Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

trojan win 32 generic [Closed]


  • This topic is locked This topic is locked

#1
mpurcell71

mpurcell71

    New Member

  • Member
  • Pip
  • 1 posts
I have run the scans already....and here are the results.....can you help.

OTL logfile created on: 10/31/2012 8:05:20 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\mpurcell.JPENERGY\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.41 Gb Total Physical Memory | 2.53 Gb Available Physical Memory | 74.25% Memory free
5.25 Gb Paging File | 4.37 Gb Available in Paging File | 83.29% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 238.46 Gb Total Space | 190.07 Gb Free Space | 79.71% Space Free | Partition Type: NTFS
Drive X: | 204.18 Gb Total Space | 117.44 Gb Free Space | 57.52% Space Free | Partition Type: NTFS
Drive Y: | 135.50 Gb Total Space | 71.55 Gb Free Space | 52.81% Space Free | Partition Type: NTFS
Drive Z: | 135.50 Gb Total Space | 71.55 Gb Free Space | 52.81% Space Free | Partition Type: NTFS

Computer Name: IT203 | User Name: mpurcell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/10/31 08:02:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\OTL.exe
PRC - [2012/07/27 02:30:58 | 000,112,968 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\IPROSetMonitor.exe
PRC - [2012/07/19 10:00:54 | 000,365,376 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2012/07/19 10:00:52 | 000,277,824 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2012/07/19 10:00:28 | 000,166,720 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
PRC - [2012/06/19 19:03:28 | 000,462,088 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe
PRC - [2012/02/13 22:20:00 | 001,433,692 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
PRC - [2012/02/13 22:20:00 | 000,290,898 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\stacsv.exe
PRC - [2011/10/12 12:31:36 | 001,627,504 | ---- | M] (GFI Software) -- C:\Program Files\GFI Software\GFIAgent\SBAMTray.exe
PRC - [2011/10/12 12:28:54 | 002,804,312 | ---- | M] (GFI Software) -- C:\Program Files\GFI Software\GFIAgent\SBAMSvc.exe
PRC - [2011/10/12 12:28:36 | 000,181,616 | ---- | M] (GFI Software) -- C:\Program Files\GFI Software\GFIAgent\SBPIMSvc.exe
PRC - [2011/07/28 15:00:42 | 001,469,296 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe
PRC - [2011/07/28 14:57:56 | 000,379,760 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe
PRC - [2011/05/25 09:31:18 | 000,223,848 | ---- | M] (O2Micro.) -- C:\WINDOWS\system32\SDIOAssist.exe
PRC - [2010/11/17 09:53:16 | 000,113,288 | ---- | M] (Renesas Electronics Corporation) -- C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2010/02/10 17:50:50 | 000,072,296 | ---- | M] (O2Micro International) -- C:\WINDOWS\system32\drivers\o2flash.exe
PRC - [2009/07/07 02:06:00 | 000,737,280 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\AESTFltr.exe
PRC - [2008/05/19 12:32:24 | 000,045,056 | ---- | M] (ESRI ) -- C:\Program Files\ArcGIS\Bin\AppLockMgr.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/05/04 00:04:28 | 009,150,464 | ---- | M] (Microsoft Corporation) -- c:\MSSQL2K\MSSQL\Binn\sqlservr.exe
PRC - [2005/05/03 21:42:56 | 000,323,584 | ---- | M] (Microsoft Corporation) -- c:\MSSQL2K\MSSQL\Binn\sqlagent.exe
PRC - [2003/04/18 18:06:26 | 000,008,192 | ---- | M] () -- C:\WINDOWS\system32\srvany.exe


========== Modules (No Company Name) ==========

MOD - [2012/09/25 16:07:36 | 000,165,768 | ---- | M] () -- C:\Program Files\GFI Software\GFIAgent\Definitions\libMachoUniv.dll
MOD - [2012/09/25 16:07:34 | 000,190,344 | ---- | M] () -- C:\Program Files\GFI Software\GFIAgent\Definitions\libBase64.dll
MOD - [2012/08/27 21:33:32 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/08/27 21:33:08 | 001,242,512 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2012/07/18 11:55:20 | 001,198,912 | ---- | M] () -- C:\Program Files\Intel\Intel® Management Engine Components\UNS\ACE.dll
MOD - [2012/06/13 06:18:00 | 000,143,360 | ---- | M] () -- C:\WINDOWS\system32\preflib.dll
MOD - [2012/06/13 06:17:58 | 000,868,352 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll
MOD - [2011/03/10 02:14:20 | 000,888,832 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\KOAZCJ_O.DLL
MOD - [2011/01/19 11:20:14 | 000,308,560 | ---- | M] () -- C:\Program Files\GFI Software\GFIAgent\vipre.dll
MOD - [2008/05/19 18:36:04 | 000,080,384 | ---- | M] () -- C:\Program Files\ArcGIS\Bin\ONCRPC.DLL
MOD - [2005/12/22 17:28:40 | 000,160,768 | ---- | M] () -- C:\Program Files\GFI Software\GFIAgent\unrar.dll
MOD - [2003/04/18 18:06:26 | 000,008,192 | ---- | M] () -- C:\WINDOWS\system32\srvany.exe


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\WINDOWS\system32\bgftmig.dll -- (vzmqsznt)
SRV - File not found [Auto | Unknown] -- C:\WINDOWS\system32\bgftmig.dll -- (gvjzlm)
SRV - [2012/10/29 08:26:28 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/10/19 10:52:40 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/27 02:30:58 | 000,112,968 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\WINDOWS\system32\IPROSetMonitor.exe -- (Intel®
SRV - [2012/07/19 10:00:54 | 000,365,376 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2012/07/19 10:00:52 | 000,277,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2012/07/19 10:00:28 | 000,166,720 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2012/06/19 19:03:28 | 000,462,088 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel®
SRV - [2012/02/13 22:20:00 | 000,290,898 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv.exe -- (STacSV)
SRV - [2011/10/12 12:28:54 | 002,804,312 | ---- | M] (GFI Software) [Auto | Running] -- C:\Program Files\GFI Software\GFIAgent\SBAMSvc.exe -- (SBAMSvc)
SRV - [2011/10/12 12:28:36 | 000,181,616 | ---- | M] (GFI Software) [Auto | Running] -- C:\Program Files\GFI Software\GFIAgent\SBPIMSvc.exe -- (SBPIMSvc)
SRV - [2011/07/28 14:57:56 | 000,379,760 | ---- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe -- (dcpsysmgrsvc)
SRV - [2010/02/10 17:50:50 | 000,072,296 | ---- | M] (O2Micro International) [Auto | Running] -- C:\WINDOWS\system32\drivers\o2flash.exe -- (O2FLASH)
SRV - [2005/06/08 05:40:00 | 000,065,585 | ---- | M] (IBM Corporation) [On_Demand | Stopped] -- C:\WINDOWS\cwbrxd.exe -- (Cwbrxd)
SRV - [2005/05/04 00:04:28 | 009,150,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\MSSQL2K\MSSQL\Binn\sqlservr.exe -- (MSSQLSERVER)
SRV - [2005/05/03 21:42:56 | 000,323,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\MSSQL2K\MSSQL\Binn\sqlagent.exe -- (SQLSERVERAGENT)
SRV - [2003/04/18 18:06:26 | 000,008,192 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\srvany.exe -- (O2SDIOAssist)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/08/10 17:22:21 | 000,218,448 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1c5132.sys -- (e1cexpress)
DRV - [2012/07/02 15:16:00 | 000,055,104 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HECI.sys -- (MEI)
DRV - [2012/06/13 06:18:00 | 003,369,984 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2012/02/13 22:20:00 | 001,984,771 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2011/12/06 04:24:14 | 000,270,080 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntcDAud.sys -- (IntcDAud)
DRV - [2011/11/04 09:17:28 | 000,059,888 | ---- | M] (STMicroelectronics) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ST_ACCEL.sys -- (ST_ACCEL)
DRV - [2011/09/09 14:46:30 | 000,212,568 | ---- | M] (Sunbelt Software, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\sbtis.sys -- (SbTis)
DRV - [2011/08/30 06:56:24 | 000,101,624 | ---- | M] (GFI Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SBREDrv.sys -- (SBRE)
DRV - [2011/08/30 06:56:24 | 000,074,104 | ---- | M] (GFI Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\sbapifs.sys -- (sbapifs)
DRV - [2011/08/30 06:56:24 | 000,021,496 | ---- | M] (GFI Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\sbaphd.sys -- (sbaphd)
DRV - [2011/07/15 21:30:50 | 000,017,904 | ---- | M] (ST Microelectronics) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\stdcfltn.sys -- (stdcfltn)
DRV - [2011/03/23 13:51:56 | 000,063,976 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\o2sdjxp.sys -- (O2SDJRDR)
DRV - [2009/04/21 22:13:00 | 000,113,664 | ---- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AESTAud.sys -- (AESTAud)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-776561741-152049171-1060284298-1111\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-776561741-152049171-1060284298-3328\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-776561741-152049171-1060284298-3328\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-776561741-152049171-1060284298-3328\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B4 08 5F 63 14 B6 CD 01 [binary data]
IE - HKU\S-1-5-21-776561741-152049171-1060284298-3328\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-776561741-152049171-1060284298-3328\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...Box&Form=IE8SRC
IE - HKU\S-1-5-21-776561741-152049171-1060284298-3328\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-776561741-152049171-1060284298-3328\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: [email protected]:1.0
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}:6.0.37
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/10/29 08:26:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2012/10/19 10:16:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Mozilla\Extensions
[2012/10/24 10:24:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Mozilla\Firefox\Profiles\15i4hefe.default\extensions
[2012/10/29 15:36:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/10/29 08:26:26 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012/10/26 08:59:08 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/10/29 08:26:28 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/10/10 20:05:38 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/10 20:05:38 | 000,002,058 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [AESTFltr] C:\WINDOWS\System32\AESTFltr.exe (Andrea Electronics Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Client Access Service] C:\Program Files\IBM\Client Access\cwbsvstr.exe (IBM Corporation)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [pynnrocxv] rundll32.exe "C:\WINDOWS\system32\bgftmig.dll",rredlmb File not found
O4 - HKLM..\Run: [SBAMTray] C:\Program Files\GFI Software\GFIAgent\SBAMTray.exe (GFI Software)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell System Manager.lnk = C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe (Dell Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-776561741-152049171-1060284298-1111\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-776561741-152049171-1060284298-3328\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://windowsupdate...b?1350481973734 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_37)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = jpenergy.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ABE866BA-F014-4B42-B93D-AA9F98ED3832}: NameServer = 192.168.32.251
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop BackupWallPaper:
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/10/16 09:32:19 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/31 08:02:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\OTL.exe
[2012/10/30 10:45:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\My Documents\Google Earth Maps
[2012/10/30 10:03:23 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Resource Kits
[2012/10/30 08:23:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Google
[2012/10/30 08:23:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2012/10/30 08:20:13 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2012/10/30 08:20:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Local Settings\Application Data\Google
[2012/10/29 15:11:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Windows Search
[2012/10/29 08:26:26 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012/10/26 10:27:18 | 000,000,000 | ---D | C] -- C:\Program Files\NirSoft
[2012/10/26 08:59:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2012/10/26 08:58:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2012/10/23 10:49:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2012/10/22 13:13:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Python 2.5
[2012/10/22 13:13:12 | 002,113,536 | ---- | C] (Python Software Foundation) -- C:\WINDOWS\System32\python25.dll
[2012/10/22 13:10:39 | 000,000,000 | ---D | C] -- C:\Program Files\ESRI
[2012/10/22 13:10:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\ESRI
[2012/10/22 13:05:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ArcGIS
[2012/10/22 13:04:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AnswerWorks 4.0
[2012/10/22 13:02:10 | 000,000,000 | ---D | C] -- C:\Program Files\Leica Geosystems
[2012/10/22 12:53:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ESRI
[2012/10/22 12:52:37 | 000,000,000 | ---D | C] -- C:\Python25
[2012/10/22 12:52:37 | 000,000,000 | ---D | C] -- C:\Program Files\ArcGIS
[2012/10/22 10:19:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Local Settings\Application Data\Help
[2012/10/22 10:19:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Help
[2012/10/22 09:31:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Local Settings\Application Data\Adobe
[2012/10/19 15:39:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2012/10/19 15:39:15 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2012/10/19 15:16:11 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012/10/19 15:16:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/10/19 15:15:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Sun
[2012/10/19 15:12:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2012/10/19 15:07:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Local Settings\Application Data\Identities
[2012/10/19 15:07:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Windows Desktop Search
[2012/10/19 15:07:04 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
[2012/10/19 15:07:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2012/10/19 14:48:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\SchCache
[2012/10/19 14:46:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
[2012/10/19 14:46:29 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2012/10/19 14:46:12 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2012/10/19 14:45:47 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2012/10/19 14:40:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2012/10/19 14:40:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Local Settings\Application Data\Microsoft Help
[2012/10/19 14:40:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012/10/19 14:40:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2012/10/19 14:39:08 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2012/10/19 13:22:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Macromedia
[2012/10/19 13:22:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Adobe
[2012/10/19 13:17:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Local Settings\Application Data\Apple Computer
[2012/10/19 13:17:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Apple Computer
[2012/10/19 13:17:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2012/10/19 13:17:01 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/10/19 13:17:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2012/10/19 13:17:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/10/19 13:16:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Local Settings\Application Data\Apple
[2012/10/19 13:16:29 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2012/10/19 13:16:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2012/10/19 13:16:08 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2012/10/19 13:15:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2012/10/19 13:15:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple
[2012/10/19 11:00:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2012/10/19 10:46:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2012/10/19 10:37:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2012/10/19 10:19:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\My Documents\Downloads
[2012/10/19 10:16:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Local Settings\Application Data\Mozilla
[2012/10/19 10:16:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Mozilla
[2012/10/19 10:00:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\My Documents\IBM
[2012/10/19 09:58:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\IBM iSeries Access for Windows
[2012/10/19 09:58:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\IBM
[2012/10/19 09:57:39 | 000,000,000 | ---D | C] -- C:\Program Files\IBM
[2012/10/19 09:40:25 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/10/19 09:40:17 | 000,000,000 | ---D | C] -- C:\Program Files\RF IDeas
[2012/10/19 09:05:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\desktop folders
[2012/10/19 07:28:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\TEMP FOLDER
[2012/10/19 07:16:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\AMI Related
[2012/10/19 07:14:32 | 000,000,000 | ---D | C] -- C:\Troopmaster Software
[2012/10/19 07:13:17 | 000,000,000 | ---D | C] -- C:\Program Files\Ultimate
[2012/10/19 07:10:32 | 000,000,000 | ---D | C] -- C:\FileZilla FTP Client
[2012/10/19 07:06:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2012/10/19 07:05:28 | 000,000,000 | ---D | C] -- C:\Spybot - Search & Destroy
[2012/10/18 15:13:03 | 000,074,104 | ---- | C] (GFI Software) -- C:\WINDOWS\System32\drivers\sbapifs.sys
[2012/10/18 15:13:03 | 000,021,496 | ---- | C] (GFI Software) -- C:\WINDOWS\System32\drivers\sbaphd.sys
[2012/10/18 15:09:55 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2012/10/18 15:07:23 | 000,000,000 | ---D | C] -- C:\Program Files\FileZilla FTP Client
[2012/10/18 15:06:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\GFI Software
[2012/10/18 15:06:29 | 000,212,568 | ---- | C] (Sunbelt Software, Inc.) -- C:\WINDOWS\System32\drivers\sbtis.sys
[2012/10/18 15:04:57 | 000,000,000 | ---D | C] -- C:\Program Files\GFI Software
[2012/10/18 15:04:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\GFI Software
[2012/10/18 14:23:43 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\mpurcell.JPENERGY\IECompatCache
[2012/10/18 14:23:13 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\mpurcell.JPENERGY\PrivacIE
[2012/10/18 14:22:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\My Documents\My Pictures
[2012/10/18 14:22:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\My Documents\My Music
[2012/10/18 14:22:47 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\mpurcell.JPENERGY\IETldCache
[2012/10/18 14:22:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Identities
[2012/10/18 14:22:46 | 000,000,000 | --SD | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Microsoft
[2012/10/18 14:22:46 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\SendTo
[2012/10/18 14:22:46 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Recent
[2012/10/18 14:22:46 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data
[2012/10/18 14:22:46 | 000,000,000 | R--D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Start Menu\Programs\Startup
[2012/10/18 14:22:46 | 000,000,000 | R--D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Start Menu
[2012/10/18 14:22:46 | 000,000,000 | R--D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\My Documents
[2012/10/18 14:22:46 | 000,000,000 | R--D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Favorites
[2012/10/18 14:22:46 | 000,000,000 | R--D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Start Menu\Programs\Accessories
[2012/10/18 14:22:46 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Cookies
[2012/10/18 14:22:46 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Templates
[2012/10/18 14:22:46 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\PrintHood
[2012/10/18 14:22:46 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\NetHood
[2012/10/18 14:22:46 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Local Settings
[2012/10/18 14:22:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Local Settings\Application Data\Microsoft
[2012/10/18 14:22:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop
[2012/10/18 13:14:49 | 000,000,000 | ---D | C] -- C:\Program Files\UAI
[2012/10/18 13:14:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\UAI
[2012/10/18 13:14:45 | 000,000,000 | ---D | C] -- C:\Program Files\ReSizOCX
[2012/10/18 13:14:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Data Dynamics
[2012/10/18 13:14:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\UAI
[2012/10/18 13:14:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ESRI
[2012/10/18 13:13:55 | 000,000,000 | ---D | C] -- C:\UAPROGRAMS
[2012/10/18 13:10:08 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2012/10/18 13:09:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTEMP
[2012/10/18 12:55:24 | 000,000,000 | ---D | C] -- C:\UAHOME
[2012/10/18 08:24:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft SQL Server - Switch
[2012/10/18 08:24:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft SQL Server
[2012/10/18 08:22:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Designer
[2012/10/18 08:21:44 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server
[2012/10/18 08:06:25 | 000,000,000 | ---D | C] -- C:\MSSQL2K
[2012/10/18 07:33:06 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2012/10/17 15:21:22 | 000,017,904 | ---- | C] (ST Microelectronics) -- C:\WINDOWS\System32\drivers\stdcfltn.sys
[2012/10/17 15:21:22 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2012/10/17 15:21:14 | 000,067,184 | ---- | C] (ST Microelectronics) -- C:\WINDOWS\System32\stdcfltnco02.dll
[2012/10/17 15:21:14 | 000,059,888 | ---- | C] (STMicroelectronics) -- C:\WINDOWS\System32\drivers\ST_ACCEL.sys
[2012/10/17 15:21:14 | 000,000,000 | ---D | C] -- C:\Program Files\STMicroelectronics
[2012/10/17 15:21:05 | 000,000,000 | ---D | C] -- C:\Program Files\ST Microelectronics
[2012/10/17 15:16:56 | 000,223,848 | ---- | C] (O2Micro.) -- C:\WINDOWS\System32\SDIOAssist.exe
[2012/10/17 15:16:55 | 001,145,448 | ---- | C] (O2Micro) -- C:\WINDOWS\System32\O2Icon.dll
[2012/10/17 15:16:55 | 000,072,296 | ---- | C] (O2Micro International) -- C:\WINDOWS\System32\drivers\o2flash.exe
[2012/10/17 15:16:55 | 000,063,976 | ---- | C] (O2Micro ) -- C:\WINDOWS\System32\drivers\o2sdjxp.sys
[2012/10/17 15:16:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SDA
[2012/10/17 15:16:53 | 000,000,000 | ---D | C] -- C:\Program Files\O2Micro
[2012/10/17 15:06:51 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\WINDOWS\System32\CSVer.dll
[2012/10/17 14:58:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\postureAgent
[2012/10/17 13:53:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Dell System Manager
[2012/10/17 13:52:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Dell
[2012/10/17 12:54:34 | 000,000,000 | ---D | C] -- C:\9161841d7f9f76392774
[2012/10/17 12:41:25 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/10/17 11:34:02 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2012/10/17 11:34:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2012/10/17 11:33:58 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2012/10/17 11:33:34 | 000,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2012/10/17 11:33:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2012/10/17 09:40:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2012/10/17 09:40:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2012/10/17 09:39:55 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2012/10/17 08:55:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2012/10/17 08:55:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2012/10/17 08:53:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2012/10/17 08:45:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\{8D66B53E-07E4-45E0-B29F-D3285859C9EF}
[2012/10/17 08:29:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Intel
[2012/10/17 08:29:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2012/10/17 08:29:26 | 000,000,000 | ---D | C] -- C:\Intel
[2012/10/17 08:19:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\DW WLAN
[2012/10/17 08:19:43 | 002,670,592 | ---- | C] (BCGSoft Ltd) -- C:\WINDOWS\System32\WLBCGCBPRO731.DLL
[2012/10/17 08:19:43 | 000,069,632 | ---- | C] (CACE Technologies) -- C:\WINDOWS\System32\bcmwlpkt.dll
[2012/10/17 08:19:43 | 000,033,664 | ---- | C] (CACE Technologies) -- C:\WINDOWS\System32\drivers\BCMWLNPF.SYS
[2012/10/17 08:19:43 | 000,000,000 | ---D | C] -- C:\Program Files\Dell
[2012/10/17 08:19:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Renesas Electronics
[2012/10/17 08:19:06 | 000,000,000 | ---D | C] -- C:\Program Files\Renesas Electronics
[2012/10/17 08:06:32 | 000,000,000 | ---D | C] -- C:\Program Files\IDT
[2012/10/16 15:18:41 | 011,870,298 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\idtsg.cpl
[2012/10/16 15:18:41 | 004,644,864 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\stlang.dll
[2012/10/16 15:18:27 | 001,984,771 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\drivers\sthda.sys
[2012/10/16 15:18:27 | 000,544,866 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\stacapi.dll
[2012/10/16 15:18:27 | 000,211,456 | ---- | C] (IDT, Inc.) -- C:\WINDOWS\System32\st326388.dll
[2012/10/16 15:18:26 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2012/10/16 15:10:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2012/10/16 15:07:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
[2012/10/16 15:07:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2012/10/16 15:07:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-us
[2012/10/16 15:07:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2012/10/16 15:07:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2012/10/16 15:06:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2012/10/16 15:06:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\network diagnostic
[2012/10/16 15:06:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2012/10/16 15:05:42 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2012/10/16 15:02:56 | 000,000,000 | ---D | C] -- C:\Program Files\BitZipper
[2012/10/16 11:14:34 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012/10/16 11:14:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla
[2012/10/16 10:33:22 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2012/10/16 09:35:13 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2012/10/16 09:34:32 | 000,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft
[2012/10/16 09:34:32 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2012/10/16 09:34:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2012/10/16 09:34:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2012/10/16 09:34:15 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2012/10/16 09:34:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2012/10/16 09:33:29 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2012/10/16 09:33:29 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2012/10/16 09:32:52 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2012/10/16 09:32:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2012/10/16 09:32:36 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2012/10/16 09:32:36 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2012/10/16 09:32:31 | 000,000,000 | ---D | C] -- C:\DELL
[2012/10/16 09:32:25 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
[2012/10/16 09:32:02 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\DRM
[2012/10/16 09:32:00 | 000,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2012/10/16 09:32:00 | 000,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages
[2012/10/16 09:31:58 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2012/10/16 09:31:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2012/10/16 09:31:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2012/10/16 09:31:18 | 000,000,000 | --SD | C] -- C:\WINDOWS\Tasks
[2012/10/16 09:31:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap
[2012/10/16 09:31:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2012/10/16 09:31:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2012/10/16 09:31:05 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker
[2012/10/16 09:30:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore
[2012/10/16 09:30:54 | 000,000,000 | ---D | C] -- C:\Program Files\NetMeeting
[2012/10/16 09:30:51 | 000,000,000 | ---D | C] -- C:\Program Files\Outlook Express
[2012/10/16 09:30:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\System
[2012/10/16 09:30:42 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures
[2012/10/16 09:30:42 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Explorer
[2012/10/16 09:30:37 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Games
[2012/10/16 09:30:35 | 000,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications
[2012/10/16 09:30:34 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
[2012/10/16 09:30:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2012/10/16 09:30:33 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music
[2012/10/16 09:30:33 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2012/10/16 09:30:33 | 000,000,000 | ---D | C] -- C:\Program Files\Online Services
[2012/10/16 09:30:31 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger
[2012/10/16 09:30:27 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Gaming Zone
[2012/10/16 09:29:55 | 000,000,000 | ---D | C] -- C:\Program Files\MSN
[2012/10/16 09:29:53 | 000,000,000 | ---D | C] -- C:\Program Files\Windows NT
[2012/10/16 09:29:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2012/10/16 09:29:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2012/10/16 09:29:36 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2012/10/16 09:29:33 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Accessories
[2012/10/16 04:27:19 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2012/10/16 04:27:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2012/10/16 04:27:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2012/10/16 04:27:16 | 000,000,000 | R--D | C] -- C:\Program Files
[2012/10/16 04:27:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared
[2012/10/16 04:27:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files
[2012/10/16 04:26:58 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup
[2012/10/16 04:26:58 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu
[2012/10/16 04:26:58 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents
[2012/10/16 04:26:58 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Templates
[2012/10/16 04:26:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites
[2012/10/16 04:26:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop
[2012/10/16 04:26:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2012/10/16 04:26:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2012/10/16 04:26:42 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2012/10/16 04:26:42 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data
[2012/10/16 04:26:24 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012/10/16 04:26:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings
[2012/10/16 04:20:25 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2012/10/16 04:20:25 | 000,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2012/10/16 04:20:25 | 000,000,000 | R--D | C] -- C:\WINDOWS\Web
[2012/10/16 04:20:25 | 000,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\system
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\security
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\repair
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Provisioning
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\PeerNet
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\pchealth
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\mui
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Media
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\java
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\ime
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\ehome
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\dell
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\config
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Config
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2012/10/16 04:20:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/31 08:05:11 | 000,000,068 | ---- | M] () -- C:\Documents and Settings\mpurcell.JPENERGY\YCOptions.DAT
[2012/10/31 08:04:56 | 000,000,618 | ---- | M] () -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\IT203Session1.WS
[2012/10/31 08:04:53 | 000,001,780 | -H-- | M] () -- C:\Documents and Settings\mpurcell.JPENERGY\My Documents\Default.rdp
[2012/10/31 08:02:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\OTL.exe
[2012/10/31 07:38:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/31 07:25:00 | 000,000,890 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/30 10:49:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/10/30 09:58:08 | 000,379,392 | ---- | M] () -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\subinacl.msi
[2012/10/30 08:25:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/30 08:23:04 | 000,001,915 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2012/10/30 07:30:14 | 000,483,030 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/10/30 07:30:14 | 000,086,646 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/10/30 07:28:06 | 000,002,262 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/10/30 07:26:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/10/30 07:08:05 | 000,006,142 | RHS- | M] () -- C:\Documents and Settings\mpurcell.JPENERGY\ntuser.pol
[2012/10/29 15:40:42 | 000,000,402 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2012/10/29 15:05:25 | 010,488,167 | ---- | M] () -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\Windows6.1-KB2722913-x86.msu
[2012/10/26 08:38:10 | 000,330,688 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/10/25 08:13:54 | 000,012,905 | ---- | M] () -- C:\Documents and Settings\mpurcell.JPENERGY\My Documents\Firmware Version 4.4.csv
[2012/10/22 13:31:53 | 000,007,150 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\services
[2012/10/22 10:44:21 | 000,000,364 | ---- | M] () -- C:\WINDOWS\hpbafd.ini
[2012/10/19 15:07:38 | 000,001,787 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2012/10/19 15:06:53 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/10/19 14:48:42 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012/10/19 10:46:49 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2012/10/19 10:00:33 | 000,001,820 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\IBM iSeries Access for Windows.lnk
[2012/10/19 09:58:59 | 000,000,785 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iSeries Navigator.lnk
[2012/10/19 09:52:54 | 000,003,584 | ---- | M] () -- C:\Documents and Settings\mpurcell.JPENERGY\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/18 14:22:49 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/10/18 14:22:48 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/10/18 13:32:16 | 000,000,591 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Utility Center (2).lnk
[2012/10/18 13:14:58 | 000,000,428 | ---- | M] () -- C:\WINDOWS\System32\log4net.config
[2012/10/18 12:49:02 | 000,001,416 | ---- | M] () -- C:\WINDOWS\setup.iss
[2012/10/18 12:48:59 | 000,001,806 | ---- | M] () -- C:\WINDOWS\sql.mif
[2012/10/18 08:24:36 | 000,001,852 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
[2012/10/18 07:33:16 | 000,004,376 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol
[2012/10/17 15:21:22 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_ST_ACCEL_01009.Wdf
[2012/10/17 15:21:18 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2012/10/17 13:53:22 | 000,001,785 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell System Manager.lnk
[2012/10/16 15:10:14 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2012/10/16 15:06:31 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2012/10/16 11:14:34 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/10/16 09:34:17 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[2012/10/16 09:33:45 | 000,000,261 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2012/10/16 09:32:19 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/10/16 09:32:19 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2012/10/16 09:32:19 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2012/10/16 09:32:19 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2012/10/16 09:32:19 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2012/10/16 09:32:18 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2012/10/16 09:32:18 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2012/10/16 09:32:16 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2012/10/16 09:30:36 | 000,021,640 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012/10/16 09:29:29 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/30 09:58:06 | 000,379,392 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\subinacl.msi
[2012/10/30 08:23:04 | 000,001,915 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2012/10/30 08:20:14 | 000,000,890 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/30 08:20:14 | 000,000,886 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/29 15:06:18 | 010,488,167 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\Windows6.1-KB2722913-x86.msu
[2012/10/26 08:37:34 | 000,167,456 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/10/26 07:21:14 | 005,199,144 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\SSClean.exe
[2012/10/25 08:13:54 | 000,012,905 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\My Documents\Firmware Version 4.4.csv
[2012/10/24 10:32:00 | 000,001,780 | -H-- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\My Documents\Default.rdp
[2012/10/22 10:17:08 | 000,000,364 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2012/10/19 15:23:58 | 000,000,068 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\YCOptions.DAT
[2012/10/19 15:07:38 | 000,001,803 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Search.lnk
[2012/10/19 15:07:38 | 000,001,787 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2012/10/19 14:48:42 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012/10/19 13:16:32 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/10/19 13:16:29 | 000,001,830 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2012/10/19 10:52:40 | 000,000,830 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/19 10:46:49 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
[2012/10/19 10:46:49 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2012/10/19 10:35:30 | 000,000,373 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\70_to_67_Character_Billing_File_Convertor.bat
[2012/10/19 10:13:09 | 000,000,618 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\Desktop\IT203Session1.WS
[2012/10/19 10:00:33 | 000,001,820 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\IBM iSeries Access for Windows.lnk
[2012/10/19 09:58:59 | 000,000,785 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iSeries Navigator.lnk
[2012/10/19 09:58:33 | 000,020,534 | ---- | C] () -- C:\WINDOWS\System32\cwbunplp.exe
[2012/10/19 09:58:25 | 000,172,032 | ---- | C] () -- C:\WINDOWS\System32\cwbrw.dll
[2012/10/19 09:58:25 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\cwbsv.dll
[2012/10/19 09:58:25 | 000,020,529 | ---- | C] () -- C:\WINDOWS\System32\cwbwiz.dll
[2012/10/19 09:58:25 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\cwbsy.dll
[2012/10/19 09:58:25 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\cwbnl.dll
[2012/10/19 09:58:25 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\cwbnldlg.dll
[2012/10/19 09:58:25 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\cwbad.dll
[2012/10/19 09:58:24 | 000,126,976 | ---- | C] () -- C:\WINDOWS\cwbzip.exe
[2012/10/19 09:58:24 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\cwbco.dll
[2012/10/19 09:52:54 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/18 14:22:49 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/10/18 14:22:49 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\Start Menu\Programs\Internet Explorer.lnk
[2012/10/18 14:22:48 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/10/18 14:22:47 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\Start Menu\Programs\Outlook Express.lnk
[2012/10/18 14:22:46 | 000,006,142 | RHS- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\ntuser.pol
[2012/10/18 14:22:46 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\Start Menu\Programs\Remote Assistance.lnk
[2012/10/18 14:22:46 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\mpurcell.JPENERGY\Start Menu\Programs\Windows Media Player.lnk
[2012/10/18 13:57:20 | 000,000,402 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012/10/18 13:32:16 | 000,000,591 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Utility Center (2).lnk
[2012/10/18 13:14:58 | 000,000,428 | ---- | C] () -- C:\WINDOWS\System32\log4net.config
[2012/10/18 13:14:41 | 000,149,504 | ---- | C] () -- C:\WINDOWS\System32\Unwise32.exe
[2012/10/18 08:24:36 | 000,001,852 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
[2012/10/18 08:24:36 | 000,001,806 | ---- | C] () -- C:\WINDOWS\sql.mif
[2012/10/18 08:23:41 | 000,036,939 | ---- | C] () -- C:\WINDOWS\System32\insrepim.exe
[2012/10/18 08:03:30 | 000,001,416 | ---- | C] () -- C:\WINDOWS\setup.iss
[2012/10/18 07:33:16 | 000,004,376 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
[2012/10/17 15:21:22 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_ST_ACCEL_01009.Wdf
[2012/10/17 15:21:18 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2012/10/17 15:16:56 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\instsrv.exe
[2012/10/17 15:16:56 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\srvany.exe
[2012/10/17 13:53:22 | 000,001,785 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell System Manager.lnk
[2012/10/17 09:17:48 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/10/17 09:17:48 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/10/17 08:29:36 | 001,674,683 | ---- | C] () -- C:\WINDOWS\System32\igxpxa32.cpa
[2012/10/17 08:29:36 | 000,561,128 | ---- | C] () -- C:\WINDOWS\System32\igfcg700m.bin
[2012/10/17 08:29:36 | 000,206,074 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.el-GR.resources
[2012/10/17 08:29:36 | 000,190,306 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.ru-RU.resources
[2012/10/17 08:29:36 | 000,163,151 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.ar-SA.resources
[2012/10/17 08:29:36 | 000,156,020 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.he-IL.resources
[2012/10/17 08:29:36 | 000,146,945 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.it-IT.resources
[2012/10/17 08:29:36 | 000,145,552 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.ko-KR.resources
[2012/10/17 08:29:36 | 000,143,191 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.ro-RO.resources
[2012/10/17 08:29:36 | 000,142,741 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.fr-FR.resources
[2012/10/17 08:29:36 | 000,142,035 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.tr-TR.resources
[2012/10/17 08:29:36 | 000,141,610 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.pt-BR.resources
[2012/10/17 08:29:36 | 000,140,501 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.pt-PT.resources
[2012/10/17 08:29:36 | 000,140,404 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.sv-SE.resources
[2012/10/17 08:29:36 | 000,139,864 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.pl-PL.resources
[2012/10/17 08:29:36 | 000,139,596 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.fi-FI.resources
[2012/10/17 08:29:36 | 000,139,095 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.sk-SK.resources
[2012/10/17 08:29:36 | 000,138,414 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.hr-HR.resources
[2012/10/17 08:29:36 | 000,135,443 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.sl-SI.resources
[2012/10/17 08:29:36 | 000,122,610 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.zh-CN.resources
[2012/10/17 08:29:36 | 000,042,572 | ---- | C] () -- C:\WINDOWS\System32\igxpxs32.vp
[2012/10/17 08:29:36 | 000,009,216 | ---- | C] ( ) -- C:\WINDOWS\System32\IGFXDEVLib.dll
[2012/10/17 08:29:36 | 000,001,023 | ---- | C] () -- C:\WINDOWS\System32\igxpxa32.vp
[2012/10/17 08:29:35 | 000,732,392 | ---- | C] () -- C:\WINDOWS\System32\igkrng700.bin
[2012/10/17 08:29:35 | 000,219,086 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.th-TH.resources
[2012/10/17 08:29:35 | 000,160,288 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.ja-JP.resources
[2012/10/17 08:29:35 | 000,144,621 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.es-ES.resources
[2012/10/17 08:29:35 | 000,144,499 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.de-DE.resources
[2012/10/17 08:29:35 | 000,141,258 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.nl-NL.resources
[2012/10/17 08:29:35 | 000,141,134 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.hu-HU.resources
[2012/10/17 08:29:35 | 000,139,824 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.cs-CZ.resources
[2012/10/17 08:29:35 | 000,135,396 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.nb-NO.resources
[2012/10/17 08:29:35 | 000,134,952 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.da-DK.resources
[2012/10/17 08:29:35 | 000,130,383 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.en-US.resources
[2012/10/17 08:29:35 | 000,124,032 | ---- | C] () -- C:\WINDOWS\System32\Gfxres.zh-TW.resources
[2012/10/17 08:29:35 | 000,058,558 | ---- | C] () -- C:\WINDOWS\System32\igxpxk32.vp
[2012/10/17 08:29:35 | 000,000,255 | ---- | C] () -- C:\WINDOWS\System32\GfxUI.exe.config
[2012/10/17 08:19:48 | 001,011,854 | ---- | C] () -- C:\WINDOWS\System32\oem18.inf
[2012/10/17 08:19:43 | 000,868,352 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2012/10/17 08:19:43 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2012/10/17 08:19:43 | 000,025,088 | ---- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
[2012/10/17 08:19:43 | 000,000,445 | ---- | C] () -- C:\WINDOWS\System32\vcredist_x86.bat
[2012/10/16 15:07:33 | 000,613,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplayer.chm
[2012/10/16 15:07:33 | 000,572,557 | ---- | C] () -- C:\WINDOWS\System32\dllcache\rtuner.wmv
[2012/10/16 15:07:33 | 000,375,519 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nuskin.wmv
[2012/10/16 15:07:33 | 000,354,468 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud1.wav
[2012/10/16 15:07:33 | 000,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud7.wav
[2012/10/16 15:07:33 | 000,343,204 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud6.wav
[2012/10/16 15:07:33 | 000,300,969 | ---- | C] () -- C:\WINDOWS\System32\dllcache\viz.wmv
[2012/10/16 15:07:33 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud9.wav
[2012/10/16 15:07:33 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud8.wav
[2012/10/16 15:07:33 | 000,172,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud3.wav
[2012/10/16 15:07:33 | 000,086,196 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud5.wav
[2012/10/16 15:07:33 | 000,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud4.wav
[2012/10/16 15:07:33 | 000,086,180 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpaud2.wav
[2012/10/16 15:07:33 | 000,077,307 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plyr_err.chm
[2012/10/16 15:07:33 | 000,067,374 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplayer.adm
[2012/10/16 15:07:33 | 000,066,725 | ---- | C] () -- C:\WINDOWS\System32\dllcache\revert.wmz
[2012/10/16 15:07:33 | 000,029,070 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmp.inf
[2012/10/16 15:07:33 | 000,023,829 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tourbg.gif
[2012/10/16 15:07:33 | 000,023,195 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmplay.chm
[2012/10/16 15:07:33 | 000,022,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npds.zip
[2012/10/16 15:07:33 | 000,017,489 | ---- | C] () -- C:\WINDOWS\System32\dllcache\videobg.gif
[2012/10/16 15:07:33 | 000,017,272 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmdm.inf
[2012/10/16 15:07:33 | 000,010,457 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.hta
[2012/10/16 15:07:33 | 000,008,677 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm7.gif
[2012/10/16 15:07:33 | 000,007,892 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm9.gif
[2012/10/16 15:07:33 | 000,007,636 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm2.gif
[2012/10/16 15:07:33 | 000,007,369 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm4.gif
[2012/10/16 15:07:33 | 000,006,769 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmfsdk.inf
[2012/10/16 15:07:33 | 000,006,241 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm3.gif
[2012/10/16 15:07:33 | 000,006,060 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm6.gif
[2012/10/16 15:07:33 | 000,005,789 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm1.gif
[2012/10/16 15:07:33 | 000,005,290 | ---- | C] () -- C:\WINDOWS\System32\dllcache\vidsamp.gif
[2012/10/16 15:07:33 | 000,004,193 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm8.gif
[2012/10/16 15:07:33 | 000,003,187 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tour.js
[2012/10/16 15:07:33 | 000,002,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wm5.gif
[2012/10/16 15:07:33 | 000,002,469 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplay.gif
[2012/10/16 15:07:33 | 000,002,450 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpause.gif
[2012/10/16 15:07:33 | 000,002,375 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tplayh.gif
[2012/10/16 15:07:33 | 000,002,371 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tpauseh.gif
[2012/10/16 15:07:33 | 000,001,771 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmptour.css
[2012/10/16 15:07:33 | 000,001,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst6.wpl
[2012/10/16 15:07:33 | 000,001,477 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst5.wpl
[2012/10/16 15:07:33 | 000,001,474 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst3.wpl
[2012/10/16 15:07:33 | 000,001,451 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst12.wpl
[2012/10/16 15:07:33 | 000,001,448 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst4.wpl
[2012/10/16 15:07:33 | 000,001,398 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taon.gif
[2012/10/16 15:07:33 | 000,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taonh.gif
[2012/10/16 15:07:33 | 000,001,380 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoff.gif
[2012/10/16 15:07:33 | 000,001,367 | ---- | C] () -- C:\WINDOWS\System32\dllcache\taoffh.gif
[2012/10/16 15:07:33 | 000,001,250 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst1.wpl
[2012/10/16 15:07:33 | 000,001,148 | ---- | C] () -- C:\WINDOWS\System32\dllcache\snd.htm
[2012/10/16 15:07:33 | 000,001,049 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst2.wpl
[2012/10/16 15:07:33 | 000,001,046 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst7.wpl
[2012/10/16 15:07:33 | 000,001,036 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst8.wpl
[2012/10/16 15:07:33 | 000,000,908 | ---- | C] () -- C:\WINDOWS\System32\dllcache\skins.inf
[2012/10/16 15:07:33 | 000,000,855 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmpocm.inf
[2012/10/16 15:07:33 | 000,000,789 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst11.wpl
[2012/10/16 15:07:33 | 000,000,787 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst10.wpl
[2012/10/16 15:07:33 | 000,000,784 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst9.wpl
[2012/10/16 15:07:33 | 000,000,783 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst13.wpl
[2012/10/16 15:07:33 | 000,000,775 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst14.wpl
[2012/10/16 15:07:33 | 000,000,733 | ---- | C] () -- C:\WINDOWS\System32\dllcache\plylst15.wpl
[2012/10/16 15:07:33 | 000,000,420 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmploc.js
[2012/10/16 15:07:33 | 000,000,403 | ---- | C] () -- C:\WINDOWS\System32\dllcache\npdrmv2.zip
[2012/10/16 15:07:32 | 000,457,607 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mdlib.wmv
[2012/10/16 15:07:32 | 000,381,425 | ---- | C] () -- C:\WINDOWS\System32\dllcache\copycd.wmv
[2012/10/16 15:07:32 | 000,184,959 | ---- | C] () -- C:\WINDOWS\System32\dllcache\compact.wmz
[2012/10/16 15:07:32 | 000,018,286 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.inf
[2012/10/16 15:07:32 | 000,009,585 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.css
[2012/10/16 15:07:32 | 000,008,298 | ---- | C] () -- C:\WINDOWS\System32\dllcache\contents.htm
[2012/10/16 15:07:32 | 000,006,878 | ---- | C] () -- C:\WINDOWS\System32\dllcache\controls.js
[2012/10/16 15:07:32 | 000,005,971 | ---- | C] () -- C:\WINDOWS\System32\dllcache\events.js
[2012/10/16 15:07:32 | 000,002,778 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogoh.gif
[2012/10/16 15:07:32 | 000,002,545 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplogo.gif
[2012/10/16 15:07:32 | 000,000,999 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bktrh.gif
[2012/10/16 15:07:32 | 000,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnth.gif
[2012/10/16 15:07:32 | 000,000,773 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cnt.gif
[2012/10/16 15:07:32 | 000,000,772 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cntd.gif
[2012/10/16 15:07:32 | 000,000,760 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapph.gif
[2012/10/16 15:07:32 | 000,000,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\cloapp.gif
[2012/10/16 15:06:34 | 000,129,045 | ---- | C] () -- C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2012/10/16 15:06:34 | 000,067,866 | ---- | C] () -- C:\WINDOWS\System32\drivers\netwlan5.img
[2012/10/16 15:06:34 | 000,064,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmc20.cod
[2012/10/16 11:14:34 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/10/16 11:14:34 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/10/16 10:33:16 | 000,001,904 | ---- | C] () -- C:\WINDOWS\System32\SetupBD.din
[2012/10/16 09:34:17 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2012/10/16 09:33:43 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012/10/16 09:33:25 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2012/10/16 09:33:18 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2012/10/16 09:33:14 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2012/10/16 09:33:13 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2012/10/16 09:33:11 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2012/10/16 09:33:04 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2012/10/16 09:33:01 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2012/10/16 09:32:54 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2012/10/16 09:32:19 | 000,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/10/16 09:32:19 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2012/10/16 09:32:19 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2012/10/16 09:32:19 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2012/10/16 09:32:19 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2012/10/16 09:32:18 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2012/10/16 09:32:18 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2012/10/16 09:32:17 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
[2012/10/16 09:31:57 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2012/10/16 09:31:54 | 004,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex
[2012/10/16 09:31:29 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
[2012/10/16 09:31:29 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
[2012/10/16 09:31:23 | 000,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
[2012/10/16 09:30:37 | 000,000,609 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2012/10/16 09:30:36 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012/10/16 09:30:33 | 000,001,986 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk
[2012/10/16 09:30:15 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp
[2012/10/16 09:30:15 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp
[2012/10/16 09:30:15 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp
[2012/10/16 09:30:15 | 000,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp
[2012/10/16 09:30:15 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp
[2012/10/16 09:30:15 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp
[2012/10/16 09:30:15 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp
[2012/10/16 09:30:15 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp
[2012/10/16 09:30:15 | 000,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp
[2012/10/16 09:30:15 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2012/10/16 09:30:15 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp
[2012/10/16 09:30:12 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2012/10/16 09:30:12 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2012/10/16 09:30:11 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2012/10/16 09:30:05 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
[2012/10/16 04:27:21 | 000,001,393 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2012/10/16 04:27:19 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012/10/16 04:27:18 | 001,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2012/10/16 04:27:18 | 000,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2012/10/16 04:27:17 | 000,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2012/10/16 04:27:17 | 000,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2012/10/16 04:27:01 | 000,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2012/10/16 04:26:58 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2012/10/16 04:26:58 | 000,007,710 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2012/10/16 04:26:58 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2012/10/16 04:26:57 | 001,042,903 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP2.CAT
[2012/10/16 04:26:57 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2012/10/16 04:26:57 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2012/10/16 04:26:57 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2012/10/16 04:26:57 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2012/10/16 04:26:24 | 000,330,688 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/10/16 04:25:37 | 000,000,261 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
[2012/10/16 04:25:37 | 000,000,211 | -HS- | C] () -- C:\boot.ini
[2012/06/19 18:48:46 | 000,001,536 | ---- | C] () -- C:\WINDOWS\System32\IusEventLog.dll

========== ZeroAccess Check ==========

[2012/10/17 11:33:34 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2012/08/30 15:29:36 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 07:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 05:42:10 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/10/19 13:17:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/10/22 12:53:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESRI
[2012/10/18 15:04:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GFI Software
[2012/10/16 15:03:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mpurcell\Application Data\BitZipper
[2012/10/30 08:52:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\ESRI
[2012/10/18 15:06:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\GFI Software
[2012/10/19 15:07:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Windows Desktop Search
[2012/10/29 15:11:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\mpurcell.JPENERGY\Application Data\Windows Search

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 05:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2004/08/04 05:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/04 05:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/04 05:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe

< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT /s >
"Type" = 1
"Start" = 1
"ErrorControl" = 1
"Tag" = 6
"ImagePath" = system32\DRIVERS\netbt.sys -- [2008/04/14 00:51:02 | 000,162,816 | ---- | M] (Microsoft Corporation)
"DisplayName" = NetBios over Tcpip
"Group" = PNP_TDI
"DependOnService" = Tcpip [binary data]
"DependOnGroup" = [binary data]
"Description" = NetBios over Tcpip
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Linkage]
"OtherDependencies" = Tcpip [binary data]
"Bind" = \Device\Tcpip_{3E1B4260-3A1C-4B73- [Binary data over 200 bytes]
"Route" = "Tcpip" "{3E1B4260-3A1C-4B73-99A0- [Binary data over 200 bytes]
"Export" = \Device\NetBT_Tcpip_{3E1B4260-3A1C [Binary data over 200 bytes]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters]
"NbProvider" = _tcp
"NameServerPort" = 137
"CacheTimeout" = 600000
"BcastNameQueryCount" = 3
"BcastQueryTimeout" = 750
"NameSrvQueryCount" = 3
"NameSrvQueryTimeout" = 1500
"Size/Small/Medium/Large" = 1
"SessionKeepAlive" = 3600000
"TransportBindName" = \Device\
"EnableLMHOSTS" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces\Tcpip_{2C8517A0-58A3-4486-99F6-61FCA4932D7C}]
"NameServerList" = [binary data]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces\Tcpip_{3E1B4260-3A1C-4B73-99A0-E48047DB47DF}]
"NameServerList" = [binary data]
"NetbiosOptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces\Tcpip_{ABE866BA-F014-4B42-B93D-AA9F98ED3832}]
"NameServerList" = 192.168.32.251 [binary data]
"NetbiosOptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Parameters\Interfaces\Tcpip_{EED08171-1A76-4EF8-8685-5A60941B44FF}]
"NameServerList" = [binary data]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Security]
"Security" = 01 00 14 80 E8 00 00 00 F4 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 B8 00 08 00 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 9D 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 25 02 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 14 00 40 00 00 00 01 01 00 00 00 00 00 05 13 00 00 00 00 00 14 00 40 00 00 00 01 01 00 00 00 00 00 05 14 00 00 00 00 00 18 00 9D 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 2C 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00 [Binary data over 200 bytes]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT\Enum]
"0" = Root\LEGACY_NETBT\0000
"Count" = 1
"NextInstance" = 1

< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS /s >
"Type" = 2
"Start" = 1
"ErrorControl" = 1
"Tag" = 1
"ImagePath" = system32\DRIVERS\netbios.sys -- [2008/04/14 00:26:04 | 000,034,688 | ---- | M] (Microsoft Corporation)
"DisplayName" = NetBIOS Interface
"Group" = NetBIOSGroup
"Description" = NetBIOS Interface
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage]
"LanaMap" = 01 03 01 00 00 01 00 02 [binary data]
"Bind" = \Device\NetBT_Tcpip_{3E1B4260-3A1C [Binary data over 200 bytes]
"Route" = "NetBT" "Tcpip" "{3E1B4260-3A1C-4B [Binary data over 200 bytes]
"Export" = \Device\NetBIOS_NetBT_Tcpip_{3E1B4 [Binary data over 200 bytes]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS\Parameters]
"MaxLana" = 3
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS\Parameters\Winsock]
"HelperDllName" = %SystemRoot%\System32\wshnetbs.dll -- [2004/08/04 05:00:00 | 000,007,168 | ---- | M] (Microsoft Corporation)
"MaxSockAddrLength" = 20
"MinSockAddrLength" = 20
"Mapping" = 02 00 00 00 03 00 00 00 11 00 00 00 05 00 00 00 00 00 00 00 11 00 00 00 02 00 00 00 00 00 00 00 [binary data]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS\Security]
"Security" = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00 [Binary data over 200 bytes]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS\Enum]
"0" = Root\LEGACY_NETBIOS\0000
"Count" = 1
"NextInstance" = 1

< C:\Windows\assembly\tmp\U\*.* /s >
[2012/10/16 09:31:18 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2012/10/16 09:34:32 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2012/10/19 10:52:40 | 000,000,830 | ---- | C] () -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012/10/19 13:16:32 | 000,000,284 | ---- | C] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2012/10/30 08:20:14 | 000,000,886 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2012/10/30 08:20:14 | 000,000,890 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

< %Temp%\smtmp\1\*.* >

< %Temp%\smtmp\2\*.* >

< %Temp%\smtmp\3\*.* >

< %Temp%\smtmp\4\*.* >

< End of report >

Attached Files


  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi what symptoms are you experiencing ?

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Posted Image
:OTL
SRV - File not found [Auto | Stopped] -- C:\WINDOWS\system32\bgftmig.dll -- (vzmqsznt)
SRV - File not found [Auto | Unknown] -- C:\WINDOWS\system32\bgftmig.dll -- (gvjzlm)
O4 - HKLM..\Run: [pynnrocxv] rundll32.exe "C:\WINDOWS\system32\bgftmig.dll",rredlmb File not found
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_06)

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

  • 0

#3
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP