Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Trojan.Gen infections -- *.mexw32


  • Please log in to reply

#1
rberdani

rberdani

    New Member

  • Member
  • Pip
  • 1 posts
My antivirus just blew up with notifications of a bunch of .mexw32 infections in my MATLAB directory. Any help is greatly appreciated. Thank you so much!

My OTL log is attached here:




OTL logfile created on: 6/13/2011 12:35:47 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 35.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.76 Gb Total Space | 110.25 Gb Free Space | 47.37% Space Free | Partition Type: NTFS
Drive R: | 7.63 Gb Total Space | 5.22 Gb Free Space | 68.36% Space Free | Partition Type: NTFS
Drive S: | 488.28 Mb Total Space | 439.31 Mb Free Space | 89.97% Space Free | Partition Type: NTFS
Drive Y: | 488.28 Mb Total Space | 439.31 Mb Free Space | 89.97% Space Free | Partition Type: NTFS

Computer Name: TSPCPC131 | User Name: Reid | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/20 12:28:26 | 001,949,088 | ---- | M] (Binary Fortress Software) -- C:\Program Files\DisplayFusion\DisplayFusion.exe
PRC - [2011/05/18 09:07:52 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Desktop\OTL.exe
PRC - [2011/05/03 10:00:41 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/04/29 13:20:40 | 012,594,352 | ---- | M] (Mozilla Messaging) -- C:\Program Files\Mozilla Thunderbird\thunderbird.exe
PRC - [2011/01/27 11:51:05 | 002,253,688 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2010/09/13 21:02:44 | 000,399,872 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\Program Files\UPHClean\uphclean.exe
PRC - [2009/11/02 16:44:12 | 000,108,392 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2009/11/02 16:44:10 | 000,115,560 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2009/11/02 16:44:08 | 001,455,432 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
PRC - [2009/11/02 16:44:06 | 002,477,304 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
PRC - [2009/11/02 16:44:06 | 001,864,888 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
PRC - [2009/11/02 16:44:06 | 000,181,616 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SavUI.exe
PRC - [2009/06/18 08:01:50 | 000,356,912 | ---- | M] (National Instruments Corporation) -- C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
PRC - [2009/06/18 07:57:28 | 000,042,544 | ---- | M] (National Instruments Corporation) -- C:\WINDOWS\system32\lkads.exe
PRC - [2009/06/18 07:56:32 | 000,053,296 | ---- | M] (National Instruments Corporation) -- C:\WINDOWS\system32\lktsrv.exe
PRC - [2009/06/15 21:44:40 | 000,012,696 | ---- | M] (National Instruments Corporation) -- C:\Program Files\National Instruments\MAX\nimxs.exe
PRC - [2009/06/04 05:14:28 | 000,013,896 | ---- | M] (National Instruments Corporation) -- C:\WINDOWS\system32\nisvcloc.exe
PRC - [2008/12/08 17:49:04 | 000,509,256 | ---- | M] (Agilent Technologies) -- C:\Program Files\Agilent\IO Libraries Suite\bin\iprocsvr.exe
PRC - [2008/12/08 17:49:04 | 000,095,560 | ---- | M] (Agilent Technologies) -- C:\Program Files\Agilent\IO Libraries Suite\bin\iproc8491.exe
PRC - [2008/12/08 17:49:04 | 000,070,984 | ---- | M] (Agilent Technologies) -- C:\Program Files\Agilent\IO Libraries Suite\bin\iproc488.exe
PRC - [2008/12/08 17:45:40 | 000,049,152 | ---- | M] (Agilent) -- C:\Program Files\Agilent\IO Libraries Suite\Agilent.TMFramework.Connectivity.AgilentIOLibrariesService.exe
PRC - [2008/12/08 17:45:38 | 000,102,400 | ---- | M] (Agilent) -- C:\Program Files\Agilent\IO Libraries Suite\Agilent.TMFramework.Connectivity.NkoServer.exe
PRC - [2008/12/02 11:47:30 | 000,262,144 | ---- | M] (Agilent Technologies, Inc.) -- C:\Program Files\Agilent\LXI Mdns Responder\LxiMdnsResponder.exe
PRC - [2008/12/01 10:22:58 | 000,066,912 | ---- | M] (Agilent Technologies) -- C:\Program Files\Agilent\IO Libraries Suite\bin\iproc82357.exe
PRC - [2008/08/21 23:51:44 | 000,012,696 | ---- | M] (National Instruments Corporation) -- C:\WINDOWS\system32\nipalsm.exe
PRC - [2008/06/20 16:46:24 | 000,607,848 | ---- | M] (National Instruments Corporation) -- C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
PRC - [2008/04/17 01:28:48 | 000,818,176 | ---- | M] (Jay Elaraj) -- C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/03/25 13:55:26 | 004,912,368 | ---- | M] (Itiva Digital Media) -- C:\Program Files\Itiva\Itiva Media Accelerator\ItivaMediaAccelerator.exe
PRC - [2007/07/26 21:03:46 | 000,358,936 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007/07/26 21:03:44 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2007/01/23 05:58:04 | 000,133,968 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\ASF Agent\ASFAgent.exe
PRC - [2006/11/17 14:40:56 | 000,136,768 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2006/11/17 14:39:58 | 000,136,768 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2006/11/17 14:37:44 | 000,104,000 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2006/11/17 04:06:00 | 000,086,016 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\Mctray.exe
PRC - [2006/11/08 17:01:54 | 000,049,152 | ---- | M] (Primax Electronics Ltd.) -- C:\WINDOWS\system32\ico.exe
PRC - [2006/10/20 19:23:38 | 000,118,784 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2006/09/25 11:12:20 | 000,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2006/08/17 11:00:00 | 001,116,920 | ---- | M] (Roxio) -- C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
PRC - [2004/03/18 10:33:26 | 000,892,928 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\iTouch\iTouch.exe


========== Modules (SafeList) ==========

MOD - [2011/05/18 09:07:52 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Desktop\OTL.exe
MOD - [2011/05/12 19:12:40 | 000,096,168 | ---- | M] (Binary Fortress Software) -- C:\Program Files\DisplayFusion\Hooks\DisplayFusionHookx86_86F1FF57-A6D8-4B71-8E14-C6F627DA4971.dll
MOD - [2010/08/23 12:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2004/03/18 10:26:50 | 000,004,608 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\iTouch\itchhk.dll
MOD - [2004/03/18 10:26:48 | 000,114,688 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\Scrolling\LGMSGHK.DLL


========== Win32 Services (SafeList) ==========

SRV - [2011/01/27 11:51:05 | 002,253,688 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2010/09/13 21:02:44 | 000,399,872 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Auto | Running] -- C:\Program Files\UPHClean\uphclean.exe -- (UPHClean)
SRV - [2009/11/02 16:44:12 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2009/11/02 16:44:12 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2009/11/02 16:44:08 | 000,341,320 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE -- (SNAC)
SRV - [2009/11/02 16:44:06 | 002,477,304 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2009/11/02 16:44:06 | 001,864,888 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe -- (SmcService)
SRV - [2009/10/02 14:28:09 | 002,969,600 | ---- | M] (ANSYS, Inc.) [Auto | Stopped] -- C:\Program Files\ANSYS Inc\Shared Files\Licensing\win32\ansysli_server.exe -- (ANSYS, Inc. License Manager)
SRV - [2009/09/18 11:10:28 | 001,007,616 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe -- (NILM License Manager)
SRV - [2009/06/18 08:01:50 | 000,356,912 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe -- (NIDomainService)
SRV - [2009/06/18 07:57:28 | 000,042,544 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\WINDOWS\system32\lkads.exe -- (lkClassAds)
SRV - [2009/06/18 07:56:32 | 000,053,296 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\WINDOWS\system32\lktsrv.exe -- (lkTimeSync)
SRV - [2009/06/15 21:44:40 | 000,012,696 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Program Files\National Instruments\MAX\nimxs.exe -- (mxssvr)
SRV - [2009/06/04 05:14:28 | 000,013,896 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\WINDOWS\System32\nisvcloc.exe -- (niSvcLoc)
SRV - [2009/03/20 19:10:15 | 003,093,880 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
SRV - [2008/12/08 17:45:40 | 000,049,152 | ---- | M] (Agilent) [Auto | Running] -- C:\Program Files\Agilent\IO Libraries Suite\Agilent.TMFramework.Connectivity.AgilentIOLibrariesService.exe -- (AgilentIOLibrariesService)
SRV - [2008/12/02 11:47:30 | 000,262,144 | ---- | M] (Agilent Technologies, Inc.) [Auto | Running] -- C:\Program Files\Agilent\LXI Mdns Responder\LxiMdnsResponder.exe -- (AgtMdnsResponder)
SRV - [2008/10/31 15:52:54 | 000,695,136 | ---- | M] (National Instruments, Inc.) [On_Demand | Stopped] -- C:\WINDOWS\system32\lkcitdl.exe -- (LkCitadelServer)
SRV - [2008/08/21 23:51:44 | 000,012,696 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\WINDOWS\system32\nipalsm.exe -- (nipxirmu)
SRV - [2008/08/21 23:51:44 | 000,012,696 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\WINDOWS\system32\nipalsm.exe -- (nidevldu)
SRV - [2008/06/20 16:46:24 | 000,607,848 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe -- (NITaggerService)
SRV - [2008/03/18 06:28:46 | 000,068,096 | ---- | M] () [On_Demand | Stopped] -- C:\cygwin\bin\cygrunsrv.exe -- (BrlAPI)
SRV - [2007/07/26 21:03:46 | 000,358,936 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®
SRV - [2007/01/23 05:58:04 | 000,133,968 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\ASF Agent\ASFAgent.exe -- (ASFAgent)
SRV - [2006/11/17 14:37:44 | 000,104,000 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2004/12/02 09:28:32 | 000,098,304 | ---- | M] (OPC Foundation) [On_Demand | Stopped] -- C:\WINDOWS\system32\Opcenum.exe -- (OpcEnum)


========== Driver Services (SafeList) ==========

DRV - [2011/05/18 04:00:00 | 001,542,392 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110612.002\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/05/18 04:00:00 | 000,086,008 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110612.002\NAVENG.SYS -- (NAVENG)
DRV - [2011/05/09 04:00:00 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011/05/09 04:00:00 | 000,105,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/05/03 16:58:25 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/01/12 05:42:12 | 000,025,088 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV - [2010/01/10 04:53:04 | 000,011,904 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nipalfwedl.sys -- (nipalfwedl)
DRV - [2010/01/10 04:52:36 | 000,597,592 | ---- | M] (National Instruments Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\nipalk.sys -- (NIPALK)
DRV - [2010/01/10 04:51:00 | 000,011,896 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nipalusbedl.sys -- (nipalusbedl)
DRV - [2009/11/13 16:15:48 | 000,011,360 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nimdbgkl.sys -- (nimdbgk)
DRV - [2009/11/02 16:44:14 | 000,320,560 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2009/11/02 16:44:14 | 000,281,648 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)
DRV - [2009/11/02 16:44:14 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2009/11/02 16:44:00 | 000,421,424 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2009/10/22 16:11:14 | 000,057,800 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2009/10/22 16:09:34 | 000,072,520 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftser2k.sys -- (FTSER2K)
DRV - [2009/08/03 11:00:00 | 000,004,096 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\cvintdrv.sys -- (cvintdrv)
DRV - [2009/07/07 18:34:44 | 000,011,344 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nimxdfkl.sys -- (nimxdfk)
DRV - [2009/07/07 17:50:20 | 000,011,360 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nidimkl.sys -- (nidimk)
DRV - [2009/07/07 14:43:06 | 000,011,344 | ---- | M] (National Instruments Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nipxirmkl.sys -- (nipxirmk)
DRV - [2009/07/07 11:23:02 | 000,015,448 | ---- | M] (National Instruments Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\nipbcfk.sys -- (nipbcfk)
DRV - [2009/06/17 16:26:12 | 000,011,344 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nidsarkl.sys -- (nidsark)
DRV - [2009/06/17 12:35:48 | 000,011,344 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ni1045kl.sys -- (ni1045k)
DRV - [2009/06/17 02:13:36 | 000,011,336 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nidmxfkl.sys -- (nidmxfk)
DRV - [2009/06/17 01:05:26 | 000,011,368 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nimxpkl.sys -- (nimxpk)
DRV - [2009/06/14 16:32:28 | 000,011,344 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\niorbkl.sys -- (niorbk)
DRV - [2009/06/06 02:31:00 | 000,151,683 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nimsrlk.dll -- (nimsrlk)
DRV - [2009/06/06 02:30:58 | 000,014,464 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nimslk.dll -- (nimslk)
DRV - [2009/05/28 23:17:52 | 000,011,336 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\niemrkl.sys -- (niemrk)
DRV - [2009/05/28 23:17:24 | 000,011,336 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nissrkl.sys -- (nissrk)
DRV - [2009/05/28 23:17:10 | 000,011,336 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nicsrkl.sys -- (nicsrk)
DRV - [2009/05/28 23:16:28 | 000,011,368 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\niufurkl.sys -- (niufurk)
DRV - [2009/05/28 23:15:56 | 000,011,336 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nixsrkl.sys -- (nixsrk)
DRV - [2009/05/28 23:15:20 | 000,011,336 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\niwfrkl.sys -- (niwfrk)
DRV - [2009/05/28 23:10:16 | 000,011,336 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\niesrkl.sys -- (niesrk)
DRV - [2009/04/01 16:31:02 | 000,022,608 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ni1065k.sys -- (ni1065k)
DRV - [2009/04/01 16:16:54 | 000,026,192 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ni1006k.sys -- (ni1006k)
DRV - [2009/03/30 14:58:56 | 000,011,344 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nisftkl.sys -- (nisftk)
DRV - [2009/03/30 14:58:46 | 000,011,360 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ninshsdkl.sys -- (ninshsdk)
DRV - [2009/02/05 23:32:12 | 000,011,352 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nisdigkl.sys -- (nisdigk)
DRV - [2009/01/06 17:51:10 | 000,011,352 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nifslkl.sys -- (nifslk)
DRV - [2009/01/05 10:28:24 | 000,011,376 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nispdkl.sys -- (nispdk)
DRV - [2009/01/05 10:28:22 | 000,011,376 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\niscdkl.sys -- (niscdk)
DRV - [2009/01/02 18:54:08 | 000,011,360 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nitiorkl.sys -- (nitiork)
DRV - [2009/01/02 18:40:54 | 000,011,360 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nistcrkl.sys -- (nistcrk)
DRV - [2009/01/02 18:37:02 | 000,011,312 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nistc2kl.sys -- (nistc2k)
DRV - [2009/01/02 18:02:06 | 000,011,352 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nicdrkl.sys -- (nicdrk)
DRV - [2008/12/29 19:24:52 | 000,011,392 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nimsdrkl.sys -- (nimsdrk)
DRV - [2008/12/29 19:17:34 | 000,011,360 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nimstskl.sys -- (nimstsk)
DRV - [2008/12/05 17:21:24 | 000,020,104 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvalarmk.sys -- (lvalarmk)
DRV - [2008/11/24 02:42:02 | 000,011,360 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nimru2kl.sys -- (nimru2k)
DRV - [2008/07/28 16:08:36 | 000,011,336 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\niswdkl.sys -- (niswdk)
DRV - [2008/06/25 13:02:24 | 000,020,568 | ---- | M] (National Instruments Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nipxigpk.sys -- (nipxigpk)
DRV - [2007/10/07 16:05:06 | 002,455,040 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2007/09/24 21:12:48 | 000,392,960 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)
DRV - [2007/07/23 20:42:12 | 000,045,056 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HECI.sys -- (HECI) Intel®
DRV - [2007/06/01 14:41:00 | 000,018,432 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pmxmouse.sys -- (pmxmouse)
DRV - [2007/05/24 17:56:00 | 000,014,336 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pmxusblf.sys -- (pmxusblf)
DRV - [2006/08/18 15:18:08 | 000,009,400 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResM.SYS -- (DLADResM)
DRV - [2006/08/18 15:17:46 | 000,035,096 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABMFSM.SYS -- (DLABMFSM)
DRV - [2006/08/18 15:17:44 | 000,097,848 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2006/08/18 15:17:44 | 000,094,648 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2006/08/18 15:17:42 | 000,026,008 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2006/08/18 15:17:40 | 000,032,472 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2006/08/18 15:17:38 | 000,104,472 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2006/08/18 15:17:38 | 000,014,520 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2006/08/11 12:35:18 | 000,012,920 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2006/08/11 12:35:16 | 000,028,184 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_M.SYS -- (DLARTL_M)
DRV - [2004/03/03 10:50:00 | 000,037,887 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidUsb.sys -- (LHidUsb)
DRV - [2004/03/03 10:50:00 | 000,014,095 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LCcfltr.sys -- (LCcfltr)
DRV - [2003/06/24 19:42:04 | 000,035,128 | ---- | M] (National Instruments) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NiViUsbK.sys -- (NIVIUSBK)
DRV - [2003/06/24 19:41:24 | 000,017,920 | ---- | M] (National Instruments) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\NiViPxiK.sys -- (NiViPxiK)
DRV - [2001/08/17 14:06:02 | 000,154,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Icam4USB.sys -- (Icam4USB)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1071212
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1071212

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1071212
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...=us&ibd=1071212
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.msn.com/sphome.aspx
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.9.7.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24

FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/03 10:00:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/02 14:39:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.10\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/05/11 09:01:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.10\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2010/02/02 20:41:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Tempuser\Application Data\Mozilla\Extensions
[2010/02/02 20:41:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Tempuser\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/06/12 16:23:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Tempuser\Application Data\Mozilla\Firefox\Profiles\09rzlysw.default\extensions
[2010/11/01 16:58:25 | 000,000,000 | ---D | M] (Forecastfox Weather) -- C:\Documents and Settings\Tempuser\Application Data\Mozilla\Firefox\Profiles\09rzlysw.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010/07/10 14:54:13 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Tempuser\Application Data\Mozilla\Firefox\Profiles\09rzlysw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/04/03 16:59:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Tempuser\Application Data\Mozilla\Firefox\Profiles\09rzlysw.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}-trash
[2011/05/12 10:07:35 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Documents and Settings\Tempuser\Application Data\Mozilla\Firefox\Profiles\09rzlysw.default\extensions\[email protected]
[2011/05/03 10:07:30 | 000,000,000 | ---D | M] (Grooveshark Remote Control) -- C:\Documents and Settings\Tempuser\Application Data\Mozilla\Firefox\Profiles\09rzlysw.default\extensions\jid0-louF1d9B6fCB9aYNBoUJcV7HSHw@jetpack
[2011/02/15 13:03:58 | 000,000,000 | ---D | M] (Maximum AdBlock) -- C:\Documents and Settings\Tempuser\Application Data\Mozilla\Firefox\Profiles\09rzlysw.default\extensions\[email protected]
[2011/04/03 17:05:33 | 000,000,000 | ---D | M] (startup.service) -- C:\Documents and Settings\Tempuser\Application Data\Mozilla\Firefox\Profiles\09rzlysw.default\extensions\[email protected]
[2011/05/24 09:19:54 | 000,000,000 | ---D | M] (Echofon) -- C:\Documents and Settings\Tempuser\Application Data\Mozilla\Firefox\Profiles\09rzlysw.default\extensions\[email protected]
[2011/06/12 17:09:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/10/31 18:16:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/16 18:55:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/10 13:03:53 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/12 17:09:55 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- C:\DOCUMENTS AND SETTINGS\TEMPUSER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\09RZLYSW.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\TEMPUSER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\09RZLYSW.DEFAULT\EXTENSIONS\[email protected]
[2010/02/02 18:21:15 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/05/03 10:00:40 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2008/08/16 18:42:02 | 000,070,456 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2008/08/16 18:42:12 | 000,091,448 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2008/08/16 18:42:08 | 000,020,800 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2008/05/21 09:41:08 | 000,479,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2008/05/21 09:41:08 | 000,548,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2008/05/21 09:41:08 | 000,626,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2011/05/04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2008/08/16 18:44:46 | 000,427,312 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2007/02/08 11:48:16 | 000,028,448 | ---- | M] (National Instruments) -- C:\Program Files\Mozilla Firefox\plugins\NPLV82Win32.dll
[2008/08/16 18:42:04 | 000,023,864 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll
[2011/04/03 16:59:51 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2004/08/04 07:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Itiva Media Accelerator] C:\Program Files\Itiva\Itiva Media Accelerator\ItivaMediaAccelerator.exe (Itiva Digital Media)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [niDevMon] C:\Program Files\National Instruments\NI-DAQ\HWConfig\nidevmon.exe (National Instruments Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PMX Daemon] C:\WINDOWS\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe (Roxio)
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
O4 - HKCU..\Run: [DisplayFusion] C:\Program Files\DisplayFusion\DisplayFusion.exe (Binary Fortress Software)
O4 - HKCU..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe (Jay Elaraj)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\IO Control.lnk = C:\WINDOWS\Installer\{16BF3865-0DA3-4BC1-BA21-0395CEB38B2A}\NewShortcut2.53194037_DDF3_483C_97E9_67D689D47D96.exe (Macrovision Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Agilent\LXI Mdns Responder\LxiMdnsNsp.dll (Agilent Technologies, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1199902897890 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/...SetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ecn.purdue.edu
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Tempuser\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 15:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/12 18:14:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tempuser\Desktop\GT2011 Papers
[2011/06/12 18:09:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tempuser\My Documents\BOOKS
[2011/05/23 12:57:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tempuser\Start Menu\Programs\Juniper Networks
[2011/05/23 12:57:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Tempuser\Application Data\Juniper Networks
[2011/05/23 12:57:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2011/05/18 09:08:50 | 000,000,000 | ---D | C] -- C:\Desktop

========== Files - Modified Within 30 Days ==========

[2011/06/13 12:26:00 | 000,000,990 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2118329724-1061487763-1882075788-1009UA.job
[2011/06/12 16:29:48 | 000,000,065 | ---- | M] () -- C:\WINDOWS\iTouch.ini
[2011/06/12 16:26:00 | 000,000,938 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2118329724-1061487763-1882075788-1009Core.job
[2011/06/12 16:21:23 | 000,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/06/12 16:20:39 | 000,002,427 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\IO Control.lnk
[2011/06/12 16:19:24 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/05/18 09:02:36 | 000,002,309 | ---- | M] () -- C:\Documents and Settings\Tempuser\Desktop\Google Chrome.lnk
[2011/05/17 12:44:33 | 000,010,250 | ---- | M] () -- C:\Documents and Settings\Tempuser\annulus_100.igs
[2011/05/17 12:42:05 | 001,048,576 | ---- | M] () -- C:\Documents and Settings\Tempuser\annulus.dbs
[2011/05/17 12:42:05 | 000,005,381 | ---- | M] () -- C:\Documents and Settings\Tempuser\annulus.trn
[2011/05/17 12:42:05 | 000,002,672 | ---- | M] () -- C:\Documents and Settings\Tempuser\annulus.jou

========== Files Created - No Company Name ==========

[2011/05/17 12:44:33 | 000,010,250 | ---- | C] () -- C:\Documents and Settings\Tempuser\annulus_100.igs
[2011/05/17 12:42:05 | 001,048,576 | ---- | C] () -- C:\Documents and Settings\Tempuser\annulus.dbs
[2011/05/17 12:42:05 | 000,005,381 | ---- | C] () -- C:\Documents and Settings\Tempuser\annulus.trn
[2011/05/17 12:42:05 | 000,002,672 | ---- | C] () -- C:\Documents and Settings\Tempuser\annulus.jou
[2011/05/11 11:44:12 | 000,260,531 | ---- | C] () -- C:\WINDOWS\pdfcvt.dat
[2011/02/23 17:54:40 | 000,000,051 | ---- | C] () -- C:\WINDOWS\SW_Win9423X24.DLL
[2011/02/23 17:54:36 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\FreeImage3.dll
[2011/02/23 17:54:36 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\FreeImage.dll
[2011/02/23 17:54:36 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\DVM.dll
[2011/02/23 17:54:36 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\RegisterExe.exe
[2011/02/20 16:07:21 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2010/11/09 11:16:17 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\default_user_class.dat
[2010/11/02 15:57:11 | 000,000,028 | ---- | C] () -- C:\WINDOWS\pdf995.ini
[2010/11/02 15:46:03 | 000,000,059 | ---- | C] () -- C:\WINDOWS\wpd99.drv
[2010/11/02 15:46:02 | 000,051,716 | ---- | C] () -- C:\WINDOWS\System32\pdf995mon.dll
[2010/10/31 18:08:30 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/10/31 17:15:20 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/06/05 18:32:05 | 000,012,800 | ---- | C] () -- C:\Documents and Settings\Tempuser\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/29 15:34:59 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\ltserial.dll
[2010/02/24 10:11:56 | 000,000,288 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/02/03 10:31:05 | 000,000,065 | ---- | C] () -- C:\WINDOWS\iTouch.ini
[2010/01/10 04:53:32 | 000,003,520 | ---- | C] () -- C:\WINDOWS\System32\nipalpg.dll
[2009/11/23 16:07:09 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\Tempuser\Local Settings\Application Data\fusioncache.dat
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/08/03 11:00:00 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\cvintdrv.sys
[2009/06/14 15:15:52 | 000,000,244 | ---- | C] () -- C:\WINDOWS\System32\nirpc.ini
[2009/01/26 13:57:38 | 000,022,897 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB72F30200.bin
[2009/01/26 13:57:38 | 000,022,897 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB72F3.bin
[2009/01/26 13:57:38 | 000,022,897 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB72CC0200.bin
[2009/01/26 13:57:38 | 000,022,897 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB72CC.bin
[2009/01/26 13:57:38 | 000,012,307 | R--- | C] () -- C:\WINDOWS\System32\drivers\NIUSB71D7.bin
[2009/01/26 13:57:38 | 000,012,307 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB71D80200.bin
[2009/01/26 13:57:38 | 000,012,307 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB71D70200.bin
[2009/01/26 13:57:38 | 000,012,307 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB71D60200.bin
[2009/01/26 13:57:38 | 000,012,307 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB717B0200.bin
[2009/01/26 13:57:38 | 000,012,307 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB717A0200.bin
[2009/01/26 13:57:38 | 000,009,669 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB71DF0200.bin
[2009/01/26 13:57:38 | 000,009,669 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB71DF.bin
[2009/01/26 13:57:38 | 000,009,381 | R--- | C] () -- C:\WINDOWS\System32\drivers\NIUSB717B.bin
[2009/01/26 13:57:38 | 000,009,381 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB717B0100.bin
[2009/01/26 13:57:38 | 000,009,295 | R--- | C] () -- C:\WINDOWS\System32\drivers\NIUSB71D8.bin
[2009/01/26 13:57:38 | 000,009,295 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB71D80100.bin
[2009/01/26 13:57:38 | 000,009,158 | R--- | C] () -- C:\WINDOWS\System32\drivers\NIUSB71D6.bin
[2009/01/26 13:57:38 | 000,009,158 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB71D60100.bin
[2009/01/26 13:57:38 | 000,009,146 | R--- | C] () -- C:\WINDOWS\System32\drivers\NIUSB717A.bin
[2009/01/26 13:57:38 | 000,009,146 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB717A0100.bin
[2009/01/26 13:57:38 | 000,008,091 | R--- | C] () -- C:\WINDOWS\System32\drivers\NIUSB718A.bin
[2009/01/26 13:57:38 | 000,008,091 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB718A0100.bin
[2009/01/26 13:57:38 | 000,007,697 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIUSB718A0200.bin
[2009/01/07 19:20:24 | 000,050,208 | ---- | C] () -- C:\WINDOWS\System32\nispdu.dll
[2009/01/05 10:28:24 | 000,070,176 | ---- | C] () -- C:\WINDOWS\System32\drivers\nispdk.dll
[2009/01/05 10:28:12 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\niscdrau.dll
[2008/01/30 15:17:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/01/07 16:00:05 | 000,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2007/12/12 20:22:17 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007/12/12 20:20:09 | 000,056,056 | ---- | C] () -- C:\WINDOWS\System32\DLAAPI_W.DLL
[2007/12/12 20:20:09 | 000,000,120 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2007/12/12 20:17:01 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\FontZoom.exe
[2007/12/12 20:17:01 | 000,131,066 | ---- | C] () -- C:\WINDOWS\System32\DellPM.ini
[2007/12/12 20:05:16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2007/12/12 20:03:39 | 000,077,824 | ---- | C] () -- C:\WINDOWS\setpwr32.exe
[2007/12/12 20:03:38 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
[2007/12/12 20:03:38 | 003,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2007/12/12 20:03:38 | 000,972,072 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2007/12/12 20:03:38 | 000,156,671 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2007/12/12 20:03:38 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ATIODE.exe
[2007/12/12 20:03:38 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ATIODCLI.exe
[2007/12/12 20:02:43 | 000,001,027 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2007/02/28 07:03:32 | 000,080,720 | ---- | C] () -- C:\WINDOWS\System32\AsfBios.dll
[2007/01/23 05:45:40 | 000,025,424 | ---- | C] () -- C:\WINDOWS\System32\drivers\netamsg.dll
[2006/11/07 06:25:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006/09/17 01:36:50 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/17 01:36:50 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2004/08/10 15:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 15:07:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/10 15:02:15 | 000,023,444 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 15:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 14:57:52 | 000,004,346 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 14:57:15 | 000,346,608 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 14:51:20 | 000,444,320 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/10 14:51:20 | 000,072,992 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/10 14:51:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/04 08:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/04 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/04 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2003/05/19 10:12:08 | 000,196,608 | ---- | C] () -- C:\WINDOWS\System32\hpbvnstp.dll
[2003/03/10 18:02:04 | 000,000,254 | ---- | C] () -- C:\WINDOWS\System32\hpbvnstp.dat
[2003/02/25 19:19:56 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL

========== LOP Check ==========

[2010/01/15 19:36:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Agilent
[2010/04/05 16:06:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ANSYSInstall
[2011/04/20 10:05:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hummingbird
[2010/04/05 18:04:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IsolatedStorage
[2008/02/14 17:24:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Itiva
[2010/01/15 19:36:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IVI Foundation
[2011/05/23 12:57:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2010/03/04 20:52:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\National Instruments
[2011/05/11 12:12:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pdf995
[2008/01/30 15:11:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VanDyke
[2010/05/26 00:29:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/02/02 18:36:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/01/15 19:37:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\Agilent
[2011/01/19 15:38:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\Amazon
[2010/04/05 16:57:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\anshelp
[2011/04/16 15:49:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\Ansys
[2011/05/23 09:42:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\DisplayFusion
[2010/09/10 13:35:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\Dropbox
[2011/04/20 10:06:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\Hummingbird
[2010/02/10 21:51:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\ICAClient
[2010/03/06 19:02:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\inkscape
[2011/05/23 12:59:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\Juniper Networks
[2010/11/29 17:32:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\Launcher
[2010/05/30 18:46:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\MuPAD
[2010/11/02 15:57:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\pdf995
[2011/04/11 15:23:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\PTC
[2010/11/01 14:58:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\SecurityHeroes
[2011/02/03 11:19:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\TeamViewer
[2010/02/02 20:41:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\Thunderbird
[2011/01/28 12:42:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\VanDyke
[2011/05/12 15:41:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\WinEdt
[2010/11/01 16:57:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tempuser\Application Data\WinEdt Team

========== Purity Check ==========



< End of report >
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP