This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] laptop hangs up

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello guys…merry x-mas to you all…

i am working on my cousin's laptop and he was having probs with starting up his laptop…his laptop hangs and have to restart right away..task manager nothing opens up..first and last option is to restart..

here is my hijackthis log..please let me know what are the next steps..thanks



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:18:03 PM, on 25/12/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe
C:\Program Files\ltmoh\ltmoh.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.ca/welcome
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.getfreeflashgames.com/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.ca/welcome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshiba.ca/welcome
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Presented by TOSHIBA Leading Innovation >>>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Engine\16.7.2.11\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TWebCamera] "%ProgramFiles(x86)%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [cfFncEnabler.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\cfFncEnabler.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files (x86)\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: TOSHIBA Web Camera Service (camsvc) - TOSHIBA - C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
O23 - Service: ConfigFree Gadget Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files (x86)\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RelevantKnowledge - Unknown owner - C:\Program Files (x86)\RelevantKnowledge\rlservice.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: TOSHIBA Modem region select service (RSELSVC) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\rselect\RSelSvc.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 11152 bytes
Hi,

Please do the following:

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
here are the logs..otl.txt follows by extra.txt

OTL logfile created on: 30/12/2009 9:45:59 AM - Run 1
OTL by OldTimer - Version 3.1.20.1 Folder = C:\Users\Owner\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18865)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 67.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 275.61 Gb Total Space | 119.06 Gb Free Space | 43.20% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 9.76 Gb Total Space | 9.68 Gb Free Space | 99.17% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-PC
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Owner\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe (TOSHIBA)
PRC - C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
PRC - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Owner\Downloads\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV:64bit: - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (RSELSVC) – C:\Program Files\TOSHIBA\rselect\RSelSvc.exe (TOSHIBA Corporation)
SRV:64bit: - (AgereModemAudio) – C:\Windows\SysNative\agr64svc.exe (Agere Systems)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (msvsmon90) – C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (gusvc) – C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (Norton AntiVirus) – C:\Program Files (x86)\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe (Symantec Corporation)
SRV - (camsvc) – C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe (TOSHIBA)
SRV - (TMachInfo) – C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (TNaviSrv) – C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ConfigFree Service) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (ConfigFree Gadget Service) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe (TOSHIBA CORPORATION)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2006/11/02 08:34:14 | 00,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) – C:\Windows\SysWOW64\wbem\vss.mof ()
SRV - (LightScribeService) – C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (IDriverT) – C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (MDM) – C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.ca/welcome
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.toshiba.ca/welcome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.ca/welcome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.toshiba.ca/welcome

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.ca/welcome
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.getfreeflashgames.com/search.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/12/18 01:55:26 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/12/18 01:55:26 | 00,000,000 | —D | M]

[2009/09/03 23:58:28 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2009/12/29 12:16:50 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\oeozqfpq.default\extensions
[2009/12/29 11:51:29 | 00,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\oeozqfpq.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/10/07 21:37:48 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\oeozqfpq.default\extensions\[removed]
[2009/11/03 07:00:02 | 00,000,939 | —- | M] () – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\oeozqfpq.default\searchplugins\dictionary.xml
[2009/12/29 11:13:13 | 00,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions

O1 HOSTS File: (761 bytes) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll (Google Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Engine\16.7.2.11\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPCHWMsg] C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [cfFncEnabler.exe] C:\Program Files (x86)\TOSHIBA\ConfigFree\cfFncEnabler.exe (Toshiba Corporation)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NDSTray.exe] C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TWebCamera] File not found
O4 - HKCU..\Run: [Active Desktop Calendar] C:\Program Files (x86)\XemiComputers\Active Desktop Calendar\ADC.exe File not found
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe File not found
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{4613d63f-ecb8-11de-9579-da110de6d290}\Shell\AutoRun\command - "" = D:\WDSetup.exe – File not found
O33 - MountPoints2\{eca286de-9a57-11de-9c76-00225fd91d33}\Shell\AutoRun\command - "" = D:\RECYCLERS-1-6-21-1257894210-1075856346-012573477-2510\systemdl32.exe – File not found
O33 - MountPoints2\{eca286de-9a57-11de-9c76-00225fd91d33}\Shell\open\command - "" = D:\RECYCLERS-1-6-21-1257894210-1075856346-012573477-2510\systemdl32.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
64bit: O35 - comfile [open] – "%1" %* File not found
64bit: O35 - exefile [open] – "%1" %* File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2008/01/20 22:06:38 | 00,000,000 | —D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll (Microsoft Corporation)
NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008/01/20 22:08:35 | 00,000,000 | —D | M]
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)
OTL cannot create restorepoints on Vista OSs!

========== Files/Folders - Created Within 14 Days ==========

[2009/12/25 18:17:48 | 00,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2009/12/25 18:06:54 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\Malwarebytes
[2009/12/25 18:06:50 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2009/12/25 18:06:49 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/12/25 18:06:48 | 00,022,104 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2009/12/25 18:06:48 | 00,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2009/12/24 22:44:07 | 00,000,000 | —D | C] – C:\Users\Owner\{30c4bf95-b0e7-43a5-b65d-44895fedbafd}
[2009/12/19 14:51:54 | 00,000,000 | —D | C] – C:\Users\Owner\AppData\Local\Downloaded Installations
[2009/12/19 14:39:58 | 00,000,000 | —D | C] – C:\Program Files (x86)\Electronic Arts
[2009/12/19 14:27:15 | 00,000,000 | —D | C] – C:\Users\Owner\Desktop\rld-burp
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2009/12/30 09:50:52 | 00,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/12/30 09:50:52 | 00,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/12/30 09:44:47 | 02,883,584 | -HS- | M] () – C:\Users\Owner\NTUSER.DAT
[2009/12/30 09:40:29 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/12/30 02:44:41 | 00,760,772 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2009/12/30 02:44:41 | 00,649,990 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2009/12/30 02:44:41 | 00,124,338 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2009/12/30 02:38:01 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/12/30 02:37:36 | 41,565,42976 | -HS- | M] () – C:\hiberfil.sys
[2009/12/30 02:36:49 | 00,524,288 | -HS- | M] () – C:\Users\Owner\NTUSER.DAT{17f9910f-f1a9-11de-9a73-00225fd91d33}.TMContainer00000000000000000001.regtrans-ms
[2009/12/30 02:36:49 | 00,065,536 | -HS- | M] () – C:\Users\Owner\NTUSER.DAT{17f9910f-f1a9-11de-9a73-00225fd91d33}.TM.blf
[2009/12/29 12:17:33 | 00,373,248 | —- | M] () – C:\Users\Owner\Documents\Himani_Bio_data.doc
[2009/12/29 11:50:51 | 00,000,983 | —- | M] () – C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2009/12/29 11:36:35 | 00,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{A04C75CE-D23C-445B-8282-EB572FC79C98}.job
[2009/12/25 18:43:58 | 03,152,954 | —- | M] () – C:\Users\Owner\Desktop\THESOURCE.bmp
[2009/12/25 18:17:49 | 00,001,939 | —- | M] () – C:\Users\Owner\Desktop\HijackThis.lnk
[2009/12/25 17:59:57 | 00,524,288 | -HS- | M] () – C:\Users\Owner\NTUSER.DAT{17f9910f-f1a9-11de-9a73-00225fd91d33}.TMContainer00000000000000000002.regtrans-ms
[2009/12/25 11:01:19 | 00,524,288 | -HS- | M] () – C:\Users\Owner\NTUSER.DAT{1c63e82a-f107-11de-bf36-001e33dd3fd8}.TMContainer00000000000000000001.regtrans-ms
[2009/12/25 11:01:19 | 00,065,536 | -HS- | M] () – C:\Users\Owner\NTUSER.DAT{1c63e82a-f107-11de-bf36-001e33dd3fd8}.TM.blf
[2009/12/24 22:40:32 | 00,524,288 | -HS- | M] () – C:\Users\Owner\NTUSER.DAT{1c63e82a-f107-11de-bf36-001e33dd3fd8}.TMContainer00000000000000000002.regtrans-ms
[2009/12/22 17:22:49 | 00,065,412 | —- | M] () – C:\Users\Owner\Desktop\schedule.xlsx
[2009/12/21 18:29:36 | 00,226,304 | —- | M] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/19 14:57:51 | 00,524,288 | -HS- | M] () – C:\Users\Owner\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2009/12/19 14:57:51 | 00,065,536 | -HS- | M] () – C:\Users\Owner\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2009/12/19 14:52:35 | 00,000,640 | —- | M] () – C:\Windows\SysWow64\ealregsnapshot1.reg
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2009/12/30 02:37:36 | 41,565,42976 | -HS- | C] () – C:\hiberfil.sys
[2009/12/29 12:17:12 | 00,373,248 | —- | C] () – C:\Users\Owner\Documents\Himani_Bio_data.doc
[2009/12/29 11:50:51 | 00,000,983 | —- | C] () – C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2009/12/25 18:43:57 | 03,152,954 | —- | C] () – C:\Users\Owner\Desktop\THESOURCE.bmp
[2009/12/25 18:17:49 | 00,001,939 | —- | C] () – C:\Users\Owner\Desktop\HijackThis.lnk
[2009/12/25 17:59:57 | 00,524,288 | -HS- | C] () – C:\Users\Owner\NTUSER.DAT{17f9910f-f1a9-11de-9a73-00225fd91d33}.TMContainer00000000000000000002.regtrans-ms
[2009/12/25 17:59:57 | 00,524,288 | -HS- | C] () – C:\Users\Owner\NTUSER.DAT{17f9910f-f1a9-11de-9a73-00225fd91d33}.TMContainer00000000000000000001.regtrans-ms
[2009/12/25 17:59:57 | 00,065,536 | -HS- | C] () – C:\Users\Owner\NTUSER.DAT{17f9910f-f1a9-11de-9a73-00225fd91d33}.TM.blf
[2009/12/24 22:40:32 | 00,524,288 | -HS- | C] () – C:\Users\Owner\NTUSER.DAT{1c63e82a-f107-11de-bf36-001e33dd3fd8}.TMContainer00000000000000000002.regtrans-ms
[2009/12/24 22:40:32 | 00,524,288 | -HS- | C] () – C:\Users\Owner\NTUSER.DAT{1c63e82a-f107-11de-bf36-001e33dd3fd8}.TMContainer00000000000000000001.regtrans-ms
[2009/12/24 22:40:32 | 00,065,536 | -HS- | C] () – C:\Users\Owner\NTUSER.DAT{1c63e82a-f107-11de-bf36-001e33dd3fd8}.TM.blf
[2009/12/19 14:52:35 | 00,000,640 | —- | C] () – C:\Windows\SysWow64\ealregsnapshot1.reg
[2009/12/19 14:24:48 | 32,059,94496 | —- | C] () – C:\Users\Owner\Desktop\rld-burp.iso
[2009/12/15 19:13:57 | 00,000,732 | —- | C] () – C:\Users\Owner\AppData\Local\d3d9caps64.dat
[2009/12/15 12:54:46 | 00,000,182 | —- | C] () – C:\Users\Owner\AppData\Roaming\wklnhst.dat
[2009/12/10 20:02:21 | 00,024,226 | —- | C] () – C:\Users\Owner\AppData\Roaming\UserTile.png
[2009/12/06 09:43:55 | 00,175,228 | —- | C] () – C:\Users\Owner\AppData\Local\dd_SqlPubWiz.msi482B.txt
[2009/12/06 09:43:53 | 00,262,506 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_RefInt_x64_MSI4825.txt
[2009/12/06 09:43:44 | 00,648,322 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_NetFxTools_x64_MSI4807.txt
[2009/12/06 09:43:37 | 00,383,742 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_Win32Tools_x64_MSI47F0.txt
[2009/12/06 09:42:49 | 04,341,660 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_Build_x64_MSI4754.txt
[2009/12/06 09:42:43 | 00,588,182 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_Tools_x64_MSI4740.txt
[2009/12/06 09:42:19 | 02,379,610 | —- | C] () – C:\Users\Owner\AppData\Local\dd_CrystalReports2007_x64_MSI46F2.txt
[2009/12/06 09:40:23 | 04,875,040 | —- | C] () – C:\Users\Owner\AppData\Local\dd_CrystalReports2007_MSI4577.txt
[2009/12/06 09:40:15 | 01,096,544 | —- | C] () – C:\Users\Owner\AppData\Local\dd_RDBG_AMD64_MSI455D.txt
[2009/12/06 09:40:12 | 00,288,062 | —- | C] () – C:\Users\Owner\AppData\Local\dd_64bitEmulator_MSI4553.txt
[2009/12/06 09:39:27 | 04,492,058 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WMSP_5_0_MSI44C0.txt
[2009/12/06 09:38:31 | 06,057,752 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WMPPC_5_0_MSI4409.txt
[2009/12/06 09:38:22 | 00,669,838 | —- | C] () – C:\Users\Owner\AppData\Local\dd_SSCEDeviceRuntime_MSI43EC.txt
[2009/12/06 09:38:19 | 00,303,818 | —- | C] () – C:\Users\Owner\AppData\Local\dd_SQLCEToolsForVS2007_MSI43E2.txt
[2009/12/06 09:38:15 | 00,367,306 | —- | C] () – C:\Users\Owner\AppData\Local\dd_SSCERuntime_MSI43D5.txt
[2009/12/06 09:37:32 | 00,777,004 | —- | C] () – C:\Users\Owner\AppData\Local\dd_VSTOR_MSI4349.txt
[2009/12/06 09:37:15 | 00,706,652 | —- | C] () – C:\Users\Owner\AppData\Local\dd_NETCFSetupv35_MSI4311.txt
[2009/12/06 09:36:56 | 00,612,704 | —- | C] () – C:\Users\Owner\AppData\Local\dd_NETCFSetupv2_MSI42D3.txt
[2009/12/06 09:27:29 | 41,901,808 | —- | C] () – C:\Users\Owner\AppData\Local\VSMsiLog3B97.txt
[2009/12/06 09:26:44 | 02,833,140 | —- | C] () – C:\Users\Owner\AppData\Local\dd_Dexplorer90_retMSI3B04.txt
[2009/12/06 09:26:40 | 00,350,328 | —- | C] () – C:\Users\Owner\AppData\Local\dd_PreReq_AMD64_MSI3AF7.txt
[2009/12/06 09:26:34 | 00,886,976 | —- | C] () – C:\Users\Owner\AppData\Local\dd_VC_MinRed_MSI3AE4.txt
[2009/12/05 14:29:54 | 00,174,060 | —- | C] () – C:\Users\Owner\AppData\Local\dd_SqlPubWiz.msi54EB.txt
[2009/12/05 14:29:52 | 00,262,734 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_RefInt_x64_MSI54E5.txt
[2009/12/05 14:29:41 | 00,646,870 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_NetFxTools_x64_MSI54C1.txt
[2009/12/05 14:29:35 | 00,383,788 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_Win32Tools_x64_MSI54AD.txt
[2009/12/05 14:28:37 | 04,341,890 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_Build_x64_MSI53F0.txt
[2009/12/05 14:28:29 | 00,588,080 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_Tools_x64_MSI53D6.txt
[2009/12/05 14:28:05 | 02,369,270 | —- | C] () – C:\Users\Owner\AppData\Local\dd_CrystalReports2007_x64_MSI5387.txt
[2009/12/05 14:26:11 | 04,866,858 | —- | C] () – C:\Users\Owner\AppData\Local\dd_CrystalReports2007_MSI5213.txt
[2009/12/05 14:26:01 | 01,096,380 | —- | C] () – C:\Users\Owner\AppData\Local\dd_RDBG_AMD64_MSI51F2.txt
[2009/12/05 14:25:57 | 00,288,332 | —- | C] () – C:\Users\Owner\AppData\Local\dd_64bitEmulator_MSI51E5.txt
[2009/12/05 14:25:11 | 04,489,508 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WMSP_5_0_MSI514F.txt
[2009/12/05 14:24:10 | 06,054,882 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WMPPC_5_0_MSI5088.txt
[2009/12/05 14:23:58 | 00,663,458 | —- | C] () – C:\Users\Owner\AppData\Local\dd_SSCEDeviceRuntime_MSI5061.txt
[2009/12/05 14:23:56 | 00,303,674 | —- | C] () – C:\Users\Owner\AppData\Local\dd_SQLCEToolsForVS2007_MSI505A.txt
[2009/12/05 14:23:52 | 00,366,602 | —- | C] () – C:\Users\Owner\AppData\Local\dd_SSCERuntime_MSI504D.txt
[2009/12/05 14:23:20 | 00,777,348 | —- | C] () – C:\Users\Owner\AppData\Local\dd_VSTOR_MSI4FE5.txt
[2009/12/05 14:23:04 | 00,706,168 | —- | C] () – C:\Users\Owner\AppData\Local\dd_NETCFSetupv35_MSI4FB0.txt
[2009/12/05 14:22:48 | 00,612,564 | —- | C] () – C:\Users\Owner\AppData\Local\dd_NETCFSetupv2_MSI4F7C.txt
[2009/12/05 14:08:46 | 41,917,058 | —- | C] () – C:\Users\Owner\AppData\Local\VSMsiLog44BF.txt
[2009/12/05 14:08:00 | 02,841,368 | —- | C] () – C:\Users\Owner\AppData\Local\dd_Dexplorer90_retMSI4428.txt
[2009/12/05 14:07:57 | 00,350,624 | —- | C] () – C:\Users\Owner\AppData\Local\dd_PreReq_AMD64_MSI441F.txt
[2009/12/05 14:07:49 | 00,891,884 | —- | C] () – C:\Users\Owner\AppData\Local\dd_VC_MinRed_MSI4404.txt
[2009/12/05 13:30:36 | 09,804,224 | —- | C] () – C:\Users\Owner\AppData\Local\VSMsiLog2788.txt
[2009/12/03 22:47:13 | 00,014,216 | —- | C] () – C:\Users\Owner\AppData\Local\dd_rdbg64_80UI3549.txt
[2009/12/03 22:47:06 | 00,014,216 | —- | C] () – C:\Users\Owner\AppData\Local\dd_rdbg64_80UI3532.txt
[2009/11/17 03:07:03 | 00,000,774 | —- | C] () – C:\Windows\Calendar.INI
[2009/09/16 17:26:07 | 00,083,743 | —- | C] () – C:\Users\Owner\AppData\Local\dd_depcheck_MSDN_vs_90.txt
[2009/09/16 17:25:59 | 00,458,606 | —- | C] () – C:\Users\Owner\AppData\Local\dd_install_msdn_vs_90.txt
[2009/09/16 17:25:59 | 00,000,002 | —- | C] () – C:\Users\Owner\AppData\Local\dd_error_msdn_vs_90.txt
[2009/09/16 17:23:53 | 00,193,120 | —- | C] () – C:\Users\Owner\AppData\Local\dd_SqlPubWiz.msi6F71.txt
[2009/09/16 17:23:49 | 00,286,828 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_RefInt_x64_MSI6F64.txt
[2009/09/16 17:23:39 | 00,559,448 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_NetFxTools_x64_MSI6F43.txt
[2009/09/16 17:23:31 | 00,443,378 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_Win32Tools_x64_MSI6F29.txt
[2009/09/16 17:22:46 | 05,362,464 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_Build_x64_MSI6E96.txt
[2009/09/16 17:22:38 | 00,655,838 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WinSDK_Tools_x64_MSI6E7C.txt
[2009/09/16 17:21:52 | 02,528,958 | —- | C] () – C:\Users\Owner\AppData\Local\dd_CrystalReports2007_x64_MSI6DE6.txt
[2009/09/16 17:18:02 | 04,666,582 | —- | C] () – C:\Users\Owner\AppData\Local\dd_CrystalReports2007_MSI6AF7.txt
[2009/09/16 17:17:45 | 01,235,658 | —- | C] () – C:\Users\Owner\AppData\Local\dd_RDBG_AMD64_MSI6ABF.txt
[2009/09/16 17:16:15 | 00,766,538 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2009/09/16 17:11:00 | 00,302,238 | —- | C] () – C:\Users\Owner\AppData\Local\dd_64bitEmulator_MSI6595.txt
[2009/09/16 17:10:21 | 05,177,352 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WMSP_5_0_MSI6515.txt
[2009/09/16 17:09:23 | 07,088,550 | —- | C] () – C:\Users\Owner\AppData\Local\dd_WMPPC_5_0_MSI6458.txt
[2009/09/16 17:09:15 | 00,746,158 | —- | C] () – C:\Users\Owner\AppData\Local\dd_SSCEDeviceRuntime_MSI643E.txt
[2009/09/16 17:09:12 | 00,337,592 | —- | C] () – C:\Users\Owner\AppData\Local\dd_SQLCEToolsForVS2007_MSI6434.txt
[2009/09/16 17:09:07 | 00,364,646 | —- | C] () – C:\Users\Owner\AppData\Local\dd_SSCERuntime_MSI6424.txt
[2009/09/16 17:08:23 | 00,877,734 | —- | C] () – C:\Users\Owner\AppData\Local\dd_VSTOR_MSI6394.txt
[2009/09/16 17:08:08 | 01,055,894 | —- | C] () – C:\Users\Owner\AppData\Local\dd_NETCFSetupv35_MSI6363.txt
[2009/09/16 17:07:55 | 01,021,924 | —- | C] () – C:\Users\Owner\AppData\Local\dd_NETCFSetupv2_MSI6339.txt
[2009/09/16 16:53:36 | 52,179,768 | —- | C] () – C:\Users\Owner\AppData\Local\VSMsiLog5844.txt
[2009/09/16 16:42:51 | 37,612,016 | —- | C] () – C:\Users\Owner\AppData\Local\VSMsiLog5009.txt
[2009/09/16 16:39:10 | 02,934,810 | —- | C] () – C:\Users\Owner\AppData\Local\dd_Dexplorer90_retMSI4D38.txt
[2009/09/16 16:39:04 | 00,364,438 | —- | C] () – C:\Users\Owner\AppData\Local\dd_PreReq_AMD64_MSI4D24.txt
[2009/09/16 16:38:50 | 00,857,712 | —- | C] () – C:\Users\Owner\AppData\Local\dd_VC_MinRed_MSI4CF6.txt
[2009/09/16 16:37:50 | 00,811,117 | —- | C] () – C:\Users\Owner\AppData\Local\dd_depcheck_VS_PRO_90.txt
[2009/09/16 16:37:36 | 02,170,726 | —- | C] () – C:\Users\Owner\AppData\Local\dd_install_vs_procore_90.txt
[2009/09/16 16:37:36 | 00,005,976 | —- | C] () – C:\Users\Owner\AppData\Local\dd_error_vs_procore_90.txt
[2009/09/16 08:56:13 | 02,119,576 | —- | C] () – C:\Users\Owner\AppData\Local\dd_NET_Framework35_x64_MSI6AE4.txt
[2009/09/16 08:55:19 | 00,156,896 | —- | C] () – C:\Users\Owner\AppData\Local\dd_depcheck_NETFX_EXP_35.txt
[2009/09/16 08:55:03 | 00,040,134 | —- | C] () – C:\Users\Owner\AppData\Local\uxeventlog.txt
[2009/09/16 08:55:03 | 00,000,002 | —- | C] () – C:\Users\Owner\AppData\Local\dd_dotnetfx35error.txt
[2009/09/16 08:55:02 | 00,291,108 | —- | C] () – C:\Users\Owner\AppData\Local\dd_dotnetfx35install.txt
[2009/09/11 00:28:23 | 00,006,756 | —- | C] () – C:\Users\Owner\AppData\Local\d3d9caps.dat
[2009/09/05 15:19:14 | 00,000,520 | —- | C] () – C:\Windows\ODBC.INI
[2009/09/03 23:14:25 | 00,226,304 | —- | C] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/03 22:54:03 | 00,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/09/03 22:53:52 | 00,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/08/14 07:16:37 | 00,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2009/08/14 06:43:33 | 00,209,040 | —- | C] () – C:\Windows\SysWow64\IVIresizeW7.dll
[2009/08/14 06:43:33 | 00,204,944 | —- | C] () – C:\Windows\SysWow64\IVIresizeA6.dll
[2009/08/14 06:43:33 | 00,196,752 | —- | C] () – C:\Windows\SysWow64\IVIresizeP6.dll
[2009/08/14 06:43:33 | 00,196,752 | —- | C] () – C:\Windows\SysWow64\IVIresizeM6.dll
[2009/08/14 06:43:33 | 00,192,656 | —- | C] () – C:\Windows\SysWow64\IVIresizePX.dll
[2009/08/14 06:43:33 | 00,024,720 | —- | C] () – C:\Windows\SysWow64\IVIresize.dll
[2009/08/14 06:22:47 | 00,131,072 | —- | C] () – C:\Windows\SysWow64\EnumDevLib.dll
[2008/01/20 21:50:05 | 00,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini

========== LOP Check ==========

[2009/12/06 08:16:56 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\com.cbs.himym.desktop.E9E67C1457924EABBA27327D1BAF79E9B78ADD40.1
[2009/12/18 02:17:51 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\DC++
[2009/12/10 20:02:20 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\PeerNetworking
[2009/12/15 12:54:48 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Template
[2009/09/21 14:02:33 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\toshiba
[2009/09/04 00:35:40 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\WildTangent
[2009/09/23 13:46:31 | 00,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\XemiComputers
[2009/12/29 11:11:55 | 00,032,652 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2009/12/29 11:36:35 | 00,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{A04C75CE-D23C-445B-8282-EB572FC79C98}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/03/25 22:53:12 | 00,064,568 | —- | M] (Microsoft Corporation) MD5=18369BF8FD59C22E4C12ABD2A3A5AB2D – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6000.20800_none_14d4e8ca930556b0\AGP440.sys
[2008/03/24 22:56:03 | 00,064,568 | —- | M] (Microsoft Corporation) MD5=82EB67122D92A53BBBC33FC731682E10 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.22142_none_1691e66e904a8cec\AGP440.sys
[2008/01/20 21:46:51 | 00,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008/01/20 21:46:51 | 00,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/01/20 21:46:50 | 00,022,584 | —- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2008/06/03 00:44:43 | 00,022,584 | —- | M] (Microsoft Corporation) MD5=35137384FFB6FB4B4C3063CEB5DB34BE – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.20847_none_37d5e5fef5f86cf7\atapi.sys
[2008/06/02 23:12:37 | 00,022,584 | —- | M] (Microsoft Corporation) MD5=B388797CAAB36D523840347CC6A39B96 – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.22193_none_398211faf34b271a\atapi.sys
[2009/04/10 23:15:02 | 00,020,952 | —- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 06:16:48 | 00,014,848 | —- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006/11/02 04:46:03 | 00,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 04:46:03 | 00,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 04:46:03 | 00,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2009/02/11 19:26:18 | 00,407,576 | —- | M] (Intel Corporation) MD5=1ADAA4F16073FD0C7270F451FD024E97 – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2009/02/11 19:11:50 | 00,329,752 | —- | M] (Intel Corporation) MD5=71ECC07BC7C5E24C3DD01D8A29A24054 – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\driver\IaStor.sys

< MD5 for: IASTORV.SYS >
[2008/01/20 21:46:59 | 00,290,872 | —- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2008/01/20 21:51:03 | 00,716,800 | —- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009/04/10 22:28:24 | 00,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/10 22:28:24 | 00,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/10 22:28:24 | 00,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009/04/10 23:11:18 | 00,717,312 | —- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008/01/20 21:48:28 | 00,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2008/01/20 21:46:54 | 00,054,328 | —- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/20 21:50:28 | 00,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationenginecli
ent_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008/01/20 21:49:49 | 00,235,520 | —- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009/04/10 22:28:26 | 00,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/10 22:28:26 | 00,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/10 22:28:26 | 00,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009/04/10 23:11:24 | 00,235,520 | —- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll

< %systemroot%\*. /mp /s >
< End of report >


extrA.txt

OTL Extras logfile created on: 30/12/2009 9:45:59 AM - Run 1
OTL by OldTimer - Version 3.1.20.1 Folder = C:\Users\Owner\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18865)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 67.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 275.61 Gb Total Space | 119.06 Gb Free Space | 43.20% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 9.76 Gb Total Space | 9.68 Gb Free Space | 99.17% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-PC
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – "%SystemRoot%\hh.exe" %1

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – "%SystemRoot%\hh.exe" %1
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
chm.file [open] – "%SystemRoot%\hh.exe" %1 File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
chm.file [open] – "%SystemRoot%\hh.exe" %1
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 7D 2F 7D 03 16 2D CA 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B8B58ED-6057-4E19-A8BB-24AAE8E78E64}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{14D5550C-CEF0-4828-835C-87AF95ECAE39}" = lport=2869 | protocol=6 | dir=in | app=system |
"{17E8059C-86BC-47A9-83C0-DFB7893D4F9C}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\netproj.exe |
"{18411265-8B26-404B-A46B-E3409DAC58FA}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{28FA19A3-F300-436F-BEEC-3654786EC468}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{297AE437-A819-4178-A000-F831BA3B8B85}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{418100C5-C31B-484F-B0C3-2EFF553A5CB4}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{437B4577-FB0D-41F2-922F-B011BB4690BC}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{54E3D004-385B-4D10-B066-B5CF2B8CE705}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{55322B8E-FB91-4249-8B63-747E08147E44}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{5CF1ECB6-2D03-40C3-8F5D-8508021D3115}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{5E595B62-8016-4549-B2DD-2338F4898965}" = rport=5358 | protocol=6 | dir=out | app=system |
"{5F8CE087-2A8A-48C8-9390-B0A4BA633DA0}" = lport=5358 | protocol=6 | dir=in | app=system |
"{6A80BDB7-7DCC-44F6-A8C0-34DD87FB9816}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{6AFBDF09-E8F8-4DB0-B143-4513D6A0D883}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\netproj.exe |
"{7737CDE9-FC28-44D9-BCEB-D7F1955418CB}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{88EFEDB7-C4D3-42E4-809B-5453660CE40E}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{8D5D9D69-4C03-4106-9FEB-54AC9A82888A}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\netproj.exe |
"{908B252E-5A03-44E7-995B-91DD09E4B778}" = lport=5357 | protocol=6 | dir=in | app=system |
"{99EEBB09-8449-4D97-B12B-508519B4CD47}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{9B58CCDB-ED37-46FF-82C1-E45FE0402B4F}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{A362AEF4-34B1-4B64-84F5-1B9603330BEC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A7810A14-F453-4F50-AF57-E87793D92715}" = rport=5357 | protocol=6 | dir=out | app=system |
"{AA4DCF95-F7B4-40FD-B868-7C2B9651C757}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AB415133-74C0-4B2D-9A50-C943ABCCEF9C}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{C4D2B060-D8A6-46E0-85FB-44F64A5DB7C9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CAA83C46-697C-4417-9015-C8DF5D7149E6}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\netproj.exe |
"{CD7B4512-B8D4-4A33-82B0-E91DD610B710}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{EAA6AE6C-1349-4A9F-8631-491DE2E56DCC}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{EE7CC6DA-6269-4C0B-87E1-C2BB5C188B2C}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{F81C08E1-C71F-474E-AEB7-D68F2257DF96}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{174BC13E-260F-4F58-9427-265AFB8B87B6}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutlauncher.exe |
"{191FA339-39A1-4516-9EAF-C8DAA95F3B66}" = protocol=6 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{22D87957-CE52-4D51-8FD7-BE19C4046CB9}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{292E6ECE-EE01-480E-992C-F76087E9CCD3}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{2B6E1731-9184-403A-BBA7-C0443654D779}" = protocol=6 | dir=in | app=c:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe |
"{2DDD7580-B6D3-40C2-9E47-E4A29BF266FF}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{37437890-8908-4046-B561-A719E166F385}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutconfigtool.exe |
"{40018970-37E5-49E2-971C-404DB86B9954}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutparadise.exe |
"{435EDF1B-9E3B-4E08-A768-905B695DFB7B}" = protocol=6 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{4C609730-5D26-4925-84E5-5E4218D03B58}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{4DD8783D-A968-4472-AC14-9E2992CA8076}" = protocol=17 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{64227C83-4156-4319-B371-BB96770A17D4}" = protocol=6 | dir=in | app=c:\windows\temp\~os2175.tmp\rlvknlg.exe |
"{66531377-5AC6-435F-8431-E45B111BCAC5}" = protocol=17 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{749F19C5-F77A-4AE2-ACD4-A00475F0F6C4}" = protocol=6 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{74C74ED9-AFA1-48E0-B4D6-6757A28CD4AF}" = protocol=6 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{78040874-0984-4DCC-BEA7-AFEB98F1116A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{81325598-DE46-480B-A407-BC71BFE633EB}" = protocol=17 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{82B0C40D-E4FD-448B-889A-6120BEAF06BD}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{9F166E13-96BD-406B-AC63-141B83124DC1}" = protocol=6 | dir=in | app=c:\program files (x86)\relevantknowledge\rlvknlg.exe |
"{A0526AF8-7A82-42DD-9324-6C7D732B351B}" = protocol=17 | dir=in | app=c:\program files (x86)\relevantknowledge\rlvknlg.exe |
"{A20B8F6B-2C32-486E-BC27-D030F3D7E3A9}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{A6504F35-8392-4087-A389-E706359F1DDF}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{B07320D0-A29C-422F-9239-35A3D6EC0E72}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{B126E556-3073-4217-95AC-163397988FE2}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{B87DA7DF-DE9B-44B4-829E-F7C71C89617E}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutconfigtool.exe |
"{BBA7B859-B57A-47FA-BF65-0E4089BDFD1C}" = protocol=6 | dir=in | app=%systemroot%\system32\netproj.exe |
"{C266378B-DC9A-47DD-A6AC-8CA5517C3178}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{C316C936-46F4-4718-A040-CB6C486E992A}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{C42AA396-1D38-4EBA-B27D-17D3F24EE78D}" = protocol=17 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{D31CAC70-0913-4661-8B44-51F78991937D}" = protocol=17 | dir=in | app=c:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe |
"{D66B033B-46A3-45C0-A719-1908AEDCAB41}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutparadise.exe |
"{DC984F40-641C-4EA0-BAE4-78B17333225A}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\burnout™ paradise the ultimate box\burnoutlauncher.exe |
"{E2D2A5E2-7FFC-4141-878D-2B093A1B500D}" = protocol=6 | dir=out | app=%systemroot%\system32\netproj.exe |
"{F1AF20DE-C6AD-4D75-84F2-200D8B5BBD7E}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{FFC63CBC-AABE-4BFF-B1B6-A86091DCC4B4}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"TCP Query User{10A8B6FF-BAC3-43E0-89DF-DECF882C09F6}C:\program files (x86)\dc++\dcplusplus.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dc++\dcplusplus.exe |
"TCP Query User{56A053EB-B835-4DD0-BC6B-7B608379C311}C:\program files (x86)\microsoft office\office12\drat.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\drat.exe |
"TCP Query User{7CD42D17-CBF1-4EA3-8B39-A489708324E3}C:\users\owner\downloads\games\left 4 dead\left 4 dead\left4dead.exe" = protocol=6 | dir=in | app=c:\users\owner\downloads\games\left 4 dead\left 4 dead\left4dead.exe |
"TCP Query User{A1FF3850-397F-4574-97C5-840459730EE0}C:\users\owner\appdata\local\temp\rar$ex00.723\dcplusplus.exe" = protocol=6 | dir=in | app=c:\users\owner\appdata\local\temp\rar$ex00.723\dcplusplus.exe |
"TCP Query User{B71D1E4D-48E3-4CFD-AAF9-AA72BD283217}C:\users\owner\appdata\local\temp\rar$ex21.063\dcplusplus.exe" = protocol=6 | dir=in | app=c:\users\owner\appdata\local\temp\rar$ex21.063\dcplusplus.exe |
"TCP Query User{C49CBB62-3E19-473E-B6A1-ED267D7D8AA3}C:\program files (x86)\valve\hltv.exe" = protocol=6 | dir=in | app=c:\program files (x86)\valve\hltv.exe |
"TCP Query User{F2319360-AC4E-4089-BA22-49A79E5F60D8}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{1B98290C-8F84-48F4-B5A7-E1E3BECD6FF4}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{1F2B7B74-BC2E-4412-86FB-E41F43B87588}C:\program files (x86)\microsoft office\office12\drat.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\drat.exe |
"UDP Query User{37DAE972-223E-4C2A-9487-45B176D22740}C:\users\owner\appdata\local\temp\rar$ex21.063\dcplusplus.exe" = protocol=17 | dir=in | app=c:\users\owner\appdata\local\temp\rar$ex21.063\dcplusplus.exe |
"UDP Query User{7FF9CD01-17D9-4A06-BB68-EBAD07E8BDB0}C:\users\owner\downloads\games\left 4 dead\left 4 dead\left4dead.exe" = protocol=17 | dir=in | app=c:\users\owner\downloads\games\left 4 dead\left 4 dead\left4dead.exe |
"UDP Query User{894EA466-2831-4D04-A9B3-764AB619CCC6}C:\users\owner\appdata\local\temp\rar$ex00.723\dcplusplus.exe" = protocol=17 | dir=in | app=c:\users\owner\appdata\local\temp\rar$ex00.723\dcplusplus.exe |
"UDP Query User{8BA9AFDF-12E3-4094-A8BB-6A401C10B8CB}C:\program files (x86)\valve\hltv.exe" = protocol=17 | dir=in | app=c:\program files (x86)\valve\hltv.exe |
"UDP Query User{E3034F8E-2D13-49E4-ABDD-77E78C8E8728}C:\program files (x86)\dc++\dcplusplus.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dc++\dcplusplus.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{08D401E5-E23D-4372-8F9E-764963B19483}" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
"{29C93182-34F6-3275-A18D-59326851CD57}" = Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools
"{2BFA9B05-7418-4EDE-A6FC-620427BAAAA3}" = Crystal Reports Basic Runtime for Visual Studio 2008 (x64)
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5DE154DF-A55E-4FA5-BE59-32E78FCACF3E}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{62EED300-E841-4083-A1D6-60B906271804}" = Microsoft Windows SDK for Visual Studio 2008 Tools
"{64D5BBC6-5270-3711-AA39-31C1087AF4E6}" = Microsoft Visual Studio 2008 Remote Debugger - ENU
"{704ABF63-B0B1-446B-9D92-C5D06AFCE7B6}" = PlayReady PC runtime
"{79BF7CB8-1E09-489F-9547-DB3EE8EA3F16}" = Microsoft SQL Server Native Client
"{86177DAE-38B1-49DD-912E-35CB703AB779}" = Microsoft SQL Server VSS Writer
"{89F7D66C-777D-473B-AA11-319C0F190EAC}" = TOSHIBA Internal Modem Region Select Utility
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9aa5f39c-a8de-46b0-919a-0248f8bc8490}" = Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense
"{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor
"{A992BBAA-723D-4574-A07F-983BF8FAA3E1}" = Microsoft Windows SDK for Visual Studio 2008 Win32 Tools
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D3E39E77-0EB4-36FB-B97A-8C8AB21B9A45}" = Visual Studio .NET Prerequisites - English
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{EF8B1A2E-9CCB-3AB2-91E3-4EEDAB1294E1}" = Microsoft Device Emulator (64 bit) version 3.0 - ENU
"{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"D27D7E9318CFA89EDDE8D448B507A8EB725F5A52" = Windows Driver Package - TOSHIBA (FwLnk) System (11/19/2006 1.0.0.3)
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
"Microsoft Visual Studio 2008 Remote Debugger - ENU" = Microsoft Visual Studio 2008 Remote Debugger - ENU
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{02CA24DD-C8B0-4280-BE53-7862869C2EB1}" = Realtek WiFi Protected Setup Library
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{0FB630AB-7BD8-40AE-B223-60397D57C3C9}" = Realtek WLAN Driver
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1B87C40B-A60B-4EF3-9A68-706CF4B69978}" = TOSHIBA Assist
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23E5C72C-CC08-4EE0-9CC2-D925B232B331}" = Microsoft MSDN 2005 Express Edition - ENU
"{241F2BF7-69EB-42A4-9156-96B2426C7504}" = Microsoft SQL Server Compact 3.5 for Devices ENU
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 17
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{2E5C075E-11AB-4BDD-918C-7B9A68953FF8}" = Microsoft SQL Server Compact 3.5 Design Tools ENU
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3A762A82-618D-3CAA-B847-D074ABFA0B2E}" = MSDN Library for Visual Studio 2008 - ENU
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4C3F3228-13BE-41D0-A782-3DDE7CB2479A}" = CD/DVD Drive Acoustic Silencer
"{50F68032-B5B7-4513-9116-C978DBD8F27A}" = DVD MovieFactory for TOSHIBA
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6C9F6D23-E9AD-43C9-B43A-011562AAF876}" = Windows Mobile 5.0 SDK R2 for Pocket PC
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7E7D7935-B0C8-4032-80BA-2CDC9E43C3B8}" = Microsoft Visual C# 2005 Express Edition - ENU
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{870815CA-6B60-47B6-88DD-A67F42D2F03E}" = GPL MPEG-1/2 DirectShow Decoder Filter
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-0021-0000-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer 2007
"{90120000-0021-0000-0000-0000000FF1CE}_VisualWebDeveloper_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0021-0409-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer MUI (English) 2007
"{90120000-0021-0409-0000-0000000FF1CE}_VisualWebDeveloper_{E1044ED2-E4AD-4B39-B500-31109750F6B4}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9656F3AC-6BA9-43F0-ABED-F214B5DAB27B}" = Windows Mobile 5.0 SDK R2 for Smartphone
"{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}" = Microsoft SQL Server Database Publishing Wizard 1.2
"{9A996B6A-846E-4A89-B9C4-17546B7BE49F}" = Burnout™ Paradise The Ultimate Box
"{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}" = Counter-Strike 1.6
"{9C201F63-DE1C-0984-0FA3-85604539B5C6}" = How I Met Your Mother Desktop
"{A208044D-A88B-4ACF-AE95-E4F213E6EDC0}" = TOSHIBA Supervisor Password
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AA467959-A1D6-4F45-90CD-11DC57733F32}" = Crystal Reports Basic for Visual Studio 2008
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{AE8FFD41-8BFC-47D3-829E-77D23BFF09FF}" = My TOSHIBA
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BCC899FE-2DAA-460C-A5FB-60291E73D9C3}" = Microsoft SQL Server Compact 3.5 ENU
"{D0387727-C89D-4774-B643-B9333EAA09DE}" = TOSHIBA Hardware Setup
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D7DAD1E4-45F4-3B2B-899A-EA728167EC4F}" = Microsoft Visual Studio 2008 Professional Edition - ENU
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1
"{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}" = Microsoft .NET Compact Framework 2.0 SP2
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0A386D2-6E15-4A8F-A04E-87CE9BED0D48}" = TOSHIBA ConfigFree
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2004B8D-7791-4B35-A3FA-D8CA8BB4DD81}" = Direct DiscRecorder
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FF29527A-44CD-3422-945E-981A13584000}" = VC Runtimes MSI
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"com.cbs.himym.desktop.E9E67C1457924EABBA27327D1BAF79E9B78ADD40.1" = How I Met Your Mother Desktop
"DC++" = DC++ 0.750
"Desktop Calendar_is1" = Desktop Calendar 0.43b
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"InstallShield_{50F68032-B5B7-4513-9116-C978DBD8F27A}" = DVD MovieFactory for TOSHIBA
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{89F7D66C-777D-473B-AA11-319C0F190EAC}" = TOSHIBA Internal Modem Region Select Utility
"InstallShield_{B3FF1CD9-B2F0-4D71-BB55-5F580401C48E}" = TOSHIBA eco Utility
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"InstallShield_{F2004B8D-7791-4B35-A3FA-D8CA8BB4DD81}" = Direct DiscRecorder
"InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft MSDN 2005 Express Edition - ENU" = Microsoft MSDN 2005 Express Edition - ENU
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual C# 2005 Express Edition - ENU" = Microsoft Visual C# 2005 Express Edition - ENU
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Microsoft Visual Studio 2008 Professional Edition - ENU" = Microsoft Visual Studio 2008 Professional Edition - ENU
"Mozilla Firefox (3.5.6)" = Mozilla Firefox (3.5.6)
"MSDN Library for Visual Studio 2008 - ENU" = MSDN Library for Visual Studio 2008 - ENU
"NAV" = Norton AntiVirus
"Picasa 3" = Picasa 3
"Veoh Web Player Beta" = Veoh Web Player
"Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"VisualWebDeveloper" = Microsoft Visual Studio Web Authoring Component
"VLC media player" = VLC media player 1.0.3
"WildTangent toshiba Master Uninstall" = WildTangent Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 19/12/2009 12:08:41 PM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 19/12/2009 12:08:41 PM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 19/12/2009 12:08:41 PM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 19/12/2009 12:08:41 PM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 19/12/2009 12:08:41 PM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 19/12/2009 12:08:41 PM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 19/12/2009 3:39:55 PM | Computer Name = Owner-PC | Source = System Restore | ID = 8193
Description =

Error - 19/12/2009 3:53:22 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 11722
Description =

Error - 20/12/2009 1:02:53 AM | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description =

Error - 20/12/2009 12:46:55 PM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application rlvknlg.exe, version 1.3.324.349, time stamp
0x4ab39488, faulting module kernel32.dll, version 6.0.6002.18005, time stamp 0x49e038c0,
exception code 0xc0000005, fault offset 0x000135ff, process id 0x108c, application
start time 0x01ca8131adf6b51c.

[ Media Center Events ]
Error - 12/12/2009 3:09:38 PM | Computer Name = Owner-PC | Source = MCUpdate | ID = 0
Description = Failed to retrieve SportsSchedule (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)
(2916.1114)

Error - 12/12/2009 4:09:39 PM | Computer Name = Owner-PC | Source = MCUpdate | ID = 0
Description = Failed to retrieve SportsSchedule (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)
(3432.1114)

Error - 12/12/2009 5:09:41 PM | Computer Name = Owner-PC | Source = MCUpdate | ID = 0
Description = Failed to retrieve SportsSchedule (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)
(1584.1114)

Error - 12/12/2009 6:09:44 PM | Computer Name = Owner-PC | Source = MCUpdate | ID = 0
Description = Failed to retrieve SportsSchedule (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)
(1340.1114)

Error - 16/12/2009 3:43:47 AM | Computer Name = Owner-PC | Source = MCUpdate | ID = 0
Description = Failed to retrieve Directory (Error: The underlying connection was
closed: Could not establish trust relationship for the SSL/TLS secure channel.)
(7004.1114)

Error - 16/12/2009 3:43:48 AM | Computer Name = Owner-PC | Source = MCUpdate | ID = 0
Description = Failed to retrieve SportsSchedule (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)
(7004.1114)

Error - 16/12/2009 3:43:48 AM | Computer Name = Owner-PC | Source = MCUpdate | ID = 0
Description = Failed to retrieve SportsTemplate (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)
(7004.1114)

Error - 16/12/2009 3:43:48 AM | Computer Name = Owner-PC | Source = MCUpdate | ID = 0
Description = Failed to retrieve MCESpotlight (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)
(7004.1114)

Error - 16/12/2009 3:43:48 AM | Computer Name = Owner-PC | Source = MCUpdate | ID = 0
Description = Failed to retrieve MCEClientUX (Error: The underlying connection was
closed: Could not establish trust relationship for the SSL/TLS secure channel.)
(7004.1114)

Error - 16/12/2009 3:43:48 AM | Computer Name = Owner-PC | Source = MCUpdate | ID = 0
Description = Failed to retrieve ClientUpdate (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)
(7004.1114)

[ System Events ]
Error - 07/12/2009 11:38:26 PM | Computer Name = Owner-PC | Source = DCOM | ID = 10010
Description =

Error - 07/12/2009 11:54:25 PM | Computer Name = Owner-PC | Source = DCOM | ID = 10010
Description =

Error - 07/12/2009 11:54:56 PM | Computer Name = Owner-PC | Source = DCOM | ID = 10010
Description =

Error - 08/12/2009 12:22:12 AM | Computer Name = Owner-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 11:14:29 PM on 07/12/2009 was unexpected.

Error - 08/12/2009 12:27:01 AM | Computer Name = Owner-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 11:26:01 PM on 07/12/2009 was unexpected.

Error - 08/12/2009 12:27:31 AM | Computer Name = Owner-PC | Source = DCOM | ID = 10005
Description =

Error - 08/12/2009 12:27:39 AM | Computer Name = Owner-PC | Source = DCOM | ID = 10005
Description =

Error - 08/12/2009 12:27:41 AM | Computer Name = Owner-PC | Source = DCOM | ID = 10005
Description =

Error - 08/12/2009 12:27:41 AM | Computer Name = Owner-PC | Source = DCOM | ID = 10005
Description =

Error - 08/12/2009 12:27:41 AM | Computer Name = Owner-PC | Source = DCOM | ID = 10005
Description =


< End of report >
Hi,

please do the following:



Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O33 - MountPoints2\{4613d63f-ecb8-11de-9579-da110de6d290}\Shell\AutoRun\command - "" = D:\WDSetup.exe – File not found
    O33 - MountPoints2\{eca286de-9a57-11de-9c76-00225fd91d33}\Shell\AutoRun\command - "" = D:\RECYCLERS-1-6-21-1257894210-1075856346-012573477-2510\systemdl32.exe – File not found
    O33 - MountPoints2\{eca286de-9a57-11de-9c76-00225fd91d33}\Shell\open\command - "" = D:\RECYCLERS-1-6-21-1257894210-1075856346-012573477-2510\systemdl32.exe – File not found
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log



NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.




NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
hey here are the reports… All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4613d63f-ecb8-11de-9579-da110de6d290}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4613d63f-ecb8-11de-9579-da110de6d290}\ not found. File D:\WDSetup.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{eca286de-9a57-11de-9c76-00225fd91d33}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{eca286de-9a57-11de-9c76-00225fd91d33}\ not found. File D:\RECYCLERS-1-6-21-1257894210-1075856346-012573477-2510\systemdl32.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{eca286de-9a57-11de-9c76-00225fd91d33}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{eca286de-9a57-11de-9c76-00225fd91d33}\ not found. File D:\RECYCLERS-1-6-21-1257894210-1075856346-012573477-2510\systemdl32.exe not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 57482 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Owner ->Temp folder emptied: 748904139 bytes ->Temporary Internet Files folder emptied: 47449754 bytes ->Java cache emptied: 38979182 bytes ->FireFox cache emptied: 58035779 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes Windows Temp folder emptied: 79552693 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 5263936 bytes Total Files Cleaned = 933.00 mb OTL by OldTimer - Version 3.1.20.1 log created on 12312009_001612 Files\Folders moved on Reboot… File\Folder C:\Windows\temp\JET1257.tmp not found! Registry entries deleted on Reboot… malwarebytes Malwarebytes' Anti-Malware 1.43 Database version: 3461 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18865 31/12/2009 12:28:53 AM mbam-log-2009-12-31 (00-28-53).txt Scan type: Quick Scan Objects scanned: 99086 Time elapsed: 4 minute(s), 47 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) oinline scanner ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, December 31, 2009 Operating system: Microsoft Windows Vista Home Premium Edition, 64-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Thursday, December 31, 2009 05:30:47 Records in database: 3418541 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ E:\ F:\ Scan statistics: Objects scanned: 183493 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 10:11:32 No threats found. Scanned area is clean. Selected area has been scanned.
Hi,

You appear to be clean,

Just some housekeeping to do now.

Please do the following:

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


NEXT

Set correct settings for files that should be hidden in Windows Vista
  • Click Start.
  • Open My Computer.
  • Select Folder and Search Options
  • Select the View Tab.
  • Under the Hidden files and folders heading select Hide hidden files and folders.
  • Check Hide file extensions for known file types
  • Check the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.


NEXT


Now we need to create a new clean SYSTEM RESTORE point.

  • press the Win key on the keyboard, type Restore then press enter to get to the System Restore section.
  • Click "Create a restore point" Click on the "Create" button to create a new restore point. You may be prompted for permission to continue - ALLOW it to continue. You'll be prompted for a name, and you might want to give it a useful name that you'll be able to easily identify later.
  • Click the Create button, and then the system will create the restore point.
  • When it's all finished, you'll get a message saying it's completed successfully.
  • You will now have a new restore point

Then remove all previous Restore Points
  • Click Win key on the keyboard, type cleanmgr to access the disk cleanup
  • choose all files on the computer, then choose the C: drive, press OK Disk cleanup calculates the files, this takes a few minutes > another menu will pop up.
  • At the top, click on the More Options tab, under System Restore and Shadow Copies group,
  • Click the Clean up button,
  • Vista will ask you if you’re sure, click on the Delete button, click OK > Delete Files


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI