This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware gives LOADs to cpu and blocks access to anti-malware sites

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello WhatTheTech team,

First, thank you for giving the efforts to set up this well-thought site to help the infected like me :wacko:
Here is my situation: I notice my laptop is behaving badly in the past 2 days.

(1) A simple routine like watching a dvd-movie has been giving some inconvenience; the movies skipped,
which it never did before. I tested my favorite dvds, and still skipped.

(2) Then I noticed the laptop's clock is late. I could notice the lag of ticking on the 'second' count. Regardless
I update the time, it always is late again. BUT, when the laptop is restarted, it always gives the right time… then
the time slows down.

(3) Very noticeable, at the Task Manager, the cpu works very hard, above 90% most of the time with only Windows
Vista running. Never the cpu is very slow like this before. The funny thing is, if I 'END PROCESS' on the most
consuming cpu item, then a few seconds later another item used up the same amount of cpu. Luckily the items
compared were not critical, so I could end them without having a system problem.

(4) I tried to do a System Restore, but wow, I could not find any Restore Point.

(5) I found 2 csrss.exe running. After googling, many said that one of them is an evil n fake file.

(6) Cannot access microsoft.com, mcafee.com, and other anti-malware sites. I could still google and visit other
sites, and luckily I found WhatTheTech.com and found an article:
http://forums.whatthetech.com/Malware_bloc…st_t106981.html



What had happened 2 days ago was: I played the Conquest with 3 friends using WLAN. A friend installed a codec
to fix the sound problem. I suspect this is the gate of this trouble.

For the last 5 hours, these what have been happening:

(1) Using CNET.com, I get MalwareBytes 1.46 and ran the full scan. Got 14 bugs, most of them are Worm.Conficker.
I will post the result below. Then using Avast! Antivirus, Only 08b7c.tmp is found as a trojan and deleted.

(2) Like once every an hour, C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe is trying to link to
kukutrustnet777.info/?1419543=63225802 but was blocked by the Avast! Antivirus.

(3) I found your website and read CatByte's replies on the above posting, I then ran exeHelper, Win32KDiag, OTL,
and HjackThis. I will post the results.


Any help, inputs, suggestions will be very appreciated :D
Thanks,
Ed
LOG from: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org

Database version: 4624
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943

9/16/2010 1:41:02 AM
mbam-log-2010-09-16 (01-41-02).txt

Scan type: Full scan (C:\|)
Objects scanned: 464382
Time elapsed: 2 hour(s), 44 minute(s), 46 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 14

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\WinRAR\Zip.SFX (Backdoor.Bot) -> No action taken.
C:\Users\User\AppData\Local\Temp\{FCD90D44-3E7D-45ED-944D-C699382B11D0} (P2P.Worm) -> No action taken.
C:\Windows\System32\01093.tmp (Worm.Conficker) -> No action taken.
C:\Windows\System32\03810.tmp (Worm.Conficker) -> No action taken.
C:\Windows\System32\05215.tmp (Worm.Conficker) -> No action taken.
C:\Windows\System32\05A8D.tmp (Worm.Conficker) -> No action taken.
C:\Windows\System32\07290.tmp (Worm.Conficker) -> No action taken.
C:\Windows\System32\0991.tmp (Worm.Conficker) -> No action taken.
C:\Windows\System32\0A5FE.tmp (Worm.Conficker) -> No action taken.
C:\Windows\System32\0C30F.tmp (Worm.Conficker) -> No action taken.
C:\Windows\System32\0CBA7.tmp (Worm.Conficker) -> No action taken.
C:\Windows\System32\0D03B.tmp (Worm.Conficker) -> No action taken.
C:\Windows\System32\0DC1B.tmp (Worm.Conficker) -> No action taken.
C:\Windows\System32\0E5BC.tmp (Worm.Conficker) -> No action taken.

___________
My NOTES: Then all the 14 bugs are deleted. However, I did not notice any difference in
performance. Still I could not access the anti-malware sites, even microsoft.com. But
other sites are normal. And Avast! Antivirus keep alerting me about the a system file try to
connect to kukutrustnet777.info.
LOG from: OTL logfile created on: 9/16/2010 8:46:50 AM - Run 1

OTL by OldTimer - Version 3.2.12.1 Folder = C:\Users\User\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 43.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 63.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.95 Gb Total Space | 55.38 Gb Free Space | 19.23% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 138.25 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 3.77 Gb Total Space | 3.77 Gb Free Space | 99.94% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: USER-PC
Current User Name: User
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe (TOSHIBA)
PRC - C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TECO\TEco.exe (TOSHIBA Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\igfxext.exe (Intel Corporation)
PRC - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Microsoft IntelliType Pro\type32.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\User\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS) – c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (MSSQL$MSSMLBIZ) SQL Server (MSSMLBIZ) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (camsvc) – C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe (TOSHIBA)
SRV - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV - (TMachInfo) – C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (TNaviSrv) – C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV - (ConfigFree Service) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (BcmSqlStartupSvc) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (RSELSVC) – C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe (TOSHIBA Corporation)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (SQLBrowser) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (Adobe Version Cue CS4) – C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe Systems Incorporated)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (Point32) – C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (tosrfec) – C:\Windows\System32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (TosRfSnd) – C:\Windows\System32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (TVALZFL) – C:\Windows\System32\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV - (Tosrfusb) – C:\Windows\System32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (PGEffect) – C:\Windows\System32\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics Incorporated)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (tosrfnds) – C:\Windows\System32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (Tosrfhid) – C:\Windows\System32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (tosrfbnp) – C:\Windows\System32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (mcdbus) – C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (Tosrfcom) – C:\Windows\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (iaStor) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (tos_sps32) – C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (NETw5v32) Intel® – C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (tosrfbd) – C:\Windows\System32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (IntcHdmiAddService) Intel® – C:\Windows\System32\drivers\IntcHdmi.sys (Intel® Corporation)
DRV - (adfs) – C:\Windows\System32\drivers\adfs.sys (Adobe Systems, Inc.)
DRV - (tosporte) – C:\Windows\System32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (UsbDiag) – C:\Windows\System32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\Windows\System32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\Windows\System32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (FwLnk) – C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…S&bmod=TSHS
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…S&bmod=TSHS

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…S&bmod=TSHS
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig?source=gama&hl=en
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?source=gama&hl=en"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/16 08:45:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/20 09:36:13 | 000,000,000 | —D | M]

[2009/11/02 17:13:20 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\mozilla\Extensions
[2010/09/16 07:56:59 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\c9lses9z.default\extensions
[2010/04/28 08:54:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\c9lses9z.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/16 07:56:59 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/14 11:36:23 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/01 22:55:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2009/09/26 23:40:25 | 000,000,794 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SearchSettings Class) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll (Spigot, Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [cfFncEnabler.exe] C:\Program Files\TOSHIBA\ConfigFree\cfFncEnabler.exe (Toshiba Corporation)
O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [NDSTray.exe] C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [type32] C:\Program Files\Microsoft IntelliType Pro\type32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [iowmjosoi] C:\Users\User\AppData\Roaming\hmcencx.DLL File not found
O4 - HKCU..\Run: [TOSCDSPD] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\User\Desktop\ED\Original Image\Tuscan Art 3SMALL.jpg
O24 - Desktop BackupWallPaper: C:\Users\User\Desktop\ED\Original Image\Tuscan Art 3SMALL.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 04:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2006/10/10 01:31:41 | 000,000,079 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{6a1d445c-4ce6-11df-a9bb-001e33c70f70}\Shell - "" = AutoRun
O33 - MountPoints2\{6a1d445c-4ce6-11df-a9bb-001e33c70f70}\Shell\AutoRun\command - "" = E:\setup.exe – [2006/10/10 01:33:58 | 144,845,461 | R— | M] ()
O33 - MountPoints2\{b2844106-2dcf-11df-a77f-001e33c70f70}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe – File not found
O33 - MountPoints2\{b2844106-2dcf-11df-a77f-001e33c70f70}\Shell\open\command - "" = F:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\Windows\System32\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\vio\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.iac2 - C:\Windows\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.mpegacm - C:\Program Files\Common Files\Ulead Systems\MPEG\MPEGACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.siren - C:\Windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.ulmp3acm - C:\Program Files\Common Files\Ulead Systems\MPEG\ulmp3acm.acm (Ulead systems)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\Windows\System32\ir32_32.dll (Intel® Corporation)
Drivers32: vidc.iv32 - C:\Windows\System32\ir32_32.dll (Intel® Corporation)
Drivers32: vidc.iv41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.vp60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.wmv3 - C:\Windows\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.xvid - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/09/16 04:03:47 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\User\Desktop\HiJackThis.exe
[2010/09/16 04:03:17 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2010/09/16 02:54:38 | 000,165,584 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/09/16 02:54:38 | 000,017,744 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/09/16 02:54:37 | 000,046,672 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/09/16 02:54:37 | 000,023,376 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/09/16 02:54:36 | 000,050,768 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/09/16 02:53:55 | 000,167,592 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2010/09/16 02:53:55 | 000,038,848 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2010/09/16 02:53:47 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/09/16 02:53:47 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/09/15 22:18:44 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Malwarebytes
[2010/09/15 22:18:37 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/09/15 22:18:35 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/09/15 22:18:35 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/15 22:18:35 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/09/14 12:02:48 | 000,000,000 | —D | C] – C:\Users\User\Documents\The KMPlayer
[2010/09/14 12:01:01 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010/09/14 12:00:05 | 000,000,000 | —D | C] – C:\Program Files\The KMPlayer
[2010/09/14 11:54:29 | 000,000,000 | —D | C] – C:\Users\User\Desktop\HD Movies
[2010/09/14 08:26:13 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Yahoo!
[2010/09/12 23:20:04 | 000,000,000 | —D | C] – C:\Users\User\Desktop\101MSDCF
[2010/09/12 20:19:36 | 000,737,280 | —- | C] (Indigo Rose Corporation) – C:\Windows\iun6002.exe
[2010/09/11 18:12:40 | 000,038,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2010/09/01 22:55:41 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/09/01 22:55:20 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/09/01 22:55:20 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/09/01 22:55:20 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/08/19 00:29:00 | 000,022,872 | R— | C] (Adobe Systems Inc.) – C:\Windows\System32\AdobePDFUI.dll
[2010/08/18 11:45:34 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/08/18 11:45:33 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/08/18 11:45:32 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/08/18 11:45:32 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/08/18 11:45:32 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/08/18 11:45:32 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/08/18 11:45:32 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/08/18 11:45:31 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/08/18 11:45:31 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/08/18 11:45:30 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/08/18 11:45:30 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/08/18 11:45:30 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/08/18 11:45:30 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/08/18 11:45:30 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/08/18 11:45:27 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/08/18 11:45:20 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtutils.dll
[2010/08/18 11:45:18 | 002,037,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/08/18 11:44:57 | 000,081,920 | —- | C] (Radius Inc.) – C:\Windows\System32\iccvid.dll
[2010/08/18 11:44:17 | 003,600,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2010/08/18 11:44:17 | 003,548,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/16 08:46:02 | 004,718,592 | -HS- | M] () – C:\Users\User\ntuser.dat
[2010/09/16 08:22:01 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/16 07:44:50 | 000,838,884 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/16 07:44:50 | 000,700,964 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/16 07:44:50 | 000,140,320 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/16 07:03:55 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/16 07:03:55 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/16 04:04:04 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\User\Desktop\HiJackThis.exe
[2010/09/16 04:04:03 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2010/09/16 03:51:17 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{BF9B40AA-0200-4418-BD40-CB9BD059C263}.job
[2010/09/16 02:54:38 | 000,001,811 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/09/16 02:54:36 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2010/09/16 02:50:27 | 000,047,616 | —- | M] () – C:\Users\User\Desktop\Win32kDiag.exe
[2010/09/16 02:49:17 | 000,294,400 | —- | M] () – C:\Users\User\Desktop\exeHelper.com
[2010/09/16 02:15:12 | 000,000,878 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/16 02:13:24 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/16 02:13:18 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/16 02:13:15 | 2009,059,328 | -HS- | M] () – C:\hiberfil.sys
[2010/09/16 02:11:51 | 000,524,288 | -HS- | M] () – C:\Users\User\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms
[2010/09/16 02:11:51 | 000,065,536 | -HS- | M] () – C:\Users\User\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf
[2010/09/16 02:11:47 | 004,027,487 | -H– | M] () – C:\Users\User\AppData\Local\IconCache.db
[2010/09/15 22:18:39 | 000,000,789 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/15 01:04:22 | 000,204,548 | —- | M] () – C:\Users\User\Desktop\layout2_Besar.jpg
[2010/09/15 00:58:18 | 000,092,634 | —- | M] () – C:\Users\User\Desktop\layout2b.jpg
[2010/09/15 00:57:52 | 000,120,320 | —- | M] () – C:\Users\User\Desktop\layout2b.fla
[2010/09/14 13:06:23 | 000,000,729 | —- | M] () – C:\Windows\system.ini
[2010/09/14 12:13:02 | 000,002,569 | —- | M] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2007.lnk
[2010/09/14 12:00:14 | 000,000,803 | —- | M] () – C:\Users\User\Desktop\KMPlayer.lnk
[2010/09/12 22:40:17 | 000,036,352 | —- | M] () – C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/12 20:25:28 | 000,000,019 | —- | M] () – C:\Windows\popcinfo.dat
[2010/09/12 20:19:17 | 000,737,280 | —- | M] (Indigo Rose Corporation) – C:\Windows\iun6002.exe
[2010/09/11 19:29:08 | 000,135,920 | —- | M] () – C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/09/11 18:17:33 | 002,379,344 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/09/11 18:13:20 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_point32k_01009.Wdf
[2010/09/11 18:13:16 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010/09/09 23:33:57 | 000,095,232 | —- | M] () – C:\Users\User\Desktop\layout2.fla
[2010/09/09 19:44:38 | 000,086,016 | —- | M] () – C:\Users\User\Desktop\Logo Shiimeji Brown.fla
[2010/09/09 19:43:36 | 000,044,544 | —- | M] () – C:\Users\User\Desktop\Logo Kuping with Bowl.fla
[2010/09/09 19:42:10 | 000,084,992 | —- | M] () – C:\Users\User\Desktop\Logo Kuping.fla
[2010/09/09 19:35:37 | 000,084,480 | —- | M] () – C:\Users\User\Desktop\Logo Shiimeji White.fla
[2010/09/07 22:12:17 | 000,038,848 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2010/09/07 22:11:54 | 000,167,592 | —- | M] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2010/09/07 21:52:25 | 000,046,672 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/09/07 21:52:03 | 000,165,584 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/09/07 21:47:46 | 000,023,376 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/09/07 21:47:30 | 000,050,768 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/09/07 21:47:07 | 000,017,744 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/09/03 19:18:33 | 000,002,611 | —- | M] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk
[2010/08/31 00:21:40 | 000,076,857 | —- | M] () – C:\Users\User\Desktop\lantai2.jpg
[2010/08/30 22:39:29 | 000,069,120 | —- | M] () – C:\Users\User\Desktop\layout.fla
[2010/08/30 22:38:49 | 000,087,838 | —- | M] () – C:\Users\User\Desktop\layout.jpg
[2010/08/30 22:30:48 | 000,059,392 | —- | M] () – C:\Users\User\Desktop\storage bibit.fla
[2010/08/30 17:30:30 | 000,032,768 | —- | M] () – C:\Users\User\Desktop\map2.fla
[2010/08/30 10:28:31 | 000,001,356 | —- | M] () – C:\Users\User\AppData\Local\d3d9caps.dat
[2010/08/26 23:38:50 | 000,182,272 | —- | M] () – C:\Users\User\Desktop\EdMap.fla
[2010/08/26 10:39:08 | 000,023,256 | —- | M] () – C:\Users\User\Desktop\mapEdward.jpg
[2010/08/23 20:35:13 | 000,103,424 | —- | M] () – C:\Users\User\Desktop\Logo.fla
[2010/08/18 11:53:06 | 000,000,118 | —- | M] () – C:\Windows\System32\MRT.INI
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/16 02:54:38 | 000,001,811 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/09/16 02:50:25 | 000,047,616 | —- | C] () – C:\Users\User\Desktop\Win32kDiag.exe
[2010/09/16 02:49:17 | 000,294,400 | —- | C] () – C:\Users\User\Desktop\exeHelper.com
[2010/09/15 22:18:39 | 000,000,789 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/15 01:04:22 | 000,204,548 | —- | C] () – C:\Users\User\Desktop\layout2_Besar.jpg
[2010/09/15 00:58:16 | 000,092,634 | —- | C] () – C:\Users\User\Desktop\layout2b.jpg
[2010/09/14 12:00:14 | 000,000,803 | —- | C] () – C:\Users\User\Desktop\KMPlayer.lnk
[2010/09/12 20:25:28 | 000,000,019 | —- | C] () – C:\Windows\popcinfo.dat
[2010/09/11 18:13:20 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_point32k_01009.Wdf
[2010/09/11 18:13:16 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010/09/11 18:12:41 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
[2010/09/09 23:34:03 | 000,120,320 | —- | C] () – C:\Users\User\Desktop\layout2b.fla
[2010/09/09 19:43:35 | 000,044,544 | —- | C] () – C:\Users\User\Desktop\Logo Kuping with Bowl.fla
[2010/09/09 19:36:22 | 000,084,992 | —- | C] () – C:\Users\User\Desktop\Logo Kuping.fla
[2010/09/09 18:40:35 | 000,086,016 | —- | C] () – C:\Users\User\Desktop\Logo Shiimeji Brown.fla
[2010/09/09 18:38:40 | 000,084,480 | —- | C] () – C:\Users\User\Desktop\Logo Shiimeji White.fla
[2010/08/31 00:19:29 | 000,076,857 | —- | C] () – C:\Users\User\Desktop\lantai2.jpg
[2010/08/30 22:39:37 | 000,095,232 | —- | C] () – C:\Users\User\Desktop\layout2.fla
[2010/08/30 22:34:59 | 000,087,838 | —- | C] () – C:\Users\User\Desktop\layout.jpg
[2010/08/30 20:07:54 | 000,059,392 | —- | C] () – C:\Users\User\Desktop\storage bibit.fla
[2010/08/30 20:07:34 | 000,069,120 | —- | C] () – C:\Users\User\Desktop\layout.fla
[2010/08/30 17:30:30 | 000,032,768 | —- | C] () – C:\Users\User\Desktop\map2.fla
[2010/08/26 23:38:49 | 000,182,272 | —- | C] () – C:\Users\User\Desktop\EdMap.fla
[2010/08/26 10:38:03 | 000,023,256 | —- | C] () – C:\Users\User\Desktop\mapEdward.jpg
[2010/08/26 09:48:09 | 000,000,331 | —- | C] () – C:\ProgramData\hpzinstall.log
[2010/08/23 14:29:45 | 000,103,424 | —- | C] () – C:\Users\User\Desktop\Logo.fla
[2010/07/15 18:50:58 | 000,000,118 | —- | C] () – C:\Windows\System32\MRT.INI
[2010/06/16 17:03:49 | 000,000,657 | —- | C] () – C:\Windows\wininit.ini
[2010/04/21 13:46:52 | 000,691,696 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2010/01/19 12:05:29 | 000,004,096 | -H– | C] () – C:\Users\User\AppData\Local\keyfile3.drm
[2009/12/11 04:49:54 | 000,000,576 | —- | C] () – C:\ProgramData\afl.log
[2009/12/03 09:27:28 | 000,080,416 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/11/06 23:52:48 | 000,010,240 | —- | C] () – C:\Windows\System32\vidx16.dll
[2009/11/06 23:32:19 | 000,056,832 | —- | C] () – C:\Windows\System32\Iyvu9_32.dll
[2009/10/05 10:30:30 | 000,004,522 | —- | C] () – C:\Users\User\AppData\Roaming\ReplayConverterLog.log
[2009/10/02 12:42:52 | 000,002,554 | —- | C] () – C:\Windows\WAVEMIX.INI
[2009/09/16 22:38:15 | 000,001,356 | —- | C] () – C:\Users\User\AppData\Local\d3d9caps.dat
[2009/09/13 11:27:49 | 000,036,352 | —- | C] () – C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/28 02:04:44 | 000,557,003 | —- | C] () – C:\Windows\System32\libmplayer.dll
[2009/08/28 02:04:32 | 000,811,835 | —- | C] () – C:\Windows\System32\ff_x264.dll
[2009/08/28 02:03:52 | 004,456,201 | —- | C] () – C:\Windows\System32\libavcodec.dll
[2009/08/26 01:07:36 | 000,328,334 | —- | C] () – C:\Windows\System32\ff_kernelDeint.dll
[2009/08/26 00:38:04 | 000,425,040 | —- | C] () – C:\Windows\System32\TomsMoComp_ff.dll
[2009/08/25 23:56:56 | 000,829,781 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2009/08/25 23:37:02 | 000,146,098 | —- | C] () – C:\Windows\System32\libmpeg2_ff.dll
[2009/08/24 12:22:46 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/08/21 19:18:27 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/06/18 02:34:22 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2009/06/18 01:49:41 | 000,209,040 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2009/06/18 01:49:41 | 000,204,944 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2009/06/18 01:49:41 | 000,196,752 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2009/06/18 01:49:41 | 000,196,752 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2009/06/18 01:49:41 | 000,192,656 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2009/06/18 01:49:41 | 000,024,720 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2009/06/03 00:15:44 | 000,113,152 | —- | C] () – C:\Windows\System32\ff_unrar.dll
[2009/06/03 00:15:18 | 000,146,944 | —- | C] () – C:\Windows\System32\ff_tremor.dll
[2009/06/03 00:15:04 | 000,183,296 | —- | C] () – C:\Windows\System32\ff_samplerate.dll
[2009/06/03 00:14:56 | 000,178,688 | —- | C] () – C:\Windows\System32\ff_libmad.dll
[2009/06/03 00:14:30 | 000,486,400 | —- | C] () – C:\Windows\System32\ff_libfaad2.dll
[2009/06/03 00:13:58 | 000,257,024 | —- | C] () – C:\Windows\System32\ff_libdts.dll
[2009/06/03 00:13:50 | 000,142,848 | —- | C] () – C:\Windows\System32\ff_liba52.dll
[2009/06/03 00:11:26 | 000,098,304 | —- | C] () – C:\Windows\System32\ff_wmv9.dll
[2009/06/03 00:11:16 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2009/03/04 02:17:44 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1670.dll
[2009/01/11 05:17:32 | 000,163,840 | —- | C] () – C:\Windows\System32\ts.dll
[2009/01/11 05:16:56 | 000,148,480 | —- | C] () – C:\Windows\System32\mkx.dll
[2009/01/11 05:16:50 | 000,108,032 | —- | C] () – C:\Windows\System32\avi.dll
[2009/01/11 05:16:14 | 000,141,312 | —- | C] () – C:\Windows\System32\mp4.dll
[2009/01/11 05:15:54 | 000,120,832 | —- | C] () – C:\Windows\System32\ogm.dll
[2009/01/11 05:15:44 | 000,159,744 | —- | C] () – C:\Windows\System32\mmfinfo.dll
[2009/01/11 05:15:32 | 000,102,400 | —- | C] () – C:\Windows\System32\avss.dll
[2009/01/11 05:15:28 | 000,246,784 | —- | C] () – C:\Windows\System32\dxr.dll
[2009/01/11 05:15:12 | 000,097,280 | —- | C] () – C:\Windows\System32\avs.dll
[2009/01/11 05:14:08 | 000,079,360 | —- | C] () – C:\Windows\System32\mkzlib.dll
[2009/01/11 05:14:06 | 000,023,552 | —- | C] () – C:\Windows\System32\mkunicode.dll
[2008/12/04 05:11:50 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/11/06 23:37:32 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/11/06 23:34:00 | 000,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/09/22 20:49:24 | 000,004,608 | —- | C] () – C:\Windows\System32\HdmiCoin.dll
[2007/10/13 16:30:20 | 000,000,137 | —- | C] () – C:\Windows\System32\Registration.ini
[2007/07/11 00:10:12 | 000,000,547 | —- | C] () – C:\Windows\System32\ff_vfw.dll.manifest
[2006/11/02 14:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2003/05/10 05:36:30 | 000,151,744 | —- | C] () – C:\Windows\System32\ir32.dll

========== LOP Check ==========

[2010/04/21 14:44:49 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\DAEMON Tools Lite
[2009/09/11 22:48:24 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\GlobalSCAPE
[2009/12/12 05:35:49 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\GSC 2.00
[2010/06/04 23:36:50 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\TOSHIBA
[2010/06/22 19:31:58 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Tropico 3
[2009/10/10 19:08:13 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Ulead Systems
[2010/09/16 02:12:06 | 000,032,546 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/09/16 03:51:17 | 000,000,420 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{BF9B40AA-0200-4418-BD40-CB9BD059C263}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/19 04:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 13:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/04/23 01:41:33 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/19 04:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/09/16 02:13:15 | 2009,059,328 | -HS- | M] () – C:\hiberfil.sys
[2009/10/04 10:11:35 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/06/18 01:42:15 | 000,000,516 | -H– | M] () – C:\log.txt
[2009/10/04 10:11:35 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/09/16 02:13:14 | 2322,845,696 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 19:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 19:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 19:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/08/21 20:09:11 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/19 04:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 16:46:03 | 000,070,144 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNBPP3.DLL
[2006/11/05 20:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNMPD8O.DLL
[2006/11/05 20:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\Windows\System32\spool\prtprocs\w32x86\CNMPP8O.DLL
[2008/01/21 09:32:37 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/09/07 22:12:17 | 000,038,848 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/21 09:57:01 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/21 10:31:11 | 015,716,352 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 10:31:01 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 10:31:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 17:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 17:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2008/12/18 01:07:02 | 000,004,096 | -HS- | M] () – C:\Windows\System32\Thumbs.db

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/08/23 23:24:49 | 000,000,472 | -HS- | M] () – C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/09/16 04:04:04 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\User\Desktop\HiJackThis.exe
[2010/09/16 04:04:03 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2010/09/16 02:50:27 | 000,047,616 | —- | M] () – C:\Users\User\Desktop\Win32kDiag.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-04 15:31:17
< End of report >
LOG from: Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 9:03:09 AM, on 9/16/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\TECO\TEco.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\User\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
O1 - Hosts: ::1 localhost
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [cfFncEnabler.exe] "C:\Program Files\TOSHIBA\ConfigFree\cfFncEnabler.exe"
O4 - HKLM\..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [iowmjosoi] rundll32.exe "C:\Users\User\AppData\Roaming\hmcencx.dll",bpbudske
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: TOSHIBA Web Camera Service (camsvc) - TOSHIBA - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: TOSHIBA Modem region select service (RSELSVC) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe

–
End of file - 11868 bytes
LOG from: OTL Extras logfile created on: 9/16/2010 8:46:50 AM - Run 1

OTL by OldTimer - Version 3.2.12.1 Folder = C:\Users\User\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 43.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 63.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.95 Gb Total Space | 55.38 Gb Free Space | 19.23% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 138.25 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 3.77 Gb Total Space | 3.77 Gb Free Space | 99.94% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: USER-PC
Current User Name: User
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2650233981-2903192531-2482617129-1004]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04C4D87A-4D94-4A33-96DA-9BFC5CD6F4C6}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{05C0CC48-9343-450A-B46B-FBCBB19BF37C}" = rport=138 | protocol=17 | dir=out | app=system |
"{05DB24B7-25D5-4EEB-9C75-3140D75731FD}" = lport=51001 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{0EB8CEA5-ECC0-4E25-B683-ED880E98B6B8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{0EE5231B-DB54-4478-85C1-98D1C5B416C9}" = lport=137 | protocol=17 | dir=in | app=system |
"{10B7DD60-0B80-47A5-B292-4A95B30FC6D0}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{1CB96B42-21A4-4AC3-8225-C3BB1262E0DC}" = rport=139 | protocol=6 | dir=out | app=system |
"{20E77C05-8BDF-40A3-ACC9-7E0558FA3AF4}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{21F9AEF3-3D7C-409A-91E7-14FE7ECD13E5}" = rport=137 | protocol=17 | dir=out | app=system |
"{299B4642-2ADF-4B8F-ABD9-4F9420CDA4F3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{37707DA8-EDF1-41C4-9834-BF6AE0FF529A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{38F28986-7D34-4462-B860-C429806F4561}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{40267123-42FF-47E1-BB3C-640566F90EAE}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{48AC50AD-134E-4994-8046-3D7175CE4AF3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{4A56DDF9-B258-4119-AED9-7BE8FF4B646D}" = rport=10243 | protocol=6 | dir=out | app=system |
"{4C6E4B26-1769-4197-9B9B-4D2B1D3B8E20}" = lport=rpc | protocol=6 | dir=in | svc=policyagent | app=c:\windows\system32\svchost.exe |
"{55058C9B-BDE8-445B-9DD1-F8E4F64263DD}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{5601A5D9-BFFA-4379-B82C-53016C5AA8E6}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{613A40E1-E476-4243-B263-8DC159F84424}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6B1000B0-6CC0-4C05-B582-FC217F2DF5FE}" = rport=445 | protocol=6 | dir=out | app=system |
"{72C008F3-76CF-4519-A810-470608340360}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{760FAACE-980D-499C-892C-8728A911B450}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{7FD6E9F6-7436-42BA-9265-442F818636E6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{894879B9-995A-46F6-91E5-4C05CE1F9B55}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{894DB9CC-07D1-4431-8177-40DA54A6E852}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{8CF2BCE5-16C6-4D49-AB5A-7CEF62EFF586}" = lport=445 | protocol=6 | dir=in | app=system |
"{9404F8D4-4C29-43B8-965A-E973659CAC19}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9439233E-9293-4FAC-AA51-F85D64A5D479}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{97C77201-9303-49DB-A1CF-2919C5BB49B7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{9C9AAEB9-A50E-42CF-9546-5F8762A72563}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{A4C7C77A-D833-4272-BE01-DDBAA3B34A65}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=c:\windows\system32\svchost.exe |
"{B17AFBF3-E744-49B9-BA88-0D2E8E63526A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B5834DBD-B982-482F-A3B3-B306D634D451}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BA770C0D-90C4-4374-BDA3-D7D0209DD41A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{BDBF9FA2-9DFC-46F9-8802-DE63AF4E549F}" = lport=135 | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{BEC1ABD1-944A-4C64-959E-951B43AB94C3}" = lport=51000 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{C12A69CF-EDD0-440A-9DD9-C024ABFE6A71}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{C311BCC4-7791-4B9C-B9FF-97476A5EE7F2}" = rport=2869 | protocol=6 | dir=out | app=system |
"{C3314633-6C8D-454C-9E7F-3DA4EA1AE0A9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |
"{C56E1AFA-462E-4C78-AB31-E126553981A2}" = lport=138 | protocol=17 | dir=in | app=system |
"{D400D66B-09A2-4F57-A703-C14D3EAB8D8A}" = lport=10243 | protocol=6 | dir=in | app=system |
"{D5621FFD-9A63-4527-862B-4BC6D70E144F}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DD6AA10E-6E15-4CF7-9A80-DEF024CAAA66}" = lport=139 | protocol=6 | dir=in | app=system |
"{DF5CFD26-4F22-4FF6-B3F1-BE22AEE635D0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{EAF2D177-2A0E-4290-B459-E873297479A9}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{EE8AAE7D-4C50-499A-8497-98E6EA9941AD}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=c:\windows\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0BC0C34C-F62B-4E55-89CE-5D1DD960D46D}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{102997B2-053C-4E5F-9EBE-C2CE06A69E79}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{119C0B34-605D-4ECF-A509-D63ABEB56FCC}" = protocol=6 | dir=in | app=c:\program files\ea games\battlefield 1942\bf1942.exe |
"{1254DDD1-522D-4CC2-83F2-B94D8E5B28FD}" = protocol=17 | dir=in | app=c:\program files\ea games\battlefield 1942\bf1942.exe |
"{26EC160B-4D8A-4674-8A01-22EC90BCF718}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{3954E074-2F84-47CE-BD01-6582CC5A7510}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{3D3A75D2-E498-4B09-8285-9E943852AF7D}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{3FE5BB79-785B-43F4-B238-C0E81DC74F8C}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{4DBB53F1-E2AF-4B01-A7E4-D12DBA79224C}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{551A4705-22FF-4205-B0BB-D607510C8119}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe |
"{55271077-4EFF-481B-8D68-66B2C1931C76}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe |
"{557103AA-44C7-4CCF-A018-20B0C9B74BA0}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{59306AD8-A1F9-48D3-BE52-455FBC8714E2}" = protocol=6 | dir=in | app=c:\program files\windows media player\wmpnetwk.exe |
"{5A04BB9F-7565-44C4-8ABC-0C2509F02EFA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{5B9CFB99-AEBC-4AC6-B2B4-B02155080E52}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{5CF41482-C4A0-40F5-9CF3-4A0DEFE59073}" = protocol=6 | dir=in | app=c:\windows\system32\plasrv.exe |
"{5EB0E688-BC0E-4EF8-9CC7-A732F7A5EABA}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{6085711A-5F53-413E-BEF4-46EAAA51C997}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{7151968A-3147-4012-BDDF-6F40DD196AEC}" = protocol=17 | dir=in | app=c:\program files\magitech corporation\takeda 3\k4.exe |
"{726FF822-4B87-4AD4-9BE2-432E74D164E1}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{8401D361-094D-47B3-A6C0-0B40AB2C80DD}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{957E0831-1041-4C33-989B-894ECB2F2EED}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{9AFC17F3-4ED5-49D6-AC12-B37CB60BE576}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{A09D2960-8DF9-484A-895C-C9487B490ACF}" = protocol=6 | dir=in | app=c:\program files\magitech corporation\takeda 3\k4.exe |
"{AADDD069-A166-46F0-B5C5-A1D3EA060A43}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{ADC7B685-6CF3-43F0-99D8-1924B7282949}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{B107756D-1C69-49F7-A349-0C7ECADC506D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B6BBD706-4C4E-424B-9B72-03D6C9145B4E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{BE3CED09-DB09-4D78-96E9-DC3645DCC42B}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{C8AAF7D4-7379-4A76-BFDF-8817D8212CF5}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{C968B171-214D-4C57-AB0A-4A290C642ABA}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{CE746725-75EF-431A-9AA0-6F2DC9AC452C}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{D1360945-414B-4F64-9F1B-A69AD1AE6D96}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{D24DDD6B-C3F7-4C95-9F58-970DC8C6F5A6}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D466D7DF-218F-443A-A166-4A43CA075406}" = protocol=6 | dir=out | app=system |
"{D58E830A-3484-4A40-ABD8-7DBE74CD91F1}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{DC3E8D58-D247-45DB-9AC2-EF7922A01348}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmpnetwk.exe |
"{F167BF91-E689-4647-90CB-889EF5BEF6E7}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{F2F6CC30-A88A-4CF1-A29F-C3BD23AC19BE}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{FE7C7831-B1E2-441F-8DEA-7E988789B775}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"TCP Query User{0279F611-955D-4DDC-97C7-34A021518FDA}C:\program files\toshiba\configfree\cfswmgr.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\configfree\cfswmgr.exe |
"TCP Query User{036250BF-C733-4371-98C9-6E0253078C21}C:\program files\toshiba\configfree\ndstray.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\configfree\ndstray.exe |
"TCP Query User{04FA565F-34B4-4BE4-AB70-0606D8150C78}C:\program files\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"TCP Query User{0538C77F-D561-4753-B1DF-71A59BCDB32E}C:\program files\microsoft office\office12\groovemonitor.exe" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groovemonitor.exe |
"TCP Query User{056B788A-5427-4012-9D06-7E8E03648A49}C:\program files\ubisoft\the settlers 7 - paths to a kingdom\data\base\_dbg\bin\release\settlers7r.exe" = protocol=6 | dir=in | app=c:\program files\ubisoft\the settlers 7 - paths to a kingdom\data\base\_dbg\bin\release\settlers7r.exe |
"TCP Query User{057E8A94-606D-4118-BFAF-B6C4C4C3E072}C:\windows\system32\mobsync.exe" = protocol=6 | dir=in | app=c:\windows\system32\mobsync.exe |
"TCP Query User{06005599-EF86-43F7-BD3F-77AA82FF0A22}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{0B421284-94D8-4317-9CD1-4AE388991241}C:\windows\system32\macromed\flash\flashutil10d.exe" = protocol=6 | dir=in | app=c:\windows\system32\macromed\flash\flashutil10d.exe |
"TCP Query User{1230A95E-45DA-42F9-9412-8D3E2B9D5846}C:\windows\system32\notepad.exe" = protocol=6 | dir=in | app=c:\windows\system32\notepad.exe |
"TCP Query User{12AABBCD-61DA-47DB-A258-589B453251C4}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{13F6C551-A255-4BA7-87CB-1DDBF6EA6041}C:\program files\toshiba\power saver\tpwrmain.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\power saver\tpwrmain.exe |
"TCP Query User{14D638A9-DA99-4413-B2EE-A1D7374841CC}C:\program files\microsoft office\office12\winword.exe" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\winword.exe |
"TCP Query User{16966B11-BA2A-4C37-B386-B9EA5670B4A1}C:\program files\adobe\acrobat 9.0\acrobat\acrobat_sl.exe" = protocol=6 | dir=in | app=c:\program files\adobe\acrobat 9.0\acrobat\acrobat_sl.exe |
"TCP Query User{1C3800EB-E024-4638-8A30-468E1E8D78D4}C:\program files\toshiba\bluetooth toshiba stack\tosbthsp.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosbthsp.exe |
"TCP Query User{1C9F3C9D-8F73-472F-93C7-2D1A8F65398E}C:\program files\toshiba\bluetooth toshiba stack\tosbthid.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosbthid.exe |
"TCP Query User{1D5EDEB1-DA99-44E1-AD16-518A5BDF5DD2}C:\program files\toshiba\toscdspd\toscdspd.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\toscdspd\toscdspd.exe |
"TCP Query User{1F2CA9B5-DE3D-4884-9CBF-B24AE53B964D}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe |
"TCP Query User{1FE1AE51-FBB4-46ED-B278-4ACB9CC5009F}C:\program files\realtek\audio\hda\rthdvcpl.exe" = protocol=6 | dir=in | app=c:\program files\realtek\audio\hda\rthdvcpl.exe |
"TCP Query User{206D8ED0-1CF8-472F-903C-6BCE77DE2150}C:\windows\system32\wuauclt.exe" = protocol=6 | dir=in | app=c:\windows\system32\wuauclt.exe |
"TCP Query User{29E33413-75F8-4212-BF53-5CADAA7B03A7}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{2B1937D3-5B27-48F1-A2FB-D606280F2D32}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{2E320E24-1305-4FC1-AF7E-56BBE0DBB1FA}C:\program files\microsoft intellitype pro\type32.exe" = protocol=6 | dir=in | app=c:\program files\microsoft intellitype pro\type32.exe |
"TCP Query User{304B04DD-F89E-481C-86DB-46E3A4D8BB7E}C:\program files\yahoo!\messenger\ymsgr_tray.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\ymsgr_tray.exe |
"TCP Query User{32CAB4D9-5C3A-4D82-A946-AC279FA3CD73}C:\windows\system32\gphotos.scr" = protocol=6 | dir=in | app=c:\windows\system32\gphotos.scr |
"TCP Query User{37FC7BA3-A642-4378-823F-C76837F44208}C:\windows\system32\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"TCP Query User{388E8B39-72C3-437B-8799-C4FF1C7015FA}C:\program files\toshiba\teco\teco.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\teco\teco.exe |
"TCP Query User{38CA0095-79F9-4BB7-AB16-272DEBACC4C6}C:\program files\toshiba\bluetooth toshiba stack\tosbthid.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosbthid.exe |
"TCP Query User{416B553E-12A6-44CD-A9A3-338B1EB7CA27}C:\program files\windows media player\wmpnscfg.exe" = protocol=6 | dir=in | app=c:\program files\windows media player\wmpnscfg.exe |
"TCP Query User{41D22C78-6DDC-433B-AD7F-5EA0C619AD37}C:\program files\toshiba\bluetooth toshiba stack\tosbtmng.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosbtmng.exe |
"TCP Query User{45B404CA-13E8-4ADF-A4A2-B01A7362EFD1}C:\windows\system32\dwm.exe" = protocol=6 | dir=in | app=c:\windows\system32\dwm.exe |
"TCP Query User{4A8A00AB-0BF4-4983-BC9C-0C018D3D5DE7}C:\program files\adobe\reader 9.0\reader\reader_sl.exe" = protocol=6 | dir=in | app=c:\program files\adobe\reader 9.0\reader\reader_sl.exe |
"TCP Query User{4F1B6D1B-6CE0-46DA-A590-CB572829797A}C:\program files\dosbox-0.73\dosbox.exe" = protocol=6 | dir=in | app=c:\program files\dosbox-0.73\dosbox.exe |
"TCP Query User{5048E270-1CB0-4011-96B4-718D9BF77ADB}C:\program files\toshiba\toshiba hdd ssd alert\tossenotify.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\toshiba hdd ssd alert\tossenotify.exe |
"TCP Query User{527D5B9D-F00E-409B-82C2-210C10FE85CF}C:\windows\system32\msfeedssync.exe" = protocol=6 | dir=in | app=c:\windows\system32\msfeedssync.exe |
"TCP Query User{5B3BD6F9-E187-4DD3-99AA-1A3690E221D5}C:\program files\adobe\acrobat 9.0\acrobat\acrobat_sl.exe" = protocol=6 | dir=in | app=c:\program files\adobe\acrobat 9.0\acrobat\acrobat_sl.exe |
"TCP Query User{5B63043D-C4C5-4E29-8284-00DD9EAD3381}C:\program files\valusoft\prison tycoon 3\data\prisontycoon3.exe" = protocol=6 | dir=in | app=c:\program files\valusoft\prison tycoon 3\data\prisontycoon3.exe |
"TCP Query User{61930430-0154-439A-B237-8C03536B9D05}C:\windows\system32\dwm.exe" = protocol=6 | dir=in | app=c:\windows\system32\dwm.exe |
"TCP Query User{61B1B731-AE10-414F-909F-8CB4F0BD5A85}C:\windows\system32\userinit.exe" = protocol=6 | dir=in | app=c:\windows\system32\userinit.exe |
"TCP Query User{63467AE6-5C71-423B-92C7-A590372CD197}C:\windows\system32\igfxsrvc.exe" = protocol=6 | dir=in | app=c:\windows\system32\igfxsrvc.exe |
"TCP Query User{6888EDC3-A00C-40A9-B6AF-1CDD19AFA87B}C:\program files\toshiba\configfree\cffncenabler.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\configfree\cffncenabler.exe |
"TCP Query User{6F63404F-470D-4547-B12B-9E72AD0AD7F9}C:\program files\windows defender\msascui.exe" = protocol=6 | dir=in | app=c:\program files\windows defender\msascui.exe |
"TCP Query User{7254340C-0BBD-4E1B-AC6C-BFE391938466}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{73723ED2-51B2-4B79-9AE3-374DA333165D}C:\program files\toshiba\bluetooth toshiba stack\tosbtmng.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosbtmng.exe |
"TCP Query User{7451763D-B593-47DE-A7FF-2837E390E245}C:\program files\toshiba\bluetooth toshiba stack\tosavrc.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosavrc.exe |
"TCP Query User{7588DC36-3DF4-4C98-BD0A-5A68C1EBAD27}C:\program files\ea games\battlefield 1942\bf1942.exe" = protocol=6 | dir=in | app=c:\program files\ea games\battlefield 1942\bf1942.exe |
"TCP Query User{775D132D-774D-4BCD-8C8A-B180528B0D9D}C:\program files\toshiba\flashcards\tcrdmain.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\flashcards\tcrdmain.exe |
"TCP Query User{8033ADBB-8A02-4824-AD08-7236CA52C98D}C:\program files\windows defender\msascui.exe" = protocol=6 | dir=in | app=c:\program files\windows defender\msascui.exe |
"TCP Query User{8566E779-480D-4D63-92C0-4372916E7B8F}C:\program files\common files\real\update_ob\realsched.exe" = protocol=6 | dir=in | app=c:\program files\common files\real\update_ob\realsched.exe |
"TCP Query User{876692A8-EFA7-46B5-9D38-3DF1041FF7D2}C:\windows\system32\igfxtray.exe" = protocol=6 | dir=in | app=c:\windows\system32\igfxtray.exe |
"TCP Query User{88234ACB-3CD3-4A8E-9D68-2964F29E849C}C:\program files\yahoo!\messenger\ymsgr_tray.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\ymsgr_tray.exe |
"TCP Query User{8C47F284-7696-4E71-8E44-ADF71659D7DE}C:\program files\microsoft games\freecell\freecell.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\freecell\freecell.exe |
"TCP Query User{8F0D95EC-9A4D-4150-B8B0-2C7A5ACAC7CA}C:\program files\microsoft games\freecell\freecell.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\freecell\freecell.exe |
"TCP Query User{93AEAB52-7874-4890-B52D-E15CFFF47575}C:\program files\toshiba\toscdspd\toscdspd.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\toscdspd\toscdspd.exe |
"TCP Query User{954B9BAB-E2C0-45A4-94B2-C836E16EE165}F:\recycler\s-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe" = protocol=6 | dir=in | app=f:\recycler\s-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe |
"TCP Query User{96E9652F-4BDB-4D4B-8B1E-26B159CEE89A}C:\windows\system32\searchprotocolhost.exe" = protocol=6 | dir=in | app=c:\windows\system32\searchprotocolhost.exe |
"TCP Query User{99813C1D-4BC2-4C3E-98C2-EACBA343068B}C:\program files\adobe\acrobat 9.0\acrobat\acrodist.exe" = protocol=6 | dir=in | app=c:\program files\adobe\acrobat 9.0\acrobat\acrodist.exe |
"TCP Query User{9ACE0EE7-1C99-44B3-8E3F-75BDA0251E35}C:\windows\system32\igfxext.exe" = protocol=6 | dir=in | app=c:\windows\system32\igfxext.exe |
"TCP Query User{9BEFE402-4F53-48F1-9A68-489A0F41BEB0}C:\program files\synaptics\syntp\syntpenh.exe" = protocol=6 | dir=in | app=c:\program files\synaptics\syntp\syntpenh.exe |
"TCP Query User{9CDD999A-B86A-4C6D-B6D4-9BA908737538}C:\program files\microsoft office\office12\excel.exe" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\excel.exe |
"TCP Query User{9DB3464A-E9B0-46A5-9FBC-DA343AD81955}C:\windows\system32\hkcmd.exe" = protocol=6 | dir=in | app=c:\windows\system32\hkcmd.exe |
"TCP Query User{A01375F9-6588-4671-95EB-C3FF9359CC0C}C:\program files\adobe media player\adobe media player.exe" = protocol=6 | dir=in | app=c:\program files\adobe media player\adobe media player.exe |
"TCP Query User{A0B4E58C-3114-4057-9348-718E71361C2D}C:\program files\toshiba\power saver\tpwrmain.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\power saver\tpwrmain.exe |
"TCP Query User{A5ED5882-9735-4E73-AC5A-CCDF944ACEBB}C:\windows\system32\igfxpers.exe" = protocol=6 | dir=in | app=c:\windows\system32\igfxpers.exe |
"TCP Query User{AA6CF83F-FE48-4BC6-8CB1-373838C9234E}C:\program files\toshiba\toshiba hdd ssd alert\tossenotify.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\toshiba hdd ssd alert\tossenotify.exe |
"TCP Query User{AA6E8806-6612-4C3B-A03E-E7E32D36A2F9}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{AAC3FF67-63CC-4988-A8D8-5687B20B31EA}C:\windows\system32\igfxsrvc.exe" = protocol=6 | dir=in | app=c:\windows\system32\igfxsrvc.exe |
"TCP Query User{AF7A071E-7200-4B24-B50E-F7B3C151094F}C:\program files\common files\real\update_ob\realsched.exe" = protocol=6 | dir=in | app=c:\program files\common files\real\update_ob\realsched.exe |
"TCP Query User{B446629A-C72B-4C9D-AB6E-2E3B958F5602}C:\program files\windows mail\winmail.exe" = protocol=6 | dir=in | app=c:\program files\windows mail\winmail.exe |
"TCP Query User{B793DCA5-A016-42CD-9C70-D7B85C755D71}C:\program files\magicdisc\magicdisc.exe" = protocol=6 | dir=in | app=c:\program files\magicdisc\magicdisc.exe |
"TCP Query User{B84ABAC8-6FB8-43B2-9BA0-17410B7C7D7D}C:\program files\toshiba\configfree\cfswmgr.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\configfree\cfswmgr.exe |
"TCP Query User{B9226E34-8EBA-4387-B9F1-C9D7AF94CFAD}C:\windows\system32\wuauclt.exe" = protocol=6 | dir=in | app=c:\windows\system32\wuauclt.exe |
"TCP Query User{B9FF002B-10AD-413B-9DE1-006DBB82788A}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{BA926C5D-62D1-4A8C-AC39-625B1298F382}C:\program files\ubi soft games\conquest frontier wars\conquest.exe" = protocol=6 | dir=in | app=c:\program files\ubi soft games\conquest frontier wars\conquest.exe |
"TCP Query User{BCAF8114-F9B5-4B83-AB76-D634DC1DFFC4}C:\program files\adobe\acrobat 9.0\acrobat\acrodist.exe" = protocol=6 | dir=in | app=c:\program files\adobe\acrobat 9.0\acrobat\acrodist.exe |
"TCP Query User{C036036A-84D5-485E-9A1B-4D75718E7B92}C:\program files\toshiba\teco\teco.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\teco\teco.exe |
"TCP Query User{C2977E85-2A4D-4712-8204-E6D7D6726D4E}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{C339AA42-8BFA-4E38-9DB3-3CB8D82D4579}C:\program files\toshiba\bluetooth toshiba stack\itsecmng.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\itsecmng.exe |
"TCP Query User{C5194405-1300-4FB7-BC21-8794A6464728}C:\windows\system32\igfxpers.exe" = protocol=6 | dir=in | app=c:\windows\system32\igfxpers.exe |
"TCP Query User{C59F73A9-9A8A-46DD-BE87-406B20F7A607}C:\program files\search settings\searchsettings.exe" = protocol=6 | dir=in | app=c:\program files\search settings\searchsettings.exe |
"TCP Query User{C602A5F9-EAD6-4CCA-A5AB-B6FCAE2B8943}C:\program files\toshiba\flashcards\tcrdmain.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\flashcards\tcrdmain.exe |
"TCP Query User{C866FB56-AE85-4E86-BDBB-AB97ABD2E13E}C:\program files\adobe\acrobat 9.0\acrobat\acrotray.exe" = protocol=6 | dir=in | app=c:\program files\adobe\acrobat 9.0\acrobat\acrotray.exe |
"TCP Query User{CA723A7A-A803-4448-B1EF-2D14490F5B67}C:\program files\microsoft office\office12\groovemonitor.exe" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groovemonitor.exe |
"TCP Query User{D4717C28-212C-4FB8-802D-4800061B3023}C:\windows\system32\hkcmd.exe" = protocol=6 | dir=in | app=c:\windows\system32\hkcmd.exe |
"TCP Query User{D5445121-40CE-43C1-AF9B-F3E38CD2129B}C:\program files\search settings\searchsettings.exe" = protocol=6 | dir=in | app=c:\program files\search settings\searchsettings.exe |
"TCP Query User{D581650C-77F6-4BDB-AFF0-17FAD0CB2F92}C:\program files\synaptics\syntp\syntphelper.exe" = protocol=6 | dir=in | app=c:\program files\synaptics\syntp\syntphelper.exe |
"TCP Query User{D64E830B-F1DA-42C2-BCA6-25EBFFAC8DD8}C:\windows\system32\mspaint.exe" = protocol=6 | dir=in | app=c:\windows\system32\mspaint.exe |
"TCP Query User{D913A7F5-5375-4237-9AD7-B612DC638C95}C:\windows\system32\werfault.exe" = protocol=6 | dir=in | app=c:\windows\system32\werfault.exe |
"TCP Query User{DE4B179C-0164-409E-9552-6C32C6DBC6A4}C:\users\user\documents\the sims 3\game\bin\ts3.exe.exe" = protocol=6 | dir=in | app=c:\users\user\documents\the sims 3\game\bin\ts3.exe.exe |
"TCP Query User{DF202015-C476-4508-B2BB-4F8661578EE1}C:\program files\toshiba\configfree\ndstray.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\configfree\ndstray.exe |
"TCP Query User{DF7C5D0C-D383-4D40-81B2-E432F0383AF2}C:\program files\toshiba\bluetooth toshiba stack\tosa2dp.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosa2dp.exe |
"TCP Query User{E5BA05C0-CC3A-472F-95D1-C72FC6C57F9F}C:\windows\system32\rundll32.exe" = protocol=6 | dir=in | app=c:\windows\system32\rundll32.exe |
"TCP Query User{E602728F-79B0-4F58-A312-8A9D2A73ACA7}C:\program files\microsoft intellipoint\ipoint.exe" = protocol=6 | dir=in | app=c:\program files\microsoft intellipoint\ipoint.exe |
"TCP Query User{E808949A-15F2-49DC-A585-EC7ED71F478F}C:\program files\adobe\acrobat 9.0\acrobat\acrotray.exe" = protocol=6 | dir=in | app=c:\program files\adobe\acrobat 9.0\acrobat\acrotray.exe |
"TCP Query User{E80BCFC4-F9AE-4DD4-A2DA-A967EADBA9EC}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"TCP Query User{E969009A-D105-402D-A9D6-82CA91449D37}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{E9B97122-61A9-4425-814D-3FFA1BDC691D}C:\windows\system32\igfxtray.exe" = protocol=6 | dir=in | app=c:\windows\system32\igfxtray.exe |
"TCP Query User{ED430C7F-8692-4894-BDCF-25DED539B190}C:\program files\toshiba\bluetooth toshiba stack\tosbthsp.exe" = protocol=6 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosbthsp.exe |
"TCP Query User{EE556BE5-D916-44A7-95FB-7CBC76931315}C:\program files\adobe media player\adobe media player.exe" = protocol=6 | dir=in | app=c:\program files\adobe media player\adobe media player.exe |
"TCP Query User{EE7DD61A-97D8-45DF-8AF9-59B1E6195C64}C:\program files\synaptics\syntp\syntpenh.exe" = protocol=6 | dir=in | app=c:\program files\synaptics\syntp\syntpenh.exe |
"TCP Query User{EE8C0E1C-C39E-4FAB-8FA4-6C1E32C36555}C:\program files\realtek\audio\hda\rthdvcpl.exe" = protocol=6 | dir=in | app=c:\program files\realtek\audio\hda\rthdvcpl.exe |
"TCP Query User{F1454A1E-1FEC-4F52-9E21-5103CE8CD6FB}C:\program files\microsoft intellitype pro\type32.exe" = protocol=6 | dir=in | app=c:\program files\microsoft intellitype pro\type32.exe |
"TCP Query User{F611EEEE-BE6D-4AB4-9092-FD970737FD84}C:\windows\system32\igfxext.exe" = protocol=6 | dir=in | app=c:\windows\system32\igfxext.exe |
"TCP Query User{F91FAF88-86C8-4B88-B440-21193EAC7EC4}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{03AF58A8-42C4-474B-B128-50A93AE03F1C}C:\program files\toshiba\bluetooth toshiba stack\tosbthid.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosbthid.exe |
"UDP Query User{0684798F-2525-469E-853F-176A6AC6C992}C:\users\user\documents\the sims 3\game\bin\ts3.exe.exe" = protocol=17 | dir=in | app=c:\users\user\documents\the sims 3\game\bin\ts3.exe.exe |
"UDP Query User{0B9A9CDC-F97C-4445-93B2-B401F5511D61}C:\program files\toshiba\bluetooth toshiba stack\tosbtmng.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosbtmng.exe |
"UDP Query User{0C5625FD-D274-470D-BBAF-EC88CDED5A17}C:\program files\yahoo!\messenger\ymsgr_tray.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\ymsgr_tray.exe |
"UDP Query User{0C8F6B60-0F7F-484D-8E12-644A5B9F64F5}C:\program files\microsoft intellitype pro\type32.exe" = protocol=17 | dir=in | app=c:\program files\microsoft intellitype pro\type32.exe |
"UDP Query User{15D79114-88A4-44C5-B88F-DB1BE1DEC563}C:\program files\adobe media player\adobe media player.exe" = protocol=17 | dir=in | app=c:\program files\adobe media player\adobe media player.exe |
"UDP Query User{15E84AE0-762A-4608-8DB1-4CFA3A42F317}C:\program files\microsoft intellipoint\ipoint.exe" = protocol=17 | dir=in | app=c:\program files\microsoft intellipoint\ipoint.exe |
"UDP Query User{18B0B89C-41D6-4511-956B-0B417B386186}C:\windows\system32\notepad.exe" = protocol=17 | dir=in | app=c:\windows\system32\notepad.exe |
"UDP Query User{19551A78-9B0B-4E1E-8D86-F9CA4722BFAD}C:\program files\toshiba\configfree\ndstray.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\configfree\ndstray.exe |
"UDP Query User{1FB881A0-B58C-419F-9B05-A39274AACE1C}C:\program files\microsoft games\freecell\freecell.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\freecell\freecell.exe |
"UDP Query User{235B8D7A-1B3A-45F0-BB2C-4972D8F41F7B}C:\program files\toshiba\flashcards\tcrdmain.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\flashcards\tcrdmain.exe |
"UDP Query User{24085D35-E061-4FE5-B574-894021A26197}C:\program files\toshiba\configfree\cffncenabler.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\configfree\cffncenabler.exe |
"UDP Query User{275B57CC-91C7-4310-9C80-9FB3B3E24013}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{30B3FD5B-385F-45D5-8755-B3AEC7CF809D}C:\program files\yahoo!\messenger\ymsgr_tray.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\ymsgr_tray.exe |
"UDP Query User{311FDA3A-C68D-49C7-819F-7B95E0EB8B81}C:\program files\adobe\acrobat 9.0\acrobat\acrotray.exe" = protocol=17 | dir=in | app=c:\program files\adobe\acrobat 9.0\acrobat\acrotray.exe |
"UDP Query User{36AA61F4-53C6-44C9-8B6F-01807F446834}C:\program files\toshiba\teco\teco.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\teco\teco.exe |
"UDP Query User{3804045D-B54A-4CFB-A18D-347FA9B115E2}C:\program files\synaptics\syntp\syntpenh.exe" = protocol=17 | dir=in | app=c:\program files\synaptics\syntp\syntpenh.exe |
"UDP Query User{398A7417-6125-4988-B807-979F13C8D3B8}C:\program files\microsoft office\office12\excel.exe" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\excel.exe |
"UDP Query User{3CA8A4AE-B3A2-477E-86CF-824E09511AB8}C:\program files\synaptics\syntp\syntphelper.exe" = protocol=17 | dir=in | app=c:\program files\synaptics\syntp\syntphelper.exe |
"UDP Query User{3D21949E-1970-4168-AA9E-8CDA843225B3}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{3E791AB5-215D-47E4-80A2-039C3B4DE6BF}C:\windows\system32\mobsync.exe" = protocol=17 | dir=in | app=c:\windows\system32\mobsync.exe |
"UDP Query User{3EAA81D1-DB49-4BC1-9993-8F04C3FA4CED}C:\program files\adobe media player\adobe media player.exe" = protocol=17 | dir=in | app=c:\program files\adobe media player\adobe media player.exe |
"UDP Query User{3F886FEE-5BEE-4457-90AB-1771457073A3}C:\windows\system32\dwm.exe" = protocol=17 | dir=in | app=c:\windows\system32\dwm.exe |
"UDP Query User{421F37FA-676F-4481-94AB-14004233B9DA}C:\program files\microsoft office\office12\groovemonitor.exe" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groovemonitor.exe |
"UDP Query User{44151713-0DBF-4776-B4D0-BC360F1BB32C}C:\program files\realtek\audio\hda\rthdvcpl.exe" = protocol=17 | dir=in | app=c:\program files\realtek\audio\hda\rthdvcpl.exe |
"UDP Query User{461FCC22-D56C-4B44-BE55-289D47556F08}C:\windows\system32\igfxsrvc.exe" = protocol=17 | dir=in | app=c:\windows\system32\igfxsrvc.exe |
"UDP Query User{463D463E-C368-4375-94A6-A0477C0231ED}C:\program files\microsoft office\office12\groovemonitor.exe" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groovemonitor.exe |
"UDP Query User{4AE95B15-B9BA-4E08-BE03-BD2D5E39A77F}C:\program files\ubi soft games\conquest frontier wars\conquest.exe" = protocol=17 | dir=in | app=c:\program files\ubi soft games\conquest frontier wars\conquest.exe |
"UDP Query User{4CF43790-27A1-49FF-A43F-926DC37390F2}C:\program files\toshiba\configfree\cfswmgr.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\configfree\cfswmgr.exe |
"UDP Query User{4DB215A4-9767-43CF-97E1-AC41E62A0992}C:\windows\system32\igfxtray.exe" = protocol=17 | dir=in | app=c:\windows\system32\igfxtray.exe |
"UDP Query User{545C2008-207F-4793-B330-9B156A671465}C:\windows\system32\userinit.exe" = protocol=17 | dir=in | app=c:\windows\system32\userinit.exe |
"UDP Query User{5521A0D8-D970-4D59-A4F6-5115CB217BD0}C:\program files\toshiba\bluetooth toshiba stack\tosbthsp.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosbthsp.exe |
"UDP Query User{56BB7ED3-2201-4CE7-A670-7A4442242DC1}C:\windows\system32\rundll32.exe" = protocol=17 | dir=in | app=c:\windows\system32\rundll32.exe |
"UDP Query User{570A57C2-1141-4591-899A-7247589FD320}C:\program files\microsoft office\office12\winword.exe" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\winword.exe |
"UDP Query User{572D6CE7-67AC-48C9-A7A9-64B111079B25}C:\windows\system32\wuauclt.exe" = protocol=17 | dir=in | app=c:\windows\system32\wuauclt.exe |
"UDP Query User{57A02F64-5814-48E0-9EAC-ABDB51CCE886}C:\program files\windows media player\wmpnscfg.exe" = protocol=17 | dir=in | app=c:\program files\windows media player\wmpnscfg.exe |
"UDP Query User{5CD9E2D6-643B-435A-BFE0-105C37ABD119}C:\program files\toshiba\bluetooth toshiba stack\tosbtmng.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosbtmng.exe |
"UDP Query User{5FD1BA25-8489-41A2-A693-58854022B06A}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{63E3B53B-5B55-4B02-975F-3766265CD780}C:\windows\system32\igfxsrvc.exe" = protocol=17 | dir=in | app=c:\windows\system32\igfxsrvc.exe |
"UDP Query User{67F27469-C605-41E3-A7C3-6D730864D308}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{6A8E4621-0C8A-4798-81E9-852AC9A49C46}C:\program files\toshiba\power saver\tpwrmain.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\power saver\tpwrmain.exe |
"UDP Query User{6BEB8388-2C6F-44E9-BAFD-4E26FF508540}C:\program files\adobe\reader 9.0\reader\reader_sl.exe" = protocol=17 | dir=in | app=c:\program files\adobe\reader 9.0\reader\reader_sl.exe |
"UDP Query User{6C73FBDA-3F3A-4261-A58E-363ED30D2EBC}C:\windows\system32\igfxtray.exe" = protocol=17 | dir=in | app=c:\windows\system32\igfxtray.exe |
"UDP Query User{6D1859F3-ACBC-422C-8B73-E08C8AE88D11}C:\program files\adobe\acrobat 9.0\acrobat\acrobat_sl.exe" = protocol=17 | dir=in | app=c:\program files\adobe\acrobat 9.0\acrobat\acrobat_sl.exe |
"UDP Query User{6E264343-5FD3-4ED3-80DF-4D863A8A0588}F:\recycler\s-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe" = protocol=17 | dir=in | app=f:\recycler\s-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe |
"UDP Query User{6E810E27-70B3-4AB1-BE5A-DB89F81BCBBA}C:\program files\search settings\searchsettings.exe" = protocol=17 | dir=in | app=c:\program files\search settings\searchsettings.exe |
"UDP Query User{6EA36A4C-D50C-44B7-A961-8B498B0D2F94}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{733B9AB7-CB60-463C-AFE2-C67815BB9861}C:\windows\system32\hkcmd.exe" = protocol=17 | dir=in | app=c:\windows\system32\hkcmd.exe |
"UDP Query User{74E7A41E-5FE7-40D3-8A01-EC0D57C4C1A9}C:\program files\toshiba\toshiba hdd ssd alert\tossenotify.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\toshiba hdd ssd alert\tossenotify.exe |
"UDP Query User{75F33F39-4A39-4014-A32A-1A8C5C3A0E9E}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{7AC2DFE1-9B58-49F3-AE45-224B5E9AC89E}C:\program files\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\plugin-container.exe |
"UDP Query User{7EE8EA8A-13E0-4D18-90BA-DE1E6418885B}C:\program files\valusoft\prison tycoon 3\data\prisontycoon3.exe" = protocol=17 | dir=in | app=c:\program files\valusoft\prison tycoon 3\data\prisontycoon3.exe |
"UDP Query User{853D9B53-4A76-4915-9021-04298E4AD20D}C:\program files\toshiba\configfree\ndstray.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\configfree\ndstray.exe |
"UDP Query User{88FEC331-56C6-4392-B2C0-026DDE440D14}C:\program files\dosbox-0.73\dosbox.exe" = protocol=17 | dir=in | app=c:\program files\dosbox-0.73\dosbox.exe |
"UDP Query User{89530C51-2897-4D68-B7B4-B333293A73A3}C:\windows\system32\hkcmd.exe" = protocol=17 | dir=in | app=c:\windows\system32\hkcmd.exe |
"UDP Query User{89FFAE74-B7AC-4C53-8DD9-5F8EEDDDF253}C:\windows\system32\werfault.exe" = protocol=17 | dir=in | app=c:\windows\system32\werfault.exe |
"UDP Query User{8A9FFB79-ECE6-47C8-B9E2-91FE55468706}C:\program files\toshiba\bluetooth toshiba stack\tosbthid.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosbthid.exe |
"UDP Query User{8B24A642-5E64-4A2B-AC0A-C045F52F1433}C:\program files\ea games\battlefield 1942\bf1942.exe" = protocol=17 | dir=in | app=c:\program files\ea games\battlefield 1942\bf1942.exe |
"UDP Query User{8C651F10-EEF4-452E-861C-CA1D0F7FDB6D}C:\windows\system32\wuauclt.exe" = protocol=17 | dir=in | app=c:\windows\system32\wuauclt.exe |
"UDP Query User{8D0D2D63-CEB2-4F4E-A2EC-19FAF5D64143}C:\program files\microsoft games\freecell\freecell.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\freecell\freecell.exe |
"UDP Query User{8E53C198-880B-4853-AD67-D160BF0BA677}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{9692A24F-6DA9-40B0-922E-7ACC472DB071}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{9EB8B43E-0443-4B05-9DE4-2E92F99DE6E6}C:\program files\adobe\acrobat 9.0\acrobat\acrotray.exe" = protocol=17 | dir=in | app=c:\program files\adobe\acrobat 9.0\acrobat\acrotray.exe |
"UDP Query User{A231861A-F742-4F0C-9F5C-5E3EF797CF68}C:\program files\microsoft intellitype pro\type32.exe" = protocol=17 | dir=in | app=c:\program files\microsoft intellitype pro\type32.exe |
"UDP Query User{A2B183A8-ABC2-41EF-AFF2-548829477D40}C:\program files\ubisoft\the settlers 7 - paths to a kingdom\data\base\_dbg\bin\release\settlers7r.exe" = protocol=17 | dir=in | app=c:\program files\ubisoft\the settlers 7 - paths to a kingdom\data\base\_dbg\bin\release\settlers7r.exe |
"UDP Query User{A527221E-7965-4220-98A5-BFD05F265287}C:\windows\system32\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\system32\dplaysvr.exe |
"UDP Query User{ABD81BDC-61EE-46D6-83AB-645AF4A080BE}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{AD3249CA-BB67-4FE8-BC81-AA89AF796A96}C:\program files\toshiba\power saver\tpwrmain.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\power saver\tpwrmain.exe |
"UDP Query User{B0348E9C-231C-45B9-99CC-9857EE8A943A}C:\windows\system32\mspaint.exe" = protocol=17 | dir=in | app=c:\windows\system32\mspaint.exe |
"UDP Query User{B1108982-891A-495F-9918-5BE099DFCB60}C:\windows\system32\igfxpers.exe" = protocol=17 | dir=in | app=c:\windows\system32\igfxpers.exe |
"UDP Query User{B156D853-A8F2-448C-A477-F1C5D3BA63DA}C:\program files\magicdisc\magicdisc.exe" = protocol=17 | dir=in | app=c:\program files\magicdisc\magicdisc.exe |
"UDP Query User{B571AD21-24BF-48CA-A6F8-276B0DF976E2}C:\program files\adobe\acrobat 9.0\acrobat\acrodist.exe" = protocol=17 | dir=in | app=c:\program files\adobe\acrobat 9.0\acrobat\acrodist.exe |
"UDP Query User{B922116B-F4FD-4117-86A9-D9A9EFFD9064}C:\windows\system32\igfxpers.exe" = protocol=17 | dir=in | app=c:\windows\system32\igfxpers.exe |
"UDP Query User{BA21953E-14CD-4E33-8585-34B706521864}C:\program files\toshiba\toshiba hdd ssd alert\tossenotify.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\toshiba hdd ssd alert\tossenotify.exe |
"UDP Query User{BD1C6EC9-CA28-4C4A-B5FF-42966B860758}C:\program files\adobe\acrobat 9.0\acrobat\acrobat_sl.exe" = protocol=17 | dir=in | app=c:\program files\adobe\acrobat 9.0\acrobat\acrobat_sl.exe |
"UDP Query User{BDAA4B27-B265-44A6-8F41-7F6D1235FBC5}C:\program files\search settings\searchsettings.exe" = protocol=17 | dir=in | app=c:\program files\search settings\searchsettings.exe |
"UDP Query User{C022BA9B-7538-439E-8416-83708BE0A5A5}C:\program files\windows defender\msascui.exe" = protocol=17 | dir=in | app=c:\program files\windows defender\msascui.exe |
"UDP Query User{C80D2558-E21E-4E87-AEC5-EFEAB56F60B2}C:\program files\toshiba\teco\teco.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\teco\teco.exe |
"UDP Query User{C86D8E1F-17A3-455E-AC71-99B7D82C880C}C:\windows\system32\msfeedssync.exe" = protocol=17 | dir=in | app=c:\windows\system32\msfeedssync.exe |
"UDP Query User{CFF10F5D-88E3-405C-A3EC-8E38C23CCB56}C:\program files\toshiba\toscdspd\toscdspd.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\toscdspd\toscdspd.exe |
"UDP Query User{D0629DCE-5348-4B0F-AC6F-875C3FD0A9F8}C:\program files\toshiba\bluetooth toshiba stack\itsecmng.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\itsecmng.exe |
"UDP Query User{D3E15C24-C4B8-4B87-BB25-E2BB616B74FC}C:\windows\system32\dwm.exe" = protocol=17 | dir=in | app=c:\windows\system32\dwm.exe |
"UDP Query User{D665C345-8E40-4A4D-9117-030F775E4F63}C:\program files\realtek\audio\hda\rthdvcpl.exe" = protocol=17 | dir=in | app=c:\program files\realtek\audio\hda\rthdvcpl.exe |
"UDP Query User{D6A30024-7332-4BA4-82B8-F1B93224BA96}C:\program files\synaptics\syntp\syntpenh.exe" = protocol=17 | dir=in | app=c:\program files\synaptics\syntp\syntpenh.exe |
"UDP Query User{D7D4C4E4-4FBD-408D-BC68-914FCBBCD7B0}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{D9CDE595-A985-4A74-94F1-1D32F31C6230}C:\windows\system32\searchprotocolhost.exe" = protocol=17 | dir=in | app=c:\windows\system32\searchprotocolhost.exe |
"UDP Query User{DA572A8A-96F3-431B-BAB4-8434C58983A5}C:\windows\system32\igfxext.exe" = protocol=17 | dir=in | app=c:\windows\system32\igfxext.exe |
"UDP Query User{DB4C3121-5091-4634-9E1B-50DBA9EB1EB2}C:\program files\common files\real\update_ob\realsched.exe" = protocol=17 | dir=in | app=c:\program files\common files\real\update_ob\realsched.exe |
"UDP Query User{DBF542F5-E39E-41E1-9B4E-D6A9DF874602}C:\windows\system32\macromed\flash\flashutil10d.exe" = protocol=17 | dir=in | app=c:\windows\system32\macromed\flash\flashutil10d.exe |
"UDP Query User{E1683993-552A-4DF5-A867-156315ACA445}C:\program files\toshiba\configfree\cfswmgr.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\configfree\cfswmgr.exe |
"UDP Query User{E4AB132A-4259-4907-85AA-FC2C58889DF5}C:\program files\common files\real\update_ob\realsched.exe" = protocol=17 | dir=in | app=c:\program files\common files\real\update_ob\realsched.exe |
"UDP Query User{E7E9600E-5740-4FEB-B25E-EA19EE28BC8C}C:\program files\adobe\acrobat 9.0\acrobat\acrodist.exe" = protocol=17 | dir=in | app=c:\program files\adobe\acrobat 9.0\acrobat\acrodist.exe |
"UDP Query User{EAF5DA76-386C-444D-9AD2-98B40093A153}C:\program files\windows mail\winmail.exe" = protocol=17 | dir=in | app=c:\program files\windows mail\winmail.exe |
"UDP Query User{EB5FBA60-55A9-45CD-AAC0-DD1593880603}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{EDB69C3A-818D-4273-BA01-F4FA9E9A8ECD}C:\program files\toshiba\bluetooth toshiba stack\tosbthsp.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosbthsp.exe |
"UDP Query User{F03C3A79-2366-45BC-A953-ECD093F47E5D}C:\program files\windows defender\msascui.exe" = protocol=17 | dir=in | app=c:\program files\windows defender\msascui.exe |
"UDP Query User{F114DECD-651C-4AF1-B754-0AAD289D14EA}C:\program files\toshiba\bluetooth toshiba stack\tosavrc.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosavrc.exe |
"UDP Query User{F222F6DF-4802-44C8-BF53-512B401DD2DC}C:\program files\toshiba\flashcards\tcrdmain.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\flashcards\tcrdmain.exe |
"UDP Query User{F2AC3191-5D87-4E28-8EF2-52C23193AE79}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{F3832889-3F2D-4445-BEE5-316E123CE3E6}C:\windows\system32\gphotos.scr" = protocol=17 | dir=in | app=c:\windows\system32\gphotos.scr |
"UDP Query User{F661A1B7-2C67-46D2-8FA0-25AECA11160A}C:\program files\toshiba\bluetooth toshiba stack\tosa2dp.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\bluetooth toshiba stack\tosa2dp.exe |
"UDP Query User{F77C0426-6059-4F1B-9509-B2F999A6C2BD}C:\windows\system32\igfxext.exe" = protocol=17 | dir=in | app=c:\windows\system32\igfxext.exe |
"UDP Query User{F9B094D1-2A0E-4221-829B-D1B0FCB3AA31}C:\program files\toshiba\toscdspd\toscdspd.exe" = protocol=17 | dir=in | app=c:\program files\toshiba\toscdspd\toscdspd.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}" = Search Settings 1.2.2
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{14F70205-1940-4000-88C7-BE799A6B2CAD}" = Adobe Soundbooth CS4
"{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
"{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
"{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 21
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{35C0A1E4-D02A-412C-841F-266DBB116ABB}" = Intel® PROSet/Wireless WiFi Software
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3BEF9769-BA52-18F7-1D02-2362F6A27E38}" = Adobe Media Player
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims 2 Pets
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
"{4CA9839A-F660-4F7F-BD45-F466512ECE20}" = LegionArena
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{50F68032-B5B7-4513-9116-C978DBD8F27A}" = DVD MovieFactory for TOSHIBA
"{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
"{53536479-DFB0-47ED-9D10-43F3708C222D}" = TOSHIBA eco Utility
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{5EAD5443-7194-46CC-A055-428E6ABB1BAF}" = Adobe Encore CS4
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}" = Battlefield 1942
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6BDD9CE6-D0A6-478A-BAD3-BA6945E89EB0}" = The Sims 2 Family Fun Stuff
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6DEF11C0-35FF-4160-A543-FDD336C4DAE5}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
"{6E7DD182-9FC6-4651-0095-2E666CC6AF35}" = The Sims 2
"{7406DF60-016D-476B-A2C7-55D997592047}" = Adobe OnLocation CS4
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
"{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
"{7E64B067-2EF5-4CC0-9CA9-06589057983D}" = Capitalism II
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{81463B08-A929-4125-A5F4-1B053AC35A09}" = Microsoft IntelliType Pro 5.0
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F7D66C-777D-473B-AA11-319C0F190EAC}" = TOSHIBA Internal Modem Region Select Utility
"{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}" = The Sims 2 University
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}" = The Sims 2 Glamour Life Stuff
"{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A208044D-A88B-4ACF-AE95-E4F213E6EDC0}" = TOSHIBA Supervisor Password
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A6EC82A0-1414-475D-8AFD-469089F3080D}" = Adobe Contribute CS4
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}_933" = Adobe Acrobat 9.3.3 - CPSID_83708
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.1
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP2
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D0387727-C89D-4774-B643-B9333EAA09DE}" = TOSHIBA Hardware Setup
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = The Sims™ 2 Seasons
"{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
"{EAE56E0A-E758-4878-B40F-6C99B7B4D864}" = Takeda 3
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{F0A386D2-6E15-4A8F-A04E-87CE9BED0D48}" = TOSHIBA ConfigFree
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2004B8D-7791-4B35-A3FA-D8CA8BB4DD81}" = Direct DiscRecorder
"{F248ADFA-64E0-4b03-8A83-059078BED6A0}" = The Sims™ 2 Bon Voyage
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = The Sims 2 Nightlife
"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Activision_CivCTPUninstallKey" = Civilization: Call To Power
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_b2d6abde968e6f277ddbfd501383e02" = Adobe Creative Suite 4 Master Collection
"avast5" = avast! Free Antivirus
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP2
"CEP - Colour Enable Packages_is1" = CEP (Color Enable Package) v.9.2 (beta)
"com.adobe.amp.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Media Player
"CuteFTP Pro" = CuteFTP Pro
"ENTERPRISE" = Microsoft Office Enterprise 2007
"GSC 2.00" = GSC 2.00
"HDMI" = Intel® Graphics Media Accelerator Driver
"Hospital" = Theme Hospital
"Indeo® software" = Indeo® software
"InstallShield_{50F68032-B5B7-4513-9116-C978DBD8F27A}" = DVD MovieFactory for TOSHIBA
"InstallShield_{53536479-DFB0-47ED-9D10-43F3708C222D}" = TOSHIBA eco Utility
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{89F7D66C-777D-473B-AA11-319C0F190EAC}" = TOSHIBA Internal Modem Region Select Utility
"InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"InstallShield_{F2004B8D-7791-4B35-A3FA-D8CA8BB4DD81}" = Direct DiscRecorder
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Media Player - Codec Pack" = Media Player Codec Pack 3.8.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"O.R.B" = O.R.B
"Picasa 3" = Picasa 3
"PROHYBRIDR" = 2007 Microsoft Office system
"ProInst" = Intel PROSet Wireless
"RealPlayer 12.0" = RealPlayer
"S2TNG" = The Settlers II - 10th Anniversary
"Student and Home Edition" = Student and Home Edition
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"The KMPlayer" = The KMPlayer (remove only)
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Tropico3" = Tropico 3 1.00
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/21/2010 10:21:06 PM | Computer Name = User-PC | Source = WinMgmt | ID = 10
Description =

Error - 6/21/2010 10:21:33 PM | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application AdobeARM.exe, version 1.1.5.0, time stamp 0x4b22dc74,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0xde89d84e, process id 0x1198, application start time 0x01cb11b1a17ad225.

Error - 6/21/2010 11:50:27 PM | Computer Name = User-PC | Source = Desktop Window Manager | ID = 9020
Description = The Desktop Window Manager has encountered a fatal error (0x88980406)

Error - 6/22/2010 1:53:45 AM | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application AdobeARM.exe, version 1.1.5.0, time stamp 0x4b22dc74,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0xdf4ad858, process id 0x1540, application start time 0x01cb11cf467da7d5.

Error - 6/22/2010 3:25:43 AM | Computer Name = User-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 1.9.2.3743 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 380 Start Time: 01cb11be15d3d4d5 Termination Time: 0

Error - 6/22/2010 8:22:07 AM | Computer Name = User-PC | Source = Google Update | ID = 20
Description =

Error - 6/22/2010 8:24:50 PM | Computer Name = User-PC | Source = WinMgmt | ID = 10
Description =

Error - 6/22/2010 8:24:58 PM | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application AdobeARM.exe, version 1.1.5.0, time stamp 0x4b22dc74,
faulting module AdobeARM.exe, version 1.1.5.0, time stamp 0x4b22dc74, exception
code 0xc0000005, fault offset 0x0002d33b, process id 0xef0, application start time
0x01cb126a8177259f.

Error - 6/22/2010 10:09:05 PM | Computer Name = User-PC | Source = WinMgmt | ID = 10
Description =

Error - 6/22/2010 10:09:24 PM | Computer Name = User-PC | Source = Application Error | ID = 1000
Description = Faulting application AdobeARM.exe, version 1.1.5.0, time stamp 0x4b22dc74,
faulting module AdobeARM.exe, version 1.1.5.0, time stamp 0x4b22dc74, exception
code 0xc0000005, fault offset 0x0002d341, process id 0x1224, application start time
0x01cb127918bf44ed.

[ OSession Events ]
Error - 12/3/2009 1:28:55 AM | Computer Name = User-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 102
seconds with 60 seconds of active time. This session ended with a crash.

Error - 12/3/2009 1:33:44 AM | Computer Name = User-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 282
seconds with 240 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 9/15/2010 11:18:58 AM | Computer Name = User-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 9/15/2010 2:00:20 PM | Computer Name = User-PC | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address [removed] on
the Network Card with network address 001E33C70F70.

Error - 9/15/2010 3:13:43 PM | Computer Name = User-PC | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address [removed],
since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which
addresses are being allocated to DHCP clients. To enable the DHCP allocator on this
IP address, change the scope to include the IP address, or change the IP address
to fall within the scope.

Error - 9/15/2010 3:19:55 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7031
Description =

Error - 9/15/2010 3:20:04 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7031
Description =

Error - 9/15/2010 5:50:35 PM | Computer Name = User-PC | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address [removed] on
the Network Card with network address 001E33C70F70.

Error - 9/15/2010 5:50:39 PM | Computer Name = User-PC | Source = ipnathlp | ID = 31004
Description = The DNS proxy agent was unable to allocate 0 bytes of memory. This
may indicate that the system is low on virtual memory, or that the memory manager
has encountered an internal error.

Error - 9/15/2010 7:07:49 PM | Computer Name = User-PC | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address [removed] on
the Network Card with network address 001E33C70F70.

Error - 9/15/2010 7:07:51 PM | Computer Name = User-PC | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address [removed],
since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which
addresses are being allocated to DHCP clients. To enable the DHCP allocator on this
IP address, change the scope to include the IP address, or change the IP address
to fall within the scope.

Error - 9/15/2010 7:07:53 PM | Computer Name = User-PC | Source = ipnathlp | ID = 31004
Description = The DNS proxy agent was unable to allocate 0 bytes of memory. This
may indicate that the system is low on virtual memory, or that the memory manager
has encountered an internal error.

< End of report >
LOG from: exeHelper by Raktor

Build 20100414
Run at 02:49:37 on 09/16/10
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–
LOG from: Win32KDiag

Running from: C:\Users\[removed]\Desktop\Win32kDiag.exe
Log file at : C:\Users\User\Desktop\Win32kDiag.txt
WARNING: Could not get backup privileges!
Searching 'C:\Windows'…

Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
[1] 2010-09-16 02:13:35 64 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl ()

Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
[1] 2010-09-16 02:13:21 64 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl ()

Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
[1] 2010-09-16 02:13:21 64 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl ()

Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
[1] 2010-09-16 02:13:21 64 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl ()

Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession.etl
[1] 2010-09-16 02:14:25 0 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession.etl ()

Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMuroc System Trace.etl
[1] 2010-09-16 02:13:38 0 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMuroc System Trace.etl ()

Finished!
Posted Image


DO NOT use any TOOLS such as Combofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.




Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI