:02:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Applications
[2010/03/01 14:16:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2010/02/21 12:36:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
[2005/02/07 07:55:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Network Associates
[2009/07/15 08:36:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2011/02/15 17:52:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Radialpoint
[2009/11/01 14:04:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2009/02/02 10:33:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/03/16 08:03:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SkyGolf
[2010/03/01 15:33:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 11
[2011/02/15 17:42:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2011/03/07 11:39:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/07/23 09:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/07/15 08:32:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\zeon
[2009/07/15 08:19:53 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Amazon
[2010/08/30 13:20:38 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Bytescout Software
[2008/12/18 16:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/11/17 17:41:01 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Dimdim
[2010/08/09 10:33:11 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Free Download Manager
[2006/08/18 10:47:56 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Fujitsu
[2010/08/11 08:11:13 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\GARMIN
[2009/06/30 11:53:27 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Helios
[2008/03/26 10:52:12 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\ICQ Toolbar
[2005/10/14 16:05:29 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Leadertech
[2009/10/06 13:15:32 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Nuance
[2009/01/22 11:07:19 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\PC-FAX TX
[2010/09/29 08:22:42 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Research In Motion
[2009/01/22 09:07:12 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\ScanSoft
[2010/03/16 08:03:26 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\SkyGolf
[2010/02/24 00:46:37 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Software Informer
[2010/05/18 14:07:42 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Sparx Systems
[2011/02/15 11:56:35 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\TechWizard
[2008/04/11 15:46:44 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Thunderbird
[2008/02/25 10:48:44 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Viewpoint
[2007/08/21 09:34:08 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\WeatherBug
[2011/02/23 16:17:02 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\webex
[2009/06/10 07:41:22 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Windows Desktop Search
[2009/12/03 15:52:24 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Windows Search
[2009/04/14 16:02:06 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\YouSendIt
[2009/07/15 08:35:18 | 000,000,000 | —D | M] – C:\Documents and Settings\mstarnes\Application Data\Zeon
[2011/03/07 17:03:00 | 000,000,260 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/02/17 11:00:40 | 000,000,656 | —- | M] () – C:\bar.emf
[2005/02/03 08:00:58 | 000,000,211 | -HS- | M] () – C:\BOOT.INI
[2008/12/31 15:24:34 | 000,014,228 | —- | M] () – C:\Bundled order.docx
[2010/05/21 14:16:38 | 000,062,703 | —- | M] () – C:\CSE101 Enterprise Quotation WRPS.pdf
[2005/01/24 19:16:54 | 000,004,689 | RH– | M] () – C:\DELL.SDR
[2009/07/20 15:24:56 | 000,000,666 | —- | M] () – C:\escor_rethink.log
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 07:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 07:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 07:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2010/07/08 16:48:58 | 000,377,213 | —- | M] () – C:\golf drop rule.pptx
[2009/03/05 09:30:13 | 000,791,791 | —- | M] () – C:\GT Dashboard Concept.pptx
[2011/03/07 11:36:04 | 2146,742,272 | -HS- | M] () – C:\hiberfil.sys
[2008/11/17 09:07:45 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2007/11/07 07:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 07:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 07:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 07:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 07:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 07:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 07:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 07:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 07:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 07:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 07:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2009/03/05 16:08:42 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/12/31 15:36:30 | 000,033,792 | —- | M] () – C:\KAP bundled order proposal.doc
[2008/12/31 15:25:56 | 000,014,243 | —- | M] () – C:\KAP bundled order proposal.docx
[2009/03/05 16:08:42 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/12/05 10:38:49 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2010/08/13 09:05:47 | 000,000,464 | —- | M] () – C:\ODBCServiceLog.txt
[2011/02/17 08:02:12 | 000,216,582 | —- | M] () – C:\OFFICIAL VISA.pdf
[2011/03/07 11:35:55 | 3219,128,320 | -HS- | M] () – C:\pagefile.sys
[2010/07/08 16:24:46 | 000,839,294 | —- | M] () – C:\SmartCloud Dashboard Concept.pptx
[2010/10/15 08:02:14 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2010/10/18 10:34:49 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2010/11/03 11:36:15 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2010/11/11 08:41:27 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2010/11/13 16:18:25 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2010/11/30 11:49:23 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2010/11/30 12:00:54 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2010/12/16 08:45:53 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2010/12/19 22:35:26 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2011/01/03 09:09:01 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2011/01/13 08:50:38 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2011/01/18 16:02:40 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2011/01/20 15:45:25 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2011/01/31 09:53:13 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2011/02/12 14:28:21 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2011/02/26 13:12:12 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2011/03/04 08:43:12 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2011/03/07 11:41:04 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2010/10/13 19:54:36 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2010/10/14 02:19:15 | 000,000,172 | -H– | M] () – C:\sqmdata19.sqm
[2010/10/15 08:02:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/10/18 10:34:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/11/03 11:36:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2010/11/11 08:41:26 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/11/13 16:18:24 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/11/30 11:49:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/11/30 12:00:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/12/16 08:45:52 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/12/19 22:35:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2011/01/03 09:09:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2011/01/13 08:50:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2011/01/18 16:02:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2011/01/20 15:45:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2011/01/31 09:53:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2011/02/12 14:28:20 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2011/02/26 13:12:11 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2011/03/04 08:43:11 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2011/03/07 11:41:04 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2010/10/13 19:54:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2010/10/14 02:19:15 | 000,000,172 | -H– | M] () – C:\sqmnoopt19.sqm
[2009/06/29 15:11:48 | 000,026,747 | —- | M] () – C:\Thortons Thunder.xlsm
[2009/05/27 08:03:04 | 000,012,118 | —- | M] () – C:\Thortons Thunder.xlsx
[2011/01/11 17:04:41 | 000,008,704 | -HS- | M] () – C:\Thumbs.db
[2009/03/06 14:36:13 | 000,005,267 | —- | M] () – C:\tw-8-log.txt
[2007/11/07 07:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 07:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 07:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2009/05/15 09:22:39 | 000,004,031 | —- | M] () – C:\yugmaerr.log
[2009/05/15 09:22:39 | 000,000,098 | —- | M] () – C:\yugmaout.log
[2008/12/31 15:36:30 | 000,000,162 | -H– | M] () – C:\~$P bundled order proposal.doc

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/11 18:14:22 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\filterpipelineprintproc.dll
[2009/03/13 19:30:56 | 000,081,240 | —- | M] (Microsoft Corporation.) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\lmdippr8.dll
[2004/03/22 17:17:06 | 000,025,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2010/02/09 16:00:33 | 000,053,321 | —- | M] () – C:\Program Files\Default.htm
[2010/02/09 16:00:34 | 000,086,468 | —- | M] () – C:\Program Files\Demos.htm
[2010/06/27 08:43:52 | 297,947,136 | —- | M] () – C:\Program Files\en_expression_studio_4_premium_x86_dvd_537029.iso
[2009/08/26 09:57:57 | 000,000,000 | —- | M] () – C:\Program Files\error.dat
[2007/10/30 10:50:32 | 005,809,216 | —- | M] (Hypnotizer) – C:\Program Files\hyplay.exe
[2010/02/09 16:00:34 | 000,124,628 | —- | M] () – C:\Program Files\Labs.htm
[2010/01/20 15:37:53 | 000,018,130 | —- | M] () – C:\Program Files\Overview.docx
[2010/02/09 16:00:34 | 000,004,820 | —- | M] () – C:\Program Files\Prerequisites.htm
[2010/02/09 16:00:34 | 000,104,832 | —- | M] () – C:\Program Files\Presentations.htm
[2010/02/09 16:00:35 | 000,066,797 | —- | M] () – C:\Program Files\TableOfContents.htm
[2010/02/09 16:00:35 | 000,091,742 | —- | M] () – C:\Program Files\Videos.htm

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/11 18:06:14 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2004/08/11 18:06:14 | 000,659,456 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2004/08/11 18:06:14 | 000,876,544 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/12/05 10:48:18 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2005/01/24 19:36:08 | 000,000,310 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\convert.log

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/05/20 16:04:50 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\mstarnes\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2004/08/11 18:20:42 | 000,000,079 | —- | M] () – C:\Documents and Settings\mstarnes\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[1999/08/30 16:39:30 | 001,145,344 | —- | M] (Claris Corporation) – C:\Documents and Settings\mstarnes\Desktop\FleMkr.exe
[2005/05/12 03:14:08 | 005,177,344 | —- | M] (Gensym Corporation) – C:\Documents and Settings\mstarnes\Desktop\tw.exe
[2006/05/25 20:43:40 | 007,725,056 | —- | M] (Gensym Corporation) – C:\Documents and Settings\mstarnes\Desktop\tw1.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-04 08:04:51

========== Alternate Data Streams ==========

@Alternate Data Stream - 241 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E55808C
@Alternate Data Stream - 229 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:527B6DAD
@Alternate Data Stream - 215 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B9252F22

< End of report >
Hi mstarnes,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Agent.exe is a fairly common name used by many different programs. You've got a couple onboard. However, it could also be malware (though I'm not seeing any nefarious agent.exe in your log).

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:OTL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No CLSID value found.
O4 - HKCU..\Run: [fsm] File not found
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O21 - SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - CLSID or File not found.
  
C:\sqmdata17.sqm
C:\sqmnoopt17.sqm
C:\sqmdata16.sqm
C:\sqmnoopt16.sqm
C:\sqmdata15.sqm
C:\sqmnoopt15.sqm
C:\sqmdata14.sqm
C:\sqmnoopt14.sqm
C:\sqmdata00.sqm
C:\sqmdata01.sqm
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata04.sqm
C:\sqmdata05.sqm
C:\sqmdata06.sqm
C:\sqmdata07.sqm
C:\sqmdata08.sqm
C:\sqmdata09.sqm
C:\sqmdata10.sqm
C:\sqmdata11.sqm
C:\sqmdata12.sqm
C:\sqmdata13.sqm
C:\sqmdata14.sqm
C:\sqmdata15.sqm
C:\sqmdata16.sqm
C:\sqmdata17.sqm
C:\sqmdata18.sqm
C:\sqmdata19.sqm
C:\sqmnoopt00.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt02.sqm
C:\sqmnoopt03.sqm
C:\sqmnoopt04.sqm
C:\sqmnoopt05.sqm
C:\sqmnoopt06.sqm
C:\sqmnoopt07.sqm
C:\sqmnoopt08.sqm
C:\sqmnoopt09.sqm
C:\sqmnoopt10.sqm
C:\sqmnoopt11.sqm
C:\sqmnoopt12.sqm
C:\sqmnoopt13.sqm
C:\sqmnoopt14.sqm
C:\sqmnoopt15.sqm
C:\sqmnoopt16.sqm
C:\sqmnoopt17.sqm
C:\sqmnoopt18.sqm
C:\sqmnoopt19.sqm

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI