This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help please.. browser hihacked ,OTL print out enclosed

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

]Help please… my computers got a browser hijacker,every time i try to open up a link on google it take sme somewhere random :( doing my nut in …..heres the OTL print out..and the thanks in advance .

OTL logfile created on: 28/11/2010 12:42:27 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\E140462\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68.18 Gb Total Space | 32.87 Gb Free Space | 48.21% Space Free | Partition Type: NTFS
Drive E: | 10.15 Gb Total Space | 5.34 Gb Free Space | 52.65% Space Free | Partition Type: NTFS
Drive G: | 70.72 Gb Total Space | 8.27 Gb Free Space | 11.70% Space Free | Partition Type: NTFS

Computer Name: ABDL_JCMQ04J | User Name: E140462 | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\E140462\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Documents and Settings\E140462\Local Settings\Temp\HouseCall\housecall.bin (Trend Micro Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\McAfee\Common Framework\McScript_InUse.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Program Files\Windows Live\Toolbar\wltuser.exe (Microsoft Corporation)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe (McAfee, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\ssonsvr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe (McAfee, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
PRC - C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe (Juniper Networks)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
PRC - G:\Program Files\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
PRC - G:\Program Files\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
PRC - G:\Program Files\VMware\VMware Workstation\hqtray.exe (VMware, Inc.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe (VMware, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\E140462\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\hccutils.dll (Intel Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe (McAfee, Inc.)
SRV - (mfevtp) – C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McTaskManager) – C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe (McAfee, Inc.)
SRV - (McAfeeEngineService) – C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe (McAfee, Inc.)
SRV - (enterceptAgent) – C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe (McAfee, Inc.)
SRV - (hips) – C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe (McAfee, Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
SRV - (dsNcService) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (JuniperAccessService) – C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe (Juniper Networks)
SRV - (VMnetDHCP) – C:\WINDOWS\system32\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMware NAT Service) – C:\WINDOWS\system32\vmnat.exe (VMware, Inc.)
SRV - (VMAuthdService) – G:\Program Files\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
SRV - (ufad-ws60) – G:\Program Files\VMware\VMware Workstation\vmware-ufad.exe (VMware, Inc.)
SRV - (STacSV) – C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\stacsv.exe (SigmaTel, Inc.)
SRV - (vmount2) – C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe (VMware, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (Cwbrxd) – C:\WINDOWS\cwbrxd.exe (IBM Corporation)


========== Driver Services (SafeList) ==========

DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdik) – C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (firelm01) – C:\WINDOWS\system32\drivers\firelm01.sys (McAfee, Inc.)
DRV - (FireTDI) – C:\WINDOWS\system32\drivers\FireTDI.sys (McAfee, Inc.)
DRV - (FirePM) – C:\WINDOWS\system32\Drivers\FirePM.sys (McAfee, Inc.)
DRV - (HIPQK) – C:\WINDOWS\system32\drivers\HIPQK.sys (McAfee, Inc.)
DRV - (HIPPSK) – C:\WINDOWS\system32\drivers\HIPPSK.sys (McAfee, Inc.)
DRV - (HIPK) – C:\WINDOWS\system32\drivers\HIPK.sys (McAfee, Inc.)
DRV - (NEOFLTR_610_13733) Juniper Networks TDI Filter Driver (NEOFLTR_610_13733) – C:\WINDOWS\system32\drivers\NEOFLTR_610_13733.sys (Juniper Networks)
DRV - (dsNcAdpt) – C:\WINDOWS\system32\drivers\dsNcAdpt.sys (Juniper Networks)
DRV - (FirehkMP) – C:\WINDOWS\system32\drivers\firehk.sys (McAfee, Inc.)
DRV - (Firehk) – C:\WINDOWS\system32\drivers\firehk.sys (McAfee, Inc.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (hcmon) – C:\WINDOWS\system32\drivers\hcmon.sys (VMware, Inc.)
DRV - (vmx86) – C:\WINDOWS\system32\drivers\vmx86.sys (VMware, Inc.)
DRV - (VMnetuserif) – C:\WINDOWS\system32\drivers\vmnetuserif.sys (VMware, Inc.)
DRV - (vmkbd) – C:\WINDOWS\system32\drivers\VMkbd.sys (VMware, Inc.)
DRV - (VMnetBridge) – C:\WINDOWS\system32\drivers\vmnetbridge.sys (VMware, Inc.)
DRV - (VMnetAdapter) – C:\WINDOWS\system32\drivers\vmnetadapter.sys (VMware, Inc.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (vstor2-ws60) – G:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys (VMware, Inc.)
DRV - (NETw4x32) Intel® – C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (hotcore3) – C:\WINDOWS\system32\drivers\hotcore3.sys (Paragon Software Group)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (guardian2) – C:\WINDOWS\system32\drivers\oz776.sys (O2Micro)
DRV - (vstor2) – C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys (VMware, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (FTD2XX) – C:\WINDOWS\system32\drivers\FTD2XX.sys (FTDI Ltd.)
DRV - (DirectNT) – C:\WINDOWS\System32\drivers\DirectNT.sys (c't)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://intranet/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2010/11/27 21:44:34 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Client Access Check Version] C:\Program Files\IBM\Client Access\cwbckver.exe (IBM Corporation)
O4 - HKLM..\Run: [Client Access Express Welcome] C:\Program Files\IBM\Client Access\cwbwlwiz.exe (IBM Corporation)
O4 - HKLM..\Run: [Client Access Help Update] C:\Program Files\IBM\Client Access\cwbinhlp.exe (IBM Corporation)
O4 - HKLM..\Run: [Client Access PC5250 Sound] C:\Program Files\IBM\Client Access\Emulator\pcssnd.exe (IBM Corporation)
O4 - HKLM..\Run: [Client Access Service] C:\Program Files\IBM\Client Access\cwbsvstr.exe (IBM Corporation)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [McAfee Host Intrusion Prevention Tray] C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [VMware hqtray] G:\Program Files\VMware\VMware Workstation\hqtray.exe (VMware, Inc.)
O4 - HKLM..\Run: [vmware-tray] G:\Program Files\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: 515crpweb ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: 515crpwebcapture ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: 515opweb ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: 515opwebcapture ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: techno-media.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([515endweb] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([elm] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([elm] https in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([hrmsonline] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([hrmsonline] https in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([hrtstapp01] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([hrtstapp01] https in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([intranet] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([intranettest] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([pdmdv] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([pdmpd] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([pdmpy] http in Local intranet)
O15 - HKCU\..Trusted Domains: weatherford.com ([psoftelm] http in Trusted sites)
O15 - HKCU\..Trusted Domains: weatherford.com ([psoftelm] https in Trusted sites)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1282655466752 (WUWebControl Class)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupSP1 Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wft.root.loc
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\E140462\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\E140462\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/24 09:20:06 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\##Uk-data#abd_tt\Shell - "" = AutoRun
O33 - MountPoints2\##Uk-data#abd_tt\Shell\AuTOplay\COmmand - "" = xnuhwp.pif
O33 - MountPoints2\##Uk-data#abd_tt\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\##Uk-data#abd_tt\Shell\AutoRun\command - "" = xnuhwp.pif
O33 - MountPoints2\##Uk-data#abd_tt\Shell\ExPLOre\cOmmanD - "" = xnuhwp.pif
O33 - MountPoints2\##Uk-data#abd_tt\Shell\oPEn\CoMMANd - "" = xnuhwp.pif
O33 - MountPoints2\{ee1abd06-f038-11df-a114-005056c00001}\Shell - "" = Autorun
O33 - MountPoints2\{ee1abd06-f038-11df-a114-005056c00001}\Shell\AutoRun\command - "" = H:\Install_Nokia_Ovi_Suite.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: VIDC.VMnc - C:\WINDOWS\System32\vmnc.dll (VMware, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55182706186649600)

========== Files/Folders - Created Within 60 Days ==========

[2010/11/28 12:40:01 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\E140462\Desktop\OTL.exe
[2010/11/28 12:19:23 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/11/28 12:18:24 | 000,000,000 | —D | C] – C:\Program Files\Windows Defender
[2010/11/27 23:50:49 | 000,038,528 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\HIPIS0e011a2.dll
[2010/11/26 21:22:03 | 000,000,000 | —D | C] – C:\NFS-Backup
[2010/11/26 21:22:03 | 000,000,000 | —D | C] – C:\NCSEXPER
[2010/11/26 21:22:03 | 000,000,000 | —D | C] – C:\Entwicklungsdaten
[2010/11/26 21:22:03 | 000,000,000 | —D | C] – C:\EDIABAS
[2010/11/26 19:46:27 | 000,000,000 | —D | C] – C:\NCSEXPER(2)
[2010/11/26 19:36:34 | 000,000,000 | —D | C] – C:\NCSEXPER(3)
[2010/11/26 19:36:34 | 000,000,000 | —D | C] – C:\EDIABAS(2)
[2010/11/26 18:48:14 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\lma
[2010/11/26 18:47:57 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\cas
[2010/11/26 16:11:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2010/11/24 09:05:56 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2010/11/24 09:05:42 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2010/11/24 09:04:33 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2010/11/24 09:04:33 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2010/11/24 09:04:33 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2010/11/24 09:04:33 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2010/11/24 09:04:33 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2010/11/24 09:04:33 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2010/11/24 09:04:32 | 000,000,000 | —D | C] – C:\ed83c0a3c21fea46856c3dda2633
[2010/11/23 17:53:50 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\FSW files
[2010/11/23 13:45:25 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\read
[2010/11/22 00:53:44 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\print
[2010/11/18 08:50:15 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\Storengy CE19
[2010/11/18 08:49:58 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\Job Folder
[2010/11/15 00:12:28 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\My Documents\My Virtual Machines
[2010/11/14 23:52:13 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Desktop\Bmw stuff
[2010/11/14 20:43:02 | 000,000,000 | —D | C] – C:\Program Files\BMW Diagnostic Head Emulator
[2010/11/14 19:53:56 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\My Documents\ADS
[2010/11/14 19:37:48 | 000,000,000 | —D | C] – C:\EC-APPS
[2010/11/14 18:34:44 | 000,000,000 | —D | C] – C:\INPA
[2010/11/12 21:46:10 | 000,016,816 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\vmnetadapter.sys
[2010/11/12 21:46:10 | 000,013,104 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\vnetinst.dll
[2010/11/12 21:45:57 | 000,121,392 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetdhcp.exe
[2010/11/12 21:45:52 | 000,150,064 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnat.exe
[2010/11/12 21:45:51 | 000,025,136 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\vmnetuserif.sys
[2010/11/12 21:45:46 | 000,028,592 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\vmnetbridge.sys
[2010/11/12 21:45:43 | 000,050,992 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge.dll
[2010/11/12 21:45:43 | 000,017,712 | R— | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\vmnet.sys
[2010/11/12 21:45:41 | 000,436,784 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vnetlib.dll
[2010/11/12 21:45:16 | 000,020,912 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\drivers\VMkbd.sys
[2010/11/11 19:07:55 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\VMware
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(9).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(8).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(7).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(6).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(5).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(4).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(3).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(2).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(11).dll
[2010/11/11 14:30:17 | 000,050,992 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetbridge(10).dll
[2010/11/11 09:54:19 | 000,000,000 | —D | C] – C:\Config.Msi
[2010/11/11 08:48:13 | 000,003,424 | —- | C] (c't) – C:\WINDOWS\System32\drivers\DirectNT.sys
[2010/11/08 20:11:11 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Application Data\VMware
[2010/11/08 20:05:05 | 000,121,392 | —- | C] (VMware, Inc.) – C:\WINDOWS\System32\vmnetdhcp(2).exe
[2010/11/08 20:03:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\VMware
[2010/11/08 20:02:44 | 000,000,000 | —D | C] – C:\Program Files\VMware
[2010/11/08 20:02:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\VMware
[2010/11/02 09:02:25 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/11/02 09:02:25 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/11/02 09:02:25 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/11/01 13:14:57 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2010/11/01 13:14:57 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2010/10/31 22:01:00 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/10/31 21:58:11 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Application Data\Google
[2010/10/31 21:56:37 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Local Settings\Application Data\Temp
[2010/10/31 21:56:36 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/10/31 21:56:24 | 000,000,000 | —D | C] – C:\Program Files\Google
[2010/10/31 21:56:24 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Local Settings\Application Data\Google
[2010/10/15 10:35:34 | 000,000,000 | –SD | C] – C:\Documents and Settings\E140462\My Documents\My Shapes
[2010/10/15 10:25:19 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ICS
[2010/10/15 10:24:57 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Local Settings\Application Data\Deployment
[2010/10/15 09:47:30 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Adobe
[2010/10/07 12:16:47 | 000,017,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sermouse.sys
[2010/10/07 07:41:41 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Application Data\Xerox
[2010/09/29 13:12:01 | 000,000,000 | —D | C] – C:\Program Files\XML Notepad 2007
[2010/09/29 13:00:31 | 000,000,000 | —D | C] – C:\Documents and Settings\E140462\Application Data\WinRAR
[2008/11/21 19:32:04 | 000,069,632 | —- | C] (Juniper Networks) – C:\Documents and Settings\All Users\Application Data\NeoterisSetup.ocx
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 60 Days ==========

[2010/11/28 12:40:09 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\E140462\Desktop\OTL.exe
[2010/11/28 12:32:49 | 000,000,036 | —- | M] () – C:\Documents and Settings\E140462\Local Settings\Application Data\housecall.guid.cache
[2010/11/28 12:21:35 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/28 12:18:02 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/11/28 12:17:00 | 000,000,290 | -H– | M] () – C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/11/28 12:01:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/27 23:55:04 | 000,458,580 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/11/27 23:55:04 | 000,080,556 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/11/27 23:53:01 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/11/27 23:50:50 | 000,000,113 | —- | M] () – C:\WINDOWS\System32\api_hook_list.dat
[2010/11/27 23:50:26 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/27 23:50:26 | 000,000,312 | -HS- | M] () – C:\WINDOWS\tasks\habpswz.job
[2010/11/27 23:50:09 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/26 21:22:27 | 000,063,151 | —- | M] () – C:\WINDOWS\unins001.dat
[2010/11/26 21:22:26 | 000,001,510 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\WinKFP.lnk
[2010/11/26 21:22:26 | 000,001,454 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\NCS-Expert tool.lnk
[2010/11/26 21:22:26 | 000,001,427 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Tool32.lnk
[2010/11/26 21:19:49 | 000,630,217 | —- | M] () – C:\WINDOWS\unins001.exe
[2010/11/26 19:37:40 | 000,034,213 | —- | M] () – C:\Documents and Settings\E140462\Desktop\New Microsoft Office Word Document (2).docx
[2010/11/25 20:36:16 | 000,000,623 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\NcsDummy.lnk
[2010/11/25 19:58:33 | 000,014,149 | —- | M] () – C:\Documents and Settings\E140462\Desktop\body modules.docx
[2010/11/25 19:04:57 | 000,095,885 | —- | M] () – C:\Documents and Settings\E140462\Desktop\fault.pdf
[2010/11/24 18:04:31 | 000,008,568 | —- | M] () – C:\Documents and Settings\E140462\Desktop\INPA-PrintFile - na_aif.pdf
[2010/11/24 18:04:12 | 000,011,774 | —- | M] () – C:\Documents and Settings\E140462\Desktop\INPA-PrintFile - na_id.pdf
[2010/11/24 17:39:51 | 000,029,192 | —- | M] () – C:\Documents and Settings\E140462\Desktop\engine code.pdf
[2010/11/24 15:07:59 | 000,012,507 | —- | M] () – C:\Documents and Settings\E140462\My Documents\WMG Gauge Batteries.docx
[2010/11/24 14:29:20 | 000,002,513 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Weatherford Offline Tracking System.lnk
[2010/11/24 11:35:37 | 000,266,208 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/11/23 21:11:14 | 000,090,539 | —- | M] () – C:\Documents and Settings\E140462\Desktop\print at work.docx
[2010/11/23 14:58:47 | 000,014,565 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Car VA.docx
[2010/11/23 14:08:25 | 000,013,083 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Doc1l.docx
[2010/11/23 11:55:19 | 000,039,418 | —- | M] () – C:\Documents and Settings\E140462\Desktop\delete.docx
[2010/11/23 01:15:43 | 000,000,450 | —- | M] () – C:\Documents and Settings\E140462\Desktop\WORK.lnk
[2010/11/22 08:57:19 | 000,017,255 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Make a copy of the FSW.docx
[2010/11/22 00:13:51 | 000,011,643 | —- | M] () – C:\Documents and Settings\E140462\Desktop\How to rcode modules with NCexpert.docx
[2010/11/21 22:34:21 | 000,000,404 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Bmw stuff.lnk
[2010/11/21 22:08:03 | 000,012,767 | —- | M] () – C:\Documents and Settings\E140462\Desktop\How to read module trace files with NCexpert.docx
[2010/11/21 14:37:04 | 000,113,116 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Doc1.docx
[2010/11/16 22:41:25 | 000,068,855 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Doc2.docx
[2010/11/16 21:18:50 | 000,170,727 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Dme dde.docx
[2010/11/16 20:27:06 | 000,000,205 | —- | M] () – C:\WINDOWS\inpa_ist.ini
[2010/11/16 20:18:32 | 000,000,227 | —- | M] () – C:\Documents and Settings\E140462\bestview.ini
[2010/11/12 21:45:10 | 000,001,024 | —- | M] () – C:\.rnd
[2010/11/12 19:11:00 | 000,001,024 | —- | M] () – C:\Documents and Settings\E140462\My Documents\.rnd
[2010/11/11 09:40:37 | 000,630,217 | —- | M] () – C:\WINDOWS\unins000.exe
[2010/11/10 19:49:12 | 000,004,973 | —- | M] () – C:\WINDOWS\System32\SiteList.xml
[2010/11/10 18:58:50 | 000,098,392 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/11/10 17:41:55 | 000,000,063 | —- | M] () – C:\WINDOWS\WINHELP.BMK
[2010/11/04 12:37:42 | 000,002,521 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Microsoft Office Outlook 2007.lnk
[2010/11/04 10:50:19 | 000,009,002 | RHS- | M] () – C:\Documents and Settings\E140462\ntuser.pol
[2010/11/03 19:22:33 | 000,000,055 | —- | M] () – C:\WINDOWS\SIERRA.INI
[2010/10/31 21:58:03 | 000,001,915 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/10/25 08:00:54 | 000,000,303 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Employee Connect.url
[2010/10/20 14:41:42 | 001,224,704 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Publication1.pub
[2010/10/20 14:05:05 | 000,016,550 | RHS- | M] () – C:\Documents and Settings\All Users\ntuser.pol
[2010/10/19 10:41:44 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/10/18 18:45:08 | 000,988,200 | —- | M] () – C:\Documents and Settings\E140462\My Documents\Publication1.pdf
[2010/10/15 13:08:53 | 000,002,443 | —- | M] () – C:\Documents and Settings\E140462\Desktop\Nucleus 4.1.lnk
[2010/10/15 10:29:48 | 000,000,162 | —- | M] () – C:\WINDOWS\ODBC.INI
[2010/10/01 09:29:26 | 000,000,016 | —- | M] () – C:\WINDOWS\popcinfo.dat
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/28 12:32:49 | 000,000,036 | —- | C] () – C:\Documents and Settings\E140462\Local Settings\Application Data\housecall.guid.cache
[2010/11/28 12:21:35 | 000,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/27 23:50:50 | 000,000,113 | —- | C] () – C:\WINDOWS\System32\api_hook_list.dat
[2010/11/26 21:22:26 | 000,001,510 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\WinKFP.lnk
[2010/11/26 21:22:26 | 000,001,454 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\NCS-Expert tool.lnk
[2010/11/26 21:22:26 | 000,001,427 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Tool32.lnk
[2010/11/26 21:22:04 | 000,630,217 | —- | C] () – C:\WINDOWS\unins001.exe
[2010/11/26 21:22:04 | 000,063,151 | —- | C] () – C:\WINDOWS\unins001.dat
[2010/11/26 18:45:25 | 000,034,213 | —- | C] () – C:\Documents and Settings\E140462\Desktop\New Microsoft Office Word Document (2).docx
[2010/11/25 19:58:32 | 000,014,149 | —- | C] () – C:\Documents and Settings\E140462\Desktop\body modules.docx
[2010/11/25 19:04:57 | 000,095,885 | —- | C] () – C:\Documents and Settings\E140462\Desktop\fault.pdf
[2010/11/24 18:04:31 | 000,008,568 | —- | C] () – C:\Documents and Settings\E140462\Desktop\INPA-PrintFile - na_aif.pdf
[2010/11/24 18:04:12 | 000,011,774 | —- | C] () – C:\Documents and Settings\E140462\Desktop\INPA-PrintFile - na_id.pdf
[2010/11/24 17:39:47 | 000,029,192 | —- | C] () – C:\Documents and Settings\E140462\Desktop\engine code.pdf
[2010/11/24 15:07:08 | 000,012,507 | —- | C] () – C:\Documents and Settings\E140462\My Documents\WMG Gauge Batteries.docx
[2010/11/24 09:06:28 | 000,158,528 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/11/23 21:18:32 | 000,001,075 | —- | C] () – C:\Documents and Settings\E140462\Desktop\REVTOR.PFL
[2010/11/23 21:11:13 | 000,090,539 | —- | C] () – C:\Documents and Settings\E140462\Desktop\print at work.docx
[2010/11/23 20:21:22 | 000,000,623 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\NcsDummy.lnk
[2010/11/23 14:58:46 | 000,014,565 | —- | C] () – C:\Documents and Settings\E140462\Desktop\Car VA.docx
[2010/11/23 14:08:24 | 000,013,083 | —- | C] () – C:\Documents and Settings\E140462\Desktop\Doc1l.docx
[2010/11/23 11:55:18 | 000,039,418 | —- | C] () – C:\Documents and Settings\E140462\Desktop\delete.docx
[2010/11/23 01:15:43 | 000,000,450 | —- | C] () – C:\Documents and Settings\E140462\Desktop\WORK.lnk
[2010/11/22 08:57:19 | 000,017,255 | —- | C] () – C:\Documents and Settings\E140462\Desktop\Make a copy of the FSW.docx
[2010/11/21 22:34:21 | 000,000,404 | —- | C] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Bmw stuff.lnk
[2010/11/21 22:08:45 | 000,011,643 | —- | C] () – C:\Documents and Settings\E140462\Desktop\How to rcode modules with NCexpert.docx
[2010/11/21 22:08:03 | 000,012,767 | —- | C] () – C:\Documents and Settings\E140462\Desktop\How to read module trace files with NCexpert.docx
[2010/11/16 22:41:25 | 000,068,855 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Doc2.docx
[2010/11/16 21:18:50 | 000,170,727 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Dme dde.docx
[2010/11/16 20:27:06 | 000,000,205 | —- | C] () – C:\WINDOWS\inpa_ist.ini
[2010/11/16 20:18:19 | 000,000,227 | —- | C] () – C:\Documents and Settings\E140462\bestview.ini
[2010/11/15 16:34:00 | 000,113,116 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Doc1.docx
[2010/11/12 21:45:10 | 000,001,024 | —- | C] () – C:\.rnd
[2010/11/11 09:42:46 | 000,630,217 | —- | C] () – C:\WINDOWS\unins000.exe
[2010/11/10 19:49:12 | 000,004,973 | —- | C] () – C:\WINDOWS\System32\SiteList.xml
[2010/11/10 17:41:53 | 000,000,063 | —- | C] () – C:\WINDOWS\WINHELP.BMK
[2010/11/08 20:04:18 | 000,001,024 | —- | C] () – C:\Documents and Settings\E140462\My Documents\.rnd
[2010/10/31 21:58:03 | 000,001,915 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/10/31 21:56:33 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/31 21:56:32 | 000,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/15 12:04:37 | 000,988,200 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Publication1.pdf
[2010/10/15 10:29:48 | 000,000,162 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/10/14 12:39:26 | 000,002,443 | —- | C] () – C:\Documents and Settings\E140462\Desktop\Nucleus 4.1.lnk
[2010/10/12 18:17:26 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/10/06 19:09:33 | 001,224,704 | —- | C] () – C:\Documents and Settings\E140462\My Documents\Publication1.pub
[2010/09/29 14:23:39 | 000,299,008 | —- | C] () – C:\Documents and Settings\E140462\Desktop\OMATIC.EXE
[2010/09/19 20:01:34 | 000,000,130 | —- | C] () – C:\Documents and Settings\E140462\Local Settings\Application Data\fusioncache.dat
[2010/09/18 15:30:12 | 000,000,055 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2010/09/14 17:09:40 | 000,155,648 | RHS- | C] () – C:\WINDOWS\System32\pstorsvc0.dll
[2010/09/09 12:37:15 | 000,000,105 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2010/09/06 08:53:16 | 000,000,045 | —- | C] () – C:\WINDOWS\UNITC.INI
[2010/09/04 14:30:07 | 004,244,744 | —- | C] () – C:\WINDOWS\System32\qtp-mt334.dll
[2010/09/04 14:30:07 | 000,247,560 | —- | C] () – C:\WINDOWS\System32\prgiso.dll
[2010/09/04 14:30:07 | 000,013,576 | —- | C] () – C:\WINDOWS\System32\wnaspi32.dll
[2010/08/31 16:20:42 | 000,000,300 | —- | C] () – C:\WINDOWS\REDBOOK2.INI
[2010/08/30 19:18:15 | 000,022,528 | —- | C] () – C:\Documents and Settings\E140462\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/30 18:59:11 | 000,000,078 | —- | C] () – C:\WINDOWS\init.ini
[2010/08/24 12:57:39 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2010/08/24 12:53:42 | 000,000,251 | —- | C] () – C:\WINDOWS\System32\drivers\hlldrvr.sys
[2010/08/24 12:53:17 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\cwbrw.dll
[2010/08/24 12:53:17 | 000,020,528 | —- | C] () – C:\WINDOWS\System32\cwbwiz.dll
[2010/08/24 12:53:17 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\cwbad.dll
[2010/08/24 12:53:16 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\cwbsv.dll
[2010/08/24 12:53:16 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\cwbsy.dll
[2010/08/24 12:53:16 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\cwbnl.dll
[2010/08/24 12:53:16 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\cwbco.dll
[2010/08/24 12:53:16 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\cwbnldlg.dll
[2010/08/24 10:04:24 | 001,843,784 | —- | C] () – C:\WINDOWS\System32\igklg400.dll
[2010/08/24 10:04:24 | 001,399,880 | —- | C] () – C:\WINDOWS\System32\igklg450.dll
[2010/08/24 10:04:24 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2010/08/24 10:04:24 | 000,104,636 | —- | C] () – C:\WINDOWS\System32\igmedcompkrn.dll
[2010/08/24 09:59:39 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/04/14 07:00:00 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2008/04/14 07:00:00 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2008/04/14 07:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2008/04/14 07:00:00 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2008/04/14 07:00:00 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2004/12/15 17:54:04 | 000,000,269 | —- | C] () – C:\WINDOWS\System32\FTD2XXUN.ini
[2002/10/06 18:42:57 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 23:04:25 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\vorbisenc.dll
[2002/10/04 23:04:24 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 23:04:17 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll

========== LOP Check ==========

[2010/09/07 17:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2010/08/30 18:57:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2010/09/07 17:39:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2010/08/24 12:58:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2010/09/30 12:33:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/10/18 16:12:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/09/18 12:27:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/09/14 17:39:15 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/11/26 07:22:39 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\ICAClient
[2010/09/07 18:16:57 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\ImgBurn
[2010/08/30 17:14:37 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Juniper Networks
[2010/09/17 21:15:12 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Quest3D
[2010/09/17 21:15:12 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Roaming
[2010/09/09 19:37:24 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Weatherford
[2010/10/07 07:41:41 | 000,000,000 | —D | M] – C:\Documents and Settings\E140462\Application Data\Xerox
[2010/11/27 23:53:01 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/11/27 23:50:26 | 000,000,312 | -HS- | M] () – C:\WINDOWS\Tasks\habpswz.job
[2010/11/28 12:21:35 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/11/28 12:17:00 | 000,000,290 | -H– | M] () – C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/11/12 21:45:10 | 000,001,024 | —- | M] () – C:\.rnd
[2010/11/27 23:49:59 | 000,026,003 | —- | M] () – C:\aaw7boot.log
[2010/08/24 09:20:06 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/08/24 09:05:58 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/08/24 09:20:06 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/08/24 09:20:06 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/09/18 13:29:06 | 016,777,234 | —- | M] () – C:\MRMRender.tga
[2010/08/24 09:20:06 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 07:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/11/27 23:50:01 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/08/24 09:19:41 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >
[2010/09/08 10:21:24 | 000,097,949 | —- | M] () – C:\WINDOWS\system32\AITYAHIA.jpg
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/08/24 09:57:32 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/08/24 09:57:32 | 001,089,536 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/08/24 09:57:32 | 000,929,792 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/24 09:20:13 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/24 11:15:08 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/08/24 11:15:08 | 000,000,079 | —- | M] () – C:\Documents and Settings\E140462\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2001/02/06 19:55:14 | 000,581,632 | —- | M] (Joshua F. Madison) – C:\Documents and Settings\E140462\Desktop\Convert1.exe
[1997/11/02 21:50:38 | 000,299,008 | —- | M] () – C:\Documents and Settings\E140462\Desktop\OMATIC.EXE
[2010/11/28 12:40:09 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\E140462\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >[/b
Your post has been Moved, Closed or Edited for one of the following reasons: 1.) You posted multiple topics and only one is required 2.) You are spamming links to other places without approval 3.) Abusive language or other problems in your text 4.) Your topic is too old (20 days or more) and no replies from you after a volunteer tried to help you This is a family oriented forum to help those that need help. ==============================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI