This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] VX2.Look2Me

56 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi. I apparently have the VX2.Look2Me trojan (according to Spy Doctor) and though I can't see any obvious problems I'm hoping to get rid of it before it starts messing with my system. I tried several programs to remove it and nothing worked, so I'm hoping someone here could help. I run Windows Vista. Thanks in advance!

HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:27:07 AM, on 13/03/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18385)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ltmoh\ltmoh.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Microsoft Windows OneCare Live\WinSSNotifyE.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
c:\program files\aim toolbar\aimtbServer.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10e.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Users\Marwa\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\Explorer.EXE
C:\Users\Marwa\Desktop\Illustrator\Illustrator.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.shoptoshiba.ca/welcome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Megaupload Toolbar - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: Megaupload Toolbar - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL (file missing)
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\Windows\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Marwa\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [googletalk] C:\Users\Marwa\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Aim] "C:\Program Files\AIM\aim.exe" /d locale=en-CA
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB6.3; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; MEGAUPLOAD 3.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618; OfficeLiveConnector.1.3; OfficeLivePatch.0.0)" -"http://www.allthingsmustpass.com/"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: McAfee Security Scan.lnk = ?
O8 - Extra context menu item: &AIM Toolbar Search - C:\ProgramData\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.adobe.com
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8942.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Jumpstart\jswpsapi.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 16127 bytes
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems. I'd be grateful if you would note the following:
  • Logs from malware removal programs (DDS is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator!
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    . I will post a reminder should you seem to fail to do this, however, if you fail to reply within two days then,
    unless I have been notified of your absence in advance, the topic shall be closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic.
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________


Running OTS
To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTS to your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Under Additional Scans click the "Extras" button
  • In the custom scans section copy and paste in the following


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav

  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post


NEXT:



Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection
    so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    [external image: Posted Image]
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.


NEXT:



Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that was produced after running OTS.
3. The log that was produced after running GMER.
4. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Thank you for your help!

1. I was running GMER and two things happened. First, it froze/stopped scanning for a good half an hour or so. I started the scan again. I got the blue screen and my laptop restarted itself. I don't remember the last time I got the blue screen, or even if I did, so it's not a common occurrence.
2. Attached OTS file.
3. Unsure on whether I should run GMER again and get a log file, so decided to ask you first.
4. My computer is running the same as far as I can see. I forgot to mention in my first post that occasionally Windows Explorer freezes and I have to let it restart the toolbar a few times. Sometimes Ineternet Explorer also crashes.

Attachments:

Please try running GMER in safe mode. Instructions can be found below.

Entering Safe Mode

  • Restart your computer.
  • As the computer starts to boot-up, Tap the F8 KEY repeatedly,
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll to Safe Mode
  • Then press the Enter Key on your Keyboard
  • Go into your usual account
(Much less results showed up in safe mode than when it was running in normal.)

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-13 16:23:25
Windows 6.0.6001 Service Pack 1
Running: 2rhmxnjv.exe; Driver: C:\Users\Marwa\AppData\Local\Temp\kwlcypob.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x82720CDC]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x82720ECE]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x82720982]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x827210D6]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetTimerEx + 43C 820EEB00 3 Bytes [DC, 0C, 72] {FMUL QWORD [EDX+ESI*2]}
.text ntkrnlpa.exe!KeSetTimerEx + 440 820EEB04 3 Bytes [CE, 0E, 72]
.text ntkrnlpa.exe!KeSetTimerEx + 854 820EEF18 3 Bytes [82, 09, 72] {OR BYTE [ECX], 0x72}
.text ntkrnlpa.exe!KeSetTimerEx + 918 820EEFDC 3 Bytes [D6, 10, 72]
.text C:\Windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x8A959000, 0x4036D, 0xE8000020]
.dsrt C:\Windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x8A9A2000, 0x510, 0x40000040]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
CKScanner
Download CKScanner.
Important - Save it to your desktop.
Doubleclick CKScanner.exe and click Search For Files.
After a very short time, when the cursor hourglass disappears, click Save List To File.
A message box will verify the file saved.
Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.
Questions:
Your logs are showing me that you have quite a few security programs installed.

Do you currently have active subscriptions to these two security programs: Spyware Doctor and Windows OneCare Live? Do you have an up to date Anti-Virus program?


NEXT:



Peer to Peer Program
While reviewing your logs I noticed that you currently have Peer to Peer program(s) installed on your computer.

You currently have the following P2P programs installed:
  • BitTorrent
Most of the infections that we see today are through P2P file sharing. By uninstalling the programs that I mentioned above you will be doing yourself a favor. It's impossible to trust the source of what is being downloaded from them and a file may or may not be what it appears to be.

Should you decide to keep these programs installed on your computer PLEASE do not use these programs while we are getting your P.C. cleaned up.

How to Uninstall the P2P Programs:

  • Click on Start > Control Panel and double click on Programs and Features.
  • Locate BitTorrent and click on the Uninstall button to uninstall it.
  • Close Control Panel when done.

PLEASE NOTE: When your uninstalling the P2P Program(s) some questions are worded in various ways to try and deceive you and keep you from uninstalling their Program.


NEXT:


Running OTS Fix
Start OTS Copy/Paste the information inside the codebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Registry - Safe List]
< FireFox Settings [Prefs.js] > -> C:\Users\Marwa\AppData\Roaming\Mozilla\FireFox\Profiles\l5fh2u0x.default\prefs.js
YN -> browser.search.param.yahoo-fr -> "megaup"
YN -> browser.search.param.yahoo-fr-cjkt -> "megaup"
YN -> network.proxy.ftp -> "127.0.0.1"
YN -> network.proxy.ftp_port -> 9666
YN -> network.proxy.gopher -> "127.0.0.1"
YN -> network.proxy.gopher_port -> 9666
YN -> network.proxy.http -> "127.0.0.1"
YN -> network.proxy.http_port -> 9666
YN -> network.proxy.share_proxy_settings -> true
YN -> network.proxy.socks -> "127.0.0.1"
YN -> network.proxy.socks_port -> 9666
YN -> network.proxy.ssl -> "127.0.0.1"
YN -> network.proxy.ssl_port -> 9666
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {5C255C8A-E604-49b4-9D64-90988571CECB} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {A057A204-BACC-4D26-C39E-35F1D2A32EC8} [HKLM] -> C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL [Megaupload Toolbar]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "{A057A204-BACC-4D26-C39E-35F1D2A32EC8}" [HKLM] -> C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL [Megaupload Toolbar]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\] > -> HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{A057A204-BACC-4D26-C39E-35F1D2A32EC8}" [HKLM] -> C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL [Megaupload Toolbar]
< RunOnce [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
YN -> "Uninstall Adobe Download Manager" -> ["C:\Windows\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp]
< RunOnce [HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\] > -> HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
YN -> "Shockwave Updater" -> C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB6.3; Mozilla\4.0 ( [C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB6.3; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1); SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; MEGAUPLOAD 3.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618; OfficeLiveConnector.1.3; OfficeLivePatch.0.0)" -"http://www.allthingsmustpass.com/"]
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
YN -> "C:\Program Files\BitTorrent\bittorrent.exe" -> C:\Program Files\BitTorrent\bittorrent.exe [C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent]
[Files/Folders - Modified Within 30 Days]
NY ->  Miloyski.com_the.office.61617.hdtv-lol.avi -> C:\Users\Marwa\Desktop\Miloyski.com_the.office.61617.hdtv-lol.avi
NY ->  49 C:\Users\Marwa\AppData\Local\Temp\*.tmp files -> C:\Users\Marwa\AppData\Local\Temp\*.tmp
NY ->  40 C:\Users\Marwa\AppData\Local\Temp\Low\*.tmp files -> C:\Users\Marwa\AppData\Local\Temp\Low\*.tmp
NY ->  2 C:\Users\Marwa\Documents\*.tmp files -> C:\Users\Marwa\Documents\*.tmp
NY ->  15 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp
NY ->  1 C:\Windows\*.tmp files -> C:\Windows\*.tmp
NY ->  1 C:\Users\Marwa\Desktop\*.tmp files -> C:\Users\Marwa\Desktop\*.tmp
[Alternate Data Streams]
NY -> @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:8CE646EE
NY -> @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
NY -> @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:88050731
NY -> @Alternate Data Stream - 171 bytes -> C:\ProgramData\TEMP:DFC5A2B2
NY -> @Alternate Data Stream - 22528 bytes -> C:\Windows\System32\autochk.exe:BAK
[Empty Temp Folders]
[Reboot]

The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix. Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTS will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply.


NEXT:


Scanning with MalwareBytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


NEXT:



Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. An answer to my questions above.
3. The log that was produced after running the OTS fix.
4. The log that was produced after running MalwareBytes' Anti-Malware.
5. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
1. OTS stopped working during last two items on list (Empty temp folders/Reboot). Program was forced to shut down by system. I restarted. Got a log file upon reboot. 2. I have an active subscription to Windows OneCare Live. It's my anti-virus program. No subscription to Spyware Doctor. 3. Files\Folders moved on Reboot… File\Folder C:\Windows\temp\mpengine.dll not found! File\Folder C:\Windows\temp\TMP0000000191EAF2476D026C0A not found! File\Folder C:\Windows\temp\TMP0000000D3604635CA047A758 not found! Registry entries deleted on Reboot… 4. Malwarebytes' Anti-Malware 1.44 Database version: 3865 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 14/03/2010 4:45:26 AM mbam-log-2010-03-14 (04-45-26).txt Scan type: Quick Scan Objects scanned: 107608 Time elapsed: 16 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 9 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/Windows/Downloaded Program Files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Windows\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully. 5. Nothing new.
Uninstalling Spyware Doctor

If you don't have a subscription to Spyware Doctor I don't see much use in having it installed. Some users find that it slows down their computer.

You may want to consider uninstalling it.

We need to remove a program. To do this please do the following:
For Vista Users:
  • Click on Start > Control Panel and double click on Programs and Features.
  • Locate Spyware Doctor and click on the Uninstall button to uninstall it.
  • Close Control Panel when done.

NEXT:



Running OTS Fix

The OTS fix that I gave to you didn't work properly. Please try the one provided below.

Start OTS Copy/Paste the information inside the codebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Unregister Dlls]
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {5C255C8A-E604-49b4-9D64-90988571CECB} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {A057A204-BACC-4D26-C39E-35F1D2A32EC8} [HKLM] -> C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL [Megaupload Toolbar]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "{A057A204-BACC-4D26-C39E-35F1D2A32EC8}" [HKLM] -> C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL [Megaupload Toolbar]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\] > -> HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{A057A204-BACC-4D26-C39E-35F1D2A32EC8}" [HKLM] -> C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL [Megaupload Toolbar]
< RunOnce [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
YN -> "Uninstall Adobe Download Manager" -> ["C:\Windows\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp]
< RunOnce [HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\] > -> HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
YN -> "Shockwave Updater" -> C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB6.3; Mozilla\4.0 ( [C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB6.3; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1); SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; MEGAUPLOAD 3.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618; OfficeLiveConnector.1.3; OfficeLivePatch.0.0)" -"http://www.allthingsmustpass.com/"]
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
YN -> "C:\Program Files\BitTorrent\bittorrent.exe" -> C:\Program Files\BitTorrent\bittorrent.exe [C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent]
[Files/Folders - Modified Within 30 Days]
NY ->  Miloyski.com_the.office.61617.hdtv-lol.avi -> C:\Users\Marwa\Desktop\Miloyski.com_the.office.61617.hdtv-lol.avi
NY ->  49 C:\Users\Marwa\AppData\Local\Temp\*.tmp files -> C:\Users\Marwa\AppData\Local\Temp\*.tmp
NY ->  40 C:\Users\Marwa\AppData\Local\Temp\Low\*.tmp files -> C:\Users\Marwa\AppData\Local\Temp\Low\*.tmp
NY ->  2 C:\Users\Marwa\Documents\*.tmp files -> C:\Users\Marwa\Documents\*.tmp
NY ->  15 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp
NY ->  1 C:\Windows\*.tmp files -> C:\Windows\*.tmp
NY ->  1 C:\Users\Marwa\Desktop\*.tmp files -> C:\Users\Marwa\Desktop\*.tmp
[Alternate Data Streams]
NY -> @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:8CE646EE
NY -> @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
NY -> @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:88050731
NY -> @Alternate Data Stream - 171 bytes -> C:\ProgramData\TEMP:DFC5A2B2
NY -> @Alternate Data Stream - 22528 bytes -> C:\Windows\System32\autochk.exe:BAK
[Empty Temp Folders]

The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix. Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTS will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply.


NEXT:


Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply


NEXT:



Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that was produced after running the new OTS fix.
3. The log that was produced after running the Kaspersky Online Scan.
4. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
1. N/A. 2. All Processes Killed [Registry - Safe List] Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-C39E-35F1D2A32EC8}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-C39E-35F1D2A32EC8}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{A057A204-BACC-4D26-C39E-35F1D2A32EC8} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-C39E-35F1D2A32EC8}\ not found. Registry value HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A057A204-BACC-4D26-C39E-35F1D2A32EC8} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-C39E-35F1D2A32EC8}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\Uninstall Adobe Download Manager not found. Registry value HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\Shockwave Updater not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\BitTorrent\bittorrent.exe not found. [Files/Folders - Modified Within 30 Days] File C:\Users\Marwa\Desktop\Miloyski.com_the.office.61617.hdtv-lol.avi not found! C:\Users\Marwa\AppData\Local\Temp\_iu14D2N.tmp deleted successfully. C:\Users\Marwa\AppData\Local\Temp\_iu14D2O.tmp deleted successfully. C:\Windows\Temp\Win5FBA.tmp deleted successfully. C:\Windows\Temp\Win83AE.tmp deleted successfully. [Alternate Data Streams] Unable to delete ADS C:\ProgramData\TEMP:8CE646EE . ADS C:\ProgramData\TEMP:A8ADE5D8 deleted successfully. Unable to delete ADS C:\ProgramData\TEMP:88050731 . ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully. Unable to delete ADS C:\Windows\System32\autochk.exe:BAK . [Empty Temp Folders] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Marwa ->Temp folder emptied: 871863 bytes ->Temporary Internet Files folder emptied: 37895523 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 991 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 9449790 bytes %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 16933832 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 62.00 mb < End of fix log > OTS by OldTimer - Version 3.1.26.0 fix logfile created on 03142010_131041 Files\Folders moved on Reboot… Registry entries deleted on Reboot… 3. There were 0 infections/threats/suspicious objects, but for some reason the report would 'save' but not show up on my Desktop when I went to retrieve it. 4. As is. I believe the Windows Explorer problem still exists. (That it occasionally 'stops working' and I have to hit 'restart program'. Could this issue be unrelated to malware/spyware/virus?)
Can you do me a favor and provide me with a new OTS log.



As is. I believe the Windows Explorer problem still exists. (That it occasionally 'stops working' and I have to hit 'restart program'. Could this issue be unrelated to malware/spyware/virus?)

I'd like to come back to this issue at the end when we are cleaning you up.
OTS logfile created on: 14/03/2010 3:40:55 PM - Run 2
OTS by OldTimer - Version 3.1.26.0	 Folder = C:\Users\Marwa\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
 
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 54.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 135.27 Gb Total Space | 59.06 Gb Free Space | 43.66% Space Free | Partition Type: NTFS
Drive D: | 6.32 Gb Total Space | 6.26 Gb Free Space | 99.05% Space Free | Partition Type: NTFS
Drive E: | 37.19 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: MARWA-PC
Current User Name: Marwa
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
 
[Processes - Safe List]
ots.exe -> C:\Users\Marwa\Desktop\OTS.exe -> [2010/03/13 14:21:10 | 000,636,928 | —- | M] (OldTimer Tools)
winssnotify.exe -> C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe -> [2010/02/05 17:19:46 | 000,065,256 | —- | M] (Microsoft Corporation)
winss.exe -> C:\Program Files\Microsoft Windows OneCare Live\winss.exe -> [2010/02/05 17:19:44 | 001,141,112 | —- | M] (Microsoft Corporation)
ochealthmon.exe -> C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe -> [2010/02/05 17:19:42 | 000,026,120 | —- | M] (Microsoft Corporation)
flashutil10e.exe -> C:\Windows\System32\Macromed\Flash\FlashUtil10e.exe -> [2010/01/26 20:58:38 | 000,256,280 | R— | M] (Adobe Systems, Inc.)
aim.exe -> C:\Program Files\AIM\aim.exe -> [2009/12/01 13:38:47 | 003,951,976 | —- | M] (AOL LLC)
ssscheduler.exe -> C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe -> [2009/07/27 20:19:10 | 000,199,184 | —- | M] (McAfee, Inc.)
rimautoupdate.exe -> C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe -> [2009/07/02 00:12:46 | 000,623,960 | —- | M] (Research In Motion Limited)
realsched.exe -> C:\Program Files\Common Files\Real\Update_OB\realsched.exe -> [2009/03/30 19:42:22 | 000,198,160 | —- | M] (RealNetworks, Inc.)
pwrisovm.exe -> C:\Program Files\PowerISO\PWRISOVM.EXE -> [2009/03/15 06:15:16 | 000,180,224 | —- | M] (PowerISO Computing, Inc.)
googletoolbarnotifier.exe -> C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> [2009/01/12 14:42:44 | 000,039,408 | —- | M] (Google Inc.)
explorer.exe -> C:\Windows\explorer.exe -> [2008/10/29 02:29:41 | 002,927,104 | —- | M] (Microsoft Corporation)
msmpeng.exe -> C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe -> [2008/07/09 17:05:22 | 000,018,704 | —- | M] (Microsoft Corporation)
toscdspd.exe -> C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe -> [2008/07/04 14:51:54 | 000,430,080 | —- | M] (TOSHIBA)
jusched.exe -> C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe -> [2008/06/10 04:27:04 | 000,144,784 | —- | M] (Sun Microsystems, Inc.)
rthdvcpl.exe -> C:\Windows\RtHDVCpl.exe -> [2008/01/29 06:51:52 | 004,911,104 | —- | M] (Realtek Semiconductor)
tcrdmain.exe -> C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe -> [2008/01/22 14:25:26 | 000,712,704 | —- | M] (TOSHIBA Corporation)
tnavisrv.exe -> C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe -> [2008/01/21 16:54:46 | 000,083,312 | —- | M] (TOSHIBA Corporation)
ieuser.exe -> C:\Program Files\Internet Explorer\ieuser.exe -> [2008/01/20 22:24:49 | 000,299,520 | —- | M] (Microsoft Corporation)
conime.exe -> C:\Windows\System32\conime.exe -> [2008/01/20 22:24:13 | 000,069,120 | —- | M] (Microsoft Corporation)
tpwrmain.exe -> C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe -> [2008/01/17 16:27:52 | 000,431,456 | —- | M] (TOSHIBA Corporation)
toscosrv.exe -> C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -> [2008/01/17 16:27:34 | 000,431,456 | —- | M] (TOSHIBA Corporation)
cec_main.exe -> C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe -> [2008/01/04 08:45:00 | 004,415,488 | —- | M] ()
cfsvcs.exe -> C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -> [2007/12/25 17:07:14 | 000,040,960 | —- | M] (TOSHIBA CORPORATION)
tosipcsrv.exe -> C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe -> [2007/12/03 17:03:52 | 000,126,976 | —- | M] (TOSHIBA Corporation)
msfwsvc.exe -> C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe -> [2007/11/27 22:45:02 | 000,869,952 | —- | M] (Microsoft Corporation)
toddsrv.exe -> C:\Windows\System32\TODDSrv.exe -> [2007/11/21 21:23:32 | 000,129,632 | —- | M] (TOSHIBA Corporation)
traybar.exe -> C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe -> [2007/10/25 17:41:18 | 000,413,696 | —- | M] (Chicony)
smoothview.exe -> C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe -> [2007/06/15 21:01:58 | 000,448,080 | —- | M] (TOSHIBA Corporation)
ltmoh.exe -> C:\Program Files\ltmoh\ltmoh.exe -> [2007/01/09 02:23:04 | 000,191,552 | —- | M] (Agere Systems)
viewpointservice.exe -> C:\Program Files\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 17:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation)
agrsmsvc.exe -> C:\Windows\System32\agrsmsvc.exe -> [2006/10/05 00:10:12 | 000,009,216 | —- | M] (Agere Systems)
ulcdrsvr.exe -> C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -> [2006/08/23 16:39:48 | 000,049,152 | —- | M] (Ulead Systems, Inc.)
sqlservr.exe -> C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -> [2002/12/17 18:26:22 | 007,520,337 | —- | M] (Microsoft Corporation)
 
[Modules - Safe List]
ots.exe -> C:\Users\Marwa\Desktop\OTS.exe -> [2010/03/13 14:21:10 | 000,636,928 | —- | M] (OldTimer Tools)
comctl32.dll -> C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll -> [2008/01/20 22:23:44 | 001,684,480 | —- | M] (Microsoft Corporation)
 
[Win32 Services - Safe List]
(CLTNetCnService) Symantec Lic NetConnect service [Auto | Stopped] ->  -> File not found
(Lavasoft Ad-Aware Service) Lavasoft Ad-Aware Service [Auto | Stopped] -> C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -> [2010/03/09 11:20:05 | 001,229,232 | —- | M] (Lavasoft)
(FLEXnet Licensing Service) FLEXnet Licensing Service [On_Demand | Stopped] -> C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> [2010/02/12 00:25:44 | 000,655,624 | —- | M] (Acresso Software Inc.)
(winss) Windows Live OneCare [Auto | Running] -> C:\Program Files\Microsoft Windows OneCare Live\winss.exe -> [2010/02/05 17:19:44 | 001,141,112 | —- | M] (Microsoft Corporation)
(OcHealthMon) Windows Live OneCare Health Monitor [Auto | Running] -> C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe -> [2010/02/05 17:19:42 | 000,026,120 | —- | M] (Microsoft Corporation)
(OneCareMP) OneCare AntiSpyware and AntiVirus [Auto | Running] -> C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe -> [2008/07/09 17:05:22 | 000,018,704 | —- | M] (Microsoft Corporation)
(TNaviSrv) TOSHIBA Navi Support Service [Auto | Running] -> C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe -> [2008/01/21 16:54:46 | 000,083,312 | —- | M] (TOSHIBA Corporation)
(WinDefend) Windows Defender [Auto | Stopped] -> C:\Program Files\Windows Defender\MpSvc.dll -> [2008/01/20 22:23:32 | 000,272,952 | —- | M] (Microsoft Corporation)
(TosCoSrv) TOSHIBA Power Saver [Auto | Running] -> C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -> [2008/01/17 16:27:34 | 000,431,456 | —- | M] (TOSHIBA Corporation)
(ConfigFree Service) ConfigFree Service [Auto | Running] -> C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -> [2007/12/25 17:07:14 | 000,040,960 | —- | M] (TOSHIBA CORPORATION)
(TOSHIBA SMART Log Service) TOSHIBA SMART Log Service [Auto | Running] -> C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe -> [2007/12/03 17:03:52 | 000,126,976 | —- | M] (TOSHIBA Corporation)
(msfwsvc) OneCare Firewall [Auto | Running] -> C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe -> [2007/11/27 22:45:02 | 000,869,952 | —- | M] (Microsoft Corporation)
(TODDSrv) TOSHIBA Optical Disc Drive Service [Auto | Running] -> C:\Windows\System32\TODDSrv.exe -> [2007/11/21 21:23:32 | 000,129,632 | —- | M] (TOSHIBA Corporation)
(jswpsapi) Jumpstart Wifi Protected Setup [On_Demand | Stopped] -> C:\Program Files\Jumpstart\jswpsapi.exe -> [2007/10/30 00:35:40 | 000,937,984 | —- | M] (Atheros Communications, Inc.)
(Viewpoint Manager Service) Viewpoint Manager Service [Auto | Running] -> C:\Program Files\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 17:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation)
(AgereModemAudio) Agere Modem Call Progress Audio [Auto | Running] -> C:\Windows\System32\agrsmsvc.exe -> [2006/10/05 00:10:12 | 000,009,216 | —- | M] (Agere Systems)
(UleadBurningHelper) Ulead Burning Helper [Auto | Running] -> C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -> [2006/08/23 16:39:48 | 000,049,152 | —- | M] (Ulead Systems, Inc.)
(MSSQL$SONY_MEDIAMGR) MSSQL$SONY_MEDIAMGR [Auto | Running] -> C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -> [2002/12/17 18:26:22 | 007,520,337 | —- | M] (Microsoft Corporation)
(SQLAgent$SONY_MEDIAMGR) SQLAgent$SONY_MEDIAMGR [On_Demand | Stopped] -> C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -> [2002/12/17 18:23:30 | 000,311,872 | —- | M] (Microsoft Corporation)
 
[Driver Services - Safe List]
(Lbd) Lbd [File_System | Boot | Running] -> C:\Windows\system32\DRIVERS\Lbd.sys -> [2010/02/04 11:53:02 | 000,064,288 | —- | M] (Lavasoft AB)
(SCDEmu) SCDEmu [Kernel | System | Running] -> C:\Windows\System32\drivers\scdemu.sys -> [2009/03/15 06:25:46 | 000,056,268 | —- | M] (PowerISO Computing, Inc.)
(SynTP) Synaptics TouchPad Driver [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\SynTP.sys -> [2008/08/14 11:40:40 | 000,203,312 | —- | M] (Synaptics, Inc.)
(RTL8169) Realtek 8169 NT Driver [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\Rtlh86.sys -> [2008/08/06 09:26:08 | 000,124,928 | —- | M] (Realtek Corporation											)
(athr) Atheros Extensible Wireless LAN device driver [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\athr.sys -> [2008/07/29 06:05:04 | 000,919,552 | —- | M] (Atheros Communications, Inc.)
(LTXMD_VAC) Litex Media Virtual Audio Cable (WDM) [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\lmvac.sys -> [2008/07/01 00:16:26 | 000,018,912 | —- | M] (Windows (R) Codename Longhorn DDK provider)
(RTSTOR) Realtek USB 2.0 Card Reader [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\RTSTOR.sys -> [2008/06/23 10:44:54 | 000,062,464 | —- | M] (Realtek Semiconductor Corp.)
(MpFilter) Microsoft Malware Protection Driver [File_System | On_Demand | Stopped] -> C:\Windows\System32\drivers\MpFilter.sys -> [2008/05/15 16:15:16 | 000,053,168 | —- | M] (Microsoft Corporation)
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\RTKVHDA.sys -> [2008/01/29 23:34:20 | 002,058,528 | —- | M] (Realtek Semiconductor Corp.)
(tapvpn) TAP VPN Adapter [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\tapvpn.sys -> [2008/01/23 17:25:32 | 000,027,136 | —- | M] (The OpenVPN Project)
(tos_sps32) TOSHIBA tos_sps32 Service [Kernel | Boot | Running] -> C:\Windows\system32\DRIVERS\tos_sps32.sys -> [2008/01/21 15:42:24 | 000,285,184 | —- | M] (TOSHIBA Corporation)
(MegaSR) MegaSR [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\megasr.sys -> [2008/01/20 22:23:27 | 000,386,616 | —- | M] (LSI Corporation, Inc.)
(adpu320) adpu320 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adpu320.sys -> [2008/01/20 22:23:27 | 000,149,560 | —- | M] (Adaptec, Inc.)
(megasas) megasas [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\megasas.sys -> [2008/01/20 22:23:27 | 000,031,288 | —- | M] (LSI Corporation)
(adpu160m) adpu160m [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adpu160m.sys -> [2008/01/20 22:23:26 | 000,101,432 | —- | M] (Adaptec, Inc.)
(SiSRaid4) SiSRaid4 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\sisraid4.sys -> [2008/01/20 22:23:26 | 000,074,808 | —- | M] (Silicon Integrated Systems)
(HpCISSs) HpCISSs [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\hpcisss.sys -> [2008/01/20 22:23:26 | 000,040,504 | —- | M] (Hewlett-Packard Company)
(adpahci) adpahci [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adpahci.sys -> [2008/01/20 22:23:25 | 000,300,600 | —- | M] (Adaptec, Inc.)
(LSI_SAS) LSI_SAS [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\lsi_sas.sys -> [2008/01/20 22:23:25 | 000,089,656 | —- | M] (LSI Logic)
(ql2300) QLogic Fibre Channel Miniport Driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ql2300.sys -> [2008/01/20 22:23:24 | 001,122,360 | —- | M] (QLogic Corporation)
(E1G60) Intel(R) PRO/1000 NDIS 6 Adapter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\E1G60I32.sys -> [2008/01/20 22:23:24 | 000,118,784 | —- | M] (Intel Corporation)
(arcsas) arcsas [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\arcsas.sys -> [2008/01/20 22:23:24 | 000,079,928 | —- | M] (Adaptec, Inc.)
(iaStorV) Intel RAID Controller Vista [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iastorv.sys -> [2008/01/20 22:23:23 | 000,235,064 | —- | M] (Intel Corporation)
(vsmraid) vsmraid [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\vsmraid.sys -> [2008/01/20 22:23:23 | 000,130,616 | —- | M] (VIA Technologies Inc.,Ltd)
(ulsata2) ulsata2 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ulsata2.sys -> [2008/01/20 22:23:23 | 000,115,816 | —- | M] (Promise Technology, Inc.)
(LSI_SCSI) LSI_SCSI [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\lsi_scsi.sys -> [2008/01/20 22:23:23 | 000,096,312 | —- | M] (LSI Logic)
(LSI_FC) LSI_FC [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\lsi_fc.sys -> [2008/01/20 22:23:23 | 000,096,312 | —- | M] (LSI Logic)
(arc) arc [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\arc.sys -> [2008/01/20 22:23:23 | 000,079,416 | —- | M] (Adaptec, Inc.)
(elxstor) elxstor [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\elxstor.sys -> [2008/01/20 22:23:22 | 000,342,584 | —- | M] (Emulex)
(adp94xx) adp94xx [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\adp94xx.sys -> [2008/01/20 22:23:21 | 000,422,968 | —- | M] (Adaptec, Inc.)
(nvraid) NVIDIA nForce RAID Driver	[Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\nvraid.sys -> [2008/01/20 22:23:21 | 000,102,968 | —- | M] (NVIDIA Corporation)
(nvstor) nvstor [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\nvstor.sys -> [2008/01/20 22:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation)
(uliahci) uliahci [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\uliahci.sys -> [2008/01/20 22:23:20 | 000,238,648 | —- | M] (ULi Electronics Inc.)
(viaide) viaide [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\viaide.sys -> [2008/01/20 22:23:00 | 000,020,024 | —- | M] (VIA Technologies, Inc.)
(cmdide) cmdide [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\cmdide.sys -> [2008/01/20 22:23:00 | 000,019,000 | —- | M] (CMD Technology, Inc.)
(aliide) aliide [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\aliide.sys -> [2008/01/20 22:23:00 | 000,017,464 | —- | M] (Acer Laboratories Inc.)
(UVCFTR) UVCFTR [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\UVCFTR_S.SYS -> [2007/12/17 11:45:20 | 000,018,432 | —- | M] (Chicony Electronics Co., Ltd.)
(MSFWDrv) MSFWDrv [Kernel | Auto | Running] -> C:\Windows\System32\drivers\msfwdrv.sys -> [2007/11/27 22:45:00 | 000,091,200 | —- | M] (Microsoft Corporation)
(MSFWHLPR) MSFWHLPR [Kernel | System | Running] -> C:\Windows\System32\drivers\msfwhlpr.sys -> [2007/11/27 22:44:54 | 000,037,440 | —- | M] (Microsoft Corporation)
(TVALZ) TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver [Kernel | Boot | Running] -> C:\Windows\system32\DRIVERS\TVALZ_O.SYS -> [2007/11/09 14:00:52 | 000,023,640 | —- | M] (TOSHIBA Corporation)
(iaStor) Intel AHCI Controller [Kernel | Boot | Running] -> C:\Windows\system32\DRIVERS\iaStor.sys -> [2007/09/30 02:03:12 | 000,308,248 | —- | M] (Intel Corporation)
(igfx) igfx [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\igdkmd32.sys -> [2007/09/13 02:23:50 | 001,925,632 | —- | M] (Intel Corporation)
(jswpslwf) JumpStart Wireless Filter Driver [Kernel | System | Running] -> C:\Windows\System32\drivers\jswpslwf.sys -> [2007/08/31 17:43:32 | 000,020,352 | —- | M] (Atheros Communications, Inc.)
(AgereSoftModem) TOSHIBA V92 Software Modem [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\AGRSM.sys -> [2006/11/28 03:11:00 | 001,161,888 | —- | M] (Agere Systems)
(FwLnk) FwLnk Driver [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\FwLnk.sys -> [2006/11/20 18:11:14 | 000,007,168 | —- | M] (TOSHIBA Corporation)
(ql40xx) QLogic iSCSI Miniport Driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ql40xx.sys -> [2006/11/02 05:50:35 | 000,106,088 | —- | M] (QLogic Corporation)
(UlSata) UlSata [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ulsata.sys -> [2006/11/02 05:50:35 | 000,098,408 | —- | M] (Promise Technology, Inc.)
(nfrd960) nfrd960 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\nfrd960.sys -> [2006/11/02 05:50:19 | 000,045,160 | —- | M] (IBM Corporation)
(iirsp) iirsp [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iirsp.sys -> [2006/11/02 05:50:17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH)
(aic78xx) aic78xx [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\djsvs.sys -> [2006/11/02 05:50:11 | 000,071,272 | —- | M] (Adaptec, Inc.)
(iteraid) ITERAID_Service_Install [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iteraid.sys -> [2006/11/02 05:50:09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.)
(iteatapi) ITEATAPI_Service_Install [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\iteatapi.sys -> [2006/11/02 05:50:07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.)
(Symc8xx) Symc8xx [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\symc8xx.sys -> [2006/11/02 05:50:05 | 000,035,944 | —- | M] (LSI Logic)
(Sym_u3) Sym_u3 [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\sym_u3.sys -> [2006/11/02 05:50:03 | 000,034,920 | —- | M] (LSI Logic)
(Mraid35x) Mraid35x [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\mraid35x.sys -> [2006/11/02 05:49:59 | 000,033,384 | —- | M] (LSI Logic Corporation)
(Sym_hi) Sym_hi [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\sym_hi.sys -> [2006/11/02 05:49:56 | 000,031,848 | —- | M] (LSI Logic)
(Brserid) Brother MFC Serial Port Interface Driver (WDM) [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\brserid.sys -> [2006/11/02 04:25:24 | 000,071,808 | —- | M] (Brother Industries Ltd.)
(BrUsbSer) Brother MFC USB Serial WDM Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\brusbser.sys -> [2006/11/02 04:24:47 | 000,011,904 | —- | M] (Brother Industries Ltd.)
(BrFiltUp) Brother USB Mass-Storage Upper Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\brfiltup.sys -> [2006/11/02 04:24:46 | 000,005,248 | —- | M] (Brother Industries, Ltd.)
(BrFiltLo) Brother USB Mass-Storage Lower Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\system32\drivers\brfiltlo.sys -> [2006/11/02 04:24:45 | 000,013,568 | —- | M] (Brother Industries, Ltd.)
(BrSerWdm) Brother WDM Serial driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\brserwdm.sys -> [2006/11/02 04:24:44 | 000,062,336 | —- | M] (Brother Industries Ltd.)
(BrUsbMdm) Brother MFC USB Fax Only Modem [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\brusbmdm.sys -> [2006/11/02 04:24:44 | 000,012,160 | —- | M] (Brother Industries Ltd.)
(ntrigdigi) N-trig HID Tablet Driver [Kernel | Disabled | Stopped] -> C:\Windows\system32\drivers\ntrigdigi.sys -> [2006/11/02 03:36:50 | 000,020,608 | —- | M] (N-trig Innovative Technologies)
(tdcmdpst) TOSHIBA Writing Engine Filter Driver [Kernel | On_Demand | Running] -> C:\Windows\System32\drivers\tdcmdpst.sys -> [2006/10/18 15:50:04 | 000,016,128 | —- | M] (TOSHIBA Corporation.)
(ICDUSB2) Sony IC Recorder (P) [Kernel | On_Demand | Stopped] -> C:\Windows\System32\drivers\IcdUsb2.sys -> [2002/11/28 21:23:24 | 000,039,048 | —- | M] (Sony Corporation)
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://www.shoptoshiba.ca/welcome -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://www.shoptoshiba.ca/welcome -> 
HKEY_LOCAL_MACHINE\: URLSearchHooks\\"{03402f96-3dc7-4285-bc50-9e81fefafe43}" [HKLM] -> C:\Program Files\AIM Toolbar\aimtb.dll [AIM Toolbar Search Class] -> [2009/05/06 14:14:26 | 001,279,272 | —- | M] (AOL LLC.)
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> 
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> 
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\] > -> -> 
HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\: Main\\"Start Page" -> http://www.shoptoshiba.ca/welcome -> 
HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\: Main\\"StartPageCache" -> 1 -> 
HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\: URLSearchHooks\\"{03402f96-3dc7-4285-bc50-9e81fefafe43}" [HKLM] -> C:\Program Files\AIM Toolbar\aimtb.dll [AIM Toolbar Search Class] -> [2009/05/06 14:14:26 | 001,279,272 | —- | M] (AOL LLC.)
HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\: "ProxyEnable" -> 0 -> 
HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\: "ProxyOverride" -> local -> 
< FireFox Settings [Prefs.js] > -> C:\Users\Marwa\AppData\Roaming\Mozilla\FireFox\Profiles\l5fh2u0x.default\prefs.js -> 
browser.search.defaultenginename -> "AIM Search" ->
browser.search.defaulturl -> "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=&query;=" ->
browser.search.order.1 -> "Ask" ->
browser.search.param.yahoo-fr -> "" ->
browser.search.param.yahoo-fr-cjkt -> "" ->
browser.search.selectedEngine -> "AIM Search" ->
browser.search.useDBForOrder -> true ->
extensions.enabledItems -> {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1 ->
extensions.enabledItems -> 6 ->
extensions.enabledItems -> 2 ->
extensions.enabledItems -> 48 ->
extensions.enabledItems -> {c2f863cd-0429-48c7-bb54-db756a951760}:[removed] ->
extensions.enabledItems -> {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.2 ->
extensions.enabledItems -> {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1 ->
extensions.enabledItems -> {c50ca3c4-5656-43c2-a061-13e717f73fc8}:2.0 ->
extensions.enabledItems -> {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:[removed] ->
extensions.enabledItems -> {c95a4e8e-816d-4655-8c79-d736da1adb6d}:[removed] ->
extensions.enabledItems -> [removed]:3.1 ->
extensions.enabledItems -> {991A772A-BA13-4c1d-A9EF-F897F31DEC7D}:3.1 ->
extensions.enabledItems -> {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0 ->
keyword.URL -> "http://ca.search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=" ->
network.proxy.backup.ftp -> "" ->
network.proxy.backup.ftp_port -> 0 ->
network.proxy.backup.gopher -> "" ->
network.proxy.backup.gopher_port -> 0 ->
network.proxy.backup.socks -> "" ->
network.proxy.backup.socks_port -> 0 ->
network.proxy.backup.ssl -> "" ->
network.proxy.backup.ssl_port -> 0 ->
network.proxy.ftp -> "" ->
network.proxy.ftp_port -> "" ->
network.proxy.gopher -> "" ->
network.proxy.gopher_port -> "" ->
network.proxy.http -> "" ->
network.proxy.http_port -> "" ->
network.proxy.share_proxy_settings -> "" ->
network.proxy.socks -> "" ->
network.proxy.socks_port -> "" ->
network.proxy.ssl -> "" ->
network.proxy.ssl_port -> "" ->
< FireFox Settings [User.js] > -> C:\Users\Marwa\AppData\Roaming\Mozilla\FireFox\Profiles\l5fh2u0x.default\user.js -> 
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions ->  -> 
HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758} -> C:\Program Files\Real\RealPlayer\browserrecord [C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD] -> [2009/03/30 19:42:43 | 000,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions ->  -> 
HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Components -> C:\Program Files\Mozilla Firefox\components [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2010/02/18 17:06:08 | 000,000,000 | —D | M]
HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Plugins -> C:\Program Files\Mozilla Firefox\plugins [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2010/03/13 16:26:32 | 000,000,000 | —D | M]
< FireFox Extensions [User Folders] > -> 
  -> C:\Users\Marwa\AppData\Roaming\Mozilla\Extensions -> [2008/08/30 19:24:00 | 000,000,000 | —D | M]
  -> C:\Users\Marwa\AppData\Roaming\Mozilla\Firefox\Profiles\l5fh2u0x.default\extensions -> [2010/03/10 02:32:21 | 000,000,000 | —D | M]
FlashGot   -> C:\Users\Marwa\AppData\Roaming\Mozilla\Firefox\Profiles\l5fh2u0x.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34} -> [2009/09/07 04:24:28 | 000,000,000 | —D | M]
Microsoft .NET Framework Assistant   -> C:\Users\Marwa\AppData\Roaming\Mozilla\Firefox\Profiles\l5fh2u0x.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} -> [2009/09/05 02:59:03 | 000,000,000 | —D | M]
No name found   -> C:\Users\Marwa\AppData\Roaming\Mozilla\Firefox\Profiles\l5fh2u0x.default\extensions\{991A772A-BA13-4c1d-A9EF-F897F31DEC7D} -> [2008/11/06 23:13:11 | 000,000,000 | —D | M]
No name found   -> C:\Users\Marwa\AppData\Roaming\Mozilla\Firefox\Profiles\l5fh2u0x.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760} -> [2009/06/24 05:19:08 | 000,000,000 | —D | M]
Fast Video Download   -> C:\Users\Marwa\AppData\Roaming\Mozilla\Firefox\Profiles\l5fh2u0x.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8} -> [2009/03/17 17:05:37 | 000,000,000 | —D | M]
Hotspot Shield Toolbar   -> C:\Users\Marwa\AppData\Roaming\Mozilla\Firefox\Profiles\l5fh2u0x.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d} -> [2008/10/14 13:22:17 | 000,000,000 | —D | M]
Adobe DLM (powered by getPlus(R))   -> C:\Users\Marwa\AppData\Roaming\Mozilla\Firefox\Profiles\l5fh2u0x.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} -> [2009/10/19 13:56:39 | 000,000,000 | —D | M]
No name found   -> C:\Users\Marwa\AppData\Roaming\Mozilla\Firefox\Profiles\l5fh2u0x.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D} -> [2009/03/17 17:10:44 | 000,000,000 | —D | M]
  -> C:\Users\Marwa\AppData\Roaming\Mozilla\Firefox\Profiles\l5fh2u0x.default\extensions\[removed] -> [2009/10/01 00:42:37 | 000,000,000 | —D | M]
< FireFox SearchPlugins [User Folders] > -> 
 aim-search.xml -> C:\Users\Marwa\AppData\Roaming\Mozilla\Firefox\Profiles\l5fh2u0x.default\searchplugins\aim-search.xml -> [2009/06/24 05:19:12 | 000,004,196 | —- | M] ()
 ask.xml -> C:\Users\Marwa\AppData\Roaming\Mozilla\Firefox\Profiles\l5fh2u0x.default\searchplugins\ask.xml -> [2009/03/17 17:13:11 | 000,000,681 | —- | M] ()
< FireFox Extensions [Program Folders] > -> 
  -> C:\Program Files\Mozilla Firefox\extensions -> [2008/10/14 13:22:21 | 000,000,000 | —D | M]
< HOSTS File > ([2006/09/18 17:41:30 | 000,000,761 | —- | M] - 20 lines) -> C:\Windows\System32\drivers\etc\hosts -> 
Reset Hosts
127.0.0.1	   localhost
::1			 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/22 23:08:42 | 000,062,080 | —- | M] (Adobe Systems Incorporated)
{201f27d4-3704-41d6-89c1-aa35e39143ed} [HKLM] -> C:\Program Files\AskBarDis\bar\bin\askBar.dll [AskBar BHO] -> [2008/08/26 10:32:12 | 000,279,944 | —- | M] (Ask.com)
{3049C3E9-B461-4BC5-8870-4C09146192CA} [HKLM] -> C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [RealPlayer Download and Record Plugin for Internet Explorer] -> [2009/03/30 19:42:42 | 000,312,928 | —- | M] (RealPlayer)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [SSVHelper Class] -> [2008/06/10 04:27:02 | 000,509,328 | —- | M] (Sun Microsystems, Inc.)
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [Google Toolbar Helper] -> [2010/01/30 12:52:04 | 000,279,664 | —- | M] (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [Google Toolbar Notifier BHO] -> [2010/02/09 17:32:45 | 000,812,528 | —- | M] (Google Inc.)
{b0cda128-b425-4eef-a174-61a11ac5dbf8} [HKLM] -> C:\Program Files\AIM Toolbar\aimtb.dll [AIM Toolbar Loader] -> [2009/05/06 14:14:26 | 001,279,272 | —- | M] (AOL LLC.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [Google Toolbar] -> [2010/01/30 12:52:04 | 000,279,664 | —- | M] (Google Inc.)
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}" [HKLM] -> C:\Program Files\AskBarDis\bar\bin\askBar.dll [Ask Toolbar] -> [2008/08/26 10:32:12 | 000,279,944 | —- | M] (Ask.com)
"{61539ecd-cc67-4437-a03c-9aaccbd14326}" [HKLM] -> C:\Program Files\AIM Toolbar\aimtb.dll [AIM Toolbar] -> [2009/05/06 14:14:26 | 001,279,272 | —- | M] (AOL LLC.)
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\] > -> HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [Google Toolbar] -> [2010/01/30 12:52:04 | 000,279,664 | —- | M] (Google Inc.)
WebBrowser\\"{3041D03E-FD4B-44E0-B742-2D9B88305F98}" [HKLM] -> C:\Program Files\AskBarDis\bar\bin\askBar.dll [Ask Toolbar] -> [2008/08/26 10:32:12 | 000,279,944 | —- | M] (Ask.com)
WebBrowser\\"{472734EA-242A-422B-ADF8-83D1E48CC825}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
WebBrowser\\"{61539ECD-CC67-4437-A03C-9AACCBD14326}" [HKLM] -> C:\Program Files\AIM Toolbar\aimtb.dll [AIM Toolbar] -> [2009/05/06 14:14:26 | 001,279,272 | —- | M] (AOL LLC.)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"00TCrdMain" -> C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe] -> [2008/01/22 14:25:26 | 000,712,704 | —- | M] (TOSHIBA Corporation)
"Adobe Reader Speed Launcher" -> C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008/01/11 22:16:38 | 000,039,792 | —- | M] (Adobe Systems Incorporated)
"AdobeCS4ServiceManager" -> C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe ["C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin] -> [2008/08/14 08:58:34 | 000,611,712 | —- | M] (Adobe Systems Incorporated)
"AppleSyncNotifier" -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe] -> [2008/10/01 13:57:42 | 000,111,936 | —- | M] (Apple Inc.)
"BlackBerryAutoUpdate" -> C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe [C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background] -> [2009/07/02 00:12:46 | 000,623,960 | —- | M] (Research In Motion Limited)
"Camera Assistant Software" -> C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe ["C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start] -> [2007/10/25 17:41:18 | 000,413,696 | —- | M] (Chicony)
"LtMoh" -> C:\Program Files\ltmoh\ltmoh.exe [C:\Program Files\ltmoh\Ltmoh.exe] -> [2007/01/09 02:23:04 | 000,191,552 | —- | M] (Agere Systems)
"Malwarebytes Anti-Malware (reboot)" -> C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe ["C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript] -> [2010/01/07 16:07:10 | 001,394,000 | —- | M] (Malwarebytes Corporation)
"OneCareUI" -> C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe ["C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"] -> [2010/02/05 17:19:46 | 000,065,256 | —- | M] (Microsoft Corporation)
"PWRISOVM.EXE" -> C:\Program Files\PowerISO\PWRISOVM.EXE [C:\Program Files\PowerISO\PWRISOVM.EXE] -> [2009/03/15 06:15:16 | 000,180,224 | —- | M] (PowerISO Computing, Inc.)
"RtHDVCpl" -> C:\Windows\RtHDVCpl.exe [RtHDVCpl.exe] -> [2008/01/29 06:51:52 | 004,911,104 | —- | M] (Realtek Semiconductor)
"Skytel" -> C:\Windows\SkyTel.exe [Skytel.exe] -> [2007/11/20 06:15:58 | 001,826,816 | —- | M] (Realtek Semiconductor Corp.)
"SmoothView" -> C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe [%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe] -> [2007/06/15 21:01:58 | 000,448,080 | —- | M] (TOSHIBA Corporation)
"SunJavaUpdateSched" -> C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe ["C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"] -> [2008/06/10 04:27:04 | 000,144,784 | —- | M] (Sun Microsystems, Inc.)
"TkBellExe" -> C:\Program Files\Common Files\Real\Update_OB\realsched.exe ["C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot] -> [2009/03/30 19:42:22 | 000,198,160 | —- | M] (RealNetworks, Inc.)
"TPwrMain" -> C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe [%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE] -> [2008/01/17 16:27:52 | 000,431,456 | —- | M] (TOSHIBA Corporation)
"Windows Defender" -> C:\Program Files\Windows Defender\MSASCui.exe [%ProgramFiles%\Windows Defender\MSASCui.exe -hide] -> [2008/01/20 22:23:32 | 001,008,184 | —- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"WindowsWelcomeCenter" -> C:\Windows\System32\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2008/01/20 22:23:39 | 002,153,472 | —- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"WindowsWelcomeCenter" -> C:\Windows\System32\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2008/01/20 22:23:39 | 002,153,472 | —- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\] > -> HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Aim" -> C:\Program Files\AIM\aim.exe ["C:\Program Files\AIM\aim.exe" /d locale=en-CA] -> [2009/12/01 13:38:47 | 003,951,976 | —- | M] (AOL LLC)
"googletalk" -> C:\Users\Marwa\AppData\Roaming\Google\Google Talk\googletalk.exe [C:\Users\Marwa\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart] -> [2007/01/01 17:22:02 | 003,739,648 | —- | M] (Google)
"swg" -> C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ["C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"] -> [2009/01/12 14:42:44 | 000,039,408 | —- | M] (Google Inc.)
"TOSCDSPD" -> C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe] -> [2008/07/04 14:51:54 | 000,430,080 | —- | M] (TOSHIBA)
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003] > -> HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\] > -> HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\Software\Microsoft\Internet Explorer\MenuExt\ -> 
&AIM; Toolbar Search -> C:\ProgramData\AIM Toolbar\ieToolbar\resources\en-US\local\search.html [C:\ProgramData\AIM Toolbar\ieToolbar\resources\en-US\local\search.html] -> [2008/05/22 10:44:38 | 000,000,747 | —- | M] ()
E&xport; to Microsoft Excel -> C:\Program Files\Microsoft Office\Office12\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000] -> [2010/01/15 00:57:10 | 018,343,272 | —- | M] (Microsoft Corporation)
Google Sidewiki… -> C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll [res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html] -> [2010/01/30 12:52:19 | 000,848,896 | —- | M] (Google Inc.)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} [HKLM] -> C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll [Menu: Sun Java Console] -> [2008/06/10 04:27:02 | 000,132,496 | —- | M] (Sun Microsystems, Inc.)
{0b83c99c-1efa-4259-858f-bcb33e007a5b}:{61539ecd-cc67-4437-a03c-9aaccbd14326} [HKLM] -> C:\Program Files\AIM Toolbar\aimtb.dll [Button: AIM Toolbar] -> [2009/05/06 14:14:26 | 001,279,272 | —- | M] (AOL LLC.)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll [Button: Send to OneNote] -> [2008/10/25 07:52:00 | 000,604,056 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll [Menu: S&end; to OneNote] -> [2008/10/25 07:52:00 | 000,604,056 | —- | M] (Microsoft Corporation)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL [Button: Research] -> [2009/03/06 04:04:56 | 000,039,464 | —- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\] > -> HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 2 domain(s) found. -> 
www_adobe.com [http] -> Trusted sites -> 
my_ryerson.ca [https] -> Trusted sites -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\] > -> HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-21-1713085100-2583350799-4195904723-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{5ED80217-570B-4DA9-BF44-BE107C0EC166} [HKLM] -> http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab [Windows Live Safety Center Base Module] -> 
{615F158E-D5CA-422F-A8E7-F6A5EED7063B} [HKLM] -> http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab [Bejeweled Control] -> 
{67DABFBF-D0AB-41FA-9C46-CC0F21721616} [HKLM] -> http://download.divx.com/player/DivXBrowserPlugin.cab [DivXBrowserPlugin Object] -> 
{8100D56A-5661-482C-BEE8-AFECE305D968} [HKLM] -> http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab [Facebook Photo Uploader 5 Control] -> 
{8A94C905-FF9D-43B6-8708-F0F22D22B1CB} [HKLM] -> http://www.worldwinner.com/games/shared/wwlaunch.cab [Wwlaunch Control] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab [Java Plug-in 1.6.0_07] -> 
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab [Reg Error: Key error.] -> 
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab [Java Plug-in 1.6.0_03] -> 
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab [Java Plug-in 1.6.0_07] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab [Java Plug-in 1.6.0_07] -> 
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} [HKLM] -> http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab [Reg Error: Key error.] -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ -> 
DhcpNameServer -> 192.168.0.1 -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{11E4BC55-D55A-4150-B8E9-7C3C560E1BD5}\\DhcpNameServer -> 192.168.0.1   (Realtek RTL8102E Family PCI-E Fast Ethernet NIC (NDIS 6.0)) -> 
{E2A2204D-54FA-4703-A65D-719DA08FF974}\\DhcpNameServer -> 192.168.0.1   (Atheros AR5007EG Wireless Network Adapter) -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
explorer.exe -> C:\Windows\explorer.exe -> [2008/10/29 02:29:41 | 002,927,104 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 
igfxcui -> C:\Windows\System32\igfxdev.dll -> [2007/09/13 02:10:04 | 000,204,800 | —- | M] (Intel Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> 
"C:\Program Files\iCall\iCall.exe" -> C:\Program Files\iCall\iCall.exe [C:\Program Files\iCall\iCall.exe:*:Enabled:iCall] -> [2007/08/28 14:24:22 | 001,191,936 | —- | M] ()
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" ->  [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > ->  -> 
C:\autoexec.bat [REM Dummy file for NTVDM | ] -> C:\autoexec.bat [ NTFS ] -> [2006/09/18 17:43:36 | 000,000,024 | —- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command -> 
comfile [open] -> "%1" %* -> 
exefile [open] -> "%1" %* -> 
 
 
[Files/Folders - Created Within 30 Days]
 Malwarebytes -> C:\Users\Marwa\AppData\Roaming\Malwarebytes -> [2010/03/14 04:27:29 | 000,000,000 | —D | C]
 mbamswissarmy.sys -> C:\Windows\System32\drivers\mbamswissarmy.sys -> [2010/03/14 04:27:15 | 000,038,224 | —- | C] (Malwarebytes Corporation)
 Malwarebytes -> C:\ProgramData\Malwarebytes -> [2010/03/14 04:27:07 | 000,000,000 | —D | C]
 mbam.sys -> C:\Windows\System32\drivers\mbam.sys -> [2010/03/14 04:27:06 | 000,019,160 | —- | C] (Malwarebytes Corporation)
 Malwarebytes' Anti-Malware -> C:\Program Files\Malwarebytes' Anti-Malware -> [2010/03/14 04:27:05 | 000,000,000 | —D | C]
 mbam-setup.exe -> C:\Users\Marwa\Desktop\mbam-setup.exe -> [2010/03/14 04:25:33 | 005,115,824 | —- | C] (Malwarebytes Corporation									)
 _OTS -> C:\_OTS -> [2010/03/14 04:03:45 | 000,000,000 | —D | C]
 nshhttp.dll -> C:\Windows\System32\nshhttp.dll -> [2010/03/14 04:01:14 | 000,024,064 | —- | C] (Microsoft Corporation)
 httpapi.dll -> C:\Windows\System32\httpapi.dll -> [2010/03/14 04:01:06 | 000,031,232 | —- | C] (Microsoft Corporation)
 OTS.exe -> C:\Users\Marwa\Desktop\OTS.exe -> [2010/03/13 14:20:54 | 000,636,928 | —- | C] (OldTimer Tools)
 ERDNT -> C:\Windows\ERDNT -> [2010/03/13 01:19:08 | 000,000,000 | —D | C]
 ERUNT -> C:\Program Files\ERUNT -> [2010/03/13 01:18:39 | 000,000,000 | —D | C]
 erunt_setup.exe -> C:\Users\Marwa\Desktop\erunt_setup.exe -> [2010/03/13 01:16:38 | 000,791,393 | —- | C] (Lars Hederer												)
 Trend Micro -> C:\Program Files\Trend Micro -> [2010/03/13 01:01:39 | 000,000,000 | —D | C]
 Threat Expert -> C:\Users\Marwa\AppData\Local\Threat Expert -> [2010/03/09 17:07:33 | 000,000,000 | —D | C]
 YouSendIt -> C:\Users\Marwa\AppData\Roaming\YouSendIt -> [2010/03/09 14:55:19 | 000,000,000 | —D | C]
 YouSendIt -> C:\Program Files\YouSendIt -> [2010/03/09 14:40:20 | 000,000,000 | —D | C]
 SBREDrv.sys -> C:\Windows\System32\drivers\SBREDrv.sys -> [2010/03/09 11:20:56 | 000,095,024 | —- | C] (Sunbelt Software)
 Lbd.sys -> C:\Windows\System32\drivers\Lbd.sys -> [2010/03/09 11:20:47 | 000,064,288 | —- | C] (Lavasoft AB)
 {74D08EB8-01D1-4BAE-91E3-F30C1B031AC6} -> C:\ProgramData\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6} -> [2010/03/09 11:17:51 | 000,000,000 | -H-D | C]
 spdoc.exe -> C:\Users\Marwa\Desktop\spdoc.exe -> [2010/03/09 10:35:21 | 034,595,080 | —- | C] (PC Tools													)
 Art -> C:\Users\Marwa\Desktop\Art -> [2010/02/27 18:21:09 | 000,000,000 | —D | C]
 Illustrator -> C:\Users\Marwa\Desktop\Illustrator -> [2010/02/27 17:07:50 | 000,000,000 | —D | C]
 Thinstall -> C:\Users\Marwa\AppData\Roaming\Thinstall -> [2010/02/26 18:47:01 | 000,000,000 | —D | C]
 tzres.dll -> C:\Windows\System32\tzres.dll -> [2010/02/23 15:43:24 | 000,002,048 | —- | C] (Microsoft Corporation)
 RMActivate_isv.exe -> C:\Windows\System32\RMActivate_isv.exe -> [2010/02/23 15:42:18 | 000,523,776 | —- | C] (Microsoft Corporation)
 RMActivate.exe -> C:\Windows\System32\RMActivate.exe -> [2010/02/23 15:42:17 | 000,511,488 | —- | C] (Microsoft Corporation)
 RMActivate_ssp.exe -> C:\Windows\System32\RMActivate_ssp.exe -> [2010/02/23 15:42:14 | 000,347,136 | —- | C] (Microsoft Corporation)
 RMActivate_ssp_isv.exe -> C:\Windows\System32\RMActivate_ssp_isv.exe -> [2010/02/23 15:42:13 | 000,346,624 | —- | C] (Microsoft Corporation)
 secproc_isv.dll -> C:\Windows\System32\secproc_isv.dll -> [2010/02/23 15:42:12 | 000,472,576 | —- | C] (Microsoft Corporation)
 secproc.dll -> C:\Windows\System32\secproc.dll -> [2010/02/23 15:42:12 | 000,472,064 | —- | C] (Microsoft Corporation)
 msdrm.dll -> C:\Windows\System32\msdrm.dll -> [2010/02/23 15:42:09 | 000,329,216 | —- | C] (Microsoft Corporation)
 secproc_ssp_isv.dll -> C:\Windows\System32\secproc_ssp_isv.dll -> [2010/02/23 15:42:09 | 000,151,040 | —- | C] (Microsoft Corporation)
 secproc_ssp.dll -> C:\Windows\System32\secproc_ssp.dll -> [2010/02/23 15:42:09 | 000,151,040 | —- | C] (Microsoft Corporation)
 
[Files/Folders - Modified Within 30 Days]
 NTUSER.DAT -> C:\Users\Marwa\NTUSER.DAT -> [2010/03/14 15:44:14 | 005,242,880 | -HS- | M] ()
 GoogleUpdateTaskMachineUA.job -> C:\Windows\tasks\GoogleUpdateTaskMachineUA.job -> [2010/03/14 15:43:00 | 000,000,886 | —- | M] ()
 7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [2010/03/14 15:14:26 | 000,003,216 | -H– | M] ()
 7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [2010/03/14 15:14:26 | 000,003,216 | -H– | M] ()
 GoogleUpdateTaskUserS-1-5-21-1713085100-2583350799-4195904723-1003UA.job -> C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1713085100-2583350799-4195904723-1003UA.job -> [2010/03/14 14:49:00 | 000,000,908 | —- | M] ()
 GoogleUpdateTaskUserS-1-5-21-1713085100-2583350799-4195904723-1003Core.job -> C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1713085100-2583350799-4195904723-1003Core.job -> [2010/03/14 13:49:00 | 000,000,856 | —- | M] ()
 PerfStringBackup.INI -> C:\Windows\System32\PerfStringBackup.INI -> [2010/03/14 13:21:21 | 000,717,234 | —- | M] ()
 perfh009.dat -> C:\Windows\System32\perfh009.dat -> [2010/03/14 13:21:21 | 000,618,208 | —- | M] ()
 perfc009.dat -> C:\Windows\System32\perfc009.dat -> [2010/03/14 13:21:21 | 000,113,536 | —- | M] ()
 Ad-Aware Update (Weekly).job -> C:\Windows\tasks\Ad-Aware Update (Weekly).job -> [2010/03/14 13:16:46 | 000,000,370 | —- | M] ()
 GoogleUpdateTaskMachineCore.job -> C:\Windows\tasks\GoogleUpdateTaskMachineCore.job -> [2010/03/14 13:15:00 | 000,000,882 | —- | M] ()
 SA.DAT -> C:\Windows\tasks\SA.DAT -> [2010/03/14 13:14:33 | 000,000,006 | -H– | M] ()
 bootstat.dat -> C:\Windows\bootstat.dat -> [2010/03/14 13:14:21 | 000,067,584 | –S- | M] ()
 hiberfil.sys -> C:\hiberfil.sys -> [2010/03/14 13:14:16 | 3208,642,560 | -HS- | M] ()
 NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Marwa\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms -> [2010/03/14 13:13:24 | 000,524,288 | -HS- | M] ()
 NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf -> C:\Users\Marwa\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf -> [2010/03/14 13:13:24 | 000,065,536 | -HS- | M] ()
 IconCache.db -> C:\Users\Marwa\AppData\Local\IconCache.db -> [2010/03/14 04:45:51 | 002,034,062 | -H– | M] ()
 mbam-setup.exe -> C:\Users\Marwa\Desktop\mbam-setup.exe -> [2010/03/14 04:26:08 | 005,115,824 | —- | M] (Malwarebytes Corporation									)
 CKScanner.exe -> C:\Users\Marwa\Desktop\CKScanner.exe -> [2010/03/13 18:18:27 | 000,451,584 | —- | M] ()
 MEMORY.DMP -> C:\Windows\MEMORY.DMP -> [2010/03/13 16:24:21 | 440,383,907 | —- | M] ()
 2rhmxnjv.exe -> C:\Users\Marwa\Desktop\2rhmxnjv.exe -> [2010/03/13 15:35:38 | 000,293,376 | —- | M] ()
 OTS.exe -> C:\Users\Marwa\Desktop\OTS.exe -> [2010/03/13 14:21:10 | 000,636,928 | —- | M] (OldTimer Tools)
 Picture 1.png -> C:\Users\Marwa\Desktop\Picture 1.png -> [2010/03/13 02:14:03 | 000,044,706 | —- | M] ()
 erunt_setup.exe -> C:\Users\Marwa\Desktop\erunt_setup.exe -> [2010/03/13 01:18:09 | 000,791,393 | —- | M] (Lars Hederer												)
 HijackThis.lnk -> C:\Users\Marwa\Desktop\HijackThis.lnk -> [2010/03/13 01:01:40 | 000,001,885 | —- | M] ()
 _DSC0137.png -> C:\Users\Marwa\Desktop\_DSC0137.png -> [2010/03/11 22:34:21 | 000,783,669 | —- | M] ()
 _DSC0099.png -> C:\Users\Marwa\Desktop\_DSC0099.png -> [2010/03/10 04:41:43 | 000,667,201 | —- | M] ()
 Feature - first draft.docx -> C:\Users\Marwa\Documents\Feature - first draft.docx -> [2010/03/10 00:56:00 | 000,020,790 | —- | M] ()
 reviews.docx -> C:\Users\Marwa\Documents\reviews.docx -> [2010/03/10 00:39:34 | 000,016,887 | —- | M] ()
 SBREDrv.sys -> C:\Windows\System32\drivers\SBREDrv.sys -> [2010/03/09 11:20:47 | 000,095,024 | —- | M] (Sunbelt Software)
 lsdelete.exe -> C:\Windows\System32\lsdelete.exe -> [2010/03/09 11:20:39 | 000,015,880 | —- | M] ()
 Ad-Aware.lnk -> C:\Users\Public\Desktop\Ad-Aware.lnk -> [2010/03/09 11:17:48 | 000,001,018 | —- | M] ()
 spdoc.exe -> C:\Users\Marwa\Desktop\spdoc.exe -> [2010/03/09 10:40:44 | 034,595,080 | —- | M] (PC Tools													)
 exefix.reg -> C:\Users\Marwa\Desktop\exefix.reg -> [2010/03/09 10:32:42 | 000,000,285 | —- | M] ()
 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Users\Marwa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2010/03/08 01:25:38 | 000,191,488 | —- | M] ()
 ~$ature - first draft.docx -> C:\Users\Marwa\Documents\~$ature - first draft.docx -> [2010/03/03 18:39:12 | 000,000,162 | -H– | M] ()
 Feature, scene.docx -> C:\Users\Marwa\Documents\Feature, scene.docx -> [2010/03/02 15:15:34 | 000,017,999 | —- | M] ()
 GDIPFONTCACHEV1.DAT -> C:\Users\Marwa\AppData\Local\GDIPFONTCACHEV1.DAT -> [2010/02/24 04:27:55 | 000,113,408 | —- | M] ()
 FNTCACHE.DAT -> C:\Windows\System32\FNTCACHE.DAT -> [2010/02/24 04:25:23 | 001,745,864 | —- | M] ()
 nshhttp.dll -> C:\Windows\System32\nshhttp.dll -> [2010/02/20 19:39:35 | 000,024,064 | —- | M] (Microsoft Corporation)
 httpapi.dll -> C:\Windows\System32\httpapi.dll -> [2010/02/20 19:37:20 | 000,031,232 | —- | M] (Microsoft Corporation)
 The first time Sean does it.docx -> C:\Users\Marwa\Documents\The first time Sean does it.docx -> [2010/02/19 15:34:03 | 000,016,814 | —- | M] ()
 
[Files - No Company Name]
 Ad-Aware Update (Weekly).job -> C:\Windows\tasks\Ad-Aware Update (Weekly).job -> [2010/03/14 13:16:45 | 000,000,370 | —- | C] ()
 IconCache.db -> C:\Users\Marwa\AppData\Local\IconCache.db -> [2010/03/14 04:45:51 | 002,034,062 | -H– | C] ()
 CKScanner.exe -> C:\Users\Marwa\Desktop\CKScanner.exe -> [2010/03/13 18:18:20 | 000,451,584 | —- | C] ()
 hiberfil.sys -> C:\hiberfil.sys -> [2010/03/13 17:24:59 | 3208,642,560 | -HS- | C] ()
 2rhmxnjv.exe -> C:\Users\Marwa\Desktop\2rhmxnjv.exe -> [2010/03/13 15:35:30 | 000,293,376 | —- | C] ()
 Picture 1.png -> C:\Users\Marwa\Desktop\Picture 1.png -> [2010/03/13 02:16:27 | 000,044,706 | —- | C] ()
 HijackThis.lnk -> C:\Users\Marwa\Desktop\HijackThis.lnk -> [2010/03/13 01:01:40 | 000,001,885 | —- | C] ()
 _DSC0137.png -> C:\Users\Marwa\Desktop\_DSC0137.png -> [2010/03/11 22:34:18 | 000,783,669 | —- | C] ()
 _DSC0099.png -> C:\Users\Marwa\Desktop\_DSC0099.png -> [2010/03/10 04:41:29 | 000,667,201 | —- | C] ()
 reviews.docx -> C:\Users\Marwa\Documents\reviews.docx -> [2010/03/09 22:53:11 | 000,016,887 | —- | C] ()
 Ad-Aware.lnk -> C:\Users\Public\Desktop\Ad-Aware.lnk -> [2010/03/09 11:17:48 | 000,001,018 | —- | C] ()
 exefix.reg -> C:\Users\Marwa\Desktop\exefix.reg -> [2010/03/09 10:32:42 | 000,000,285 | —- | C] ()
 ~$ature - first draft.docx -> C:\Users\Marwa\Documents\~$ature - first draft.docx -> [2010/03/03 18:39:11 | 000,000,162 | -H– | C] ()
 Feature - first draft.docx -> C:\Users\Marwa\Documents\Feature - first draft.docx -> [2010/03/02 15:16:35 | 000,020,790 | —- | C] ()
 Feature, scene.docx -> C:\Users\Marwa\Documents\Feature, scene.docx -> [2010/02/24 04:59:27 | 000,017,999 | —- | C] ()
 The first time Sean does it.docx -> C:\Users\Marwa\Documents\The first time Sean does it.docx -> [2010/02/19 06:18:47 | 000,016,814 | —- | C] ()
 DivXVfWCodec.dll -> C:\Windows\System32\DivXVfWCodec.dll -> [2008/12/22 00:59:26 | 000,025,312 | —- | C] ()
 SamsungVfWCodec.dll -> C:\Windows\System32\SamsungVfWCodec.dll -> [2008/12/22 00:59:24 | 000,025,312 | —- | C] ()
 OpenQuicktimeLib.dll -> C:\Windows\System32\OpenQuicktimeLib.dll -> [2008/12/22 00:59:08 | 000,447,200 | —- | C] ()
 libfaac.dll -> C:\Windows\System32\libfaac.dll -> [2008/12/22 00:52:02 | 000,066,272 | —- | C] ()
 trc.dll -> C:\Windows\System32\trc.dll -> [2008/10/09 10:20:28 | 000,122,880 | —- | C] ()
 dsp_trc.dll -> C:\Windows\System32\dsp_trc.dll -> [2008/10/09 10:20:20 | 000,081,920 | —- | C] ()
 qt-dx331.dll -> C:\Windows\System32\qt-dx331.dll -> [2008/09/15 20:14:24 | 003,596,288 | —- | C] ()
 dtu100.dll.manifest -> C:\Windows\System32\dtu100.dll.manifest -> [2008/09/15 20:12:02 | 000,000,416 | —- | C] ()
 dpl100.dll.manifest -> C:\Windows\System32\dpl100.dll.manifest -> [2008/09/15 20:12:02 | 000,000,416 | —- | C] ()
 DivXWMPExtType.dll -> C:\Windows\System32\DivXWMPExtType.dll -> [2008/09/15 20:11:10 | 000,012,288 | —- | C] ()
 IVIresizeW7.dll -> C:\Windows\System32\IVIresizeW7.dll -> [2008/08/28 13:47:37 | 000,204,800 | —- | C] ()
 IVIresizeA6.dll -> C:\Windows\System32\IVIresizeA6.dll -> [2008/08/28 13:47:37 | 000,200,704 | —- | C] ()
 IVIresizeP6.dll -> C:\Windows\System32\IVIresizeP6.dll -> [2008/08/28 13:47:37 | 000,192,512 | —- | C] ()
 IVIresizeM6.dll -> C:\Windows\System32\IVIresizeM6.dll -> [2008/08/28 13:47:37 | 000,192,512 | —- | C] ()
 IVIresizePX.dll -> C:\Windows\System32\IVIresizePX.dll -> [2008/08/28 13:47:37 | 000,188,416 | —- | C] ()
 IVIresize.dll -> C:\Windows\System32\IVIresize.dll -> [2008/08/28 13:47:37 | 000,020,480 | —- | C] ()
 csellang.ini -> C:\Windows\System32\csellang.ini -> [2008/08/28 13:28:07 | 000,128,113 | —- | C] ()
 csellang.dll -> C:\Windows\System32\csellang.dll -> [2008/08/28 13:28:07 | 000,045,056 | —- | C] ()
 tosmreg.ini -> C:\Windows\System32\tosmreg.ini -> [2008/08/28 13:28:07 | 000,010,150 | —- | C] ()
 cseltbl.ini -> C:\Windows\System32\cseltbl.ini -> [2008/08/28 13:28:07 | 000,007,671 | —- | C] ()
 NDSTray.INI -> C:\Windows\NDSTray.INI -> [2008/02/11 20:10:35 | 000,000,000 | —- | C] ()
 WdfCoInstaller01000.dll -> C:\Windows\System32\WdfCoInstaller01000.dll -> [2008/02/11 19:16:12 | 001,060,424 | —- | C] ()
 igmedkrn.dll -> C:\Windows\System32\igmedkrn.dll -> [2008/02/11 19:05:13 | 001,238,832 | —- | C] ()
 igfxTMM.dll -> C:\Windows\System32\igfxTMM.dll -> [2008/02/11 19:05:13 | 000,249,856 | —- | C] ()
 igfxCoIn_v1329.dll -> C:\Windows\System32\igfxCoIn_v1329.dll -> [2008/02/11 19:05:13 | 000,147,456 | —- | C] ()
 igmedcompkrn.dll -> C:\Windows\System32\igmedcompkrn.dll -> [2008/02/11 19:05:13 | 000,104,636 | —- | C] ()
 SmartFaceVCapt.dll -> C:\Windows\System32\SmartFaceVCapt.dll -> [2008/01/28 18:01:42 | 000,057,344 | —- | C] ()
 SmartFaceVCP.dll -> C:\Windows\System32\SmartFaceVCP.dll -> [2008/01/28 18:01:06 | 000,471,040 | —- | C] ()
 FaceHI.dll -> C:\Windows\System32\FaceHI.dll -> [2008/01/28 17:53:02 | 006,701,056 | —- | C] ()
 FaceRec.dll -> C:\Windows\System32\FaceRec.dll -> [2008/01/28 17:53:02 | 000,995,328 | —- | C] ()
 SmartFaceVCtrl.dll -> C:\Windows\System32\SmartFaceVCtrl.dll -> [2008/01/28 17:53:02 | 000,126,976 | —- | C] ()
 IppLib.dll -> C:\Windows\System32\IppLib.dll -> [2008/01/28 17:52:28 | 000,094,208 | —- | C] ()
 GlobalUserInterface.CompositeFont -> C:\Windows\Fonts\GlobalUserInterface.CompositeFont -> [2006/11/02 08:37:35 | 000,030,808 | —- | C] ()
 GlobalSerif.CompositeFont -> C:\Windows\Fonts\GlobalSerif.CompositeFont -> [2006/11/02 08:37:35 | 000,029,779 | —- | C] ()
 GlobalSansSerif.CompositeFont -> C:\Windows\Fonts\GlobalSansSerif.CompositeFont -> [2006/11/02 08:37:35 | 000,026,489 | —- | C] ()
 GlobalMonospace.CompositeFont -> C:\Windows\Fonts\GlobalMonospace.CompositeFont -> [2006/11/02 08:37:35 | 000,026,040 | —- | C] ()
 sysprepMCE.dll -> C:\Windows\System32\sysprepMCE.dll -> [2006/11/02 08:35:32 | 000,005,632 | —- | C] ()
 pacerprf.ini -> C:\Windows\System32\pacerprf.ini -> [2006/11/02 03:40:29 | 000,013,750 | —- | C] ()
 
[Alternate Data Streams]
@Alternate Data Stream - 22528 bytes -> C:\Windows\System32\autochk.exe:BAK
< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI