muznik
Topic Starter
Hi All
I am having a problem with a virus or malware on my laptop.
When i open a webp[age it says it is infected with BNK.Win32.KeyLogger.gen.
It came up with all these pop ups and scanners saying i am infected and i need to purchase to get rid of.
Obviously I did not but just closing them they would pop up again 5 minutes later
Lots of Vista security measures try to run.
It disabled the laptop pretty much with me unable to run anything or open a web page.
I ran Malwarebytes last night from safemode as administrator and it found one file infected and removed it.
The laptop then loaded ok in normal mode but when I try to open a web page all the pop ups appear again.
I hope someone can help.
Thanks in advance.
My DDS log follows.
.
DDS (Ver_2011-06-03.01) - NTFSx86
Internet Explorer: 8.0.6001.19048 BrowserJavaVersion: 1.6.0_22
Run by [removed] at 6:57:01 on 2011-06-07
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.2908.1723 [GMT 10:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agrsmsvc.exe
C:\Windows\System32\svchost.exe -k Akamai
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Common Files\Livescribe\PenComm\PenCommService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\TECO\TEco.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Telstra\BigPond Wireless Broadband\BigPond_CM.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Livescribe\Livescribe Desktop\LDTray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Telstra\Telstra Turbo Modem Manager\Service\MdmMgr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Windows\ehome\ehsched.exe
C:\Windows\ehome\ehRecvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.telstra.com/
uStart Page = hxxp://www.news.com.au/
uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSHN&bmod=TSHN
uSearch Bar = hxxp://www.google.com/ie
uWindow Title = Telstra BigPond Home Internet Explorer
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHN&bmod=TSHN
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSHN&bmod=TSHN
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: @c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
uRun: [LDTray] c:\program files\livescribe\livescribe desktop\LDTray.exe
uRun: [4E3E0230AEBB4E96] c:\recycle.bin\Recycle.Bin.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRunOnce: [Application Restart #5] c:\windows\system32\mshta.exe "c:\sea752\nextgen\applyo~1\InstallUpdate.hta" "http://afg.xgate.com.au/xgate/WebServices/updatedownload.asp?FileName=UpdateAFG20100625-20101028.exe&UpdateVersion=ApplyonlineMobile/AFG/2010-10-28&AOLMUserID=SMURRAY" "8979F91F-EBC2-494D-A5EB-D8BE2BA0BE41"
mRun: []
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosSENotify.exe
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [TPCHWMsg] %ProgramFiles%\TOSHIBA\TPHM\TPCHWMsg.exe
mRun: [NDSTray.exe] "c:\program files\toshiba\configfree\NDSTray.exe"
mRun: [cfFncEnabler.exe] "c:\program files\toshiba\configfree\cfFncEnabler.exe"
mRun: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [HWSetup] "c:\program files\toshiba\utilities\HWSetup.exe" hwSetUP
mRun: [SVPWUTIL] c:\program files\toshiba\utilities\SVPWUTIL.exe SVPwUTIL
mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [BigPondWirelessBroadbandCM] "c:\program files\telstra\bigpond wireless broadband\BigPond_CM.exe" -tsr
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Skytel] c:\program files\realtek\audio\hda\Skytel.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\telstr~1.lnk - c:\program files\telstra\telstra turbo modem manager\service\MdmMgr.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert link target to existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: afgonline.com.au
Trusted Zone: afgonline.com.au\flex
Trusted Zone: localhost
Trusted Zone: MUZNIK-PC
DPF: {831FB9D5-7704-46BE-B4AE-BD946EE97F4C} - hxxps://flex.afgonline.com.au/fins_enu/20433/applets/SiebelAx_OutBound_mail.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} - hxxps://flex.afgonline.com.au/fins_enu/20433/applets/SiebelAx_Desktop_Integration.cab
DPF: {A62585A1-D5ED-4505-9A71-0268DD51982C} - hxxps://flex.afgonline.com.au/fins_enu/20433/applets/SiebelAx_HI_Client.cab
DPF: {B2B2C3F9-CFB2-49CC-942D-103E68E09B74} - hxxps://flex.afgonline.com.au/fins_enu/20420/applets/SiebelAx_OutBound_mail.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CD9C0F1B-D8F9-4229-B76C-5EF6B14372E4} - hxxps://flex.afgonline.com.au/fins_enu/20420/applets/SiebelAx_HI_Client.cab
DPF: {E16AD7BB-6189-4C16-985A-7314EF875AC8} - hxxps://flex.afgonline.com.au/fins_enu/20433/applets/SiebelAx_Calendar.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUplden-au.cab
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{1F204A7B-CDB6-427E-9EE5-48B55B41D706} : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{7087B38D-EFAD-4EC4-B07F-3F14A2D16198} : DhcpNameServer = 10.0.0.2
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~3\GOEC62~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\muznik\appdata\roaming\mozilla\firefox\profiles\7ihl1j2t.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\picasa2\npPicasa2.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-8-4 11608]
R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\system32\drivers\RtlProt.sys [2009-7-6 25896]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-21 21504]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-8-4 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-8-4 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-8-4 56816]
R2 camsvc;TOSHIBA Web Camera Service;c:\program files\toshiba\toshiba web camera application\TWebCameraSrv.exe [2009-7-6 20544]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-11 46448]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 PenCommService;Livescribe Pulse Smartpen Service;c:\program files\common files\livescribe\pencomm\PenCommService.exe [2010-2-18 265728]
R2 RSELSVC;TOSHIBA Modem region select service;c:\program files\toshiba\rselect\RSelSvc.exe [2009-2-20 57344]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-4-15 176128]
R2 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-3-18 73728]
R2 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-4-10 656752]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-3-21 12920]
R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2009-7-6 22272]
R3 rtl819xp;Realtek RTL8190\RTL8192E 802.11n Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\drivers\rtl819xp.sys [2009-7-6 500224]
R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2009-7-6 51576]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-1 135664]
S3 cmusbnet;WAN Driver @ 3GPP (6280);c:\windows\system32\drivers\cmusbnet.sys [2010-3-11 81152]
S3 cmusbser;%CMUSBSER%;c:\windows\system32\drivers\cmusbser.sys [2010-3-11 87040]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-7-6 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-1-1 135664]
S3 PulseUsb;Livescribe Pulse Smartpen USB Driver;c:\windows\system32\drivers\PulseUsb.sys [2010-2-18 19968]
S3 SWNC8UA3;Sierra Wireless MUX NDIS Driver (UMTSA3);c:\windows\system32\drivers\swnc8ua3.sys [2010-6-8 197504]
S3 SWUMXA3;Sierra Wireless USB MUX Driver (UMTSA3);c:\windows\system32\drivers\swumxa3.sys [2010-6-8 148992]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-1-21 16896]
.
=============== Created Last 30 ================
.
2011-06-06 20:43:10 ——– d—–w- c:\program files\CCleaner
2011-06-06 11:25:27 ——– d—–w- c:\users\muznik\appdata\local\{DB640025-5FA8-4B18-9F25-C6D5B6A0F744}
2011-06-06 02:13:13 ——– d—–w- c:\users\muznik\appdata\local\{B7D5B708-DBAA-4F82-9C37-E6DBD1EBE56C}
2011-06-06 01:41:42 ——– d—–w- c:\users\muznik\appdata\local\{05A41B95-B6F8-4FC2-B15F-73C0703BA55D}
2011-06-05 20:38:27 ——– d—–w- c:\users\muznik\appdata\local\{534EE54F-722F-4A49-82AC-193C37004A5F}
2011-06-05 11:28:03 348160 –sha-w- c:\users\muznik\appdata\local\hvo.exe
2011-06-05 06:46:24 ——– d—–w- c:\users\muznik\appdata\local\{87BD7E36-65E4-40B6-9450-8B85861C22E8}
2011-06-04 07:03:01 ——– d—–w- c:\users\muznik\appdata\local\{C07D6BF2-B707-4C51-BD85-47F06724DBE2}
2011-06-03 12:33:50 6962000 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{dd00766d-a7c9-4987-a4f1-57de56fd64c8}\mpengine.dll
2011-06-03 12:14:03 ——– d—–w- c:\users\muznik\appdata\local\{3F40A92C-073D-4C4D-BDD7-95A6B4EDA95E}
2011-06-02 23:14:14 ——– d—–w- c:\users\muznik\appdata\local\{EF4CD6D3-D118-4961-B6FB-68FA314909DD}
2011-06-01 23:20:19 ——– d—–w- c:\users\muznik\appdata\local\{C235B860-595C-4EE2-97E2-0AC914854E77}
2011-05-31 23:36:05 ——– d—–w- c:\users\muznik\appdata\local\{631B33AB-5D7C-45BE-91E8-53FE5F2D18FA}
2011-05-31 09:27:40 ——– d—–w- c:\users\muznik\appdata\local\{0998968F-E78C-4D4D-B608-EDBAB4F0BAC1}
2011-05-30 23:42:29 ——– d—–w- c:\users\muznik\appdata\local\{70E12D8E-48E4-45E8-8F94-6983BEC44FD0}
2011-05-29 23:46:40 ——– d—–w- c:\users\muznik\appdata\local\{ACA9E517-D1F0-4D20-8739-FD31B9F96B07}
2011-05-29 05:27:30 ——– d—–w- c:\users\muznik\appdata\local\{A9744360-8021-4477-8A0F-5BD8923785FF}
2011-05-28 12:22:52 ——– d—–w- c:\users\muznik\appdata\local\{62438A43-4DAB-4FCA-B352-274CC166ECE3}
2011-05-27 23:07:26 ——– d—–w- c:\users\muznik\appdata\local\{669BE9E6-2B98-489C-A299-683A255D9410}
2011-05-27 11:07:03 ——– d—–w- c:\users\muznik\appdata\local\{F5FE4E0A-4C54-4BAA-A329-648C94E28E39}
2011-05-26 23:25:23 ——– d—–w- c:\users\muznik\appdata\local\{0E8DB37E-CE63-4007-BC04-C12FB2374B9B}
2011-05-26 11:05:50 ——– d—–w- c:\program files\iPod
2011-05-26 11:02:46 ——– d—–w- c:\program files\Bonjour
2011-05-26 08:48:12 ——– d—–w- c:\users\muznik\appdata\local\{9B2F27FE-1B1B-4891-A303-15B76DF65E46}
2011-05-25 12:35:22 ——– d—–w- c:\users\muznik\appdata\local\{F8AC8537-EA14-497F-A14D-BAFE7A10320F}
2011-05-24 23:21:53 ——– d—–w- c:\users\muznik\appdata\local\{935D1BC0-25F6-4947-B797-A0019EBEBB72}
2011-05-23 23:10:49 ——– d—–w- c:\users\muznik\appdata\local\{2EAD7648-3100-43BE-AFC9-78CBC0308F7E}
2011-05-23 04:40:58 ——– d—–w- c:\users\muznik\appdata\local\{5306FB3F-8178-4B52-851E-764AE0B1A766}
2011-05-22 23:19:03 ——– d—–w- c:\users\muznik\appdata\local\{72559FCB-8DB3-4086-ABC3-F08B9FFC544A}
2011-05-21 11:26:08 ——– d—–w- c:\users\muznik\appdata\local\{E72C095C-4AF7-4BAB-914A-163DCE5EC481}
2011-05-20 08:18:15 ——– d—–w- c:\users\muznik\appdata\local\{1131F506-4C0C-4533-B741-822F86E3E45D}
2011-05-19 23:35:56 ——– d—–w- c:\users\muznik\appdata\local\{47CFB6BC-67F4-403F-A12A-6C5EC7B7C908}
2011-05-19 07:54:27 ——– d—–w- c:\users\muznik\appdata\local\{13D8ED7F-CB20-4ED5-95A1-1935BEE10BDD}
2011-05-18 15:20:39 ——– d—–w- c:\users\muznik\appdata\local\{91E24001-A883-4C1E-8792-566347C2DA01}
2011-05-17 23:18:49 ——– d—–w- c:\users\muznik\appdata\local\{F760C2DE-DF3D-4CF8-B9AD-B49E4F4CB435}
2011-05-17 06:05:03 ——– d—–w- c:\users\muznik\appdata\local\{F4E2A7C4-0642-4CE0-9691-0590A69B9AA7}
2011-05-16 07:30:17 ——– d—–w- c:\users\muznik\appdata\local\{E3A044DB-05D5-4C73-9926-0DCDDE4420C0}
2011-05-15 22:59:46 ——– d—–w- c:\users\muznik\appdata\local\{2B78C7F9-F464-4EDA-AB7A-96AD6B92FB7B}
2011-05-14 05:57:41 ——– d—–w- c:\users\muznik\appdata\local\{B42B2CF3-079F-4684-914E-745F3E8DCF18}
2011-05-12 22:58:35 ——– d—–w- c:\users\muznik\appdata\local\{AE78F80E-61DE-4AE4-BAE6-03DC0327F895}
2011-05-12 22:57:50 ——– d—–w- c:\users\muznik\appdata\local\{B41F49E0-7DAE-4BE3-8127-E5ACA749A95D}
2011-05-12 10:48:13 ——– d—–w- c:\users\muznik\appdata\local\{A6624622-A22D-409F-9586-03AF8AD0B13C}
2011-05-11 22:53:05 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2011-05-11 22:46:54 ——– d—–w- c:\users\muznik\appdata\local\{EE175D11-7F0C-4F40-B27D-2187692A96D5}
2011-05-10 07:21:23 ——– d—–w- c:\users\muznik\appdata\local\{989F3F69-79BE-4DB9-9E23-DB53273C7BC6}
2011-05-09 07:40:17 ——– d—–w- c:\users\muznik\appdata\local\{390307AA-615F-4090-8C99-CAD5276C0DF1}
2011-05-08 11:33:51 ——– d—–w- c:\users\muznik\appdata\local\{D8C16B60-87E8-45E8-95D7-D7B8E7E0B857}
.
==================== Find3M ====================
.
2011-04-06 06:20:16 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 06:20:16 75040 —-a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 06:20:16 197920 —-a-w- c:\windows\system32\dnssdX.dll
2011-04-06 06:20:16 107808 —-a-w- c:\windows\system32\dns-sd.exe
2011-03-12 21:55:52 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-03-10 17:03:51 1162240 —-a-w- c:\windows\system32\mfc42u.dll
2011-03-10 17:03:51 1136640 —-a-w- c:\windows\system32\mfc42.dll
.
============= FINISH: 6:58:02.88 ===============
Thanks