Thanks Noodle Texh,
Here's the first OTL report
OTL logfile created on: 07/03/2011 09:16:30 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = D:\Documents and Settings\ucyzdun\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 4096 4096 [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 31.25 Gb Total Space | 26.21 Gb Free Space | 83.88% Space Free | Partition Type: NTFS
Drive D: | 122.24 Gb Total Space | 95.37 Gb Free Space | 78.01% Space Free | Partition Type: NTFS
Drive E: | 79.33 Gb Total Space | 78.47 Gb Free Space | 98.91% Space Free | Partition Type: NTFS
Drive M: | 326.75 Gb Total Space | 47.43 Gb Free Space | 14.52% Space Free | Partition Type: NTFS
Drive W: | 5.03 Gb Total Space | 1.25 Gb Free Space | 24.82% Space Free | Partition Type: NTFS
Drive X: | 5.03 Gb Total Space | 1.25 Gb Free Space | 24.82% Space Free | Partition Type: NTFS
Drive Y: | 326.75 Gb Total Space | 47.43 Gb Free Space | 14.52% Space Free | Partition Type: NTFS
Drive Z: | 353.52 Gb Total Space | 23.98 Gb Free Space | 6.78% Space Free | Partition Type: NTFS
Computer Name: H7N80CFJ-HR | User Name: ucyzdun | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/03/07 09:15:42 | 000,580,608 | —- | M] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe
PRC - [2011/02/25 21:20:02 | 000,128,512 | RHS- | M] () – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe
PRC - [2011/02/21 15:15:46 | 000,806,912 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Remote Management System\RouterNT.exe
PRC - [2011/02/21 15:15:43 | 000,282,624 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
PRC - [2011/02/09 17:08:06 | 000,273,784 | —- | M] (DameWare Development) – D:\WINDOWS\dwrcs\DWRCST.EXE
PRC - [2011/02/09 17:07:58 | 000,576,888 | —- | M] (DameWare Development LLC) – D:\WINDOWS\dwrcs\DWRCS.EXE
PRC - [2010/11/23 15:34:19 | 001,541,360 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
PRC - [2010/11/23 15:34:11 | 000,097,520 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
PRC - [2010/11/23 15:34:07 | 000,163,056 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
PRC - [2010/09/30 12:08:31 | 000,439,536 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\AutoUpdate\ALMon.exe
PRC - [2010/09/30 12:08:30 | 000,230,640 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\AutoUpdate\ALsvc.exe
PRC - [2008/12/04 13:00:26 | 000,354,840 | —- | M] (Intel Corporation) – D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/12/04 13:00:20 | 000,186,904 | —- | M] (Intel Corporation) – D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/11/12 10:12:40 | 000,152,064 | —- | M] (Documentum, a division of EMC Corporation) – D:\Program Files\Documentum\AppConnector\EventServer.exe
PRC - [2008/11/12 10:12:40 | 000,045,056 | —- | M] (Documentum, a division of EMC Corporation) – D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe
PRC - [2008/07/23 09:56:14 | 002,054,680 | —- | M] (Intel Corporation) – D:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
PRC - [2008/07/23 09:56:14 | 000,773,144 | —- | M] (Intel Corporation) – D:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
PRC - [2008/07/23 09:56:12 | 000,174,616 | —- | M] (Intel Corporation) – D:\Program Files\Intel\AMT\LMS.exe
PRC - [2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) – D:\WINDOWS\explorer.exe
PRC - [2008/01/31 03:09:30 | 001,277,952 | —- | M] (Altiris, Inc.) – D:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe
PRC - [2005/11/09 15:34:10 | 000,294,912 | —- | M] () – D:\Program Files\MMTaskbar\MultiMon.exe
PRC - [2005/07/15 21:48:33 | 000,479,232 | —- | M] (Google Inc.) – D:\Program Files\Google\Gmail Notifier\gnotify.exe
PRC - [1999/09/30 21:31:38 | 000,869,376 | —- | M] (Fred's Software) – D:\Program Files\PrintKey2000\Printkey2000.exe
========== Modules (SafeList) ==========
MOD - [2011/03/07 09:15:42 | 000,580,608 | —- | M] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe
MOD - [2011/02/21 15:16:23 | 000,234,408 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll
MOD - [2010/08/23 16:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2003/09/02 14:15:16 | 000,057,344 | —- | M] () – D:\Program Files\MMTaskbar\shellhook.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/02/21 15:15:46 | 000,806,912 | —- | M] (Sophos Plc) [Auto | Running] – D:\Program Files\Sophos\Remote Management System\RouterNT.exe – (Sophos Message Router)
SRV - [2011/02/21 15:15:43 | 000,282,624 | —- | M] (Sophos Plc) [Auto | Running] – D:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe – (Sophos Agent)
SRV - [2011/02/09 17:07:58 | 000,576,888 | —- | M] (DameWare Development LLC) [Auto | Running] – D:\WINDOWS\dwrcs\DWRCS.EXE – (dwmrcs)
SRV - [2010/11/23 15:34:19 | 001,541,360 | —- | M] (Sophos Plc) [Auto | Running] – D:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe – (swi_service)
SRV - [2010/11/23 15:34:11 | 000,097,520 | —- | M] (Sophos Plc) [Unknown | Running] – D:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe – (SAVService)
SRV - [2010/11/23 15:34:07 | 000,163,056 | —- | M] (Sophos Plc) [Unknown | Running] – D:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe – (SAVAdminService)
SRV - [2010/09/30 12:08:30 | 000,230,640 | —- | M] (Sophos Plc) [Auto | Running] – D:\Program Files\Sophos\AutoUpdate\ALsvc.exe – (Sophos AutoUpdate Service)
SRV - [2008/12/04 13:00:26 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2008/07/23 09:56:14 | 002,054,680 | —- | M] (Intel Corporation) [Auto | Running] – D:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe – (UNS) Intel®
SRV - [2008/07/23 09:56:12 | 000,174,616 | —- | M] (Intel Corporation) [Auto | Running] – D:\Program Files\Intel\AMT\LMS.exe – (LMS) Intel®
SRV - [2008/01/31 03:09:30 | 001,277,952 | —- | M] (Altiris, Inc.) [Auto | Running] – D:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe – (AeXNSClient)
========== Driver Services (SafeList) ==========
DRV - [2010/11/23 15:34:16 | 000,024,064 | —- | M] (Sophos Plc) [File_System | System | Running] – D:\WINDOWS\system32\drivers\savonaccessfilter.sys – (SAVOnAccessFilter)
DRV - [2010/11/23 15:34:14 | 000,014,976 | —- | M] (Sophos Plc) [Kernel | Disabled | Stopped] – D:\WINDOWS\system32\drivers\SophosBootDriver.sys – (SophosBootDriver)
DRV - [2010/11/23 15:34:12 | 000,023,928 | —- | M] (Sophos Plc) [Kernel | On_Demand | Stopped] – D:\WINDOWS\system32\drivers\sdcfilter.sys – (sdcfilter)
DRV - [2010/11/23 15:34:11 | 000,153,344 | —- | M] (Sophos Plc) [File_System | System | Running] – D:\WINDOWS\system32\drivers\savonaccesscontrol.sys – (SAVOnAccessControl)
DRV - [2008/12/01 22:13:40 | 003,452,928 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – D:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2008/07/23 09:42:30 | 000,040,832 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – D:\WINDOWS\system32\drivers\HECI.sys – (HECI) Intel®
DRV - [2008/06/05 11:58:18 | 000,144,480 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – D:\WINDOWS\system32\drivers\e1k5132.sys – (e1kexpress) Intel®
DRV - [2008/03/28 10:14:02 | 000,024,064 | —- | M] (Sonic Focus, Inc) [Kernel | Boot | Running] – D:\WINDOWS\system32\drivers\sfaudio.sys – (SFAUDIO)
DRV - [2007/02/15 16:00:00 | 000,026,624 | —- | M] (DameWare) [Kernel | System | Running] – D:\WINDOWS\system32\drivers\dwvkbd.sys – (dwvkbd)
DRV - [2007/02/07 16:00:00 | 000,003,712 | —- | M] (DameWare Development, LLC) [Kernel | On_Demand | Running] – D:\WINDOWS\system32\drivers\DamewareMini.sys – (DwMirror)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://uk.news.yahoo.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://domredi.com/1/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.ucl.ac.uk"
FF - prefs.js..extensions.enabledItems: [removed]:1.19
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2011/03/01 12:23:10 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2011/03/01 12:23:10 | 000,000,000 | —D | M]
[2010/04/19 08:38:34 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Extensions
[2011/03/01 12:23:23 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Firefox\Profiles\bpzezwgb.default\extensions
[2010/07/27 14:21:31 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Firefox\Profiles\bpzezwgb.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/15 10:20:54 | 000,000,000 | —D | M] (Joomla! Admin) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Firefox\Profiles\bpzezwgb.default\extensions\[removed]
[2010/09/15 10:20:54 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Firefox\Profiles\bpzezwgb.default\extensions\staged-xpis
[2011/03/01 12:23:23 | 000,000,000 | —D | M] (No name found) – D:\Program Files\Mozilla Firefox\extensions
[2011/02/22 10:39:43 | 000,000,000 | —D | M] (Java Console) – D:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/04/13 11:36:00 | 000,000,000 | —D | M] (British English Dictionary) – D:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/01/06 12:34:29 | 000,000,000 | —D | M] (Java Quick Starter) – D:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/08/14 11:33:22 | 000,070,488 | —- | M] (Citrix Systems, Inc.) – D:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2009/08/14 11:33:30 | 000,091,480 | —- | M] () – D:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2009/08/14 11:33:26 | 000,020,824 | —- | M] () – D:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2007/03/16 16:33:48 | 000,479,232 | —- | M] (Microsoft Corporation) – D:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2007/03/16 16:33:48 | 000,548,864 | —- | M] (Microsoft Corporation) – D:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2007/03/16 16:33:50 | 000,626,688 | —- | M] (Microsoft Corporation) – D:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – D:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/08/14 11:35:40 | 000,427,344 | —- | M] () – D:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2005/04/05 04:38:20 | 000,053,355 | —- | M] (Oracle Corporation) – D:\Program Files\Mozilla Firefox\plugins\NPJinit13122.dll
[2005/09/19 23:00:08 | 000,053,355 | —- | M] (Oracle Corporation) – D:\Program Files\Mozilla Firefox\plugins\NPJinit13123.dll
[2007/08/07 01:37:06 | 000,053,355 | —- | M] (Oracle Corporation) – D:\Program Files\Mozilla Firefox\plugins\NPJinit13129.dll
[2009/08/14 11:33:22 | 000,023,896 | —- | M] (Citrix Systems, Inc.) – D:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll
[2010/12/03 17:47:02 | 000,001,538 | —- | M] () – D:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/12/03 17:47:02 | 000,000,947 | —- | M] () – D:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/12/03 17:47:02 | 000,000,769 | —- | M] () – D:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/12/03 17:47:02 | 000,001,135 | —- | M] () – D:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2001/08/23 11:00:00 | 000,000,734 | —- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - D:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Plc)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {3D89FF0D-3232-4116-867F-6D89B9711B5A} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {796AF358-6E53-4E90-AB45-503C3C8D2891} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] D:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] D:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AeXAgentLogon] D:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe (Altiris, Inc.)
O4 - HKLM..\Run: [AppConnectorCredentialMgr] D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe (Documentum, a division of EMC Corporation)
O4 - HKLM..\Run: [DameWare MRC Agent] D:\WINDOWS\dwrcs\DWRCST.EXE (DameWare Development)
O4 - HKLM..\Run: [hpgcrybc] D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe ()
O4 - HKLM..\Run: [IAAnotif] D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] File not found
O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] D:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [OFARegisterOCX] D:\OraHome1\olap\bin\RDONLY.OCX (Oracle Corporation)
O4 - HKLM..\Run: [OFARegisterOCX1] D:\WINDOWS\system32\FLP32X20.OCX (FarPoint Technologies, Inc.)
O4 - HKLM..\Run: [OFARegisterOCX2] D:\WINDOWS\system32\SPIN32.OCX (Outrider Systems, Inc.)
O4 - HKLM..\Run: [OFARegisterOCX3] D:\OraHome1\olap\bin\SNAPIOCX.OCX (Oracle Corporation)
O4 - HKLM..\Run: [OFARegisterOCX4] D:\OraHome1\olap\bin\XWCMDWIN.OCX (Oracle)
O4 - HKLM..\Run: [OFARegisterOCX5] D:\OraHome1\olap\bin\ORACD32.OCX (Oracle Corporation.)
O4 - HKLM..\Run: [picon] D:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe (Intel Corporation)
O4 - HKLM..\Run: [Sophos AutoUpdate Monitor] D:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
O4 - HKLM..\Run: [SunJavaUpdateSched] File not found
O4 - HKCU..\Run: [hpgcrybc] D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe ()
O4 - HKCU..\Run: [QuickTime Task] File not found
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\MultiMon Taskbar.lnk = D:\Program Files\MMTaskbar\MultiMon.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk = D:\Program Files\PrintKey2000\Printkey2000.exe (Fred's Software)
O4 - Startup: D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\frilm.exe ()
O4 - Startup: D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\peyci.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogOff = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConnectHomeDirToRoot = 0
O15 - HKCU\..Trusted Domains: ucl.ac.uk ([*.adcom] * in Local intranet)
O15 - HKCU\..Trusted Domains: ucl.ac.uk ([*.adm] * in Local intranet)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {36F17E17-AC00-42BC-A6D9-294AD4E7DCD6}
http://ads3-adm/Altiris/NS/NSCap/Bin/Win32…ntBootstrap.cab (Altiris ClientBootstraper Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/windowsupd…b?1232534038015 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1294225834643 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} Reg Error: Value error. (JInitiator 1.3.1.22)
O16 - DPF: {CAFECAFE-0013-0001-0023-ABCDEFABCDEF} Reg Error: Value error. (JInitiator [removed])
O16 - DPF: {CAFECAFE-0013-0001-0029-ABCDEFABCDEF} Reg Error: Value error. (JInitiator 1.3.1.29)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = adm.ucl.ac.uk
O20 - AppInit_DLLs: (D:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - D:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Plc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - D:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\MRCNotify: DllName - D:\WINDOWS\dwrcs\DWRCWXL.dll - D:\WINDOWS\dwrcs\DWRCWXL.dll (DameWare Development LLC)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/20 15:58:26 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{ff63e1c0-1fc1-11e0-9be0-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{ff63e1c0-1fc1-11e0-9be0-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ff63e1c0-1fc1-11e0-9be0-806d6172696f}\Shell\AutoRun\command - "" = G:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - D:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - D:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - D:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - D:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - D:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - D:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - D:\WINDOWS\System32\ir50_32.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (0)
========== Files/Folders - Created Within 30 Days ==========
[2011/03/07 09:15:38 | 000,580,608 | —- | C] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe
[2011/03/04 13:21:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Google
[2011/03/04 09:12:26 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\PCFix
[2011/03/03 13:45:09 | 000,000,000 | —D | C] – D:\Documents and Settings\LocalService\Application Data\McAfee
[2011/03/03 09:38:51 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\Excel
[2011/03/01 15:33:59 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Microsoft Help
[2011/03/01 12:40:16 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/03/01 12:40:15 | 000,000,000 | —D | C] – D:\Program Files\CCleaner
[2011/03/01 12:23:16 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Mozilla
[2011/03/01 12:23:13 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[2011/03/01 09:29:41 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/03/01 09:29:38 | 000,000,000 | —D | C] – D:\Program Files\Microsoft Silverlight
[2011/02/28 14:29:25 | 000,000,000 | —D | C] – D:\Program Files\Trend Micro
[2011/02/28 14:29:25 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\HiJackThis
[2011/02/28 13:09:52 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Temp
[2011/02/28 13:08:41 | 000,000,000 | —D | C] – D:\Program Files\Common Files\Adobe
[2011/02/28 11:36:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Sophos
[2011/02/28 08:53:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\AAT
[2011/02/23 15:35:49 | 000,000,000 | —D | C] – D:\Program Files\PrintKey2000
[2011/02/23 15:32:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\My eBooks
[2011/02/23 13:37:24 | 000,038,224 | —- | C] (Malwarebytes Corporation) – D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/23 13:37:24 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/23 13:37:24 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/23 13:37:21 | 000,020,952 | —- | C] (Malwarebytes Corporation) – D:\WINDOWS\System32\drivers\mbam.sys
[2011/02/23 13:37:21 | 000,000,000 | —D | C] – D:\Program Files\Malwarebytes' Anti-Malware
[2011/02/22 13:01:01 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\org.madan.air.ada
[2011/02/22 13:00:59 | 000,000,000 | —D | C] – D:\Program Files\ada
[2011/02/22 12:57:41 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Adobe
[2011/02/22 12:30:46 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\MultiMon Taskbar
[2011/02/22 12:30:45 | 000,000,000 | —D | C] – D:\Program Files\MMTaskbar
[2011/02/22 12:13:28 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Downloaded Installations
[2011/02/22 12:01:59 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\BusinessObjects XI 3.1
[2011/02/22 11:58:48 | 000,000,000 | —D | C] – D:\Program Files\Business Objects XI
[2011/02/22 10:39:42 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – D:\WINDOWS\System32\javaws.exe
[2011/02/22 10:39:42 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – D:\WINDOWS\System32\javaw.exe
[2011/02/22 10:39:42 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – D:\WINDOWS\System32\java.exe
[2011/02/22 10:39:11 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\McAfee
[2011/02/22 10:33:54 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2011/02/22 10:24:44 | 000,000,000 | —D | C] – D:\Program Files\Microsoft Visual Studio 8
[2011/02/22 10:07:57 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\Downloads
[2011/02/22 10:07:50 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\PC_Drivers_Headquarters
[2011/02/22 09:24:03 | 000,000,000 | —D | C] – D:\WINDOWS\dwrcs
[2011/02/22 08:54:35 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Documentum
[2011/02/22 08:48:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\ApplicationHistory
[2011/02/22 08:46:00 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\Local Settings
[2011/02/22 08:46:00 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Microsoft
[2011/02/22 08:44:54 | 000,005,632 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\ptpusb.dll
[2011/02/22 08:44:53 | 000,159,232 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\ptpusd.dll
[2011/02/22 08:44:53 | 000,015,104 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\dllcache\usbscan.sys
[2011/02/22 08:43:11 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\.alice2
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Broken Sword 2.5
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\BBC Alerts
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\AVS4YOU
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ATI
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ArcSoft
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Apple Computer
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\AdobeUM
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Adobe
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Lycos
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Logitech
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Leadertech
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Kontiki
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Identities
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ICAClient
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Help
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\gtk-2.0
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Google
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\GetRightToGo
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\FreeFixer
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\FMA
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ElevatedDiagnostics
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\EA
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\dvdcss
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\DivX
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\DAEMON Tools Lite
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\CyberLink
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\CoreFTP
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Cogniview
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Business Objects
[2011/02/22 08:43:08 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Media Player Classic
[2011/02/22 08:43:08 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Malwarebytes
[2011/02/22 08:43:08 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Macromedia
[2011/02/22 08:43:06 | 000,000,000 | –SD | C] – D:\Documents and Settings\ucyzdun\Application Data\Microsoft
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Real
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ProIV Technology Inc
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\PC Suite
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Nuance
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\NSeries
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Nokia Multimedia Player
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Nokia
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Mozilla
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Sony Online Entertainment
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Sony Ericsson
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Sony
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\SmartDraw
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\shockwave.com
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\SharePod
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Seven Zip
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ScanSoft
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Roxio
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\WinRAR
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\WindSolutions
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Windows Search
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Windows Desktop Search
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\webex
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Ulead Systems
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ubi.com
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\tidysongs16
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\TextPad
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Teleca
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Sun
[2011/02/22 08:43:03 | 000,000,000 | –SD | C] – D:\Documents and Settings\ucyzdun\My Documents\My Webs
[2011/02/22 08:43:03 | 000,000,000 | –SD | C] – D:\Documents and Settings\ucyzdun\My Documents\My Web Sites
[2011/02/22 08:43:03 | 000,000,000 | –SD | C] – D:\Documents and Settings\ucyzdun\My Documents\My Data Sources
[2011/02/22 08:43:03 | 000,000,000 | RH-D | C] – D:\Documents and Settings\ucyzdun\Application Data
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\My Documents\My Videos
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\My Documents\My Pictures
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\My Documents\My Music
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\My Documents
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Favorites
[2011/02/22 08:43:03 | 000,000,000 | -HSD | C] – D:\Documents and Settings\ucyzdun\Cookies
[2011/02/22 08:43:03 | 000,000,000 | -HSD | C] – D:\Documents and Settings\ucyzdun\Desktop\%USERPROFILE%
[2011/02/22 08:43:03 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\InstallAnywhere
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Zeon
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\WebEx
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\Updater5
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\PrintScreen Files
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\PDF Favorites
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\My Business Objects Documents
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Documentum
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Desktop
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Contacts
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Citrix
[2011/02/22 08:43:02 | 000,000,000 | RH-D | C] – D:\Documents and Settings\ucyzdun\SendTo
[2011/02/22 08:43:02 | 000,000,000 | RH-D | C] – D:\Documents and Settings\ucyzdun\Recent
[2011/02/22 08:43:02 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup
[2011/02/22 08:43:02 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Start Menu
[2011/02/22 08:43:02 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Administrative Tools
[2011/02/22 08:43:02 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Accessories
[2011/02/22 08:43:02 | 000,000,000 | -HSD | C] – D:\Documents and Settings\ucyzdun\UserData
[2011/02/22 08:43:02 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\Templates
[2011/02/22 08:43:02 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\PrintHood
[2011/02/22 08:43:02 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\NetHood
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\WinRAR
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\System
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Real
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\PrintKey2000
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\pnlinks
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\PHP 5
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\pdfFactory
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\NorthgateArinso
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Internet
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Google Chrome
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Gmail Notifier
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\FreeFixer
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Express ClickYes
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\CopyTrans Suite
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\CCleaner
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\7-Zip
[2011/02/21 16:49:33 | 000,000,000 | —D | C] – D:\Program Files\SystemRequirementsLab
[2011/02/21 16:45:43 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/02/21 15:51:06 | 000,000,000 | —D | C] – D:\Program Files\ATI Technologies
[2011/02/21 15:51:04 | 000,000,000 | —D | C] – D:\Program Files\ATI
[3 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/03/07 09:15:42 | 000,580,608 | —- | M] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe
[2011/03/07 09:08:48 | 000,002,206 | —- | M] () – D:\WINDOWS\System32\wpa.dbl
[2011/03/07 09:08:45 | 000,000,882 | —- | M] () – D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/07 08:49:00 | 000,000,886 | —- | M] () – D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/07 05:00:00 | 000,000,530 | —- | M] () – D:\WINDOWS\tasks\Scheduled Daily Scan @ 5am.job
[2011/03/04 17:21:06 | 000,009,684 | RHS- | M] () – D:\Documents and Settings\ucyzdun\ntuser.pol
[2011/03/04 17:13:10 | 000,000,754 | —- | M] () – D:\WINDOWS\WORDPAD.INI
[2011/03/04 16:08:05 | 000,260,917 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\Arsenal World.url
[2011/03/04 11:06:25 | 000,000,225 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\SELF SERVICE.url
[2011/03/04 09:33:25 | 000,000,327 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\Resource Link on the NET.url
[2011/03/02 09:53:16 | 000,000,204 | —- | M] () – D:\WINDOWS\hpbafd.ini
[2011/03/01 12:40:16 | 000,000,682 | —- | M] () – D:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/03/01 12:23:13 | 000,001,620 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/01 12:23:13 | 000,001,602 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/03/01 09:14:00 | 000,505,972 | —- | M] () – D:\WINDOWS\System32\perfh009.dat
[2011/03/01 09:14:00 | 000,089,244 | —- | M] () – D:\WINDOWS\System32\perfc009.dat
[2011/03/01 09:09:20 | 000,002,048 | –S- | M] () – D:\WINDOWS\bootstat.dat
[2011/02/28 16:45:34 | 000,000,251 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\KnowBase.url
[2011/02/28 14:36:49 | 000,000,815 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/28 14:29:25 | 000,001,988 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\HiJackThis.lnk
[2011/02/28 13:09:02 | 000,001,734 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/02/25 21:20:03 | 000,128,512 | R-S- | M] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\frilm.exe
[2011/02/25 21:20:02 | 000,128,512 | RHS- | M] () – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe
[2011/02/23 15:35:49 | 000,000,682 | —- | M] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk
[2011/02/23 15:15:16 | 000,263,824 | —- | M] () – D:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/23 13:37:24 | 000,000,784 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/22 16:07:11 | 000,000,298 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\Payslips & P60's.url
[2011/02/22 16:05:29 | 000,000,455 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\InfoView.url
[2011/02/22 13:00:59 | 000,000,568 | —- | M] () – D:\Documents and Settings\All Users\Desktop\ada.lnk
[2011/02/22 12:30:46 | 000,000,647 | —- | M] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\MultiMon Taskbar.lnk
[2011/02/22 12:30:46 | 000,000,635 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\MultiMon Taskbar.lnk
[2011/02/22 12:09:39 | 000,001,139 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\BusinessObjects 6.1 (2).lnk
[2011/02/22 12:01:32 | 000,000,804 | —- | M] () – D:\WINDOWS\ODBC.INI
[2011/02/22 11:30:01 | 000,000,792 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/02/22 10:42:38 | 000,128,512 | R-S- | M] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\peyci.exe
[2011/02/22 10:39:45 | 000,000,664 | —- | M] () – D:\WINDOWS\System32\d3d9caps.dat
[2011/02/22 08:48:09 | 000,000,130 | —- | M] () – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\fusioncache.dat
[2011/02/21 16:49:34 | 000,000,768 | —- | M] () – D:\WINDOWS\System32\d3d8caps.dat
[2011/02/21 15:16:22 | 000,131,824 | —- | M] (Sophos Plc) – D:\WINDOWS\System32\sdccoinstaller.dll
[2011/02/21 15:16:05 | 000,028,912 | —- | M] (Sophos Plc) – D:\WINDOWS\System32\SophosBootTasks.exe
[2011/02/18 10:21:37 | 000,001,374 | —- | M] () – D:\WINDOWS\imsins.BAK
[2011/02/17 14:07:41 | 000,011,810 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110217_140739.reg
[2011/02/17 09:19:20 | 000,020,910 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110217_091907.reg
[2011/02/16 11:45:11 | 000,000,205 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\HR Helpdesk Webform.url
[2011/02/15 10:41:41 | 000,071,292 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\Anders.bgl
[2011/02/14 14:50:21 | 000,452,651 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\Mock 72.pdf
[2011/02/09 15:12:34 | 000,000,122 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\schema.ini
[3 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/03/04 17:13:10 | 000,000,754 | —- | C] () – D:\WINDOWS\WORDPAD.INI
[2011/03/01 12:40:16 | 000,000,682 | —- | C] () – D:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/03/01 12:23:13 | 000,001,620 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/01 12:23:13 | 000,001,602 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/28 14:36:49 | 000,000,815 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/28 14:29:25 | 000,001,988 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\HiJackThis.lnk
[2011/02/28 13:09:02 | 000,001,734 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/02/28 13:09:01 | 000,001,804 | —- | C] () – D:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/02/25 21:20:03 | 000,128,512 | R-S- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\frilm.exe
[2011/02/23 15:35:49 | 000,000,682 | —- | C] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk
[2011/02/23 15:33:09 | 000,128,512 | RHS- | C] () – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe
[2011/02/23 15:32:12 | 000,128,512 | R-S- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\peyci.exe
[2011/02/23 15:32:12 | 000,000,738 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Outlook Express.lnk
[2011/02/23 13:37:24 | 000,000,784 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/22 13:00:59 | 000,000,574 | —- | C] () – D:\Documents and Settings\All Users\Start Menu\Programs\ada.lnk
[2011/02/22 13:00:59 | 000,000,568 | —- | C] () – D:\Documents and Settings\All Users\Desktop\ada.lnk
[2011/02/22 12:30:46 | 000,000,647 | —- | C] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\MultiMon Taskbar.lnk
[2011/02/22 12:30:46 | 000,000,635 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\MultiMon Taskbar.lnk
[2011/02/22 10:27:41 | 000,593,920 | —- | C] () – D:\WINDOWS\System32\ati2sgag.exe
[2011/02/22 08:48:36 | 000,000,204 | —- | C] () – D:\WINDOWS\hpbafd.ini
[2011/02/22 08:48:09 | 000,000,130 | —- | C] () – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\fusioncache.dat
[2011/02/22 08:45:11 | 000,000,870 | —- | C] () – D:\Documents and Settings\ucyzdun\.recently-used.xbel
[2011/02/22 08:43:46 | 000,010,825 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Comma Separated Values (Windows).CAL
[2011/02/22 08:43:46 | 000,009,399 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Comma Separated Values (DOS).EML
[2011/02/22 08:43:38 | 000,001,139 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\BusinessObjects 6.1 (2).lnk
[2011/02/22 08:43:38 | 000,000,992 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word.lnk
[2011/02/22 08:43:38 | 000,000,990 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Excel.lnk
[2011/02/22 08:43:38 | 000,000,792 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/02/22 08:43:38 | 000,000,079 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/02/22 08:43:31 | 000,009,355 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft Excel.EML
[2011/02/22 08:43:19 | 000,260,917 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Arsenal World.url
[2011/02/22 08:43:19 | 000,245,283 | —- | C] () – D:\Documents and Settings\ucyzdun\Casual open.rep
[2011/02/22 08:43:19 | 000,029,930 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Arsenal.url
[2011/02/22 08:43:19 | 000,000,751 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\KB Links.lnk
[2011/02/22 08:43:19 | 000,000,455 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\InfoView.url
[2011/02/22 08:43:19 | 000,000,327 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Resource Link on the NET.url
[2011/02/22 08:43:19 | 000,000,298 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Payslips & P60's.url
[2011/02/22 08:43:19 | 000,000,292 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Birmingham UPAY.url
[2011/02/22 08:43:19 | 000,000,251 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\KnowBase.url
[2011/02/22 08:43:19 | 000,000,248 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\WTS Page.url
[2011/02/22 08:43:19 | 000,000,225 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\SELF SERVICE.url
[2011/02/22 08:43:19 | 000,000,205 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\HR Helpdesk Webform.url
[2011/02/22 08:43:19 | 000,000,140 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\MyView TEST.url
[2011/02/22 08:43:19 | 000,000,127 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Work Station Assessment Form.url
[2011/02/22 08:43:18 | 000,452,651 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\Mock 72.pdf
[2011/02/22 08:43:18 | 000,071,292 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\Anders.bgl
[2011/02/22 08:43:18 | 000,061,224 | —- | C] () – D:\Documents and Settings\ucyzdun\GoToAssistDownloadHelper.exe
[2011/02/22 08:43:18 | 000,020,910 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110217_091907.reg
[2011/02/22 08:43:18 | 000,011,810 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110217_140739.reg
[2011/02/22 08:43:18 | 000,001,273 | —- | C] () – D:\Documents and Settings\ucyzdun\jinitiator13129.trace
[2011/02/22 08:43:18 | 000,000,912 | —- | C] () – D:\Documents and Settings\ucyzdun\jinitiator1319.trace
[2011/02/22 08:43:18 | 000,000,910 | —- | C] () – D:\Documents and Settings\ucyzdun\jinitiator13122.trace
[2011/02/22 08:43:18 | 000,000,032 | R— | C] () – D:\Documents and Settings\ucyzdun\hash.dat
[2011/02/22 08:43:13 | 000,504,038 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\sqlite3.dll
[2011/02/22 08:43:13 | 000,000,122 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\schema.ini
[2011/02/22 08:43:11 | 000,002,331 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Windows Install Clean Up.lnk
[2011/02/22 08:43:11 | 000,001,599 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Remote Assistance.lnk
[2011/02/22 08:43:11 | 000,000,803 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Internet Explorer.lnk
[2011/02/22 08:43:11 | 000,000,788 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Windows Media Player.lnk
[2011/02/22 08:43:02 | 000,009,684 | RHS- | C] () – D:\Documents and Settings\ucyzdun\ntuser.pol
[2011/02/21 16:49:34 | 000,000,768 | —- | C] () – D:\WINDOWS\System32\d3d8caps.dat
[2011/01/05 12:14:28 | 000,000,698 | —- | C] () – D:\WINDOWS\System32\DWRCCMDError.ini
[2010/11/25 10:31:37 | 000,000,038 | —- | C] () – D:\WINDOWS\XOBJECTS.INI
[2010/11/23 15:26:21 | 000,236,588 | —- | C] () – D:\WINDOWS\System32\nvdrsdb0.bin
[2010/11/23 15:26:20 | 000,236,588 | —- | C] () – D:\WINDOWS\System32\nvdrsdb1.bin
[2010/11/23 15:26:20 | 000,000,001 | —- | C] () – D:\WINDOWS\System32\nvdrssel.bin
[2010/11/23 15:25:56 | 002,195,350 | —- | C] () – D:\WINDOWS\System32\nvdata.bin
[2009/03/24 15:04:46 | 002,026,604 | —- | C] () – D:\WINDOWS\System32\igkrng500.bin
[2009/03/24 15:04:45 | 000,442,964 | —- | C] () – D:\WINDOWS\System32\igcompkrng500.bin
[2009/03/24 15:04:45 | 000,147,456 | —- | C] () – D:\WINDOWS\System32\igfxCoIn_v4977.dll
[2009/02/18 12:20:36 | 000,000,664 | —- | C] () – D:\WINDOWS\System32\d3d9caps.dat
[2009/02/18 12:01:02 | 000,000,168 | —- | C] () – D:\WINDOWS\wininit.ini
[2009/01/21 16:22:54 | 000,000,061 | —- | C] () – D:\WINDOWS\smscfg.ini
[2009/01/21 13:08:30 | 000,000,000 | —- | C] () – D:\WINDOWS\nsreg.dat
[2009/01/21 11:15:47 | 000,036,962 | —- | C] () – D:\WINDOWS\System32\ActPanel.dll
[2009/01/21 10:59:25 | 000,000,804 | —- | C] () – D:\WINDOWS\ODBC.INI
[2009/01/21 10:24:07 | 000,000,000 | —- | C] () – D:\WINDOWS\ativpsrm.bin
[2009/01/21 10:18:27 | 000,876,544 | —- | C] () – D:\WINDOWS\System32\TEACico2.dll
[2009/01/20 16:59:24 | 000,002,048 | –S- | C] () – D:\WINDOWS\bootstat.dat
[2009/01/20 16:56:52 | 000,021,640 | —- | C] () – D:\WINDOWS\System32\emptyregdb.dat
[2009/01/20 16:53:49 | 000,004,332 | —- | C] () – D:\WINDOWS\ODBCINST.INI
[2009/01/20 16:53:07 | 000,263,824 | —- | C] () – D:\WINDOWS\System32\FNTCACHE.DAT
[2008/12/01 20:11:21 | 003,107,788 | —- | C] () – D:\WINDOWS\System32\ativvaxx.dat
[2008/12/01 20:11:21 | 003,107,788 | —- | C] () – D:\WINDOWS\System32\ativva5x.dat
[2008/12/01 20:11:21 | 000,887,724 | —- | C] () – D:\WINDOWS\System32\ativva6x.dat
[2008/10/30 14:45:42 | 000,180,720 | —- | C] () – D:\WINDOWS\System32\atiicdxx.dat
[2008/04/14 04:55:28 | 000,001,804 | —- | C] () – D:\WINDOWS\System32\Dcache.bin
[2008/04/14 04:41:56 | 000,755,200 | —- | C] () – D:\WINDOWS\System32\ir50_32.dll
[2008/04/14 04:41:56 | 000,338,432 | —- | C] () – D:\WINDOWS\System32\ir41_qcx.dll
[2008/04/14 04:41:56 | 000,200,192 | —- | C] () – D:\WINDOWS\System32\ir50_qc.dll
[2008/04/14 04:41:56 | 000,183,808 | —- | C] () – D:\WINDOWS\System32\ir50_qcx.dll
[2008/04/14 04:41:56 | 000,120,320 | —- | C] () – D:\WINDOWS\System32\ir41_qc.dll
[2008/02/04 18:23:10 | 000,693,792 | —- | C] () – D:\WINDOWS\System32\OGACheckControl.DLL
[2007/05/17 16:54:00 | 000,113,664 | —- | C] () – D:\WINDOWS\System32\See32.dll
[2006/12/31 06:57:08 | 000,004,569 | —- | C] () – D:\WINDOWS\System32\secupd.dat
[2001/08/23 11:00:00 | 013,107,200 | —- | C] () – D:\WINDOWS\System32\oembios.bin
[2001/08/23 11:00:00 | 000,673,088 | —- | C] () – D:\WINDOWS\System32\mlang.dat
[2001/08/23 11:00:00 | 000,505,972 | —- | C] () – D:\WINDOWS\System32\perfh009.dat
[2001/08/23 11:00:00 | 000,272,128 | —- | C] () – D:\WINDOWS\System32\perfi009.dat
[2001/08/23 11:00:00 | 000,218,003 | —- | C] () – D:\WINDOWS\System32\dssec.dat
[2001/08/23 11:00:00 | 000,089,244 | —- | C] () – D:\WINDOWS\System32\perfc009.dat
[2001/08/23 11:00:00 | 000,046,258 | —- | C] () – D:\WINDOWS\System32\mib.bin
[2001/08/23 11:00:00 | 000,028,626 | —- | C] () – D:\WINDOWS\System32\perfd009.dat
[2001/08/23 11:00:00 | 000,004,463 | —- | C] () – D:\WINDOWS\System32\oembios.dat
[2001/08/23 11:00:00 | 000,000,741 | —- | C] () – D:\WINDOWS\System32\noise.dat
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/09/22 20:38:00 | 000,458,752 | R— | M] (Inner Media, Inc.) – D:\adfactry.dll
[2005/09/22 20:38:00 | 000,015,872 | R— | M] (Inner Media, Inc.) – D:\adreg32.exe
[2011/03/07 09:08:54 | 000,001,362 | —- | M] () – D:\deploy.log
[2005/09/22 20:38:00 | 000,073,216 | R— | M] (Inner Media, Inc.) – D:\sfxbe321.dll
[2005/09/22 20:38:00 | 000,078,336 | R— | M] (Inner Media, Inc.) – D:\sfxbe322.dll
[2005/09/22 20:38:00 | 000,053,760 | R— | M] (Inner Media, Inc.) – D:\sfxfe32.exe
[2009/01/13 11:00:57 | 000,000,584 | —- | M] () – D:\sysprep.inf
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – D:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – D:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – D:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – D:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/01/20 16:58:14 | 000,000,067 | -HS- | M] () – D:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/01/26 10:14:41 | 000,001,634 | -H– | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/01/20 16:52:43 | 000,094,208 | —- | M] () – D:\WINDOWS\system32\config\default.sav
[2009/01/20 16:52:43 | 001,089,536 | —- | M] () – D:\WINDOWS\system32\config\software.sav
[2009/01/20 16:52:43 | 000,933,888 | —- | M] () – D:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/01/20 16:58:26 | 000,000,294 | -HS- | M] () – D:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/07/31 10:51:36 | 000,000,119 | -HS- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/07/05 14:52:31 | 000,000,079 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/03/07 09:15:42 | 000,580,608 | —- | M] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
[2009/12/14 11:32:09 | 000,061,224 | —- | M] () – D:\Documents and Settings\ucyzdun\GoToAssistDownloadHelper.exe
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2009/07/31 10:51:36 | 000,000,122 | -HS- | M] () – D:\Documents and Settings\ucyzdun\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2011/01/05 10:39:20 | 000,030,058 | RHS- | M] () – D:\Documents and Settings\All Users\ntuser.pol
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2011/03/01 09:28:33 | 000,000,067 | -HS- | M] () – D:\Documents and Settings\ucyzdun\Cookies\desktop.ini
[2011/03/07 09:15:10 | 000,475,136 | -HS- | M] () – D:\Documents and Settings\ucyzdun\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoUpdate" = 0
"AUOptions" = 4
"ScheduledInstallDay" = 0
"ScheduledInstallTime" = 5
"UseWUServer" = 1
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-25 05:00:41
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 143 bytes -> D:\Documents and Settings\ucyzdun\Application Data\Microsoft Excel.EML:OECustomProperty
@Alternate Data Stream - 143 bytes -> D:\Documents and Settings\ucyzdun\Application Data\Comma Separated Values (DOS).EML:OECustomProperty
< End of report >
Second one to follow.