This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Sending Spam?

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been notified by my IP provider that someone is sending spam from our IP address. I have two other housemates using our router, so it may not originate from me, but I want to check and make sure. I have scanned my system with Norton, Malwarebytes, Ad-Aware, and Spybot S&D, found and removed something called Win32.webdir.b, and some tracking cookies. Time Warner (our Internet provider) has warned us that if reports of spam come in again, our connection will be permanently cut off…. I was told that there is a way to monitor traffic on port 25 through the firewall somehow, but I have no idea how to do this. Here is my Hijack This log, can anyone please help me figure out if I'm infected and, if so, how to get rid of it? Thanks in advance!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:52:31 PM, on 3/3/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18385)
Boot mode: Normal

Running processes:
C:\Program Files\Norton AntiVirus\Engine\17.5.0.127\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Windows\System32\ico.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\AIM6\aim6.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Tamara\Program Files\DNA\btdna.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.5.0.127\IPSBHO.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Tamara\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O19 - User stylesheet: (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\17.5.0.127\ccSvcHst.exe
O23 - Service: pinger - Unknown owner - C:\Toshiba\IVP\ISM\pinger.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
Hello finilpalma and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. OTL ncludes all the scan locations of HijackThis and more. It's not only a more comprehensive scan tool, but also offers more powerful removal features.

Download and Run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

Download DeFogger

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked.
    Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file.
  • Save it where you can easily find it, such as your desktop, and copy/paste the results in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Run DeFogger

To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.

Please be sure to include the OTL, extras, and GMER logs in your next reply.
Sorry for the wait, I've been trying to back up my system before doing anything. In any case, I ran OTL and DeFogger fine, but GMER didn't work - at first the program kept closing for some reason, and then my computer starting shutting down suddenly (blue screen), so I stopped trying. I ran DeFogger and re-enabled the drivers, and I'm posting the two text files with OTL scan results.

OTL logfile created on: 3/10/2010 9:46:06 AM - Run 1
OTL by OldTimer - Version 3.1.36.0 Folder = C:\Users\Tamara\Downloads
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 59.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 110.32 Gb Total Space | 2.12 Gb Free Space | 1.92% Space Free | Partition Type: NTFS
Drive D: | 149.05 Gb Total Space | 31.56 Gb Free Space | 21.18% Space Free | Partition Type: NTFS
Unable to calculate disk information.
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TAMARA-PC
Current User Name: Tamara
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/03/10 09:43:34 | 000,554,496 | —- | M] (OldTimer Tools) – C:\Users\Tamara\Downloads\OTL(2).exe
PRC - [2010/02/27 18:32:25 | 000,815,184 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010/02/27 18:32:24 | 001,229,232 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/12/09 04:05:51 | 000,126,392 | R— | M] (Symantec Corporation) – C:\Program Files\Norton AntiVirus\Engine\17.5.0.127\ccsvchst.exe
PRC - [2009/11/06 20:51:54 | 000,323,392 | —- | M] (BitTorrent, Inc.) – C:\Users\Tamara\Program Files\DNA\btdna.exe
PRC - [2009/07/17 22:12:12 | 000,257,440 | R— | M] (Adobe Systems, Inc.) – C:\Windows\System32\Macromed\Flash\FlashUtil10c.exe
PRC - [2009/05/19 00:23:16 | 000,049,968 | —- | M] (AOL LLC) – C:\Program Files\AIM6\aim6.exe
PRC - [2009/02/12 03:04:50 | 000,039,408 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2008/11/06 12:33:00 | 000,041,264 | —- | M] (AOL LLC) – C:\Program Files\AIM6\aolsoftware.exe
PRC - [2008/10/29 01:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/10/25 08:18:50 | 000,098,696 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2008/01/18 22:33:14 | 000,299,520 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\ieuser.exe
PRC - [2007/03/16 14:47:02 | 000,131,072 | —- | M] (Primax Electronics Ltd.) – C:\Windows\System32\PELMICED.EXE
PRC - [2007/02/13 11:30:24 | 000,405,504 | —- | M] (Chicony) – C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
PRC - [2007/02/13 01:44:26 | 004,411,392 | —- | M] () – C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
PRC - [2007/02/06 20:50:08 | 004,374,528 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
PRC - [2007/02/02 17:56:52 | 000,118,784 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
PRC - [2007/02/02 16:07:14 | 000,192,512 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynToshiba.exe
PRC - [2007/01/25 20:50:26 | 000,063,096 | —- | M] () – c:\Toshiba\IVP\swupdate\swupdtmr.exe
PRC - [2007/01/25 20:47:50 | 000,136,816 | —- | M] () – C:\Toshiba\IVP\ISM\pinger.exe
PRC - [2007/01/19 01:24:20 | 000,448,632 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\SmoothView\SmoothView.exe
PRC - [2007/01/17 16:46:32 | 000,534,648 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
PRC - [2007/01/04 16:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2006/12/20 02:16:44 | 000,411,768 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
PRC - [2006/12/20 02:15:44 | 000,428,152 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
PRC - [2006/12/03 18:51:38 | 000,021,504 | —- | M] (UPEK Inc.) – C:\Program Files\Protector Suite QL\upeksvr.exe
PRC - [2006/11/15 01:02:36 | 001,372,160 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
PRC - [2006/11/15 00:19:42 | 000,405,504 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
PRC - [2006/11/14 23:33:10 | 000,040,960 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
PRC - [2006/11/10 17:22:26 | 000,417,792 | —- | M] (TOSHIBA) – C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
PRC - [2006/10/23 12:54:36 | 000,056,128 | —- | M] (Primax Electronics Ltd.) – C:\Windows\System32\ico.exe
PRC - [2006/10/05 14:10:12 | 000,009,216 | —- | M] (Agere Systems) – C:\Windows\System32\agrsmsvc.exe
PRC - [2006/08/23 19:39:48 | 000,049,152 | —- | M] (Ulead Systems, Inc.) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
PRC - [2006/05/25 21:30:16 | 000,114,688 | —- | M] (TOSHIBA Corporation) – C:\Windows\System32\TODDSrv.exe


========== Modules (SafeList) ==========

MOD - [2010/03/10 09:43:34 | 000,554,496 | —- | M] (OldTimer Tools) – C:\Users\Tamara\Downloads\OTL(2).exe
MOD - [2008/01/18 22:26:36 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/02/27 18:32:24 | 001,229,232 | —- | M] (Lavasoft) [Auto | Running] – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2009/12/09 04:05:51 | 000,126,392 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files\Norton AntiVirus\Engine\17.5.0.127\ccSvcHst.exe – (NAV)
SRV - [2009/10/20 13:19:48 | 000,117,264 | —- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] – C:\Program Files\WinPcap\rpcapd.exe – (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2008/01/18 22:38:26 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/12/18 13:40:02 | 000,181,784 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe – (GameConsoleService)
SRV - [2007/02/02 17:56:52 | 000,118,784 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe – (TOSHIBA Bluetooth Service)
SRV - [2007/01/25 20:50:26 | 000,063,096 | —- | M] () [Auto | Running] – c:\Toshiba\IVP\swupdate\swupdtmr.exe – (Swupdtmr)
SRV - [2007/01/25 20:47:50 | 000,136,816 | —- | M] () [Auto | Running] – C:\Toshiba\IVP\ISM\pinger.exe – (pinger)
SRV - [2007/01/04 16:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Auto | Running] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2006/12/20 02:15:44 | 000,428,152 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe – (TosCoSrv)
SRV - [2006/11/14 23:33:10 | 000,040,960 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe – (CFSvcs)
SRV - [2006/10/05 14:10:12 | 000,009,216 | —- | M] (Agere Systems) [Auto | Running] – C:\Windows\System32\agrsmsvc.exe – (AgereModemAudio)
SRV - [2006/08/23 19:39:48 | 000,049,152 | —- | M] (Ulead Systems, Inc.) [Auto | Running] – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe – (UleadBurningHelper)
SRV - [2006/05/25 21:30:16 | 000,114,688 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Windows\System32\TODDSrv.exe – (TODDSrv)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://msn.com"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.53
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\IPSFFPlgn\ [2010/02/08 10:19:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/02 22:30:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/02 22:30:01 | 000,000,000 | —D | M]

[2008/12/11 21:37:14 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Mozilla\Extensions
[2010/03/10 09:21:47 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Mozilla\Firefox\Profiles\ps5dyxqc.default\extensions
[2009/09/02 20:39:25 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Tamara\AppData\Roaming\Mozilla\Firefox\Profiles\ps5dyxqc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/08 20:28:15 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\Tamara\AppData\Roaming\Mozilla\Firefox\Profiles\ps5dyxqc.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2008/12/11 23:12:58 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2007/04/16 12:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.5.0.127\ipsbho.dll (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\Protector Suite QL\launcher.exe (UPEK Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Aim6] C:\Program Files\AIM6\aim6.exe (AOL LLC)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Users\Tamara\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [TOSCDSPD] File not found
O4 - Startup: C:\Users\Tamara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (Sony Corporation)
O4 - Startup: C:\Users\Tamara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (vrlogon.dll) - C:\Windows\System32\vrlogon.dll (UPEK Inc.)
O20 - Winlogon\Notify\psfus: DllName - C:\Windows\system32\psqlpwd.dll - C:\Windows\System32\psqlpwd.dll (UPEK Inc.)
O24 - Desktop WallPaper: C:\Users\Tamara\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Tamara\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{3259739a-de20-11de-bc1e-00a0d17664fd}\Shell - "" = AutoRun
O33 - MountPoints2\{3259739a-de20-11de-bc1e-00a0d17664fd}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O33 - MountPoints2\{56d97bff-365d-11dc-aa66-0013e822c423}\Shell - "" = AutoRun
O33 - MountPoints2\{56d97bff-365d-11dc-aa66-0013e822c423}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{6cff94eb-7c0f-11de-9523-00a0d17664fd}\Shell\Auto\command - "" = RECYCLER\koyko.exe
O33 - MountPoints2\{6cff94eb-7c0f-11de-9523-00a0d17664fd}\Shell\AutoRun\command - "" = RECYCLER\koyko.exe
O33 - MountPoints2\{b727f909-165f-11dd-9739-00a0d17664fd}\Shell\AutoRun\command - "" = G:\umenu.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/09/12 16:10:34 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
OTL cannot create restorepoints on Vista OSs!

========== Files/Folders - Created Within 14 Days ==========

[2010/03/07 22:01:58 | 000,000,000 | RH-D | C] – C:\Users\Tamara\Desktop\$RECYCLE.BIN
[2010/03/05 01:48:06 | 000,000,000 | —D | C] – C:\Users\Tamara\AppData\Roaming\Wireshark
[2010/03/05 01:30:27 | 000,000,000 | —D | C] – C:\Program Files\WinPcap
[2010/03/05 01:26:45 | 000,000,000 | —D | C] – C:\Program Files\Wireshark
[2010/03/03 21:50:54 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/03/02 23:13:55 | 000,000,000 | —D | C] – C:\Users\Tamara\AppData\Roaming\Facebook
[2010/03/02 22:25:57 | 000,000,000 | —D | C] – C:\Users\Tamara\AppData\Local\CrashDumps
[2010/03/02 18:34:46 | 000,095,024 | —- | C] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/02/27 18:39:18 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/02/27 18:39:18 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/02/27 18:34:00 | 000,064,288 | —- | C] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2010/02/27 18:28:37 | 000,000,000 | -H-D | C] – C:\ProgramData\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/02/27 18:27:51 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010/02/27 18:27:51 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/02/27 18:18:37 | 000,000,000 | —D | C] – C:\Users\Tamara\AppData\Roaming\Malwarebytes
[2010/02/27 18:18:29 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/27 18:18:27 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/02/27 18:18:26 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/02/27 18:18:26 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[3 C:\Users\Tamara\Documents\*.tmp files -> C:\Users\Tamara\Documents\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/03/10 09:45:41 | 003,932,160 | -HS- | M] () – C:\Users\Tamara\ntuser.dat
[2010/03/10 08:55:44 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/10 08:54:24 | 000,000,370 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/03/10 08:53:04 | 000,059,752 | —- | M] () – C:\Users\Tamara\AppData\Roaming\nvModes.001
[2010/03/10 08:50:56 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/10 08:50:23 | 000,003,680 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/10 08:50:23 | 000,003,680 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/10 08:50:20 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/03/10 08:50:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/03/10 08:49:59 | 2145,443,840 | -HS- | M] () – C:\hiberfil.sys
[2010/03/10 08:49:55 | 289,483,030 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/03/10 01:15:56 | 000,059,752 | —- | M] () – C:\Users\Tamara\AppData\Roaming\nvModes.dat
[2010/03/09 14:15:56 | 000,063,989 | —- | M] () – C:\Users\Tamara\Documents\ACE Coding 301-351.xlsx
[2010/03/09 01:34:13 | 000,249,344 | —- | M] () – C:\Users\Tamara\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/08 17:18:20 | 000,030,720 | —- | M] () – C:\Users\Tamara\Documents\Tamara Movsesova cover letter - MHA.doc
[2010/03/08 17:10:51 | 000,037,376 | —- | M] () – C:\Users\Tamara\Documents\TamaraMovsesova resume1.doc
[2010/03/08 17:05:00 | 000,173,573 | —- | M] () – C:\Users\Tamara\Desktop\bookmarks-2010-03-08.json
[2010/03/08 01:43:16 | 000,065,536 | -HS- | M] () – C:\Users\Tamara\ntuser.dat{e7573853-26e7-11dd-b7fd-00a0d17664fd}.TM.blf
[2010/03/08 01:43:15 | 000,524,288 | -HS- | M] () – C:\Users\Tamara\ntuser.dat{e7573853-26e7-11dd-b7fd-00a0d17664fd}.TMContainer00000000000000000001.regtrans-ms
[2010/03/08 00:08:30 | 000,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/03/08 00:08:30 | 000,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/03/08 00:08:30 | 000,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/03/07 23:35:12 | 000,012,714 | —- | M] () – C:\Users\Tamara\Documents\internships.docx
[2010/03/07 21:47:35 | 000,000,165 | -H– | M] () – C:\Users\Tamara\Documents\~$ACE Coding 301-351.xlsx
[2010/03/07 19:07:08 | 000,075,623 | —- | M] () – C:\Users\Tamara\Documents\ACE Coding Sheets.xlsx
[2010/03/04 23:55:17 | 002,555,960 | -H– | M] () – C:\Users\Tamara\AppData\Local\IconCache.db
[2010/03/04 01:08:53 | 000,040,960 | —- | M] () – C:\Users\Tamara\Documents\TamaraMovsesova cv1.doc
[2010/03/03 21:50:55 | 000,001,885 | —- | M] () – C:\Users\Tamara\Desktop\HijackThis.lnk
[2010/02/28 20:10:17 | 001,830,912 | —- | M] () – C:\Users\Tamara\Documents\Movsesova - SURF.doc
[2010/02/27 22:19:52 | 001,825,280 | —- | M] () – C:\Users\Tamara\Documents\Summer_Research_Program_Application.doc
[2010/02/27 18:39:45 | 000,001,066 | —- | M] () – C:\Users\Tamara\Desktop\Spybot - Search & Destroy.lnk
[2010/02/27 18:33:28 | 000,095,024 | —- | M] (Sunbelt Software) – C:\Windows\System32\drivers\SBREDrv.sys
[2010/02/27 18:33:23 | 000,015,880 | —- | M] () – C:\Windows\System32\lsdelete.exe
[2010/02/27 18:28:33 | 000,001,018 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/02/27 18:27:04 | 000,035,328 | —- | M] () – C:\Users\Tamara\Documents\UCI SURF personal statement.doc
[2010/02/27 18:18:33 | 000,000,829 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/26 23:06:00 | 000,083,288 | —- | M] () – C:\Users\Tamara\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/02/26 22:01:49 | 000,001,356 | —- | M] () – C:\Users\Tamara\AppData\Local\d3d9caps.dat
[2010/02/26 17:54:07 | 000,326,088 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/02/25 02:04:31 | 000,030,720 | —- | M] () – C:\Users\Tamara\Documents\2010ApplicantAdvertisingLetter.doc
[2010/02/24 18:30:12 | 000,030,208 | —- | M] () – C:\Users\Tamara\Documents\NIH cover letter.doc
[3 C:\Users\Tamara\Documents\*.tmp files -> C:\Users\Tamara\Documents\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/03/10 08:54:20 | 000,000,370 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/03/08 17:04:59 | 000,173,573 | —- | C] () – C:\Users\Tamara\Desktop\bookmarks-2010-03-08.json
[2010/03/07 21:47:35 | 000,063,989 | —- | C] () – C:\Users\Tamara\Documents\ACE Coding 301-351.xlsx
[2010/03/07 21:47:35 | 000,000,165 | -H– | C] () – C:\Users\Tamara\Documents\~$ACE Coding 301-351.xlsx
[2010/03/03 21:50:55 | 000,001,885 | —- | C] () – C:\Users\Tamara\Desktop\HijackThis.lnk
[2010/02/28 20:10:15 | 001,830,912 | —- | C] () – C:\Users\Tamara\Documents\Movsesova - SURF.doc
[2010/02/28 18:32:30 | 2145,443,840 | -HS- | C] () – C:\hiberfil.sys
[2010/02/28 03:55:04 | 000,015,880 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2010/02/27 18:39:44 | 000,001,066 | —- | C] () – C:\Users\Tamara\Desktop\Spybot - Search & Destroy.lnk
[2010/02/27 18:28:32 | 000,001,018 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2010/02/27 18:26:41 | 000,035,328 | —- | C] () – C:\Users\Tamara\Documents\UCI SURF personal statement.doc
[2010/02/27 18:18:32 | 000,000,829 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/26 17:47:49 | 001,825,280 | —- | C] () – C:\Users\Tamara\Documents\Summer_Research_Program_Application.doc
[2010/02/25 02:04:31 | 000,030,720 | —- | C] () – C:\Users\Tamara\Documents\2010ApplicantAdvertisingLetter.doc
[2009/10/20 13:19:30 | 000,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2009/10/15 03:00:54 | 000,000,448 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2008/09/12 15:19:52 | 000,081,158 | —- | C] () – C:\Windows\System32\manage-bde.ini.en
[2008/09/10 20:20:45 | 000,716,272 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2008/05/18 23:07:41 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2008/04/19 23:58:03 | 000,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2008/04/19 23:58:00 | 002,102,272 | —- | C] () – C:\Windows\System32\x264vfw.dll
[2008/04/19 23:57:59 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/04/19 23:57:59 | 000,755,027 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/04/19 23:57:59 | 000,159,839 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/04/19 23:57:56 | 000,007,680 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2008/04/19 23:57:56 | 000,000,547 | —- | C] () – C:\Windows\System32\ff_vfw.dll.manifest
[2008/01/30 02:03:48 | 000,000,067 | —- | C] () – C:\Windows\swupdate.INI
[2007/09/04 12:00:01 | 000,001,356 | —- | C] () – C:\Users\Tamara\AppData\Local\d3d9caps.dat
[2007/08/25 20:30:19 | 000,031,232 | —- | C] () – C:\Windows\System32\AsynInet.dll
[2007/08/25 20:30:18 | 000,027,136 | —- | C] () – C:\Windows\System32\tdecode.dll
[2007/08/25 20:30:18 | 000,024,064 | —- | C] () – C:\Windows\System32\TWBCust.dll
[2007/07/13 22:28:34 | 000,059,752 | —- | C] () – C:\Users\Tamara\AppData\Roaming\nvModes.dat
[2007/07/13 22:28:34 | 000,059,752 | —- | C] () – C:\Users\Tamara\AppData\Roaming\nvModes.001
[2007/07/13 19:09:12 | 000,007,587 | —- | C] () – C:\ProgramData\hpzinstall.log
[2007/07/13 18:58:58 | 000,249,344 | —- | C] () – C:\Users\Tamara\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/31 02:29:53 | 000,128,113 | —- | C] () – C:\Windows\System32\csellang.ini
[2007/05/31 02:29:53 | 000,045,056 | —- | C] () – C:\Windows\System32\csellang.dll
[2007/05/31 02:29:53 | 000,010,150 | —- | C] () – C:\Windows\System32\tosmreg.ini
[2007/05/31 02:29:53 | 000,007,671 | —- | C] () – C:\Windows\System32\cseltbl.ini
[2007/03/05 12:34:28 | 000,676,224 | —- | C] () – C:\Windows\System32\OGACheckControl.DLL
[2007/03/02 14:03:00 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2007/03/02 14:03:00 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2007/03/02 14:03:00 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2007/03/02 14:03:00 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2007/03/02 14:03:00 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2007/03/02 14:03:00 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2007/02/28 15:46:33 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2007/02/28 15:39:56 | 000,524,288 | -HS- | C] () – C:\ProgramData\ntuser.dat{03e71b19-c763-11db-a603-00a0d1df23e9}.TMContainer00000000000000000002.regtrans-ms
[2007/02/28 15:39:56 | 000,524,288 | -HS- | C] () – C:\ProgramData\ntuser.dat{03e71b19-c763-11db-a603-00a0d1df23e9}.TMContainer00000000000000000001.regtrans-ms
[2007/02/28 15:39:56 | 000,065,536 | -HS- | C] () – C:\ProgramData\ntuser.dat{03e71b19-c763-11db-a603-00a0d1df23e9}.TM.blf
[2007/02/28 15:39:55 | 000,524,288 | -HS- | C] () – C:\ProgramData\ntuser.dat{03e71b09-c763-11db-a603-00a0d1df23e9}.TMContainer00000000000000000002.regtrans-ms
[2007/02/28 15:39:55 | 000,524,288 | -HS- | C] () – C:\ProgramData\ntuser.dat{03e71b09-c763-11db-a603-00a0d1df23e9}.TMContainer00000000000000000001.regtrans-ms
[2007/02/28 15:39:55 | 000,262,144 | —- | C] () – C:\ProgramData\ntuser.dat
[2007/02/28 15:39:55 | 000,065,536 | -HS- | C] () – C:\ProgramData\ntuser.dat{03e71b09-c763-11db-a603-00a0d1df23e9}.TM.blf
[2007/02/28 15:39:55 | 000,005,120 | -H– | C] () – C:\ProgramData\ntuser.dat.LOG1
[2007/02/28 15:39:55 | 000,000,000 | -H– | C] () – C:\ProgramData\ntuser.dat.LOG2
[2006/12/05 16:05:06 | 000,114,688 | —- | C] () – C:\Windows\System32\TosBtAcc.dll
[2006/11/02 07:34:20 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:25:21 | 000,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 13:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2005/07/23 00:30:20 | 000,065,536 | —- | C] () – C:\Windows\System32\TosCommAPI.dll
[2002/10/06 13:42:56 | 000,237,568 | —- | C] () – C:\Windows\System32\OggDS.dll
[2002/10/04 18:04:24 | 000,921,600 | —- | C] () – C:\Windows\System32\VorbisEnc.dll
[2002/10/04 18:04:24 | 000,188,416 | —- | C] () – C:\Windows\System32\vorbis.dll
[2002/10/04 18:04:16 | 000,045,056 | —- | C] () – C:\Windows\System32\ogg.dll
[2001/06/15 11:41:12 | 000,000,601 | —- | C] () – C:\Windows\krb5.ini
[2000/04/14 10:12:48 | 000,032,768 | —- | C] () – C:\Windows\KCLNT32.dll

========== LOP Check ==========

[2007/08/26 17:48:02 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\acccore
[2009/09/28 21:23:41 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\DC++
[2008/10/30 19:40:26 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Dev-Cpp
[2010/03/10 09:43:30 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\DNA
[2010/03/02 23:14:06 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Facebook
[2009/02/27 18:01:32 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\GetRightToGo
[2009/12/04 13:29:00 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Image Zone Express
[2007/07/19 20:28:21 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\InterVideo
[2007/09/17 23:22:26 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Printer Info Cache
[2008/09/12 00:51:33 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\SPORE
[2010/02/26 17:49:09 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\uTorrent
[2007/07/25 16:57:27 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\WildTangent
[2010/03/05 01:48:06 | 000,000,000 | —D | M] – C:\Users\Tamara\AppData\Roaming\Wireshark
[2010/03/10 08:54:24 | 000,000,370 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2010/03/05 00:03:37 | 000,032,610 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/01/19 02:42:25 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\SoftwareDistribution\Download\a58fa8f1a78b89e6c2a670e288053b8b\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/18 22:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/18 22:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/18 22:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 04:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\drivers\AGP440.sys
[2006/11/02 04:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/04/11 01:32:26 | 000,019,944 | —- | M] (Microsoft Corporation) MD5=1F05B78AB91C9075565A9D8A4B880BC4 – C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
[2008/01/19 02:41:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\SoftwareDistribution\Download\a58fa8f1a78b89e6c2a670e288053b8b\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2008/01/18 22:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\drivers\atapi.sys
[2008/01/18 22:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/18 22:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 04:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/02/13 03:07:31 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2008/02/13 03:07:31 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2008/02/13 03:07:30 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 04:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 04:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2006/12/03 18:53:08 | 000,033,280 | —- | M] (UPEK Inc.) MD5=A23819D7B19E5ECF16AAD99D90291381 – C:\Program Files\Protector Suite QL\eventlog.dll

< MD5 for: IASTORV.SYS >
[2008/01/19 02:42:51 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\SoftwareDistribution\Download\a58fa8f1a78b89e6c2a670e288053b8b\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2008/01/18 22:42:52 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/18 22:42:52 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 04:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\drivers\iaStorV.sys
[2006/11/02 04:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: KR10N.SYS >
[2007/01/03 03:43:19 | 000,207,104 | —- | M] (TOSHIBA CORPORATION) MD5=A1963360E74931222A67356C8AD48378 – C:\Windows\System32\drivers\KR10N.sys
[2007/01/03 03:43:19 | 000,207,104 | —- | M] (TOSHIBA CORPORATION) MD5=A1963360E74931222A67356C8AD48378 – C:\Windows\System32\DriverStore\FileRepository\kr10n.inf_f8c77270\KR10N.sys

< MD5 for: NETLOGON.DLL >
[2006/11/02 04:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2009/04/11 01:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[2008/01/19 02:35:36 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\SoftwareDistribution\Download\a58fa8f1a78b89e6c2a670e288053b8b\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
[2008/01/18 22:35:38 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\System32\netlogon.dll
[2008/01/18 22:35:38 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2006/11/02 04:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\drivers\nvstor.sys
[2006/11/02 04:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/19 02:42:09 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\SoftwareDistribution\Download\a58fa8f1a78b89e6c2a670e288053b8b\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
[2008/01/18 22:42:10 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/18 22:42:10 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/19 02:36:19 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\SoftwareDistribution\Download\a58fa8f1a78b89e6c2a670e288053b8b\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2008/01/18 22:36:20 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\System32\scecli.dll
[2008/01/18 22:36:20 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006/11/02 04:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
[2009/04/11 01:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/12/18 08:01:57 | 000,193,024 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\iepeers.dll
[2008/01/18 22:38:04 | 000,242,744 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2008/01/18 22:36:12 | 000,225,792 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\SLC.dll
[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2008/09/10 20:20:46 | 000,716,272 | —- | M] () Unable to obtain MD5 – C:\Windows\System32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2007/02/28 14:10:52 | 007,147,520 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2007/02/28 14:10:49 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2007/02/28 14:10:52 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2007/02/28 14:11:00 | 016,031,744 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2007/02/28 14:11:02 | 006,070,272 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

========== Files - Unicode (All) ==========
[2008/07/10 19:58:44 | 000,010,145 | —- | M] ()(C:\Users\Tamara\Documents\???????????.docx) – C:\Users\Tamara\Documents\日本語がぜんぶ忘れたよ.docx
[2008/07/10 19:58:43 | 000,010,145 | —- | C] ()(C:\Users\Tamara\Documents\???????????.docx) – C:\Users\Tamara\Documents\日本語がぜんぶ忘れたよ.docx
[2008/07/10 19:50:57 | 000,027,006 | —- | M] ()(C:\Users\Tamara\Documents\???.docx) – C:\Users\Tamara\Documents\日本語.docx
[2008/07/10 19:50:56 | 000,027,006 | —- | C] ()(C:\Users\Tamara\Documents\???.docx) – C:\Users\Tamara\Documents\日本語.docx
[2008/04/30 02:28:57 | 000,015,850 | —- | M] ()(C:\Users\Tamara\Documents\??????.docx) – C:\Users\Tamara\Documents\ロッシアお酒.docx
[2008/04/30 02:28:56 | 000,015,850 | —- | C] ()(C:\Users\Tamara\Documents\??????.docx) – C:\Users\Tamara\Documents\ロッシアお酒.docx
[2007/11/08 01:36:26 | 000,010,414 | —- | M] ()(C:\Users\Tamara\Documents\???????.docx) – C:\Users\Tamara\Documents\ひゃ二重万安い.docx
[2007/11/08 01:36:25 | 000,010,414 | —- | C] ()(C:\Users\Tamara\Documents\???????.docx) – C:\Users\Tamara\Documents\ひゃ二重万安い.docx
[2007/09/15 15:33:34 | 000,010,291 | —- | M] ()(C:\Users\Tamara\Documents\???????.docx) – C:\Users\Tamara\Documents\いった抱きます.docx
[2007/09/15 15:33:34 | 000,010,291 | —- | C] ()(C:\Users\Tamara\Documents\???????.docx) – C:\Users\Tamara\Documents\いった抱きます.docx
< End of report >
OTL Extras logfile created on: 3/10/2010 9:46:06 AM - Run 1
OTL by OldTimer - Version 3.1.36.0 Folder = C:\Users\Tamara\Downloads
Windows Vista Ultimate Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 59.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 110.32 Gb Total Space | 2.12 Gb Free Space | 1.92% Space Free | Partition Type: NTFS
Drive D: | 149.05 Gb Total Space | 31.56 Gb Free Space | 21.18% Space Free | Partition Type: NTFS
Unable to calculate disk information.
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TAMARA-PC
Current User Name: Tamara
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\TOSHIBA\ivp\NetInt\Netint.exe" = C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine – (TOSHIBA Corporation)
"C:\TOSHIBA\Ivp\ISM\pinger.exe" = C:\TOSHIBA\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger – ()


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2A6D72D3-62A1-47E8-841A-5FE3D0D1F542}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{DAA8FC11-E994-4605-A1FE-BDD6BF2CAF2E}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{5027A032-6004-4CAF-95CC-59AA5F3DC7E4}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{51915154-B2A2-4E5F-9E5F-6A037FE29BD2}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{702C5E39-BCAD-47FE-9F0E-E4397DA5AE59}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{771A1309-AB07-42F9-82D8-45A1F2834C2D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{A08A254B-0D03-4B7F-8CEA-0FE12CEEE78D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A61B3481-62C5-4760-B488-F83077BD1D77}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{AA466F9F-D8A2-4891-8D62-C8FAA1A148EE}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B7E63F99-CAAF-407C-8588-4A6044650943}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{C0F28D14-CCA5-489E-94F2-AA10C8B327D9}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{CF3B55D7-5BE4-4526-8E58-876E4BCF8FA2}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{D6355567-EAF0-4582-9018-45216AF4B2C1}" = dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{E16CE10B-7FA4-4956-B241-E3CDF32C7D35}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{FF73A77D-855D-4B30-B759-9EC40BCDAA05}" = dir=in | app=c:\program files\msn messenger\livecall.exe |
"TCP Query User{0EF66649-C9A0-496B-9196-FB0C4019A9C5}C:\program files\aim6\aim6.exe" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"TCP Query User{167A59F5-383E-499D-8967-3A2F452757DA}C:\program files\aim6\aim6.exe" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"TCP Query User{1944A66C-1F5B-411A-82D3-7D65F787ED69}C:\program files\dc++\dcplusplus.exe" = protocol=6 | dir=in | app=c:\program files\dc++\dcplusplus.exe |
"TCP Query User{6113821F-1552-4636-BFEA-FDD20BBF5076}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{66461344-5ECF-4171-B1B5-ED3344B651CB}C:\users\tamara\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\tamara\program files\dna\btdna.exe |
"TCP Query User{954896B9-6AE6-4411-B3B1-C91DCBF124FC}C:\program files\cu services\jtf\jtf.exe" = protocol=6 | dir=in | app=c:\program files\cu services\jtf\jtf.exe |
"TCP Query User{B33FE667-8229-4526-8341-D89291C6E8AD}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{CC41EA3C-35E9-472C-8781-660138238D2E}C:\users\tamara\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\tamara\program files\dna\btdna.exe |
"TCP Query User{F0800B8B-A1FB-47A9-BE52-100C9679409F}C:\windows\sidecar.exe" = protocol=6 | dir=in | app=c:\windows\sidecar.exe |
"UDP Query User{0410B084-2386-4EC2-85E8-0E2C2F9914D9}C:\program files\aim6\aim6.exe" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"UDP Query User{0C512723-C84A-4B1B-BDF2-9E538E1CDF16}C:\users\tamara\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\tamara\program files\dna\btdna.exe |
"UDP Query User{1871EF11-1AC3-4CA2-AE5C-76428335F80B}C:\users\tamara\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\tamara\program files\dna\btdna.exe |
"UDP Query User{4E219B6C-99BD-47EE-AB2D-3CA132063A1D}C:\program files\cu services\jtf\jtf.exe" = protocol=17 | dir=in | app=c:\program files\cu services\jtf\jtf.exe |
"UDP Query User{51973857-4EBD-4914-B5E1-471D14479B07}C:\windows\sidecar.exe" = protocol=17 | dir=in | app=c:\windows\sidecar.exe |
"UDP Query User{96C2498C-B701-46E8-BADD-3621AFEE6C39}C:\program files\aim6\aim6.exe" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"UDP Query User{AD2B26F9-BEE8-40D6-B882-B72889E3D420}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{ED83797D-2616-47F0-BB4F-71371244D111}C:\program files\dc++\dcplusplus.exe" = protocol=17 | dir=in | app=c:\program files\dc++\dcplusplus.exe |
"UDP Query User{F91C2095-7A64-4E45-82B8-5B5736F2B4AB}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0020FEE2-7CDB-4250-B04B-81D68D3CA18B}" =
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{10113A44-CBFF-4FF7-8A13-BD1EC4180C56}" = Protector Suite QL 5.6
"{11204BA5-626B-498F-BBA3-8412DAEC99B2}" = Bear Access Fall 2007
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for TOSHIBA
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{425A2BC2-AA64-4107-9C29-484245BBEA05}" = TOSHIBA Software Upgrades
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{744E2BC2-EC6F-44D5-AA68-451B4131383B}" = TOSHIBA Supervisor Password
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AC76BA86-7AD7-5A76-5A64-7E8A45000001}" = Adobe Reader Japanese Fonts
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B97599D2-01F7-4551-96D8-674D3D886F7B}" = TOSHIBA Hardware Setup
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{DB780B85-B4B5-4864-A49C-9B706B169C93}" = TIPCI
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{ED3F469E-D9EC-4DF1-968F-5812CE2F30F8}" = HP Driver Diagnostics
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EEDBE2DF-4141-44A9-8614-9832B16637E6}" = Mouse Suite
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AIM_6" = AIM 6
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"DC++" = DC++ 0.750
"Desktop Dialer" = Desktop Dialer
"Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2)
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for TOSHIBA
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"KLiteCodecPack_is1" = K-Lite Codec Pack 3.9.0 Full
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.0.18)" = Mozilla Firefox (3.0.18)
"MyCamera" = Canon Utilities MyCamera
"MyCameraDC" = Canon Utilities MyCamera DC
"NAV" = Norton AntiVirus
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoStitch" = Canon Utilities PhotoStitch
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureDC" = Canon Utilities RemoteCapture DC
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOSHIBA Game Console" = TOSHIBA Game Console
"TOSHIBA Media Center Game Console" = TOSHIBA Media Center Game Console
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"ViewpointMediaPlayer" = Viewpoint Media Player
"VisDir Free Disk Space Finder_is1" = VisDir Free Disk Space Finder v 1.5
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinPcapInst" = WinPcap 4.1.1
"WinRAR archiver" = WinRAR archiver
"Wireshark" = Wireshark 1.2.6
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent DNA" = DNA
"Facebook Plug-In" = Facebook Plug-In
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/19/2010 12:35:47 AM | Computer Name = Tamara-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 7.0.6001.18349 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1fd8 Start Time: 01ca98beeddc5ad0 Termination Time: 0

Error - 1/19/2010 12:52:57 AM | Computer Name = Tamara-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 7.0.6001.18349 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1a84 Start Time: 01ca98c0deeac0f0 Termination Time: 0

Error - 1/20/2010 1:41:52 AM | Computer Name = Tamara-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 1.9.0.3642 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1288 Start Time: 01ca9882d55701e0 Termination Time: 679

Error - 1/24/2010 1:06:58 AM | Computer Name = Tamara-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 1.9.0.3642 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 14d0 Start Time: 01ca9c83aa71d4a0 Termination Time: 30

Error - 2/7/2010 5:13:15 AM | Computer Name = Tamara-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 1.9.0.3642 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 178c Start Time: 01caa702080578f0 Termination Time: 37

Error - 2/7/2010 5:19:17 AM | Computer Name = Tamara-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 1.9.0.3642 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 14c0 Start Time: 01caa7d5ca6c2c80 Termination Time: 397

Error - 2/7/2010 2:09:01 PM | Computer Name = Tamara-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 1.9.0.3642 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 698 Start Time: 01caa7d6a115c980 Termination Time: 99

Error - 2/7/2010 2:10:02 PM | Computer Name = Tamara-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 2/9/2010 5:43:37 PM | Computer Name = Tamara-PC | Source = Application Hang | ID = 1002
Description = The program Aurora.scr version 6.0.6001.18000 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 179c Start Time: 01caa9cfe1bbdbf0 Termination Time: 29104

Error - 2/9/2010 5:44:33 PM | Computer Name = Tamara-PC | Source = Application Hang | ID = 1002
Description = The program iTunes.exe version 9.0.2.25 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 10e0 Start Time: 01caa8d2ea5596a0 Termination Time: 216

[ OSession Events ]
Error - 8/24/2007 2:40:20 AM | Computer Name = Tamara-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 41713
seconds with 120 seconds of active time. This session ended with a crash.


========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
P2P - I see you have P2P software (BitTorrent & µTorrent ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

Please be aware it would appear there has been a program called AtomicLog installed on your machine at some point in the past. The files in question have a creation date of 2007. I do not see any evidence of the program currently running, but I wanted to make you aware it appears to have been on the machine. AtomicLog is a program that logs all traffic to and from the Internet and is stored via log file. The log file can only be accessed by the person who installed the program, exposing vital Internet information that you entered like usernames, passwords and credit card numbers. If you knowingly installed the program it is fine, but if you did not, you may need to consider what kind of information may have possibly been compromised.

In light of the above information, I would really like you to try and run GMER again, this time in safe mode.

Run DeFogger

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Boot your computer in Safe Mode
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode.

Run GMER while in Safe Mode
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked.
    Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file.
  • Save it where you can easily find it, such as your desktop, and copy/paste the results in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Reboot into normal mode

Run DeFogger

To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.

If you are able to run GMER in safe mode please include the results in your next reply. If it still won't run we will continue on.

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Just checking to see if you are still with me. Were you able to get GMER to run? If not, please move ahead and try Combofix and post the results.

Reminder: Topics with no reply in 4 days are closed!
Ok, took forever but here are the results:

GMER:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-14 16:27:21
Windows 6.0.6001 Service Pack 1
Running: gmer.exe; Driver: C:\Users\Tamara\AppData\Local\Temp\uwlyipow.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x87 0x66 0xF8 0x24 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xF8 0x86 0xF5 0x35 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x65 0xBA 0x19 0xC2 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x87 0x66 0xF8 0x24 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xF8 0x86 0xF5 0x35 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x65 0xBA 0x19 0xC2 …

—- EOF - GMER 1.0.15 —-

Combofix:
ComboFix 10-03-14.03 - Tamara 03/14/2010 18:11:47.1.2 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.2045.1298 [GMT -4:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1640735721-911341716-1164966957-1001
c:\$recycle.bin\S-1-5-21-1640735721-911341716-1164966957-500
c:\$recycle.bin\S-1-5-21-4289756712-2649719067-2863229470-500
c:\programdata\Microsoft\Windows\Start Menu\Programs\AVI Codec Pack +
c:\programdata\Microsoft\Windows\Start Menu\Programs\AVI Codec Pack +\Check For Updates.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\AVI Codec Pack +\Uninstall.lnk
c:\programdata\ntuser.dat{03e71b09-c763-11db-a603-00a0d1df23e9}.TMContainer00000000000000000001.regtrans-ms
c:\programdata\ntuser.dat{03e71b19-c763-11db-a603-00a0d1df23e9}.TMContainer00000000000000000001.regtrans-ms

.
((((((((((((((((((((((((( Files Created from 2010-02-14 to 2010-03-14 )))))))))))))))))))))))))))))))
.

2010-03-14 22:23 . 2010-03-14 22:25 ——– d—–w- c:\users\Tamara\AppData\Local\temp
2010-03-14 22:23 . 2010-03-14 22:23 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-03-14 20:45 . 2010-02-08 15:40 84912 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100314.003\NAVENG.SYS
2010-03-14 20:45 . 2010-02-08 15:40 177520 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100314.003\NAVENG32.DLL
2010-03-14 20:45 . 2010-02-08 15:40 1647984 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100314.003\NAVEX32A.DLL
2010-03-14 20:45 . 2010-02-08 15:40 1324720 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100314.003\NAVEX15.SYS
2010-03-14 20:45 . 2010-02-08 15:40 371248 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100314.003\EECTRL.SYS
2010-03-14 20:45 . 2010-02-08 15:40 2747440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100314.003\CCERASER.DLL
2010-03-14 20:45 . 2010-02-08 15:40 259440 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100314.003\ECMSVR32.DLL
2010-03-14 20:45 . 2010-02-08 15:40 102448 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20100314.003\ERASER.SYS
2010-03-11 08:02 . 2010-02-20 23:39 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-03-11 08:02 . 2010-02-20 21:18 411136 —-a-w- c:\windows\system32\drivers\http.sys
2010-03-11 08:02 . 2010-02-20 23:37 31232 —-a-w- c:\windows\system32\httpapi.dll
2010-03-10 19:28 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100310.001\Scxpx86.dll
2010-03-10 19:28 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100310.001\IDSvix86.sys
2010-03-10 19:28 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100310.001\IDSXpx86.sys
2010-03-10 19:28 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100310.001\IDSxpx86.dll
2010-03-10 19:28 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100310.001\IDSviA64.sys
2010-03-08 19:54 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100305.002\IDSvix86.sys
2010-03-08 19:54 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100305.002\IDSXpx86.sys
2010-03-08 19:54 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100305.002\Scxpx86.dll
2010-03-08 19:54 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100305.002\IDSxpx86.dll
2010-03-08 19:54 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100305.002\IDSviA64.sys
2010-03-05 06:48 . 2010-03-05 06:48 ——– d—–w- c:\users\Tamara\AppData\Roaming\Wireshark
2010-03-05 06:30 . 2010-03-05 06:30 ——– d—–w- c:\program files\WinPcap
2010-03-05 06:26 . 2010-03-05 06:30 ——– d—–w- c:\program files\Wireshark
2010-03-04 02:50 . 2010-03-04 02:50 ——– d—–w- c:\program files\Trend Micro
2010-03-03 04:14 . 2010-03-03 04:14 50354 —-a-w- c:\users\Tamara\AppData\Roaming\Facebook\uninstall.exe
2010-03-03 04:13 . 2010-03-03 04:14 ——– d—–w- c:\users\Tamara\AppData\Roaming\Facebook
2010-03-03 03:25 . 2010-03-10 15:31 ——– d—–w- c:\users\Tamara\AppData\Local\CrashDumps
2010-03-02 23:34 . 2010-02-27 23:33 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-02-28 08:55 . 2010-02-27 23:33 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-02-27 23:39 . 2010-02-28 03:19 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-02-27 23:39 . 2010-02-27 23:39 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-02-27 23:34 . 2010-02-04 15:53 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-02-27 23:32 . 2010-02-27 23:32 17480 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll
2010-02-27 23:32 . 2010-02-27 23:32 961984 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-02-27 23:32 . 2010-02-27 23:32 835312 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-02-27 23:32 . 2010-02-27 23:32 842992 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-02-27 23:32 . 2010-02-27 23:32 1593320 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-02-27 23:32 . 2010-02-27 23:32 815184 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-02-27 23:32 . 2010-02-27 23:32 1229232 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-02-27 23:28 . 2010-02-28 08:45 ——– dc-h–w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-27 23:28 . 2010-02-04 15:53 2954656 -c–a-w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-02-27 23:27 . 2010-02-27 23:34 ——– d—–w- c:\programdata\Lavasoft
2010-02-27 23:27 . 2010-02-27 23:28 ——– d—–w- c:\program files\Lavasoft
2010-02-27 23:18 . 2010-02-27 23:18 ——– d—–w- c:\users\Tamara\AppData\Roaming\Malwarebytes
2010-02-27 23:18 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-27 23:18 . 2010-02-27 23:18 ——– d—–w- c:\programdata\Malwarebytes
2010-02-27 23:18 . 2010-02-27 23:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-27 23:18 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-26 06:41 . 2010-02-26 06:41 847040 —-a-w- c:\users\Tamara\AppData\Roaming\Facebook\axfbootloader.dll
2010-02-26 06:41 . 2010-02-26 06:41 5582848 —-a-w- c:\users\Tamara\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
2010-02-25 20:41 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100224.002\IDSvix86.sys
2010-02-25 20:41 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100224.002\IDSXpx86.sys
2010-02-25 20:41 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100224.002\Scxpx86.dll
2010-02-25 20:41 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100224.002\IDSxpx86.dll
2010-02-25 20:41 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100224.002\IDSviA64.sys
2010-02-24 15:22 . 2010-01-23 09:44 2048 —-a-w- c:\windows\system32\tzres.dll
2010-02-24 15:21 . 2010-01-25 12:48 472576 —-a-w- c:\windows\system32\secproc_isv.dll
2010-02-24 15:21 . 2010-01-25 12:48 472064 —-a-w- c:\windows\system32\secproc.dll
2010-02-24 15:21 . 2010-01-25 08:35 346624 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-02-24 15:21 . 2010-01-25 08:35 523776 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-02-24 15:21 . 2010-01-25 08:34 511488 —-a-w- c:\windows\system32\RMActivate.exe
2010-02-24 15:21 . 2010-01-25 08:34 347136 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-02-24 15:21 . 2010-01-25 12:48 151040 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-02-24 15:21 . 2010-01-25 12:48 151040 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-02-24 15:21 . 2010-01-25 12:45 329216 —-a-w- c:\windows\system32\msdrm.dll
2010-02-23 00:50 . 2010-02-23 00:50 ——– d—–w- c:\program files\Microsoft Silverlight
2010-02-22 02:39 . 2010-02-22 02:39 ——– d—–w- c:\program files\Common Files\PX Storage Engine
2010-02-22 02:39 . 2010-03-03 03:29 ——– d—–w- c:\program files\Winamp
2010-02-19 23:14 . 2009-10-28 22:37 811896 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100218.001\Scxpx86.dll
2010-02-19 23:14 . 2009-10-28 22:37 343088 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100218.001\IDSvix86.sys
2010-02-19 23:14 . 2009-10-28 22:37 329592 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100218.001\IDSXpx86.sys
2010-02-19 23:14 . 2009-10-28 22:37 488312 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100218.001\IDSxpx86.dll
2010-02-19 23:14 . 2009-10-28 22:37 466992 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100218.001\IDSviA64.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-14 22:04 . 2009-05-07 18:57 ——– d—–w- c:\users\Tamara\AppData\Roaming\DNA
2010-03-14 18:55 . 2007-07-14 03:28 59752 —-a-w- c:\users\Tamara\AppData\Roaming\nvModes.dat
2010-03-13 08:32 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-03-11 08:06 . 2007-05-31 07:49 ——– d—–w- c:\programdata\Microsoft Help
2010-02-27 04:06 . 2007-07-13 23:51 83288 —-a-w- c:\users\Tamara\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-27 03:01 . 2007-09-04 17:00 1356 —-a-w- c:\users\Tamara\AppData\Local\d3d9caps.dat
2010-02-26 22:49 . 2009-07-12 05:05 ——– d—–w- c:\users\Tamara\AppData\Roaming\uTorrent
2010-02-17 01:33 . 2008-07-27 05:02 ——– d—–w- c:\users\Tamara\AppData\Roaming\ZoomBrowser EX
2010-02-11 18:44 . 2010-02-11 18:44 201616 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20100211.001\BHRules.dll
2010-02-11 18:44 . 2010-02-11 18:44 1406352 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20100211.001\BHEngine.dll
2010-02-11 18:44 . 2010-02-11 18:44 676912 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20100211.001\BHDrvx64.sys
2010-02-11 18:44 . 2010-02-11 18:44 536112 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20100211.001\BHDrvx86.sys
2010-02-11 18:44 . 2010-02-11 18:44 611216 —-a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20100211.001\bbRGen.dll
2010-02-09 15:19 . 2007-08-18 05:05 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-02-08 15:19 . 2009-12-16 00:03 ——– d—–w- c:\programdata\Norton
2010-02-08 15:16 . 2010-02-08 15:14 ——– d—–w- c:\program files\Symantec
2010-02-08 15:14 . 2010-02-08 15:16 805 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-02-08 15:14 . 2010-02-08 15:16 7443 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-02-08 15:14 . 2010-02-08 15:16 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-02-08 15:11 . 2010-02-08 15:11 ——– d—–w- c:\program files\Norton AntiVirus
2010-02-06 19:46 . 2007-08-18 05:06 ——– d—–w- c:\programdata\Symantec
2010-02-06 19:38 . 2010-02-06 19:38 ——– d—–w- c:\programdata\PCSettings
2010-02-06 19:38 . 2010-02-06 19:38 ——– d—–w- c:\programdata\NortonInstaller
2010-02-06 19:38 . 2010-02-06 19:38 ——– d—–w- c:\program files\NortonInstaller
2010-02-06 19:36 . 2009-11-07 01:17 80528056 —-a-w- c:\programdata\Norton\{NAV_Production_94_17.1.0.19_NUC}\NAV10UPEN.exe
2010-02-02 05:44 . 2007-02-28 20:11 ——– d—–w- c:\program files\Google
2010-02-01 22:17 . 2010-02-01 22:17 509552 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtb36BA.tmp.exe
2010-01-30 23:25 . 2010-01-30 23:25 509552 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtb1F0F.tmp.exe
2010-01-29 22:50 . 2010-01-29 22:50 509552 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtbBB32.tmp.exe
2009-12-28 12:35 . 2010-02-10 15:47 11776 —-a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:35 . 2010-02-10 15:47 1314816 —-a-w- c:\windows\system32\quartz.dll
2009-12-28 12:32 . 2010-02-10 15:47 22528 —-a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:32 . 2010-02-10 15:47 31744 —-a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:32 . 2010-02-10 15:47 123904 —-a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:32 . 2010-02-10 15:47 13312 —-a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:31 . 2010-02-10 15:47 82944 —-a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:31 . 2010-02-10 15:47 50176 —-a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:28 . 2010-02-10 15:47 91136 —-a-w- c:\windows\system32\avifil32.dll
2009-12-28 12:28 . 2010-02-10 15:47 65024 —-a-w- c:\windows\system32\avicap32.dll
2009-12-18 13:05 . 2010-01-23 01:35 833024 —-a-w- c:\windows\system32\wininet.dll
2009-12-18 13:01 . 2010-01-23 01:35 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-12-18 10:14 . 2010-01-23 01:35 26624 —-a-w- c:\windows\system32\ieUnatt.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2006-12-04 00:03 2854912 —-a-w- c:\program files\Protector Suite QL\farchns.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2006-12-04 00:03 2854912 —-a-w- c:\program files\Protector Suite QL\farchns.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-12 39408]
"BitTorrent DNA"="c:\users\Tamara\Program Files\DNA\btdna.exe" [2009-11-07 323392]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 52\axcmd.exe" [2008-03-20 216520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-02-13 405504]
"PSQLLauncher"="c:\program files\Protector Suite QL\launcher.exe" [2006-12-03 49168]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-07 4374528]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-02 835584]
"NDSTray.exe"="NDSTray.exe" [BU]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-12-20 411768]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-08 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-01-19 448632]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-01-17 534648]
"Mouse Suite 98 Daemon"="ICO.EXE" [2006-10-23 56128]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-01-13 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-01-13 7766016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-01-13 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]

c:\users\Tamara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Cyber-shot Viewer Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-7-13 155648]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2006-12-03 23:50 90112 —-a-w- c:\windows\System32\psqlpwd.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2008-09-11 716272]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
R3 IO_Memory;IO_Memory;c:\windows\SYSTEM32\SYSPREP\Drivers\ioport.sys [x]
R3 XDva098;XDva098;c:\windows\system32\XDva098.sys [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-02-04 64288]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NAV\1105000.07F\SYMDS.SYS [2009-11-05 328752]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1105000.07F\SYMEFA.SYS [2009-11-26 172592]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20100211.001\BHDrvx86.sys [2010-02-11 536112]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1105000.07F\ccHPx86.sys [2009-12-09 501888]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20100310.001\IDSvix86.sys [2009-10-28 343088]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NAV\1105000.07F\Ironx86.SYS [2009-11-26 116272]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\NAV\1105000.07F\SYMTDIV.SYS [2009-11-22 340016]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-02-27 1229232]
S2 NAV;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\17.5.0.127\ccSvcHst.exe [2009-12-09 126392]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-02-08 102448]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2010-03-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 05:44]

2010-03-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 05:44]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\users\Tamara\AppData\Roaming\Mozilla\Firefox\Profiles\ps5dyxqc.default\
FF - prefs.js: browser.startup.homepage - hxxp://msn.com
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\users\Tamara\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\users\Tamara\AppData\Roaming\Mozilla\Firefox\Profiles\ps5dyxqc.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\users\Tamara\Program Files\DNA\plugins\npbtdna.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-14 18:25
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NAV]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\17.5.0.127\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files\Norton AntiVirus\Engine\17.5.0.127\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1640735721-911341716-1164966957-1000\Software\SecuROM\License information*]
"datasecu"=hex:45,67,62,3d,ec,16,e0,5d,f2,51,55,49,1a,31,b1,12,e2,99,86,62,94,
11,f9,c2,03,31,aa,90,66,2b,22,33,2a,46,e8,33,bc,bc,9e,be,8d,8a,27,d5,2b,71,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(724)
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\program files\Protector Suite QL\infra.dll
.
Completion time: 2010-03-14 18:29:05
ComboFix-quarantined-files.txt 2010-03-14 22:28

Pre-Run: 9,588,281,344 bytes free
Post-Run: 11,101,736,960 bytes free

- - End Of File - - 00F5528BFFBAB55725EE99EE3A184237
Also, I don't ever remember installing or using AtomicLog… Is there a way I can remove it? I've searched my system for it but I can't find it…
Just to be clear, I don't see AtomicLog currently running, and the files I saw are probably leftovers after it was removed. I'll be sure we get rid of those remaining files just to be safe.

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O33 - MountPoints2\{6cff94eb-7c0f-11de-9523-00a0d17664fd}\Shell\Auto\command - "" = RECYCLER\koyko.exe
    O33 - MountPoints2\{6cff94eb-7c0f-11de-9523-00a0d17664fd}\Shell\AutoRun\command - "" = RECYCLER\koyko.exe
    [2007/08/25 20:30:19 | 000,031,232 | —- | C] () – C:\Windows\System32\AsynInet.dll
    [2007/08/25 20:30:18 | 000,027,136 | —- | C] () – C:\Windows\System32\tdecode.dll
    [2007/08/25 20:30:18 | 000,024,064 | —- | C] () – C:\Windows\System32\TWBCust.dll
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

I see you have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates. Allow it to check for and apply any updates.
  • Select the Scanner tab, and Perform Quick Scan
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Please post the log in your next reply.

Please do a scan with Kaspersky Online Scanner
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
  • Text file [*.txt] Then, click: Save

Please post the Kaspersky Online Scanner Report in your reply.
I know there were a lot of steps in that last set of instructions. OTL, JavaRa and MBAM should go fairly quickly. The online scan will take a bit of time.

Even if you can't get through all the steps to post at once, I'd like to see the new OTL log and the MBAM log. You can run the online scan and post it separately if you like.

Let me know how you're coming on these. :)

Reminder: Topics with no reply in 4 days are closed!
Thanks for your patience, once again :D Here are the OTL scan results: All processes killed ========== OTL ========== No active process named explorer.exe was found! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6cff94eb-7c0f-11de-9523-00a0d17664fd}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6cff94eb-7c0f-11de-9523-00a0d17664fd}\ not found. File C:\RECYCLER\koyko.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6cff94eb-7c0f-11de-9523-00a0d17664fd}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6cff94eb-7c0f-11de-9523-00a0d17664fd}\ not found. File C:\RECYCLER\koyko.exe not found. C:\Windows\System32\AsynInet.dll moved successfully. C:\Windows\System32\tdecode.dll moved successfully. C:\Windows\System32\TWBCust.dll moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes User: Tamara ->Temp folder emptied: 47968356 bytes ->Temporary Internet Files folder emptied: 419144533 bytes ->Java cache emptied: 12388552 bytes ->FireFox cache emptied: 72817663 bytes ->Flash cache emptied: 556041 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 675840 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 702062 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 53760 bytes Total Files Cleaned = 529.00 mb OTL by OldTimer - Version 3.1.34.0 log created on 03182010_183409 Files\Folders moved on Reboot… Registry entries deleted on Reboot… MBAM Results: Malwarebytes' Anti-Malware 1.44 Database version: 3884 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 3/18/2010 7:15:35 PM mbam-log-2010-03-18 (19-15-35).txt Scan type: Quick Scan Objects scanned: 110661 Time elapsed: 12 minute(s), 47 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ________ Also, I just wanted to ask….Does it seem like there is any progress/improvement from all of these scans and fixes? I can't tell, obviously, since I don't understand the scan logs….But is there actually anything malicious present, or has it not been found yet (if anything is there)? I will do the JavaRa and Kaspersky scans later tonight and will post the results ASAP :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI