Jump to content

Cannot find/remove MyWebSearch


Recommended Posts

Hello,

I have a system that is being blocked by our proxy for having MyWebSearch on the system. To date I have been unable to fix this issue. Here is a HJT log from this machine..maybe I am overlooking something. It also passed an updated MBAM scan without any detections.

Thanks...

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 2:27:39 PM, on 8/17/2011

Platform: Unknown Windows (WinNT 6.01.3504)

MSIE: Internet Explorer v8.00 (8.00.7600.16800)

Boot mode: Normal

Running processes:

C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe

C:\Program Files\Lenovo\Zoom\TpScrex.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Citrix\ICA Client\concentr.exe

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe

C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe

C:\Program Files\Cisco\Cisco NAC Agent\NACAgentUI.exe

C:\Windows\System32\TpShocks.exe

C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe

C:\Program Files\Microsoft IntelliType Pro\itype.exe

C:\Program Files\Iron Mountain\Connected BackupPC\Agent.exe

C:\Program Files\McAfee\Common Framework\UdaterUI.exe

C:\Program Files\Microsoft IntelliPoint\ipoint.exe

C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\McAfee\Common Framework\McTray.exe

C:\PROGRA~1\ThinkPad\UTILIT~1\SCHTASK.exe

C:\notes\NLNOTES.EXE

C:\notes\framework\rcp\eclipse\plugins\com.ibm.rcp.base_6.2.1.20090925-1604\win32\x86\notes2.exe

C:\notes\ntaskldr.EXE

C:\Program Files\Microsoft Office\Office12\EXCEL.EXE

C:\Program Files\Microsoft Office\Office12\WINWORD.EXE

C:\Program Files\Microsoft Office\Office12\WINWORD.EXE

C:\Windows\system32\cmd.exe

C:\Windows\system32\conhost.exe

C:\Windows\System32\rdpclip.exe

C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe

C:\Windows\system32\taskhost.exe

C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe

C:\Windows\system32\Dwm.exe

C:\Program Files\Lenovo\Zoom\TpScrex.exe

C:\Windows\Explorer.EXE

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Citrix\ICA Client\concentr.exe

C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe

C:\Program Files\Citrix\ICA Client\wfcrun32.exe

C:\Windows\System32\TpShocks.exe

C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe

C:\Windows\System32\rundll32.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\Microsoft IntelliType Pro\itype.exe

C:\Program Files\Iron Mountain\Connected BackupPC\Agent.exe

C:\Program Files\Microsoft IntelliPoint\ipoint.exe

C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe

C:\PROGRA~1\ThinkPad\UTILIT~1\SCHTASK.exe

C:\Windows\system32\igfxext.exe

C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

C:\Program Files\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe

C:\Windows\system32\SearchFilterHost.exe

C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Liquid Machines Browser Helper Object - {04DC8126-476E-48b9-8202-59A4E90124CD} - C:\Program Files\Liquid Machines\Client\LmFFBHO.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll

O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll

O2 - BHO: ZeonIEEventHelper Class - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: Nuance PDF - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll

O4 - HKLM\..\Run: [synTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [synTPLpr] \Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup

O4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE

O4 - HKLM\..\Run: [McAfee Host Intrusion Prevention Tray] "C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe"

O4 - HKLM\..\Run: [PDFHook] C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe

O4 - HKLM\..\Run: [PDF6 Registry Controller] C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe

O4 - HKLM\..\Run: [NACAgentUI] C:\Program Files\Cisco\Cisco NAC Agent\NACAgentUI.exe

O4 - HKLM\..\Run: [iME JPN 2007 Migration] C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEJP\IMJPKLMG.EXE /Preload

O4 - HKLM\..\Run: [TpShocks] TpShocks.exe

O4 - HKLM\..\Run: [iMSS] "C:\Program Files\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe"

O4 - HKLM\..\Run: [RotateImage] C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [smartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t

O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor

O4 - HKLM\..\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe

O4 - HKLM\..\Run: [WatcherHelper] "C:\Program Files\Sierra Wireless Inc\Watcher\WaHelper.exe"

O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"

O4 - HKLM\..\Run: [AgentUiRunKey] "C:\Program Files\Iron Mountain\Connected BackupPC\Agent.exe" -ni -sss -e http://localhost:16386/

O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey

O4 - HKLM\..\Run: [intelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-21-790525478-688789844-854245398-10585\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - Global Startup: VPN Client.lnk = ?

O8 - Extra context menu item: Append the content of the link to existing PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML

O8 - Extra context menu item: Append the content of the selected links to existing PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML

O8 - Extra context menu item: Append to existing PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML

O8 - Extra context menu item: Create PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML

O8 - Extra context menu item: Create PDF file from the content of the link - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML

O8 - Extra context menu item: Create PDF files from the selected links - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML

O8 - Extra context menu item: Open with Nuance PDF Converter 6.0 - res://C:\Program Files\Nuance\PDF Professional 6\cnvres_eng.dll /100

O8 - Extra context menu item: Open with PDF Professional 6 - res://C:\Program Files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O13 - Gopher Prefix:

O16 - DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} (Cisco AnyConnect VPN Client Web Control)

O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = xxxxx.com

O17 - HKLM\Software\..\Telephony: DomainName = xxxxx.com

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = xxxxx.com

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = xxxxx.com

O20 - AppInit_DLLs: C:\PROGRA~1\LIQUID~1\Client\LMBUND~1.DLL

O23 - Service: AgentService - Iron Mountain Incorporated - C:\Program Files\Iron Mountain\Connected BackupPC\AgentService.exe

O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

O23 - Service: Lenovo Doze Mode Service (DozeSvc) - Lenovo. - C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE

O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe

O23 - Service: McAfee Host Intrusion Prevention Service (enterceptAgent) - McAfee, Inc. - C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe

O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe

O23 - Service: McAfee HIPSCore Service (hips) - McAfee, Inc. - C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe

O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo. - C:\Windows\system32\ibmpmsvc.exe

O23 - Service: iPassConnectEngine - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe

O23 - Service: iPassPeriodicUpdateApp - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe

O23 - Service: iPassPeriodicUpdateService - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe

O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe

O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe

O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe

O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe

O23 - Service: Liquid Machines Client Service (LmGuardSvc) - Liquid Machines, Inc. - C:\Program Files\Liquid Machines\Client\lmguardsvc32.exe

O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe

O23 - Service: Lotus Notes Diagnostics - IBM - C:\notes\nsd.exe

O23 - Service: Lotus Notes Single Logon - IBM Corp - C:\notes\nslsvice.exe

O23 - Service: McAfee Engine Service (McAfeeEngineService) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe

O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe

O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe

O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe

O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Windows\system32\mfevtps.exe

O23 - Service: Cisco NAC Agent (NACAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco\Cisco NAC Agent\NACAgent.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: PDFProFiltSrv - Nuance Communications, Inc. - C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe

O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE

O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe

O23 - Service: Track-It! Remote Control (TIRmtCtl) - Intuit Track-It! - C:\WINDOWS\TIREMOTE\wuser32.exe

O23 - Service: Track-It! Workstation Manager (TIRmtSvc) - Numara Software, Inc. - C:\WINDOWS\TIREMOTE\TIRemoteService.exe

O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\Windows\System32\TPHDEXLG.exe

O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe

O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe

O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe

O23 - Service: Cisco AnyConnect VPN Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe

--

End of file - 14608 bytes

Link to post
Share on other sites
  • Staff

Hi and welcome to Malwarebytes.

Please update MBAM, run a Quick Scan, and post its log.

Next, download DDS by sUBs and save it to your Desktop.

Double-click on the DDS icon and let the scan run. When it has run two logs will be produced, please post only DDS.txt directly into your reply.

Link to post
Share on other sites

hi,

thank you for the response. this is a remote machine and i am in the process of obtaining the requested logs. please leave this thread open and i will update when i have them.

hi, thanks i was able to get the log files. here they are:

mbam log:

Malwarebytes' Anti-Malware (tech) 1.50.1.1100

www.malwarebytes.org

Database version: 7556

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

8/24/2011 1:31:06 PM

mbam-log-2011-08-24 (13-31-06).txt

Scan type: Quick scan

Objects scanned: 268305

Time elapsed: 2 minute(s), 46 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

DDS.txt

.

DDS (Ver_2011-06-23.01) - NTFSx86

Internet Explorer: 8.0.7600.16385

Run by user at 13:33:19 on 2011-08-24

Microsoft Windows 7 Enterprise 6.1.7600.0.1252.1.1033.18.2996.1157 [GMT -6:00]

.

AV: McAfee VirusScan Enterprise *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: McAfee VirusScan Enterprise Antispyware Module *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}

FW: McAfee Host Intrusion Prevention Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\ibmpmsvc.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\system32\WLANExt.exe

C:\Windows\system32\conhost.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\System32\svchost.exe -k NetworkService

C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe

C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe

C:\Program Files\Iron Mountain\Connected BackupPC\AgentService.exe

C:\PROGRA~1\Lenovo\HOTKEY\tpnumlk.exe

C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

C:\Program Files\Juniper Networks\Common Files\dsNcService.exe

C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe

C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe

C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe

C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe

C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe

C:\notes\nsd.exe

C:\notes\nslsvice.exe

C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe

C:\Program Files\McAfee\Common Framework\FrameworkService.exe

C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

C:\Windows\system32\mfevtps.exe

C:\Program Files\Cisco\Cisco NAC Agent\NACAgent.exe

C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe

C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\WINDOWS\TIREMOTE\wuser32.exe

C:\WINDOWS\TIREMOTE\TIRemoteService.exe

C:\Program Files\Liquid Machines\Client\lmguardsvc32.exe

C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe

C:\Windows\system32\CCM\CcmExec.exe

C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe

C:\Windows\system32\conhost.exe

C:\Program Files\Intel\WiFi\bin\EvtEng.exe

C:\Program Files\Liquid Machines\Client\lmdci.exe

C:\Program Files\McAfee\Common Framework\naPrdMgr.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\UI0Detect.exe

C:\Windows\system32\svchost.exe -k bthsvcs

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\taskhost.exe

C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe

C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe

C:\Windows\system32\Dwm.exe

C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe

C:\Windows\Explorer.EXE

C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe

C:\Program Files\Lenovo\Zoom\TpScrex.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Citrix\ICA Client\concentr.exe

C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe

C:\Program Files\Citrix\ICA Client\wfcrun32.exe

C:\Program Files\Cisco\Cisco NAC Agent\NACAgentUI.exe

C:\Windows\System32\TpShocks.exe

C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Windows\system32\igfxsrvc.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe

C:\Program Files\Microsoft IntelliType Pro\itype.exe

C:\Program Files\Iron Mountain\Connected BackupPC\Agent.exe

C:\Program Files\McAfee\Common Framework\UdaterUI.exe

C:\Program Files\Microsoft IntelliPoint\ipoint.exe

C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

C:\Program Files\McAfee\Common Framework\McTray.exe

C:\Windows\system32\SearchIndexer.exe

C:\PROGRA~1\ThinkPad\UTILIT~1\SCHTASK.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\igfxext.exe

C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe

C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe

C:\Program Files\Lenovo\System Update\SUService.exe

C:\Windows\system32\UI0Detect.exe

C:\Program Files\Cisco Systems\VPN Client\vpngui.exe

C:\notes\NLNOTES.EXE

C:\notes\framework\rcp\eclipse\plugins\com.ibm.rcp.base_6.2.1.20090925-1604\win32\x86\notes2.exe

C:\notes\ntaskldr.EXE

C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE

C:\Windows\system32\RCAgent.exe

C:\Program Files\McAfee\VirusScan Enterprise\mcconsol.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\wbem\wmiprvse.exe

.

============== Pseudo HJT Report ===============

.

uSearch Bar = Preserve

uStart Page = hxxp://www.google.com/

uDefault_Page_URL = hxxp://www.google.com

mDefault_Page_URL = hxxp://www.google.com

mStart Page = hxxp://www.google.com

uInternet Settings,ProxyOverride = <local>

BHO: Liquid Machines Browser Helper Object: {04dc8126-476e-48b9-8202-59a4e90124cd} - c:\program files\liquid machines\client\LmFFBHO.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: PlusIEEventHelper Class: {551a852f-39a6-44a7-9c13-afbec9185a9d} - c:\program files\nuance\pdf professional 6\bin\PlusIEContextMenu.dll

BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptsn.dll

BHO: ZeonIEEventHelper Class: {da986d7d-ccaf-47b2-84fe-bfa1549bebf9} - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

uRun: [skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized

mRun: [synTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

mRun: [synTPLpr] \Synaptics\SynTP\SynTPLpr.exe

mRun: [nwiz] nwiz.exe /installquiet

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [ConnectionCenter] "c:\program files\citrix\ica client\concentr.exe" /startup

mRun: [shStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE

mRun: [McAfee Host Intrusion Prevention Tray] "c:\program files\mcafee\host intrusion prevention\FireTray.exe"

mRun: [PDFHook] c:\program files\nuance\pdf professional 6\pdfpro6hook.exe

mRun: [PDF6 Registry Controller] c:\program files\nuance\pdf professional 6\RegistryController.exe

mRun: [NACAgentUI] c:\program files\cisco\cisco nac agent\NACAgentUI.exe

mRun: [iME JPN 2007 Migration] c:\progra~1\common~1\micros~1\ime12\imejp\IMJPKLMG.EXE /Preload

mRun: [<NO NAME>]

mRun: [TpShocks] TpShocks.exe

mRun: [iMSS] "c:\program files\intel\intel® management engine components\imss\PIconStartup.exe"

mRun: [RotateImage] c:\program files\integrated camera driver\RCIMGDIR.exe

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

mRun: [Persistence] c:\windows\system32\igfxpers.exe

mRun: [smartAudio] c:\program files\conexant\saii\SAIICpl.exe /t

mRun: [PWMTRV] rundll32 c:\progra~1\thinkpad\utilit~1\PWMTR32V.DLL,PwrMgrBkGndMonitor

mRun: [LENOVO.TPKNRRES] c:\program files\lenovo\communications utility\TPKNRRES.exe

mRun: [AirCardEnabler]

mRun: [WatcherHelper] "c:\program files\sierra wireless inc\watcher\WaHelper.exe"

mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"

mRun: [AgentUiRunKey] "c:\program files\iron mountain\connected backuppc\Agent.exe" -ni -sss -e http://localhost:16386/

mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\udaterui.exe" /StartedFromRunKey

mRun: [intelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"

StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{21e247d4-5e27-4bea-aa4d-19a81203fe2a}\Icon3E5562ED7.ico

mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: PromptOnSecureDesktop = 0 (0x0)

mPolicies-system: FilterAdministratorToken = 1 (0x1)

mPolicies-system: LocalAccountTokenFilterPolicy = 1 (0x1)

IE: Open with Nuance PDF Converter 6.0 - c:\program files\nuance\pdf professional 6\cnvres_eng.dll /100

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab

TCP: DhcpNameServer = 192.168.0.1 205.171.3.25 192.168.1.1

TCP: Interfaces\{2CF2A4F8-2174-4EAB-BBF3-50662F4F66C0} : DhcpNameServer = 192.168.0.1 205.171.3.25 192.168.1.1

TCP: Interfaces\{2CF2A4F8-2174-4EAB-BBF3-50662F4F66C0}\3586162796370275962756C6563737 : DhcpNameServer = 4.2.2.1 4.2.2.2

TCP: Interfaces\{2CF2A4F8-2174-4EAB-BBF3-50662F4F66C0}\36F657274797162746 : DhcpNameServer = 192.168.11.1

TCP: Interfaces\{2CF2A4F8-2174-4EAB-BBF3-50662F4F66C0}\C696E6B6379737 : DhcpNameServer = 204.130.255.3 209.63.0.6

TCP: Interfaces\{F5A562CC-6CF6-4289-B978-69BC6A1547B5} : NameServer = 10.12.16.5,10.22.16.5

Handler: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\SAPHTMLP.DLL

Handler: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\SAPHTMLP.DLL

Notify: igfxcui - igfxdev.dll

AppInit_DLLs: c:\progra~1\liquid~1\client\LMBUND~1.DLL

.

============= SERVICES / DRIVERS ===============

.

P2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\mcshield.exe [2010-3-25 147472]

R0 DozeHDD;DozeHDD;c:\windows\system32\drivers\DOZEHDD.SYS [2011-3-1 25968]

R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-11-10 343920]

R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2010-6-16 20592]

R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [2009-9-8 65584]

R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\drivers\smiif32.sys [2011-3-1 13680]

R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]

R2 AgentService;AgentService;c:\program files\iron mountain\connected backuppc\AgentService.exe [2011-5-3 7580576]

R2 enterceptAgent;McAfee Host Intrusion Prevention Service;c:\program files\mcafee\host intrusion prevention\FireSvc.exe [2010-2-16 1498224]

R2 hips;McAfee HIPSCore Service;c:\program files\mcafee\host intrusion prevention\hipscore\HIPSvc.exe [2010-11-11 35696]

R2 LENOVO.CAMMUTE;Lenovo Camera Mute;c:\program files\lenovo\communications utility\CamMute.exe [2011-3-1 50536]

R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\lenovo\hotkey\micmute.exe [2011-3-1 45496]

R2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;c:\program files\lenovo\communications utility\TPKNRSVC.exe [2011-3-1 74088]

R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;c:\program files\lenovo\virtscrl\lvvsst.exe [2011-3-1 93032]

R2 LmGuardSvc;Liquid Machines Client Service;c:\program files\liquid machines\client\lmguardsvc32.exe [2010-8-20 4722688]

R2 Lotus Notes Diagnostics;Lotus Notes Diagnostics;c:\notes\nsd.exe -svcinvoke -ini "c:\notes\notes.ini" --> c:\notes\nsd.exe -svcinvoke -ini c:\notes\notes.ini [?]

R2 LV_Tracker;LV_Tracker;c:\windows\system32\drivers\LV_Tracker.sys [2010-9-25 45384]

R2 McAfeeEngineService;McAfee Engine Service;c:\program files\mcafee\virusscan enterprise\engineserver.exe [2010-3-25 22816]

R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2010-6-1 120128]

R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\vstskmgr.exe [2010-3-25 66880]

R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2010-11-10 70728]

R2 NACAgent;Cisco NAC Agent;c:\program files\cisco\cisco nac agent\NACAgent.exe [2010-2-5 742144]

R2 PDFProFiltSrv;PDFProFiltSrv;c:\program files\nuance\pdf professional 6\PDFProFiltSrv.exe [2009-6-30 134944]

R2 TIRmtCtl;Track-It! Remote Control;c:\windows\tiremote\wuser32.exe [2011-3-14 311374]

R2 TIRmtSvc;Track-It! Workstation Manager;c:\windows\tiremote\TIRemoteService.exe [2011-3-14 613888]

R2 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\lenovo\hotkey\tphkload.exe [2011-3-1 99328]

R2 TPHKSVC;On Screen Display;c:\program files\lenovo\hotkey\TPHKSVC.exe [2011-3-1 64440]

R2 UNS;Intel® Management & Security Application User Notification Service;c:\program files\intel\intel® management engine components\uns\UNS.exe [2011-3-1 2533400]

R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\cisco\cisco anyconnect vpn client\vpnagent.exe [2009-12-17 497856]

R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-11-10 45352]

R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k6232.sys [2011-3-2 215208]

R3 FirehkMP;FirehkMP;c:\windows\system32\drivers\firehk.sys [2010-11-11 44680]

R3 HIPK;McAfee Inc. HIPK;c:\windows\system32\drivers\HIPK.sys [2010-11-11 107896]

R3 HIPPSK;McAfee Inc. HIPPSK;c:\windows\system32\drivers\HIPPSK.sys [2010-11-11 38680]

R3 HIPQK;McAfee Inc. HIPQK;c:\windows\system32\drivers\HIPQK.sys [2010-11-11 35584]

R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-11-10 132480]

R3 IntcDAud;Intel® Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2011-3-1 269824]

R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-11-10 91832]

R3 NETwNs32;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\drivers\NETwNs32.sys [2011-3-2 7122944]

R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]

S3 5U877;USB Video Device;c:\windows\system32\drivers\5U877.sys [2011-3-1 132608]

S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]

S3 DozeSvc;Lenovo Doze Mode Service;c:\program files\thinkpad\utilities\DOZESVC.EXE [2011-3-1 128360]

S3 Firehk;McAfee NDIS Intermediate Filter;c:\windows\system32\drivers\firehk.sys [2010-11-11 44680]

S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-11-10 43288]

S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-11-10 66600]

S3 NETw5s32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\drivers\NETw5s32.sys [2010-11-10 6758912]

S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-11-10 105576]

S3 PCDSRVC{3037D694-FD904ACA-06020101}_0;PCDSRVC{3037D694-FD904ACA-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor\pcdsrvc.pkms [2010-12-9 21744]

S3 Power Manager DBC Service;Power Manager DBC Service;c:\program files\thinkpad\utilities\PWMDBSVC.exe [2011-3-1 79208]

S3 rimspci;rimspci;c:\windows\system32\drivers\rimspe86.sys [2009-10-26 48640]

S3 rixdpcie;rixdpcie;c:\windows\system32\drivers\rixdpe86.sys [2010-11-10 38912]

S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360]

S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]

S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]

S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]

S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-11-10 1343400]

.

=============== Created Last 30 ================

.

2011-08-24 16:55:08 14256 ----a-w- c:\temp\ccmcache\15be7631-252b-4924-9f00-54e0684a7985.1.system\mpsyschk.exe

2011-08-24 16:15:58 -------- d-----w- c:\users\user\appdata\roaming\smkits

2011-08-22 16:25:01 243360 ----a-w- c:\temp\ccmcache\vus000c6.1.system\pkg\uninstall_flash_player.exe

2011-08-17 20:31:57 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-08-17 20:31:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware (tech)

2011-08-16 06:15:26 -------- d-----w- c:\windows\CMAgent

2011-08-16 05:38:22 3229560 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\admin\oct.dll

2011-08-16 05:35:09 434528 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\office.en-us\dwtrig20.exe

2011-08-16 05:34:51 1636240 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\office 2007 help docs\powerpoint 2007\powerpoint 2003 to powerpoint 2007 interactive command reference guide\pp2003_2007CmdRef.exe

2011-08-16 05:32:47 1591184 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\office 2007 help docs\word 2007\word 2003 to word 2007 interactive command reference guide\wd2003_2007CmdRef.exe

2011-08-16 05:32:17 1564048 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\office 2007 help docs\excel 2007\excel 2003 to excel 2007 command reference\xl2003_2007CmdRef.exe

2011-08-16 05:32:03 423312 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\admin\en-us\octres.dll

2011-08-16 05:28:25 813384 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\office.en-us\DW20.EXE

2011-08-16 05:28:23 76120 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\admin\patchca.dll

2011-08-16 05:27:09 394080 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\admin\zh-cn\octres.dll

2011-08-16 05:26:45 439568 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\office.en-us\dwdcw20.dll

2011-08-16 05:26:41 443304 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\admin\fr-fr\octres.dll

2011-08-16 05:20:04 626688 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\office.en-us\msvcr80.dll

2011-08-16 05:17:54 96576 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\admin\octca.dll

2011-08-16 05:17:25 2394050 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\office 2007 help docs\word 2007\word 2003 to word 2007 interactive command reference guide\word quick reference guide\INTERA~1.EXE

2011-08-16 05:16:41 6536992 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\proplus.ww\osetup.dll

2011-08-15 23:15:40 108872 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\office.en-us\1033\dwintl20.dll

2011-08-15 23:15:25 438728 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\admin\it-it\octres.dll

2011-08-15 23:15:23 440728 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\admin\de-de\octres.dll

2011-08-15 23:15:21 184632 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\office.en-us\osetupui.dll

2011-08-15 23:15:16 145184 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\proplus.ww\ose.exe

2011-08-15 18:09:21 40328 ----a-w- c:\windows\system32\HIPIS0e011b3.dll

2011-08-14 18:17:50 441800 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\admin\es-es\octres.dll

2011-08-14 18:15:54 403352 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\admin\ko-kr\octres.dll

2011-08-14 18:15:51 463152 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\setup.exe

2011-08-14 18:11:12 395104 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\admin\zh-tw\octres.dll

2011-08-14 18:09:26 406880 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\admin\ja-jp\octres.dll

2011-08-14 18:09:13 2366920 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\office 2007 help docs\excel 2007\excel 2003 to excel 2007 command reference\excel quick reference guide\INTERA~1.EXE

2011-08-14 18:08:36 2432140 ----a-w- c:\temp\ccmcache\vus000c2.1.system\pkg\office 2007 help docs\powerpoint 2007\powerpoint 2003 to powerpoint 2007 interactive command reference guide\pp quick reference guide\INTERA~1.EXE

2011-07-26 20:17:13 60416 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS

2011-07-26 20:17:12 393216 ----a-w- c:\windows\system32\drivers\bthport.sys

.

==================== Find3M ====================

.

2011-08-11 12:14:57 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

2011-08-05 07:56:14 136512 ----a-w- c:\windows\system32\KevlarSigs.dll

2011-07-06 15:18:21 5292253 ----a-w- c:\windows\FramePkg.exe

2011-06-30 15:13:45 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-06-11 02:37:19 2332672 ----a-w- c:\windows\system32\win32k.sys

2011-06-02 05:58:05 290816 ----a-w- c:\windows\system32\KernelBase.dll

2011-06-02 03:45:49 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll

2011-06-02 03:45:49 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll

2011-06-02 03:45:49 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll

2011-06-02 03:45:49 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll

2011-05-28 03:00:02 1638912 ----a-w- c:\windows\system32\mshtml.tlb

.

============= FINISH: 13:33:41.28 ===============

Link to post
Share on other sites
  • 2 weeks later...
  • 1 month later...
  • Staff

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites
Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.