oneeyefrail
Topic Starter
]Help please… my computers got a browser hijacker,every time i try to open up a link on google it take sme somewhere random
doing my nut in …..heres the OTL print out..and the thanks in advance .
OTL logfile created on: 28/11/2010 12:42:27 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\E140462\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68.18 Gb Total Space | 32.87 Gb Free Space | 48.21% Space Free | Partition Type: NTFS
Drive E: | 10.15 Gb Total Space | 5.34 Gb Free Space | 52.65% Space Free | Partition Type: NTFS
Drive G: | 70.72 Gb Total Space | 8.27 Gb Free Space | 11.70% Space Free | Partition Type: NTFS
Computer Name: ABDL_JCMQ04J | User Name: E140462 | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\E140462\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Documents and Settings\E140462\Local Settings\Temp\HouseCall\housecall.bin (Trend Micro Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\McAfee\Common Framework\McScript_InUse.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Program Files\Windows Live\Toolbar\wltuser.exe (Microsoft Corporation)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe (McAfee, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\ssonsvr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe (McAfee, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
PRC - C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe (Juniper Networks)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
PRC - G:\Program Files\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
PRC - G:\Program Files\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
PRC - G:\Program Files\VMware\VMware Workstation\hqtray.exe (VMware, Inc.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe (VMware, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\E140462\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\hccutils.dll (Intel Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
SRV - (mfevtp) – C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McTaskManager) – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
SRV - (McAfeeEngineService) – C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe (McAfee, Inc.)
SRV - (enterceptAgent) – C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe (McAfee, Inc.)
SRV - (hips) – C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe (McAfee, Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
SRV - (dsNcService) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (JuniperAccessService) – C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe (Juniper Networks)
SRV - (VMnetDHCP) – C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMware NAT Service) – C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
SRV - (VMAuthdService) – G:\Program Files\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
SRV - (ufad-ws60) – G:\Program Files\VMware\VMware Workstation\vmware-ufad.exe (VMware, Inc.)
SRV - (STacSV) – C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)
SRV - (vmount2) – C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe (VMware, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (Cwbrxd) – C:\WINDOWS\cwbrxd.exe (IBM Corporation)
========== Driver Services (SafeList) ==========
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdik) – C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (firelm01) – C:\WINDOWS\system32\drivers\firelm01.sys (McAfee, Inc.)
DRV - (FireTDI) – C:\WINDOWS\system32\drivers\FireTDI.sys (McAfee, Inc.)
DRV - (FirePM) – C:\WINDOWS\system32\Drivers\FirePM.sys (McAfee, Inc.)
DRV - (HIPQK) – C:\WINDOWS\system32\drivers\HIPQK.sys (McAfee, Inc.)
DRV - (HIPPSK) – C:\WINDOWS\system32\drivers\HIPPSK.sys (McAfee, Inc.)
DRV - (HIPK) – C:\WINDOWS\system32\drivers\HIPK.sys (McAfee, Inc.)
DRV - (NEOFLTR_610_13733) Juniper Networks TDI Filter Driver (NEOFLTR_610_13733) – C:\WINDOWS\system32\drivers\NEOFLTR_610_13733.sys (Juniper Networks)
DRV - (dsNcAdpt) – C:\WINDOWS\system32\drivers\dsNcAdpt.sys (Juniper Networks)
DRV - (FirehkMP) – C:\WINDOWS\system32\drivers\firehk.sys (McAfee, Inc.)
DRV - (Firehk) – C:\WINDOWS\system32\drivers\firehk.sys (McAfee, Inc.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (hcmon) – C:\WINDOWS\system32\drivers\hcmon.sys (VMware, Inc.)
DRV - (vmx86) – C:\WINDOWS\system32\drivers\vmx86.sys (VMware, Inc.)
DRV - (VMnetuserif) – C:\WINDOWS\system32\drivers\vmnetuserif.sys (VMware, Inc.)
DRV - (vmkbd) – C:\WINDOWS\system32\drivers\VMkbd.sys (VMware, Inc.)
DRV - (VMnetBridge) – C:\WINDOWS\system32\drivers\vmnetbridge.sys (VMware, Inc.)
DRV - (VMnetAdapter) – C:\WINDOWS\system32\drivers\vmnetadapter.sys (VMware, Inc.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (vstor2-ws60) – G:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys (VMware, Inc.)
DRV - (NETw4x32) Intel® – C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (hotcore3) – C:\WINDOWS\system32\drivers\hotcore3.sys (Paragon Software Group)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (guardian2) – C:\WINDOWS\system32\drivers\oz776.sys (O2Micro)
DRV - (vstor2) – C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys (VMware, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (FTD2XX) – C:\WINDOWS\system32\drivers\FTD2XX.sys (FTDI Ltd.)
DRV - (DirectNT) – C:\WINDOWS\System32\drivers\DirectNT.sys (c't)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://intranet/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2010/11/27 21:44:34 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Client Access Check Version] C:\Program Files\IBM\Client Access\cwbckver.exe (IBM Corporation)
O4 - HKLM..\Run: [Client Access Express Welcome] C:\Program Files\IBM\Client Access\cwbwlwiz.exe (IBM Corporation)
O4 - HKLM..\Run: [Client Access Help Update] C:\Program Files\IBM\Client Access\cwbinhlp.exe (IBM Corporation)
O4 - HKLM..\Run: [Client Access PC5250 Sound] C:\Program Files\IBM\Client Access\Emulator\pcssnd.exe (IBM Corporation)
O4 - HKLM..\Run: [Client Access Service] C:\Program Files\IBM\Client Access\cwbsvstr.exe (IBM Corporation)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [McAfee Host Intrusion Prevention Tray] C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [VMware hqtray] G:\Program Files\VMware\VMware Workstation\hqtray.exe (VMware, Inc.)
O4 - HKLM..\Run: [vmware-tray] G:\Program Files\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: 515crpweb ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: 515crpwebcapture ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: 515opweb ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: 515opwebcapture ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: techno-media.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([515endweb] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([elm] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([elm] https in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([hrmsonline] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([hrmsonline] https in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([hrtstapp01] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([hrtstapp01] https in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([intranet] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([intranettest] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([pdmdv] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([pdmpd] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([pdmpy] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([psoftelm] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([psoftelm] https in Trusted sites)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1282655466752 (WUWebControl Class)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupSP1 Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wft.root.loc
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\E140462\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\E140462\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/24 09:20:06 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\##Uk-data#abd_tt\Shell - "" = AutoRun
O33 - MountPoints2\##Uk-data#abd_tt\Shell\AuTOplay\COmmand - "" = xnuhwp.pif
O33 - MountPoints2\##Uk-data#abd_tt\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\##Uk-data#abd_tt\Shell\AutoRun\command - "" = xnuhwp.pif
O33 - MountPoints2\##Uk-data#abd_tt\Shell\ExPLOre\cOmmanD - "" = xnuhwp.pif
O33 - MountPoints2\##Uk-data#abd_tt\Shell\oPEn\CoMMANd - "" = xnuhwp.pif
O33 - MountPoints2\{ee1abd06-f038-11df-a114-005056c00001}\Shell - "" = Autorun
O33 - MountPoints2\{ee1abd06-f038-11df-a114-005056c00001}\Shell\AutoRun\command - "" = H:\Install_Nokia_Ovi_Suite.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: VIDC.VMnc - C:\WINDOWS\System32\vmnc.dll (VMware, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55182706186649600)
========== Files/Folders - Created Within 60 Days ==========
[2010/11/28 12:40:01 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\E140462\Desktop\OTL.exe
[2010/11/28 12:19:23 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/11/28 12:18:24 | 000,000,000 | —D | C] – C:\Program Files\Windows Defender
[2010/11/27 23:50:49 | 000,038,528 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\HIPIS0e011a2.dll
[2010/11/26 21:22:03 | 000,000,000 | —D | C] – C:\NFS-Backup
[2010/11/26 21:22:03 | 000,000,000 | —D | C] – C:\NCSEXPER
[2010/11/26 21:22:03 | 000,000,000 | —D | C] – C:\Entwicklungsdaten
[2010/11/26 21:22:03 | 000,000,000 | —D | C] – C:\EDIABAS
[2010/11/26 19:46:27 | 000,000,000 | —D | C] – C:\NCSEXPER(2)
[2010/11/26 19:36:34 | 000,000,000 | —D | C] – C:\NCSEXPER(3)
[2010/11/26 19:36:34 | 000,000,000 | —D | C] – C:\EDIABAS(2)
[2010/11/26 18:48:14 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\lma
[2010/11/26 18:47:57 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\cas
[2010/11/26 16:11:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2010/11/24 09:05:56 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2010/11/24 09:05:42 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2010/11/24 09:04:33 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2010/11/24 09:04:33 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2010/11/24 09:04:33 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2010/11/24 09:04:33 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2010/11/24 09:04:33 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2010/11/24 09:04:33 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2010/11/24 09:04:32 | 000,000,000 | —D | C] – C:\ed83c0a3c21fea46856c3dda2633
[2010/11/23 17:53:50 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\FSW files
[2010/11/23 13:45:25 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\read
[2010/11/22 00:53:44 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\print
[2010/11/18 08:50:15 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\Storengy CE19
[2010/11/18 08:49:58 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\Job Folder
[2010/11/15 00:12:28 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\My Documents\My Virtual Machines
[2010/11/14 23:52:13 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\Bmw stuff
[2010/11/14 20:43:02 | 000,000,000 | —D | C] – C:\Program Files\BMW Diagnostic Head Emulator
[2010/11/14 19:53:56 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\My Documents\ADS
[2010/11/14 19:37:48 | 000,000,000 | —D | C] – C:\EC-APPS
[2010/11/14 18:34:44 | 000,000,000 | —D | C] – C:\INPA
[2010/11/12 21:46:10 | 000,016,816 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\vmnetadapter.sys
[2010/11/12 21:46:10 | 000,013,104 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\vnetinst.dll
[2010/11/12 21:45:57 | 000,121,392 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetdhcp.exe
[2010/11/12 21:45:52 | 000,150,064 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnat.exe
[2010/11/12 21:45:51 | 000,025,136 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\vmnetuserif.sys
[2010/11/12 21:45:46 | 000,028,592 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\vmnetbridge.sys
[2010/11/12 21:45:43 | 000,050,992 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge.dll
[2010/11/12 21:45:43 | 000,017,712 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\vmnet.sys
[2010/11/12 21:45:41 | 000,436,784 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vnetlib.dll
[2010/11/12 21:45:16 | 000,020,912 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\VMkbd.sys
[2010/11/11 19:07:55 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\VMware
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(9).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(8).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(7).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(6).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(5).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(4).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(3).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(2).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(11).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(10).dll
[2010/11/11 09:54:19 | 000,000,000 | —D | C] – C:\Config.Msi
[2010/11/11 08:48:13 | 000,003,424 | —- | C] (c't) – C:\WINDOWS\System32\drivers\DirectNT.sys
[2010/11/08 20:11:11 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Application Data\VMware
[2010/11/08 20:05:05 | 000,121,392 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetdhcp(2).exe
[2010/11/08 20:03:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\VMware
[2010/11/08 20:02:44 | 000,000,000 | —D | C] – C:\Program Files\VMware
[2010/11/08 20:02:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\VMware
[2010/11/02 09:02:25 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/11/02 09:02:25 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/11/02 09:02:25 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/11/01 13:14:57 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2010/11/01 13:14:57 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2010/10/31 22:01:00 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/10/31 21:58:11 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Application Data\Google
[2010/10/31 21:56:37 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Local Settings\Application Data\Temp
[2010/10/31 21:56:36 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/10/31 21:56:24 | 000,000,000 | —D | C] – C:\Program Files\Google
[2010/10/31 21:56:24 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Local Settings\Application Data\Google
[2010/10/15 10:35:34 | 000,000,000 | –SD | C] – C:\Documents and Settings\E140462\My Documents\My Shapes
[2010/10/15 10:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ICS
[2010/10/15 10:24:57 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Local Settings\Application Data\Deployment
[2010/10/15 09:47:30 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Adobe
[2010/10/07 12:16:47 | 000,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sermouse.sys
[2010/10/07 07:41:41 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Application Data\Xerox
[2010/09/29 13:12:01 | 000,000,000 | —D | C] – C:\Program Files\XML Notepad 2007
[2010/09/29 13:00:31 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Application Data\WinRAR
[2008/11/21 19:32:04 | 000,069,632 | —- | C] (Juniper Networks) – C:\Documents and Settings\All Users\Application Data\NeoterisSetup.ocx
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 60 Days ==========
[2010/11/28 12:40:09 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\E140462\Desktop\OTL.exe
[2010/11/28 12:32:49 | 000,000,036 | —- | M] () – C:\Documents and Settings\E140462\Local Settings\Application Data\housecall.guid.cache
[2010/11/28 12:21:35 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/28 12:18:02 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/11/28 12:17:00 | 000,000,290 | -H– | M] () – C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/11/28 12:01:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/27 23:55:04 | 000,458,580 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/11/27 23:55:04 | 000,080,556 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/11/27 23:53:01 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/11/27 23:50:50 | 000,000,113 | —- | M] () – C:\WINDOWS\System32\api_hook_list.dat
[2010/11/27 23:50:26 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/27 23:50:26 | 000,000,312 | -HS- | M] () – C:\WINDOWS\tasks\habpswz.job
[2010/11/27 23:50:09 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/26 21:22:27 | 000,063,151 | —- | M] () – C:\WINDOWS\unins001.dat
[2010/11/26 21:22:26 | 000,001,510 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\WinKFP.lnk
[2010/11/26 21:22:26 | 000,001,454 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\NCS-Expert tool.lnk
[2010/11/26 21:22:26 | 000,001,427 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Tool32.lnk
[2010/11/26 21:19:49 | 000,630,217 | —- | M] () – C:\WINDOWS\unins001.exe
[2010/11/26 19:37:40 | 000,034,213 | —- | M] () – C:\Documents and Settings\E140462\Desktop\New Microsoft Office Word Document (2).docx
[2010/11/25 20:36:16 | 000,000,623 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\NcsDummy.lnk
[2010/11/25 19:58:33 | 000,014,149 | —- | M] () – C:\Documents and Settings\E140462\Desktop\body modules.docx
[2010/11/25 19:04:57 | 000,095,885 | —- | M] () – C:\Documents and Settings\E140462\Desktop\fault.pdf
[2010/11/24 18:04:31 | 000,008,568 | —- | M] () – C:\Documents and Settings\E140462\Desktop\INPA-PrintFile - na_aif.pdf
[2010/11/24 18:04:12 | 000,011,774 | —- | M] () – C:\Documents and Settings\E140462\Desktop\INPA-PrintFile - na_id.pdf
[2010/11/24 17:39:51 | 000,029,192 | —- | M] () – C:\Documents and Settings\E140462\Desktop\engine code.pdf
[2010/11/24 15:07:59 | 000,012,507 | —- | M] () – C:\Documents and Settings\E140462\My Documents\WMG Gauge Batteries.docx
[2010/11/24 14:29:20 | 000,002,513 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Weatherford Offline Tracking System.lnk
[2010/11/24 11:35:37 | 000,266,208 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/11/23 21:11:14 | 000,090,539 | —- | M] () – C:\Documents and Settings\E140462\Desktop\print at work.docx
[2010/11/23 14:58:47 | 000,014,565 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Car VA.docx
[2010/11/23 14:08:25 | 000,013,083 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Doc1l.docx
[2010/11/23 11:55:19 | 000,039,418 | —- | M] () – C:\Documents and Settings\E140462\Desktop\delete.docx
[2010/11/23 01:15:43 | 000,000,450 | —- | M] () – C:\Documents and Settings\E140462\Desktop\WORK.lnk
[2010/11/22 08:57:19 | 000,017,255 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Make a copy of the FSW.docx
[2010/11/22 00:13:51 | 000,011,643 | —- | M] () – C:\Documents and Settings\E140462\Desktop\How to rcode modules with NCexpert.docx
[2010/11/21 22:34:21 | 000,000,404 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Bmw stuff.lnk
[2010/11/21 22:08:03 | 000,012,767 | —- | M] () – C:\Documents and Settings\E140462\Desktop\How to read module trace files with NCexpert.docx
[2010/11/21 14:37:04 | 000,113,116 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Doc1.docx
[2010/11/16 22:41:25 | 000,068,855 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Doc2.docx
[2010/11/16 21:18:50 | 000,170,727 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Dme dde.docx
[2010/11/16 20:27:06 | 000,000,205 | —- | M] () – C:\WINDOWS\inpa_ist.ini
[2010/11/16 20:18:32 | 000,000,227 | —- | M] () – C:\Documents and Settings\E140462\bestview.ini
[2010/11/12 21:45:10 | 000,001,024 | —- | M] () – C:\.rnd
[2010/11/12 19:11:00 | 000,001,024 | —- | M] () – C:\Documents and Settings\E140462\My Documents\.rnd
[2010/11/11 09:40:37 | 000,630,217 | —- | M] () – C:\WINDOWS\unins000.exe
[2010/11/10 19:49:12 | 000,004,973 | —- | M] () – C:\WINDOWS\System32\SiteList.xml
[2010/11/10 18:58:50 | 000,098,392 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/11/10 17:41:55 | 000,000,063 | —- | M] () – C:\WINDOWS\WINHELP.BMK
[2010/11/04 12:37:42 | 000,002,521 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Microsoft Office Outlook 2007.lnk
[2010/11/04 10:50:19 | 000,009,002 | RHS- | M] () – C:\Documents and Settings\E140462\ntuser.pol
[2010/11/03 19:22:33 | 000,000,055 | —- | M] () – C:\WINDOWS\SIERRA.INI
[2010/10/31 21:58:03 | 000,001,915 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/10/25 08:00:54 | 000,000,303 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Employee Connect.url
[2010/10/20 14:41:42 | 001,224,704 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Publication1.pub
[2010/10/20 14:05:05 | 000,016,550 | RHS- | M] () – C:\Documents and Settings\All Users\ntuser.pol
[2010/10/19 10:41:44 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/10/18 18:45:08 | 000,988,200 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Publication1.pdf
[2010/10/15 13:08:53 | 000,002,443 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Nucleus 4.1.lnk
[2010/10/15 10:29:48 | 000,000,162 | —- | M] () – C:\WINDOWS\ODBC.INI
[2010/10/01 09:29:26 | 000,000,016 | —- | M] () – C:\WINDOWS\popcinfo.dat
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/11/28 12:32:49 | 000,000,036 | —- | C] () – C:\Documents and Settings\E140462\Local Settings\Application Data\housecall.guid.cache
[2010/11/28 12:21:35 | 000,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/27 23:50:50 | 000,000,113 | —- | C] () – C:\WINDOWS\System32\api_hook_list.dat
[2010/11/26 21:22:26 | 000,001,510 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\WinKFP.lnk
[2010/11/26 21:22:26 | 000,001,454 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\NCS-Expert tool.lnk
[2010/11/26 21:22:26 | 000,001,427 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Tool32.lnk
[2010/11/26 21:22:04 | 000,630,217 | —- | C] () – C:\WINDOWS\unins001.exe
[2010/11/26 21:22:04 | 000,063,151 | —- | C] () – C:\WINDOWS\unins001.dat
[2010/11/26 18:45:25 | 000,034,213 | —- | C] () – C:\Documents and Settings\E140462\Desktop\New Microsoft Office Word Document (2).docx
[2010/11/25 19:58:32 | 000,014,149 | —- | C] () – C:\Documents and Settings\E140462\Desktop\body modules.docx
[2010/11/25 19:04:57 | 000,095,885 | —- | C] () – C:\Documents and Settings\E140462\Desktop\fault.pdf
[2010/11/24 18:04:31 | 000,008,568 | —- | C] () – C:\Documents and Settings\E140462\Desktop\INPA-PrintFile - na_aif.pdf
[2010/11/24 18:04:12 | 000,011,774 | —- | C] () – C:\Documents and Settings\E140462\Desktop\INPA-PrintFile - na_id.pdf
[2010/11/24 17:39:47 | 000,029,192 | —- | C] () – C:\Documents and Settings\E140462\Desktop\engine code.pdf
[2010/11/24 15:07:08 | 000,012,507 | —- | C] () – C:\Documents and Settings\E140462\My Documents\WMG Gauge Batteries.docx
[2010/11/24 09:06:28 | 000,158,528 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/11/23 21:18:32 | 000,001,075 | —- | C] () – C:\Documents and Settings\E140462\Desktop\REVTOR.PFL
[2010/11/23 21:11:13 | 000,090,539 | —- | C] () – C:\Documents and Settings\E140462\Desktop\print at work.docx
[2010/11/23 20:21:22 | 000,000,623 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\NcsDummy.lnk
[2010/11/23 14:58:46 | 000,014,565 | —- | C] () – C:\Documents and Settings\E140462\Desktop\Car VA.docx
[2010/11/23 14:08:24 | 000,013,083 | —- | C] () – C:\Documents and Settings\E140462\Desktop\Doc1l.docx
[2010/11/23 11:55:18 | 000,039,418 | —- | C] () – C:\Documents and Settings\E140462\Desktop\delete.docx
[2010/11/23 01:15:43 | 000,000,450 | —- | C] () – C:\Documents and Settings\E140462\Desktop\WORK.lnk
[2010/11/22 08:57:19 | 000,017,255 | —- | C] () – C:\Documents and Settings\E140462\Desktop\Make a copy of the FSW.docx
[2010/11/21 22:34:21 | 000,000,404 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Bmw stuff.lnk
[2010/11/21 22:08:45 | 000,011,643 | —- | C] () – C:\Documents and Settings\E140462\Desktop\How to rcode modules with NCexpert.docx
[2010/11/21 22:08:03 | 000,012,767 | —- | C] () – C:\Documents and Settings\E140462\Desktop\How to read module trace files with NCexpert.docx
[2010/11/16 22:41:25 | 000,068,855 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Doc2.docx
[2010/11/16 21:18:50 | 000,170,727 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Dme dde.docx
[2010/11/16 20:27:06 | 000,000,205 | —- | C] () – C:\WINDOWS\inpa_ist.ini
[2010/11/16 20:18:19 | 000,000,227 | —- | C] () – C:\Documents and Settings\E140462\bestview.ini
[2010/11/15 16:34:00 | 000,113,116 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Doc1.docx
[2010/11/12 21:45:10 | 000,001,024 | —- | C] () – C:\.rnd
[2010/11/11 09:42:46 | 000,630,217 | —- | C] () – C:\WINDOWS\unins000.exe
[2010/11/10 19:49:12 | 000,004,973 | —- | C] () – C:\WINDOWS\System32\SiteList.xml
[2010/11/10 17:41:53 | 000,000,063 | —- | C] () – C:\WINDOWS\WINHELP.BMK
[2010/11/08 20:04:18 | 000,001,024 | —- | C] () – C:\Documents and Settings\E140462\My Documents\.rnd
[2010/10/31 21:58:03 | 000,001,915 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/10/31 21:56:33 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/31 21:56:32 | 000,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/15 12:04:37 | 000,988,200 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Publication1.pdf
[2010/10/15 10:29:48 | 000,000,162 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/10/14 12:39:26 | 000,002,443 | —- | C] () – C:\Documents and Settings\E140462\Desktop\Nucleus 4.1.lnk
[2010/10/12 18:17:26 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/10/06 19:09:33 | 001,224,704 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Publication1.pub
[2010/09/29 14:23:39 | 000,299,008 | —- | C] () – C:\Documents and Settings\E140462\Desktop\OMATIC.EXE
[2010/09/19 20:01:34 | 000,000,130 | —- | C] () – C:\Documents and Settings\E140462\Local Settings\Application Data\fusioncache.dat
[2010/09/18 15:30:12 | 000,000,055 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2010/09/14 17:09:40 | 000,155,648 | RHS- | C] () – C:\WINDOWS\System32\pstorsvc0.dll
[2010/09/09 12:37:15 | 000,000,105 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2010/09/06 08:53:16 | 000,000,045 | —- | C] () – C:\WINDOWS\UNITC.INI
[2010/09/04 14:30:07 | 004,244,744 | —- | C] () – C:\WINDOWS\System32\qtp-mt334.dll
[2010/09/04 14:30:07 | 000,247,560 | —- | C] () – C:\WINDOWS\System32\prgiso.dll
[2010/09/04 14:30:07 | 000,013,576 | —- | C] () – C:\WINDOWS\System32\wnaspi32.dll
[2010/08/31 16:20:42 | 000,000,300 | —- | C] () – C:\WINDOWS\REDBOOK2.INI
[2010/08/30 19:18:15 | 000,022,528 | —- | C] () – C:\Documents and Settings\E140462\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/30 18:59:11 | 000,000,078 | —- | C] () – C:\WINDOWS\init.ini
[2010/08/24 12:57:39 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2010/08/24 12:53:42 | 000,000,251 | —- | C] () – C:\WINDOWS\System32\drivers\hlldrvr.sys
[2010/08/24 12:53:17 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\cwbrw.dll
[2010/08/24 12:53:17 | 000,020,528 | —- | C] () – C:\WINDOWS\System32\cwbwiz.dll
[2010/08/24 12:53:17 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\cwbad.dll
[2010/08/24 12:53:16 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\cwbsv.dll
[2010/08/24 12:53:16 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\cwbsy.dll
[2010/08/24 12:53:16 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\cwbnl.dll
[2010/08/24 12:53:16 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\cwbco.dll
[2010/08/24 12:53:16 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\cwbnldlg.dll
[2010/08/24 10:04:24 | 001,843,784 | —- | C] () – C:\WINDOWS\System32\igklg400.dll
[2010/08/24 10:04:24 | 001,399,880 | —- | C] () – C:\WINDOWS\System32\igklg450.dll
[2010/08/24 10:04:24 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2010/08/24 10:04:24 | 000,104,636 | —- | C] () – C:\WINDOWS\System32\igmedcompkrn.dll
[2010/08/24 09:59:39 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/04/14 07:00:00 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2008/04/14 07:00:00 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2008/04/14 07:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2008/04/14 07:00:00 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2008/04/14 07:00:00 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2004/12/15 17:54:04 | 000,000,269 | —- | C] () – C:\WINDOWS\System32\FTD2XXUN.ini
[2002/10/06 18:42:57 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 23:04:25 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\vorbisenc.dll
[2002/10/04 23:04:24 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 23:04:17 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
========== LOP Check ==========
[2010/09/07 17:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2010/08/30 18:57:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2010/09/07 17:39:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2010/08/24 12:58:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2010/09/30 12:33:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/10/18 16:12:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/09/18 12:27:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/09/14 17:39:15 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/11/26 07:22:39 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\ICAClient
[2010/09/07 18:16:57 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\ImgBurn
[2010/08/30 17:14:37 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Juniper Networks
[2010/09/17 21:15:12 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Quest3D
[2010/09/17 21:15:12 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Roaming
[2010/09/09 19:37:24 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Weatherford
[2010/10/07 07:41:41 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Xerox
[2010/11/27 23:53:01 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/11/27 23:50:26 | 000,000,312 | -HS- | M] () – C:\WINDOWS\Tasks\habpswz.job
[2010/11/28 12:21:35 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/11/28 12:17:00 | 000,000,290 | -H– | M] () – C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/11/12 21:45:10 | 000,001,024 | —- | M] () – C:\.rnd
[2010/11/27 23:49:59 | 000,026,003 | —- | M] () – C:\aaw7boot.log
[2010/08/24 09:20:06 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/08/24 09:05:58 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/08/24 09:20:06 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/08/24 09:20:06 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/09/18 13:29:06 | 016,777,234 | —- | M] () – C:\MRMRender.tga
[2010/08/24 09:20:06 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 07:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/11/27 23:50:01 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/08/24 09:19:41 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
[2010/09/08 10:21:24 | 000,097,949 | —- | M] () – C:\WINDOWS\system32\AITYAHIA.jpg
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/08/24 09:57:32 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/08/24 09:57:32 | 001,089,536 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/08/24 09:57:32 | 000,929,792 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/24 09:20:13 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/24 11:15:08 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/08/24 11:15:08 | 000,000,079 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2001/02/06 19:55:14 | 000,581,632 | —- | M] (Joshua F. Madison) – C:\Documents and Settings\E140462\Desktop\Convert1.exe
[1997/11/02 21:50:38 | 000,299,008 | —- | M] () – C:\Documents and Settings\E140462\Desktop\OMATIC.EXE
[2010/11/28 12:40:09 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\E140462\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >[/b
OTL logfile created on: 28/11/2010 12:42:27 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\E140462\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68.18 Gb Total Space | 32.87 Gb Free Space | 48.21% Space Free | Partition Type: NTFS
Drive E: | 10.15 Gb Total Space | 5.34 Gb Free Space | 52.65% Space Free | Partition Type: NTFS
Drive G: | 70.72 Gb Total Space | 8.27 Gb Free Space | 11.70% Space Free | Partition Type: NTFS
Computer Name: ABDL_JCMQ04J | User Name: E140462 | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\E140462\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Documents and Settings\E140462\Local Settings\Temp\HouseCall\housecall.bin (Trend Micro Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\McAfee\Common Framework\McScript_InUse.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Program Files\Windows Live\Toolbar\wltuser.exe (Microsoft Corporation)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe (McAfee, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\ssonsvr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe (McAfee, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
PRC - C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe (Juniper Networks)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
PRC - G:\Program Files\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
PRC - G:\Program Files\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
PRC - G:\Program Files\VMware\VMware Workstation\hqtray.exe (VMware, Inc.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe (VMware, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\E140462\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\hccutils.dll (Intel Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
SRV - (mfevtp) – C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McTaskManager) – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
SRV - (McAfeeEngineService) – C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe (McAfee, Inc.)
SRV - (enterceptAgent) – C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe (McAfee, Inc.)
SRV - (hips) – C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe (McAfee, Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
SRV - (dsNcService) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (JuniperAccessService) – C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe (Juniper Networks)
SRV - (VMnetDHCP) – C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMware NAT Service) – C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
SRV - (VMAuthdService) – G:\Program Files\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
SRV - (ufad-ws60) – G:\Program Files\VMware\VMware Workstation\vmware-ufad.exe (VMware, Inc.)
SRV - (STacSV) – C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)
SRV - (vmount2) – C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe (VMware, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (Cwbrxd) – C:\WINDOWS\cwbrxd.exe (IBM Corporation)
========== Driver Services (SafeList) ==========
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdik) – C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (firelm01) – C:\WINDOWS\system32\drivers\firelm01.sys (McAfee, Inc.)
DRV - (FireTDI) – C:\WINDOWS\system32\drivers\FireTDI.sys (McAfee, Inc.)
DRV - (FirePM) – C:\WINDOWS\system32\Drivers\FirePM.sys (McAfee, Inc.)
DRV - (HIPQK) – C:\WINDOWS\system32\drivers\HIPQK.sys (McAfee, Inc.)
DRV - (HIPPSK) – C:\WINDOWS\system32\drivers\HIPPSK.sys (McAfee, Inc.)
DRV - (HIPK) – C:\WINDOWS\system32\drivers\HIPK.sys (McAfee, Inc.)
DRV - (NEOFLTR_610_13733) Juniper Networks TDI Filter Driver (NEOFLTR_610_13733) – C:\WINDOWS\system32\drivers\NEOFLTR_610_13733.sys (Juniper Networks)
DRV - (dsNcAdpt) – C:\WINDOWS\system32\drivers\dsNcAdpt.sys (Juniper Networks)
DRV - (FirehkMP) – C:\WINDOWS\system32\drivers\firehk.sys (McAfee, Inc.)
DRV - (Firehk) – C:\WINDOWS\system32\drivers\firehk.sys (McAfee, Inc.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (hcmon) – C:\WINDOWS\system32\drivers\hcmon.sys (VMware, Inc.)
DRV - (vmx86) – C:\WINDOWS\system32\drivers\vmx86.sys (VMware, Inc.)
DRV - (VMnetuserif) – C:\WINDOWS\system32\drivers\vmnetuserif.sys (VMware, Inc.)
DRV - (vmkbd) – C:\WINDOWS\system32\drivers\VMkbd.sys (VMware, Inc.)
DRV - (VMnetBridge) – C:\WINDOWS\system32\drivers\vmnetbridge.sys (VMware, Inc.)
DRV - (VMnetAdapter) – C:\WINDOWS\system32\drivers\vmnetadapter.sys (VMware, Inc.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (vstor2-ws60) – G:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys (VMware, Inc.)
DRV - (NETw4x32) Intel® – C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (hotcore3) – C:\WINDOWS\system32\drivers\hotcore3.sys (Paragon Software Group)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (guardian2) – C:\WINDOWS\system32\drivers\oz776.sys (O2Micro)
DRV - (vstor2) – C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys (VMware, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (FTD2XX) – C:\WINDOWS\system32\drivers\FTD2XX.sys (FTDI Ltd.)
DRV - (DirectNT) – C:\WINDOWS\System32\drivers\DirectNT.sys (c't)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://intranet/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2010/11/27 21:44:34 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Client Access Check Version] C:\Program Files\IBM\Client Access\cwbckver.exe (IBM Corporation)
O4 - HKLM..\Run: [Client Access Express Welcome] C:\Program Files\IBM\Client Access\cwbwlwiz.exe (IBM Corporation)
O4 - HKLM..\Run: [Client Access Help Update] C:\Program Files\IBM\Client Access\cwbinhlp.exe (IBM Corporation)
O4 - HKLM..\Run: [Client Access PC5250 Sound] C:\Program Files\IBM\Client Access\Emulator\pcssnd.exe (IBM Corporation)
O4 - HKLM..\Run: [Client Access Service] C:\Program Files\IBM\Client Access\cwbsvstr.exe (IBM Corporation)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [McAfee Host Intrusion Prevention Tray] C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [VMware hqtray] G:\Program Files\VMware\VMware Workstation\hqtray.exe (VMware, Inc.)
O4 - HKLM..\Run: [vmware-tray] G:\Program Files\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: 515crpweb ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: 515crpwebcapture ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: 515opweb ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: 515opwebcapture ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: techno-media.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([515endweb] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([elm] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([elm] https in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([hrmsonline] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([hrmsonline] https in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([hrtstapp01] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([hrtstapp01] https in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([intranet] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([intranettest] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([pdmdv] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([pdmpd] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([pdmpy] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([psoftelm] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([psoftelm] https in Trusted sites)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1282655466752 (WUWebControl Class)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupSP1 Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wft.root.loc
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\E140462\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\E140462\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/24 09:20:06 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\##Uk-data#abd_tt\Shell - "" = AutoRun
O33 - MountPoints2\##Uk-data#abd_tt\Shell\AuTOplay\COmmand - "" = xnuhwp.pif
O33 - MountPoints2\##Uk-data#abd_tt\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\##Uk-data#abd_tt\Shell\AutoRun\command - "" = xnuhwp.pif
O33 - MountPoints2\##Uk-data#abd_tt\Shell\ExPLOre\cOmmanD - "" = xnuhwp.pif
O33 - MountPoints2\##Uk-data#abd_tt\Shell\oPEn\CoMMANd - "" = xnuhwp.pif
O33 - MountPoints2\{ee1abd06-f038-11df-a114-005056c00001}\Shell - "" = Autorun
O33 - MountPoints2\{ee1abd06-f038-11df-a114-005056c00001}\Shell\AutoRun\command - "" = H:\Install_Nokia_Ovi_Suite.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: VIDC.VMnc - C:\WINDOWS\System32\vmnc.dll (VMware, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55182706186649600)
========== Files/Folders - Created Within 60 Days ==========
[2010/11/28 12:40:01 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\E140462\Desktop\OTL.exe
[2010/11/28 12:19:23 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/11/28 12:18:24 | 000,000,000 | —D | C] – C:\Program Files\Windows Defender
[2010/11/27 23:50:49 | 000,038,528 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\HIPIS0e011a2.dll
[2010/11/26 21:22:03 | 000,000,000 | —D | C] – C:\NFS-Backup
[2010/11/26 21:22:03 | 000,000,000 | —D | C] – C:\NCSEXPER
[2010/11/26 21:22:03 | 000,000,000 | —D | C] – C:\Entwicklungsdaten
[2010/11/26 21:22:03 | 000,000,000 | —D | C] – C:\EDIABAS
[2010/11/26 19:46:27 | 000,000,000 | —D | C] – C:\NCSEXPER(2)
[2010/11/26 19:36:34 | 000,000,000 | —D | C] – C:\NCSEXPER(3)
[2010/11/26 19:36:34 | 000,000,000 | —D | C] – C:\EDIABAS(2)
[2010/11/26 18:48:14 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\lma
[2010/11/26 18:47:57 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\cas
[2010/11/26 16:11:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2010/11/24 09:05:56 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2010/11/24 09:05:42 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2010/11/24 09:04:33 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2010/11/24 09:04:33 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2010/11/24 09:04:33 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2010/11/24 09:04:33 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2010/11/24 09:04:33 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2010/11/24 09:04:33 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2010/11/24 09:04:32 | 000,000,000 | —D | C] – C:\ed83c0a3c21fea46856c3dda2633
[2010/11/23 17:53:50 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\FSW files
[2010/11/23 13:45:25 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\read
[2010/11/22 00:53:44 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\print
[2010/11/18 08:50:15 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\Storengy CE19
[2010/11/18 08:49:58 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\Job Folder
[2010/11/15 00:12:28 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\My Documents\My Virtual Machines
[2010/11/14 23:52:13 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\Bmw stuff
[2010/11/14 20:43:02 | 000,000,000 | —D | C] – C:\Program Files\BMW Diagnostic Head Emulator
[2010/11/14 19:53:56 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\My Documents\ADS
[2010/11/14 19:37:48 | 000,000,000 | —D | C] – C:\EC-APPS
[2010/11/14 18:34:44 | 000,000,000 | —D | C] – C:\INPA
[2010/11/12 21:46:10 | 000,016,816 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\vmnetadapter.sys
[2010/11/12 21:46:10 | 000,013,104 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\vnetinst.dll
[2010/11/12 21:45:57 | 000,121,392 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetdhcp.exe
[2010/11/12 21:45:52 | 000,150,064 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnat.exe
[2010/11/12 21:45:51 | 000,025,136 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\vmnetuserif.sys
[2010/11/12 21:45:46 | 000,028,592 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\vmnetbridge.sys
[2010/11/12 21:45:43 | 000,050,992 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge.dll
[2010/11/12 21:45:43 | 000,017,712 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\vmnet.sys
[2010/11/12 21:45:41 | 000,436,784 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vnetlib.dll
[2010/11/12 21:45:16 | 000,020,912 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\VMkbd.sys
[2010/11/11 19:07:55 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\VMware
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(9).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(8).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(7).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(6).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(5).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(4).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(3).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(2).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(11).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(10).dll
[2010/11/11 09:54:19 | 000,000,000 | —D | C] – C:\Config.Msi
[2010/11/11 08:48:13 | 000,003,424 | —- | C] (c't) – C:\WINDOWS\System32\drivers\DirectNT.sys
[2010/11/08 20:11:11 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Application Data\VMware
[2010/11/08 20:05:05 | 000,121,392 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetdhcp(2).exe
[2010/11/08 20:03:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\VMware
[2010/11/08 20:02:44 | 000,000,000 | —D | C] – C:\Program Files\VMware
[2010/11/08 20:02:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\VMware
[2010/11/02 09:02:25 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/11/02 09:02:25 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/11/02 09:02:25 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/11/01 13:14:57 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2010/11/01 13:14:57 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2010/10/31 22:01:00 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/10/31 21:58:11 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Application Data\Google
[2010/10/31 21:56:37 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Local Settings\Application Data\Temp
[2010/10/31 21:56:36 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/10/31 21:56:24 | 000,000,000 | —D | C] – C:\Program Files\Google
[2010/10/31 21:56:24 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Local Settings\Application Data\Google
[2010/10/15 10:35:34 | 000,000,000 | –SD | C] – C:\Documents and Settings\E140462\My Documents\My Shapes
[2010/10/15 10:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ICS
[2010/10/15 10:24:57 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Local Settings\Application Data\Deployment
[2010/10/15 09:47:30 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Adobe
[2010/10/07 12:16:47 | 000,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sermouse.sys
[2010/10/07 07:41:41 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Application Data\Xerox
[2010/09/29 13:12:01 | 000,000,000 | —D | C] – C:\Program Files\XML Notepad 2007
[2010/09/29 13:00:31 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Application Data\WinRAR
[2008/11/21 19:32:04 | 000,069,632 | —- | C] (Juniper Networks) – C:\Documents and Settings\All Users\Application Data\NeoterisSetup.ocx
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 60 Days ==========
[2010/11/28 12:40:09 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\E140462\Desktop\OTL.exe
[2010/11/28 12:32:49 | 000,000,036 | —- | M] () – C:\Documents and Settings\E140462\Local Settings\Application Data\housecall.guid.cache
[2010/11/28 12:21:35 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/28 12:18:02 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/11/28 12:17:00 | 000,000,290 | -H– | M] () – C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/11/28 12:01:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/27 23:55:04 | 000,458,580 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/11/27 23:55:04 | 000,080,556 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/11/27 23:53:01 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/11/27 23:50:50 | 000,000,113 | —- | M] () – C:\WINDOWS\System32\api_hook_list.dat
[2010/11/27 23:50:26 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/27 23:50:26 | 000,000,312 | -HS- | M] () – C:\WINDOWS\tasks\habpswz.job
[2010/11/27 23:50:09 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/26 21:22:27 | 000,063,151 | —- | M] () – C:\WINDOWS\unins001.dat
[2010/11/26 21:22:26 | 000,001,510 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\WinKFP.lnk
[2010/11/26 21:22:26 | 000,001,454 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\NCS-Expert tool.lnk
[2010/11/26 21:22:26 | 000,001,427 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Tool32.lnk
[2010/11/26 21:19:49 | 000,630,217 | —- | M] () – C:\WINDOWS\unins001.exe
[2010/11/26 19:37:40 | 000,034,213 | —- | M] () – C:\Documents and Settings\E140462\Desktop\New Microsoft Office Word Document (2).docx
[2010/11/25 20:36:16 | 000,000,623 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\NcsDummy.lnk
[2010/11/25 19:58:33 | 000,014,149 | —- | M] () – C:\Documents and Settings\E140462\Desktop\body modules.docx
[2010/11/25 19:04:57 | 000,095,885 | —- | M] () – C:\Documents and Settings\E140462\Desktop\fault.pdf
[2010/11/24 18:04:31 | 000,008,568 | —- | M] () – C:\Documents and Settings\E140462\Desktop\INPA-PrintFile - na_aif.pdf
[2010/11/24 18:04:12 | 000,011,774 | —- | M] () – C:\Documents and Settings\E140462\Desktop\INPA-PrintFile - na_id.pdf
[2010/11/24 17:39:51 | 000,029,192 | —- | M] () – C:\Documents and Settings\E140462\Desktop\engine code.pdf
[2010/11/24 15:07:59 | 000,012,507 | —- | M] () – C:\Documents and Settings\E140462\My Documents\WMG Gauge Batteries.docx
[2010/11/24 14:29:20 | 000,002,513 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Weatherford Offline Tracking System.lnk
[2010/11/24 11:35:37 | 000,266,208 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/11/23 21:11:14 | 000,090,539 | —- | M] () – C:\Documents and Settings\E140462\Desktop\print at work.docx
[2010/11/23 14:58:47 | 000,014,565 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Car VA.docx
[2010/11/23 14:08:25 | 000,013,083 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Doc1l.docx
[2010/11/23 11:55:19 | 000,039,418 | —- | M] () – C:\Documents and Settings\E140462\Desktop\delete.docx
[2010/11/23 01:15:43 | 000,000,450 | —- | M] () – C:\Documents and Settings\E140462\Desktop\WORK.lnk
[2010/11/22 08:57:19 | 000,017,255 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Make a copy of the FSW.docx
[2010/11/22 00:13:51 | 000,011,643 | —- | M] () – C:\Documents and Settings\E140462\Desktop\How to rcode modules with NCexpert.docx
[2010/11/21 22:34:21 | 000,000,404 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Bmw stuff.lnk
[2010/11/21 22:08:03 | 000,012,767 | —- | M] () – C:\Documents and Settings\E140462\Desktop\How to read module trace files with NCexpert.docx
[2010/11/21 14:37:04 | 000,113,116 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Doc1.docx
[2010/11/16 22:41:25 | 000,068,855 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Doc2.docx
[2010/11/16 21:18:50 | 000,170,727 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Dme dde.docx
[2010/11/16 20:27:06 | 000,000,205 | —- | M] () – C:\WINDOWS\inpa_ist.ini
[2010/11/16 20:18:32 | 000,000,227 | —- | M] () – C:\Documents and Settings\E140462\bestview.ini
[2010/11/12 21:45:10 | 000,001,024 | —- | M] () – C:\.rnd
[2010/11/12 19:11:00 | 000,001,024 | —- | M] () – C:\Documents and Settings\E140462\My Documents\.rnd
[2010/11/11 09:40:37 | 000,630,217 | —- | M] () – C:\WINDOWS\unins000.exe
[2010/11/10 19:49:12 | 000,004,973 | —- | M] () – C:\WINDOWS\System32\SiteList.xml
[2010/11/10 18:58:50 | 000,098,392 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/11/10 17:41:55 | 000,000,063 | —- | M] () – C:\WINDOWS\WINHELP.BMK
[2010/11/04 12:37:42 | 000,002,521 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Microsoft Office Outlook 2007.lnk
[2010/11/04 10:50:19 | 000,009,002 | RHS- | M] () – C:\Documents and Settings\E140462\ntuser.pol
[2010/11/03 19:22:33 | 000,000,055 | —- | M] () – C:\WINDOWS\SIERRA.INI
[2010/10/31 21:58:03 | 000,001,915 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/10/25 08:00:54 | 000,000,303 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Employee Connect.url
[2010/10/20 14:41:42 | 001,224,704 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Publication1.pub
[2010/10/20 14:05:05 | 000,016,550 | RHS- | M] () – C:\Documents and Settings\All Users\ntuser.pol
[2010/10/19 10:41:44 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/10/18 18:45:08 | 000,988,200 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Publication1.pdf
[2010/10/15 13:08:53 | 000,002,443 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Nucleus 4.1.lnk
[2010/10/15 10:29:48 | 000,000,162 | —- | M] () – C:\WINDOWS\ODBC.INI
[2010/10/01 09:29:26 | 000,000,016 | —- | M] () – C:\WINDOWS\popcinfo.dat
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/11/28 12:32:49 | 000,000,036 | —- | C] () – C:\Documents and Settings\E140462\Local Settings\Application Data\housecall.guid.cache
[2010/11/28 12:21:35 | 000,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/27 23:50:50 | 000,000,113 | —- | C] () – C:\WINDOWS\System32\api_hook_list.dat
[2010/11/26 21:22:26 | 000,001,510 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\WinKFP.lnk
[2010/11/26 21:22:26 | 000,001,454 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\NCS-Expert tool.lnk
[2010/11/26 21:22:26 | 000,001,427 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Tool32.lnk
[2010/11/26 21:22:04 | 000,630,217 | —- | C] () – C:\WINDOWS\unins001.exe
[2010/11/26 21:22:04 | 000,063,151 | —- | C] () – C:\WINDOWS\unins001.dat
[2010/11/26 18:45:25 | 000,034,213 | —- | C] () – C:\Documents and Settings\E140462\Desktop\New Microsoft Office Word Document (2).docx
[2010/11/25 19:58:32 | 000,014,149 | —- | C] () – C:\Documents and Settings\E140462\Desktop\body modules.docx
[2010/11/25 19:04:57 | 000,095,885 | —- | C] () – C:\Documents and Settings\E140462\Desktop\fault.pdf
[2010/11/24 18:04:31 | 000,008,568 | —- | C] () – C:\Documents and Settings\E140462\Desktop\INPA-PrintFile - na_aif.pdf
[2010/11/24 18:04:12 | 000,011,774 | —- | C] () – C:\Documents and Settings\E140462\Desktop\INPA-PrintFile - na_id.pdf
[2010/11/24 17:39:47 | 000,029,192 | —- | C] () – C:\Documents and Settings\E140462\Desktop\engine code.pdf
[2010/11/24 15:07:08 | 000,012,507 | —- | C] () – C:\Documents and Settings\E140462\My Documents\WMG Gauge Batteries.docx
[2010/11/24 09:06:28 | 000,158,528 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/11/23 21:18:32 | 000,001,075 | —- | C] () – C:\Documents and Settings\E140462\Desktop\REVTOR.PFL
[2010/11/23 21:11:13 | 000,090,539 | —- | C] () – C:\Documents and Settings\E140462\Desktop\print at work.docx
[2010/11/23 20:21:22 | 000,000,623 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\NcsDummy.lnk
[2010/11/23 14:58:46 | 000,014,565 | —- | C] () – C:\Documents and Settings\E140462\Desktop\Car VA.docx
[2010/11/23 14:08:24 | 000,013,083 | —- | C] () – C:\Documents and Settings\E140462\Desktop\Doc1l.docx
[2010/11/23 11:55:18 | 000,039,418 | —- | C] () – C:\Documents and Settings\E140462\Desktop\delete.docx
[2010/11/23 01:15:43 | 000,000,450 | —- | C] () – C:\Documents and Settings\E140462\Desktop\WORK.lnk
[2010/11/22 08:57:19 | 000,017,255 | —- | C] () – C:\Documents and Settings\E140462\Desktop\Make a copy of the FSW.docx
[2010/11/21 22:34:21 | 000,000,404 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Bmw stuff.lnk
[2010/11/21 22:08:45 | 000,011,643 | —- | C] () – C:\Documents and Settings\E140462\Desktop\How to rcode modules with NCexpert.docx
[2010/11/21 22:08:03 | 000,012,767 | —- | C] () – C:\Documents and Settings\E140462\Desktop\How to read module trace files with NCexpert.docx
[2010/11/16 22:41:25 | 000,068,855 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Doc2.docx
[2010/11/16 21:18:50 | 000,170,727 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Dme dde.docx
[2010/11/16 20:27:06 | 000,000,205 | —- | C] () – C:\WINDOWS\inpa_ist.ini
[2010/11/16 20:18:19 | 000,000,227 | —- | C] () – C:\Documents and Settings\E140462\bestview.ini
[2010/11/15 16:34:00 | 000,113,116 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Doc1.docx
[2010/11/12 21:45:10 | 000,001,024 | —- | C] () – C:\.rnd
[2010/11/11 09:42:46 | 000,630,217 | —- | C] () – C:\WINDOWS\unins000.exe
[2010/11/10 19:49:12 | 000,004,973 | —- | C] () – C:\WINDOWS\System32\SiteList.xml
[2010/11/10 17:41:53 | 000,000,063 | —- | C] () – C:\WINDOWS\WINHELP.BMK
[2010/11/08 20:04:18 | 000,001,024 | —- | C] () – C:\Documents and Settings\E140462\My Documents\.rnd
[2010/10/31 21:58:03 | 000,001,915 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/10/31 21:56:33 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/31 21:56:32 | 000,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/15 12:04:37 | 000,988,200 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Publication1.pdf
[2010/10/15 10:29:48 | 000,000,162 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/10/14 12:39:26 | 000,002,443 | —- | C] () – C:\Documents and Settings\E140462\Desktop\Nucleus 4.1.lnk
[2010/10/12 18:17:26 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/10/06 19:09:33 | 001,224,704 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Publication1.pub
[2010/09/29 14:23:39 | 000,299,008 | —- | C] () – C:\Documents and Settings\E140462\Desktop\OMATIC.EXE
[2010/09/19 20:01:34 | 000,000,130 | —- | C] () – C:\Documents and Settings\E140462\Local Settings\Application Data\fusioncache.dat
[2010/09/18 15:30:12 | 000,000,055 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2010/09/14 17:09:40 | 000,155,648 | RHS- | C] () – C:\WINDOWS\System32\pstorsvc0.dll
[2010/09/09 12:37:15 | 000,000,105 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2010/09/06 08:53:16 | 000,000,045 | —- | C] () – C:\WINDOWS\UNITC.INI
[2010/09/04 14:30:07 | 004,244,744 | —- | C] () – C:\WINDOWS\System32\qtp-mt334.dll
[2010/09/04 14:30:07 | 000,247,560 | —- | C] () – C:\WINDOWS\System32\prgiso.dll
[2010/09/04 14:30:07 | 000,013,576 | —- | C] () – C:\WINDOWS\System32\wnaspi32.dll
[2010/08/31 16:20:42 | 000,000,300 | —- | C] () – C:\WINDOWS\REDBOOK2.INI
[2010/08/30 19:18:15 | 000,022,528 | —- | C] () – C:\Documents and Settings\E140462\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/30 18:59:11 | 000,000,078 | —- | C] () – C:\WINDOWS\init.ini
[2010/08/24 12:57:39 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2010/08/24 12:53:42 | 000,000,251 | —- | C] () – C:\WINDOWS\System32\drivers\hlldrvr.sys
[2010/08/24 12:53:17 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\cwbrw.dll
[2010/08/24 12:53:17 | 000,020,528 | —- | C] () – C:\WINDOWS\System32\cwbwiz.dll
[2010/08/24 12:53:17 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\cwbad.dll
[2010/08/24 12:53:16 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\cwbsv.dll
[2010/08/24 12:53:16 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\cwbsy.dll
[2010/08/24 12:53:16 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\cwbnl.dll
[2010/08/24 12:53:16 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\cwbco.dll
[2010/08/24 12:53:16 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\cwbnldlg.dll
[2010/08/24 10:04:24 | 001,843,784 | —- | C] () – C:\WINDOWS\System32\igklg400.dll
[2010/08/24 10:04:24 | 001,399,880 | —- | C] () – C:\WINDOWS\System32\igklg450.dll
[2010/08/24 10:04:24 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2010/08/24 10:04:24 | 000,104,636 | —- | C] () – C:\WINDOWS\System32\igmedcompkrn.dll
[2010/08/24 09:59:39 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/04/14 07:00:00 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2008/04/14 07:00:00 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2008/04/14 07:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2008/04/14 07:00:00 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2008/04/14 07:00:00 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2004/12/15 17:54:04 | 000,000,269 | —- | C] () – C:\WINDOWS\System32\FTD2XXUN.ini
[2002/10/06 18:42:57 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 23:04:25 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\vorbisenc.dll
[2002/10/04 23:04:24 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 23:04:17 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
========== LOP Check ==========
[2010/09/07 17:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2010/08/30 18:57:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2010/09/07 17:39:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2010/08/24 12:58:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2010/09/30 12:33:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/10/18 16:12:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/09/18 12:27:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/09/14 17:39:15 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/11/26 07:22:39 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\ICAClient
[2010/09/07 18:16:57 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\ImgBurn
[2010/08/30 17:14:37 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Juniper Networks
[2010/09/17 21:15:12 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Quest3D
[2010/09/17 21:15:12 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Roaming
[2010/09/09 19:37:24 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Weatherford
[2010/10/07 07:41:41 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Xerox
[2010/11/27 23:53:01 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/11/27 23:50:26 | 000,000,312 | -HS- | M] () – C:\WINDOWS\Tasks\habpswz.job
[2010/11/28 12:21:35 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/11/28 12:17:00 | 000,000,290 | -H– | M] () – C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/11/12 21:45:10 | 000,001,024 | —- | M] () – C:\.rnd
[2010/11/27 23:49:59 | 000,026,003 | —- | M] () – C:\aaw7boot.log
[2010/08/24 09:20:06 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/08/24 09:05:58 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/08/24 09:20:06 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/08/24 09:20:06 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/09/18 13:29:06 | 016,777,234 | —- | M] () – C:\MRMRender.tga
[2010/08/24 09:20:06 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 07:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/11/27 23:50:01 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/08/24 09:19:41 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
[2010/09/08 10:21:24 | 000,097,949 | —- | M] () – C:\WINDOWS\system32\AITYAHIA.jpg
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/08/24 09:57:32 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/08/24 09:57:32 | 001,089,536 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/08/24 09:57:32 | 000,929,792 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/24 09:20:13 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/24 11:15:08 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/08/24 11:15:08 | 000,000,079 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2001/02/06 19:55:14 | 000,581,632 | —- | M] (Joshua F. Madison) – C:\Documents and Settings\E140462\Desktop\Convert1.exe
[1997/11/02 21:50:38 | 000,299,008 | —- | M] () – C:\Documents and Settings\E140462\Desktop\OMATIC.EXE
[2010/11/28 12:40:09 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\E140462\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >[/b