OTL logfile created on: 8/14/2010 12:45:50 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\hcistaff\Desktop
Windows XP Tablet PC Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 244.00 Mb Available Physical Memory | 48.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 44.95 Gb Free Space | 80.43% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: 873046LT
Current User Name: hcistaff
NOT logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/08/14 12:21:22 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\hcistaff\Desktop\OTL.exe
PRC - [2010/08/14 10:40:19 | 000,098,304 | ---- | M] () -- C:\Documents and Settings\hcistaff\Application Data\conhost.exe
PRC - [2010/08/14 02:19:41 | 000,059,904 | ---- | M] () -- C:\Documents and Settings\hcistaff\Start Menu\Programs\Startup\csrss.exe
PRC - [2010/08/13 22:51:13 | 000,079,872 | -HS- | M] (Ptuqckg Trbpryd) -- C:\Documents and Settings\hcistaff\Application Data\SystemProc\lsass.exe
PRC - [2008/04/14 05:42:42 | 000,293,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wisptis.exe
PRC - [2008/04/14 05:42:38 | 000,271,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Ink\tabtip.exe
PRC - [2008/04/14 05:42:38 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Ink\tcserver.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/08/02 01:38:30 | 000,802,816 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2006/08/02 01:27:54 | 000,479,232 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2002/08/29 04:41:28 | 000,035,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\tabbtnu.exe
========== Modules (SafeList) ========== MOD - [2010/08/14 12:21:22 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\hcistaff\Desktop\OTL.exe
MOD - [2008/04/14 05:42:08 | 000,250,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ime\sptip.dll
MOD - [2008/04/14 05:42:08 | 000,210,944 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Ink\tiptsf.dll
MOD - [2008/04/14 05:42:08 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Ink\tipcomponentsps.dll
MOD - [2008/04/14 05:42:00 | 000,068,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msctfp.dll
MOD - [2008/04/14 05:40:22 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
MOD - [2008/04/13 23:09:26 | 002,897,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\xpsp2res.dll
MOD - [2008/04/13 22:13:20 | 000,062,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ime\spgrmr.dll
MOD - [2002/08/29 04:41:08 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Journal\nbmaptip.dll
========== Win32 Services (SafeList) ========== ========== Driver Services (SafeList) ========== ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://sslvpn.hamiltoncenter.org/dana-na/auth/url_default/welcome.cgiIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2008/04/14 16:07:40 | 000,000,736 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [000StTHK] C:\WINDOWS\System32\000StTHK.exe ()
O4 - HKLM..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [CrossMenu] C:\Program Files\Toshiba\CrossMenu\CrossMenu.exe (TOSHIBA)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TabletTip] C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe (Microsoft Corporation)
O4 - HKLM..\Run: [TabletWizard] C:\WINDOWS\Help\splshwrp.exe (Microsoft Corporation)
O4 - HKCU..\Run: [RTHDBPL] C:\Documents and Settings\hcistaff\Application Data\SystemProc\lsass.exe (Ptuqckg Trbpryd)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\hcistaff\Start Menu\Programs\Startup\csrss.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Download present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\New Windows present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\SQM present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1207239893781 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1208195572328 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B}
https://sslvpn.hamiltoncenter.org/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupSP1 Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 76.85.229.110 76.85.229.111
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = hamiltoncenter.org
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\loginkey: DllName - C:\Program Files\Common Files\Microsoft Shared\Ink\loginkey.dll - C:\Program Files\Common Files\Microsoft Shared\Ink\loginkey.dll (Microsoft Corporation)
O20 - Winlogon\Notify\TabBtnWL: DllName - TabBtnWL.dll - C:\WINDOWS\System32\tabbtnwl.dll (Microsoft Corporation)
O20 - Winlogon\Notify\tpgwlnotify: DllName - tpgwlnot.dll - C:\WINDOWS\System32\tpgwlnot.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/03 11:27:21 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/08/14 12:13:04 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\hcistaff\Desktop\OTL.exe
[2010/08/14 01:11:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\F-Secure
[2010/08/14 01:07:07 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\hcistaff\Desktop\mbam-setup.exe
[2010/08/14 00:50:04 | 001,870,800 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\hcistaff\Desktop\HousecallLauncher.exe
[2010/08/13 23:49:23 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\hcistaff\Desktop\zztoy.exe
[2010/08/13 23:04:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\hcistaff\Application Data\scdata
[2010/08/13 22:57:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\hcistaff\Application Data\Wireshark Antivirus
[2010/08/13 22:55:29 | 002,089,472 | ---- | C] (Intsys) -- C:\Documents and Settings\hcistaff\Application Data\wshark.exe
[2010/08/13 22:51:19 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\hcistaff\Application Data\SystemProc
[2010/08/12 03:06:13 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2008/04/03 17:02:49 | 000,049,152 | ---- | C] ( ) -- C:\WINDOWS\System32\BrigthDL.dll
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2099/01/01 12:00:00 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/08/14 12:45:23 | 000,000,095 | ---- | M] () -- C:\Documents and Settings\hcistaff\Application Data\sh4.dat
[2010/08/14 12:45:23 | 000,000,001 | ---- | M] () -- C:\Documents and Settings\hcistaff\Application Data\sh3.dat
[2010/08/14 12:45:11 | 000,059,904 | ---- | M] () -- C:\Documents and Settings\hcistaff\Application Data\csrss.exe
[2010/08/14 12:45:11 | 000,002,035 | ---- | M] () -- C:\Documents and Settings\hcistaff\Desktop\Wireshark Antivirus.lnk
[2010/08/14 12:21:22 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\hcistaff\Desktop\OTL.exe
[2010/08/14 10:40:19 | 000,098,304 | ---- | M] () -- C:\Documents and Settings\hcistaff\Application Data\conhost.exe
[2010/08/14 04:22:13 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/08/14 04:22:10 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/08/14 04:21:06 | 002,883,584 | -H-- | M] () -- C:\Documents and Settings\hcistaff\NTUSER.DAT
[2010/08/14 04:21:06 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\hcistaff\ntuser.ini
[2010/08/14 02:19:41 | 000,059,904 | ---- | M] () -- C:\Documents and Settings\hcistaff\Start Menu\Programs\Startup\csrss.exe
[2010/08/14 01:07:15 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\hcistaff\Desktop\mbam-setup.exe
[2010/08/14 00:50:29 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\hcistaff\Local Settings\Application Data\housecall.guid.cache
[2010/08/14 00:50:26 | 001,870,800 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\hcistaff\Desktop\HousecallLauncher.exe
[2010/08/14 00:15:49 | 000,472,064 | ---- | M] ( ) -- C:\Documents and Settings\hcistaff\Desktop\RootRepeal.exe
[2010/08/14 00:14:48 | 000,464,491 | ---- | M] () -- C:\Documents and Settings\hcistaff\Desktop\RootRepeal.zip
[2010/08/14 00:11:43 | 000,363,520 | ---- | M] () -- C:\Documents and Settings\hcistaff\Desktop\rkill.scr
[2010/08/14 00:11:21 | 000,363,520 | ---- | M] () -- C:\Documents and Settings\hcistaff\Desktop\rkill.com
[2010/08/13 23:49:23 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\hcistaff\Desktop\zztoy.exe
[2010/08/13 23:01:08 | 000,018,632 | ---- | M] () -- C:\Documents and Settings\hcistaff\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/08/13 22:57:25 | 000,000,009 | ---- | M] () -- C:\Documents and Settings\hcistaff\Application Data\nuar.old
[2010/08/13 22:57:24 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\hcistaff\Application Data\skynet.dat
[2010/08/13 22:57:19 | 002,089,472 | ---- | M] (Intsys) -- C:\Documents and Settings\hcistaff\Application Data\wshark.exe
[2010/08/12 03:30:46 | 000,115,768 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/12 03:11:46 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/08/12 03:11:04 | 000,000,603 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/08/12 03:08:40 | 000,522,418 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/12 03:08:40 | 000,456,832 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/08/12 03:08:40 | 000,075,854 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/08/09 19:47:18 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/08/02 15:44:49 | 000,055,655 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol
[2010/07/19 15:03:18 | 005,884,284 | -H-- | M] () -- C:\Documents and Settings\hcistaff\Local Settings\Application Data\IconCache.db
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/08/14 01:11:49 | 000,059,904 | ---- | C] () -- C:\Documents and Settings\hcistaff\Start Menu\Programs\Startup\csrss.exe
[2010/08/14 01:05:45 | 000,002,035 | ---- | C] () -- C:\Documents and Settings\hcistaff\Desktop\Wireshark Antivirus.lnk
[2010/08/14 00:50:29 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\hcistaff\Local Settings\Application Data\housecall.guid.cache
[2010/08/14 00:14:44 | 000,464,491 | ---- | C] () -- C:\Documents and Settings\hcistaff\Desktop\RootRepeal.zip
[2010/08/13 23:46:06 | 000,363,520 | ---- | C] () -- C:\Documents and Settings\hcistaff\Desktop\rkill.com
[2010/08/13 23:39:04 | 000,363,520 | ---- | C] () -- C:\Documents and Settings\hcistaff\Desktop\rkill.scr
[2010/08/13 22:57:25 | 000,098,304 | ---- | C] () -- C:\Documents and Settings\hcistaff\Application Data\conhost.exe
[2010/08/13 22:57:25 | 000,000,009 | ---- | C] () -- C:\Documents and Settings\hcistaff\Application Data\nuar.old
[2010/08/13 22:57:24 | 000,059,904 | ---- | C] () -- C:\Documents and Settings\hcistaff\Application Data\csrss.exe
[2010/08/13 22:57:24 | 000,000,095 | ---- | C] () -- C:\Documents and Settings\hcistaff\Application Data\sh4.dat
[2010/08/13 22:57:24 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\hcistaff\Application Data\skynet.dat
[2010/08/13 22:57:24 | 000,000,001 | ---- | C] () -- C:\Documents and Settings\hcistaff\Application Data\sh3.dat
[2008/04/14 13:43:45 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/04/03 17:02:49 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\Volume.dll
[2008/04/03 15:53:07 | 000,128,113 | ---- | C] () -- C:\WINDOWS\System32\csellang.ini
[2008/04/03 15:53:07 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\csellang.dll
[2008/04/03 15:53:07 | 000,010,165 | ---- | C] () -- C:\WINDOWS\System32\tosmreg.ini
[2008/04/03 15:53:07 | 000,007,671 | ---- | C] () -- C:\WINDOWS\System32\cseltbl.ini
[2006/01/18 06:09:00 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006/01/18 06:09:00 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006/01/18 06:09:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006/01/18 06:09:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2005/09/02 15:44:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\TosBtAcc.dll
[2005/07/22 22:30:20 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\TosCommAPI.dll
[2004/07/20 18:04:02 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/15 15:43:28 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\TBTMonUI.dll
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
< End of report >