This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

searchqu/406 removal on Chrome/FF/IE

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I accidentally downloaded the iLivid toolbar and with it came the searchqu/406 browser hijack. I've uninstalled the iLivid toolbar but I can see that the files still remain in my directory. I think I've reset my browser settings for Chrome, FF and IE but would like to be sure that everything is removed.

I primarily use Chrome13.0.782.112 and FF3.6.18 on my Windows7 laptop but removal instructions for IE would be much appreciated as well.

Here are my logs:

~~~~
OTL
~~~~

OTL logfile created on: 8/10/2011 9:14:58 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Bianca\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.73 Gb Total Physical Memory | 2.14 Gb Available Physical Memory | 57.38% Memory free
7.47 Gb Paging File | 5.71 Gb Available in Paging File | 76.43% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 454.39 Gb Total Space | 404.62 Gb Free Space | 89.05% Space Free | Partition Type: NTFS

Computer Name: BIANCA-PC | User Name: Bianca | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Bianca\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Users\Bianca\AppData\Local\Google\Update\1.3.21.65\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\SSU.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Users\Bianca\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (TosCoSrv) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WiMAXAppSrv) – C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe (Intel® Corporation)
SRV:64bit: - (DMAgent) – C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe (Red Bend Ltd.)
SRV:64bit: - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (Thpsrv) – C:\Windows\SysNative\ThpSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WRConsumerService) – C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (WebrootSpySweeperService) – C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (BrYNSvc) – C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (TMachInfo) – C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (ssidrv) – C:\Windows\SysNative\drivers\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (ssfmonm) – C:\Windows\SysNative\drivers\ssfmonm.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (NETwNs64) ___ Intel® – C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (wdkmd) – C:\Windows\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (bpmp) Intel® Centrino® – C:\Windows\SysNative\drivers\bpmp.sys (Intel Corporation)
DRV:64bit: - (bpusb) – C:\Windows\SysNative\drivers\bpusb.sys (Intel Corporation)
DRV:64bit: - (bpenum) – C:\Windows\SysNative\drivers\bpenum.sys (Intel Corporation)
DRV:64bit: - (tos_sps64) – C:\Windows\SysNative\drivers\tos_sps64.sys (TOSHIBA Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (risdpcie) – C:\Windows\SysNative\drivers\risdpe64.sys (REDC)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation)
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (e1kexpress) Intel® – C:\Windows\SysNative\drivers\e1k62x64.sys (Intel Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (tdcmdpst) – C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (TVALZ) – C:\Windows\SysNative\drivers\TVALZ.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Thpevm) – C:\Windows\SysNative\drivers\Thpevm.sys (TOSHIBA Corporation)
DRV:64bit: - (Thpdrv) – C:\Windows\SysNative\drivers\thpdrv.sys (TOSHIBA Corporation)
DRV:64bit: - (PGEffect) – C:\Windows\SysNative\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV:64bit: - (TVALZFL) – C:\Windows\SysNative\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (Ser2pl) – C:\Windows\SysNative\drivers\ser2pl64.sys (Prolific Technology Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…D&bmod=TSND
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…D&bmod=TSND

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig?brand=TSND&bmod=TSND
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://start.toshiba.com/g/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://start.toshiba.com/g/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig?brand=TSND&bmod=TSND
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Search Results"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q="

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Bianca\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Bianca\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Bianca\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Bianca\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/06/03 14:01:13 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/22 11:00:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/06/22 11:00:52 | 000,000,000 | —D | M]

[2011/08/10 17:57:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Bianca\AppData\Roaming\Mozilla\Extensions
[2011/08/10 19:31:34 | 000,000,000 | —D | M] (No name found) – C:\Users\Bianca\AppData\Roaming\Mozilla\Firefox\Profiles\2c5mqxwn.default\extensions
[2011/08/04 22:10:09 | 000,002,501 | —- | M] () – C:\Users\Bianca\AppData\Roaming\Mozilla\Firefox\Profiles\2c5mqxwn.default\searchplugins\SearchResults.xml
[2011/08/10 17:57:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/06/09 14:05:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/06/03 14:01:13 | 000,000,000 | —D | M] (Adobe Acrobat - Create PDF) – C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 10.0\ACROBAT\BROWSER\WCFIREFOXEXTN
[2011/08/04 22:10:09 | 000,002,501 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\SearchResults.xml

O1 HOSTS File: ([2011/08/10 17:51:33 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll ()
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [IntelWirelessWiMAX] C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [ThpSrv] C:\windows\SysNative\thpsrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\Toshiba\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] File not found
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [BrStsMon01] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TOSDCR] C:\Program Files (x86)\TOSHIBA\PasswordUtility\TOSDCR.exe ()
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TSleepSrv] File not found
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [WebrootTrayApp] C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe (Webroot Software, Inc. )
O4 - HKCU..\Run: [Best Buy pc app] File not found
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] File not found
O4 - Startup: C:\Users\Bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll (Google Inc.)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{9e0f7209-6aa3-11e0-8af0-002318bbd495}\Shell - "" = AutoRun
O33 - MountPoints2\{9e0f7209-6aa3-11e0-8af0-002318bbd495}\Shell\AutoRun\command - "" = E:\TL-Bootstrap.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/08/10 21:13:04 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Users\Bianca\Desktop\OTL.exe
[2011/08/10 17:49:47 | 000,000,000 | —D | C] – C:\ProgramData\boost_interprocess
[2011/08/09 15:16:15 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xmllite.dll
[2011/08/09 15:16:13 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\odbccp32.dll
[2011/08/09 15:16:13 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\odbccu32.dll
[2011/08/09 15:16:13 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\odbccr32.dll
[2011/08/09 15:16:12 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\odbcjt32.dll
[2011/08/09 15:16:12 | 000,212,992 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\odbctrac.dll
[2011/08/09 15:16:12 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\odbccp32.dll
[2011/08/09 15:16:12 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\odbccr32.dll
[2011/08/09 15:16:11 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\odbctrac.dll
[2011/08/09 15:16:11 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\odbccu32.dll
[2011/08/09 15:15:58 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\kernel32.dll
[2011/08/09 15:15:58 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\conhost.exe
[2011/08/09 15:15:57 | 000,422,400 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\KernelBase.dll
[2011/08/09 15:15:57 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wow64.dll
[2011/08/09 15:15:57 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\winsrv.dll
[2011/08/09 15:15:56 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wow64win.dll
[2011/08/09 15:15:56 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\setup16.exe
[2011/08/09 15:15:56 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntvdm64.dll
[2011/08/09 15:15:56 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntvdm64.dll
[2011/08/09 15:15:56 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wow64cpu.dll
[2011/08/09 15:15:54 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\wow32.dll
[2011/08/09 15:15:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2011/08/09 15:15:53 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/09 15:15:53 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2011/08/09 15:15:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2011/08/09 15:15:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2011/08/09 15:15:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/09 15:15:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2011/08/09 15:15:52 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/09 15:15:52 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2011/08/09 15:15:52 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/09 15:15:52 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/09 15:15:52 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2011/08/09 15:15:51 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/09 15:15:51 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2011/08/09 15:15:51 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/09 15:15:51 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/09 15:15:51 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2011/08/09 15:15:50 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2011/08/09 15:15:50 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2011/08/09 15:15:50 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/09 15:15:50 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/09 15:15:49 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/09 15:15:49 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/09 15:15:49 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/09 15:15:49 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/09 15:15:48 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2011/08/09 15:15:48 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/09 15:15:47 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2011/08/09 15:15:47 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2011/08/09 15:15:47 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/09 15:15:47 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2011/08/09 15:15:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/09 15:15:47 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2011/08/09 15:15:46 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2011/08/09 15:15:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2011/08/09 15:15:45 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\instnm.exe
[2011/08/09 15:15:45 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2011/08/09 15:15:44 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\user.exe
[2011/08/09 15:15:21 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\msfeeds.dll
[2011/08/09 15:15:20 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msfeeds.dll
[2011/08/09 15:15:17 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\url.dll
[2011/08/09 15:15:16 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\iepeers.dll
[2011/08/09 15:15:16 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieui.dll
[2011/08/09 15:15:16 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieui.dll
[2011/08/09 15:15:15 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\iepeers.dll
[2011/08/09 15:15:15 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\url.dll
[2011/08/09 15:15:15 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mshtmled.dll
[2011/08/09 15:15:15 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mshtmled.dll
[2011/08/09 15:15:13 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\licmgr10.dll
[2011/08/09 15:15:13 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\licmgr10.dll
[2011/08/09 15:15:11 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\html.iec
[2011/08/09 15:15:11 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\msfeedssync.exe
[2011/08/09 15:15:11 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msfeedssync.exe
[2011/08/09 15:15:10 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\html.iec
[2011/08/09 15:15:04 | 005,507,968 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntoskrnl.exe
[2011/08/09 15:15:03 | 003,957,120 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntkrnlpa.exe
[2011/08/09 15:15:01 | 003,902,336 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntoskrnl.exe
[2011/08/08 16:00:01 | 000,000,000 | —D | C] – C:\Users\Bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ruby 1.8.7-p352
[2011/08/08 15:59:45 | 000,000,000 | —D | C] – C:\Ruby187
[2011/08/04 22:13:49 | 000,000,000 | —D | C] – C:\Users\Bianca\AppData\Local\Ilivid Player
[2011/08/04 22:11:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\iLivid
[2011/08/02 11:44:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/07/26 12:10:09 | 000,000,000 | —D | C] – C:\Users\Bianca\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/07/18 22:08:42 | 000,000,000 | —D | C] – C:\Users\Bianca\AppData\Roaming\Spotify
[2011/07/18 22:08:42 | 000,000,000 | —D | C] – C:\Users\Bianca\AppData\Local\Spotify
[2011/07/18 22:08:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spotify
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/10 21:13:07 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Users\Bianca\Desktop\OTL.exe
[2011/08/10 21:13:04 | 000,015,792 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/08/10 21:13:04 | 000,015,792 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/08/10 21:04:21 | 000,000,908 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/10 21:03:48 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/08/10 21:03:42 | 3007,647,744 | -HS- | M] () – C:\hiberfil.sys
[2011/08/10 20:53:12 | 000,000,912 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/10 20:52:58 | 000,000,912 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-938898086-3655011318-2894540618-1001UA.job
[2011/08/10 20:52:58 | 000,000,860 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-938898086-3655011318-2894540618-1001Core.job
[2011/08/10 18:03:30 | 000,741,240 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/08/10 18:03:30 | 000,624,622 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/08/10 18:03:30 | 000,106,708 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/08/04 22:03:20 | 000,000,000 | -H– | M] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/07/18 22:08:31 | 000,001,002 | —- | M] () – C:\Users\Bianca\Desktop\Spotify.lnk
[2011/07/15 22:26:54 | 000,362,496 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\wow64win.dll
[2011/07/15 22:26:53 | 000,243,200 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\wow64.dll
[2011/07/15 22:26:53 | 000,013,312 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\wow64cpu.dll
[2011/07/15 22:26:18 | 000,214,528 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\winsrv.dll
[2011/07/15 22:24:09 | 000,016,384 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\ntvdm64.dll
[2011/07/15 22:21:32 | 001,162,240 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\kernel32.dll
[2011/07/15 22:21:32 | 000,422,400 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\KernelBase.dll
[2011/07/15 22:17:46 | 000,338,432 | —- | M] (Microsoft Corporation) – C:\windows\SysNative\conhost.exe
[2011/07/15 22:04:54 | 000,006,144 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2011/07/15 22:04:54 | 000,005,120 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2011/07/15 22:04:54 | 000,004,608 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2011/07/15 22:04:54 | 000,004,608 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2011/07/15 22:04:54 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/07/15 22:04:54 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2011/07/15 22:04:54 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2011/07/15 22:04:54 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2011/07/15 22:04:54 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2011/07/15 21:36:09 | 000,014,336 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\ntvdm64.dll
[2011/07/15 21:31:50 | 000,025,600 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\setup16.exe
[2011/07/15 21:30:29 | 000,005,120 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\wow32.dll
[2011/07/15 21:19:58 | 000,005,120 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2011/07/15 21:19:58 | 000,004,608 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2011/07/15 21:19:58 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/07/15 21:19:58 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2011/07/15 21:19:58 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2011/07/15 21:19:58 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2011/07/15 21:19:58 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2011/07/15 21:19:58 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2011/07/15 19:26:12 | 000,007,680 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\instnm.exe
[2011/07/15 19:26:11 | 000,002,048 | —- | M] (Microsoft Corporation) – C:\windows\SysWow64\user.exe
[2011/07/15 19:21:47 | 000,006,144 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2011/07/15 19:21:47 | 000,004,608 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2011/07/15 19:21:47 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2011/07/15 19:21:47 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2011/07/13 20:48:13 | 004,900,096 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/08/04 22:03:20 | 000,000,000 | -H– | C] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/07/18 22:08:31 | 000,001,032 | —- | C] () – C:\Users\Bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
[2011/07/18 22:08:31 | 000,001,002 | —- | C] () – C:\Users\Bianca\Desktop\Spotify.lnk
[2011/04/26 21:22:06 | 000,003,584 | —- | C] () – C:\Users\Bianca\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/25 15:58:02 | 000,030,424 | —- | C] () – C:\windows\SysWow64\wrLZMA.dll
[2011/03/12 22:36:12 | 000,731,106 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/03/11 10:24:37 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/04/30 11:17:38 | 000,870,560 | —- | C] () – C:\windows\SysWow64\igkrng575.bin
[2010/04/30 11:17:38 | 000,127,868 | —- | C] () – C:\windows\SysWow64\igcompkrng575.bin
[2010/04/30 11:17:38 | 000,104,636 | —- | C] () – C:\windows\SysWow64\igfcg575m.bin
[2010/04/30 10:42:24 | 000,208,896 | —- | C] () – C:\windows\SysWow64\iglhsip32.dll
[2010/04/30 10:42:24 | 000,143,360 | —- | C] () – C:\windows\SysWow64\iglhcp32.dll
[2009/07/13 22:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 19:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 19:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 17:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 14:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat
[2005/01/17 00:10:16 | 000,045,056 | —- | C] () – C:\windows\SysWow64\BRTCPCON.DLL
[2004/08/09 00:00:42 | 000,000,114 | —- | C] () – C:\windows\SysWow64\BRLMW03A.INI

========== LOP Check ==========

[2011/07/26 12:10:09 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/03 10:56:33 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/08/10 21:05:25 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\Dropbox
[2011/08/10 17:39:23 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\SoftGrid Client
[2011/08/10 17:29:52 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\Spotify
[2011/03/14 09:19:00 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\Toshiba
[2011/03/12 22:37:19 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\TP
[2011/03/08 21:24:09 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\WinBatch
[2011/04/19 12:40:24 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\Windows Live Writer
[2009/07/13 22:08:49 | 000,018,960 | —- | M] () – C:\windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/04/19 13:08:44 | 000,018,153 | —- | M] () – C:\1020.log
[2009/07/13 18:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/07/29 18:29:57 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/08/10 21:03:42 | 3007,647,744 | -HS- | M] () – C:\hiberfil.sys
[2011/08/10 21:03:43 | 4010,201,088 | -HS- | M] () – C:\pagefile.sys
[2 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/03/08 21:26:17 | 000,000,221 | -HS- | M] () – C:\Users\Bianca\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/08/10 21:13:07 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Users\Bianca\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >

~~~~
HijackThis
~~~~

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:23:58 PM, on 8/10/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16839)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Bianca\AppData\Local\Google\Update\1.3.21.65\GoogleCrashHandler.exe
C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Bianca\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [TOSDCR] "%ProgramFiles%\TOSHIBA\PasswordUtility\TOSDCR.exe"
O4 - HKLM\..\Run: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
O4 - HKLM\..\Run: [TSleepSrv] "%ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe"
O4 - HKLM\..\Run: [WebrootTrayApp] "C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe"
O4 - HKLM\..\Run: [BrStsMon00] "C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe" /AUTORUN
O4 - HKLM\..\Run: [BrStsMon01] "C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe" /AUTORUN
O4 - HKLM\..\Run: [SwitchBoard] "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Best Buy pc app] C:\Users\Bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy\Best Buy pc app.appref-ms
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Bianca\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] "C:\Windows\System32\StikyNot.exe"
O4 - .DEFAULT User Startup: Best Buy pc app.lnk = C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (User 'Default user')
O4 - Startup: Dropbox.lnk = Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs:
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe
O23 - Service: Intel® PROSet/Wireless WiMAX Red Bend Device Management Service (DMAgent) - Red Bend Ltd. - C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TOSHIBA HDD Protection (Thpsrv) - Unknown owner - C:\windows\system32\ThpSrv.exe (file missing)
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe
O23 - Service: Intel® PROSet/Wireless WiMAX Service (WiMAXAppSrv) - Intel® Corporation - C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe

–
End of file - 13840 bytes

~~~~
DDS
~~~~
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 8:43:50.82 on Thu 08/11/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3824.2218 [GMT -7:00]
.
AV: Webroot AntiVirus with Spy Sweeper *Enabled/Updated* {53211D91-0C31-95F2-E3A5-7661FB22889E}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Webroot AntiVirus with Spy Sweeper *Enabled/Updated* {E840FC75-2A0B-9A7C-D915-4D1380A5C223}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\WLANExt.exe
C:\windows\system32\conhost.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\ThpSrv.exe
C:\windows\system32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe
C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\windows\system32\wbem\unsecapp.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\notepad.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Toshiba\TECO\Teco.exe
C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe
C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\System32\StikyNot.exe
C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\windows\system32\igfxext.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Users\Bianca\AppData\Local\Google\Update\1.3.21.65\GoogleCrashHandler.exe
C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe
C:\windows\system32\igfxsrvc.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Browny02\BrYNSvc.exe
C:\windows\system32\wbem\unsecapp.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\taskmgr.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\SSU.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\windows\system32\NOTEPAD.EXE
C:\windows\system32\NOTEPAD.EXE
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\windows\servicing\TrustedInstaller.exe
C:\windows\system32\NOTEPAD.EXE
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\Users\Bianca\Desktop\dds.scr
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.com/ig?brand=TSND&bmod=TSND
uDefault_Page_URL = hxxp://www.google.com/ig?brand=TSND&bmod=TSND
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: TOSHIBA Media Controller Plug-in: {f3c88694-effa-4d78-b409-54b7b2535b14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [Best Buy pc app] C:\Users\Bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy\Best Buy pc app.appref-ms
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [Google Update] "C:\Users\Bianca\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [RESTART_STICKY_NOTES] "C:\Windows\System32\StikyNot.exe"
mRun: [TOSDCR] "%ProgramFiles%\TOSHIBA\PasswordUtility\TOSDCR.exe"
mRun: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
mRun: [TSleepSrv] "%ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe"
mRun: [WebrootTrayApp] "C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe"
mRun: [BrStsMon00] "C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe" /AUTORUN
mRun: [BrStsMon01] "C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe" /AUTORUN
mRun: [SwitchBoard] "C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe"
mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: []
mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
StartupFolder: C:\Users\Bianca\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000
IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs:
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
TB-X64: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
mRun-x64: [(Default)]
mRun-x64: [IgfxTray] "C:\windows\system32\igfxtray.exe"
mRun-x64: [HotKeysCmds] "C:\windows\system32\hkcmd.exe"
mRun-x64: [Persistence] "C:\windows\system32\igfxpers.exe"
mRun-x64: [RtHDVCpl] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [IntelWirelessWiMAX] "C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe" /tasktray /nosplash
mRun-x64: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun-x64: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun-x64: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun-x64: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun-x64: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
mRun-x64: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun-x64: [TosSENotify] "C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe"
mRun-x64: [ThpSrv] "C:\windows\system32\thpsrv" /logon
mRun-x64: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
mRun-x64: [TosVolRegulator] "C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe"
mRun-x64: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
mRun-x64: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
mRun-x64: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
AppInit_DLLs-X64:
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Bianca\AppData\Roaming\Mozilla\Firefox\Profiles\2c5mqxwn.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q=
FF - component: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn\components\WCFirefoxExtn.dll
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Bianca\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: C:\Users\Bianca\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Bianca\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Adobe Acrobat - Create PDF: [removed] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
.
============= SERVICES / DRIVERS ===============
.
R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\Windows\System32\drivers\thpdrv.sys [2009-6-29 34880]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\Windows\System32\drivers\Thpevm.sys [2009-6-29 14784]
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\Windows\System32\drivers\tos_sps64.sys [2010-11-22 482384]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-2-28 821664]
R2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [2010-6-7 408576]
R2 risdpcie;risdpcie;C:\Windows\System32\drivers\risdpe64.sys [2010-11-22 81920]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-4-24 483688]
R2 ssfmonm;ssfmonm;C:\Windows\System32\drivers\ssfmonm.sys [2011-4-25 56920]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\Toshiba\TECO\TecoService.exe [2010-4-23 259440]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\Windows\System32\drivers\TVALZFL.sys [2009-6-19 14472]
R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-11-22 2320920]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\AEI.exe [2011-4-25 3996864]
R2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [2010-6-7 911872]
R2 WRConsumerService;Webroot Client Service;C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe [2011-8-8 3381184]
R3 bpenum;bpenum;C:\Windows\System32\drivers\bpenum.sys [2010-5-16 71168]
R3 bpmp;Intel® Centrino® WiMAX 6050 Series;C:\Windows\System32\drivers\bpmp.sys [2010-5-16 175104]
R3 bpusb;bpusb;C:\Windows\System32\drivers\bpusb.sys [2010-5-16 81920]
R3 BrYNSvc;BrYNSvc;C:\Program Files (x86)\Browny02\BrYNSvc.exe [2011-5-25 245760]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;C:\Windows\System32\drivers\e1k62x64.sys [2010-11-22 295088]
R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-11-22 56344]
R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-2-26 158976]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-2-3 271872]
R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETwNs64.sys [2010-10-18 8153088]
R3 PGEffect;Pangu effect driver;C:\Windows\System32\drivers\PGEffect.sys [2010-11-22 35008]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2010-4-24 721768]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2010-4-24 269672]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2010-4-24 25960]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2010-4-24 22376]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-4-24 209768]
R3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-11-22 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-2-5 137560]
R3 TPCHSrv;TPCH Service;C:\Program Files\Toshiba\TPHM\TPCHSrv.exe [2010-5-10 836016]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-13 17920]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2010-6-18 39832]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-29 136176]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-29 136176]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-10-19 340240]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-2-24 78336]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-2-24 181248]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-3-10 1255736]
.
=============== Created Last 30 ================
.
2011-08-11 04:32:42 ——– d—–w- C:\_OTL
2011-08-11 00:49:47 ——– d—–w- C:\PROGRA~3\boost_interprocess
2011-08-09 22:15:58 338432 —-a-w- C:\windows\System32\conhost.exe
2011-08-09 22:10:49 8578896 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{FF23A8F3-2C66-4A01-8870-8EB509C1FBB4}\mpengine.dll
2011-08-08 22:59:45 ——– d—–w- C:\Ruby187
2011-08-05 05:13:49 ——– d—–w- C:\Users\Bianca\AppData\Local\Ilivid Player
2011-08-05 05:11:45 ——– d—–w- C:\Program Files (x86)\iLivid
2011-07-26 19:10:09 ——– d—–w- C:\Users\Bianca\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-07-19 05:08:42 ——– d—–w- C:\Users\Bianca\AppData\Roaming\Spotify
2011-07-19 05:08:42 ——– d—–w- C:\Users\Bianca\AppData\Local\Spotify
2011-07-19 05:08:24 ——– d—–w- C:\Program Files (x86)\Spotify
2011-07-13 16:07:17 3134464 —-a-w- C:\windows\System32\win32k.sys
.
==================== Find3M ====================
.
2011-07-22 05:35:08 1638912 —-a-w- C:\windows\System32\mshtml.tlb
2011-07-22 04:56:17 1638912 —-a-w- C:\windows\SysWow64\mshtml.tlb
2011-07-16 05:26:54 362496 —-a-w- C:\windows\System32\wow64win.dll
2011-07-16 05:26:53 243200 —-a-w- C:\windows\System32\wow64.dll
2011-07-16 05:26:53 13312 —-a-w- C:\windows\System32\wow64cpu.dll
2011-07-16 05:26:18 214528 —-a-w- C:\windows\System32\winsrv.dll
2011-07-16 05:24:09 16384 —-a-w- C:\windows\System32\ntvdm64.dll
2011-07-16 05:21:32 422400 —-a-w- C:\windows\System32\KernelBase.dll
2011-07-16 04:36:09 14336 —-a-w- C:\windows\SysWow64\ntvdm64.dll
2011-07-16 04:32:14 44032 —-a-w- C:\windows\apppatch\acwow64.dll
2011-07-16 04:31:50 25600 —-a-w- C:\windows\SysWow64\setup16.exe
2011-07-16 04:30:29 5120 —-a-w- C:\windows\SysWow64\wow32.dll
2011-07-16 04:30:27 272384 —-a-w- C:\windows\SysWow64\KernelBase.dll
2011-07-16 02:26:12 7680 —-a-w- C:\windows\SysWow64\instnm.exe
2011-07-16 02:26:11 2048 —-a-w- C:\windows\SysWow64\user.exe
2011-07-16 02:21:47 6144 —ha-w- C:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:21:47 4608 —ha-w- C:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:21:47 3584 —ha-w- C:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:21:47 3072 —ha-w- C:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-07-11 17:07:54 136224 —-a-w- C:\windows\System32\drivers\ssidrv.sys
2011-07-11 17:07:50 56920 —-a-w- C:\windows\System32\drivers\ssfmonm.sys
2011-07-09 02:44:55 287744 —-a-w- C:\windows\System32\drivers\mrxsmb10.sys
2011-06-23 05:29:39 5507968 —-a-w- C:\windows\System32\ntoskrnl.exe
2011-06-23 04:38:05 3957120 —-a-w- C:\windows\SysWow64\ntkrnlpa.exe
2011-06-23 04:38:04 3902336 —-a-w- C:\windows\SysWow64\ntoskrnl.exe
2011-06-21 06:27:14 1896832 —-a-w- C:\windows\System32\drivers\tcpip.sys
2011-06-21 06:20:48 1197056 —-a-w- C:\windows\System32\wininet.dll
2011-06-21 06:20:06 57856 —-a-w- C:\windows\System32\licmgr10.dll
2011-06-21 05:36:36 981504 —-a-w- C:\windows\SysWow64\wininet.dll
2011-06-21 05:35:05 44544 —-a-w- C:\windows\SysWow64\licmgr10.dll
2011-06-21 05:05:13 482816 —-a-w- C:\windows\System32\html.iec
2011-06-21 04:26:02 386048 —-a-w- C:\windows\SysWow64\html.iec
2011-06-15 09:58:31 212992 —-a-w- C:\windows\System32\odbctrac.dll
2011-06-15 09:58:31 163840 —-a-w- C:\windows\System32\odbccp32.dll
2011-06-15 09:58:31 106496 —-a-w- C:\windows\System32\odbccu32.dll
2011-06-15 09:58:31 106496 —-a-w- C:\windows\System32\odbccr32.dll
2011-06-15 09:04:46 86016 —-a-w- C:\windows\SysWow64\odbccu32.dll
2011-06-15 09:04:46 81920 —-a-w- C:\windows\SysWow64\odbccr32.dll
2011-06-15 09:04:46 319488 —-a-w- C:\windows\SysWow64\odbcjt32.dll
2011-06-15 09:04:46 163840 —-a-w- C:\windows\SysWow64\odbctrac.dll
2011-06-15 09:04:46 122880 —-a-w- C:\windows\SysWow64\odbccp32.dll
2011-05-25 02:14:10 270720 ——w- C:\windows\System32\MpSigStub.exe
2011-05-24 11:21:59 404992 —-a-w- C:\windows\System32\umpnpmgr.dll
2011-05-24 10:34:20 64512 —-a-w- C:\windows\SysWow64\devobj.dll
2011-05-24 10:34:20 44544 —-a-w- C:\windows\SysWow64\devrtl.dll
2011-05-24 10:34:00 145920 —-a-w- C:\windows\SysWow64\cfgmgr32.dll
2011-05-24 10:32:46 252928 —-a-w- C:\windows\SysWow64\drvinst.exe
.
============= FINISH: 8:45:38.64 ===============
Hi,

Please do the following:


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2011/08/04 22:13:49 | 000,000,000 | —D | C] – C:\Users\Bianca\AppData\Local\Ilivid Player
    [2011/08/04 22:11:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\iLivid
    O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4:64bit: - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [] File not found
    O33 - MountPoints2\{9e0f7209-6aa3-11e0-8af0-002318bbd495}\Shell - "" = AutoRun
    O33 - MountPoints2\{9e0f7209-6aa3-11e0-8af0-002318bbd495}\Shell\AutoRun\command - "" = E:\TL-Bootstrap.exe
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log



NEXT



Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
Hi CatByte, Thanks so much for your response and for your help. I'm running OTL.exe right now and in the middle of the running the fix, it seems to be stuck on the reset hosts section. About two minutes after getting to that section I had an error message pop up that said "cannot write to c:\…hosts file"(Sorry, I realize in retrospect I should've written down the path). There was only an OK button, so I clicked it, and now OTL just seems to but stuck on Resetting Hosts and has been for over an hour. Task Manager seems to think the application is running - should I just relax and let it keep running? Sorry for all the trouble. Thanks!!
I ran ComboFix but it keeps getting stuck after "Completed Stage_4". I've let it run for over 1+ hours a couple of times. I did reboot, and then got this log from OTL: Files\Folders moved on Reboot… C:\windows\System32\drivers\etc\Hosts moved successfully. Registry entries deleted on Reboot… ————————————————– Thanks again for the help.
Please try running ComboFix in safe mode:

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY repeatedly,
  • this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
  • go into your usual account
OK, phew, I was able to run ComboFix in safe mode with no problem. Thank you! Here is the log: ComboFix 11-08-15.08 - Bianca 08/16/2011 8:34.5.4 - x64 MINIMAL Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3824.2782 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {53211D91-0C31-95F2-E3A5-7661FB22889E} SP: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {E840FC75-2A0B-9A7C-D915-4D1380A5C223} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Browny02\Brother\BrStMonW.exe c:\programdata\Roaming . . ((((((((((((((((((((((((( Files Created from 2011-07-16 to 2011-08-16 ))))))))))))))))))))))))))))))) . . 2011-08-12 16:17 . 2011-07-13 04:53 8578896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{764B996C-D401-40CC-9484-2A64B4AD189E}\mpengine.dll 2011-08-11 04:32 . 2011-08-11 04:32 ——– d—–w- C:\_OTL 2011-08-11 00:49 . 2011-08-11 01:21 ——– d—–w- c:\programdata\boost_interprocess 2011-08-08 22:59 . 2011-08-08 23:00 ——– d—–w- C:\Ruby187 2011-07-26 19:10 . 2011-07-26 19:10 ——– d—–w- c:\users\Bianca\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2011-07-19 05:08 . 2011-08-11 00:29 ——– d—–w- c:\users\Bianca\AppData\Roaming\Spotify 2011-07-19 05:08 . 2011-07-27 14:55 ——– d—–w- c:\users\Bianca\AppData\Local\Spotify 2011-07-19 05:08 . 2011-07-19 05:08 ——– d—–w- c:\program files (x86)\Spotify . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-07-16 04:32 . 2011-08-09 22:15 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2011-07-16 04:30 . 2011-08-09 22:15 5120 —-a-w- c:\windows\SysWow64\wow32.dll 2011-07-11 17:07 . 2011-04-25 22:57 136224 —-a-w- c:\windows\system32\drivers\ssidrv.sys 2011-07-11 17:07 . 2011-04-25 22:57 56920 —-a-w- c:\windows\system32\drivers\ssfmonm.sys 2011-06-21 05:36 . 2011-08-09 22:15 981504 —-a-w- c:\windows\SysWow64\wininet.dll 2011-06-11 02:56 . 2011-07-13 16:07 3134464 —-a-w- c:\windows\system32\win32k.sys 2011-05-25 02:14 . 2011-03-09 04:38 270720 ——w- c:\windows\system32\MpSigStub.exe 2011-05-24 11:21 . 2011-06-29 16:19 404992 —-a-w- c:\windows\system32\umpnpmgr.dll 2011-05-24 10:34 . 2011-06-29 16:19 64512 —-a-w- c:\windows\SysWow64\devobj.dll 2011-05-24 10:34 . 2011-06-29 16:19 44544 —-a-w- c:\windows\SysWow64\devrtl.dll 2011-05-24 10:34 . 2011-06-29 16:19 145920 —-a-w- c:\windows\SysWow64\cfgmgr32.dll 2011-05-24 10:32 . 2011-06-29 16:19 252928 —-a-w- c:\windows\SysWow64\drvinst.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-07-30 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "TOSDCR"="c:\program files (x86)\TOSHIBA\PasswordUtility\TOSDCR.exe" [2007-08-28 169296] "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-05-02 2454840] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136] "WebrootTrayApp"="c:\program files (x86)\Webroot\Security\Current\Framework\WRTray.exe" [2011-08-09 1382984] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-10-25 932288] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2010-10-25 36760] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2010-10-25 821144] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736] . c:\users\Bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2010-6-24 9216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService] @="Service" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-30 136176] R3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe [2010-01-25 245760] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-30 136176] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-10-19 340240] R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x] R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [x] S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x] S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664] S2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [2010-06-07 408576] S2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe64.sys [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-04-24 483688] S2 ssfmonm;ssfmonm;c:\windows\system32\DRIVERS\ssfmonm.sys [x] S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-04-24 259440] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920] S2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2010-06-07 911872] S2 WRConsumerService;Webroot Client Service;c:\program files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe [2011-08-09 3381184] S3 bpenum;bpenum;c:\windows\system32\DRIVERS\bpenum.sys [x] S3 bpmp;Intel® Centrino® WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [x] S3 bpusb;bpusb;c:\windows\system32\Drivers\bpusb.sys [x] S3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-04-24 209768] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-06 137560] S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-05-11 836016] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-08-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-30 01:28] . 2011-08-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-30 01:28] . 2011-08-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-938898086-3655011318-2894540618-1001Core.job - c:\users\Bianca\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-11 01:28] . 2011-08-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-938898086-3655011318-2894540618-1001UA.job - c:\users\Bianca\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-11 01:28] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Bianca\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ThpSrv"="c:\windows\system32\thpsrv" [X] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-05-12 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-05-12 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-05-12 414744] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-07 10144288] "IntelWirelessWiMAX"="c:\program files\Intel\WiMAX\Bin\WiMAXCU.exe" [2010-06-08 1441792] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-06 709976] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-10-19 1931024] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ig?brand=TSND&bmod=TSND uDefault_Search_URL = hxxp://www.google.com/ie mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html IE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = [removed] [removed] FF - ProfilePath - c:\users\Bianca\AppData\Roaming\Mozilla\Firefox\Profiles\2c5mqxwn.default\ FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Adobe Acrobat - Create PDF: [removed] - c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe Wow6432Node-HKLM-Run-TSleepSrv - %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe Wow6432Node-HKLM-Run-BrStsMon00 - c:\program files (x86)\Browny02\Brother\BrStMonW.exe Wow6432Node-HKLM-Run-BrStsMon01 - c:\program files (x86)\Browny02\Brother\BrStMonW.exe HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-938898086-3655011318-2894540618-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-938898086-3655011318-2894540618-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe . ************************************************************************** . Completion time: 2011-08-16 08:48:21 - machine was rebooted ComboFix-quarantined-files.txt 2011-08-16 15:48 . Pre-Run: 433,895,743,488 bytes free Post-Run: 433,521,430,528 bytes free . - - End Of File - - E8D64F76F52B17E238F6498E6C740A16
Hi,

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
I ran both programs, no threats were found in either, so no log generated for ESET. Here is the log for MBAM: Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7479 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 8/16/2011 9:12:12 AM mbam-log-2011-08-16 (09-12-12).txt Scan type: Quick scan Objects scanned: 174527 Time elapsed: 1 minute(s), 56 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi

Please do the following:

[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 20 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


Clear Java cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT



Please post a fresh OTL Log and advise how your computer is running now and if there are any outstanding issues
Everything seems to working fine, I had a weird startup issue from hibernation where my computer seemed to get stuck going into hibernation so I had to do a hard reboot but that's happened once or twice before.

Thanks so much for all the help and the effort, I really appreciate. I think my computer is clean now but let me know if you see any issues in the OTL log below.

Thank you!

OTL logfile created on: 8/16/2011 5:37:48 PM - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\Bianca\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.73 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 51.87% Memory free
7.47 Gb Paging File | 5.58 Gb Available in Paging File | 74.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 454.39 Gb Total Space | 404.28 Gb Free Space | 88.97% Space Free | Partition Type: NTFS

Computer Name: BIANCA-PC | User Name: Bianca | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Bianca\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe (Webroot Software, Inc. )
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files (x86)\Webroot\Security\Current\plugins\antimalware\SSU.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Users\Bianca\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe (Google)
PRC - C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Bianca\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (TosCoSrv) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WiMAXAppSrv) – C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe (Intel® Corporation)
SRV:64bit: - (DMAgent) – C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe (Red Bend Ltd.)
SRV:64bit: - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (Thpsrv) – C:\Windows\SysNative\ThpSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WRConsumerService) – C:\Program Files (x86)\Webroot\Security\Current\Framework\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (WebrootSpySweeperService) – C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (BrYNSvc) – C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (TMachInfo) – C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (ssidrv) – C:\Windows\SysNative\drivers\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (ssfmonm) – C:\Windows\SysNative\drivers\ssfmonm.sys (Webroot Software, Inc. (www.webroot.com))
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (NETwNs64) ___ Intel® – C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (wdkmd) – C:\Windows\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (bpmp) Intel® Centrino® – C:\Windows\SysNative\drivers\bpmp.sys (Intel Corporation)
DRV:64bit: - (bpusb) – C:\Windows\SysNative\drivers\bpusb.sys (Intel Corporation)
DRV:64bit: - (bpenum) – C:\Windows\SysNative\drivers\bpenum.sys (Intel Corporation)
DRV:64bit: - (tos_sps64) – C:\Windows\SysNative\drivers\tos_sps64.sys (TOSHIBA Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (risdpcie) – C:\Windows\SysNative\drivers\risdpe64.sys (REDC)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation)
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (e1kexpress) Intel® – C:\Windows\SysNative\drivers\e1k62x64.sys (Intel Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (tdcmdpst) – C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (TVALZ) – C:\Windows\SysNative\drivers\TVALZ.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (Thpevm) – C:\Windows\SysNative\drivers\Thpevm.sys (TOSHIBA Corporation)
DRV:64bit: - (Thpdrv) – C:\Windows\SysNative\drivers\thpdrv.sys (TOSHIBA Corporation)
DRV:64bit: - (PGEffect) – C:\Windows\SysNative\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV:64bit: - (TVALZFL) – C:\Windows\SysNative\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (Ser2pl) – C:\Windows\SysNative\drivers\ser2pl64.sys (Prolific Technology Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…D&bmod=TSND

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://start.toshiba.com/g/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig?brand=TSND&bmod=TSND
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q="

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Bianca\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Bianca\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Bianca\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Bianca\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/06/03 14:01:13 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/22 11:00:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/06/22 11:00:52 | 000,000,000 | —D | M]

[2011/08/10 17:57:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Bianca\AppData\Roaming\Mozilla\Extensions
[2011/08/10 19:31:34 | 000,000,000 | —D | M] (No name found) – C:\Users\Bianca\AppData\Roaming\Mozilla\Firefox\Profiles\2c5mqxwn.default\extensions
[2011/08/04 22:10:09 | 000,002,501 | —- | M] () – C:\Users\Bianca\AppData\Roaming\Mozilla\Firefox\Profiles\2c5mqxwn.default\searchplugins\SearchResults.xml
[2011/08/10 17:57:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/06/09 14:05:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/06/03 14:01:13 | 000,000,000 | —D | M] (Adobe Acrobat - Create PDF) – C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 10.0\ACROBAT\BROWSER\WCFIREFOXEXTN
[2011/08/04 22:10:09 | 000,002,501 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\SearchResults.xml

O1 HOSTS File: ([2011/08/16 14:37:31 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll ()
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [IntelWirelessWiMAX] C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [ThpSrv] C:\windows\SysNative\thpsrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\Toshiba\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] File not found
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TOSDCR] C:\Program Files (x86)\TOSHIBA\PasswordUtility\TOSDCR.exe ()
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [WebrootTrayApp] C:\Program Files (x86)\Webroot\Security\Current\Framework\WRTray.exe (Webroot Software, Inc. )
O4 - Startup: C:\Users\Bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Bianca\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll (Google Inc.)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/08/16 09:20:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/08/16 09:09:38 | 000,000,000 | —D | C] – C:\Users\Bianca\AppData\Roaming\Malwarebytes
[2011/08/16 09:09:27 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\windows\SysWow64\drivers\mbamswissarmy.sys
[2011/08/16 09:09:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/08/16 09:09:27 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/08/16 09:09:24 | 000,025,912 | —- | C] (Malwarebytes Corporation) – C:\windows\SysNative\drivers\mbam.sys
[2011/08/16 09:09:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/08/16 08:42:17 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/08/15 17:44:13 | 000,518,144 | —- | C] (SteelWerX) – C:\windows\SWREG.exe
[2011/08/15 17:44:13 | 000,060,416 | —- | C] (NirSoft) – C:\windows\NIRCMD.exe
[2011/08/15 17:44:12 | 000,406,528 | —- | C] (SteelWerX) – C:\windows\SWSC.exe
[2011/08/15 17:43:51 | 000,000,000 | —D | C] – C:\windows\ERDNT
[2011/08/15 17:41:34 | 000,000,000 | —D | C] – C:\Qoobox
[2011/08/15 17:38:43 | 004,173,282 | R— | C] (Swearware) – C:\Users\Bianca\Desktop\ComboFix.exe
[2011/08/10 21:32:42 | 000,000,000 | —D | C] – C:\_OTL
[2011/08/10 21:28:41 | 001,915,904 | —- | C] (AVAST Software) – C:\Users\Bianca\Desktop\aswMBR.exe
[2011/08/10 21:22:10 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Bianca\Desktop\HiJackThis.exe
[2011/08/10 21:13:04 | 000,579,584 | —- | C] (OldTimer Tools) – C:\Users\Bianca\Desktop\OTL.exe
[2011/08/10 17:49:47 | 000,000,000 | —D | C] – C:\ProgramData\boost_interprocess
[2011/08/09 15:16:15 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\xmllite.dll
[2011/08/09 15:16:13 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\odbccp32.dll
[2011/08/09 15:16:13 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\odbccu32.dll
[2011/08/09 15:16:13 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\odbccr32.dll
[2011/08/09 15:16:12 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\odbcjt32.dll
[2011/08/09 15:16:12 | 000,212,992 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\odbctrac.dll
[2011/08/09 15:16:12 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\odbccp32.dll
[2011/08/09 15:16:12 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\odbccr32.dll
[2011/08/09 15:16:11 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\odbctrac.dll
[2011/08/09 15:16:11 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\odbccu32.dll
[2011/08/09 15:15:58 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\kernel32.dll
[2011/08/09 15:15:58 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\conhost.exe
[2011/08/09 15:15:57 | 000,422,400 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\KernelBase.dll
[2011/08/09 15:15:57 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wow64.dll
[2011/08/09 15:15:57 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\winsrv.dll
[2011/08/09 15:15:56 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wow64win.dll
[2011/08/09 15:15:56 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\setup16.exe
[2011/08/09 15:15:56 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntvdm64.dll
[2011/08/09 15:15:56 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntvdm64.dll
[2011/08/09 15:15:56 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wow64cpu.dll
[2011/08/09 15:15:54 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\wow32.dll
[2011/08/09 15:15:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2011/08/09 15:15:53 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/09 15:15:53 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2011/08/09 15:15:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2011/08/09 15:15:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2011/08/09 15:15:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/09 15:15:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2011/08/09 15:15:52 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/09 15:15:52 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2011/08/09 15:15:52 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/09 15:15:52 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/09 15:15:52 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2011/08/09 15:15:51 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/09 15:15:51 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2011/08/09 15:15:51 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/09 15:15:51 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/09 15:15:51 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2011/08/09 15:15:50 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2011/08/09 15:15:50 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2011/08/09 15:15:50 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/09 15:15:50 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/09 15:15:49 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/09 15:15:49 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/09 15:15:49 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/09 15:15:49 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/09 15:15:49 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/09 15:15:48 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2011/08/09 15:15:48 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/09 15:15:48 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/09 15:15:47 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2011/08/09 15:15:47 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2011/08/09 15:15:47 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/09 15:15:47 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2011/08/09 15:15:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/09 15:15:47 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2011/08/09 15:15:46 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2011/08/09 15:15:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2011/08/09 15:15:45 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\instnm.exe
[2011/08/09 15:15:45 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2011/08/09 15:15:44 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\user.exe
[2011/08/09 15:15:21 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\msfeeds.dll
[2011/08/09 15:15:20 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msfeeds.dll
[2011/08/09 15:15:17 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\url.dll
[2011/08/09 15:15:16 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\iepeers.dll
[2011/08/09 15:15:16 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieui.dll
[2011/08/09 15:15:16 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieui.dll
[2011/08/09 15:15:15 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\iepeers.dll
[2011/08/09 15:15:15 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\url.dll
[2011/08/09 15:15:15 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mshtmled.dll
[2011/08/09 15:15:15 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mshtmled.dll
[2011/08/09 15:15:13 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\licmgr10.dll
[2011/08/09 15:15:13 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\licmgr10.dll
[2011/08/09 15:15:11 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\html.iec
[2011/08/09 15:15:11 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\msfeedssync.exe
[2011/08/09 15:15:11 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msfeedssync.exe
[2011/08/09 15:15:10 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\html.iec
[2011/08/09 15:15:04 | 005,507,968 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntoskrnl.exe
[2011/08/09 15:15:03 | 003,957,120 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntkrnlpa.exe
[2011/08/09 15:15:01 | 003,902,336 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntoskrnl.exe
[2011/08/08 16:00:01 | 000,000,000 | —D | C] – C:\Users\Bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ruby 1.8.7-p352
[2011/08/08 15:59:45 | 000,000,000 | —D | C] – C:\Ruby187
[2011/08/02 11:44:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/07/26 12:10:09 | 000,000,000 | —D | C] – C:\Users\Bianca\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/07/18 22:08:42 | 000,000,000 | —D | C] – C:\Users\Bianca\AppData\Roaming\Spotify
[2011/07/18 22:08:42 | 000,000,000 | —D | C] – C:\Users\Bianca\AppData\Local\Spotify
[2011/07/18 22:08:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spotify
[2 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/16 17:41:56 | 000,015,792 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/08/16 17:41:56 | 000,015,792 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/08/16 17:38:00 | 000,000,912 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/16 17:32:24 | 000,000,908 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/16 17:31:54 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/08/16 17:31:52 | 3007,647,744 | -HS- | M] () – C:\hiberfil.sys
[2011/08/16 17:05:23 | 000,000,912 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-938898086-3655011318-2894540618-1001UA.job
[2011/08/16 14:37:31 | 000,000,027 | —- | M] () – C:\windows\SysNative\drivers\etc\hosts
[2011/08/16 09:09:27 | 000,001,120 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/15 20:45:00 | 000,000,860 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-938898086-3655011318-2894540618-1001Core.job
[2011/08/15 20:24:10 | 000,727,182 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/08/15 20:24:10 | 000,624,622 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/08/15 20:24:10 | 000,106,708 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/08/15 17:39:00 | 004,173,282 | R— | M] (Swearware) – C:\Users\Bianca\Desktop\ComboFix.exe
[2011/08/10 21:29:36 | 001,915,904 | —- | M] (AVAST Software) – C:\Users\Bianca\Desktop\aswMBR.exe
[2011/08/10 21:24:57 | 000,625,664 | —- | M] () – C:\Users\Bianca\Desktop\dds.scr
[2011/08/10 21:22:13 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Bianca\Desktop\HiJackThis.exe
[2011/08/10 21:13:07 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Users\Bianca\Desktop\OTL.exe
[2011/08/04 22:03:20 | 000,000,000 | -H– | M] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/07/18 22:08:31 | 000,001,002 | —- | M] () – C:\Users\Bianca\Desktop\Spotify.lnk
[2 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/08/16 09:09:27 | 000,001,120 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/15 17:44:13 | 000,256,000 | —- | C] () – C:\windows\PEV.exe
[2011/08/15 17:44:13 | 000,208,896 | —- | C] () – C:\windows\MBR.exe
[2011/08/15 17:44:12 | 000,098,816 | —- | C] () – C:\windows\sed.exe
[2011/08/15 17:44:12 | 000,080,412 | —- | C] () – C:\windows\grep.exe
[2011/08/15 17:44:12 | 000,068,096 | —- | C] () – C:\windows\zip.exe
[2011/08/10 21:24:54 | 000,625,664 | —- | C] () – C:\Users\Bianca\Desktop\dds.scr
[2011/08/04 22:03:20 | 000,000,000 | -H– | C] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/07/18 22:08:31 | 000,001,032 | —- | C] () – C:\Users\Bianca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
[2011/07/18 22:08:31 | 000,001,002 | —- | C] () – C:\Users\Bianca\Desktop\Spotify.lnk
[2011/04/26 21:22:06 | 000,003,584 | —- | C] () – C:\Users\Bianca\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/25 15:58:02 | 000,030,424 | —- | C] () – C:\windows\SysWow64\wrLZMA.dll
[2011/03/12 22:36:12 | 000,731,106 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/03/11 10:24:37 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/04/30 11:17:38 | 000,870,560 | —- | C] () – C:\windows\SysWow64\igkrng575.bin
[2010/04/30 11:17:38 | 000,127,868 | —- | C] () – C:\windows\SysWow64\igcompkrng575.bin
[2010/04/30 11:17:38 | 000,104,636 | —- | C] () – C:\windows\SysWow64\igfcg575m.bin
[2010/04/30 10:42:24 | 000,208,896 | —- | C] () – C:\windows\SysWow64\iglhsip32.dll
[2010/04/30 10:42:24 | 000,143,360 | —- | C] () – C:\windows\SysWow64\iglhcp32.dll
[2009/07/13 22:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 19:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 19:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 17:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 14:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat
[2005/01/17 00:10:16 | 000,045,056 | —- | C] () – C:\windows\SysWow64\BRTCPCON.DLL
[2004/08/09 00:00:42 | 000,000,114 | —- | C] () – C:\windows\SysWow64\BRLMW03A.INI

========== LOP Check ==========

[2011/07/26 12:10:09 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/03 10:56:33 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/08/16 17:33:34 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\Dropbox
[2011/08/16 11:51:05 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\SoftGrid Client
[2011/08/10 17:29:52 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\Spotify
[2011/03/14 09:19:00 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\Toshiba
[2011/03/12 22:37:19 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\TP
[2011/03/08 21:24:09 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\WinBatch
[2011/04/19 12:40:24 | 000,000,000 | —D | M] – C:\Users\Bianca\AppData\Roaming\Windows Live Writer
[2009/07/13 22:08:49 | 000,020,460 | —- | M] () – C:\windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/04/19 13:08:44 | 000,018,153 | —- | M] () – C:\1020.log
[2009/07/13 18:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/07/29 18:29:57 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/08/16 08:48:21 | 000,021,802 | —- | M] () – C:\ComboFix.txt
[2011/08/16 17:31:52 | 3007,647,744 | -HS- | M] () – C:\hiberfil.sys
[2011/08/16 17:31:52 | 4010,201,088 | -HS- | M] () – C:\pagefile.sys
[2 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/03/08 21:26:17 | 000,000,221 | -HS- | M] () – C:\Users\Bianca\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/08/10 21:29:36 | 001,915,904 | —- | M] (AVAST Software) – C:\Users\Bianca\Desktop\aswMBR.exe
[2011/08/15 17:39:00 | 004,173,282 | R— | M] (Swearware) – C:\Users\Bianca\Desktop\ComboFix.exe
[2011/08/10 21:22:13 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Bianca\Desktop\HiJackThis.exe
[2011/08/10 21:13:07 | 000,579,584 | —- | M] (OldTimer Tools) – C:\Users\Bianca\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
Hi,

Make sure you use the Temp File Cleaner (TFC) that I am linking you to below, try a defrag, that might help with the odd hibernation behaviour

First open an elevated Command Prompt
  • Go to Start > All Programs > Accessories
  • right click on the Command Prompt and choose “Run as administrator”
  • Type the following see how much your hard drive is fragmented (in this example, your C:\ drive):
  • defrag c: -a
  • Vista will tell you a “Percent file fragmentation” and, at the bottom, if you need to defragment the drive or not.
  • To fully defragment your C:\ drive type the following:
  • defrag c: -w
  • Give it time to run (best to leave the computer alone) and then you’re done!

NEXT


we have some housekeeping to do, please do the following:



You can delete the aswMBR logs and program from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT



Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.



If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Hi, I defragmented my hard drive and uninstalled and deleted the applications and logs per your instructions. I also followed the additional housekeeping instructions and appreciate the links to the various resources online. Thank you very much for the time and effort in helping me to resolve my issue. You and this forum are a fantastic resource!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI