This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] BaseLine NAR.VBS problem

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey,

Im surching for experts in the feild and looks like I found you. Thanks in advance.

I have a Toshiba Sat A215 series laptop. My Gateway and most of my portable HDs were infected with NAR.VBS. Problems accessing drives thru diffrent routes IE My Comp..Had to use explore. I ve been researching and I have set an ERU restore point, ive run Malwarebytes, Trendmicro security and this Baseline listed below for Hijackthisfor this machine. If you could take a look and point out what I missed i will be at your mercy. I am also looking at taking the class but I need a clean platform to take it. Thanks

D

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:36:16 PM, on 2/15/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Users\Dwight\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [Google Update] "C:\Users\Dwight\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O13 - Gopher Prefix:
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: pinger - Unknown owner - C:\Toshiba\IVP\ISM\pinger.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 6832 bytes
Hi

My name is Extremeboy (or EB for short), and I will be helping you with your log.

If you do not make a reply in 5 days, we will need to close your topic.

Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Please reply using the [external image: Posted Image] button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just post back here so that we know you're still here.



Download and Run OTViewit
  • Please download OTViewIt by OldTimer.
  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the [external image: Posted Image] button.
  • Two reports will open, copy and paste them in a reply here:
  • OTViewIt.txt <– Will be opened
  • Extra.txt <– Will be minimized

Download and run MalwareBytes Anti-Malware(Full Scan)

Please download Malwarebytes Anti-Malware and save it to your desktop if you lost your copy and need to install it, otherwise skip the installation step and continue with the Full Scan.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Full Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

For complete or visual instructions on installing and running Malwarebytes Anti-Malware please read this link

In your next reply please include the following:
  • OTViewIt.txt
  • Extra.txt
  • MBAM scan Log
  • Description of Problems you still have

Important Note: For other users who are reading this topic,the instructions provided in this topic are for the original topic starter ONLY. Even if you have similar problems or even log entries to those given here, please do not follow the directions, especially those involving specific tools and scripts. Doing so can result in serious damage to your computer. Instead, please start your own topic and feel free to link to any relevant topics as needed.Please Do NOT follow the instructions provided for this topic.

With Regards,
Extremeboy
Hey EB,

Whan I was in Iraq last year I contracted the nar.vbs virus. A short history is this. I have three Computers:this Satellite with Vista, a Gateway laptop with XP and and a desk top with XP. My Gateway laptop was infected. In turn all of my external storage became infected with the NAR.VBS. I followed a post on the whatthetech website that had similar issues. I want to insure that Ive cleaned my computer properly and that I have no other infections. Hopfully I can make my security a little stronger and learn a little in the process.

Also, My Trend keeps poping up with an access to the internet that I cant figure out. I think it may be that stupid Google updater but Im not sure.

I will be heading to Iraq on the 28feb09. It may be dificult to respond but I think I may be able to handle a 5 day window. Thanks for the support EB. Im glad you can make since of all this.

Y Lee

OTview.TXT

OTViewIt logfile created on: 2/18/2009 2:39:55 PM - Run 3
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Users\Dwight\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 231.42 Gb Total Space | 59.08 Gb Free Space | 25.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 4.18 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DWIGHT-PC
Current User Name: Dwight
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== Processes ==========

[2008/01/19 02:33:37 | 00,096,768 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wininit.exe
[2008/01/19 02:33:14 | 00,229,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\lsm.exe
[2008/06/19 20:14:44 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
[2007/07/14 01:50:18 | 00,606,208 | —- | M] (ATI Technologies Inc.) – C:\Windows\System32\Ati2evxx.exe
[2008/01/19 02:33:22 | 02,623,488 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SLsvc.exe
[2007/07/14 01:50:18 | 00,606,208 | —- | M] (ATI Technologies Inc.) – C:\Windows\System32\Ati2evxx.exe
[2006/10/05 16:10:12 | 00,009,216 | —- | M] (Agere Systems) – C:\Windows\System32\agrsmsvc.exe
[2006/11/14 23:33:10 | 00,040,960 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
[2009/02/11 10:19:38 | 00,179,856 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
[2000/08/06 01:50:20 | 07,442,493 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
[2007/01/25 21:47:50 | 00,136,816 | —- | M] () – C:\Toshiba\IVP\ISM\pinger.exe
[2008/07/29 14:24:36 | 00,698,888 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
[2007/10/23 19:27:16 | 00,066,928 | —- | M] () – c:\Toshiba\IVP\swupdate\swupdtmr.exe
[2007/06/28 19:25:30 | 00,077,824 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
[2006/05/25 21:30:16 | 00,114,688 | —- | M] (TOSHIBA Corporation) – C:\Windows\System32\TODDSrv.exe
[2007/03/29 13:39:20 | 00,427,576 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
[2007/02/26 00:55:18 | 00,125,048 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
[2006/08/23 19:39:48 | 00,049,152 | —- | M] (Ulead Systems, Inc.) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
[2007/01/04 16:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe
[2008/05/27 00:18:43 | 00,439,808 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SearchIndexer.exe
[2008/02/15 23:39:30 | 00,333,064 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe
[2008/01/19 02:33:32 | 00,169,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskeng.exe
[2008/01/19 02:33:08 | 00,081,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dwm.exe
[2007/04/10 19:40:28 | 00,413,696 | —- | M] (Chicony) – C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
[2007/06/01 13:52:10 | 00,049,152 | —- | M] (Advanced Micro Devices Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
[2007/06/13 16:11:30 | 04,489,216 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
[2006/11/15 01:02:36 | 01,372,160 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
[2006/11/06 20:14:44 | 00,034,352 | —- | M] () – C:\Program Files\Toshiba\Utilities\KeNotify.exe
[2007/03/29 13:39:18 | 00,411,192 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
[2007/06/16 00:01:58 | 00,448,080 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\SmoothView\SmoothView.exe
[2008/10/15 01:04:34 | 00,039,792 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[2008/07/29 14:24:38 | 01,398,024 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
[2007/05/17 19:03:24 | 04,813,312 | —- | M] () – C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
[2008/06/20 07:37:00 | 01,316,136 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[2009/02/11 10:19:38 | 00,399,504 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
[2008/06/20 07:14:00 | 00,200,704 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynToshiba.exe
[2008/12/29 19:00:56 | 00,133,104 | —- | M] (Google Inc.) – C:\Users\Dwight\AppData\Local\Google\Update\GoogleUpdate.exe
[2008/01/19 02:33:39 | 00,202,240 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnscfg.exe
[2008/01/19 02:33:39 | 00,896,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe
[2008/01/19 02:33:39 | 00,245,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wbem\WmiPrvSE.exe
[2008/01/19 02:33:15 | 00,095,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mobsync.exe
[2008/02/16 00:58:10 | 00,488,768 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
[2006/11/15 00:19:42 | 00,405,504 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
[2008/02/16 00:58:10 | 00,648,456 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
[2007/06/01 13:52:34 | 00,049,152 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
[2008/01/19 02:33:32 | 00,169,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskeng.exe
[2008/05/27 00:18:16 | 00,184,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SearchProtocolHost.exe
[2008/05/27 00:17:55 | 00,087,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SearchFilterHost.exe
[2008/06/20 07:37:00 | 00,103,720 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
[2009/02/18 14:34:57 | 00,422,912 | —- | M] (OldTimer Tools) – C:\Users\Dwight\Desktop\OTViewIt.exe

========== (O23) Win32 Services ==========

[2006/10/05 16:10:12 | 00,009,216 | —- | M] (Agere Systems) – C:\Windows\System32\agrsmsvc.exe – (AgereModemAudio [Auto | Running])
[2007/07/14 01:50:18 | 00,606,208 | —- | M] (ATI Technologies Inc.) – C:\Windows\System32\Ati2evxx.exe – (Ati External Event Utility [Auto | Running])
File not found – – (CertPropSvc [Unknown | Stopped])
[2006/11/14 23:33:10 | 00,040,960 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe – (CFSvcs [Auto | Running])
[2008/07/27 13:03:13 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
File not found – – (DcomLaunch [Unknown | Running])
[2008/01/19 02:33:06 | 02,091,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dfsr.exe – (DFSR [On_Demand | Stopped])
[2008/01/19 02:34:06 | 00,134,656 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dps.dll – (DPS [Unknown | Running])
[2008/01/19 02:33:09 | 00,292,352 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehrecvr.exe – (ehRecvr [On_Demand | Stopped])
[2006/11/02 07:35:29 | 00,131,072 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehsched.exe – (ehSched [On_Demand | Stopped])
[2008/06/19 20:14:44 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [Auto | Running])
[2008/01/19 02:34:25 | 00,574,464 | —- | M] (Microsoft Corporation) – C:\Windows\System32\gpsvc.dll – (gpsvc [Unknown | Running])
[2007/11/21 02:14:22 | 00,138,168 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [On_Demand | Stopped])
[2005/11/14 04:06:04 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
[2009/02/11 10:19:38 | 00,179,856 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService [Auto | Running])
[2006/11/02 08:04:14 | 00,000,000 | —D | M] – C:\Windows\System32\Msdtc – (MSDTC [Unknown | Stopped])
[2000/08/06 01:50:20 | 07,442,493 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe – (MSSQLSERVER [Auto | Running])
[2000/08/06 01:50:18 | 00,065,602 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe – (MSSQLServerADHelper [On_Demand | Stopped])
[2008/06/19 20:14:31 | 00,132,096 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
[2007/01/25 21:47:50 | 00,136,816 | —- | M] () – C:\Toshiba\IVP\ISM\pinger.exe – (pinger [Auto | Running])
[2008/01/19 02:36:19 | 00,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SCardSvr.dll – (SCardSvr [Unknown | Stopped])
File not found – – (Schedule [Unknown | Running])
File not found – – (SCPolicySvc [Unknown | Stopped])
[2008/07/29 14:24:36 | 00,698,888 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe – (SfCtlCom [Auto | Running])
[2008/01/19 02:33:22 | 02,623,488 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SLsvc.exe – (slsvc [Auto | Running])
[2006/11/02 04:45:46 | 00,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\snmptrap.exe – (SNMPTRAP [On_Demand | Stopped])
[2000/08/06 01:50:18 | 00,303,170 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE – (SQLSERVERAGENT [On_Demand | Stopped])
[2007/10/23 19:27:16 | 00,066,928 | —- | M] () – c:\Toshiba\IVP\swupdate\swupdtmr.exe – (Swupdtmr [Auto | Running])
[2008/02/15 23:39:30 | 00,333,064 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe – (TMBMServer [Auto | Running])
[2008/02/16 00:58:10 | 00,488,768 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe – (TmPfw [On_Demand | Running])
[2008/02/16 00:58:10 | 00,648,456 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe – (tmproxy [On_Demand | Running])
[2007/06/28 19:25:30 | 00,077,824 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe – (TNaviSrv [Auto | Running])
[2006/05/25 21:30:16 | 00,114,688 | —- | M] (TOSHIBA Corporation) – C:\Windows\System32\TODDSrv.exe – (TODDSrv [Auto | Running])
[2007/03/29 13:39:20 | 00,427,576 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe – (TosCoSrv [Auto | Running])
[2007/02/26 00:55:18 | 00,125,048 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe – (TOSHIBA Bluetooth Service [Auto | Running])
[2008/01/19 02:33:33 | 00,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UI0Detect.exe – (UI0Detect [On_Demand | Stopped])
[2006/08/23 19:39:48 | 00,049,152 | —- | M] (Ulead Systems, Inc.) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe – (UleadBurningHelper [Auto | Running])
[2008/01/19 02:33:33 | 00,382,976 | —- | M] (Microsoft Corporation) – C:\Windows\System32\vds.exe – (vds [On_Demand | Stopped])
[2007/01/04 16:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service [Auto | Running])
File not found – – (WdiServiceHost [Unknown | Stopped])
File not found – – (WdiSystemHost [Unknown | Running])
[2008/01/19 02:33:39 | 00,896,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Running])
[2008/05/27 00:18:43 | 00,439,808 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SearchIndexer.exe – (WSearch [Auto | Running])

========== Driver Services ==========

[2006/11/02 04:51:38 | 00,420,968 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\adp94xx.sys – (adp94xx [Disabled | Stopped])
[2006/11/02 04:51:32 | 00,297,576 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\adpahci.sys – (adpahci [Disabled | Stopped])
[2006/11/02 04:50:35 | 00,098,408 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\adpu160m.sys – (adpu160m [Disabled | Stopped])
[2006/11/02 04:51:00 | 00,147,048 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\adpu320.sys – (adpu320 [Disabled | Stopped])
[2006/11/28 19:11:00 | 01,161,888 | —- | M] (Agere Systems) – C:\Windows\System32\drivers\AGRSM.sys – (AgereSoftModem [On_Demand | Running])
[2006/11/02 04:50:11 | 00,071,272 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\djsvs.sys – (aic78xx [Disabled | Stopped])
[2006/11/02 04:49:20 | 00,014,952 | —- | M] (Acer Laboratories Inc.) – C:\Windows\System32\drivers\aliide.sys – (aliide [Disabled | Stopped])
[2006/11/02 04:49:59 | 00,054,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\AMDAGP.SYS – (amdagp [On_Demand | Stopped])
[2006/11/02 04:49:26 | 00,015,464 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\amdide.sys – (amdide [Disabled | Stopped])
[2006/11/02 03:30:18 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\amdk7.sys – (AmdK7 [Disabled | Stopped])
[2008/01/19 00:27:20 | 00,044,032 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\amdk8.sys – (AmdK8 [On_Demand | Running])
[2006/08/30 12:35:58 | 00,140,800 | —- | M] (Alps Electric Co., Ltd.) – C:\Windows\System32\drivers\Apfiltr.sys – (ApfiltrService [On_Demand | Stopped])
[2006/11/02 04:50:09 | 00,067,688 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\arc.sys – (arc [Disabled | Stopped])
[2006/11/02 04:50:10 | 00,067,688 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\arcsas.sys – (arcsas [Disabled | Stopped])
[2008/07/29 05:05:04 | 00,919,552 | —- | M] (Atheros Communications, Inc.) – C:\Windows\System32\drivers\athr.sys – (athr [On_Demand | Running])
[2007/07/14 02:01:30 | 02,771,968 | —- | M] (ATI Technologies Inc.) – C:\Windows\System32\drivers\atikmdag.sys – (atikmdag [On_Demand | Running])
[2008/01/19 00:28:26 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\bowser.sys – (bowser [On_Demand | Running])
[2006/11/02 03:24:45 | 00,013,568 | —- | M] (Brother Industries, Ltd.) – C:\Windows\System32\drivers\BrFiltLo.sys – (BrFiltLo [On_Demand | Stopped])
[2006/11/02 03:24:46 | 00,005,248 | —- | M] (Brother Industries, Ltd.) – C:\Windows\System32\drivers\BrFiltUp.sys – (BrFiltUp [On_Demand | Stopped])
[2006/11/02 03:25:24 | 00,071,808 | —- | M] (Brother Industries Ltd.) – C:\Windows\System32\drivers\BrSerId.sys – (Brserid [Disabled | Stopped])
[2006/11/02 03:24:44 | 00,062,336 | —- | M] (Brother Industries Ltd.) – C:\Windows\System32\drivers\BrSerWdm.sys – (BrSerWdm [Disabled | Stopped])
[2006/11/02 03:24:44 | 00,012,160 | —- | M] (Brother Industries Ltd.) – C:\Windows\System32\drivers\BrUsbMdm.sys – (BrUsbMdm [Disabled | Stopped])
[2006/11/02 03:24:47 | 00,011,904 | —- | M] (Brother Industries Ltd.) – C:\Windows\System32\drivers\BrUsbSer.sys – (BrUsbSer [On_Demand | Stopped])
[2006/11/02 03:55:23 | 00,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\bthmodem.sys – (BTHMODEM [Disabled | Stopped])
[2006/10/04 21:42:42 | 00,002,432 | —- | M] (Sonic Solutions) – C:\Windows\System32\drivers\cdr4_xp.sys – (Cdr4_xp [System | Running])
[2006/10/04 21:42:42 | 00,002,560 | —- | M] (Sonic Solutions) – C:\Windows\System32\drivers\cdralw2k.sys – (Cdralw2k [System | Running])
[2006/11/02 03:55:08 | 00,035,328 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\circlass.sys – (circlass [Disabled | Stopped])
[2008/01/19 02:42:58 | 00,247,352 | —- | M] (Microsoft Corporation) – C:\Windows\System32\clfs.sys – (CLFS [Unknown | Running])
[2006/11/02 04:49:28 | 00,016,488 | —- | M] (CMD Technology, Inc.) – C:\Windows\System32\drivers\cmdide.sys – (cmdide [Disabled | Stopped])
[2006/11/02 04:49:43 | 00,022,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\crcdisk.sys – (crcdisk [Boot | Running])
[2006/11/02 03:30:18 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\crusoe.sys – (Crusoe [Disabled | Stopped])
[2008/01/19 00:28:20 | 00,075,264 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\dfsc.sys – (DfsC [System | Running])
[2008/08/01 20:01:23 | 00,625,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgkrnl.sys – (DXGKrnl [On_Demand | Running])
[2006/11/02 02:30:54 | 00,117,760 | —- | M] (Intel Corporation) – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60 [On_Demand | Stopped])
[2008/01/19 02:42:11 | 00,143,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\ecache.sys – (Ecache [Boot | Running])
[2006/11/02 04:51:34 | 00,316,520 | —- | M] (Emulex) – C:\Windows\System32\drivers\elxstor.sys – (elxstor [Disabled | Stopped])
[2008/01/19 00:28:01 | 00,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\exfat.sys – (exfat [On_Demand | Stopped])
[2008/01/19 02:42:31 | 00,058,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\fileinfo.sys – (FileInfo [Boot | Running])
[2008/01/19 00:30:23 | 00,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\filetrace.sys – (Filetrace [On_Demand | Stopped])
[2006/11/02 04:50:04 | 00,058,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\GAGP30KX.SYS – (gagp30kx [On_Demand | Stopped])
[2006/11/02 02:36:49 | 00,235,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\HdAudio.sys – (HdAudAddService [On_Demand | Running])
[2008/01/18 23:30:49 | 00,053,760 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\hdaudbus.sys – (HDAudBus [On_Demand | Running])
[2006/11/02 03:55:22 | 00,029,184 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\hidbth.sys – (HidBth [Disabled | Stopped])
[2006/11/02 03:55:01 | 00,021,504 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\hidir.sys – (HidIr [Disabled | Stopped])
[2006/11/02 04:50:10 | 00,037,480 | —- | M] (Hewlett-Packard Company) – C:\Windows\System32\drivers\HpCISSs.sys – (HpCISSs [Disabled | Stopped])
[2006/11/02 04:51:25 | 00,232,040 | —- | M] (Intel Corporation) – C:\Windows\System32\drivers\iaStorV.sys – (iaStorV [Disabled | Stopped])
[2006/11/02 04:50:17 | 00,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) – C:\Windows\System32\drivers\iirsp.sys – (iirsp [Disabled | Stopped])
[2007/06/12 10:05:34 | 01,787,816 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\System32\drivers\RTKVHDA.sys – (IntcAzAudAddService [On_Demand | Running])
[2006/11/02 03:42:03 | 00,065,536 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\IPMIDrv.sys – (IPMIDRV [Disabled | Stopped])
[2008/01/19 02:42:35 | 00,181,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\msiscsi.sys – (iScsiPrt [On_Demand | Running])
[2006/11/02 04:50:07 | 00,035,944 | —- | M] (Integrated Technology Express, Inc.) – C:\Windows\System32\drivers\iteatapi.sys – (iteatapi [Disabled | Stopped])
[2006/11/02 04:50:09 | 00,035,944 | —- | M] (Integrated Technology Express, Inc.) – C:\Windows\System32\drivers\iteraid.sys – (iteraid [Disabled | Stopped])
[2006/11/02 03:51:12 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\kbdhid.sys – (kbdhid [Disabled | Stopped])
[2007/10/31 20:57:55 | 00,219,264 | —- | M] (TOSHIBA CORPORATION) – C:\Windows\System32\drivers\KR10I.sys – (KR10I [Disabled | Stopped])
[2007/10/31 20:58:10 | 00,211,072 | —- | M] (TOSHIBA CORPORATION) – C:\Windows\System32\drivers\KR10N.sys – (KR10N [Disabled | Stopped])
[2007/10/31 20:59:57 | 00,479,488 | —- | M] (TOSHIBA CORPORATION) – C:\Windows\System32\drivers\kr3npxp.sys – (KR3NPXP [Disabled | Stopped])
[2008/01/19 00:55:03 | 00,047,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\lltdio.sys – (lltdio [Auto | Running])
[2006/07/28 19:25:26 | 00,019,456 | —- | M] (COMPAL ELECTRONIC INC.) – C:\Windows\System32\drivers\LPCFilter.sys – (LPCFilter [Boot | Running])
[2006/11/02 04:50:04 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\System32\drivers\lsi_fc.sys – (LSI_FC [Disabled | Stopped])
[2006/11/02 04:50:05 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\System32\drivers\lsi_sas.sys – (LSI_SAS [Disabled | Stopped])
[2006/11/02 04:50:10 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\System32\drivers\lsi_scsi.sys – (LSI_SCSI [Disabled | Stopped])
[2008/01/19 00:30:36 | 00,084,480 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\luafv.sys – (luafv [Auto | Running])
[2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys – (MBAMProtector [On_Demand | Running])
[2006/11/02 04:49:53 | 00,028,776 | —- | M] (LSI Logic Corporation) – C:\Windows\System32\drivers\megasas.sys – (megasas [Disabled | Stopped])
[2008/01/19 00:52:19 | 00,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\monitor.sys – (monitor [On_Demand | Running])
[2007/06/18 20:18:26 | 00,023,680 | —- | M] (Motorola) – C:\Windows\System32\drivers\motmodem.sys – (motmodem [On_Demand | Stopped])
[2006/11/02 04:50:16 | 00,078,952 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mpio.sys – (mpio [Disabled | Stopped])
[2008/01/19 00:54:46 | 00,064,000 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mpsdrv.sys – (mpsdrv [On_Demand | Running])
[2006/11/02 04:49:59 | 00,033,384 | —- | M] (LSI Logic Corporation) – C:\Windows\System32\drivers\Mraid35x.sys – (Mraid35x [Disabled | Stopped])
[2008/11/15 02:27:29 | 00,212,480 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb10.sys – (mrxsmb10 [On_Demand | Running])
[2008/01/19 00:28:37 | 00,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb20.sys – (mrxsmb20 [On_Demand | Running])
[2006/11/02 04:49:44 | 00,023,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\msahci.sys – (msahci [Disabled | Stopped])
[2006/11/02 04:50:17 | 00,080,488 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\msdsm.sys – (msdsm [Disabled | Stopped])
[2008/01/19 02:41:14 | 00,016,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\msisadrv.sys – (msisadrv [Boot | Running])
[2008/01/19 02:42:29 | 00,163,384 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\msrpc.sys – (MsRPC [On_Demand | Stopped])
[2008/05/19 21:07:31 | 00,148,480 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\nwifi.sys – (NativeWifiP [On_Demand | Running])
[2008/12/27 12:24:51 | 00,027,136 | —- | M] (NCH Swift Sound) – C:\Windows\System32\drivers\nchssvad.sys – (NCHSSVAD [On_Demand | Stopped])
[2006/11/02 04:50:19 | 00,045,160 | —- | M] (IBM Corporation) – C:\Windows\System32\drivers\nfrd960.sys – (nfrd960 [Disabled | Stopped])
[2008/01/19 00:55:50 | 00,016,384 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\nsiproxy.sys – (nsiproxy [System | Running])
[2006/11/02 02:36:50 | 00,020,608 | —- | M] (N-trig Innovative Technologies) – C:\Windows\System32\drivers\ntrigdigi.sys – (ntrigdigi [Disabled | Stopped])
[2006/11/02 04:50:24 | 00,088,680 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvraid.sys – (nvraid [Disabled | Stopped])
[2006/11/02 04:50:13 | 00,040,040 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvstor.sys – (nvstor [Disabled | Stopped])
[2006/11/02 04:50:40 | 00,106,600 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\NV_AGP.SYS – (nv_agp [On_Demand | Stopped])
[2006/11/02 04:04:35 | 00,878,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\PEAuth.sys – (PEAUTH [Auto | Running])
[2008/04/04 20:21:42 | 00,072,192 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\pacer.sys – (PSched [System | Running])
[2008/07/31 17:17:04 | 00,043,872 | —- | M] (Sonic Solutions) – C:\Windows\System32\drivers\pxhelp20.sys – (PxHelp20 [Boot | Running])
[2006/11/02 04:51:45 | 00,900,712 | —- | M] (QLogic Corporation) – C:\Windows\System32\drivers\ql2300.sys – (ql2300 [Disabled | Stopped])
[2006/11/02 04:50:35 | 00,106,088 | —- | M] (QLogic Corporation) – C:\Windows\System32\drivers\ql40xx.sys – (ql40xx [Disabled | Stopped])
[2008/01/19 00:56:07 | 00,031,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\qwavedrv.sys – (QWAVEdrv [On_Demand | Stopped])
[2008/01/19 00:56:43 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\rassstp.sys – (RasSstp [On_Demand | Running])
[2008/01/19 01:01:09 | 00,006,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\RDPENCDD.sys – (RDPENCDD [System | Running])
[2008/01/19 00:55:03 | 00,060,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\rspndr.sys – (rspndr [Auto | Running])
[2007/04/30 16:42:14 | 00,081,408 | —- | M] (Realtek Corporation ) – C:\Windows\System32\drivers\Rtlh86.sys – (RTL8169 [On_Demand | Running])
[2006/11/02 04:50:16 | 00,076,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\sbp2port.sys – (sbp2port [Disabled | Stopped])
[2008/07/07 02:40:49 | 00,056,108 | —- | M] (PowerISO Computing, Inc.) – C:\Windows\System32\drivers\scdemu.sys – (SCDEmu [System | Running])
[2008/01/19 00:32:56 | 00,088,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\sdbus.sys – (sdbus [On_Demand | Running])
[2006/11/02 01:37:21 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\Windows\System32\drivers\secdrv.sys – (secdrv [Auto | Running])
[2008/01/19 00:49:16 | 00,019,968 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\sermouse.sys – (sermouse [Disabled | Stopped])
[2008/01/19 00:49:46 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\sffdisk.sys – (sffdisk [On_Demand | Stopped])
[2006/11/02 03:51:40 | 00,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\sffp_mmc.sys – (sffp_mmc [On_Demand | Stopped])
[2008/01/19 00:49:46 | 00,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\sffp_sd.sys – (sffp_sd [On_Demand | Stopped])
[2006/11/02 04:49:51 | 00,053,352 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\SISAGP.SYS – (sisagp [On_Demand | Stopped])
[2006/11/02 04:50:10 | 00,038,504 | —- | M] (Silicon Integrated Systems Corp.) – C:\Windows\System32\drivers\sisraid2.sys – (SiSRaid2 [Disabled | Stopped])
[2006/11/02 04:50:16 | 00,071,784 | —- | M] (Silicon Integrated Systems) – C:\Windows\System32\drivers\sisraid4.sys – (SiSRaid4 [Disabled | Stopped])
[2008/01/19 00:55:27 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\smb.sys – (Smb [System | Running])
[2008/01/19 02:41:30 | 00,021,048 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\spldr.sys – (spldr [Boot | Running])
[2008/01/19 00:29:15 | 00,144,384 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv2.sys – (srv2 [On_Demand | Running])
[2008/01/19 00:29:12 | 00,098,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys – (srvnet [On_Demand | Running])
[2006/11/02 04:50:05 | 00,035,944 | —- | M] (LSI Logic) – C:\Windows\System32\drivers\symc8xx.sys – (Symc8xx [Disabled | Stopped])
[2006/11/02 04:49:56 | 00,031,848 | —- | M] (LSI Logic) – C:\Windows\System32\drivers\sym_hi.sys – (Sym_hi [Disabled | Stopped])
[2006/11/02 04:50:03 | 00,034,920 | —- | M] (LSI Logic) – C:\Windows\System32\drivers\sym_u3.sys – (Sym_u3 [Disabled | Stopped])
[2008/06/20 07:37:00 | 00,200,112 | —- | M] (Synaptics, Inc.) – C:\Windows\System32\drivers\SynTP.sys – (SynTP [On_Demand | Running])
[2008/01/19 00:56:07 | 00,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpipreg.sys – (tcpipreg [Auto | Running])
[2006/10/18 14:50:04 | 00,016,128 | —- | M] (TOSHIBA Corporation.) – C:\Windows\System32\drivers\tdcmdpst.sys – (tdcmdpst [On_Demand | Running])
[2008/01/19 00:55:58 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tdx.sys – (tdx [System | Running])
[2007/01/24 17:44:06 | 00,290,304 | —- | M] (Texas Instruments) – C:\Windows\System32\drivers\tifm21.sys – (tifm21 [On_Demand | Running])
[2008/02/15 23:39:30 | 00,052,496 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmactmon.sys – (tmactmon [Auto | Running])
[2008/02/15 23:39:30 | 00,138,384 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmcomm.sys – (tmcomm [Auto | Running])
[2008/02/15 23:39:30 | 00,052,240 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmevtmgr.sys – (tmevtmgr [Auto | Running])
[2008/02/15 23:39:32 | 00,141,840 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmlwf.sys – (tmlwf [System | Running])
[2008/11/26 17:42:40 | 00,036,368 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmpreflt.sys – (tmpreflt [Auto | Running])
[2008/02/15 23:39:32 | 00,065,936 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmtdi.sys – (tmtdi [System | Running])
[2008/02/15 23:39:32 | 00,234,512 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmwfp.sys – (tmwfp [Auto | Running])
[2008/11/26 17:42:42 | 00,205,328 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmxpflt.sys – (tmxpflt [Auto | Running])
[2007/06/28 19:23:14 | 00,285,184 | —- | M] (TOSHIBA Corporation) – C:\Windows\System32\drivers\tos_sps32.sys – (tos_sps32 [Boot | Running])
[2008/01/19 01:01:15 | 00,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tssecsrv.sys – (tssecsrv [On_Demand | Stopped])
[2008/01/19 00:55:41 | 00,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\TUNMP.SYS – (tunmp [On_Demand | Running])
[2008/01/19 00:55:50 | 00,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tunnel.sys – (tunnel [On_Demand | Running])
[2007/11/09 05:00:52 | 00,023,640 | —- | M] (TOSHIBA Corporation) – C:\Windows\System32\drivers\TVALZ_O.SYS – (TVALZ [Boot | Running])
[2006/11/02 04:49:59 | 00,056,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\UAGP35.SYS – (uagp35 [On_Demand | Stopped])
[2006/11/02 04:50:04 | 00,058,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\ULIAGPKX.SYS – (uliagpkx [On_Demand | Stopped])
[2006/11/02 04:51:25 | 00,235,112 | —- | M] (ULi Electronics Inc.) – C:\Windows\System32\drivers\uliahci.sys – (uliahci [Disabled | Stopped])
[2006/11/02 04:50:35 | 00,098,408 | —- | M] (Promise Technology, Inc.) – C:\Windows\System32\drivers\ulsata.sys – (UlSata [Disabled | Stopped])
[2006/11/02 04:50:45 | 00,115,816 | —- | M] (Promise Technology, Inc.) – C:\Windows\System32\drivers\ulsata2.sys – (ulsata2 [Disabled | Stopped])
[2008/01/19 00:53:40 | 00,034,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\umbus.sys – (umbus [On_Demand | Running])
[2008/01/19 00:53:23 | 00,073,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\USBAUDIO.sys – (usbaudio [On_Demand | Stopped])
[2006/11/02 03:55:09 | 00,068,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\usbcir.sys – (usbcir [Disabled | Stopped])
[2008/01/19 00:53:38 | 00,134,016 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\usbvideo.sys – (usbvideo [On_Demand | Running])
[2007/04/16 13:19:10 | 00,011,776 | —- | M] (Chicony Electronics Co., Ltd.) – C:\Windows\System32\drivers\UVCFTR_S.SYS – (UVCFTR [On_Demand | Running])
[2006/11/02 03:53:56 | 00,026,112 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\vgapnp.sys – (vga [On_Demand | Stopped])
[2006/11/02 03:30:19 | 00,039,424 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\viac7.sys – (ViaC7 [Disabled | Stopped])
[2006/11/02 04:49:30 | 00,017,512 | —- | M] (VIA Technologies, Inc.) – C:\Windows\System32\drivers\viaide.sys – (viaide [Disabled | Stopped])
[2008/01/19 02:42:18 | 00,052,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\volmgr.sys – (volmgr [Boot | Running])
[2008/01/19 02:43:03 | 00,294,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\volmgrx.sys – (volmgrx [Boot | Running])
[2008/11/26 17:39:56 | 01,195,384 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\vsapint.sys – (vsapint [Auto | Running])
[2006/11/02 04:50:41 | 00,112,232 | —- | M] (VIA Technologies Inc.,Ltd) – C:\Windows\System32\drivers\vsmraid.sys – (vsmraid [Disabled | Stopped])
[2006/11/02 03:52:52 | 00,020,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\wacompen.sys – (WacomPen [Disabled | Stopped])
[2006/11/02 04:49:38 | 00,019,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\wd.sys – (Wd [Disabled | Stopped])
[2008/01/19 02:43:27 | 00,503,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\Wdf01000.sys – (Wdf01000 [Boot | Running])
[2006/11/02 03:35:03 | 00,011,264 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\wmiacpi.sys – (WmiAcpi [Disabled | Stopped])
[2008/01/19 00:56:49 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\ws2ifsl.sys – (ws2ifsl [Disabled | Stopped])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\Windows\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.google.com/
"StartPageCache"=

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\Windows\System32\ieframe.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\Windows\System32\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\Windows\System32\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\Windows\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.google.com/
"StartPageCache"=

[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\Windows\System32\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

========== (O1) Hosts File ==========

HOSTS File = (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
First 25 entries…
127.0.0.1 localhost
::1 localhost

========== (O2) BHO's ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{02478D38-C3F9-4efb-9B51-7695ECA05670} (HKLM) – Reg Error: Key does not exist or could not be opened. File not found
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) – C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) – C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
"Camera Assistant Software"="C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" (Chicony)
"HSON"=%ProgramFiles%\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
"KeNotify"=C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()
"Malwarebytes' Anti-Malware"="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray (Malwarebytes Corporation)
"NDSTray.exe"=NDSTray.exe File not found
"RtHDVCpl"=RtHDVCpl.exe (Realtek Semiconductor)
"SmoothView"=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
"SVPWUTIL"=C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL (TOSHIBA)
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
"TPwrMain"=%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE (TOSHIBA Corporation)
"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" (Trend Micro Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Users\Dwight\AppData\Local\Google\Update\GoogleUpdate.exe" /c (Google Inc.)

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe ()

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe ()

[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Users\Dwight\AppData\Local\Google\Update\GoogleUpdate.exe" /c (Google Inc.)

========== (O6 & O7) Current Version Policies ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"ConsentPromptBehaviorAdmin"=2
"ConsentPromptBehaviorUser"=1
"EnableInstallerDetection"=1
"EnableLUA"=1
"EnableSecureUIAPaths"=1
"EnableVirtualization"=1
"PromptOnSecureDesktop"=1
"ValidateAdminCodeSignatures"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"scforceoption"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"FilterAdministratorToken"=0
"EnableUIADesktopToggle"=0
"DisableRegistryTools"=0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=1
"CF_BITMAP"=2
"CF_OEMTEXT"=7
"CF_DIB"=8
"CF_PALETTE"=9
"CF_UNICODETEXT"=13
"CF_DIBV5"=17

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDrives"=0

[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDrives"=0

========== (O8) IE Context Menu Extensions ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
Add to Google Photos Screensa&ver: C:\Windows\System32\GPhotos.scr [2009/01/05 17:33:03 | 03,751,995 | —- | M] (Google Inc.)
E&xport to Microsoft Excel: C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE File not found

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE File not found

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE File not found

[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\MenuExt\]
Add to Google Photos Screensa&ver: C:\Windows\System32\GPhotos.scr [2009/01/05 17:33:03 | 03,751,995 | —- | M] (Google Inc.)

[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\MenuExt\]
Add to Google Photos Screensa&ver: C:\Windows\System32\GPhotos.scr [2009/01/05 17:33:03 | 03,751,995 | —- | M] (Google Inc.)

[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\Software\Microsoft\Internet Explorer\MenuExt\]
Add to Google Photos Screensa&ver: C:\Windows\System32\GPhotos.scr [2009/01/05 17:33:03 | 03,751,995 | —- | M] (Google Inc.)
E&xport to Microsoft Excel: C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE File not found

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console – %ProgramFiles%\Java\jre1.6.0\bin\ssv.dll [2007/11/21 00:10:56 | 00,501,384 | —- | M] (Sun Microsystems, Inc.)

========== (O12) Internet Explorer Plugins ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find…=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}: http://download.microsoft.com/download/e/4…/OGAControl.cab – Office Genuine Advantage Validation Tool
{166B1BCA-3F9C-11CF-8075-444553540000}: http://download.macromedia.com/pub/shockwa…director/sw.cab – Shockwave ActiveX Control
{48DD0448-9209-4F81-9F6D-D83562940134}: http://lads.myspace.com/upload/MySpaceUploader1006.cab – MySpace Uploader Control
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab – Reg Error: Key does not exist or could not be opened.
{D27CDB6E-AE6D-11CF-96B8-444553540000}: http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab – Shockwave Flash Object

========== (O17) DNS Name Servers ==========

{02F7655A-98D3-4039-9B74-F755FB566EA8} (Servers: | Description: Atheros AR5007EG Wireless Network Adapter)
{46AD3553-38E8-46D5-8E94-9B847D02D5DB} (Servers: | Description: Realtek RTL8101E Family PCI-E Fast Ethernet NIC (NDIS 6.0))

========== HKLM *SecurityProviders* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders"=credssp.dll
>[2008/01/19 02:33:59 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\credssp.dll

========== LSA *Security Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages"=kerberos,msv1_0,schannel,wdigest,tspkg,
>[2008/01/19 02:36:42 | 00,062,464 | —- | M] (Microsoft Corporation) – C:\Windows\System32\TSpkg.dll

========== Safeboot Options ==========

"AlternateShell"=cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

autoexec.bat [REM Dummy file for NTVDM | ]
[2006/09/18 16:43:36 | 00,000,024 | —- | M] () – C:\autoexec.bat – [ NTFS ]


========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{225fef0d-cea6-11dd-bc21-001eec011f5b}\Shell\AutoRun\command]
""=G:\PhotoViewerAP-V305.exe – File not found


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4bc05cc0-e1b3-11dd-9e3d-001eec011f5b}\Shell\AutoRun\command]
""=E:\wd_windows_tools\setup.exe – File not found


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{747cd9e6-bc5a-11dd-a296-001eec011f5b}\Shell\AutoRun\command]
""=C:\Windows\System32\shell32.dll – [2008/11/06 08:14:25 | 11,580,928 | —- | M] (Microsoft Corporation)


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell\AutoRun\command]
""=E:\wd_windows_tools\setup.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\Windows\*.tmp files]
[2009/02/18 14:34:44 | 00,422,912 | —- | C] (OldTimer Tools) – C:\Users\Dwight\Desktop\OTViewIt.exe
[2009/02/16 15:51:04 | 00,000,496 | —- | C] () – C:\Windows\tasks\Malwarebytes' Scheduled Scan for Dwight.job
[2009/02/10 19:29:38 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/02/10 19:29:37 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/02/10 19:29:37 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/02/10 19:29:36 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/02/10 19:29:36 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/02/10 19:28:39 | 03,580,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/02/10 19:28:38 | 06,069,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/02/10 19:28:38 | 01,166,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/02/10 19:28:37 | 01,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/02/10 19:28:37 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/02/10 19:28:37 | 00,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/02/10 19:28:37 | 00,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/02/10 19:28:37 | 00,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/02/10 19:28:37 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/02/07 23:20:47 | 00,000,000 | —D | C] – C:\Windows\temp
[2009/02/07 23:17:09 | 00,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2009/02/07 23:17:09 | 00,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2009/02/07 23:17:09 | 00,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2009/02/07 23:17:09 | 00,098,816 | —- | C] () – C:\Windows\sed.exe
[2009/02/07 23:17:09 | 00,089,504 | —- | C] (Smallfrogs Studio) – C:\Windows\fdsv.exe
[2009/02/07 23:17:09 | 00,080,412 | —- | C] () – C:\Windows\grep.exe
[2009/02/07 23:17:09 | 00,068,096 | —- | C] () – C:\Windows\zip.exe
[2009/02/07 23:17:09 | 00,049,152 | —- | C] () – C:\Windows\VFIND.exe
[2009/02/07 23:17:04 | 00,000,000 | —D | C] – C:\ComboFix
[2009/02/07 23:08:55 | 00,001,845 | —- | C] () – C:\Users\Dwight\Desktop\HijackThis.lnk
[2009/02/07 15:08:07 | 00,017,408 | —- | C] () – C:\Users\Dwight\Documents\Expenses.xls
[2009/02/06 21:36:45 | 00,024,887 | —- | C] () – C:\Users\Dwight\Documents\LCIHZM.pdf
[2009/02/05 21:38:06 | 00,019,968 | —- | C] () – C:\Users\Dwight\Documents\1995 judy cr marrietta 30060.doc
[2009/02/05 15:04:29 | 00,012,387 | —- | C] () – C:\Users\Dwight\Documents\hey_hey_acoustic.gp3
[2009/02/04 22:19:22 | 00,007,038 | —- | C] () – C:\Users\Dwight\Documents\Clapton, Eric - Tears in Heaven (4).gp3
[2009/02/04 22:18:50 | 00,001,379 | —- | C] () – C:\Users\Dwight\Documents\Clapton, Eric - Tears in Heaven (4).zip
[2009/02/04 19:10:14 | 00,000,000 | —D | C] – C:\Users\Dwight\AppData\Local\Adobe
[2009/02/03 12:07:39 | 00,086,753 | —- | C] () – C:\Users\Dwight\Documents\stuck_in_the_middle.gp3
[2009/02/02 21:06:42 | 00,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
[2009/02/01 13:59:18 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/02/01 13:59:18 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/02/01 13:59:17 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/02/01 13:59:17 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/02/01 13:59:17 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/02/01 13:59:17 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/02/01 13:59:16 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/02/01 13:59:14 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/02/01 13:50:43 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/02/01 13:50:39 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/02/01 13:50:39 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/02/01 13:50:29 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/02/01 13:50:27 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/01/30 14:12:17 | 00,000,000 | —D | C] – C:\Users\Dwight\Desktop\PSP
[2009/01/28 16:59:22 | 00,700,927 | —- | C] () – C:\Users\Dwight\Documents\BH souther draw gary pfaff.wma
[2009/01/27 16:34:02 | 00,000,000 | —D | C] – C:\Users\Dwight\Documents\Recordpad
[2009/01/27 16:34:01 | 00,000,000 | —D | C] – C:\Users\Dwight\AppData\Roaming\Recordpad
[2009/01/26 16:09:38 | 04,617,920 | —- | C] () – C:\Users\Dwight\Documents\sa210v200.exe
[2009/01/24 22:35:29 | 00,029,696 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2009/01/24 22:35:21 | 00,000,000 | —D | C] – C:\Windows\ERDNT
[2009/01/24 22:35:21 | 00,000,000 | —D | C] – C:\Qoobox
[2009/01/24 21:27:59 | 00,000,000 | —D | C] – C:\Users\Dwight\AppData\Local\AOL
[2009/01/24 21:06:09 | 03,048,418 | R— | C] () – C:\Users\Dwight\Documents\ComboFix.exe
[2009/01/24 20:30:49 | 00,000,000 | —D | C] – C:\Users\Dwight\AppData\Roaming\Malwarebytes
[2009/01/24 20:30:42 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/01/24 20:30:39 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/01/24 20:30:38 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/01/24 20:30:38 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/23 16:09:10 | 00,038,912 | —- | C] () – C:\Users\Dwight\Desktop\from Charleston.doc
[2009/01/21 20:25:58 | 00,000,000 | —D | C] – C:\Users\Dwight\AppData\Roaming\WinRAR
[2009/01/20 19:51:33 | 00,000,000 | —D | C] – C:\Users\Dwight\AppData\Roaming\Mozilla
[2009/01/20 16:27:58 | 00,030,208 | —- | C] () – C:\Users\Dwight\Documents\Faith Of the Heart.doc
[2009/01/19 15:08:45 | 00,029,184 | —- | C] () – C:\Users\Dwight\Desktop\TO Charleston.doc

========== Files - Modified Within 30 Days ==========

[1 C:\Windows\*.tmp files]
[2009/02/18 14:38:24 | 00,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/02/18 14:38:23 | 00,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/02/18 14:38:17 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/02/18 14:38:14 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/02/18 14:37:00 | 04,121,740 | -H– | M] () – C:\Users\Dwight\AppData\Local\IconCache.db
[2009/02/18 14:34:57 | 00,422,912 | —- | M] (OldTimer Tools) – C:\Users\Dwight\Desktop\OTViewIt.exe
[2009/02/18 11:22:19 | 00,716,878 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/02/18 11:22:19 | 00,613,514 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/02/18 11:22:19 | 00,108,694 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/02/16 15:53:22 | 00,000,496 | —- | M] () – C:\Windows\tasks\Malwarebytes' Scheduled Scan for Dwight.job
[2009/02/16 15:49:34 | 00,236,544 | —- | M] () – C:\Users\Dwight\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/16 13:49:22 | 03,293,740 | —- | M] () – C:\Users\Dwight\Desktop\Coldplay - Don't panic.mp3
[2009/02/11 10:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/02/08 11:04:47 | 00,025,600 | —- | M] () – C:\Users\Dwight\Desktop\Pass an ID.doc
[2009/02/07 23:19:22 | 00,000,215 | —- | M] () – C:\Windows\system.ini
[2009/02/07 23:08:55 | 00,001,845 | —- | M] () – C:\Users\Dwight\Desktop\HijackThis.lnk
[2009/02/07 15:08:07 | 00,017,408 | —- | M] () – C:\Users\Dwight\Documents\Expenses.xls
[2009/02/06 21:36:46 | 00,024,887 | —- | M] () – C:\Users\Dwight\Documents\LCIHZM.pdf
[2009/02/05 21:38:08 | 00,019,968 | —- | M] () – C:\Users\Dwight\Documents\1995 judy cr marrietta 30060.doc
[2009/02/05 15:08:51 | 00,012,106 | —- | M] () – C:\Users\Dwight\Documents\summer_of_69_acoustic.gp3
[2009/02/05 15:04:30 | 00,012,387 | —- | M] () – C:\Users\Dwight\Documents\hey_hey_acoustic.gp3
[2009/02/04 22:18:52 | 00,001,379 | —- | M] () – C:\Users\Dwight\Documents\Clapton, Eric - Tears in Heaven (4).zip
[2009/02/03 19:20:17 | 00,000,761 | —- | M] () – C:\Windows\System32\drivers\etc\tmvsthfud.bin
[2009/02/03 19:20:10 | 00,000,761 | —- | M] () – C:\Windows\System32\drivers\etc\tmvsthfss.bin
[2009/02/03 18:21:12 | 21,244,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mrt.exe
[2009/02/03 12:07:39 | 00,086,753 | —- | M] () – C:\Users\Dwight\Documents\stuck_in_the_middle.gp3
[2009/02/02 21:06:42 | 00,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
[2009/01/28 16:59:22 | 00,700,927 | —- | M] () – C:\Users\Dwight\Documents\BH souther draw gary pfaff.wma
[2009/01/26 16:09:39 | 04,617,920 | —- | M] () – C:\Users\Dwight\Documents\sa210v200.exe
[2009/01/24 22:47:24 | 00,111,184 | —- | M] () – C:\Users\Dwight\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/01/24 22:45:29 | 00,390,536 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/01/24 21:06:14 | 03,048,418 | R— | M] () – C:\Users\Dwight\Documents\ComboFix.exe
[2009/01/23 16:09:11 | 00,038,912 | —- | M] () – C:\Users\Dwight\Desktop\from Charleston.doc
[2009/01/20 16:27:59 | 00,030,208 | —- | M] () – C:\Users\Dwight\Documents\Faith Of the Heart.doc
[2009/01/19 19:29:15 | 00,000,376 | —- | M] () – C:\Windows\ODBC.INI
[2009/01/19 19:29:03 | 00,000,240 | —- | M] () – C:\Windows\win.ini
[2009/01/19 15:08:46 | 00,029,184 | —- | M] () – C:\Users\Dwight\Desktop\TO Charleston.doc
< End of report >


OTViewIt Extras logfile created on: 2/18/2009 2:39:55 PM - Run 3
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Users\Dwight\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 231.42 Gb Total Space | 59.08 Gb Free Space | 25.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 4.18 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DWIGHT-PC
Current User Name: Dwight
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval"=1
"UacDisableNotify"=0
"InternetSettingsDisableNotify"=0
"AutoUpdateDisableNotify"=1
"FirewallDisableNotify"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride"=0
"AntiSpywareOverride"=0
"FirewallOverride"=0
"VistaSp1"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications"=0
"EnableFirewall"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2007/01/25 21:49:34 | 00,472,688 | —- | M] (TOSHIBA Corporation) – C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine
[2007/01/25 21:47:50 | 00,136,816 | —- | M] () – C:\TOSHIBA\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger

========== (O10) Winsock2 Catalogs ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]
NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] – C:\Windows\System32\nlaapi.dll (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] – C:\Windows\System32\NapiNSP.dll (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] – C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] – C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)

========== HKEY_LOCAL_MACHINE Protocol Defaults ==========


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults - Default Protocols
ldap – 4 = Restricted sites (Not a Default Protocol)
news – 4 = Restricted sites (Not a Default Protocol)
nntp – 4 = Restricted sites (Not a Default Protocol)
oecmd – 4 = Restricted sites (Not a Default Protocol)
snews – 4 = Restricted sites (Not a Default Protocol)

========== HKEY_USERS Protocol Defaults ==========


[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
@ivt – @ivt protocol not assigned
file – file protocol not assigned
ftp – ftp protocol not assigned
http – http protocol not assigned
https – https protocol not assigned
shell – shell protocol not assigned

========== HKEY_USERS Protocol Defaults ==========


[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
@ivt – @ivt protocol not assigned
file – file protocol not assigned
ftp – ftp protocol not assigned
http – http protocol not assigned
https – https protocol not assigned
shell – shell protocol not assigned

========== (O18) Protocol Handlers ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2004/01/29 09:08:23 | 01,130,496 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2004/01/29 09:08:23 | 01,130,496 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/01/24 15:22:56 | 07,255,384 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler])

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}"=TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{0556F885-2415-4666-B53E-33727E46AEA1}"=The Movies™
"{07DE4C59-1853-ED4C-D7F3-58B8D62A52D1}"=CCC Help Swedish
"{0DD37678-746F-0292-8061-119F51CAEEB5}"=Catalyst Control Center Localization Russian
"{0F7CB237-1CAF-FAFB-A59E-F37849B036D7}"=CCC Help Finnish
"{11765420-93F3-7FBE-B534-9C5D08741F18}"=CCC Help Hungarian
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}"=Utility Common Driver
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}"=TOSHIBA Assist
"{130555D4-8394-C474-7187-56BE801E8EBA}"=CCC Help Dutch
"{1C85F7CD-26A9-57FD-7EEE-33F92B0D5AFE}"=Catalyst Control Center Localization Portuguese
"{1D5DE126-2E69-965C-B208-E8ECD8A1234B}"=Catalyst Control Center Graphics Full New
"{22543949-70E8-45D0-A938-F38143EB8BF8}"=Catalyst Control Center - Branding
"{249D150B-3925-54BC-3128-636944EA35DA}"=Catalyst Control Center Graphics Light
"{28006915-2739-4EBE-B5E8-49B25D32EB33}"=Atheros Driver Installation Program
"{2BE9962D-0585-4AB5-00BD-6142B888EF07}"=Catalyst Control Center Localization Swedish
"{2F1EAAEC-2128-E168-42E2-FB3028EB29A0}"=Catalyst Control Center Graphics Full Existing
"{305305E9-E188-05A2-3ED6-D46C986A1AF5}"=Catalyst Control Center Core Implementation
"{3090202E-C8DF-C97F-5191-D26181952198}"=CCC Help Russian
"{320E0701-F0AF-614D-993F-CC0315FCACA6}"=CCC Help Czech
"{3248F0A8-6813-11D6-A77B-00B0D0160000}"=Java™ SE Runtime Environment 6
"{3685E0FA-A49E-4998-F1E7-B1ADFD4E7DCF}"=CCC Help Norwegian
"{37C866E4-AA67-4725-9E95-A39968DD7960}"=Camera Assistant Software for Toshiba
"{3C1A9655-2EF5-8B55-54BD-F197DC5B4120}"=CCC Help Japanese
"{3D17CA85-B2C4-0770-0FD7-91E981F49A21}"=CCC Help Polish
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}"=TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{4160DC5B-4C56-D0C3-C5FD-F5BDAD3C882B}"=ATI Catalyst Install Manager
"{425A2BC2-AA64-4107-9C29-484245BBEA05}"=TOSHIBA Software Upgrades
"{43257822-3659-C7FC-7FA1-39DB6CA8729B}"=Catalyst Control Center Localization Spanish
"{475FC1B8-37D5-61AB-C7E5-23E484BB192F}"=Catalyst Control Center Localization Italian
"{4BAEB03C-945F-DD06-CB66-BB7FA01E6F74}"=Catalyst Control Center Localization Chinese Traditional
"{4E9FF0C3-A9DE-833A-0363-C59C6E82C4C6}"=Catalyst Control Center Localization German
"{510937B5-7839-725E-0BDF-4DC6C904FA5E}"=Catalyst Control Center Localization Turkish
"{5164F8DC-F412-F815-09D4-8831ED068A2C}"=CCC Help Portuguese
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}"=TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}"=TOSHIBA Hardware Setup
"{5569EC1D-EB0A-2B1F-7556-0EFF544655BB}"=Catalyst Control Center Localization Norwegian
"{56D366C8-CD07-598D-1CEF-B8CE0B012557}"=CCC Help Korean
"{596C35F8-5E89-235D-2FEC-D418B35C92B3}"=Catalyst Control Center Localization Dutch
"{5C0DBA7C-C8D4-FAAE-F9B3-E19E006FED9E}"=Catalyst Control Center Localization Danish
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}"=TOSHIBA Disc Creator
"{5DB6B0A9-2C0B-3351-804C-D96D315BB0BC}"=CCC Help Chinese Standard
"{5E69185C-D66E-6FA5-5936-D7188B113EE5}"=Catalyst Control Center Localization Thai
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}"=TOSHIBA Extended Tiles for Windows Mobility Center
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}"=TOSHIBA Flash Cards Support Utility
"{676F4F10-4AE7-1318-2F73-D63BB95A9C6C}"=CCC Help English
"{6849D118-BF82-F0CB-EF52-F48220D351D9}"=CCC Help Chinese Traditional
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}"=TOSHIBA DVD PLAYER
"{70154DC9-1283-8C9E-0DA1-ADD9B9E7BA20}"=Catalyst Control Center Localization French
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}"=Trend Micro Internet Security
"{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable
"{7671EA0A-4072-061C-9470-DDEAEAE0ADDD}"=Catalyst Control Center Localization Chinese Standard
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}"=TOSHIBA ConfigFree
"{7BF1756D-09B7-7789-BA2D-7C5BE41EE019}"=Catalyst Control Center Localization Polish
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}"=Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{890EF3F8-742F-46BD-9E8E-084B3A1F4364}"=QuickBooks Financial Center
"{8CA50864-D2A8-C5E4-B37A-577EF430E564}"=ccc-core-static
"{8EB29328-86D5-030F-BD19-84E0719182B0}"=CCC Help Italian
"{90280409-6000-11D3-8CFE-0050048383C9}"=Microsoft Office XP Professional with FrontPage
"{9D516A16-8CF2-A41A-B08E-2E926DE216D2}"=Catalyst Control Center Localization Czech
"{9F1D6FA1-F26E-7462-7BA1-F9314AFECEE5}"=CCC Help Danish
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}"=ALPS Touch Pad Driver
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}"=CD/DVD Drive Acoustic Silencer
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}"=Microsoft Visual C++ 2005 Redistributable
"{A621B45A-D138-4A95-BE10-7CABA05EF94E}"=Trend Micro Internet Security
"{AACAFAC3-AFED-3F46-C42C-5614EA1E1C2D}"=CCC Help German
"{AC76BA86-7AD7-1033-7B44-A81300000003}"=Adobe Reader 8.1.3
"{AC76BA86-7AD7-5464-3428-800000000003}"=Spelling Dictionaries Support For Adobe Reader 8
"{B279F2F1-3B2F-3A96-AC11-5743CD43DCCB}"=Google Talk Plugin
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}"=Microsoft XML Parser
"{B6111119-1868-579F-F823-83FD3B31871C}"=CCC Help Spanish
"{B70889DF-1F95-33BA-726A-C977BAF3D0EE}"=Catalyst Control Center Localization Greek
"{BC9EB8C7-158C-FE97-C2AC-7BD719C34169}"=CCC Help Turkish
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}"=Toshiba Registration
"{CA0ACBD9-4385-D03C-4C25-76160158F4B7}"=Catalyst Control Center Graphics Previews Vista
"{CCAC0157-2138-666F-E512-86697966300F}"=ccc-utility
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}"=Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}"=Bluetooth Stack for Windows by Toshiba
"{DB238FBC-C8B1-FE77-9851-58E2257E2AAE}"=CCC Help Thai
"{DB780B85-B4B5-4864-A49C-9B706B169C93}"=TIPCI
"{DF76BE47-9C57-A83E-C01D-A0CAE4B905E6}"=Catalyst Control Center Localization Japanese
"{E09B48B5-E141-427A-AB0C-D3605127224A}"=Microsoft SQL Server Desktop Engine
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}"=Windows Media Encoder 9 Series
"{E3B67656-DAC1-D6C7-7347-3874F4F4327C}"=Skins
"{E426EFC7-7619-F987-6753-52408FBED13D}"=Catalyst Control Center Localization Korean
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}"=TOSHIBA SD Memory Utilities
"{ED017667-DB2E-4BD1-C8E4-154742C560D1}"=Catalyst Control Center Localization Hungarian
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}"=TOSHIBA Speech System Applications
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}"=Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}"=DVD MovieFactory for TOSHIBA
"{F3400EA2-11D2-62BF-8AB4-1E590A8D947B}"=CCC Help Greek
"{F40D5162-FEE0-C312-9F27-2B262F23B6CD}"=Catalyst Control Center Localization Finnish
"{F766457E-BBE1-B55A-1D46-D2D30016E52B}"=CCC Help French
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}"=TOSHIBA Value Added Package
"Adobe Flash Player ActiveX"=Adobe Flash Player 10 ActiveX
"AIM_6"=AIM 6
"Guild Wars"=Guild Wars
"Guitar Pro 5_is1"=Guitar Pro 5.2
"HijackThis"=HijackThis 2.0.2
"InstallShield_{0556F885-2415-4666-B53E-33727E46AEA1}"=The Movies™
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}"=TOSHIBA Supervisor Password
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}"=TOSHIBA Hardware Setup
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}"=TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}"=TOSHIBA Flash Cards Support Utility
"InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93}"=Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}"=TOSHIBA Value Added Package
"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1"=Microsoft .NET Framework 3.5 SP1
"MySpaceIM"=MySpaceIM
"Picasa 3"=Picasa 3
"PitchPerfect"=PitchPerfect Uninstall
"PowerISO"=PowerISO
"Switch"=Switch Sound File Converter
"SynTPDeinstKey"=Synaptics Pointing Device Driver
"ToolBox"=NCH Toolbox
"TOSHIBA Software Modem"=TOSHIBA Software Modem
"ViewpointMediaPlayer"=Viewpoint Media Player
"VLC media player"=VideoLAN VLC media player 0.8.6c
"Windows Media Encoder 9"=Windows Media Encoder 9 Series
"WinRAR archiver"=WinRAR archiver
"Yahoo! Messenger"=Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE"=Move Networks Media Player for Internet Explorer
"uTorrent"=µTorrent

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE"=Move Networks Media Player for Internet Explorer
"uTorrent"=µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/16/2009 1:15:46 AM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =

Error - 1/16/2009 2:15:35 AM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =

Error - 1/16/2009 3:15:41 AM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =

Error - 1/16/2009 4:15:42 AM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =

Error - 1/16/2009 5:15:46 AM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =

Error - 1/16/2009 6:15:35 AM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =

Error - 1/17/2009 7:39:38 PM | Computer Name = Dwight-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 7.0.6001.18000 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: cfc Start Time: 01c978fa2c7b2235 Termination Time: 16

Error - 1/23/2009 7:21:07 PM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =

Error - 1/24/2009 4:32:32 PM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =

Error - 1/24/2009 11:43:51 PM | Computer Name = Dwight-PC | Source = EventSystem | ID = 4621
Description =

[ Media Center Events ]
Error - 12/18/2008 2:34:24 PM | Computer Name = Dwight-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ System Events ]
Error - 1/28/2009 6:43:03 PM | Computer Name = Dwight-PC | Source = bowser | ID = 8003
Description =

Error - 1/28/2009 11:53:31 PM | Computer Name = Dwight-PC | Source = DCOM | ID = 10010
Description =

Error - 1/29/2009 5:04:44 PM | Computer Name = Dwight-PC | Source = HTTP | ID = 15016
Description =

Error - 1/29/2009 5:05:03 PM | Computer Name = Dwight-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/30/2009 3:43:28 PM | Computer Name = Dwight-PC | Source = DCOM | ID = 10010
Description =

Error - 1/30/2009 6:53:25 PM | Computer Name = Dwight-PC | Source = HTTP | ID = 15016
Description =

Error - 1/30/2009 6:53:38 PM | Computer Name = Dwight-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/30/2009 6:59:58 PM | Computer Name = Dwight-PC | Source = DCOM | ID = 10010
Description =

Error - 1/30/2009 7:01:09 PM | Computer Name = Dwight-PC | Source = HTTP | ID = 15016
Description =

Error - 1/30/2009 7:01:24 PM | Computer Name = Dwight-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >

Malwarebytes' Anti-Malware 1.34
Database version: 1749
Windows 6.0.6001 Service Pack 1

2/18/2009 5:33:59 PM
mbam-log-2009-02-18 (17-33-59).txt

Scan type: Full Scan (C:\|D:\|F:\|)
Objects scanned: 166794
Time elapsed: 2 hour(s), 8 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hello.

Your log looks fine. A few orphaned ("dead entries") that we can remove but they are not 'bad'.

I understand that many of your removable drives and other computers may be infected because this worm like all other worms spreads.

I see that you have run Combofix before. It probably took out most of the infections. Let's run flash-drive disinfector to help your prevent these in the future.

Download and Run FlashDisinfector

  • Please download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden file named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.

Now run an online scan please. The MBAM scan was clean as you can probably see.

Run Scan with Kaspersky

Please do a scan with Kaspersky Online Scanner.

If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.


  • Please disable your realtime protection software before proceeding. Refer to this page if you are unsure how.
  • Open the Kaspersky Scanner page.
  • Click on Accept and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.

Also run a GMER scan, as I want to make sure no rootkit was involved. Combofix is a tool that should NOT be used on a "regular bases". It's not a toy and can cause disastrous problems if used incorrectly.

Download and Run Scan with GMER

We will use GMER to scan for rootkits.
  • Download gmer.zip and save to your desktop.
    Alternate Download Site 1
  • Unzip/extract the file to its own folder. Right-Click and select Extract All…
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will now start extracting.
  • Once it is done, check (tick) the Show extracted files box and click Finish
  • When you have done this, disconnect from the Internet and close all running programs.
    There is a small chance this application may crash your computer so save any work you have open.


  • Right click on gmer.exe and select Run as administrator to run it. It will start running a scan.
    If it detects rootkit activity, you will receive a prompt to run a full scan. Click Yes..
  • When it's done scanning, you may receive another notice. Click OK if prompted.
  • Click on Save … to save the log on your desktop.
    Save the log as GMER.txt when you save it on your desktop.
  • Close Gmer and copy and paste the contents of GMER.txt in your next reply.
If you receive no notice, click on the Scan button near the bottom.


  • It will start scanning again like before.
  • When it is done, Click on Save … to save the log on your desktop.
    Save the log as GMER.txt when you save it on your desktop.
  • Close Gmer and copy and paste the contents of GMER.txt in your next reply.
If GMER doesn't work in Normal Mode try running it in Safe Mode

Note: Do Not run any program while GMER is running

Post back with:
-Kaspersky log
-GMER scan log
-Problems you may still have


With Regards,
Extremeboy
Hello.

Are you still there?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 5-7 days the topic will need to be closed.

Thanks for understanding. :)

With Regards,
Extremeboy

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI