My system got infected with Essential Cleaner Virus. Please help remove.
Malware Bytes crashes my system when I try to run it...
I have executed the OTL.exe and these are the 2 outputs I got:
OTL logfile created on: 5/6/2011 6:23:54 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = D:\Documents and Settings\501831044\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 37.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 53.00% Paging File free
Paging file location(s): C:\PageFile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 116.02 Gb Total Space | 94.52 Gb Free Space | 81.46% Space Free | Partition Type: NTFS
Drive D: | 114.85 Gb Total Space | 97.49 Gb Free Space | 84.88% Space Free | Partition Type: NTFS
Computer Name: T00690712 | User Name: 501831044 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/06 18:22:24 | 000,580,608 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\501831044\Desktop\OTL.exe
PRC - [2011/05/06 18:00:05 | 000,377,344 | ---- | M] () -- D:\Documents and Settings\All Users\Application Data\nO31000AlMdN31000\nO31000AlMdN31000.exe
PRC - [2011/04/30 16:46:15 | 000,274,608 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2011/04/30 14:26:17 | 000,139,264 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jdk1.6.0_18\bin\java.exe
PRC - [2011/04/29 14:45:47 | 000,125,992 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe
PRC - [2011/04/29 14:45:47 | 000,030,248 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe
PRC - [2011/04/29 14:45:44 | 000,093,736 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
PRC - [2011/04/29 14:45:41 | 000,104,488 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
PRC - [2011/04/29 14:45:38 | 000,802,816 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Remote Management System\RouterNT.exe
PRC - [2011/04/29 14:45:38 | 000,278,528 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
PRC - [2011/02/23 08:22:08 | 000,094,008 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files\WebEx\Productivity Tools\ptSrv.exe
PRC - [2011/02/23 08:22:06 | 000,347,448 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe
PRC - [2010/12/16 17:54:58 | 000,931,184 | ---- | M] (Juniper Networks, Inc.) -- C:\Program Files\Juniper Networks\Odyssey Access Client\odTray.exe
PRC - [2010/12/16 17:54:54 | 000,193,904 | ---- | M] (Juniper Networks, Inc.) -- C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe
PRC - [2010/12/16 17:26:50 | 000,152,944 | ---- | M] (Juniper Networks) -- C:\Program Files\Common Files\Juniper Networks\TNC Client\jTnccService.exe
PRC - [2010/12/16 05:32:26 | 000,402,800 | ---- | M] (Juniper Networks) -- C:\Program Files\Common Files\Juniper Networks\Endpoint Defense\dsEES.exe
PRC - [2010/12/16 00:37:00 | 000,198,000 | ---- | M] (Juniper Networks) -- C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe
PRC - [2010/07/07 22:43:32 | 000,217,912 | ---- | M] (WebEx) -- C:\Program Files\WebEx\Connect\wbxcOIEx.exe
PRC - [2010/07/07 22:39:36 | 003,677,496 | ---- | M] (Cisco WebEx) -- C:\Program Files\WebEx\Connect\connect.exe
PRC - [2010/05/13 04:33:44 | 000,288,112 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2010/04/21 06:58:54 | 000,495,708 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
PRC - [2010/04/21 06:58:54 | 000,237,650 | ---- | M] (IDT, Inc.) -- c:\Program Files\IDT\WDM\stacsv.exe
PRC - [2010/04/12 11:50:58 | 000,238,904 | ---- | M] () -- C:\Program Files\WebEx\Connect\Widget.exe
PRC - [2010/03/24 08:09:28 | 000,812,448 | ---- | M] (Broadcom Corporation) -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
PRC - [2010/03/24 08:09:28 | 000,027,040 | ---- | M] (Broadcom Corporation) -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
PRC - [2010/03/23 21:22:26 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2010/02/18 00:34:40 | 000,054,568 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2010/02/03 04:09:46 | 000,429,096 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\AutoUpdate\ALMon.exe
PRC - [2010/02/03 04:09:46 | 000,175,144 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
PRC - [2010/01/10 20:01:26 | 000,060,928 | ---- | M] () -- C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe
PRC - [2009/11/20 23:55:42 | 002,119,032 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
PRC - [2009/11/20 23:55:42 | 000,632,160 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2009/10/02 05:19:16 | 000,380,988 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Endpoint Encryption for PC\SbClientManager.exe
PRC - [2009/09/19 01:01:08 | 000,333,088 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwtracepktwpp.exe
PRC - [2009/08/19 09:20:52 | 000,069,632 | ---- | M] () -- C:\Program Files\SafeBoot Tray Manager\SbTrayManager.exe
PRC - [2009/07/07 10:06:46 | 000,737,280 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\AESTFltr.exe
PRC - [2009/03/26 22:58:08 | 000,431,472 | ---- | M] (Juniper Networks) -- C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
PRC - [2009/02/08 03:11:00 | 000,155,648 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\amswmagt.exe
PRC - [2009/02/08 03:10:10 | 000,026,624 | ---- | M] () -- C:\Program Files\CA\DSM\PMAgent\capmuamagt.exe
PRC - [2009/02/08 01:23:12 | 000,221,184 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\ccnfAgent.exe
PRC - [2009/02/08 01:22:48 | 000,031,232 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\ccsmagtd.exe
PRC - [2009/02/08 01:21:10 | 000,200,704 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\cfnotsrvd.exe
PRC - [2009/02/08 01:21:10 | 000,057,344 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\cfFTPlugin.exe
PRC - [2009/02/08 01:21:10 | 000,027,136 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\cfsmsmd.exe
PRC - [2009/02/08 01:21:08 | 000,188,416 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\CAF.exe
PRC - [2009/02/01 07:43:30 | 000,049,250 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2008/12/09 16:34:20 | 000,147,456 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\SC\CAM\bin\cam.exe
PRC - [2008/04/14 08:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/14 08:00:00 | 000,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cmd.exe
PRC - [2005/08/29 22:03:50 | 059,027,456 | ---- | M] (Oracle Corporation) -- d:\oracle\product\10.2.0\db_1\BIN\oracle.exe
PRC - [2005/08/16 12:22:04 | 000,006,656 | ---- | M] (Oracle Corporation) -- D:\oracle\product\10.2.0\db_1\BIN\emagent.exe
PRC - [2005/08/16 12:21:06 | 000,024,064 | ---- | M] (Oracle Corporation) -- D:\oracle\product\10.2.0\db_1\BIN\nmesrvc.exe
PRC - [2005/08/16 01:23:02 | 000,053,248 | ---- | M] (Oracle) -- D:\oracle\product\10.2.0\db_1\BIN\isqlplussvc.exe
PRC - [2005/08/15 23:57:48 | 000,204,800 | ---- | M] () -- D:\oracle\product\10.2.0\db_1\BIN\TNSLSNR.EXE
PRC - [2005/04/08 19:09:00 | 000,045,161 | ---- | M] () -- D:\oracle\product\10.2.0\db_1\jdk\bin\java.exe
PRC - [2004/11/15 09:35:30 | 000,016,384 | ---- | M] () -- D:\oracle\product\10.2.0\db_1\perl\5.8.3\bin\MSWin32-x86-multi-thread\perl.exe
========== Modules (SafeList) ==========
MOD - File not found -- C:\WINDOWS\System32\DgApi.dll
MOD - File not found -- C:\Program Files\DGAgent\plugins\09D849B6-32D3-4a40-85EE-6B84BA29E35B\AME_SMTPSensor.dll
MOD - File not found -- C:\Program Files\DGAgent\plugins\09D849B6-32D3-4a40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
MOD - File not found -- C:\Program Files\DGAgent\plugins\09D849B6-32D3-4a40-85EE-6B84BA29E35B\AE_MailSensor_Plugin.dll
MOD - [2011/05/06 18:22:24 | 000,580,608 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\501831044\Desktop\OTL.exe
MOD - [2011/04/29 14:45:40 | 000,237,832 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll
MOD - [2010/08/23 12:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/11/20 23:55:52 | 000,099,688 | ---- | M] (Broadcom Corporation.) -- C:\WINDOWS\system32\BtMmHook.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/04/29 14:45:47 | 000,125,992 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe -- (Sophos Client Firewall Manager)
SRV - [2011/04/29 14:45:47 | 000,030,248 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe -- (Sophos Client Firewall)
SRV - [2011/04/29 14:45:44 | 000,093,736 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe -- (SAVService)
SRV - [2011/04/29 14:45:41 | 000,104,488 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe -- (SAVAdminService)
SRV - [2011/04/29 14:45:38 | 000,802,816 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\Remote Management System\RouterNT.exe -- (Sophos Message Router)
SRV - [2011/04/29 14:45:38 | 000,278,528 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe -- (Sophos Agent)
SRV - [2010/12/16 17:54:54 | 000,193,904 | ---- | M] (Juniper Networks, Inc.) [Auto | Running] -- C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe -- (odClientService)
SRV - [2010/12/16 17:26:50 | 000,152,944 | ---- | M] (Juniper Networks) [On_Demand | Running] -- C:\Program Files\Common Files\Juniper Networks\TNC Client\jTnccService.exe -- (EacService)
SRV - [2010/12/16 00:37:00 | 000,198,000 | ---- | M] (Juniper Networks) [Auto | Running] -- C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe -- (JuniperAccessService)
SRV - [2010/08/14 01:11:20 | 008,750,408 | ---- | M] () [Auto | Running] -- C:\Program Files\MANDIANT\MANDIANT Intelligent Response Agent\MAVservice.exe -- (IAScan)
SRV - [2010/04/21 06:58:54 | 000,237,650 | ---- | M] (IDT, Inc.) [Auto | Running] -- c:\Program Files\IDT\WDM\stacsv.exe -- (STacSV)
SRV - [2010/03/24 08:09:28 | 000,812,448 | ---- | M] (Broadcom Corporation) [Auto | Running] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe -- (Credential Vault Host Control Service)
SRV - [2010/03/24 08:09:28 | 000,027,040 | ---- | M] (Broadcom Corporation) [Auto | Running] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe -- (Credential Vault Host Storage)
SRV - [2010/02/03 04:09:46 | 000,175,144 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\AutoUpdate\ALsvc.exe -- (Sophos AutoUpdate Service)
SRV - [2010/01/10 20:01:26 | 000,060,928 | ---- | M] () [Auto | Running] -- C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe -- (InstallFilterService)
SRV - [2009/10/02 05:19:16 | 000,380,988 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\Endpoint Encryption for PC\SbClientManager.exe -- (SafeBootClientManager)
SRV - [2009/03/26 22:58:08 | 000,431,472 | ---- | M] (Juniper Networks) [Auto | Running] -- C:\Program Files\Juniper Networks\Common Files\dsNcService.exe -- (dsNcService)
SRV - [2009/02/08 01:21:08 | 000,188,416 | ---- | M] (CA) [Auto | Running] -- C:\Program Files\CA\DSM\bin\caf.exe -- (caf)
SRV - [2008/12/09 16:34:20 | 000,147,456 | ---- | M] (CA, Inc.) [Auto | Running] -- C:\Program Files\CA\SC\CAM\bin\cam.exe -- (CA-MessageQueuing)
SRV - [2005/08/29 22:03:50 | 059,027,456 | ---- | M] (Oracle Corporation) [Auto | Running] -- d:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE -- (OracleServiceENOVIA)
SRV - [2005/08/29 19:32:22 | 000,102,400 | ---- | M] () [Disabled | Stopped] -- d:\oracle\product\10.2.0\db_1\Bin\extjob.exe -- (OracleJobSchedulerENOVIA)
SRV - [2005/08/16 12:21:06 | 000,024,064 | ---- | M] (Oracle Corporation) [Auto | Running] -- D:\oracle\product\10.2.0\db_1\BIN\nmesrvc.exe -- (OracleDBConsoleenovia)
SRV - [2005/08/16 01:23:02 | 000,053,248 | ---- | M] (Oracle) [Auto | Running] -- D:\oracle\product\10.2.0\db_1\BIN\isqlplussvc.exe -- (OracleOraDb10g_home1iSQL*Plus)
SRV - [2005/08/15 23:57:48 | 000,204,800 | ---- | M] () [Auto | Running] -- D:\oracle\product\10.2.0\db_1\BIN\TNSLSNR.exe -- (OracleOraDb10g_home1TNSListener)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DGUSBMon.SYS -- (DGUSBMon)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGTDIMon.SYS -- (DGTDIMon)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGRule.SYS -- (DGRule)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgRec.sys -- (DGREC)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGMaster.sys -- (DGMaster)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGKPMail.sys -- (DGKPMail)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGFSMon.SYS -- (DGFSMon)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgFiltr.sys -- (DGFILTR)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgDtl.sys -- (DGDTL)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgDt.sys -- (DGDT)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgDsl.sys -- (DGDSL)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgDs.sys -- (DGDS)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgDmkl.sys -- (DGDmkl)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\DgDmkDisk.sys -- (DgDmkDisk)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgDmk.sys -- (DGDmk)
DRV - File not found [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\DGCOTMAN.sys -- (DGCOTMAN)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGBusMon.SYS -- (DGBusMon)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGAPIMon.SYS -- (DGAPIMon)
DRV - [2011/04/29 21:58:18 | 000,909,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2011/04/29 21:58:18 | 000,047,656 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2011/04/29 19:05:18 | 000,019,920 | ---- | M] () [Kernel | On_Demand | Running] -- D:\Documents and Settings\All Users\Application Data\MANDIANT\MANDIANT Intelligent Response Agent\mktools.sys -- (Mandiant_Tools)
DRV - [2011/04/29 14:45:47 | 000,100,136 | ---- | M] (Sophos Plc) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\scfdriver.sys -- (scfdriver)
DRV - [2011/04/29 14:45:45 | 000,024,064 | ---- | M] (Sophos Plc) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\savonaccessfilter.sys -- (SAVOnAccessFilter)
DRV - [2011/04/29 14:45:42 | 000,023,928 | ---- | M] (Sophos Plc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sdcfilter.sys -- (sdcfilter)
DRV - [2011/04/29 14:45:42 | 000,014,976 | ---- | M] (Sophos Plc) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\SophosBootDriver.sys -- (SophosBootDriver)
DRV - [2011/04/29 14:45:40 | 000,152,192 | ---- | M] (Sophos Plc) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\savonaccesscontrol.sys -- (SAVOnAccessControl)
DRV - [2011/04/24 18:14:38 | 000,225,856 | ---- | M] (QFX Software Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\keyscrambler.sys -- (KeyScrambler)
DRV - [2010/12/16 17:09:44 | 000,282,496 | ---- | M] (Juniper Networks, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\odFips2.sys -- (odFips2)
DRV - [2010/12/16 17:09:44 | 000,009,856 | ---- | M] (Juniper Networks, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\odFips.sys -- (odFips)
DRV - [2010/07/15 15:09:18 | 000,034,800 | ---- | M] (Juniper Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\jnprvamgr.sys -- (JnprVaMgr)
DRV - [2010/07/15 15:09:14 | 000,017,776 | ---- | M] (Juniper Networks, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\jnprva.sys -- (jnprva)
DRV - [2010/07/15 15:09:12 | 000,420,464 | ---- | M] (Juniper Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\jnprna.sys -- (jnprna)
DRV - [2010/05/13 04:17:00 | 000,255,096 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2010/04/21 06:58:54 | 001,660,051 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2010/04/06 08:35:56 | 000,168,616 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1k5132.sys -- (e1kexpress) Intel(R)
DRV - [2010/03/20 00:39:08 | 000,059,904 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\risdpe86.sys -- (risdpcie)
DRV - [2010/02/27 07:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Impcd.sys -- (Impcd)
DRV - [2010/02/03 11:47:36 | 002,696,448 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2010/01/19 20:50:12 | 000,235,520 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV - [2010/01/18 15:56:26 | 000,042,672 | ---- | M] (ST Microelectronics) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Accelern.sys -- (Acceler)
DRV - [2010/01/18 15:56:26 | 000,017,072 | ---- | M] (ST Microelectronics) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\stdfltn.sys -- (stdflt)
DRV - [2009/11/04 01:40:42 | 000,033,832 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cvusbdrv.sys -- (cvusbdrv)
DRV - [2009/10/06 13:49:48 | 000,187,960 | ---- | M] (Advanced Micro Devices, Inc) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ahcix86.sys -- (ahcix86)
DRV - [2009/10/02 05:18:49 | 000,015,248 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\SbPrcCtl.sys -- (SbPrcCtl)
DRV - [2009/10/02 05:18:27 | 000,006,496 | ---- | M] (McAfee, Inc.) [File_System | Boot | Running] -- C:\WINDOWS\System32\drivers\SbFsLock.sys -- (SbFsLock)
DRV - [2009/10/02 05:18:23 | 000,033,328 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\RsvLock.sys -- (RsvLock)
DRV - [2009/10/02 05:18:16 | 000,034,480 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\SbFlop.sys -- (SbFlop)
DRV - [2009/10/02 05:17:57 | 000,103,760 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\SafeBoot.sys -- (SafeBoot)
DRV - [2009/05/21 05:48:10 | 000,029,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbccid.sys -- (USBCCID)
DRV - [2009/04/22 06:13:34 | 000,113,664 | ---- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AESTAud.sys -- (AESTAud)
DRV - [2009/03/26 22:41:04 | 000,023,552 | ---- | M] (Juniper Networks) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dsNcAdpt.sys -- (dsNcAdpt)
DRV - [2008/08/13 13:51:42 | 000,044,976 | ---- | M] (SafeBoot N.V.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\SbAlg.sys -- (SBAlg)
DRV - [2008/06/04 22:14:00 | 000,026,608 | ---- | M] (Dell Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\PBADRV.sys -- (PBADRV)
DRV - [2008/04/04 21:40:50 | 000,244,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\e1y5132.sys -- (e1yexpress) Intel(R)
DRV - [2007/09/19 15:36:16 | 000,100,096 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symmpi.sys -- (Symmpi)
DRV - [2004/11/05 16:54:50 | 000,136,704 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\fasttx2k.sys -- (fasttx2k)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://energy.home.ge.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = http://ps.setpac.ge.com/pac.pac
========== FireFox ==========
FF - prefs.js..network.proxy.autoconfig_url: "http://ps.setpac.ge.com/pac.pac"
FF - prefs.js..network.proxy.type: 2
FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: D:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/04/30 16:46:25 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/30 16:46:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/04/29 18:17:24 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\501831044\Application Data\Mozilla\Extensions
[2011/05/03 21:16:16 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\501831044\Application Data\Mozilla\Firefox\Profiles\9flgsxuu.default\extensions
[2011/04/30 16:57:40 | 000,000,000 | ---D | M] (KeyScrambler) -- D:\Documents and Settings\501831044\Application Data\Mozilla\Firefox\Profiles\9flgsxuu.default\extensions\keyscrambler@qfx.software.corporation
[2011/04/30 14:27:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2011/04/30 14:26:59 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
() (No name found) -- D:\DOCUMENTS AND SETTINGS\501831044\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\9FLGSXUU.DEFAULT\EXTENSIONS\{0545B830-F0AA-4D7E-8820-50A4629A56FE}.XPI
() (No name found) -- D:\DOCUMENTS AND SETTINGS\501831044\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\9FLGSXUU.DEFAULT\EXTENSIONS\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.XPI
[2011/04/30 16:46:25 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- D:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/04/14 12:26:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 04:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/05/05 19:43:41 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (KeyScramblerBHO Class) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Plc)
O2 - BHO: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files\WebEx\Productivity Tools\ptonecli.dll (Cisco WebEx LLC)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files\WebEx\Productivity Tools\ptonecli.dll (Cisco WebEx LLC)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [AESTFltr] C:\WINDOWS\System32\AESTFltr.exe (Andrea Electronics Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [GEvpnPacCheck] C:\Program Files\Juniper Networks\VPN_PAC_CHECK.vbs ()
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [OdTray.exe] C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe (Juniper Networks, Inc.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SafeBootTrayManager] C:\Program Files\SafeBoot Tray Manager\SbTrayManager.exe ()
O4 - HKLM..\Run: [SetCacheMode] C:\WINDOWS\System32\ptipbmf.dll ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_15\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [CheckIt] C:\WINDOWS/SYSTEM32/GE/Scripts/Checkit.vbs ()
O4 - HKCU..\Run: [PTOneClick] C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe (Cisco WebEx LLC)
O4 - HKCU..\RunOnce: [nO31000AlMdN31000] D:\Documents and Settings\All Users\Application Data\nO31000AlMdN31000\nO31000AlMdN31000.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A82000000003}\IconAC76BA86.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Sophos AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: nodrivetypeautorun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogOff = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogonScripts = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &KeyScrambler Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O15 - HKLM\..Trusted Domains: vetco.com ([]* in Local intranet)
O15 - HKLM\..Trusted Domains: vetcogray.com ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: ge.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([*.supportcentral] * in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([cincnt1.ssqc] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([cincnt2.ssqc] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([genet.ae] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([inside] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([libraries] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([ssqc] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([time.infra] * in Trusted sites)
O15 - HKCU\..Trusted Domains: logmeinrescue-enterprise.com ([secure] https in Trusted sites)
O15 - HKCU\..Trusted Domains: mahindrasatyam.com ([ontime] https in Trusted sites)
O15 - HKCU\..Trusted Domains: vetco.com ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: vetcogray.com ([]* in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://emeetings.webex.com/client/T27L10NSP21EP5-emeetings/webex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupControlXP Class)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O16 - DPF: {FCADE536-93F5-4577-80A3-E7C32FAC4C7D} http://internal.infra.ge.com/qcbin/Spider10.cab (Loader Class v5)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.178.162.3 97.81.22.195 24.159.64.23
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = psamer.ps.ge.com
O20 - AppInit_DLLs: (C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Plc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\CAF: DllName - C:\Program Files\CA\DSM\Bin\cfwlogon.dll - C:\Program Files\CA\DSM\bin\cfWlogon.dll (CA)
O20 - Winlogon\Notify\OdysseyClient: DllName - odyEvent.dll - C:\WINDOWS\System32\odyEvent.dll (Juniper Networks, Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/05 11:28:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{6d4d3ccc-e02b-11de-9e7b-ed3e4b11f6bb}\Shell\AutoRun\command - "" = Programs\nu2menu\nu2menu.exe
O33 - MountPoints2\{8a9ac29a-a232-11de-a438-844cddf9895f}\Shell\AutoRun\command - "" = Programs\nu2menu\nu2menu.exe
O33 - MountPoints2\{96e5771a-8bda-11df-b3c4-bc2b75784766}\Shell\AutoRun\command - "" = Programs\nu2menu\nu2menu.exe
O33 - MountPoints2\{dff8e6fa-7348-11df-8f47-cc826885f0a8}\Shell - "" = AutoRun
O33 - MountPoints2\{dff8e6fa-7348-11df-8f47-cc826885f0a8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{dff8e6fa-7348-11df-8f47-cc826885f0a8}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{dff8e6fb-7348-11df-8f47-c4cfda9322b7}\Shell\AutoRun\command - "" = Programs\nu2menu\nu2menu.exe
O33 - MountPoints2\{f6189e64-e23e-11df-a702-9801d6bd58ac}\Shell\AutoRun\command - "" = Programs\nu2menu\nu2menu.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/06 18:22:16 | 000,580,608 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\501831044\Desktop\OTL.exe
[2011/05/06 18:00:04 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\nO31000AlMdN31000
[2011/05/05 08:08:33 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Local Settings\Application Data\Google
[2011/05/02 14:50:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2011/05/02 10:40:11 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\ief
[2011/05/01 20:47:15 | 000,000,000 | ---D | C] -- C:\Program Files\Dassault Systemes
[2011/05/01 20:46:32 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Local Settings\Application Data\DassaultSystemes
[2011/05/01 20:46:32 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Application Data\DassaultSystemes
[2011/05/01 19:59:35 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Local Settings\Application Data\Mercury Interactive
[2011/05/01 19:58:43 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Application Data\09D849B6-32D3-4a40-85EE-6B84BA29E35B
[2011/05/01 19:56:24 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\{F28EEC54-8380-4273-BE32-4052A058D37E}
[2011/05/01 19:55:26 | 000,000,000 | ---D | C] -- D:\Documents and Settings\LocalService\Local Settings\Application Data\Seven Zip
[2011/05/01 19:49:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Mercury Interactive
[2011/05/01 00:56:39 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Start Menu\Programs\EditPlus 3
[2011/05/01 00:56:38 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Application Data\EditPlus 3
[2011/05/01 00:56:38 | 000,000,000 | ---D | C] -- C:\Program Files\EditPlus 3
[2011/04/30 17:06:55 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\QFX Software
[2011/04/30 17:06:55 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Application Data\QFX Software
[2011/04/30 16:57:28 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\KeyScrambler
[2011/04/30 16:57:26 | 000,225,856 | ---- | C] (QFX Software Corporation) -- C:\WINDOWS\System32\drivers\keyscrambler.sys
[2011/04/30 16:57:26 | 000,000,000 | ---D | C] -- C:\Program Files\KeyScrambler
[2011/04/30 16:47:26 | 000,000,000 | ---D | C] -- C:\Program Files\EditPlus 2
[2011/04/30 16:46:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2011/04/30 16:46:21 | 000,199,904 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll
[2011/04/30 16:46:16 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\WINDOWS\System32\pncrt.dll
[2011/04/30 16:46:16 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll
[2011/04/30 16:46:16 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll
[2011/04/30 16:46:16 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Real
[2011/04/30 16:46:10 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Real
[2011/04/30 16:46:10 | 000,000,000 | ---D | C] -- C:\Program Files\Real
[2011/04/30 16:45:52 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Application Data\Real
[2011/04/30 16:44:48 | 000,025,088 | ---- | C] (Microsoft Corporation) -- D:\Documents and Settings\501831044\Desktop\ZAPGRAB2.EXE
[2011/04/30 16:25:45 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\DassaultSystemes
[2011/04/30 16:03:44 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\ENOVIA Live Collaboration Server
[2011/04/30 16:01:03 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Oracle
[2011/04/30 15:54:53 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\ENOVIA Studio Modeling Platform
[2011/04/30 15:53:09 | 000,000,000 | ---D | C] -- C:\enoviav6r2010x
[2011/04/30 15:03:38 | 000,000,000 | ---D | C] -- C:\Program Files\apache-tomcat-6.0.24
[2011/04/30 14:42:17 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio .NET
[2011/04/30 14:42:17 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Local Settings\Application Data\Microsoft Help
[2011/04/30 14:41:10 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Oracle - OraDb10g_home1
[2011/04/30 14:38:03 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
[2011/04/30 14:27:25 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Sun
[2011/04/30 14:27:14 | 000,000,000 | ---D | C] -- C:\Program Files\Sun
[2011/04/29 22:02:29 | 000,016,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsgXP_2k3.dll
[2011/04/29 22:02:26 | 000,000,000 | ---D | C] -- C:\Program Files\DellTPad
[2011/04/29 22:02:23 | 001,461,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WdfCoInstaller01009.dll
[2011/04/29 22:02:23 | 000,255,096 | ---- | C] (Alps Electric Co., Ltd.) -- C:\WINDOWS\System32\drivers\Apfiltr.sys
[2011/04/29 22:02:23 | 000,109,122 | ---- | C] (Alps Electric Co., Ltd.) -- C:\WINDOWS\System32\Vxdif.dll
[2011/04/29 22:01:50 | 000,106,557 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\btw_ci.dll
[2011/04/29 22:01:50 | 000,092,072 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btwsecfl.sys
[2011/04/29 22:01:50 | 000,047,656 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btwusb.sys
[2011/04/29 22:01:49 | 000,909,736 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btkrnl.sys
[2011/04/29 22:01:45 | 000,000,000 | ---D | C] -- C:\Program Files\WIDCOMM
[2011/04/29 22:01:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\Dell
[2011/04/29 21:56:48 | 000,042,672 | ---- | C] (ST Microelectronics) -- C:\WINDOWS\System32\drivers\Accelern.sys
[2011/04/29 21:56:48 | 000,017,072 | ---- | C] (ST Microelectronics) -- C:\WINDOWS\System32\drivers\stdfltn.sys
[2011/04/29 21:56:48 | 000,000,000 | ---D | C] -- C:\Program Files\STMicroelectronics
[2011/04/29 21:56:46 | 000,000,000 | ---D | C] -- C:\Dell
[2011/04/29 21:56:32 | 002,696,448 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\drivers\BCMWL5.SYS
[2011/04/29 21:56:23 | 011,870,298 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\idtsg.cpl
[2011/04/29 21:56:23 | 003,358,720 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\stlang.dll
[2011/04/29 21:56:23 | 000,737,280 | ---- | C] (Andrea Electronics Corporation) -- C:\WINDOWS\System32\AESTFltr.exe
[2011/04/29 21:56:23 | 000,253,952 | ---- | C] (Andrea Electronics Corporation) -- C:\WINDOWS\System32\AESTCtrl.cpl
[2011/04/29 21:56:20 | 001,660,051 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\drivers\sthda.sys
[2011/04/29 21:56:20 | 000,544,866 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\stacapi.dll
[2011/04/29 21:56:20 | 000,175,616 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\st326281.dll
[2011/04/29 21:56:18 | 000,113,664 | ---- | C] (Andrea Electronics Corporation) -- C:\WINDOWS\System32\drivers\AESTAud.sys
[2011/04/29 21:56:18 | 000,000,000 | ---D | C] -- C:\Program Files\IDT
[2011/04/29 21:55:55 | 001,419,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WdfCoInstaller01005.dll
[2011/04/29 21:55:55 | 000,033,832 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\drivers\cvusbdrv.sys
[2011/04/29 21:55:22 | 000,000,000 | ---D | C] -- C:\Program Files\Broadcom Corporation
[2011/04/29 21:55:19 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2011/04/29 21:55:18 | 000,026,608 | ---- | C] (Dell Inc) -- C:\WINDOWS\System32\drivers\PBADRV.sys
[2011/04/29 21:55:15 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbccid.sys
[2011/04/29 21:55:10 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbccid.sys
[2011/04/29 21:54:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\BioAPIFFDB
[2011/04/29 21:52:07 | 000,168,616 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\drivers\e1k5132.sys
[2011/04/29 21:52:07 | 000,074,944 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\NicInstK.dll
[2011/04/29 21:52:07 | 000,068,264 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\e1kmsg.dll
[2011/04/29 21:51:59 | 000,319,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\difxapi.dll
[2011/04/29 21:51:57 | 000,132,480 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\drivers\Impcd.sys
[2011/04/29 21:51:56 | 000,006,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\splitter.sys
[2011/04/29 21:51:55 | 000,083,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wdmaud.sys
[2011/04/29 21:51:53 | 000,052,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dmusic.sys
[2011/04/29 21:51:52 | 000,056,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swmidi.sys
[2011/04/29 21:51:51 | 000,142,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aec.sys
[2011/04/29 21:51:50 | 000,172,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kmixer.sys
[2011/04/29 21:51:49 | 000,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\drmkaud.sys
[2011/04/29 21:51:48 | 000,060,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sysaudio.sys
[2011/04/29 21:51:47 | 000,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mskssrv.sys
[2011/04/29 21:51:46 | 000,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mspqm.sys
[2011/04/29 21:51:44 | 000,005,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mspclock.sys
[2011/04/29 21:51:42 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksproxy.ax
[2011/04/29 21:51:42 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksproxy.ax
[2011/04/29 21:51:42 | 000,060,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmk.sys
[2011/04/29 21:51:42 | 000,060,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\drmk.sys
[2011/04/29 21:51:42 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksuser.dll
[2011/04/29 21:51:42 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksuser.dll
[2011/04/29 21:51:39 | 000,235,520 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\IntcDAud.sys
[2011/04/29 21:51:29 | 010,960,384 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\ig4icd32.dll
[2011/04/29 21:51:29 | 004,095,488 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igxpdx32.dll
[2011/04/29 21:51:29 | 003,477,088 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igxpdv32.dll
[2011/04/29 21:51:29 | 003,145,752 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\GfxUI.exe
[2011/04/29 21:51:29 | 000,828,928 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxress.dll
[2011/04/29 21:51:29 | 000,194,048 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxpph.dll
[2011/04/29 21:51:29 | 000,181,760 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igxpgd32.dll
[2011/04/29 21:51:29 | 000,130,048 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxdo.dll
[2011/04/29 21:51:29 | 000,121,344 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\gfxSrvc.dll
[2011/04/29 21:51:29 | 000,115,200 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxcpl.cpl
[2011/04/29 21:51:29 | 000,094,720 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\hccutils.dll
[2011/04/29 21:51:29 | 000,086,528 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrfra.lrc
[2011/04/29 21:51:29 | 000,086,528 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxresn.lrc
[2011/04/29 21:51:29 | 000,086,016 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrita.lrc
[2011/04/29 21:51:29 | 000,086,016 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrdeu.lrc
[2011/04/29 21:51:29 | 000,085,504 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrptb.lrc
[2011/04/29 21:51:29 | 000,085,504 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrenu.lrc
[2011/04/29 21:51:29 | 000,082,944 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrkor.lrc
[2011/04/29 21:51:29 | 000,082,944 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrjpn.lrc
[2011/04/29 21:51:29 | 000,081,920 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrcht.lrc
[2011/04/29 21:51:29 | 000,081,920 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrchs.lrc
[2011/04/29 21:51:29 | 000,081,920 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxCoIn_v5258.dll
[2011/04/29 21:51:29 | 000,057,856 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igxprd32.dll
[2011/04/29 21:51:29 | 000,057,344 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxsrvc.dll
[2011/04/29 21:51:29 | 000,023,552 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxexps.dll
[2011/04/29 21:51:29 | 000,004,096 | ---- | C] ( ) -- C:\WINDOWS\System32\IGFXDEVLib.dll
[2011/04/29 21:50:54 | 000,196,608 | ---- | C] (RICOH) -- C:\WINDOWS\System32\RiSDIcon.dll
[2011/04/29 21:50:54 | 000,188,416 | ---- | C] (RICOH) -- C:\WINDOWS\System32\RiMMCIcon.dll
[2011/04/29 21:50:54 | 000,059,904 | ---- | C] (REDC) -- C:\WINDOWS\System32\drivers\risdpe86.sys
[2011/04/29 21:50:53 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2011/04/29 21:50:01 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\WINDOWS\System32\CSVer.dll
[2011/04/29 21:50:01 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2011/04/29 21:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2011/04/29 21:49:58 | 000,000,000 | ---D | C] -- C:\Intel
[2011/04/29 21:49:46 | 000,053,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\1394bus.sys
[2011/04/29 21:49:26 | 000,016,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll
[2011/04/29 21:49:23 | 000,032,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbccgp.sys
[2011/04/29 21:48:06 | 000,000,000 | ---D | C] -- C:\Program Files\Dell
[2011/04/29 19:30:01 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Local Settings\Application Data\WebEx
[2011/04/29 19:05:12 | 000,000,000 | -H-D | C] -- D:\Documents and Settings\All Users\Application Data\MANDIANT
[2011/04/29 19:05:12 | 000,000,000 | -H-D | C] -- C:\Program Files\MANDIANT
[2011/04/29 19:03:20 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Start Menu\Programs\Juniper Networks
Malware Bytes crashes my system when I try to run it...
I have executed the OTL.exe and these are the 2 outputs I got:
OTL logfile created on: 5/6/2011 6:23:54 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = D:\Documents and Settings\501831044\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 37.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 53.00% Paging File free
Paging file location(s): C:\PageFile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 116.02 Gb Total Space | 94.52 Gb Free Space | 81.46% Space Free | Partition Type: NTFS
Drive D: | 114.85 Gb Total Space | 97.49 Gb Free Space | 84.88% Space Free | Partition Type: NTFS
Computer Name: T00690712 | User Name: 501831044 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/06 18:22:24 | 000,580,608 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\501831044\Desktop\OTL.exe
PRC - [2011/05/06 18:00:05 | 000,377,344 | ---- | M] () -- D:\Documents and Settings\All Users\Application Data\nO31000AlMdN31000\nO31000AlMdN31000.exe
PRC - [2011/04/30 16:46:15 | 000,274,608 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2011/04/30 14:26:17 | 000,139,264 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jdk1.6.0_18\bin\java.exe
PRC - [2011/04/29 14:45:47 | 000,125,992 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe
PRC - [2011/04/29 14:45:47 | 000,030,248 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe
PRC - [2011/04/29 14:45:44 | 000,093,736 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
PRC - [2011/04/29 14:45:41 | 000,104,488 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
PRC - [2011/04/29 14:45:38 | 000,802,816 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Remote Management System\RouterNT.exe
PRC - [2011/04/29 14:45:38 | 000,278,528 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
PRC - [2011/02/23 08:22:08 | 000,094,008 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files\WebEx\Productivity Tools\ptSrv.exe
PRC - [2011/02/23 08:22:06 | 000,347,448 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe
PRC - [2010/12/16 17:54:58 | 000,931,184 | ---- | M] (Juniper Networks, Inc.) -- C:\Program Files\Juniper Networks\Odyssey Access Client\odTray.exe
PRC - [2010/12/16 17:54:54 | 000,193,904 | ---- | M] (Juniper Networks, Inc.) -- C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe
PRC - [2010/12/16 17:26:50 | 000,152,944 | ---- | M] (Juniper Networks) -- C:\Program Files\Common Files\Juniper Networks\TNC Client\jTnccService.exe
PRC - [2010/12/16 05:32:26 | 000,402,800 | ---- | M] (Juniper Networks) -- C:\Program Files\Common Files\Juniper Networks\Endpoint Defense\dsEES.exe
PRC - [2010/12/16 00:37:00 | 000,198,000 | ---- | M] (Juniper Networks) -- C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe
PRC - [2010/07/07 22:43:32 | 000,217,912 | ---- | M] (WebEx) -- C:\Program Files\WebEx\Connect\wbxcOIEx.exe
PRC - [2010/07/07 22:39:36 | 003,677,496 | ---- | M] (Cisco WebEx) -- C:\Program Files\WebEx\Connect\connect.exe
PRC - [2010/05/13 04:33:44 | 000,288,112 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2010/04/21 06:58:54 | 000,495,708 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
PRC - [2010/04/21 06:58:54 | 000,237,650 | ---- | M] (IDT, Inc.) -- c:\Program Files\IDT\WDM\stacsv.exe
PRC - [2010/04/12 11:50:58 | 000,238,904 | ---- | M] () -- C:\Program Files\WebEx\Connect\Widget.exe
PRC - [2010/03/24 08:09:28 | 000,812,448 | ---- | M] (Broadcom Corporation) -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
PRC - [2010/03/24 08:09:28 | 000,027,040 | ---- | M] (Broadcom Corporation) -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
PRC - [2010/03/23 21:22:26 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2010/02/18 00:34:40 | 000,054,568 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2010/02/03 04:09:46 | 000,429,096 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\AutoUpdate\ALMon.exe
PRC - [2010/02/03 04:09:46 | 000,175,144 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
PRC - [2010/01/10 20:01:26 | 000,060,928 | ---- | M] () -- C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe
PRC - [2009/11/20 23:55:42 | 002,119,032 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
PRC - [2009/11/20 23:55:42 | 000,632,160 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2009/10/02 05:19:16 | 000,380,988 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Endpoint Encryption for PC\SbClientManager.exe
PRC - [2009/09/19 01:01:08 | 000,333,088 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwtracepktwpp.exe
PRC - [2009/08/19 09:20:52 | 000,069,632 | ---- | M] () -- C:\Program Files\SafeBoot Tray Manager\SbTrayManager.exe
PRC - [2009/07/07 10:06:46 | 000,737,280 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\AESTFltr.exe
PRC - [2009/03/26 22:58:08 | 000,431,472 | ---- | M] (Juniper Networks) -- C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
PRC - [2009/02/08 03:11:00 | 000,155,648 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\amswmagt.exe
PRC - [2009/02/08 03:10:10 | 000,026,624 | ---- | M] () -- C:\Program Files\CA\DSM\PMAgent\capmuamagt.exe
PRC - [2009/02/08 01:23:12 | 000,221,184 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\ccnfAgent.exe
PRC - [2009/02/08 01:22:48 | 000,031,232 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\ccsmagtd.exe
PRC - [2009/02/08 01:21:10 | 000,200,704 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\cfnotsrvd.exe
PRC - [2009/02/08 01:21:10 | 000,057,344 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\cfFTPlugin.exe
PRC - [2009/02/08 01:21:10 | 000,027,136 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\cfsmsmd.exe
PRC - [2009/02/08 01:21:08 | 000,188,416 | ---- | M] (CA) -- C:\Program Files\CA\DSM\bin\CAF.exe
PRC - [2009/02/01 07:43:30 | 000,049,250 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2008/12/09 16:34:20 | 000,147,456 | ---- | M] (CA, Inc.) -- C:\Program Files\CA\SC\CAM\bin\cam.exe
PRC - [2008/04/14 08:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/14 08:00:00 | 000,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cmd.exe
PRC - [2005/08/29 22:03:50 | 059,027,456 | ---- | M] (Oracle Corporation) -- d:\oracle\product\10.2.0\db_1\BIN\oracle.exe
PRC - [2005/08/16 12:22:04 | 000,006,656 | ---- | M] (Oracle Corporation) -- D:\oracle\product\10.2.0\db_1\BIN\emagent.exe
PRC - [2005/08/16 12:21:06 | 000,024,064 | ---- | M] (Oracle Corporation) -- D:\oracle\product\10.2.0\db_1\BIN\nmesrvc.exe
PRC - [2005/08/16 01:23:02 | 000,053,248 | ---- | M] (Oracle) -- D:\oracle\product\10.2.0\db_1\BIN\isqlplussvc.exe
PRC - [2005/08/15 23:57:48 | 000,204,800 | ---- | M] () -- D:\oracle\product\10.2.0\db_1\BIN\TNSLSNR.EXE
PRC - [2005/04/08 19:09:00 | 000,045,161 | ---- | M] () -- D:\oracle\product\10.2.0\db_1\jdk\bin\java.exe
PRC - [2004/11/15 09:35:30 | 000,016,384 | ---- | M] () -- D:\oracle\product\10.2.0\db_1\perl\5.8.3\bin\MSWin32-x86-multi-thread\perl.exe
========== Modules (SafeList) ==========
MOD - File not found -- C:\WINDOWS\System32\DgApi.dll
MOD - File not found -- C:\Program Files\DGAgent\plugins\09D849B6-32D3-4a40-85EE-6B84BA29E35B\AME_SMTPSensor.dll
MOD - File not found -- C:\Program Files\DGAgent\plugins\09D849B6-32D3-4a40-85EE-6B84BA29E35B\AME_OutlookSensor.dll
MOD - File not found -- C:\Program Files\DGAgent\plugins\09D849B6-32D3-4a40-85EE-6B84BA29E35B\AE_MailSensor_Plugin.dll
MOD - [2011/05/06 18:22:24 | 000,580,608 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\501831044\Desktop\OTL.exe
MOD - [2011/04/29 14:45:40 | 000,237,832 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll
MOD - [2010/08/23 12:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2009/11/20 23:55:52 | 000,099,688 | ---- | M] (Broadcom Corporation.) -- C:\WINDOWS\system32\BtMmHook.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/04/29 14:45:47 | 000,125,992 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe -- (Sophos Client Firewall Manager)
SRV - [2011/04/29 14:45:47 | 000,030,248 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe -- (Sophos Client Firewall)
SRV - [2011/04/29 14:45:44 | 000,093,736 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe -- (SAVService)
SRV - [2011/04/29 14:45:41 | 000,104,488 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe -- (SAVAdminService)
SRV - [2011/04/29 14:45:38 | 000,802,816 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\Remote Management System\RouterNT.exe -- (Sophos Message Router)
SRV - [2011/04/29 14:45:38 | 000,278,528 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe -- (Sophos Agent)
SRV - [2010/12/16 17:54:54 | 000,193,904 | ---- | M] (Juniper Networks, Inc.) [Auto | Running] -- C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe -- (odClientService)
SRV - [2010/12/16 17:26:50 | 000,152,944 | ---- | M] (Juniper Networks) [On_Demand | Running] -- C:\Program Files\Common Files\Juniper Networks\TNC Client\jTnccService.exe -- (EacService)
SRV - [2010/12/16 00:37:00 | 000,198,000 | ---- | M] (Juniper Networks) [Auto | Running] -- C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe -- (JuniperAccessService)
SRV - [2010/08/14 01:11:20 | 008,750,408 | ---- | M] () [Auto | Running] -- C:\Program Files\MANDIANT\MANDIANT Intelligent Response Agent\MAVservice.exe -- (IAScan)
SRV - [2010/04/21 06:58:54 | 000,237,650 | ---- | M] (IDT, Inc.) [Auto | Running] -- c:\Program Files\IDT\WDM\stacsv.exe -- (STacSV)
SRV - [2010/03/24 08:09:28 | 000,812,448 | ---- | M] (Broadcom Corporation) [Auto | Running] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe -- (Credential Vault Host Control Service)
SRV - [2010/03/24 08:09:28 | 000,027,040 | ---- | M] (Broadcom Corporation) [Auto | Running] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe -- (Credential Vault Host Storage)
SRV - [2010/02/03 04:09:46 | 000,175,144 | ---- | M] (Sophos Plc) [Auto | Running] -- C:\Program Files\Sophos\AutoUpdate\ALsvc.exe -- (Sophos AutoUpdate Service)
SRV - [2010/01/10 20:01:26 | 000,060,928 | ---- | M] () [Auto | Running] -- C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe -- (InstallFilterService)
SRV - [2009/10/02 05:19:16 | 000,380,988 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\Endpoint Encryption for PC\SbClientManager.exe -- (SafeBootClientManager)
SRV - [2009/03/26 22:58:08 | 000,431,472 | ---- | M] (Juniper Networks) [Auto | Running] -- C:\Program Files\Juniper Networks\Common Files\dsNcService.exe -- (dsNcService)
SRV - [2009/02/08 01:21:08 | 000,188,416 | ---- | M] (CA) [Auto | Running] -- C:\Program Files\CA\DSM\bin\caf.exe -- (caf)
SRV - [2008/12/09 16:34:20 | 000,147,456 | ---- | M] (CA, Inc.) [Auto | Running] -- C:\Program Files\CA\SC\CAM\bin\cam.exe -- (CA-MessageQueuing)
SRV - [2005/08/29 22:03:50 | 059,027,456 | ---- | M] (Oracle Corporation) [Auto | Running] -- d:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE -- (OracleServiceENOVIA)
SRV - [2005/08/29 19:32:22 | 000,102,400 | ---- | M] () [Disabled | Stopped] -- d:\oracle\product\10.2.0\db_1\Bin\extjob.exe -- (OracleJobSchedulerENOVIA)
SRV - [2005/08/16 12:21:06 | 000,024,064 | ---- | M] (Oracle Corporation) [Auto | Running] -- D:\oracle\product\10.2.0\db_1\BIN\nmesrvc.exe -- (OracleDBConsoleenovia)
SRV - [2005/08/16 01:23:02 | 000,053,248 | ---- | M] (Oracle) [Auto | Running] -- D:\oracle\product\10.2.0\db_1\BIN\isqlplussvc.exe -- (OracleOraDb10g_home1iSQL*Plus)
SRV - [2005/08/15 23:57:48 | 000,204,800 | ---- | M] () [Auto | Running] -- D:\oracle\product\10.2.0\db_1\BIN\TNSLSNR.exe -- (OracleOraDb10g_home1TNSListener)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DGUSBMon.SYS -- (DGUSBMon)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGTDIMon.SYS -- (DGTDIMon)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGRule.SYS -- (DGRule)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgRec.sys -- (DGREC)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGMaster.sys -- (DGMaster)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGKPMail.sys -- (DGKPMail)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGFSMon.SYS -- (DGFSMon)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgFiltr.sys -- (DGFILTR)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgDtl.sys -- (DGDTL)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgDt.sys -- (DGDT)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgDsl.sys -- (DGDSL)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgDs.sys -- (DGDS)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgDmkl.sys -- (DGDmkl)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\DgDmkDisk.sys -- (DgDmkDisk)
DRV - File not found [File_System | Unknown | Stopped] -- C:\WINDOWS\System32\Drivers\DgDmk.sys -- (DGDmk)
DRV - File not found [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\DGCOTMAN.sys -- (DGCOTMAN)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGBusMon.SYS -- (DGBusMon)
DRV - File not found [Kernel | Unknown | Running] -- C:\WINDOWS\System32\Drivers\DGAPIMon.SYS -- (DGAPIMon)
DRV - [2011/04/29 21:58:18 | 000,909,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2011/04/29 21:58:18 | 000,047,656 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2011/04/29 19:05:18 | 000,019,920 | ---- | M] () [Kernel | On_Demand | Running] -- D:\Documents and Settings\All Users\Application Data\MANDIANT\MANDIANT Intelligent Response Agent\mktools.sys -- (Mandiant_Tools)
DRV - [2011/04/29 14:45:47 | 000,100,136 | ---- | M] (Sophos Plc) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\scfdriver.sys -- (scfdriver)
DRV - [2011/04/29 14:45:45 | 000,024,064 | ---- | M] (Sophos Plc) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\savonaccessfilter.sys -- (SAVOnAccessFilter)
DRV - [2011/04/29 14:45:42 | 000,023,928 | ---- | M] (Sophos Plc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sdcfilter.sys -- (sdcfilter)
DRV - [2011/04/29 14:45:42 | 000,014,976 | ---- | M] (Sophos Plc) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\SophosBootDriver.sys -- (SophosBootDriver)
DRV - [2011/04/29 14:45:40 | 000,152,192 | ---- | M] (Sophos Plc) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\savonaccesscontrol.sys -- (SAVOnAccessControl)
DRV - [2011/04/24 18:14:38 | 000,225,856 | ---- | M] (QFX Software Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\keyscrambler.sys -- (KeyScrambler)
DRV - [2010/12/16 17:09:44 | 000,282,496 | ---- | M] (Juniper Networks, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\odFips2.sys -- (odFips2)
DRV - [2010/12/16 17:09:44 | 000,009,856 | ---- | M] (Juniper Networks, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\odFips.sys -- (odFips)
DRV - [2010/07/15 15:09:18 | 000,034,800 | ---- | M] (Juniper Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\jnprvamgr.sys -- (JnprVaMgr)
DRV - [2010/07/15 15:09:14 | 000,017,776 | ---- | M] (Juniper Networks, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\jnprva.sys -- (jnprva)
DRV - [2010/07/15 15:09:12 | 000,420,464 | ---- | M] (Juniper Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\jnprna.sys -- (jnprna)
DRV - [2010/05/13 04:17:00 | 000,255,096 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2010/04/21 06:58:54 | 001,660,051 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2010/04/06 08:35:56 | 000,168,616 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1k5132.sys -- (e1kexpress) Intel(R)
DRV - [2010/03/20 00:39:08 | 000,059,904 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\risdpe86.sys -- (risdpcie)
DRV - [2010/02/27 07:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Impcd.sys -- (Impcd)
DRV - [2010/02/03 11:47:36 | 002,696,448 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2010/01/19 20:50:12 | 000,235,520 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntcDAud.sys -- (IntcDAud) Intel(R)
DRV - [2010/01/18 15:56:26 | 000,042,672 | ---- | M] (ST Microelectronics) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Accelern.sys -- (Acceler)
DRV - [2010/01/18 15:56:26 | 000,017,072 | ---- | M] (ST Microelectronics) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\stdfltn.sys -- (stdflt)
DRV - [2009/11/04 01:40:42 | 000,033,832 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cvusbdrv.sys -- (cvusbdrv)
DRV - [2009/10/06 13:49:48 | 000,187,960 | ---- | M] (Advanced Micro Devices, Inc) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ahcix86.sys -- (ahcix86)
DRV - [2009/10/02 05:18:49 | 000,015,248 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\SbPrcCtl.sys -- (SbPrcCtl)
DRV - [2009/10/02 05:18:27 | 000,006,496 | ---- | M] (McAfee, Inc.) [File_System | Boot | Running] -- C:\WINDOWS\System32\drivers\SbFsLock.sys -- (SbFsLock)
DRV - [2009/10/02 05:18:23 | 000,033,328 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\RsvLock.sys -- (RsvLock)
DRV - [2009/10/02 05:18:16 | 000,034,480 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\SbFlop.sys -- (SbFlop)
DRV - [2009/10/02 05:17:57 | 000,103,760 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\SafeBoot.sys -- (SafeBoot)
DRV - [2009/05/21 05:48:10 | 000,029,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbccid.sys -- (USBCCID)
DRV - [2009/04/22 06:13:34 | 000,113,664 | ---- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AESTAud.sys -- (AESTAud)
DRV - [2009/03/26 22:41:04 | 000,023,552 | ---- | M] (Juniper Networks) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dsNcAdpt.sys -- (dsNcAdpt)
DRV - [2008/08/13 13:51:42 | 000,044,976 | ---- | M] (SafeBoot N.V.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\SbAlg.sys -- (SBAlg)
DRV - [2008/06/04 22:14:00 | 000,026,608 | ---- | M] (Dell Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\PBADRV.sys -- (PBADRV)
DRV - [2008/04/04 21:40:50 | 000,244,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\e1y5132.sys -- (e1yexpress) Intel(R)
DRV - [2007/09/19 15:36:16 | 000,100,096 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symmpi.sys -- (Symmpi)
DRV - [2004/11/05 16:54:50 | 000,136,704 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\fasttx2k.sys -- (fasttx2k)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://energy.home.ge.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = http://ps.setpac.ge.com/pac.pac
========== FireFox ==========
FF - prefs.js..network.proxy.autoconfig_url: "http://ps.setpac.ge.com/pac.pac"
FF - prefs.js..network.proxy.type: 2
FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: D:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/04/30 16:46:25 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/30 16:46:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/04/29 18:17:24 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\501831044\Application Data\Mozilla\Extensions
[2011/05/03 21:16:16 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\501831044\Application Data\Mozilla\Firefox\Profiles\9flgsxuu.default\extensions
[2011/04/30 16:57:40 | 000,000,000 | ---D | M] (KeyScrambler) -- D:\Documents and Settings\501831044\Application Data\Mozilla\Firefox\Profiles\9flgsxuu.default\extensions\keyscrambler@qfx.software.corporation
[2011/04/30 14:27:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2011/04/30 14:26:59 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
() (No name found) -- D:\DOCUMENTS AND SETTINGS\501831044\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\9FLGSXUU.DEFAULT\EXTENSIONS\{0545B830-F0AA-4D7E-8820-50A4629A56FE}.XPI
() (No name found) -- D:\DOCUMENTS AND SETTINGS\501831044\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\9FLGSXUU.DEFAULT\EXTENSIONS\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.XPI
[2011/04/30 16:46:25 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- D:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/04/14 12:26:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 04:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/05/05 19:43:41 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (KeyScramblerBHO Class) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Plc)
O2 - BHO: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files\WebEx\Productivity Tools\ptonecli.dll (Cisco WebEx LLC)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files\WebEx\Productivity Tools\ptonecli.dll (Cisco WebEx LLC)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [AESTFltr] C:\WINDOWS\System32\AESTFltr.exe (Andrea Electronics Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [GEvpnPacCheck] C:\Program Files\Juniper Networks\VPN_PAC_CHECK.vbs ()
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [OdTray.exe] C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe (Juniper Networks, Inc.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SafeBootTrayManager] C:\Program Files\SafeBoot Tray Manager\SbTrayManager.exe ()
O4 - HKLM..\Run: [SetCacheMode] C:\WINDOWS\System32\ptipbmf.dll ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_15\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [CheckIt] C:\WINDOWS/SYSTEM32/GE/Scripts/Checkit.vbs ()
O4 - HKCU..\Run: [PTOneClick] C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe (Cisco WebEx LLC)
O4 - HKCU..\RunOnce: [nO31000AlMdN31000] D:\Documents and Settings\All Users\Application Data\nO31000AlMdN31000\nO31000AlMdN31000.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A82000000003}\IconAC76BA86.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Sophos AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: nodrivetypeautorun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogOff = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogonScripts = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &KeyScrambler Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O15 - HKLM\..Trusted Domains: vetco.com ([]* in Local intranet)
O15 - HKLM\..Trusted Domains: vetcogray.com ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: ge.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([*.supportcentral] * in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([cincnt1.ssqc] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([cincnt2.ssqc] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([genet.ae] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([inside] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([libraries] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([ssqc] http in Trusted sites)
O15 - HKCU\..Trusted Domains: ge.com ([time.infra] * in Trusted sites)
O15 - HKCU\..Trusted Domains: logmeinrescue-enterprise.com ([secure] https in Trusted sites)
O15 - HKCU\..Trusted Domains: mahindrasatyam.com ([ontime] https in Trusted sites)
O15 - HKCU\..Trusted Domains: vetco.com ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: vetcogray.com ([]* in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://emeetings.webex.com/client/T27L10NSP21EP5-emeetings/webex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://juniper.net/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupControlXP Class)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O16 - DPF: {FCADE536-93F5-4577-80A3-E7C32FAC4C7D} http://internal.infra.ge.com/qcbin/Spider10.cab (Loader Class v5)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.178.162.3 97.81.22.195 24.159.64.23
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = psamer.ps.ge.com
O20 - AppInit_DLLs: (C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Plc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\CAF: DllName - C:\Program Files\CA\DSM\Bin\cfwlogon.dll - C:\Program Files\CA\DSM\bin\cfWlogon.dll (CA)
O20 - Winlogon\Notify\OdysseyClient: DllName - odyEvent.dll - C:\WINDOWS\System32\odyEvent.dll (Juniper Networks, Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/05 11:28:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{6d4d3ccc-e02b-11de-9e7b-ed3e4b11f6bb}\Shell\AutoRun\command - "" = Programs\nu2menu\nu2menu.exe
O33 - MountPoints2\{8a9ac29a-a232-11de-a438-844cddf9895f}\Shell\AutoRun\command - "" = Programs\nu2menu\nu2menu.exe
O33 - MountPoints2\{96e5771a-8bda-11df-b3c4-bc2b75784766}\Shell\AutoRun\command - "" = Programs\nu2menu\nu2menu.exe
O33 - MountPoints2\{dff8e6fa-7348-11df-8f47-cc826885f0a8}\Shell - "" = AutoRun
O33 - MountPoints2\{dff8e6fa-7348-11df-8f47-cc826885f0a8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{dff8e6fa-7348-11df-8f47-cc826885f0a8}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{dff8e6fb-7348-11df-8f47-c4cfda9322b7}\Shell\AutoRun\command - "" = Programs\nu2menu\nu2menu.exe
O33 - MountPoints2\{f6189e64-e23e-11df-a702-9801d6bd58ac}\Shell\AutoRun\command - "" = Programs\nu2menu\nu2menu.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/06 18:22:16 | 000,580,608 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\501831044\Desktop\OTL.exe
[2011/05/06 18:00:04 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\nO31000AlMdN31000
[2011/05/05 08:08:33 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Local Settings\Application Data\Google
[2011/05/02 14:50:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2011/05/02 10:40:11 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\ief
[2011/05/01 20:47:15 | 000,000,000 | ---D | C] -- C:\Program Files\Dassault Systemes
[2011/05/01 20:46:32 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Local Settings\Application Data\DassaultSystemes
[2011/05/01 20:46:32 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Application Data\DassaultSystemes
[2011/05/01 19:59:35 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Local Settings\Application Data\Mercury Interactive
[2011/05/01 19:58:43 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Application Data\09D849B6-32D3-4a40-85EE-6B84BA29E35B
[2011/05/01 19:56:24 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\{F28EEC54-8380-4273-BE32-4052A058D37E}
[2011/05/01 19:55:26 | 000,000,000 | ---D | C] -- D:\Documents and Settings\LocalService\Local Settings\Application Data\Seven Zip
[2011/05/01 19:49:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Mercury Interactive
[2011/05/01 00:56:39 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Start Menu\Programs\EditPlus 3
[2011/05/01 00:56:38 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Application Data\EditPlus 3
[2011/05/01 00:56:38 | 000,000,000 | ---D | C] -- C:\Program Files\EditPlus 3
[2011/04/30 17:06:55 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\QFX Software
[2011/04/30 17:06:55 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Application Data\QFX Software
[2011/04/30 16:57:28 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\KeyScrambler
[2011/04/30 16:57:26 | 000,225,856 | ---- | C] (QFX Software Corporation) -- C:\WINDOWS\System32\drivers\keyscrambler.sys
[2011/04/30 16:57:26 | 000,000,000 | ---D | C] -- C:\Program Files\KeyScrambler
[2011/04/30 16:47:26 | 000,000,000 | ---D | C] -- C:\Program Files\EditPlus 2
[2011/04/30 16:46:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2011/04/30 16:46:21 | 000,199,904 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll
[2011/04/30 16:46:16 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\WINDOWS\System32\pncrt.dll
[2011/04/30 16:46:16 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll
[2011/04/30 16:46:16 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll
[2011/04/30 16:46:16 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Real
[2011/04/30 16:46:10 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Real
[2011/04/30 16:46:10 | 000,000,000 | ---D | C] -- C:\Program Files\Real
[2011/04/30 16:45:52 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Application Data\Real
[2011/04/30 16:44:48 | 000,025,088 | ---- | C] (Microsoft Corporation) -- D:\Documents and Settings\501831044\Desktop\ZAPGRAB2.EXE
[2011/04/30 16:25:45 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\DassaultSystemes
[2011/04/30 16:03:44 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\ENOVIA Live Collaboration Server
[2011/04/30 16:01:03 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Oracle
[2011/04/30 15:54:53 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\ENOVIA Studio Modeling Platform
[2011/04/30 15:53:09 | 000,000,000 | ---D | C] -- C:\enoviav6r2010x
[2011/04/30 15:03:38 | 000,000,000 | ---D | C] -- C:\Program Files\apache-tomcat-6.0.24
[2011/04/30 14:42:17 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio .NET
[2011/04/30 14:42:17 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Local Settings\Application Data\Microsoft Help
[2011/04/30 14:41:10 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Oracle - OraDb10g_home1
[2011/04/30 14:38:03 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
[2011/04/30 14:27:25 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Sun
[2011/04/30 14:27:14 | 000,000,000 | ---D | C] -- C:\Program Files\Sun
[2011/04/29 22:02:29 | 000,016,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsgXP_2k3.dll
[2011/04/29 22:02:26 | 000,000,000 | ---D | C] -- C:\Program Files\DellTPad
[2011/04/29 22:02:23 | 001,461,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WdfCoInstaller01009.dll
[2011/04/29 22:02:23 | 000,255,096 | ---- | C] (Alps Electric Co., Ltd.) -- C:\WINDOWS\System32\drivers\Apfiltr.sys
[2011/04/29 22:02:23 | 000,109,122 | ---- | C] (Alps Electric Co., Ltd.) -- C:\WINDOWS\System32\Vxdif.dll
[2011/04/29 22:01:50 | 000,106,557 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\btw_ci.dll
[2011/04/29 22:01:50 | 000,092,072 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btwsecfl.sys
[2011/04/29 22:01:50 | 000,047,656 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btwusb.sys
[2011/04/29 22:01:49 | 000,909,736 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btkrnl.sys
[2011/04/29 22:01:45 | 000,000,000 | ---D | C] -- C:\Program Files\WIDCOMM
[2011/04/29 22:01:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\Dell
[2011/04/29 21:56:48 | 000,042,672 | ---- | C] (ST Microelectronics) -- C:\WINDOWS\System32\drivers\Accelern.sys
[2011/04/29 21:56:48 | 000,017,072 | ---- | C] (ST Microelectronics) -- C:\WINDOWS\System32\drivers\stdfltn.sys
[2011/04/29 21:56:48 | 000,000,000 | ---D | C] -- C:\Program Files\STMicroelectronics
[2011/04/29 21:56:46 | 000,000,000 | ---D | C] -- C:\Dell
[2011/04/29 21:56:32 | 002,696,448 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\drivers\BCMWL5.SYS
[2011/04/29 21:56:23 | 011,870,298 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\idtsg.cpl
[2011/04/29 21:56:23 | 003,358,720 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\stlang.dll
[2011/04/29 21:56:23 | 000,737,280 | ---- | C] (Andrea Electronics Corporation) -- C:\WINDOWS\System32\AESTFltr.exe
[2011/04/29 21:56:23 | 000,253,952 | ---- | C] (Andrea Electronics Corporation) -- C:\WINDOWS\System32\AESTCtrl.cpl
[2011/04/29 21:56:20 | 001,660,051 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\drivers\sthda.sys
[2011/04/29 21:56:20 | 000,544,866 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\stacapi.dll
[2011/04/29 21:56:20 | 000,175,616 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\st326281.dll
[2011/04/29 21:56:18 | 000,113,664 | ---- | C] (Andrea Electronics Corporation) -- C:\WINDOWS\System32\drivers\AESTAud.sys
[2011/04/29 21:56:18 | 000,000,000 | ---D | C] -- C:\Program Files\IDT
[2011/04/29 21:55:55 | 001,419,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WdfCoInstaller01005.dll
[2011/04/29 21:55:55 | 000,033,832 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\drivers\cvusbdrv.sys
[2011/04/29 21:55:22 | 000,000,000 | ---D | C] -- C:\Program Files\Broadcom Corporation
[2011/04/29 21:55:19 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2011/04/29 21:55:18 | 000,026,608 | ---- | C] (Dell Inc) -- C:\WINDOWS\System32\drivers\PBADRV.sys
[2011/04/29 21:55:15 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbccid.sys
[2011/04/29 21:55:10 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbccid.sys
[2011/04/29 21:54:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\BioAPIFFDB
[2011/04/29 21:52:07 | 000,168,616 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\drivers\e1k5132.sys
[2011/04/29 21:52:07 | 000,074,944 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\NicInstK.dll
[2011/04/29 21:52:07 | 000,068,264 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\e1kmsg.dll
[2011/04/29 21:51:59 | 000,319,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\difxapi.dll
[2011/04/29 21:51:57 | 000,132,480 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\drivers\Impcd.sys
[2011/04/29 21:51:56 | 000,006,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\splitter.sys
[2011/04/29 21:51:55 | 000,083,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wdmaud.sys
[2011/04/29 21:51:53 | 000,052,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dmusic.sys
[2011/04/29 21:51:52 | 000,056,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swmidi.sys
[2011/04/29 21:51:51 | 000,142,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aec.sys
[2011/04/29 21:51:50 | 000,172,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kmixer.sys
[2011/04/29 21:51:49 | 000,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\drmkaud.sys
[2011/04/29 21:51:48 | 000,060,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sysaudio.sys
[2011/04/29 21:51:47 | 000,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mskssrv.sys
[2011/04/29 21:51:46 | 000,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mspqm.sys
[2011/04/29 21:51:44 | 000,005,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mspclock.sys
[2011/04/29 21:51:42 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksproxy.ax
[2011/04/29 21:51:42 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksproxy.ax
[2011/04/29 21:51:42 | 000,060,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmk.sys
[2011/04/29 21:51:42 | 000,060,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\drmk.sys
[2011/04/29 21:51:42 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksuser.dll
[2011/04/29 21:51:42 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksuser.dll
[2011/04/29 21:51:39 | 000,235,520 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\drivers\IntcDAud.sys
[2011/04/29 21:51:29 | 010,960,384 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\ig4icd32.dll
[2011/04/29 21:51:29 | 004,095,488 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igxpdx32.dll
[2011/04/29 21:51:29 | 003,477,088 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igxpdv32.dll
[2011/04/29 21:51:29 | 003,145,752 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\GfxUI.exe
[2011/04/29 21:51:29 | 000,828,928 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxress.dll
[2011/04/29 21:51:29 | 000,194,048 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxpph.dll
[2011/04/29 21:51:29 | 000,181,760 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igxpgd32.dll
[2011/04/29 21:51:29 | 000,130,048 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxdo.dll
[2011/04/29 21:51:29 | 000,121,344 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\gfxSrvc.dll
[2011/04/29 21:51:29 | 000,115,200 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxcpl.cpl
[2011/04/29 21:51:29 | 000,094,720 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\hccutils.dll
[2011/04/29 21:51:29 | 000,086,528 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrfra.lrc
[2011/04/29 21:51:29 | 000,086,528 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxresn.lrc
[2011/04/29 21:51:29 | 000,086,016 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrita.lrc
[2011/04/29 21:51:29 | 000,086,016 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrdeu.lrc
[2011/04/29 21:51:29 | 000,085,504 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrptb.lrc
[2011/04/29 21:51:29 | 000,085,504 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrenu.lrc
[2011/04/29 21:51:29 | 000,082,944 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrkor.lrc
[2011/04/29 21:51:29 | 000,082,944 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrjpn.lrc
[2011/04/29 21:51:29 | 000,081,920 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrcht.lrc
[2011/04/29 21:51:29 | 000,081,920 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrchs.lrc
[2011/04/29 21:51:29 | 000,081,920 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxCoIn_v5258.dll
[2011/04/29 21:51:29 | 000,057,856 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igxprd32.dll
[2011/04/29 21:51:29 | 000,057,344 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxsrvc.dll
[2011/04/29 21:51:29 | 000,023,552 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxexps.dll
[2011/04/29 21:51:29 | 000,004,096 | ---- | C] ( ) -- C:\WINDOWS\System32\IGFXDEVLib.dll
[2011/04/29 21:50:54 | 000,196,608 | ---- | C] (RICOH) -- C:\WINDOWS\System32\RiSDIcon.dll
[2011/04/29 21:50:54 | 000,188,416 | ---- | C] (RICOH) -- C:\WINDOWS\System32\RiMMCIcon.dll
[2011/04/29 21:50:54 | 000,059,904 | ---- | C] (REDC) -- C:\WINDOWS\System32\drivers\risdpe86.sys
[2011/04/29 21:50:53 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2011/04/29 21:50:01 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\WINDOWS\System32\CSVer.dll
[2011/04/29 21:50:01 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2011/04/29 21:50:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2011/04/29 21:49:58 | 000,000,000 | ---D | C] -- C:\Intel
[2011/04/29 21:49:46 | 000,053,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\1394bus.sys
[2011/04/29 21:49:26 | 000,016,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll
[2011/04/29 21:49:23 | 000,032,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbccgp.sys
[2011/04/29 21:48:06 | 000,000,000 | ---D | C] -- C:\Program Files\Dell
[2011/04/29 19:30:01 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Local Settings\Application Data\WebEx
[2011/04/29 19:05:12 | 000,000,000 | -H-D | C] -- D:\Documents and Settings\All Users\Application Data\MANDIANT
[2011/04/29 19:05:12 | 000,000,000 | -H-D | C] -- C:\Program Files\MANDIANT
[2011/04/29 19:03:20 | 000,000,000 | ---D | C] -- D:\Documents and Settings\501831044\Start Menu\Programs\Juniper Networks