Juliejules | 07.02.2011 12:29 | Hier der erste log von OTL:OTL Logfile: Code:
OTL logfile created on: 2/7/2011 12:25:36 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = D:\Documents and Settings\tiemajui\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 55.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 2962 2962 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 57.14 Gb Free Space | 76.67% Space Free | Partition Type: NTFS
Drive D: | 74.52 Gb Total Space | 66.32 Gb Free Space | 89.00% Space Free | Partition Type: NTFS
Drive H: | 3.00 Gb Total Space | 2.89 Gb Free Space | 96.33% Space Free | Partition Type: NTFS
Drive W: | 599.99 Gb Total Space | 255.02 Gb Free Space | 42.50% Space Free | Partition Type: NTFS
Computer Name: DEHER1N1755 | User Name: tiemajui | NOT logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - D:\Documents and Settings\tiemajui\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Documents and Settings\tiemajui\Application Data\webex\ptsrv.exe (Cisco WebEx LLC)
PRC - D:\Documents and Settings\tiemajui\Application Data\webex\ptoneclk.exe (Cisco WebEx LLC)
PRC - W:\APP_ADI\sim\sim.exe ()
PRC - C:\Program Files\Altiris\Altiris Agent\AeXAgentUIHost.exe (Altiris, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)
PRC - C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe (Lenovo Group Limited)
PRC - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\SAP\FrontEnd\SAPgui\saplogon.exe (SAP AG, Walldorf)
PRC - C:\WINDOWS\system32\TpShocks.exe (Lenovo.)
PRC - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel(R) Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
PRC - C:\Program Files\eRoom 7\ERClient7.exe (EMC)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\McTray.exe (McAfee, Inc.)
PRC - C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Lenovo Group Limited)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Microsoft Office Communicator\communicator.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - D:\Documents and Settings\tiemajui\Local Settings\Temp\LogonApp.exe (Websense)
========== Modules (SafeList) ==========
MOD - D:\Documents and Settings\tiemajui\Desktop\OTL.exe (OldTimer Tools)
MOD - D:\Documents and Settings\tiemajui\Local Settings\Temp\regoute.dll ()
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\AMInit32.dll (Altiris, Inc.)
MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.)
MOD - C:\WINDOWS\system32\NetProvCredMan.dll (Intel(R) Corporation)
MOD - C:\WINDOWS\system32\netui1.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\netui0.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\ntlanman.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\netrap.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\drprov.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\davclnt.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
========== Driver Services (SafeList) ==========
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://intranet
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Ggl, = hxxp://www.google.com/search?q=%s
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = hxxp://10.129.10.50/herzo.pac
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "hxxp://128.1.2.29/"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: ocplugin@webex.com:1.1
FF - prefs.js..network.proxy.autoconfig_url: "hxxp://10.129.10.50/herzo.pac"
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"
FF - prefs.js..network.proxy.type: 2
[2010/07/12 09:10:37 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\tiemajui\Application Data\Mozilla\Extensions
[2011/02/04 10:53:46 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\tiemajui\Application Data\Mozilla\Firefox\Profiles\4166a530.default\extensions
[2010/08/27 11:00:08 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- D:\Documents and Settings\tiemajui\Application Data\Mozilla\Firefox\Profiles\4166a530.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/05 08:11:23 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/02/07 10:47:47 | 000,000,000 | ---D | M] (ocplugin) -- D:\DOCUMENTS AND SETTINGS\TIEMAJUI\APPLICATION DATA\WEBEX
O1 HOSTS File: ([2008/09/10 10:39:00 | 000,000,755 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 10.127.106.9 hesv1218
O2 - BHO: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - D:\Documents and Settings\tiemajui\Application Data\webex\ptonecli.dll (Cisco WebEx LLC)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - D:\Documents and Settings\tiemajui\Application Data\webex\ptonecli.dll (Cisco WebEx LLC)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdiPowerConfig] C:\WINDOWS\System32\Powerset.lnk ()
O4 - HKLM..\Run: [AeXAgentLogon] C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe (Altiris, Inc.)
O4 - HKLM..\Run: [BLOG] C:\Program Files\ThinkPad\Utilities\BATLOGEX.DLL ()
O4 - HKLM..\Run: [Communicator] C:\Program Files\Microsoft Office Communicator\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [FingerPrintSoftware] C:\Program Files\Lenovo Fingerprint Software\fpapp.exe (Authentec,Inc)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel(R) Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PWRMGRTR] C:\Program Files\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [QPMEnroll] C:\WINDOWS\system32\QPMEnroll.exe (Quest Software, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TpShocks] C:\WINDOWS\System32\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [tsnp2uvc] File not found
O4 - HKCU..\Run: [asr_ntfs] D:\Documents and Settings\tiemajui\Local Settings\Temp\regoute.dll ()
O4 - HKCU..\Run: [PTOneClick] D:\Documents and Settings\tiemajui\Application Data\webex\ptoneclk.exe (Cisco WebEx LLC)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\RunOnce: [Shockwave Updater] File not found
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk = C:\WINDOWS\Installer\{51FB15F4-AD27-43BC-AD4B-DD0354FB6BBD}\Icon3E5562ED7.ico ()
O4 - Startup: D:\Documents and Settings\tiemajui\Start Menu\Programs\Startup\Monitor My eRooms (V7).lnk = C:\Program Files\eRoom 7\ERClient7.exe (EMC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Recovery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Safety present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\SQM present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutorun = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMSAppLogo5ChannelNotify = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Suggested Sites present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinters = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogOff = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoManageMyComputerVerb = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeAnimation = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDFSTab = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ConfirmFileDelete = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Intellimenus = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: GreyMSIAds = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMyMusic = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowCpl = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 1 = nusrmgr.cpl (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O15 - HKCU\..Trusted Domains: adidas.com ([cm] * in Trusted sites)
O15 - HKCU\..Trusted Domains: adidas.de ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: adidas.de ([evault] * in Local intranet)
O15 - HKCU\..Trusted Domains: adidas.de ([hesv1138] * in Local intranet)
O15 - HKCU\..Trusted Domains: adsint.biz ([hesv1138.emea] * in Local intranet)
O15 - HKCU\..Trusted Domains: evault ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: hesv1138 ([]* in Local intranet)
O16 - DPF: {4A3CBDDD-C4DC-4C38-B44F-704DAEF628AE} hxxp://cm.adidas.com/projectserver/objects/pjclient.cab (PjAdoInfo3 Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1240391599140 (WUWebControl Class)
O16 - DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} Reg Error: Key error. (ERPageAddin Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1257259888629 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {AF9A1421-E128-4D5F-A37E-039F305867B9} hxxp://cm.adidas.com/projectserver/objects/1033/pjcintl.cab (Pj11enuC Class)
O16 - DPF: {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_14-windows-i586.cab (Java Plug-in 1.5.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.126.193.47 10.127.1.185
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = emea.adsint.biz
O18 - Protocol\Handler\saphtmlp {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP AG, Walldorf)
O18 - Protocol\Handler\sapr3 {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\Program Files\SAP\FrontEnd\SAPgui\SAPHTMLP.DLL (SAP AG, Walldorf)
O20 - AppInit_DLLs: (AMINIT32.dll) - C:\WINDOWS\System32\AMInit32.dll (Altiris, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (ATGinaHook.dll) - C:\WINDOWS\System32\ATGinaHook.dll (AuthenTec, Inc.)
O20 - Winlogon\Notify\ATFUS: DllName - C:\WINDOWS\system32\FpWinLogonNp.dll - C:\WINDOWS\system32\FpWinlogonNp.dll (AuthenTec,Inc)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\tpfnf2: DllName - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll - C:\Program Files\Lenovo\HOTKEY\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - C:\Program Files\Lenovo\HOTKEY\tphklock.dll - C:\Program Files\Lenovo\HOTKEY\tphklock.dll (Lenovo Group Limited)
O24 - Desktop WallPaper: D:\Documents and Settings\tiemajui\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\tiemajui\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/04/30 08:13:35 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/02/07 09:11:12 | 000,602,624 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\tiemajui\Desktop\OTL.exe
[2011/02/04 14:25:26 | 000,000,000 | ---D | C] -- D:\Documents and Settings\tiemajui\Application Data\Malwarebytes
[2011/02/04 13:33:58 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/04 13:33:58 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/04 13:33:56 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/04 13:33:53 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/02/04 13:33:52 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/04 13:32:55 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- D:\Documents and Settings\tiemajui\Desktop\mbam-setup-1.50.1.1100.exe
[2011/02/02 13:57:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2011/01/31 15:34:54 | 000,000,000 | ---D | C] -- D:\Documents and Settings\tiemajui\Local Settings\Application Data\AskToolbar
[2011/01/31 15:32:58 | 000,000,000 | ---D | C] -- C:\Program Files\Ask.com
[2011/01/31 15:32:51 | 000,000,000 | ---D | C] -- C:\Program Files\PicPick
[2011/01/31 15:29:23 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Start Menu\Programs\miTeam
[2011/01/31 15:29:01 | 000,000,000 | ---D | C] -- C:\miTeam
[2011/01/14 14:38:00 | 000,000,000 | ---D | C] -- D:\Documents and Settings\tiemajui\Start Menu\Programs\WebEx
[2010/10/12 09:18:02 | 003,145,728 | ---- | C] (SAP Technology,Inc) -- C:\Program Files\Common Files\sapxlhelper.dll
[2010/10/12 09:18:02 | 000,192,512 | ---- | C] (SAP Tech Inc.) -- C:\Program Files\Common Files\sapconsr3.dll
[2010/10/12 09:18:01 | 000,626,688 | ---- | C] (SAP AG) -- C:\Program Files\Common Files\sapconsaccess.dll
[2010/10/12 09:18:01 | 000,040,960 | ---- | C] (SAP-TECHNOLOGY) -- C:\Program Files\Common Files\DigitalSignature.ocx
[2010/02/09 14:23:16 | 000,176,128 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc.dll
[2009/04/22 10:42:34 | 000,225,280 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnp2uvc.dll
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/02/07 12:01:00 | 000,000,240 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/02/07 09:42:54 | 000,146,432 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\MT_country_onboarding_milestones.xls
[2011/02/07 09:29:05 | 000,057,344 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\DHL Paket Claim Process.doc
[2011/02/07 09:18:16 | 000,001,024 | ---- | M] () -- C:\.rnd
[2011/02/07 09:18:10 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/02/07 09:11:20 | 000,602,624 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\tiemajui\Desktop\OTL.exe
[2011/02/07 08:24:42 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/02/04 16:04:50 | 000,002,377 | ---- | M] () -- D:\Documents and Settings\tiemajui\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2003.lnk
[2011/02/04 16:00:43 | 000,033,280 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\contact list mi Team expansion.xls
[2011/02/04 15:53:44 | 000,015,872 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\Next steps mi Team expansion.xls
[2011/02/04 13:33:59 | 000,000,676 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/04 13:32:56 | 007,734,208 | ---- | M] (Malwarebytes Corporation ) -- D:\Documents and Settings\tiemajui\Desktop\mbam-setup-1.50.1.1100.exe
[2011/02/04 08:24:09 | 000,445,238 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/02/04 08:24:09 | 000,072,756 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/02/03 14:55:50 | 002,003,968 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\miTeam expansion.ppt
[2011/02/03 08:18:25 | 000,011,688 | RHS- | M] () -- D:\Documents and Settings\tiemajui\ntuser.pol
[2011/02/02 13:20:57 | 000,348,672 | ---- | M] () -- D:\Documents and Settings\tiemajui\My Documents\weekly call 2_4.ppt
[2011/02/02 12:58:47 | 000,002,359 | ---- | M] () -- D:\Documents and Settings\tiemajui\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office PowerPoint 2003.lnk
[2011/02/02 08:48:30 | 000,025,600 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\contact list mi Team expansion AU NZ.xls
[2011/02/02 08:23:15 | 000,002,317 | ---- | M] () -- D:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
[2011/02/02 08:20:35 | 000,000,306 | ---- | M] () -- C:\WINDOWS\tasks\PMTask.job
[2011/02/01 13:41:47 | 000,815,616 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\Weekly Progess Update template.ppt
[2011/02/01 09:51:49 | 000,002,375 | ---- | M] () -- D:\Documents and Settings\tiemajui\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2011/01/31 16:30:26 | 000,176,128 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\Contacts mi adidas.ppt
[2011/01/31 15:29:24 | 000,000,453 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Toolkit.lnk
[2011/01/27 11:31:43 | 000,152,064 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\miadidas_SOP_miteam order in a non mi adidas.doc
[2011/01/25 15:56:02 | 000,023,552 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\contact list mi Team expansion_Russia.xls
[2011/01/25 11:35:31 | 001,067,008 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\SOP DHL.doc
[2011/01/24 10:31:48 | 001,441,792 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\DHL_trial.xls
[2011/01/24 10:31:31 | 003,644,416 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\Template.xls
[2011/01/24 08:15:25 | 000,000,002 | ---- | M] () -- D:\Documents and Settings\tiemajui\CL_Part2_Done_tiemajui.flg
[2011/01/24 08:13:23 | 000,000,002 | ---- | M] () -- D:\Documents and Settings\tiemajui\CL_Part1_Done_tiemajui.flg
[2011/01/19 16:13:31 | 000,041,472 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\DHL claim form.doc
[2011/01/14 16:25:33 | 012,500,992 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\FW_FedEx2010.xls
[2011/01/14 16:16:05 | 000,046,592 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\DEC 2010 results FW.xls
[2011/01/14 14:38:00 | 000,001,924 | ---- | M] () -- D:\Documents and Settings\tiemajui\Desktop\WebEx One-Click.lnk
[2011/01/13 08:15:10 | 000,350,616 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/12 11:12:29 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/02/07 09:18:15 | 000,001,024 | ---- | C] () -- C:\.rnd
[2011/02/04 15:53:44 | 000,015,872 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\Next steps mi Team expansion.xls
[2011/02/04 13:33:59 | 000,000,676 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/02 13:20:57 | 000,348,672 | ---- | C] () -- D:\Documents and Settings\tiemajui\My Documents\weekly call 2_4.ppt
[2011/02/02 08:48:30 | 000,025,600 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\contact list mi Team expansion AU NZ.xls
[2011/02/01 15:54:04 | 000,146,432 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\MT_country_onboarding_milestones.xls
[2011/02/01 13:41:47 | 000,815,616 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\Weekly Progess Update template.ppt
[2011/02/01 10:40:01 | 000,057,344 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\DHL Paket Claim Process.doc
[2011/01/31 15:33:01 | 000,000,240 | ---- | C] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/01/31 15:29:24 | 000,000,453 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Toolkit.lnk
[2011/01/27 11:31:43 | 000,152,064 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\miadidas_SOP_miteam order in a non mi adidas.doc
[2011/01/25 16:20:57 | 001,067,008 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\SOP DHL.doc
[2011/01/25 15:56:02 | 000,023,552 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\contact list mi Team expansion_Russia.xls
[2011/01/24 10:31:48 | 001,441,792 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\DHL_trial.xls
[2011/01/24 09:07:28 | 012,500,992 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\FW_FedEx2010.xls
[2011/01/24 09:07:23 | 030,732,288 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\FW_DHL2010.xls
[2011/01/24 09:07:23 | 000,046,592 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\DEC 2010 results FW.xls
[2011/01/24 09:06:46 | 003,644,416 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\Template.xls
[2011/01/24 08:15:25 | 000,000,002 | ---- | C] () -- D:\Documents and Settings\tiemajui\CL_Part2_Done_tiemajui.flg
[2011/01/24 08:13:23 | 000,000,002 | ---- | C] () -- D:\Documents and Settings\tiemajui\CL_Part1_Done_tiemajui.flg
[2011/01/19 16:13:31 | 000,041,472 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\DHL claim form.doc
[2011/01/17 14:08:40 | 002,003,968 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\miTeam expansion.ppt
[2011/01/14 14:38:00 | 000,001,924 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\WebEx One-Click.lnk
[2011/01/14 14:27:39 | 000,033,280 | ---- | C] () -- D:\Documents and Settings\tiemajui\Desktop\contact list mi Team expansion.xls
[2010/10/12 09:18:01 | 000,955,904 | ---- | C] () -- C:\Program Files\Common Files\SAPActiveXL.xlt
[2010/10/12 09:18:01 | 000,949,760 | ---- | C] () -- C:\Program Files\Common Files\SAPActiveXL_nosig.xlt
[2010/10/12 09:16:05 | 000,051,200 | ---- | C] () -- C:\WINDOWS\System32\h5tool32.dll
[2010/10/12 09:16:04 | 001,064,960 | ---- | C] () -- C:\WINDOWS\System32\h5krnl32.dll
[2010/10/12 09:16:04 | 000,188,928 | ---- | C] () -- C:\WINDOWS\System32\h5icon32.dll
[2010/10/12 09:16:04 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\h5menu32.dll
[2010/10/12 09:16:04 | 000,095,744 | ---- | C] () -- C:\WINDOWS\System32\h5rtf32.dll
[2010/10/06 07:57:51 | 000,022,990 | ---- | C] () -- C:\WINDOWS\sapLogon.ini
[2010/09/08 13:05:44 | 000,000,664 | ---- | C] () -- D:\Documents and Settings\tiemajui\Local Settings\Application Data\d3d9caps.dat
[2010/07/08 10:41:36 | 000,003,584 | ---- | C] () -- D:\Documents and Settings\tiemajui\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/07 14:10:10 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2010/05/31 08:52:24 | 000,024,596 | ---- | C] () -- D:\Documents and Settings\tiemajui\Application Data\ItDb.enc.bak
[2010/05/31 08:52:24 | 000,000,048 | ---- | C] () -- D:\Documents and Settings\tiemajui\Application Data\ItDb.enc
[2010/02/09 14:31:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\client.INI
[2010/02/09 14:25:51 | 004,184,169 | ---- | C] () -- C:\WINDOWS\System32\GCITA.dll
[2010/02/09 14:23:16 | 001,754,368 | ---- | C] () -- C:\WINDOWS\System32\drivers\snp2uvc.sys
[2010/02/09 14:23:16 | 000,028,800 | ---- | C] () -- C:\WINDOWS\System32\drivers\sncduvc.sys
[2010/02/09 14:23:16 | 000,015,497 | ---- | C] () -- C:\WINDOWS\snp2uvc.ini
[2009/07/08 12:49:38 | 002,854,976 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2009/04/22 10:52:20 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v5002.dll
[2009/04/21 23:06:27 | 000,000,000 | ---- | C] () -- C:\WINDOWS\dsedit.INI
[2008/11/24 16:25:16 | 000,147,456 | R--- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4990.dll
[2008/10/23 14:47:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2008/10/23 10:43:24 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/10/23 10:43:24 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/10/23 09:35:35 | 000,000,737 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/10/23 09:24:39 | 000,001,747 | ---- | C] () -- C:\WINDOWS\SAPMSG.INI
[2008/10/23 09:21:40 | 000,015,872 | ---- | C] () -- C:\WINDOWS\System32\vtssm32.dll
[2008/10/22 13:47:40 | 000,000,482 | ---- | C] () -- C:\WINDOWS\System32\profil.ini
[2008/10/22 13:47:39 | 000,000,047 | ---- | C] () -- C:\WINDOWS\System32\grantACL.ini
[2008/10/20 14:46:35 | 000,002,401 | ---- | C] () -- C:\WINDOWS\System32\drivers\AlKernel.sys
[2008/10/20 14:22:39 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/10/20 14:19:27 | 000,004,442 | ---- | C] () -- C:\WINDOWS\System32\drivers\TPPWRIF.SYS
[2008/10/20 14:16:52 | 000,056,056 | ---- | C] () -- C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/10/20 14:16:52 | 000,000,120 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/10/20 14:13:59 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2008/10/20 14:13:59 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2008/10/20 14:13:59 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2008/10/20 14:13:59 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2008/10/20 14:13:59 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2008/10/20 14:13:59 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2008/10/20 14:10:21 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4957.dll
[2008/10/20 14:07:42 | 000,004,608 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSMAPIP.SYS
[2008/08/29 21:58:26 | 000,197,408 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll
[2008/08/29 21:58:16 | 000,193,312 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2006/04/30 08:31:51 | 000,000,600 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/04/30 08:22:10 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006/04/30 01:04:28 | 000,004,346 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/11/15 14:32:22 | 000,003,638 | R--- | C] () -- C:\Program Files\Common Files\Altiris_Icon.ico
[2003/01/07 23:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 12:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[1998/06/08 08:00:00 | 000,039,936 | ---- | C] () -- C:\WINDOWS\System32\GETUSER.DLL
[1998/06/01 08:00:00 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1998/06/01 08:00:00 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
[1997/08/01 00:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL
< End of report > --- --- --- |