This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE/Firefox open tabs and go to random ad pages

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL.txt;

OTL logfile created on: 6/13/2010 12:58:26 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Tracey Carpenter\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 240.00 Mb Available Physical Memory | 47.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 63.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.18 Gb Total Space | 22.64 Gb Free Space | 31.81% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CARPHOME
Current User Name: Tracey Carpenter
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Tracey Carpenter\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Webroot\Spy Sweeper\SSU.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
PRC - C:\Program Files\Yahoo!\browser\ycommon.exe (Yahoo!, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\TrueAssistant\TrueAssistant.exe (Esaya, Inc.)
PRC - C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Tracey Carpenter\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (WRConsumerService) – C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (WebrootSpySweeperService) – C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (SfCtlCom) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
SRV - (TmProxy) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
SRV - (TMBMServer) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (tmxpflt) – C:\WINDOWS\SYSTEM32\DRIVERS\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\SYSTEM32\DRIVERS\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\SYSTEM32\DRIVERS\vsapint.sys (Trend Micro Inc.)
DRV - (SSIDRV) – C:\WINDOWS\SYSTEM32\Drivers\SSIDRV.SYS (Webroot Software, Inc. (www.webroot.com))
DRV - (SSHRMD) – C:\WINDOWS\SYSTEM32\Drivers\SSHRMD.SYS (Webroot Software, Inc. (www.webroot.com))
DRV - (ssfs0bbc) – C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (tmactmon) – C:\WINDOWS\SYSTEM32\DRIVERS\tmactmon.sys ()
DRV - (tmevtmgr) – C:\WINDOWS\SYSTEM32\DRIVERS\tmevtmgr.sys ()
DRV - (tmcomm) – C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys ()
DRV - (tmtdi) – C:\WINDOWS\SYSTEM32\DRIVERS\tmtdi.sys (Trend Micro Inc.)
DRV - (PalmUSBD) – C:\WINDOWS\SYSTEM32\DRIVERS\PalmUSBD.sys (PalmSource, Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (SSKBFD) – C:\WINDOWS\SYSTEM32\DRIVERS\sskbfd.sys (Webroot Software Inc (www.webroot.com))
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (Afc) – C:\WINDOWS\SYSTEM32\DRIVERS\afc.sys (Arcsoft, Inc.)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
DRV - (tfsnudfa) – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
DRV - (IntelC53) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys (Intel Corporation)
DRV - (netrcacm) – C:\WINDOWS\SYSTEM32\DRIVERS\netrcacm.sys (Thomson Inc.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…/search/ie.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL (Ask.com)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
FF - prefs.js..browser.search.defaulturl: "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v;=19&q;="
FF - prefs.js..browser.startup.homepage: "http://my.msn.com/"
FF - prefs.js..extensions.enabledItems: {4176DFF4-4698-11DE-BEEB-45DA55D89593}:0.7.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.3.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..keyword.URL: "http://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v;=19&tid;={5EC2975F-2FCC-96EA-BA7C-3E1A6E11DD3C}&q;="


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/06 20:33:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/02 14:38:02 | 000,000,000 | —D | M]

[2010/03/24 20:37:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Extensions
[2010/06/11 13:38:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions
[2010/04/27 15:43:27 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/24 20:56:12 | 000,000,000 | —D | M] (AniWeather) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}
[2010/05/02 14:39:08 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/03/24 20:37:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB}
[2010/06/06 21:43:31 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/06/06 21:43:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\[removed]
[2010/06/13 08:40:09 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/02 14:38:16 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/05/02 14:36:27 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/03/24 21:15:55 | 000,003,700 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fast.png
[2010/03/24 21:15:55 | 000,001,963 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fast.xml

O1 HOSTS File: ([2010/06/12 22:34:31 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Ask Search Assistant BHO) - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL (Ask.com)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O2 - BHO: (no name) - MRI_DISABLED - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe (Webroot Software, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
O4 - HKLM..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Tracey Carpenter\Start Menu\Programs\Startup\TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe (Esaya, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} http://www.linkedin.com/cab/LinkedInContactFinderControl.cab (LinkedIn ContactFinderControl)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1237139453218 (MUWebControl Class)
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} http://us-download.mcafee.com/products/protected/mvt/mvt.cab (McAfee Virtual Technician Control Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://download.yahoo.com/dl/installs/yab_af.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab (PhotosCtrl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} http://zone.msn.com/bingame/cnma/default/cinematycoon.cab (TikGames Online Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} http://www.trueswitch.com/sbc/TrueInstallSBC.exe (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Security Packages - (ecurity Packages settings…) - File not found
O30 - LSA: Security Packages - (or) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 15:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2004/12/04 01:55:46 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\SYSTEM32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 90 Days ==========

[2010/06/13 12:56:59 | 000,572,416 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Tracey Carpenter\Desktop\OTL.exe
[2010/06/12 22:59:34 | 000,000,000 | —D | C] – C:\ComboFix
[2010/06/11 11:03:35 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/06/11 10:42:41 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/06/11 10:42:41 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/06/11 10:42:41 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/06/11 10:42:41 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/06/11 10:42:06 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/06/11 10:32:40 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/08 14:05:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2010/06/08 14:05:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracey Carpenter\My Documents\My RoboForm Data
[2010/06/08 13:32:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\Temp
[2010/06/07 13:04:10 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/06/06 21:54:12 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/06/06 21:54:08 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/05 11:21:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracey Carpenter\Application Data\Malwarebytes
[2010/06/05 11:20:48 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/05 11:20:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/06/05 11:20:42 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/05 11:20:39 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/05 07:54:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\gnloyljux
[2010/05/02 14:39:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/03/24 20:57:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracey Carpenter\My Documents\Downloads
[2010/03/24 20:37:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla
[1980/01/01 02:00:00 | 000,151,552 | —- | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll
[3 C:\Documents and Settings\Tracey Carpenter\My Documents\*.tmp files -> C:\Documents and Settings\Tracey Carpenter\My Documents\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/06/13 12:56:49 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Tracey Carpenter\Desktop\OTL.exe
[2010/06/13 11:05:30 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/13 11:05:27 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/06/13 11:05:26 | 534,925,312 | -HS- | M] () – C:\hiberfil.sys
[2010/06/13 08:20:35 | 004,980,736 | -H– | M] () – C:\Documents and Settings\Tracey Carpenter\NTUSER.DAT
[2010/06/12 23:10:44 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/06/12 22:41:57 | 003,706,758 | R— | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\ComboFix.exe
[2010/06/12 22:34:31 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\HOSTS
[2010/06/12 22:27:05 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Tracey Carpenter\NTUSER.INI
[2010/06/12 10:54:06 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/12 10:51:22 | 000,000,000 | -H– | M] () – C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\IconCache.db
[2010/06/12 03:38:30 | 000,307,600 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/12 03:21:34 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/06/12 03:08:43 | 000,503,304 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/12 03:08:43 | 000,442,466 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2010/06/12 03:08:43 | 000,071,732 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2010/06/11 14:20:03 | 000,000,045 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\jagex_runescape_preferences.dat
[2010/06/11 14:16:11 | 000,000,087 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\jagex_runescape_preferences2.dat
[2010/06/11 11:03:44 | 000,000,281 | RHS- | M] () – C:\BOOT.INI
[2010/06/10 19:30:27 | 000,293,376 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\gmer.exe
[2010/06/09 10:31:55 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/06/08 16:25:40 | 000,359,929 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\dds.scr
[2010/06/08 13:59:50 | 000,000,104 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\Internet Explorer.lnk
[2010/06/08 09:01:31 | 000,000,775 | —- | M] () – C:\WINDOWS\WIN.INI
[2010/06/08 09:01:31 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/06/06 21:55:53 | 000,001,641 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Webroot AntiVirus.lnk
[2010/06/06 21:52:37 | 000,000,164 | —- | M] () – C:\WINDOWS\install.dat
[2010/06/05 14:59:07 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/05 11:20:56 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/02 19:27:01 | 000,056,578 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\Application Data\wklnhst.dat
[2010/06/01 17:42:41 | 000,035,774 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\P100416_Pete Carpenter_portal-1 (2).jpg
[2010/05/23 13:32:10 | 000,026,112 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\John Muir.doc
[2010/05/09 09:16:51 | 000,019,968 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Friendship.doc
[2010/05/02 14:48:34 | 000,000,000 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\jagex__preferences3.dat
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/26 15:58:12 | 000,256,512 | —- | M] () – C:\WINDOWS\PEV.exe
[2010/04/04 12:40:33 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/03/29 08:40:32 | 000,332,800 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Employment Application.doc
[2010/03/28 16:37:16 | 000,019,968 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Summer Party.doc
[2010/03/24 21:15:42 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/03/17 18:52:11 | 000,187,904 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Meaghan's Business 3.doc
[2010/03/15 17:27:12 | 000,021,504 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Pete Carpenter - Letter.doc
[3 C:\Documents and Settings\Tracey Carpenter\My Documents\*.tmp files -> C:\Documents and Settings\Tracey Carpenter\My Documents\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/12 22:27:45 | 534,925,312 | -HS- | C] () – C:\hiberfil.sys
[2010/06/11 11:03:44 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/06/11 11:03:37 | 000,260,272 | —- | C] () – C:\cmldr
[2010/06/11 10:42:41 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/06/11 10:42:41 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/06/11 10:42:41 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/06/11 10:42:41 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/06/11 10:42:41 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/06/11 10:31:30 | 003,706,758 | R— | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\ComboFix.exe
[2010/06/10 19:30:38 | 000,293,376 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\gmer.exe
[2010/06/08 16:25:35 | 000,359,929 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\dds.scr
[2010/06/08 13:59:50 | 000,000,104 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\Internet Explorer.lnk
[2010/06/06 21:55:53 | 000,001,641 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Webroot AntiVirus.lnk
[2010/06/05 11:20:56 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/01 17:42:41 | 000,035,774 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\P100416_Pete Carpenter_portal-1 (2).jpg
[2010/05/20 17:15:24 | 000,026,112 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\John Muir.doc
[2010/05/09 09:16:51 | 000,019,968 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Friendship.doc
[2010/05/02 14:48:34 | 000,000,000 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\jagex__preferences3.dat
[2010/03/29 06:28:21 | 000,332,800 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Employment Application.doc
[2010/03/28 16:37:15 | 000,019,968 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Summer Party.doc
[2010/03/24 20:36:15 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/03/17 18:52:09 | 000,187,904 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Meaghan's Business 3.doc
[2010/03/15 17:27:12 | 000,021,504 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Pete Carpenter - Letter.doc
[2009/11/06 12:00:28 | 000,031,088 | —- | C] () – C:\WINDOWS\System32\wrLZMA.dll
[2008/02/02 17:05:50 | 000,000,074 | —- | C] () – C:\WINDOWS\TaxACT07.ini
[2008/01/01 18:31:27 | 000,153,104 | —- | C] () – C:\WINDOWS\System32\drivers\tmcomm.sys
[2008/01/01 18:31:27 | 000,050,192 | —- | C] () – C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2008/01/01 18:31:27 | 000,050,192 | —- | C] () – C:\WINDOWS\System32\drivers\tmactmon.sys
[2007/03/13 19:20:47 | 000,001,214 | —- | C] () – C:\WINDOWS\Sdcache.ini
[2007/03/13 19:20:41 | 000,002,679 | —- | C] () – C:\WINDOWS\System32\SDUSBPDR.INI
[2007/03/13 19:16:10 | 000,002,204 | —- | C] () – C:\WINDOWS\System32\drivers\UNINST2K.SYS
[2007/02/03 18:31:54 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2007/02/03 18:30:04 | 000,000,054 | —- | C] () – C:\WINDOWS\System32\EAL32.INI
[2007/02/03 18:28:50 | 000,000,044 | —- | C] () – C:\WINDOWS\EPCX6000.ini
[2005/11/13 16:39:42 | 000,000,565 | —- | C] () – C:\WINDOWS\hegames.ini
[2005/06/19 18:44:44 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2005/04/01 16:52:37 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/03/24 19:23:32 | 000,000,029 | —- | C] () – C:\WINDOWS\RRK.INI
[2005/01/26 14:53:29 | 000,000,008 | —- | C] () – C:\WINDOWS\System32\PdSACKey.sys
[2005/01/21 20:11:50 | 000,000,159 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2005/01/08 14:39:17 | 000,000,814 | —- | C] () – C:\WINDOWS\dellstat.ini
[2005/01/04 22:31:46 | 000,031,917 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2004/12/31 12:20:10 | 000,000,190 | —- | C] () – C:\WINDOWS\disneysy.ini
[2004/12/31 10:26:16 | 000,000,165 | —- | C] () – C:\WINDOWS\ka.ini
[2004/12/26 11:02:49 | 000,000,050 | —- | C] () – C:\WINDOWS\upst.ini
[2004/12/26 11:02:49 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2004/12/25 18:34:22 | 000,000,191 | —- | C] () – C:\WINDOWS\QTW.INI
[2004/12/25 18:02:13 | 000,001,622 | —- | C] () – C:\WINDOWS\disney.ini
[2004/12/04 02:38:04 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/12/04 02:32:34 | 000,000,264 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/12/04 02:26:45 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/12/04 01:57:50 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/09/16 00:03:14 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 15:13:12 | 000,000,780 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/04 07:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[1980/01/01 02:00:00 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[1980/01/01 02:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2006/12/14 19:33:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2008/01/01 18:33:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2008/12/25 15:26:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2010/03/06 09:27:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/06/08 14:05:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2009/10/29 20:33:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SwiftKit
[2008/07/12 15:43:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/01/01 16:40:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/12/25 12:48:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2006/06/16 18:30:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Aim
[2009/02/04 07:33:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\GetRightToGo
[2008/12/25 15:24:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\HotSync
[2008/02/15 21:38:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Jasc
[2004/12/25 17:46:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Leadertech
[2006/06/16 08:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\MSNInstaller
[2010/03/06 09:27:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\PlayFirst
[2008/10/25 12:22:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\SPORE
[2007/03/09 21:49:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Viewpoint

========== Purity Check ==========



========== Custom Scans ==========


< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys

< %SYSTEMDRIVE%\*.exe >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/11/06 12:00:28 | 000,031,088 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\wrLZMA.dll
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009/04/02 19:08:54 | 000,050,192 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\DRIVERS\tmactmon.sys
[2009/04/02 19:08:48 | 000,153,104 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys
[2009/04/02 19:08:52 | 000,050,192 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\DRIVERS\tmevtmgr.sys

< %systemroot%\System32\config\*.sav >
[2004/08/10 14:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2004/08/10 14:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2004/08/10 14:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

========== Alternate Data Streams ==========

@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:17639624
< End of report >



extras.txt:

OTL Extras logfile created on: 6/13/2010 12:58:26 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Tracey Carpenter\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 240.00 Mb Available Physical Memory | 47.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 63.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.18 Gb Total Space | 22.64 Gb Free Space | 31.81% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CARPHOME
Current User Name: Tracey Carpenter
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /k "cd %L" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – File not found
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger – (America Online, Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger – (America Online, Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0030188A-533E-42EE-9837-E044F10E4369}" = Palm
"{04410044-9149-45C6-A806-F2BF9CFCE762}" = Microsoft Encarta Encyclopedia Standard 2004
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0E4BC542-9CFD-4E97-B586-9F1E5516E7B9}" = Microsoft IntelliPoint 6.1
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F745260-192A-11D5-A511-00C04F9643C9}" = ImageMate CompactFlash USB (SDDR-31) Ver. 5.05
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{1CA2E5E4-F4FE-44B4-95E9-77523FB95838}" = EPSON Stylus CX6000 Scanner Driver Update
"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004
"{1FCC574F-AFA2-4432-9EF1-79CA7BA73431}_is1" = Webroot AntiVirus with Spy Sweeper
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{33BEE6F3-9987-4F98-A069-97A64EC8321A}" = Microsoft Works Suite Add-in for Microsoft Word
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3F5B6210-0903-4DC6-8034-8F488AA3A782}" = Spy Sweeper Core
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Modem On Hold
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{40E12A55-C504-4223-AFAC-7672DBF1ACDE}" = Trend Micro AntiVirus
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{625BD732-ACDF-4552-BF22-98EBB413B6F3}" = McAfee Shredder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.3
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7148F0A8-6813-11D6-A77B-00B0D0142060}" = Java 2 Runtime Environment, SE v1.4.2_06
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro AntiVirus
"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}" = EarthLink setup files
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78D944D7-A97B-4004-AB0A-B5AD06839940}" = My Way Search Assistant
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition
"{8704D51E-25B7-4F23-81E7-AA4F54790210}" = Microsoft Streets and Trips 2004
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C64E145-54BA-11D6-91B1-00500462BE80}" = Microsoft Money 2004 System Pack
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A621B45A-D138-4A95-BE10-7CABA05EF94E}" = Trend Micro AntiVirus
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{B44AA698-B221-4B3B-8CA5-E65EF6A5AF26}" = Hoyle Card Games 2005
"{B9966F27-9678-4620-9579-925E3084647E}" = Microsoft Works
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint Plus
"{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}" = ArcSoft PhotoImpression 5
"{DBA8B9E1-C6FF-4624-9598-73D3B41A0903}" = Microsoft Picture It! Photo Premium 9
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{F3812D83-86D2-4445-A841-3E0BA4F9A11C}" = Merriam-Webster
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AskSBar Uninstall" = Ask Toolbar
"ATI Display Driver" = ATI Display Driver
"Bookworm Deluxe 1.03" = Bookworm Deluxe 1.03
"BroadJump Client Foundation" = BroadJump Client Foundation
"CDex" = CDex extraction audio
"Digital Camera_is1" = Uninstall Digital Camera Drivers
"Diner Dash - Flo on the Go" = Diner Dash - Flo on the Go
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"Graph_is1" = Graph 4.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"ImageMate/SecureMate V5.06" = SanDisk ImageMate/SecureMate
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"Jeopardy!" = Jeopardy!
"Mahjongg Platinum 2 Deluxe" = Mahjongg Platinum 2 Deluxe
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Paws and Claws Pet School" = Paws and Claws Pet School (remove only)
"Pet Vet" = Pet Vet (remove only)
"PictureIt_v9" = Microsoft Picture It! Photo Premium 9
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer
"Shockwave" = Shockwave
"Silent Package Run-Time Sample" = EPSON CX6000 Series User's Guide
"StreetPlugin" = Learn2 Player (Uninstall Only)
"TrueSwitch Wizard SBC" = TrueSwitch Wizard SBC
"UnityWebPlayer" = Unity Web Player
"WildTangent CDA" = WildTangent Web Driver
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WordSmart Vocabulary_is1" = a desktop shortcut to the WordSmart CD
"Works2004Setup" = Microsoft Works 2004 Setup Launcher
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Applications" = AT&T; Yahoo! Applications
"Zoo Tycoon 1.0" = Microsoft Zoo Tycoon

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"SwiftKit" = SwiftKit

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/9/2010 2:29:00 PM | Computer Name = CARPHOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 6/9/2010 2:29:01 PM | Computer Name = CARPHOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 6/9/2010 4:43:56 PM | Computer Name = CARPHOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 6/9/2010 4:43:57 PM | Computer Name = CARPHOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 6/9/2010 8:03:10 PM | Computer Name = CARPHOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 6/9/2010 8:03:11 PM | Computer Name = CARPHOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 6/10/2010 12:24:34 AM | Computer Name = CARPHOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 6/10/2010 12:24:34 AM | Computer Name = CARPHOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 6/10/2010 7:31:30 PM | Computer Name = CARPHOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 6/10/2010 7:31:30 PM | Computer Name = CARPHOME | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

[ OSession Events ]
Error - 3/1/2009 3:31:20 PM | Computer Name = CARPHOME | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

[ System Events ]
Error - 6/12/2010 10:53:50 AM | Computer Name = CARPHOME | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm tmtdi

Error - 6/12/2010 4:14:42 PM | Computer Name = CARPHOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 6/12/2010 4:14:50 PM | Computer Name = CARPHOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 6/12/2010 4:22:10 PM | Computer Name = CARPHOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 6/12/2010 10:19:31 PM | Computer Name = CARPHOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 6/12/2010 10:20:43 PM | Computer Name = CARPHOME | Source = Service Control Manager | ID = 7001
Description = The Trend Micro Proxy Service service depends on the Trend Micro TDI
Driver service which failed to start because of the following error: %%31

Error - 6/12/2010 10:20:43 PM | Computer Name = CARPHOME | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm tmtdi

Error - 6/12/2010 10:21:51 PM | Computer Name = CARPHOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 6/12/2010 10:27:04 PM | Computer Name = CARPHOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 6/13/2010 11:05:42 AM | Computer Name = CARPHOME | Source = Print | ID = 19
Description = Sharing printer failed + 1722, Printer EPSON Stylus CX6000 Series
share name Printer.


< End of report >
sc518,

🖼Click to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
    FF - prefs.js..browser.search.defaulturl: "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q="
    FF - prefs.js..keyword.URL: "http://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={5EC2975F-2FCC-96EA-BA7C-3E1A6E11DD3C}&q="
    [2010/03/24 21:15:55 | 000,003,700 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fast.png
    [2010/03/24 21:15:55 | 000,001,963 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fast.xml
    IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
    IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
    O2 - BHO: (no name) - MRI_DISABLED - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Key error. (Reg Error: Key error.)
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (Reg Error: Key error.)
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://download.yahoo.com/dl/installs/yab_af.cab (Reg Error: Key error.)
    O30 - LSA: Security Packages - (ecurity Packages settings…) - File not found
    O30 - LSA: Security Packages - (or) - File not found
    [3 C:\Documents and Settings\Tracey Carpenter\My Documents\*.tmp files -> C:\Documents and Settings\Tracey Carpenter\My Documents\*.tmp -> ]
    [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\*.tmp files -> C:\*.tmp -> ]
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
Please include the following in your next post:
  • OTL Fix log
All processes killed ========== OTL ========== Prefs.js: "Fast Browser Search" removed from browser.search.defaultenginename Prefs.js: "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=" removed from browser.search.defaulturl Prefs.js: "http://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={5EC2975F-2FCC-96EA-BA7C-3E1A6E11DD3C}&q=" removed from keyword.URL C:\Program Files\Mozilla Firefox\searchplugins\fast.png moved successfully. C:\Program Files\Mozilla Firefox\searchplugins\fast.xml moved successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\MRI_DISABLED\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{724D43A0-0D85-11D4-9908-00400523E39A} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{724D43A0-0D85-11D4-9908-00400523E39A}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully. Registry delete failed. HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ scheduled to be deleted on reboot. Starting removal of ActiveX control {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}\ not found. Starting removal of ActiveX control {67DABFBF-D0AB-41FA-9C46-CC0F21721616} C:\WINDOWS\Downloaded Program Files\DivXPlugin.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\ not found. Starting removal of ActiveX control {B9191F79-5613-4C76-AA2A-398534BB8999} C:\Program Files\Yahoo!\Common\yab_af.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B9191F79-5613-4C76-AA2A-398534BB8999}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B9191F79-5613-4C76-AA2A-398534BB8999}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{B9191F79-5613-4C76-AA2A-398534BB8999}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B9191F79-5613-4C76-AA2A-398534BB8999}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages:ecurity Packages settings… deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages:or deleted successfully. C:\Documents and Settings\Tracey Carpenter\My Documents\~WRD1968.tmp deleted successfully. C:\Documents and Settings\Tracey Carpenter\My Documents\~WRD3563.tmp deleted successfully. C:\Documents and Settings\Tracey Carpenter\My Documents\~WRL2923.tmp deleted successfully. C:\WINDOWS\System32\CONFIG.TMP deleted successfully. C:\WINDOWS\System32\setb4.tmp deleted successfully. C:\WINDOWS\System32\dllcache\ws2help.dll.tmp deleted successfully. C:\WINDOWS\002719_.tmp deleted successfully. C:\IO96BC~.TMP deleted successfully. ========== COMMANDS ========== [EMPTYFLASH] User: Administrator User: All Users User: Default User User: Guest User: LocalService ->Flash cache emptied: 9580 bytes User: Meaghan Carpenter User: NetworkService ->Flash cache emptied: 3108 bytes User: Owner User: Sean Carpenter User: Tracey Carpenter ->Flash cache emptied: 640804 bytes Total Flash Files Cleaned = 1.00 mb [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Java cache emptied: 128094 bytes ->FireFox cache emptied: 37686839 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 0 bytes User: Meaghan Carpenter User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 0 bytes User: Owner User: Sean Carpenter User: Tracey Carpenter ->Temp folder emptied: 884022 bytes ->Temporary Internet Files folder emptied: 2165596 bytes ->Java cache emptied: 77543131 bytes ->FireFox cache emptied: 65836347 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 32768 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 176.00 mb OTL by OldTimer - Version 3.2.6.0 log created on 06132010_143640 Files\Folders moved on Reboot… Registry entries deleted on Reboot… Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
That nuked every instance of Fast Browser Search that was visible on your log, along with some other orphaned stuff. Any sign of it now?
sc518,

Good deal! Now I have some important updating and cleanup for you to take care of, then we are done:

🖼Click to load external image (Posted Image) Clean up your old Java installs with JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
🖼Click to load external image (Posted Image) Your Adobe reader needs to be updated. Please visit Adobe's site and grab the newest version.

Go HERE to scan for any other out of date and/or vulnerable applications on your computer and follow the instructions given for updating them.

🖼Click to load external image (Posted Image) Uninstall ComboFix
  • Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens and press OK:
    Combofix /Uninstall
🖼Click to load external image (Posted Image)

🖼Click to load external image (Posted Image) Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
  • Manually delete any remaining logs or tools.
🖼Click to load external image (Posted Image) Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
  • Restart any anti-malware programs that we disabled while we were cleaning your machine.
  • Keep your antivirus application current and updated. Also, hang on to MBAM. Scan with them at least weekly.
  • Consider running in a limited user account. See this post for more information.
  • Please carefully review the information in our Security - Best Practices and Prevention forum located HERE
Please post once more so I know you are all set and I can close this thread. Good luck and stay safe!
tried that earlier today =( didn't work. just so you know, I believe I was running IE when this thing originally got installed, if that makes a difference
k here is another OTL log:

OTL logfile created on: 6/13/2010 8:54:50 PM - Run 2
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Tracey Carpenter\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 101.00 Mb Available Physical Memory | 20.00% Memory free
1.00 Gb Paging File | 0.00 Gb Available in Paging File | 35.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.18 Gb Total Space | 23.28 Gb Free Space | 32.71% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CARPHOME
Current User Name: Tracey Carpenter
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Tracey Carpenter\My Documents\Sean\SwiftKit-RS.exe (Bluelight Developments)
PRC - C:\Documents and Settings\Tracey Carpenter\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files\Java\jre6\bin\java.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\QuickTime\PictureViewer.exe (Apple Inc.)
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Webroot\Spy Sweeper\SSU.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
PRC - C:\Program Files\Yahoo!\browser\ycommon.exe (Yahoo!, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\TrueAssistant\TrueAssistant.exe (Esaya, Inc.)
PRC - C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Tracey Carpenter\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (WRConsumerService) – C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (WebrootSpySweeperService) – C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (SfCtlCom) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
SRV - (TmProxy) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
SRV - (TMBMServer) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (tmxpflt) – C:\WINDOWS\SYSTEM32\DRIVERS\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\SYSTEM32\DRIVERS\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\SYSTEM32\DRIVERS\vsapint.sys (Trend Micro Inc.)
DRV - (SSIDRV) – C:\WINDOWS\SYSTEM32\Drivers\SSIDRV.SYS (Webroot Software, Inc. (www.webroot.com))
DRV - (SSHRMD) – C:\WINDOWS\SYSTEM32\Drivers\SSHRMD.SYS (Webroot Software, Inc. (www.webroot.com))
DRV - (ssfs0bbc) – C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (tmactmon) – C:\WINDOWS\SYSTEM32\DRIVERS\tmactmon.sys ()
DRV - (tmevtmgr) – C:\WINDOWS\SYSTEM32\DRIVERS\tmevtmgr.sys ()
DRV - (tmcomm) – C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys ()
DRV - (tmtdi) – C:\WINDOWS\SYSTEM32\DRIVERS\tmtdi.sys (Trend Micro Inc.)
DRV - (PalmUSBD) – C:\WINDOWS\SYSTEM32\DRIVERS\PalmUSBD.sys (PalmSource, Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (SSKBFD) – C:\WINDOWS\SYSTEM32\DRIVERS\sskbfd.sys (Webroot Software Inc (www.webroot.com))
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (Afc) – C:\WINDOWS\SYSTEM32\DRIVERS\afc.sys (Arcsoft, Inc.)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
DRV - (tfsnudfa) – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
DRV - (IntelC53) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys (Intel Corporation)
DRV - (netrcacm) – C:\WINDOWS\SYSTEM32\DRIVERS\netrcacm.sys (Thomson Inc.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…/search/ie.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
IE - HKCU\..\URLSearchHook: {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL (Ask.com)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Fast Browser Search"
FF - prefs.js..browser.search.defaulturl: "http://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v;=19&q;="
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://my.msn.com/"
FF - prefs.js..extensions.enabledItems: {4176DFF4-4698-11DE-BEEB-45DA55D89593}:0.7.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.3.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..keyword.URL: "http://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v;=19&tid;={5EC2975F-2FCC-96EA-BA7C-3E1A6E11DD3C}&q;="


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/06 20:33:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/13 20:16:23 | 000,000,000 | —D | M]

[2010/03/24 20:37:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Extensions
[2010/06/13 20:16:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions
[2010/04/27 15:43:27 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/24 20:56:12 | 000,000,000 | —D | M] (AniWeather) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}
[2010/05/02 14:39:08 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/03/24 20:37:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB}
[2010/06/06 21:43:31 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/06/13 20:15:46 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/06/06 21:43:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla\Firefox\Profiles\gy7fmmlb.default\extensions\[removed]
[2010/06/13 20:16:16 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/02 14:38:16 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/05/02 14:36:27 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/06/13 14:50:47 | 000,003,700 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fast.png
[2010/06/13 14:50:47 | 000,001,963 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fast.xml

O1 HOSTS File: ([2010/06/12 22:34:31 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Ask Search Assistant BHO) - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL (Ask.com)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O4 - HKLM..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe (Webroot Software, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
O4 - HKLM..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\RunOnce: [Uninstall Adobe Download Manager] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Tracey Carpenter\Start Menu\Programs\Startup\TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe (Esaya, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} http://www.linkedin.com/cab/LinkedInContactFinderControl.cab (LinkedIn ContactFinderControl)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1237139453218 (MUWebControl Class)
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} http://us-download.mcafee.com/products/protected/mvt/mvt.cab (McAfee Virtual Technician Control Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab (PhotosCtrl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} http://zone.msn.com/bingame/cnma/default/cinematycoon.cab (TikGames Online Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} http://www.trueswitch.com/sbc/TrueInstallSBC.exe (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Security Packages - (ecurity Packages settings…) - File not found
O30 - LSA: Security Packages - (or) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 15:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/06/13 20:16:03 | 000,000,000 | —D | C] – C:\Program Files\NOS
[2010/06/13 20:16:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2010/06/13 20:11:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracey Carpenter\Desktop\JavaRa
[2010/06/13 14:43:23 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/06/13 14:36:40 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/13 12:56:59 | 000,572,416 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Tracey Carpenter\Desktop\OTL.exe
[2010/06/12 22:59:34 | 000,000,000 | —D | C] – C:\ComboFix
[2010/06/11 11:03:35 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/06/11 10:42:41 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/06/11 10:42:41 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/06/11 10:42:41 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/06/11 10:42:41 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/06/11 10:42:06 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/06/11 10:32:40 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/08 14:05:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2010/06/08 14:05:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracey Carpenter\My Documents\My RoboForm Data
[2010/06/08 13:32:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\Temp
[2010/06/07 13:04:10 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/06/06 21:54:12 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/06/06 21:54:08 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/05 11:21:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracey Carpenter\Application Data\Malwarebytes
[2010/06/05 11:20:48 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/05 11:20:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/06/05 11:20:42 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/05 11:20:39 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/05 07:54:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\gnloyljux
[2010/05/02 14:39:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/03/24 20:57:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracey Carpenter\My Documents\Downloads
[2010/03/24 20:37:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Tracey Carpenter\Application Data\Mozilla
[1980/01/01 02:00:00 | 000,151,552 | —- | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll

========== Files - Modified Within 90 Days ==========

[2010/06/13 20:52:46 | 000,000,087 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\jagex_runescape_preferences2.dat
[2010/06/13 20:21:15 | 000,000,045 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\jagex_runescape_preferences.dat
[2010/06/13 20:16:53 | 004,980,736 | -H– | M] () – C:\Documents and Settings\Tracey Carpenter\NTUSER.DAT
[2010/06/13 20:11:17 | 000,071,798 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\JavaRa.zip
[2010/06/13 14:43:48 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Tracey Carpenter\NTUSER.INI
[2010/06/13 14:43:21 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/13 14:43:18 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/06/13 14:43:17 | 534,925,312 | -HS- | M] () – C:\hiberfil.sys
[2010/06/13 12:56:49 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Tracey Carpenter\Desktop\OTL.exe
[2010/06/12 23:10:44 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/06/12 22:41:57 | 003,706,758 | R— | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\ComboFix.exe
[2010/06/12 22:34:31 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\HOSTS
[2010/06/12 10:54:06 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/12 10:51:22 | 000,000,000 | -H– | M] () – C:\Documents and Settings\Tracey Carpenter\Local Settings\Application Data\IconCache.db
[2010/06/12 03:38:30 | 000,307,600 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/12 03:21:34 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/06/12 03:08:43 | 000,503,304 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/12 03:08:43 | 000,442,466 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2010/06/12 03:08:43 | 000,071,732 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2010/06/11 11:03:44 | 000,000,281 | RHS- | M] () – C:\BOOT.INI
[2010/06/10 19:30:27 | 000,293,376 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\gmer.exe
[2010/06/09 10:31:55 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/06/08 16:25:40 | 000,359,929 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\dds.scr
[2010/06/08 13:59:50 | 000,000,104 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\Desktop\Internet Explorer.lnk
[2010/06/08 09:01:31 | 000,000,775 | —- | M] () – C:\WINDOWS\WIN.INI
[2010/06/08 09:01:31 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/06/06 21:55:53 | 000,001,641 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Webroot AntiVirus.lnk
[2010/06/06 21:52:37 | 000,000,164 | —- | M] () – C:\WINDOWS\install.dat
[2010/06/05 14:59:07 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/05 11:20:56 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/02 19:27:01 | 000,056,578 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\Application Data\wklnhst.dat
[2010/06/01 17:42:41 | 000,035,774 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\P100416_Pete Carpenter_portal-1 (2).jpg
[2010/05/23 13:32:10 | 000,026,112 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\John Muir.doc
[2010/05/09 09:16:51 | 000,019,968 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Friendship.doc
[2010/05/02 14:48:34 | 000,000,000 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\jagex__preferences3.dat
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/26 15:58:12 | 000,256,512 | —- | M] () – C:\WINDOWS\PEV.exe
[2010/04/04 12:40:33 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/03/29 08:40:32 | 000,332,800 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Employment Application.doc
[2010/03/28 16:37:16 | 000,019,968 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Summer Party.doc
[2010/03/24 21:15:42 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/03/17 18:52:11 | 000,187,904 | —- | M] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Meaghan's Business 3.doc

========== Files Created - No Company Name ==========

[2010/06/13 20:11:17 | 000,071,798 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\JavaRa.zip
[2010/06/12 22:27:45 | 534,925,312 | -HS- | C] () – C:\hiberfil.sys
[2010/06/11 11:03:44 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/06/11 11:03:37 | 000,260,272 | —- | C] () – C:\cmldr
[2010/06/11 10:42:41 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/06/11 10:42:41 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/06/11 10:42:41 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/06/11 10:42:41 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/06/11 10:42:41 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/06/11 10:31:30 | 003,706,758 | R— | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\ComboFix.exe
[2010/06/10 19:30:38 | 000,293,376 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\gmer.exe
[2010/06/08 16:25:35 | 000,359,929 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\dds.scr
[2010/06/08 13:59:50 | 000,000,104 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\Desktop\Internet Explorer.lnk
[2010/06/06 21:55:53 | 000,001,641 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Webroot AntiVirus.lnk
[2010/06/05 11:20:56 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/01 17:42:41 | 000,035,774 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\P100416_Pete Carpenter_portal-1 (2).jpg
[2010/05/20 17:15:24 | 000,026,112 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\John Muir.doc
[2010/05/09 09:16:51 | 000,019,968 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Friendship.doc
[2010/05/02 14:48:34 | 000,000,000 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\jagex__preferences3.dat
[2010/03/29 06:28:21 | 000,332,800 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Employment Application.doc
[2010/03/28 16:37:15 | 000,019,968 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Summer Party.doc
[2010/03/24 20:36:15 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/03/17 18:52:09 | 000,187,904 | —- | C] () – C:\Documents and Settings\Tracey Carpenter\My Documents\Meaghan's Business 3.doc
[2009/11/06 12:00:28 | 000,031,088 | —- | C] () – C:\WINDOWS\System32\wrLZMA.dll
[2008/02/02 17:05:50 | 000,000,074 | —- | C] () – C:\WINDOWS\TaxACT07.ini
[2008/01/01 18:31:27 | 000,153,104 | —- | C] () – C:\WINDOWS\System32\drivers\tmcomm.sys
[2008/01/01 18:31:27 | 000,050,192 | —- | C] () – C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2008/01/01 18:31:27 | 000,050,192 | —- | C] () – C:\WINDOWS\System32\drivers\tmactmon.sys
[2007/03/13 19:20:47 | 000,001,214 | —- | C] () – C:\WINDOWS\Sdcache.ini
[2007/03/13 19:20:41 | 000,002,679 | —- | C] () – C:\WINDOWS\System32\SDUSBPDR.INI
[2007/03/13 19:16:10 | 000,002,204 | —- | C] () – C:\WINDOWS\System32\drivers\UNINST2K.SYS
[2007/02/03 18:31:54 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2007/02/03 18:30:04 | 000,000,054 | —- | C] () – C:\WINDOWS\System32\EAL32.INI
[2007/02/03 18:28:50 | 000,000,044 | —- | C] () – C:\WINDOWS\EPCX6000.ini
[2005/11/13 16:39:42 | 000,000,565 | —- | C] () – C:\WINDOWS\hegames.ini
[2005/06/19 18:44:44 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2005/04/01 16:52:37 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/03/24 19:23:32 | 000,000,029 | —- | C] () – C:\WINDOWS\RRK.INI
[2005/01/26 14:53:29 | 000,000,008 | —- | C] () – C:\WINDOWS\System32\PdSACKey.sys
[2005/01/21 20:11:50 | 000,000,159 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2005/01/08 14:39:17 | 000,000,814 | —- | C] () – C:\WINDOWS\dellstat.ini
[2005/01/04 22:31:46 | 000,031,917 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2004/12/31 12:20:10 | 000,000,190 | —- | C] () – C:\WINDOWS\disneysy.ini
[2004/12/31 10:26:16 | 000,000,165 | —- | C] () – C:\WINDOWS\ka.ini
[2004/12/26 11:02:49 | 000,000,050 | —- | C] () – C:\WINDOWS\upst.ini
[2004/12/26 11:02:49 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2004/12/25 18:34:22 | 000,000,191 | —- | C] () – C:\WINDOWS\QTW.INI
[2004/12/25 18:02:13 | 000,001,622 | —- | C] () – C:\WINDOWS\disney.ini
[2004/12/04 02:38:04 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/12/04 02:32:34 | 000,000,264 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/12/04 02:26:45 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/12/04 01:57:50 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/09/16 00:03:14 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 15:13:12 | 000,000,780 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/04 07:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[1980/01/01 02:00:00 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[1980/01/01 02:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2006/12/14 19:33:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2008/01/01 18:33:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2008/12/25 15:26:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2010/03/06 09:27:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/06/08 14:05:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2009/10/29 20:33:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SwiftKit
[2008/07/12 15:43:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/01/01 16:40:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/12/25 12:48:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2006/06/16 18:30:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Aim
[2009/02/04 07:33:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\GetRightToGo
[2008/12/25 15:24:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\HotSync
[2008/02/15 21:38:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Jasc
[2004/12/25 17:46:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Leadertech
[2006/06/16 08:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\MSNInstaller
[2010/03/06 09:27:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\PlayFirst
[2008/10/25 12:22:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\SPORE
[2007/03/09 21:49:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Tracey Carpenter\Application Data\Viewpoint

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:17639624
< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI