rpperin
2010-08-02, 20:31
I have the exact same symptoms as another poster had on these forums.
Quoted from his thread:
"Recently my pc has been acting rather strangely. As stated in the thread title, I'm experiencing random sound losses, to fix it I have to click on the wave volume bar in system volume.
Also, when the volume is back on I often hear random clicking sounds, as if I clicked on a folder in explorer for example. Sometimes I hear an advertisement!
And lastly, I have the occasional ad popup in IE even though I never use IE, only Firefox."
Furthermore, I have left my computer in this state for about a week and a half. The randomly muted wave sound doesn't seem to be an issue anymore, but pop-ups are just as bad if not worse. And just recently I got a warning that my C: drive is running low on space (243 mb remaining) so I'm not sure if that's another symptom because I haven't done anything significant lately. I plan on exporting all important files to an external hard drive right now and hopefully you guys can help me get get this issue resolved soon! :) Thanks in advance for any help.
My DDS log is as follows:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Ryan at 13:29:45.40 on Mon 08/02/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.2.1033.18.2047.1227 [GMT -4:00]
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe 4
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
svchost.exe 4
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
F:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
F:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
F:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Norton Utilities 14\nu.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Adobe Media Player\Adobe Media Player.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Norton Utilities 14\upgrade.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
F:\Program Files\Mozilla\firefox.exe
F:\Program Files\Mozilla\plugin-container.exe
C:\Documents and Settings\Ryan\Desktop\dds.com
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [Steam] "g:\program files\steam\steam.exe" -silent
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [NortonUtilities] f:\program files\norton utilities 14\nu.exe /H
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [QuickFinder Scheduler] "f:\program files\wordperfect office 11\programs\QFSCHD110.EXE"
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe
mRun: [DAEMON Tools] "f:\program files\daemon tools\daemon.exe" -lang 1033
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Smapp] c:\program files\analog devices\soundmax\SMTray.exe
mRun: [HP Software Update] f:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "f:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10e.exe
StartupFolder: c:\docume~1\ryan\startm~1\programs\startup\adobem~1.lnk - c:\program files\adobe media player\Adobe Media Player.exe
StartupFolder: c:\docume~1\ryan\startm~1\programs\startup\erunta~1.lnk - f:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - f:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: E&xport to Microsoft Excel - f:\progra~1\micros~1\office11\EXCEL.EXE/3000
IE: {022C4009-5283-4365-97BF-144054B40E2E} - http://itv.mop.com
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - f:\progra~1\micros~1\office11\REFIEBAR.DLL
Trusted Zone: tessource.net\big
Trusted Zone: tessource.net\www
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} - hxxp://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.80_20060123.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\ryan\applic~1\mozilla\firefox\profiles\wdp37zzq.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\ryan\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\ryan\application data\mozilla\firefox\profiles\wdp37zzq.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: f:\program files\divx\divx content uploader\npUpload.dll
FF - plugin: f:\program files\divx\divx web player\npdivx32.dll
FF - plugin: f:\program files\itunes\mozilla plugins\npitunes.dll
FF - plugin: f:\program files\mozilla\plugins\npmozax.dll
FF - plugin: f:\program files\mozilla\plugins\nptgeqplugin.dll
FF - plugin: f:\program files\real\realplayer\netscape6\nppl3260.dll
FF - plugin: f:\program files\real\realplayer\netscape6\nprjplug.dll
FF - plugin: f:\program files\real\realplayer\netscape6\nprpjplug.dll
FF - plugin: f:\program files\veetle\player\npvlc.dll
FF - plugin: f:\program files\veetle\plugins\npVeetle.dll
FF - plugin: f:\program files\veetle\vlcbroadcast\npvbp.dll
FF - HiddenExtension: Java Console: No Registry Reference - f:\program files\mozilla\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - f:\program files\mozilla\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - f:\program files\mozilla\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
f:\program files\mozilla\greprefs\all.js - pref("ui.use_native_colors", true);
f:\program files\mozilla\greprefs\all.js - pref("ui.use_native_popup_windows", false);
f:\program files\mozilla\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
f:\program files\mozilla\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
f:\program files\mozilla\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
f:\program files\mozilla\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
f:\program files\mozilla\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
f:\program files\mozilla\greprefs\all.js - pref("network.proxy.type", 5);
f:\program files\mozilla\greprefs\all.js - pref("network.buffer.cache.count", 24);
f:\program files\mozilla\greprefs\all.js - pref("network.buffer.cache.size", 4096);
f:\program files\mozilla\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
f:\program files\mozilla\greprefs\all.js - pref("svg.smil.enabled", false);
f:\program files\mozilla\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.debug", false);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
f:\program files\mozilla\greprefs\all.js - pref("accelerometer.enabled", true);
f:\program files\mozilla\greprefs\all.js - pref("html5.enable", false);
f:\program files\mozilla\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
f:\program files\mozilla\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
f:\program files\mozilla\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
f:\program files\mozilla\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
f:\program files\mozilla\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
f:\program files\mozilla\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
f:\program files\mozilla\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
f:\program files\mozilla\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
f:\program files\mozilla\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
f:\program files\mozilla\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
f:\program files\mozilla\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
f:\program files\mozilla\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
f:\program files\mozilla\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
f:\program files\mozilla\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
f:\program files\mozilla\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
f:\program files\mozilla\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
f:\program files\mozilla\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
f:\program files\mozilla\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
f:\program files\mozilla\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
f:\program files\mozilla\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
f:\program files\mozilla\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
f:\program files\mozilla\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
f:\program files\mozilla\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
f:\program files\mozilla\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
f:\program files\mozilla\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
S3 c344cc55-3bbe-4f83-a257-57b070db953b;c344cc55-3bbe-4f83-a257-57b070db953b;\??\d:\cds300\cds300.dll --> d:\cds300\cds300.dll [?]
S3 JL2001;Telemax WebCam WC-50;c:\windows\system32\drivers\videocap.sys [2002-1-10 173768]
============== File Associations ===============
scrfile="c:\program files\internet explorer\Iexplore.exe" %1
=============== Created Last 30 ================
2010-07-25 21:16:41 0 d-----w- c:\windows\pss
2010-07-25 19:44:42 664 ----a-w- c:\windows\system32\d3d9caps.dat
==================== Find3M ====================
2010-08-02 01:14:21 29133 ----a-w- c:\windows\hpoins03.dat
2010-07-01 20:07:10 51716 ----a-w- c:\windows\system32\pdf995mon.dll
2010-07-01 20:07:10 249856 ----a-w- c:\windows\system32\pdfmona.dll
============= FINISH: 13:29:58.87 ===============
Quoted from his thread:
"Recently my pc has been acting rather strangely. As stated in the thread title, I'm experiencing random sound losses, to fix it I have to click on the wave volume bar in system volume.
Also, when the volume is back on I often hear random clicking sounds, as if I clicked on a folder in explorer for example. Sometimes I hear an advertisement!
And lastly, I have the occasional ad popup in IE even though I never use IE, only Firefox."
Furthermore, I have left my computer in this state for about a week and a half. The randomly muted wave sound doesn't seem to be an issue anymore, but pop-ups are just as bad if not worse. And just recently I got a warning that my C: drive is running low on space (243 mb remaining) so I'm not sure if that's another symptom because I haven't done anything significant lately. I plan on exporting all important files to an external hard drive right now and hopefully you guys can help me get get this issue resolved soon! :) Thanks in advance for any help.
My DDS log is as follows:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Ryan at 13:29:45.40 on Mon 08/02/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.2.1033.18.2047.1227 [GMT -4:00]
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe 4
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
svchost.exe 4
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
F:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
F:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
F:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Norton Utilities 14\nu.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Adobe Media Player\Adobe Media Player.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Norton Utilities 14\upgrade.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
F:\Program Files\Mozilla\firefox.exe
F:\Program Files\Mozilla\plugin-container.exe
C:\Documents and Settings\Ryan\Desktop\dds.com
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [Steam] "g:\program files\steam\steam.exe" -silent
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [NortonUtilities] f:\program files\norton utilities 14\nu.exe /H
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [QuickFinder Scheduler] "f:\program files\wordperfect office 11\programs\QFSCHD110.EXE"
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe
mRun: [DAEMON Tools] "f:\program files\daemon tools\daemon.exe" -lang 1033
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Smapp] c:\program files\analog devices\soundmax\SMTray.exe
mRun: [HP Software Update] f:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "f:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10e.exe
StartupFolder: c:\docume~1\ryan\startm~1\programs\startup\adobem~1.lnk - c:\program files\adobe media player\Adobe Media Player.exe
StartupFolder: c:\docume~1\ryan\startm~1\programs\startup\erunta~1.lnk - f:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - f:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: E&xport to Microsoft Excel - f:\progra~1\micros~1\office11\EXCEL.EXE/3000
IE: {022C4009-5283-4365-97BF-144054B40E2E} - http://itv.mop.com
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - f:\progra~1\micros~1\office11\REFIEBAR.DLL
Trusted Zone: tessource.net\big
Trusted Zone: tessource.net\www
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} - hxxp://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.80_20060123.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\ryan\applic~1\mozilla\firefox\profiles\wdp37zzq.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\ryan\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\ryan\application data\mozilla\firefox\profiles\wdp37zzq.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: f:\program files\divx\divx content uploader\npUpload.dll
FF - plugin: f:\program files\divx\divx web player\npdivx32.dll
FF - plugin: f:\program files\itunes\mozilla plugins\npitunes.dll
FF - plugin: f:\program files\mozilla\plugins\npmozax.dll
FF - plugin: f:\program files\mozilla\plugins\nptgeqplugin.dll
FF - plugin: f:\program files\real\realplayer\netscape6\nppl3260.dll
FF - plugin: f:\program files\real\realplayer\netscape6\nprjplug.dll
FF - plugin: f:\program files\real\realplayer\netscape6\nprpjplug.dll
FF - plugin: f:\program files\veetle\player\npvlc.dll
FF - plugin: f:\program files\veetle\plugins\npVeetle.dll
FF - plugin: f:\program files\veetle\vlcbroadcast\npvbp.dll
FF - HiddenExtension: Java Console: No Registry Reference - f:\program files\mozilla\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - f:\program files\mozilla\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - f:\program files\mozilla\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
f:\program files\mozilla\greprefs\all.js - pref("ui.use_native_colors", true);
f:\program files\mozilla\greprefs\all.js - pref("ui.use_native_popup_windows", false);
f:\program files\mozilla\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
f:\program files\mozilla\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
f:\program files\mozilla\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
f:\program files\mozilla\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
f:\program files\mozilla\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
f:\program files\mozilla\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
f:\program files\mozilla\greprefs\all.js - pref("network.proxy.type", 5);
f:\program files\mozilla\greprefs\all.js - pref("network.buffer.cache.count", 24);
f:\program files\mozilla\greprefs\all.js - pref("network.buffer.cache.size", 4096);
f:\program files\mozilla\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
f:\program files\mozilla\greprefs\all.js - pref("svg.smil.enabled", false);
f:\program files\mozilla\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.debug", false);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
f:\program files\mozilla\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
f:\program files\mozilla\greprefs\all.js - pref("accelerometer.enabled", true);
f:\program files\mozilla\greprefs\all.js - pref("html5.enable", false);
f:\program files\mozilla\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
f:\program files\mozilla\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
f:\program files\mozilla\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
f:\program files\mozilla\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
f:\program files\mozilla\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
f:\program files\mozilla\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
f:\program files\mozilla\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
f:\program files\mozilla\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
f:\program files\mozilla\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
f:\program files\mozilla\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
f:\program files\mozilla\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
f:\program files\mozilla\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
f:\program files\mozilla\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
f:\program files\mozilla\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
f:\program files\mozilla\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
f:\program files\mozilla\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
f:\program files\mozilla\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
f:\program files\mozilla\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
f:\program files\mozilla\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
f:\program files\mozilla\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
f:\program files\mozilla\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
f:\program files\mozilla\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
f:\program files\mozilla\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
f:\program files\mozilla\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
f:\program files\mozilla\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
S3 c344cc55-3bbe-4f83-a257-57b070db953b;c344cc55-3bbe-4f83-a257-57b070db953b;\??\d:\cds300\cds300.dll --> d:\cds300\cds300.dll [?]
S3 JL2001;Telemax WebCam WC-50;c:\windows\system32\drivers\videocap.sys [2002-1-10 173768]
============== File Associations ===============
scrfile="c:\program files\internet explorer\Iexplore.exe" %1
=============== Created Last 30 ================
2010-07-25 21:16:41 0 d-----w- c:\windows\pss
2010-07-25 19:44:42 664 ----a-w- c:\windows\system32\d3d9caps.dat
==================== Find3M ====================
2010-08-02 01:14:21 29133 ----a-w- c:\windows\hpoins03.dat
2010-07-01 20:07:10 51716 ----a-w- c:\windows\system32\pdf995mon.dll
2010-07-01 20:07:10 249856 ----a-w- c:\windows\system32\pdfmona.dll
============= FINISH: 13:29:58.87 ===============