I have an XP system that redirects browser URLs. McAfee finds TDSS e!rootkit but cannot successfully remove it. Malwarebytes finds nothing. DDS runs for about 3 minutes then hangs the machine. I've attached the GMER log. In case it's helpful, I've pasted the OTL log below and attached Extras.txt.
Thanks for your help!
OTL logfile created on: 7/3/2011 10:30:01 AM - Run 1
OTL by OldTimer - Version 3.2.25.0 Folder = C:\Documents and Settings\shera\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1014.42 Mb Total Physical Memory | 270.18 Mb Available Physical Memory | 26.63% Memory free
2.07 Gb Paging File | 1.36 Gb Available in Paging File | 65.91% Paging File free
Paging file location(s): C:\pagefile.sys 1200 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.24 Gb Total Space | 7.12 Gb Free Space | 21.42% Space Free | Partition Type: NTFS
Computer Name: EARWIG | User Name: shera | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\shera\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Applications\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\Mctray.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\scan32.exe (McAfee, Inc.)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE (IBM Corp.)
PRC - C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE (IBM Corp.)
PRC - C:\WINDOWS\system32\QCONSVC.EXE (IBM Corp.)
PRC - C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe ()
PRC - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (Symantec Corporation)
PRC - C:\Program Files\IBM\Messages By IBM\ibmmessages.exe (IBM)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe ()
PRC - C:\Applications\National Instruments\NI-DAQ\HWConfig\nidevldstat.exe (National Instruments Corporation)
PRC - C:\WINDOWS\system32\nipalsm.exe (National Instruments Corporation)
PRC - C:\Applications\bmem\bmem.exe (Brennan Underwood)
PRC - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe ()
PRC - C:\IBMTOOLS\utils\ibmprc.exe (IBM Corp.)
PRC - C:\WINDOWS\system32\TpKmpSvc.exe ()
PRC - C:\WINDOWS\system32\niSvcLoc.exe (National Instruments)
PRC - C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe (IBM Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\shera\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (PsaSrv) -- File not found
SRV - (McShield) -- C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe (McAfee, Inc.)
SRV - (McTaskManager) -- C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
SRV - (McAfeeFramework) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
SRV - (QCONSVC) -- C:\WINDOWS\system32\QCONSVC.EXE (IBM Corp.)
SRV - (SymWSC) -- c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (Symantec Corporation)
SRV - (ACS) -- C:\WINDOWS\system32\acs.exe ()
SRV - (nipxirmu) -- C:\WINDOWS\system32\nipalsm.exe (National Instruments Corporation)
SRV - (nidevldu) -- C:\WINDOWS\system32\nipalsm.exe (National Instruments Corporation)
SRV - (IBM Rapid Restore Ultra Service) -- C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe ()
SRV - (NILM License manager) -- C:\Applications\National Instruments\Shared\License Manager\Bin\lmgrd.exe (Macrovision Corporation)
SRV - (TpKmpSVC) -- C:\WINDOWS\system32\TpKmpSvc.exe ()
SRV - (niSvcLoc) -- C:\WINDOWS\System32\niSvcLoc.exe (National Instruments)
========== Driver Services (SafeList) ==========
DRV - (mfehidk) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) -- C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdik) -- C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) -- C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys (McAfee, Inc.)
DRV - (psadd) -- C:\WINDOWS\system32\drivers\psadd.sys (Windows ® 2000 DDK provider)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) -- C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (ibmfilter) -- C:\WINDOWS\system32\drivers\ibmfilter.sys (IBM)
DRV - (QCNDISIF) -- C:\WINDOWS\system32\drivers\qcndisif.sys (IBM Corporation.)
DRV - (ANC) -- C:\WINDOWS\system32\drivers\ANC.sys (IBM Corp.)
DRV - (IBMTPCHK) -- C:\WINDOWS\system32\drivers\IBMBLDID.SYS ()
DRV - (TPPWR) -- C:\WINDOWS\system32\drivers\TPPWR.SYS (IBM Corp.)
DRV - (Smapint) -- C:\WINDOWS\system32\drivers\SMAPINT.SYS (Microsoft Corporation)
DRV - (TDSMAPI) -- C:\WINDOWS\system32\drivers\TDSMAPI.SYS ()
DRV - (AR5211) -- C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (HSFHWICH) -- C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) -- C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (nissrk) -- C:\WINDOWS\system32\drivers\nissrk.dll (National Instruments Corporation)
DRV - (niwfrk) -- C:\WINDOWS\system32\drivers\niwfrk.dll (National Instruments Corporation)
DRV - (niesrk) -- C:\WINDOWS\system32\drivers\niesrk.dll (National Instruments Corporation)
DRV - (nixsrk) -- C:\WINDOWS\system32\drivers\nixsrk.dll (National Instruments Corporation)
DRV - (nidmmk) -- C:\WINDOWS\system32\drivers\nidmmk.dll (National Instruments Corporation)
DRV - (Nidaq32k) -- C:\WINDOWS\System32\drivers\nidaq32k.sys (National Instruments Corporation)
DRV - (nistck) -- C:\WINDOWS\system32\drivers\niSTCk.dll (National Instruments Corporation)
DRV - (nimdsk) -- C:\WINDOWS\system32\drivers\nimdsk.dll (National Instruments Corporation)
DRV - (nibffrk) -- C:\WINDOWS\system32\drivers\nibffrk.dll (National Instruments Corporation)
DRV - (niarbk) -- C:\WINDOWS\system32\drivers\niarbk.dll (National Instruments Corporation)
DRV - (TSMAPIP) -- C:\WINDOWS\system32\drivers\TSMAPIP.SYS ()
DRV - (NiViPxiK) -- C:\WINDOWS\System32\drivers\NiViPxiK.sys (National Instruments)
DRV - (niswdk) -- C:\WINDOWS\system32\drivers\niswdk.dll (National Instruments Corporation)
DRV - (nisdigk) -- C:\WINDOWS\system32\drivers\nisdigk.dll (National Instruments Corporation)
DRV - (nilvaik) -- C:\WINDOWS\system32\drivers\nilvaik.dll (National Instruments Corporation)
DRV - (nidsark) -- C:\WINDOWS\system32\drivers\nidsark.dll (National Instruments Corporation)
DRV - (nispdk) -- C:\WINDOWS\system32\drivers\nispdk.dll ()
DRV - (niscdk) -- C:\WINDOWS\system32\drivers\niscdk.dll (National Instruments Corporation)
DRV - (nistcrk) -- C:\WINDOWS\system32\drivers\nistcrk.dll (National Instruments Corporation)
DRV - (nitiork) -- C:\WINDOWS\system32\drivers\nitiork.dll (National Instruments Corporation)
DRV - (nimsdrk) -- C:\WINDOWS\system32\drivers\nimsdrk.dll (National Instruments Corporation)
DRV - (nicdrk) -- C:\WINDOWS\system32\drivers\nicdrk.dll (National Instruments Corporation)
DRV - (nidmxfk) -- C:\WINDOWS\system32\drivers\nidmxfk.dll (National Instruments Corporation)
DRV - (nimstsk) -- C:\WINDOWS\system32\drivers\nimstsk.dll (National Instruments Corporation)
DRV - (nimru2k) -- C:\WINDOWS\system32\drivers\nimru2k.dll (National Instruments Corporation)
DRV - (nipxirmk) -- C:\WINDOWS\system32\drivers\nipxirmk.dll (National Instruments Corporation)
DRV - (NIPALK) -- C:\WINDOWS\System32\drivers\nipalk.sys (National Instruments Corporation)
DRV - (gpib420) -- C:\WINDOWS\system32\drivers\gpib420.sys (National Instruments Corporation)
DRV - (GpibPrtK) -- C:\WINDOWS\system32\drivers\GpibPrtK.sys (National Instruments Corporation)
DRV - (lvalarmk) -- C:\WINDOWS\system32\drivers\lvalarmk.dll (National Instruments)
DRV - (niorbk) -- C:\WINDOWS\system32\drivers\niorbk.dll (National Instruments Corporation)
DRV - (nimsrlk) -- C:\WINDOWS\system32\drivers\nimsrlk.dll (National Instruments Corporation)
DRV - (nimslk) -- C:\WINDOWS\system32\drivers\nimslk.dll (National Instruments Corporation)
DRV - (nistc2k) -- C:\WINDOWS\system32\drivers\nistc2k.dll (National Instruments Corporation)
DRV - (nimxpk) -- C:\WINDOWS\system32\drivers\nimxpk.dll (National Instruments Corporation)
DRV - (nidimk) -- C:\WINDOWS\system32\drivers\nidimk.dll (National Instruments Corporation)
DRV - (nimxdfk) -- C:\WINDOWS\system32\drivers\nimxdfk.dll (National Instruments Corporation)
DRV - (nimdbgk) -- C:\WINDOWS\system32\drivers\nimdbgk.dll (National Instruments Corporation)
DRV - (cvintdrv) -- C:\WINDOWS\System32\drivers\cvintdrv.sys ()
DRV - (WINIO) -- C:\WINDOWS\system32\winio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {0506C90D-8D85-4E30-9F54-801E15B05A57}:1.9.1
FF - HKLM\software\mozilla\Firefox\extensions\\{2E68C12D-D3A2-41D1-AC22-8DFF85C16349}: C:\Documents and Settings\shera\Local Settings\Application Data\{2E68C12D-D3A2-41D1-AC22-8DFF85C16349}
FF - HKLM\software\mozilla\Firefox\extensions\\{0506C90D-8D85-4E30-9F54-801E15B05A57}: C:\Documents and Settings\pooper\Local Settings\Application Data\{0506C90D-8D85-4E30-9F54-801E15B05A57}\ [2011/06/26 20:23:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Applications\Mozilla Firefox\components [2011/06/28 23:14:50 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Applications\Mozilla Firefox\plugins [2011/06/28 23:14:29 | 000,000,000 | -H-D | M]
[2011/06/26 22:30:14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\shera\Application Data\Mozilla\Extensions
[2011/06/28 23:04:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\shera\Application Data\Mozilla\Firefox\Profiles\lv4ekymk.default\extensions
File not found (No name found) --
[2007/10/29 22:29:44 | 000,000,000 | -H-D | M] (Java Console) -- C:\APPLICATIONS\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2008/11/16 11:19:36 | 000,000,000 | -H-D | M] (Java Console) -- C:\APPLICATIONS\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2011/06/26 20:23:35 | 000,000,000 | ---D | M] (XULRunner) -- C:\DOCUMENTS AND SETTINGS\POOPER\LOCAL SETTINGS\APPLICATION DATA\{0506C90D-8D85-4E30-9F54-801E15B05A57}
[2010/12/13 21:23:30 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
O1 HOSTS File: ([2004/08/04 09:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll (McAfee, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [BMMGAG] C:\Program Files\ThinkPad\Utilities\PWRMONIT.DLL (IBM Corp.)
O4 - HKLM..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE ()
O4 - HKLM..\Run: [BMMMONWND] C:\Program Files\ThinkPad\Utilities\BATINFEX.DLL ()
O4 - HKLM..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe ()
O4 - HKLM..\Run: [IBMPRC] C:\IBMTOOLS\utils\ibmprc.exe (IBM Corp.)
O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Applications\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NIDAQmxDriverStatus] C:\Applications\National Instruments\NI-DAQ\HWConfig\nidevldstat.exe (National Instruments Corporation)
O4 - HKLM..\Run: [QCTray] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE (IBM Corp.)
O4 - HKLM..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE (IBM Corp.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe (Symantec Corporation)
O4 - HKLM..\Run: [TP4EX] C:\WINDOWS\System32\TP4EX.exe (IBM Corporation)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe ()
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe (IBM Corp.)
O4 - HKLM..\Run: [UC_SMB] File not found
O4 - HKLM..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe ()
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - Startup: C:\Documents and Settings\shera\Start Menu\Programs\Startup\bmem.lnk = C:\Applications\bmem\bmem.exe (Brennan Underwood)
O4 - Startup: C:\Documents and Settings\shera\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\shera\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1291466364281 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\QConGina: DllName - QConGina.dll - C:\WINDOWS\System32\QConGina.dll (IBM Corp.)
O24 - Desktop WallPaper: C:\Documents and Settings\shera\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\shera\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/12/15 09:16:49 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2011/07/03 10:28:02 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\shera\Desktop\OTL.exe
[2011/07/01 18:48:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MpEngineStore
[2011/07/01 18:45:13 | 000,000,000 | ---D | C] -- C:\1ff265ccf20027fc46f76727ad08f951
[2011/06/30 23:29:23 | 000,000,000 | ---D | C] -- C:\28ca9de61a140a4e92
[2011/06/30 23:20:01 | 000,105,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mup.sys
[2011/06/30 23:14:45 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/06/30 23:13:19 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab.exe
[2011/06/28 23:45:11 | 000,000,000 | ---D | C] -- C:\QUARANTINE
[2011/06/28 23:32:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Local Settings\Application Data\Adobe
[2011/06/28 23:11:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\My Documents\Downloads
[2011/06/28 22:32:34 | 001,495,552 | ---- | C] (PGP Corporation) -- C:\WINDOWS\System32\epoPGPsdk.dll
[2011/06/28 22:32:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2011/06/28 22:32:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Cisco Systems
[2011/06/28 22:32:04 | 000,034,152 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfebopk.sys
[2011/06/28 22:32:03 | 000,072,264 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeavfk.sys
[2011/06/28 22:32:03 | 000,064,360 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeapfk.sys
[2011/06/28 22:32:02 | 000,052,136 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfetdik.sys
[2011/06/28 22:32:01 | 000,170,408 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfehidk.sys
[2011/06/28 22:31:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/06/28 22:31:14 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee
[2011/06/28 22:31:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\McAfee
[2011/06/28 22:24:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\KeePass
[2011/06/28 22:24:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\Dropbox
[2011/06/28 22:23:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\ACD Systems
[2011/06/28 22:23:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\PCTeX
[2011/06/28 22:23:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\MathWorks
[2011/06/28 22:23:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\Mathematica
[2011/06/28 22:08:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Desktop\wlf
[2011/06/28 22:08:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Desktop\pdfs-etc
[2011/06/28 06:47:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\Malwarebytes
[2011/06/28 06:40:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\Adobe
[2011/06/27 05:45:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\Macromedia
[2011/06/27 05:44:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\Sun
[2011/06/26 22:29:40 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\shera\PrivacIE
[2011/06/26 22:29:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Local Settings\Application Data\Mozilla
[2011/06/26 22:28:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\Mozilla
[2011/06/26 22:27:07 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\shera\IETldCache
[2011/06/26 22:26:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\Identities
[2011/06/26 22:26:48 | 000,000,000 | --SD | C] -- C:\Documents and Settings\shera\Application Data\Microsoft
[2011/06/26 22:26:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\Sonic
[2011/06/26 22:26:47 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\shera\SendTo
[2011/06/26 22:26:47 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\shera\Recent
[2011/06/26 22:26:47 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\shera\Application Data
[2011/06/26 22:26:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\shera\Start Menu\Programs\Startup
[2011/06/26 22:26:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\shera\Start Menu
[2011/06/26 22:26:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\shera\My Documents\My Pictures
[2011/06/26 22:26:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\shera\My Documents\My Music
[2011/06/26 22:26:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\shera\My Documents
[2011/06/26 22:26:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\shera\Favorites
[2011/06/26 22:26:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\shera\Start Menu\Programs\Accessories
[2011/06/26 22:26:47 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\shera\Cookies
[2011/06/26 22:26:47 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\shera\PrintHood
[2011/06/26 22:26:47 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\shera\NetHood
[2011/06/26 22:26:47 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\shera\Local Settings
[2011/06/26 22:26:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Application Data\Symantec
[2011/06/26 22:26:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Local Settings\Application Data\Microsoft
[2011/06/26 22:26:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Desktop
[2011/06/26 22:26:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\shera\Local Settings\Application Data\BVRP Software
[2011/06/26 22:26:46 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\shera\Templates
[2011/06/26 17:42:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\bA00000FnCkF00000
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/07/03 10:28:21 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\shera\Desktop\OTL.exe
[2011/07/02 21:07:27 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2011/07/02 21:06:15 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/07/02 21:03:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/07/02 21:03:18 | 1063,768,064 | -HS- | M] () -- C:\hiberfil.sys
[2011/07/02 10:58:53 | 000,004,608 | ---- | M] () -- C:\Documents and Settings\shera\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/02 10:53:15 | 000,000,756 | ---- | M] () -- C:\Documents and Settings\shera\Desktop\Shortcut to ACDSee5.exe.lnk
[2011/07/01 18:44:56 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/07/01 07:04:58 | 000,451,836 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/07/01 07:04:57 | 000,073,684 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/07/01 00:02:15 | 000,247,752 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/06/30 05:29:38 | 000,001,002 | ---- | M] () -- C:\Documents and Settings\shera\Start Menu\Programs\Startup\Dropbox.lnk
[2011/06/28 23:37:56 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\shera\Desktop\Shortcut to mbam.exe.lnk
[2011/06/28 23:15:12 | 000,000,709 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/06/26 22:28:22 | 000,000,823 | ---- | M] () -- C:\Documents and Settings\shera\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/26 17:50:57 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Jxabologoce.dat
[2011/06/26 17:50:57 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Khewidimeqagu.bin
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/07/02 10:58:52 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\shera\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/02 10:53:12 | 000,000,756 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\Shortcut to ACDSee5.exe.lnk
[2011/06/30 05:29:34 | 000,001,002 | ---- | C] () -- C:\Documents and Settings\shera\Start Menu\Programs\Startup\Dropbox.lnk
[2011/06/28 23:37:56 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\Shortcut to mbam.exe.lnk
[2011/06/28 23:15:12 | 000,000,715 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/06/28 23:15:12 | 000,000,709 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/06/28 22:39:27 | 000,000,623 | ---- | C] () -- C:\Documents and Settings\shera\Start Menu\Programs\Startup\bmem.lnk
[2011/06/28 22:32:34 | 000,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2011/06/28 22:11:46 | 000,036,099 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\SFValeRight.fig
[2011/06/28 22:11:46 | 000,001,711 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\World Wind 1.3.lnk
[2011/06/28 22:11:46 | 000,000,790 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\Windows Media Player.lnk
[2011/06/28 22:11:46 | 000,000,630 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\Triplist.sxc.lnk
[2011/06/28 22:11:31 | 000,000,729 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\rock-talk.lnk
[2011/06/28 22:11:30 | 000,153,568 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\Polley_CV_HMSformat.pdf
[2011/06/28 22:11:30 | 000,000,735 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\PCTeXv6.lnk
[2011/06/28 22:11:30 | 000,000,728 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\PowerPoint.lnk
[2011/06/28 22:11:30 | 000,000,708 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\Photoshop.lnk
[2011/06/28 22:11:22 | 000,000,830 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\Mathematica.lnk
[2011/06/28 22:11:22 | 000,000,770 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\LabVIEW.lnk
[2011/06/28 22:11:22 | 000,000,685 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\KeePass Password Safe.lnk
[2011/06/28 22:11:22 | 000,000,614 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\JMP7.lnk
[2011/06/28 22:11:21 | 000,001,531 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\FreeMind.lnk
[2011/06/28 22:11:21 | 000,001,016 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\Dropbox.lnk
[2011/06/28 22:11:21 | 000,000,743 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\Illustrator.lnk
[2011/06/28 22:11:21 | 000,000,741 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\emacs.lnk
[2011/06/28 22:11:21 | 000,000,617 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\Gorilla.lnk
[2011/06/28 22:11:16 | 007,312,596 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\digit-exe-windows-4_1.zip
[2011/06/28 22:11:16 | 000,000,561 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\CDex.lnk
[2011/06/28 22:10:47 | 039,955,064 | ---- | C] () -- C:\Documents and Settings\shera\Desktop\Breval sonata.aif
[2011/06/26 22:28:22 | 000,000,811 | ---- | C] () -- C:\Documents and Settings\shera\Start Menu\Programs\Internet Explorer.lnk
[2011/06/26 22:28:02 | 000,000,796 | ---- | C] () -- C:\Documents and Settings\shera\Start Menu\Programs\Windows Media Player.lnk
[2011/06/26 22:26:52 | 000,000,823 | ---- | C] () -- C:\Documents and Settings\shera\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/26 22:26:52 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\shera\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/06/26 22:26:49 | 000,001,503 | ---- | C] () -- C:\Documents and Settings\shera\Start Menu\Programs\Remote Assistance.lnk
[2011/06/26 22:26:49 | 000,000,746 | ---- | C] () -- C:\Documents and Settings\shera\Start Menu\Programs\Outlook Express.lnk
[2011/06/26 17:50:57 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Jxabologoce.dat
[2011/06/26 17:50:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Khewidimeqagu.bin
[2009/04/05 14:27:12 | 000,001,363 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/03/13 13:18:00 | 000,000,048 | ---- | C] () -- C:\WINDOWS\PerWin.ini
[2004/12/15 18:18:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2004/12/15 18:08:08 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/12/15 15:32:25 | 000,099,965 | ---- | C] () -- C:\WINDOWS\UninstallFirefox.exe
[2004/12/15 15:31:18 | 000,007,469 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2004/12/15 13:18:21 | 000,041,324 | ---- | C] () -- C:\WINDOWS\System32\winio.sys
[2004/12/15 13:18:07 | 000,000,156 | ---- | C] () -- C:\WINDOWS\matlab.ini
[2004/12/15 09:19:58 | 000,069,632 | ---- | C] () -- C:\WINDOWS\uinst001.exe
[2004/12/07 21:01:52 | 000,002,481 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/12/07 20:40:33 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/12/07 20:39:07 | 000,184,320 | ---- | C] () -- C:\WINDOWS\TPBATHLP.EXE
[2004/12/07 20:37:52 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
[2004/12/07 20:37:00 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/12/07 20:37:00 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
[2004/12/07 20:36:11 | 000,002,432 | ---- | C] () -- C:\WINDOWS\System32\drivers\IBMBLDID.SYS
[2004/12/07 20:31:18 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\drivers\psasrv.exe
[2004/12/07 20:23:57 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2004/12/07 20:23:57 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2004/12/07 20:23:57 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2004/12/07 20:23:57 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2004/12/07 20:23:57 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2004/12/07 20:23:57 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2004/12/07 20:22:20 | 000,000,136 | ---- | C] () -- C:\WINDOWS\WinInit.ini
[2004/12/07 20:21:51 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\pxhpinst.exe
[2004/12/07 20:15:13 | 000,110,592 | ---- | C] () -- C:\WINDOWS\_tpiu000.exe
[2004/12/07 20:15:06 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\FPCALL.dll
[2004/12/07 20:14:19 | 000,009,341 | ---- | C] () -- C:\WINDOWS\System32\drivers\TDSMAPI.SYS
[2004/12/07 20:13:45 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\TpKmpSvc.exe
[2004/12/07 20:13:34 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2004/12/07 20:13:34 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\acs.exe
[2004/12/07 20:13:33 | 000,651,264 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2004/12/07 20:13:00 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe
[2004/08/09 15:03:43 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/09 15:01:40 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/09 14:51:56 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/09 14:46:20 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/09 14:45:31 | 000,247,752 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/07/27 01:09:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/07/15 20:25:26 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\nipxiini.dll
[2004/07/15 19:54:56 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\niidaqlv.dll
[2004/07/15 18:45:08 | 000,005,081 | ---- | C] () -- C:\WINDOWS\System32\ni7030.dat
[2004/07/15 18:35:54 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\NIAutoConfig.exe
[2004/07/15 18:35:52 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\NIAutoCfgRda.exe
[2004/07/09 13:40:48 | 000,059,497 | ---- | C] () -- C:\WINDOWS\System32\nispdu.dll
[2004/07/08 22:35:32 | 000,010,349 | ---- | C] () -- C:\WINDOWS\System32\niscdrau.dll
[2004/07/08 22:28:00 | 000,068,202 | ---- | C] () -- C:\WINDOWS\System32\drivers\nispdk.dll
[2004/07/07 14:56:20 | 000,003,584 | ---- | C] () -- C:\WINDOWS\System32\nipalpg.dll
[2004/05/03 02:13:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\gpib-vdd.dll
[2004/05/03 02:09:52 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\RemoveRebootKey.exe
[2004/03/19 16:57:22 | 000,000,244 | ---- | C] () -- C:\WINDOWS\System32\nirpc.ini
[2004/03/19 16:12:10 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\pwdmon.dll
[2004/03/19 16:12:10 | 000,019,692 | ---- | C] () -- C:\WINDOWS\ibmprc.ini
[2004/02/17 17:52:10 | 000,008,448 | ---- | C] () -- C:\WINDOWS\System32\drivers\nienetpm.sys
[2004/02/17 17:51:44 | 000,006,173 | ---- | C] () -- C:\WINDOWS\System32\gpib.ini
[2004/01/09 10:10:32 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\AIBMRUNL.dll
[2003/07/29 11:00:00 | 000,007,140 | ---- | C] () -- C:\WINDOWS\System32\drivers\cvintdrv.sys
[2002/12/11 10:57:00 | 000,012,653 | ---- | C] () -- C:\WINDOWS\System32\GPIB.DLL
[2002/03/21 13:51:52 | 000,503,808 | R--- | C] () -- C:\WINDOWS\System32\lt_xtrans.dll
[2002/03/21 13:51:52 | 000,286,720 | R--- | C] () -- C:\WINDOWS\System32\MrSIDD.dll
[2002/03/21 13:51:52 | 000,163,840 | R--- | C] () -- C:\WINDOWS\System32\lt_common.dll
[2002/03/21 13:51:52 | 000,126,976 | R--- | C] () -- C:\WINDOWS\System32\lt_trans.dll
[2002/03/21 13:51:52 | 000,069,632 | R--- | C] () -- C:\WINDOWS\System32\lt_meta.dll
[2002/03/21 13:51:52 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\lt_encrypt.dll
[2002/03/21 13:51:52 | 000,020,480 | R--- | C] () -- C:\WINDOWS\System32\lt_messagetext.dll
[2002/03/20 22:01:06 | 000,006,688 | R--- | C] () -- C:\WINDOWS\System32\Digita.sys
[2002/03/20 22:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportUSB.dll
[2002/03/20 22:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportSerial.dll
[2002/03/20 22:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportIrDA.dll
[2002/03/20 22:00:20 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\TransportIrCOMM.dll
[2002/01/09 22:38:20 | 000,106,496 | ---- | C] () -- C:\WINDOWS\desktopset.exe
[2001/10/28 17:42:30 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2001/08/23 11:26:08 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
[2001/08/23 11:24:30 | 000,004,524 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
[1999/11/15 13:58:52 | 000,028,672 | ---- | C] () -- C:\WINDOWS\NIRegApp.exe
[1999/11/04 12:00:38 | 000,001,840 | ---- | C] () -- C:\WINDOWS\System32\niidaqs.dll
[1999/01/22 14:46:56 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/10/02 13:02:46 | 000,060,416 | ---- | C] () -- C:\WINDOWS\System32\Opcenum.exe
[1980/01/01 04:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[1980/01/01 04:00:00 | 000,451,836 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[1980/01/01 04:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[1980/01/01 04:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[1980/01/01 04:00:00 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\e1000msg.dll
[1980/01/01 04:00:00 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\tp4uires.dll
[1980/01/01 04:00:00 | 000,073,684 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[1980/01/01 04:00:00 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\tp4unins.exe
[1980/01/01 04:00:00 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ibmpmsvc.exe
[1980/01/01 04:00:00 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\tpinspm.dll
[1980/01/01 04:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[1980/01/01 04:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[1980/01/01 04:00:00 | 000,005,600 | ---- | C] () -- C:\WINDOWS\System32\tp4table.dat
[1980/01/01 04:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[1980/01/01 04:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[1980/01/01 04:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2004/12/14 18:26:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2011/06/26 17:42:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\bA00000FnCkF00000
[2004/12/07 20:23:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ibm
[2011/06/28 22:24:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\shera\Application Data\ACD Systems
[2011/07/03 10:26:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\shera\Application Data\Dropbox
[2011/07/01 23:08:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\shera\Application Data\KeePass
[2011/06/28 22:23:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\shera\Application Data\PCTeX
[2005/01/29 16:39:32 | 000,000,554 | ---- | M] () -- C:\WINDOWS\Tasks\BMMTask.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2004/12/15 09:16:49 | 000,000,000 | -H-- | M] () -- C:\AUTOEXEC.BAT
[2004/12/15 09:15:46 | 000,000,194 | RHS- | M] () -- C:\BOOT.INI
[2004/12/07 20:17:08 | 000,000,000 | -H-- | M] () -- C:\BOOTLOG.PRV
[2004/12/07 20:41:40 | 000,000,000 | -H-- | M] () -- C:\BOOTLOG.TXT
[2004/08/09 14:35:38 | 000,000,512 | -HS- | M] () -- C:\BOOTSECT.DOS
[2004/12/07 20:38:46 | 000,000,355 | ---- | M] () -- C:\ccrrec.ver
[2004/12/15 09:16:49 | 000,000,000 | -H-- | M] () -- C:\CONFIG.SYS
[2004/12/07 20:21:38 | 000,000,754 | ---- | M] () -- C:\drivez.log
[2011/07/02 21:03:18 | 1063,768,064 | -HS- | M] () -- C:\hiberfil.sys
[2004/12/15 09:16:49 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2004/12/07 20:19:48 | 000,000,164 | ---- | M] () -- C:\LOGFILE.txt
[2004/08/04 09:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/01/18 12:57:40 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2011/07/02 21:03:15 | 1258,291,200 | -HS- | M] () -- C:\pagefile.sys
[2004/12/07 21:01:52 | 000,001,370 | ---- | M] () -- C:\SYSLEVEL.IBM
[2004/12/07 21:00:20 | 000,000,043 | ---- | M] () -- C:\TCPACHIP.LOG
[2004/12/15 15:00:10 | 000,000,043 | ---- | M] () -- C:\ver.txt
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/09 14:54:48 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
[2003/07/15 20:35:04 | 000,002,193 | ---- | M] () -- C:\WINDOWS\system32\TpShPrm.jpg
[6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\*.jpg >
[2002/10/10 17:07:40 | 000,055,408 | ---- | M] () -- C:\WINDOWS\1024 x 768 IBM Americas Map.jpg
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/09 14:45:10 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2004/08/09 14:45:10 | 000,659,456 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2004/08/09 14:45:10 | 000,876,544 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/06/26 22:28:18 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\shera\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/09 15:03:14 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\shera\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/07/03 10:28:21 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\shera\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-07-01 23:27:18
< End of report >
Attached File(s)
-
ark.txt (8.69K)
Number of downloads: 0 -
Extras.Txt (45.5K)
Number of downloads: 1

Help
This topic is locked

Back to top











