Here you go. I had run an earlier run of OLT before posting. At that time it posted an extras.txt log. After running TDSSKiller and combofix and then running OLT again, I got a new OLT.txt log, but no new Extras.txt log. Do you need to see the old one? Here is the complete OLT.txt log
OTL logfile created on: 7/7/2010 5:13:35 PM - Run 2
OTL by OldTimer - Version 3.2.7.1 Folder = C:\Documents and Settings\harrisap\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 95.01 Gb Free Space | 63.74% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: 7-51896
Current User Name: harrisap
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/07/07 15:34:35 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\harrisap\Desktop\OTL.exe
PRC - [2009/11/13 07:31:14 | 000,092,008 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2009/11/13 07:31:12 | 000,247,144 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2009/06/08 16:38:17 | 000,056,680 | ---- | M] (Absolute Software Corp.) -- C:\WINDOWS\system32\rpcnet.exe
PRC - [2009/05/14 11:43:12 | 000,118,784 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2009/05/14 11:34:22 | 000,057,344 | ---- | M] () -- C:\WINDOWS\system32\ibmpmsvc.exe
PRC - [2009/04/17 12:08:26 | 000,032,768 | ---- | M] (Eastman Kodak Company) -- C:\Program Files\Kodak\AiO\Center\KodakSvc.exe
PRC - [2009/04/07 17:27:30 | 001,511,424 | ---- | M] (Eastman Kodak Company) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
PRC - [2008/10/20 11:36:40 | 000,028,672 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\System Update\SUService.exe
PRC - [2008/08/05 17:58:52 | 029,184,016 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
PRC - [2008/06/04 09:51:06 | 000,262,784 | ---- | M] (F5 Networks) -- C:\WINDOWS\system32\F5InstallerService.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/03/04 11:34:20 | 000,487,424 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
PRC - [2008/03/04 11:34:12 | 001,122,304 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
PRC - [2007/12/21 14:30:40 | 000,131,072 | ---- | M] (Visioneer Inc.) -- C:\Program Files\Visioneer\OneTouch 4.0\OtService.exe
PRC - [2007/10/07 21:48:40 | 000,125,368 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\VPTray.exe
PRC - [2007/10/07 21:48:36 | 000,116,664 | ---- | M] (symantec) -- C:\Program Files\Symantec AntiVirus\SavRoam.exe
PRC - [2007/10/07 21:48:32 | 001,822,648 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe
PRC - [2007/10/07 21:48:24 | 000,031,160 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe
PRC - [2007/09/26 18:34:46 | 000,644,408 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
PRC - [2007/07/26 20:25:20 | 001,181,016 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
PRC - [2007/05/29 17:33:36 | 000,169,576 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PRC - [2007/05/29 17:33:26 | 000,192,104 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PRC - [2007/05/29 17:33:22 | 000,052,840 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2007/02/10 05:29:56 | 000,089,968 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2005/12/01 08:35:58 | 000,057,393 | ---- | M] (IBM Corp) -- C:\Notes\ntmulti.exe
PRC - [2004/08/04 04:05:00 | 000,570,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\CCM\CcmExec.exe
========== Modules (SafeList) ==========
MOD - [2010/07/07 15:34:35 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\harrisap\Desktop\OTL.exe
MOD - [2008/04/13 20:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\TFEngine\TFService.exe -- (ThreatFire)
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2009/11/13 07:31:14 | 000,092,008 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2009/06/08 16:38:17 | 000,056,680 | ---- | M] (Absolute Software Corp.) [Auto | Running] -- C:\WINDOWS\system32\rpcnet.exe -- (rpcnet) Remote Procedure Call (RPC)
SRV - [2009/05/14 11:34:22 | 000,057,344 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\ibmpmsvc.exe -- (IBMPMSVC)
SRV - [2009/05/04 12:15:26 | 000,279,960 | ---- | M] (Eastman Kodak Company) [Auto | Stopped] -- C:\Program Files\Kodak\AiO\Center\EKDiscovery.exe -- (Kodak AiO Network Discovery Service)
SRV - [2009/04/17 12:08:26 | 000,032,768 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\Program Files\Kodak\AiO\center\KodakSvc.exe -- (KodakSvc)
SRV - [2008/10/20 11:36:40 | 000,028,672 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2008/08/05 17:58:52 | 029,184,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$XACTWARE) SQL Server (XACTWARE)
SRV - [2008/06/04 09:51:06 | 000,262,784 | ---- | M] (F5 Networks) [Auto | Running] -- C:\WINDOWS\system32\F5InstallerService.exe -- (F5 Networks Component Installer)
SRV - [2008/03/04 11:34:12 | 001,122,304 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe -- (TVT Scheduler)
SRV - [2007/12/21 14:30:40 | 000,131,072 | ---- | M] (Visioneer Inc.) [Auto | Running] -- C:\Program Files\Visioneer\OneTouch 4.0\OtService.exe -- (OneTouch 4.0 Monitor)
SRV - [2007/10/07 21:48:36 | 000,116,664 | ---- | M] (symantec) [Auto | Running] -- C:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam)
SRV - [2007/10/07 21:48:32 | 001,822,648 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2007/10/07 21:48:24 | 000,031,160 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch)
SRV - [2007/09/26 18:34:46 | 000,644,408 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service)
SRV - [2007/08/28 20:04:25 | 002,999,664 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate)
SRV - [2007/08/27 18:14:00 | 000,214,408 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc)
SRV - [2007/07/26 20:25:20 | 001,181,016 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc)
SRV - [2007/05/29 17:33:36 | 000,169,576 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr)
SRV - [2007/05/29 17:33:26 | 000,192,104 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr)
SRV - [2007/02/10 09:29:47 | 000,242,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser)
SRV - [2007/02/10 05:29:56 | 000,089,968 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2005/12/01 08:35:58 | 000,057,393 | ---- | M] (IBM Corp) [Auto | Running] -- C:\Notes\ntmulti.exe -- (Multi-user Cleanup Service)
SRV - [2005/10/14 06:50:19 | 000,045,272 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper)
SRV - [2004/08/04 04:05:00 | 000,570,368 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\CCM\CcmExec.exe -- (CcmExec)
SRV - [2000/10/19 12:55:50 | 000,411,244 | ---- | M] () [On_Demand | Stopped] -- C:\oracle\ora81\bin\ONRSD.EXE -- (OracleOraHome81ClientCache)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\usbaapl.sys -- (USBAAPL)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\TfSysMon.sys -- (TfSysMon)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\TfNetMon.sys -- (TfNetMon)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\TfFsMon.sys -- (TfFsMon)
DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2010/07/07 16:39:50 | 000,003,456 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\atiide.sys -- (atiide)
DRV - [2010/05/27 04:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2010/05/27 04:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010/05/11 04:00:00 | 001,347,504 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100706.004\navex15.sys -- (NAVEX15)
DRV - [2010/05/11 04:00:00 | 000,085,552 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100706.004\naveng.sys -- (NAVENG)
DRV - [2009/10/09 23:15:18 | 000,033,920 | ---- | M] (F5 Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\covpndrv.sys -- (urvpndrv)
DRV - [2009/10/09 23:15:13 | 000,010,752 | ---- | M] (F5 Networks) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\urfltw2k.sys -- (f5ipfw)
DRV - [2009/05/14 11:43:44 | 000,328,728 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\iaStor.sys -- (iastor)
DRV - [2009/05/14 11:43:10 | 000,225,664 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2009/05/14 11:43:09 | 000,985,472 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2009/05/14 11:43:09 | 000,764,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CHDAU32.sys -- (CnxtHdAudService)
DRV - [2009/05/14 11:43:09 | 000,210,560 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2009/05/14 11:43:09 | 000,013,824 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tpm.sys -- (tpm)
DRV - [2009/05/14 11:43:08 | 000,731,264 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2009/05/14 11:42:46 | 000,040,832 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HECI.sys -- (HECI) Intel®
DRV - [2009/05/14 11:42:43 | 003,103,232 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2009/05/14 11:41:43 | 003,630,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw5x32.sys -- (NETw5x32) Intel®
DRV - [2009/05/14 11:41:40 | 000,243,856 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1y5132.sys -- (e1yexpress) Intel®
DRV - [2009/05/14 11:41:37 | 000,047,272 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2009/05/14 11:41:36 | 000,475,520 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATSwpWDF.sys -- (ATSwpWDF)
DRV - [2009/05/14 11:34:22 | 000,012,944 | ---- | M] (IBM Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ibmpmdrv.sys -- (IBMPMDRV)
DRV - [2009/03/20 20:03:36 | 000,032,408 | ---- | M] (Smith Micro Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Verizon Wireless\VZAccess Manager\SMSIVZAM5.sys -- (SMSIVZAM5)
DRV - [2008/07/07 13:23:56 | 000,020,480 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NwUsbCdFil.sys -- (NWUSBCDFIL)
DRV - [2008/06/02 17:28:50 | 000,222,720 | ---- | M] (Novatel Wireless Inc) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NWADIenum.sys -- (NWADI)
DRV - [2008/05/09 12:08:40 | 000,174,336 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nwusbser2.sys -- (NWUSBPort2)
DRV - [2008/05/09 12:08:40 | 000,174,336 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nwusbser.sys -- (NWUSBPort)
DRV - [2008/05/09 12:08:40 | 000,174,336 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nwusbmdm.sys -- (NWUSBModem)
DRV - [2008/04/13 12:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/12/26 10:49:59 | 000,110,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2007/08/27 18:13:36 | 000,189,320 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2007/08/27 18:13:32 | 000,023,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2007/07/26 20:25:18 | 000,400,216 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2007/02/19 01:56:46 | 000,021,376 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\psadd.sys -- (psadd)
DRV - [2006/09/06 15:41:20 | 000,337,592 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Symantec AntiVirus\savrt.sys -- (SAVRT)
DRV - [2006/09/06 15:41:20 | 000,054,968 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL)
DRV - [2004/06/27 03:50:00 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\CCM\PrepDrv.sys -- (prepdrvr)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
IE - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
FF - HKLM\software\mozilla\Firefox\Extensions\\{08B8D53F-FB61-4EC8-8614-ECA2133A48D4}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{08B8D53F-FB61-4EC8-8614-ECA2133A48D4}\ [2010/07/02 12:22:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{7F407392-4F54-4B22-B018-7C448707CE31}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{7F407392-4F54-4B22-B018-7C448707CE31}\ [2010/07/02 13:46:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A4423967-0FE1-45A0-A02F-24676A38EC26}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{A4423967-0FE1-45A0-A02F-24676A38EC26}\ [2010/07/02 14:36:53 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{656599F9-402B-4ABD-B3DD-B465296C0D22}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{656599F9-402B-4ABD-B3DD-B465296C0D22}\ [2010/07/02 14:39:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2DE55286-1FBD-4B5E-A2FD-A80A0E7026AF}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{2DE55286-1FBD-4B5E-A2FD-A80A0E7026AF}\ [2010/07/03 08:50:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{9DA59007-FBFE-4153-8AF3-F9C396AC0403}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{9DA59007-FBFE-4153-8AF3-F9C396AC0403}\ [2010/07/03 09:01:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A19F0325-B322-4DC2-97B2-521B259F25C5}: C:\Documents and Settings\Administrator\Local Settings\Application Data\{A19F0325-B322-4DC2-97B2-521B259F25C5}\ [2010/07/03 12:02:49 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{1A8548C6-50F1-463B-9802-225F5F94F67F}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{1A8548C6-50F1-463B-9802-225F5F94F67F}\ [2010/07/03 13:29:40 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBD154CF-3450-438A-A1ED-432C3082042C}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{BBD154CF-3450-438A-A1ED-432C3082042C}\ [2010/07/06 16:32:19 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{CCCB28FC-4068-4917-96E5-3983EF42704B}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{CCCB28FC-4068-4917-96E5-3983EF42704B}\ [2010/07/07 07:39:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6512AF10-2BD9-4242-83CE-3086EA813335}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{6512AF10-2BD9-4242-83CE-3086EA813335}\ [2010/07/07 07:44:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{95ADF2BD-4B22-46D3-AFE6-4E78ABE2E962}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{95ADF2BD-4B22-46D3-AFE6-4E78ABE2E962}\ [2010/07/07 07:46:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{4B5AF1D8-7AA8-4B62-B2F7-6F370DD89CAB}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{4B5AF1D8-7AA8-4B62-B2F7-6F370DD89CAB}\ [2010/07/07 09:42:40 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{DE5B9F1B-D5DE-4F59-9D5B-E2CAA777EF01}: C:\Documents and Settings\Administrator\Local Settings\Application Data\{DE5B9F1B-D5DE-4F59-9D5B-E2CAA777EF01}\ [2010/07/07 09:43:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{0A61CEF3-C718-4B50-889F-5D23F129ACCB}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{0A61CEF3-C718-4B50-889F-5D23F129ACCB}\ [2010/07/07 09:47:45 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{8D783363-3AE6-4CDD-B954-3B2301C786C7}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{8D783363-3AE6-4CDD-B954-3B2301C786C7}\ [2010/07/07 09:53:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{588A3060-1F7E-4B99-88A4-3A1C6BA0322E}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{588A3060-1F7E-4B99-88A4-3A1C6BA0322E}\ [2010/07/07 11:27:14 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3437F035-FDD2-4241-9294-7F0F1BB28DAB}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{3437F035-FDD2-4241-9294-7F0F1BB28DAB}\ [2010/07/07 11:36:41 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{F815F000-7EE3-4952-B739-09F30DAB8CE3}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{F815F000-7EE3-4952-B739-09F30DAB8CE3}\ [2010/07/07 12:15:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{AE76301C-C986-4B42-8668-AC7A26389266}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{AE76301C-C986-4B42-8668-AC7A26389266}\ [2010/07/07 12:24:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B4379ACC-5F74-456A-A7EE-ECB02CBD8B7D}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{B4379ACC-5F74-456A-A7EE-ECB02CBD8B7D}\ [2010/07/07 15:27:31 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{186FE95C-BF73-4B29-8447-ED6E2D4837EF}: C:\Documents and Settings\harrisap\Local Settings\Application Data\{186FE95C-BF73-4B29-8447-ED6E2D4837EF}\ [2010/07/07 16:46:52 | 000,000,000 | ---D | M]
[2010/04/24 17:44:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\harrisap\Application Data\Mozilla\Extensions
[2010/04/24 17:44:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\harrisap\Application Data\Mozilla\Extensions\home2@tomtom.com
O1 HOSTS File: ([2010/07/07 17:01:31 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hp\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hp\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Conime] C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [pdfFactory Dispatcher v3] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)
O4 - HKLM..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O7 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hp\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O15 - HKU\.DEFAULT\..Trusted Domains: adp.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: centra.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: Clientelligent.com ([]* in My Computer)
O15 - HKU\.DEFAULT\..Trusted Domains: dhl-usa.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: employeeedge.com ([]* in My Computer)
O15 - HKU\.DEFAULT\..Trusted Domains: eyeadvisor.com ([]* in My Computer)
O15 - HKU\.DEFAULT\..Trusted Domains: gabrobins.com ([]* in My Computer)
O15 - HKU\.DEFAULT\..Trusted Domains: gabrobinsna.com ([]* in My Computer)
O15 - HKU\.DEFAULT\..Trusted Domains: genesyshcm.com ([]* in My Computer)
O15 - HKU\.DEFAULT\..Trusted Domains: learn.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: microsoft.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: mygabr.com ([]* in My Computer)
O15 - HKU\.DEFAULT\..Trusted Domains: virtela.net ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: windowsupdate.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: adp.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: centra.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: Clientelligent.com ([]* in My Computer)
O15 - HKU\S-1-5-18\..Trusted Domains: dhl-usa.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: employeeedge.com ([]* in My Computer)
O15 - HKU\S-1-5-18\..Trusted Domains: eyeadvisor.com ([]* in My Computer)
O15 - HKU\S-1-5-18\..Trusted Domains: gabrobins.com ([]* in My Computer)
O15 - HKU\S-1-5-18\..Trusted Domains: gabrobinsna.com ([]* in My Computer)
O15 - HKU\S-1-5-18\..Trusted Domains: genesyshcm.com ([]* in My Computer)
O15 - HKU\S-1-5-18\..Trusted Domains: learn.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: microsoft.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: mygabr.com ([]* in My Computer)
O15 - HKU\S-1-5-18\..Trusted Domains: virtela.net ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: windowsupdate.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: adp.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: centra.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: Clientelligent.com ([]* in My Computer)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: dhl-usa.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: employeeedge.com ([]* in My Computer)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: eyeadvisor.com ([]* in My Computer)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: gabrobins.com ([]* in My Computer)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: gabrobinsna.com ([]* in My Computer)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: genesyshcm.com ([]* in My Computer)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: learn.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: microsoft.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: mygabr.com ([]* in My Computer)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: virtela.net ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2187378860-2228663326-329466524-1014\..Trusted Domains: windowsupdate.com ([]* in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.micros...tes/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/pub/shock...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2BCDB465-81F9-41CB-832C-8037A4064446}
https://gabrobins1.clnt.virtela.net/vdesk/t...1,2009,1010,313 (F5 Networks VPN Manager)
O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944}
http://www-307.ibm.c...pport/acpir.cab (IASRunner Class)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325}
http://uspsy16m.gabr...om/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E}
https://gabrobins1.clnt.virtela.net/vdesk/t...1,2009,1010,310 (F5 Networks Dynamic Application Tunnel Control)
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74}
https://gabrobins1.clnt.virtela.net/vdesk/t...,2009,1010,0312 (F5 Networks Auto Update)
O16 - DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} file://C:/Program Files/F5 VPN/F5_TMP/f5InspectionHost.cab (F5 Networks Policy Agent Host Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/microsoftupdat...b?1228492840640 (WUWebControl Class)
O16 - DPF: {68132570-CED6-11D5-91AE-000039F5040E}
http://www.employeee...m/NAVUPDPRJ.CAB (NAVUPDPRJ.NAVUPDCTL)
O16 - DPF: {6C275925-A1ED-4DD2-9CEE-9823F5FDAA10}
https://gabrobins1.clnt.virtela.net/vdesk/t...,2008,0404,2134 (F5 Networks Static Application Tunnel Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat...b?1228491044515 (MUWebControl Class)
O16 - DPF: {7584c670-2274-4efb-b00b-d6aaba6d3850} file://C:/Program Files/F5 VPN/F5_TMP/msrdp.cab (Microsoft RDP Client Control (redist))
O16 - DPF: {7E73BE8F-FD87-44EC-8E22-023D5FF960FF} file://C:/Program Files/F5 VPN/F5_TMP/vdeskctrl.cab (F5 Virtual Sandbox Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.0...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://javadl-esd.sun.com/update/1.6.0/jin...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D}
http://h20264.www2.hp.com/ediags/dd/instal...nosticsxp2k.cab (DDRevision Class)
O16 - DPF: {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7}
https://gabrobins1.clnt.virtela.net/vdesk/t...1,2009,1010,308 (F5 Networks SuperHost Class)
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2}
https://gabrobins1.clnt.virtela.net/vdesk/t...1,2009,1010,304 (F5 Networks Host Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E66D35B8-E70D-42A6-B1F5-DB784CB92B15} file://C:/Program Files/F5 VPN/F5_TMP/urvncx.cab (URVNCX Class)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 97.64.180.150 97.64.168.13
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = GABNA-AD.local
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop BackupWallPaper: C:\Documents and Settings\harrisap\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/15 12:50:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: aux - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: VIDC.MP42 - C:\WINDOWS\System32\MPG4C32.DLL (Microsoft Corporation)
Drivers32: VIDC.MPG4 - C:\WINDOWS\System32\MPG4C32.DLL (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/07/07 16:52:34 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/07/07 16:52:34 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/07/07 16:52:34 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/07/07 16:52:34 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/07/07 16:52:10 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/07/07 16:46:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{186FE95C-BF73-4B29-8447-ED6E2D4837EF}
[2010/07/07 16:37:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Desktop\tdsskiller
[2010/07/07 15:34:32 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\harrisap\Desktop\OTL.exe
[2010/07/07 15:27:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{B4379ACC-5F74-456A-A7EE-ECB02CBD8B7D}
[2010/07/07 12:24:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{AE76301C-C986-4B42-8668-AC7A26389266}
[2010/07/07 12:15:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{F815F000-7EE3-4952-B739-09F30DAB8CE3}
[2010/07/07 11:46:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{8CF5B7FA-F366-49EA-AA98-61AB007901F4}
[2010/07/07 11:43:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2010/07/07 11:36:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{3437F035-FDD2-4241-9294-7F0F1BB28DAB}
[2010/07/07 11:27:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{588A3060-1F7E-4B99-88A4-3A1C6BA0322E}
[2010/07/07 10:02:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Application Data\Malwarebytes
[2010/07/07 10:02:37 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/07 10:02:36 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/07 10:02:36 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/07 10:02:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/07/07 10:01:24 | 006,153,384 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\harrisap\Desktop\mbam-setup.exe
[2010/07/07 09:53:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{8D783363-3AE6-4CDD-B954-3B2301C786C7}
[2010/07/07 09:47:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{0A61CEF3-C718-4B50-889F-5D23F129ACCB}
[2010/07/07 09:42:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{4B5AF1D8-7AA8-4B62-B2F7-6F370DD89CAB}
[2010/07/07 09:04:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/07/07 09:04:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/07/07 07:46:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{95ADF2BD-4B22-46D3-AFE6-4E78ABE2E962}
[2010/07/07 07:44:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{6512AF10-2BD9-4242-83CE-3086EA813335}
[2010/07/07 07:39:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{CCCB28FC-4068-4917-96E5-3983EF42704B}
[2010/07/06 16:32:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{BBD154CF-3450-438A-A1ED-432C3082042C}
[2010/07/03 21:29:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Yahoo
[2010/07/03 13:39:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/07/03 13:38:30 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/07/03 13:37:50 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\harrisap\Desktop\erunt_setup.exe
[2010/07/03 13:28:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{1A8548C6-50F1-463B-9802-225F5F94F67F}
[2010/07/03 11:59:12 | 000,444,416 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\harrisap\Desktop\TFC.exe
[2010/07/03 09:01:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{9DA59007-FBFE-4153-8AF3-F9C396AC0403}
[2010/07/03 08:50:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{2DE55286-1FBD-4B5E-A2FD-A80A0E7026AF}
[2010/07/02 14:39:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{656599F9-402B-4ABD-B3DD-B465296C0D22}
[2010/07/02 14:36:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{A4423967-0FE1-45A0-A02F-24676A38EC26}
[2010/07/02 13:46:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{7F407392-4F54-4B22-B018-7C448707CE31}
[2010/07/02 12:22:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\{08B8D53F-FB61-4EC8-8614-ECA2133A48D4}
[2010/07/02 12:20:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\rkjjhtfvy
[2010/07/01 16:32:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\My Documents\My Albums
[2010/07/01 16:25:04 | 000,000,000 | ---D | C] -- C:\Program Files\WebEx
[2010/06/28 18:06:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Desktop\xact25 data
[2010/06/27 15:44:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\Threat Expert
[2010/06/27 15:10:19 | 001,652,688 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDCore.dll.old
[2010/06/27 15:04:22 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2010/06/27 15:04:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Tools
[2010/06/27 15:03:16 | 036,600,008 | ---- | C] (PC Tools ) -- C:\Documents and Settings\harrisap\Desktop\sdasetup.exe
[2010/06/26 20:55:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Local Settings\Application Data\kybocnbxw
[2010/06/24 16:20:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\Desktop\ranger
[2010/06/18 11:04:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\My Documents\PDF files
[2010/06/18 09:09:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\My Documents\Xactimate25 Office Templates
[2010/06/18 08:29:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\harrisap\My Documents\other folders
[2010/06/12 16:03:13 | 000,410,984 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
[2010/06/12 16:03:13 | 000,148,888 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/06/12 16:03:13 | 000,144,792 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/06/12 16:03:13 | 000,144,792 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/06/12 16:03:13 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010/06/12 16:02:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
========== Files - Modified Within 30 Days ==========
[2010/07/07 17:09:00 | 000,000,890 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/07 17:05:35 | 000,000,455 | ---- | M] () -- C:\WINDOWS\SMSCFG.ini
[2010/07/07 17:04:40 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/07/07 17:01:48 | 000,017,408 | ---- | M] () -- C:\WINDOWS\System32\rpcnetp.exe
[2010/07/07 17:01:45 | 000,056,680 | ---- | M] (Absolute Software Corp.) -- C:\WINDOWS\System32\rpcnet.dll
[2010/07/07 17:01:43 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/07/07 17:01:31 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/07/07 17:01:23 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/07 17:01:15 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/07/07 17:01:14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/07/07 16:59:49 | 006,029,312 | -H-- | M] () -- C:\Documents and Settings\harrisap\ntuser.dat
[2010/07/07 16:59:49 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\harrisap\ntuser.ini
[2010/07/07 16:49:45 | 003,728,027 | R--- | M] () -- C:\Documents and Settings\harrisap\Desktop\ComboFix.exe
[2010/07/07 16:39:50 | 000,003,456 | ---- | M] () -- C:\WINDOWS\System32\drivers\atiide.sys
[2010/07/07 16:37:12 | 000,981,780 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\tdsskiller.zip
[2010/07/07 15:34:35 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\harrisap\Desktop\OTL.exe
[2010/07/07 14:56:50 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Wbovete.dat
[2010/07/07 12:15:40 | 000,017,408 | ---- | M] () -- C:\WINDOWS\System32\rpcnetp.dll
[2010/07/07 11:30:38 | 000,284,915 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\gmer.zip
[2010/07/07 10:13:33 | 000,026,112 | ---- | M] () -- C:\Documents and Settings\harrisap\My Documents\Malwarebyteslog.doc
[2010/07/07 10:02:39 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/07 10:01:24 | 006,153,384 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\harrisap\Desktop\mbam-setup.exe
[2010/07/07 07:44:28 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Pjepezejohera.bin
[2010/07/06 16:59:33 | 000,171,171 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\expense76.pdf
[2010/07/06 16:58:29 | 001,043,073 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\expe 004.jpg
[2010/07/06 16:57:59 | 001,023,142 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\expe 003.jpg
[2010/07/06 16:57:32 | 001,055,982 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\expe 002.jpg
[2010/07/06 16:35:24 | 000,000,238 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Virtella SSL.url
[2010/07/06 16:23:21 | 000,152,384 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/06 10:40:30 | 000,000,732 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.bak
[2010/07/06 08:32:12 | 000,032,747 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\APP.doc
[2010/07/03 13:38:31 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\NTREGOPT.lnk
[2010/07/03 13:38:31 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\ERUNT.lnk
[2010/07/03 13:37:53 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\harrisap\Desktop\erunt_setup.exe
[2010/07/03 11:59:15 | 000,444,416 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\harrisap\Desktop\TFC.exe
[2010/07/02 06:32:55 | 000,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/07/02 06:25:22 | 000,569,786 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/02 06:25:22 | 000,489,682 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/07/02 06:25:22 | 000,089,502 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/07/01 22:09:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/30 00:05:59 | 004,844,096 | -H-- | M] () -- C:\Documents and Settings\harrisap\Local Settings\Application Data\IconCache.db
[2010/06/29 09:24:32 | 001,519,151 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\UPWARD FLAG FOOTBALL.pdf
[2010/06/28 19:16:33 | 000,001,862 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Xactimate 25.lnk
[2010/06/28 18:04:31 | 051,193,881 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\25.4.256.35490_Update.exe
[2010/06/27 15:03:16 | 036,600,008 | ---- | M] (PC Tools ) -- C:\Documents and Settings\harrisap\Desktop\sdasetup.exe
[2010/06/26 22:57:35 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\harrisap\Desktop\~$lendar.doc
[2010/06/25 23:26:50 | 000,049,664 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\calendar.doc
[2010/06/24 16:49:12 | 000,464,115 | ---- | M] () -- C:\Documents and Settings\harrisap\My Documents\InterContinental Hotels Group Your Reservation Confirmation.mht
[2010/06/23 15:38:58 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\harrisap\My Documents\44155.doc
[2010/06/18 02:07:00 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/06/16 14:47:46 | 000,163,647 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\HO3_sample.pdf
[2010/06/16 12:28:03 | 000,002,219 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\GAB SSL.lnk
[2010/06/12 16:02:59 | 000,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/06/12 16:02:59 | 000,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/06/12 16:02:58 | 000,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
[2010/06/12 16:02:58 | 000,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/06/12 16:02:58 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010/06/11 08:57:29 | 000,052,224 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\LETTERHEAD.doc
[2010/06/09 20:30:39 | 000,014,999 | ---- | M] () -- C:\Documents and Settings\harrisap\Desktop\www.martindale.com_print_sbs.aspx.pdf
========== Files Created - No Company Name ==========
[2010/07/07 16:52:34 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/07/07 16:52:34 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/07/07 16:52:34 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/07/07 16:52:34 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/07/07 16:52:34 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/07/07 16:49:39 | 003,728,027 | R--- | C] () -- C:\Documents and Settings\harrisap\Desktop\ComboFix.exe
[2010/07/07 16:36:57 | 000,981,780 | ---- | C] () -- C:\Documents and Settings\harrisap\Desktop\tdsskiller.zip
[2010/07/07 11:30:34 | 000,284,915 | ---- | C] () -- C:\Documents and Settings\harrisap\Desktop\gmer.zip
[2010/07/07 10:13:32 | 000,026,112 | ---- | C] () -- C:\Documents and Settings\harrisap\My Documents\Malwarebyteslog.doc
[2010/07/07 10:02:39 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/06 16:59:32 | 000,171,171 | ---- | C] () -- C:\Documents and Settings\harrisap\Desktop\expense76.pdf
[2010/07/06 16:57:59 | 001,043,073 | ---- | C] () -- C:\Documents and Settings\harrisap\Desktop\expe 004.jpg
[2010/07/06 16:57:32 | 001,023,142 | ---- | C] () -- C:\Documents and Settings\harrisap\Desktop\expe 003.jpg
[2010/07/06 16:57:04 | 001,055,982 | ---- | C] () -- C:\Documents and Settings\harrisap\Desktop\expe 002.jpg
[2010/07/03 13:38:31 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\harrisap\Desktop\NTREGOPT.lnk
[2010/07/03 13:38:31 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\harrisap\Desktop\ERUNT.lnk
[2010/07/02 12:22:55 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Pjepezejohera.bin
[2010/07/02 12:22:54 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Wbovete.dat
[2010/06/29 09:24:32 | 001,519,151 | ---- | C] () -- C:\Documents and Settings\harrisap\Desktop\UPWARD FLAG FOOTBALL.pdf
[2010/06/28 18:04:28 | 051,193,881 | ---- | C] () -- C:\Documents and Settings\harrisap\Desktop\25.4.256.35490_Update.exe
[2010/06/27 15:10:20 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll.old
[2010/06/26 22:57:35 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\harrisap\Desktop\~$lendar.doc
[2010/06/24 16:49:12 | 000,464,115 | ---- | C] () -- C:\Documents and Settings\harrisap\My Documents\InterContinental Hotels Group Your Reservation Confirmation.mht
[2010/06/23 15:38:57 | 000,024,064 | ---- | C] () -- C:\Documents and Settings\harrisap\My Documents\44155.doc
[2010/06/16 14:47:46 | 000,163,647 | ---- | C] () -- C:\Documents and Settings\harrisap\Desktop\HO3_sample.pdf
[2010/06/11 08:57:29 | 000,052,224 | ---- | C] () -- C:\Documents and Settings\harrisap\Desktop\LETTERHEAD.doc
[2010/06/09 20:30:39 | 000,014,999 | ---- | C] () -- C:\Documents and Settings\harrisap\Desktop\www.martindale.com_print_sbs.aspx.pdf
[2010/02/22 22:18:36 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/02/22 22:18:36 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/12/17 06:48:09 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\DM510.dll
[2009/08/30 22:46:45 | 000,012,800 | ---- | C] () -- C:\WINDOWS\System32\EKDeviceServices.dll
[2009/05/14 11:37:14 | 000,003,456 | ---- | C] () -- C:\WINDOWS\System32\drivers\atiide.sys
[2009/05/14 11:34:22 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\tpinspm.dll
[2008/03/18 11:58:05 | 000,000,058 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2007/12/26 12:18:32 | 000,000,455 | ---- | C] () -- C:\WINDOWS\SMSCFG.ini
[2007/11/28 15:39:06 | 000,000,029 | ---- | C] () -- C:\WINDOWS\vdialer.INI
[2007/11/28 12:12:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2007/11/16 15:23:19 | 000,003,981 | ---- | C] () -- C:\WINDOWS\RDSWIN.INI
[2007/11/16 12:47:22 | 000,000,033 | ---- | C] () -- C:\WINDOWS\WDTCPCON.INI
[2007/11/16 12:32:18 | 000,003,635 | ---- | C] () -- C:\WINDOWS\~WDINS.INI
[2007/11/16 10:06:19 | 000,000,555 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/11/15 12:58:54 | 000,017,408 | ---- | C] () -- C:\WINDOWS\System32\rpcnetp.dll
[2006/01/26 16:42:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/06/17 01:53:02 | 000,000,702 | ---- | C] () -- C:\WINDOWS\Cm3.ini
[2001/07/07 03:00:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[1999/07/30 09:24:34 | 000,000,218 | ---- | C] () -- C:\WINDOWS\oraodbc.ini
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2007/11/15 12:50:08 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2007/11/15 13:43:43 | 000,000,211 | RHS- | M] () -- C:\BOOT.BAK
[2009/05/27 22:07:00 | 000,000,282 | RHS- | M] () -- C:\boot.ini
[2004/08/04 00:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
[2010/07/07 17:09:39 | 000,021,663 | ---- | M] () -- C:\ComboFix.txt
[2007/11/15 12:50:08 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010/02/03 16:05:05 | 000,000,512 | ---- | M] () -- C:\Disk1.txt
[2007/09/10 10:46:02 | 005,251,072 | ---- | M] (AutoDWG) -- C:\DWG2ImageX.dll
[2009/09/30 13:42:38 | 000,001,296 | ---- | M] () -- C:\EasyCD Ripper_log.txt
[2010/04/09 08:10:53 | 000,006,016 | ---- | M] () -- C:\EZ Dock_log.txt
[2007/11/15 12:50:08 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/08/12 09:37:25 | 000,044,894 | ---- | M] () -- C:\java.txt
[2007/09/10 10:46:02 | 000,995,383 | ---- | M] (Microsoft Corporation) -- C:\MFC42.DLL
[2007/11/15 12:50:08 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/03 23:38:34 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/12/02 13:53:41 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2009/07/27 14:36:51 | 000,262,144 | ---- | M] () -- C:\ntuser.dat
[2009/07/27 14:36:51 | 000,001,024 | -H-- | M] () -- C:\ntuser.dat.LOG
[2010/07/07 17:01:04 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2009/10/19 21:23:10 | 000,003,888 | ---- | M] () -- C:\Player Library_log.txt
[2009/10/19 21:21:47 | 000,005,184 | ---- | M] () -- C:\Player Loader_log.txt
[2010/07/07 16:38:13 | 000,040,758 | ---- | M] () -- C:\TDSSKiller.2.3.2.2_07.07.2010_16.38.02_log.txt
< %systemroot%\system32\*.wt >
< %systemroot%\system32\*.ruy >
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
[2006/02/19 03:28:56 | 000,012,288 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\Fonts\RandFont.dll
< %systemroot%\Fonts\*.ini >
[2007/11/15 12:49:40 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2009/04/07 17:25:30 | 000,192,512 | ---- | M] (Eastman Kodak Company) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\EKIJ5000PPR.dll
[2008/07/06 08:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/02/09 15:43:24 | 000,074,240 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2007/10/20 18:21:50 | 000,278,016 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5mu.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2007/11/15 06:11:12 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2007/11/15 06:11:12 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2007/11/15 06:11:12 | 000,888,832 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\user32.dll /md5 >
[2008/04/13 20:12:08 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B -- C:\WINDOWS\system32\user32.dll
< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/13 20:12:10 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/13 20:12:10 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 -- C:\WINDOWS\system32\ws2help.dll
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"AutoInstallMinorUpdate" = 1
"LastWaitTimeout" = =-
"NoAutoUpdate" = 0
"AUOptions" = 4
"ScheduledInstallDay" = 0
"ScheduledInstallTime" = 5
"UseWUServer" = 1
"RescheduleWaitTimeEnabled" = 1
"RescheduleWaitTime" = 1
"NoAutoRebootWithLoggedOnUsers" = 1
"DetectionFrequencyEnabled" = 1
"DetectionFrequency" = 4
"AutoInstallMinorUpdates" = 1
"RebootWarningTimeoutEnabled" = 1
"RebootWarningTimeout" = 5
"AUPowerManagement" = 1
"NoAUAsDefaultShutdownOption" = 1
"NoAUShutdownOption" = 1
"RebootRelaunchTimeoutEnabled" = 1
"RebootRelaunchTimeout" = 10
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-03 12:55:51
========== Alternate Data Streams ==========
@Alternate Data Stream - 159 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ECF54A0E
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >