This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Please help me to remove Rapid Antivirus

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

First of all sorry for my english.

Now i will try to discribe my problems.
First my pc during short time turns off, but not like shut down or restart the pc just turns the blue window, in wich is showing that on pc there some viruses, and malwares, and i need to upgrade my antivirus programme, and remove rapid antivirus, and after showing this window for 10secundes, the windows starts again, showing that there is rapid antivirus unregistred.
Also i have problem that windows security centre recomends to turn on the automatic updates, but when i'm opening automatic updates windows, it shows that these updates are turn on.
And the last problem, on my desktop i have gay porn site icon, which i can't delete, if i delete it it will restart again.

To fix these problems i used ad-aware scan and removed all detected things, also i have legal kaspersky antivirus 2009.
I hope that you understood what i whanted to say, and i hope that somebody will help me to remove rapid antivirus.

And here is my hijakthis file:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:27:33, on 19/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\WINDOWS\system32\thpsrv.exe
C:\Program Files\TOSHIBA\Controls\VolumeIndicator.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ThpSrv.exe
C:\WINDOWS\system32\TODDSrv.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
E:\PhoneConnectorVMC.exe
E:\vmc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "c:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [ThpSrv] C:\WINDOWS\system32\thpsrv /logon
O4 - HKLM\..\Run: [Toshiba Controls Utility] "C:\Program Files\TOSHIBA\Controls\VolumeIndicator.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdglf.exe] C:\WINDOWS\system32\kdglf.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{A268E0E7-59BC-4FDF-A43A-7169B1359F28}: NameServer = 10.206.65.68 10.206.65.68
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: jhvbsg.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - c:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TOSHIBA HDD Protection (Thpsrv) - TOSHIBA Corporation - C:\WINDOWS\system32\ThpSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

–
End of file - 8953 bytes
:welcome:

My name is BHowett and I will be helping you to get sorted. If for any reason you do not understand any of the instructions, or are just unsure then please do not guess , simply post back with your question, and we will go through it again.

Please do the following…

ATF Cleaner

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

===============================================

Malwarebytes' Anti-Malware
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
===============================================

And lets take a deeper look at some things…

RSIT
  • Download random's system information tool (RSIT) by random/random from here.
  • It is important that is saved to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<

===============================================

Needed in the next reply:

Malwarebytes log
RSIT logs

Also let me know how things are running :thumbup:
hello, thank you for your reply :)
During this time i was not siiting, but i search on this site and read about this rapid antivirus, so maybe i made a mistake, but i allready donwloaded some programs, but these programmes were the same as you wrote, so now i'm giving you the rezults of the Malwarebytes' Anti-Malware:

Malwarebytes' Anti-Malware 1.30
Database version: 1412
Windows 5.1.2600 Service Pack 3

19/11/2008 22:23:53
mbam-log-2008-11-19 (22-23-53).txt

Scan type: Quick Scan
Objects scanned: 53081
Time elapsed: 2 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

RSIT:
Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-11-19 22:25:56
Microsoft Windows XP Professional Service Pack 3
System drive C: has 131 GB (86%) free of 153 GB
Total RAM: 2038 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:25:58, on 19/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ThpSrv.exe
C:\WINDOWS\system32\TODDSrv.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe
C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\WINDOWS\system32\thpsrv.exe
C:\Program Files\TOSHIBA\Controls\VolumeIndicator.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Lijanyte & Irmukas\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Lijanyte & Irmukas.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "c:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [ThpSrv] C:\WINDOWS\system32\thpsrv /logon
O4 - HKLM\..\Run: [Toshiba Controls Utility] "C:\Program Files\TOSHIBA\Controls\VolumeIndicator.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdglf.exe] C:\WINDOWS\system32\kdglf.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: jhvbsg.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - c:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TOSHIBA HDD Protection (Thpsrv) - TOSHIBA Corporation - C:\WINDOWS\system32\ThpSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

–
End of file - 8786 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll [2008-07-29 62728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-08-12 2403392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google; - c:\program files\google\googletoolbar1.dll [2008-08-12 2403392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ITSecMng"=C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [2007-09-28 75136]
"NDSTray.exe"=NDSTray.exe []
"Toshiba Hotkey Utility"=c:\Program Files\Toshiba\Windows Utilities\Hotkey.exe [2008-01-04 1773568]
"TPSMain"=C:\WINDOWS\system32\TPSMain.exe [2008-02-06 271672]
"SmoothView"=C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe [2007-05-11 143360]
"DDWMon"=C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe [2007-04-26 495616]
"Adobe Reader Speed Launcher"=c:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"topi"=C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe [2007-07-10 581632]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-01-25 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-01-25 166424]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-01-25 137752]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2007-12-15 184320]
"Camera Assistant Software"=C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe [2007-10-25 413696]
"ThpSrv"=C:\WINDOWS\system32\thpsrv /logon []
"Toshiba Controls Utility"=C:\Program Files\TOSHIBA\Controls\VolumeIndicator.exe [2008-02-01 77824]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-02-19 49152]
"C:\WINDOWS\system32\kdglf.exe"=C:\WINDOWS\system32\kdglf.exe []
"CFSServ.exe"=CFSServ.exe -NoClient []
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe [2008-07-29 206088]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"=C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe [2005-04-11 65536]
"ISUSPM"=C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe [2007-03-29 222128]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2008-08-11 21741864]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe [2008-08-12 171448]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BitTorrent DNA"=C:\Program Files\DNA\btdna.exe [2008-11-17 342336]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="jhvbsg.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-12-19 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\WINDOWS\system32\klogon.dll [2008-07-29 218376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{70E5C213-45BC-4494-BA22-025EE7A38A42}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\RayV\RayV\RayV.exe"="C:\Program Files\RayV\RayV\RayV.exe:*:Enabled:RayV"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b4d7873-6887-11dd-b6a7-806d6172696f}]
shell\AutoRun\command - D:\setup.exe /AUTORUN
shell\configure\command - D:\setup.exe
shell\install\command - D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d3bd4e86-8251-11dd-b6c9-001f3c649932}]
shell\AutoRun\command - E:\StartVMCLite.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d3bd4e87-8251-11dd-b6c9-001f3c649932}]
shell\AutoRun\command - E:\StartVMCLite.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dcf8a648-6891-11dd-b6aa-001f3c649932}]
shell\AutoRun\command - E:\StartVMCLite.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dcf8a649-6891-11dd-b6aa-001f3c649932}]
shell\AutoRun\command - E:\StartVMCLite.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1509106-688e-11dd-b6a9-001f3c649932}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com f:
shell\Open\command - F:\resycled\boot.com f:


======List of files/folders created in the last 1 months======

2008-11-19 22:25:56 —-D—- C:\rsit
2008-11-19 21:41:53 —-D—- C:\WINDOWS\Prefetch
2008-11-19 21:40:10 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2008-11-19 21:40:05 —-HDC—- C:\WINDOWS\$NtUninstallKB957097$
2008-11-19 21:40:00 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-11-19 21:39:53 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-11-19 21:39:48 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-11-19 21:39:41 —-HDC—- C:\WINDOWS\$NtUninstallKB955069$
2008-11-19 21:39:36 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-11-19 21:39:30 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2008-11-19 21:39:24 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2008-11-19 21:39:19 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2008-11-19 21:39:13 —-HDC—- C:\WINDOWS\$NtUninstallKB951698$
2008-11-19 21:39:08 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-11-19 21:39:02 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2008-11-19 21:38:57 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2008-11-19 21:38:51 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2008-11-19 21:38:46 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2008-11-19 21:38:42 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$
2008-11-19 21:38:40 —-D—- C:\WINDOWS\LastGood.Tmp
2008-11-19 21:31:08 —-D—- C:\WINDOWS\system32\scripting
2008-11-19 21:31:07 —-D—- C:\WINDOWS\system32\en
2008-11-19 21:31:07 —-D—- C:\WINDOWS\system32\bits
2008-11-19 21:31:07 —-D—- C:\WINDOWS\l2schemas
2008-11-19 21:29:26 —-D—- C:\WINDOWS\ServicePackFiles
2008-11-19 21:26:04 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2008-11-19 21:16:11 —-D—- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-11-19 21:14:39 —-HDC—- C:\WINDOWS\$NtUninstallKB957097_0$
2008-11-19 21:14:32 —-HDC—- C:\WINDOWS\$NtUninstallKB955069_0$
2008-11-19 20:27:24 —-D—- C:\Program Files\Trend Micro
2008-11-19 19:42:02 —-D—- C:\Program Files\Hijackthis
2008-11-19 19:24:25 —-D—- C:\Documents and Settings\Lijanyte & Irmukas\Application Data\Malwarebytes
2008-11-19 19:24:19 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-11-19 19:24:19 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-11-19 19:19:39 —-D—- C:\WINDOWS\ERDNT
2008-11-19 19:17:20 —-D—- C:\Program Files\ERUNT
2008-11-18 22:37:05 —-D—- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-18 21:55:47 —-D—- C:\Program Files\Kaspersky Lab
2008-11-18 21:55:11 —-D—- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-11-18 21:03:51 —-D—- C:\MSI83dc0.tmp
2008-11-18 21:01:43 —-D—- C:\MSI64183.tmp
2008-11-18 19:26:05 —-D—- C:\Program Files\Lavasoft
2008-11-18 19:26:04 —-D—- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-11-18 19:25:18 —-D—- C:\Program Files\Common Files\Wise Installation Wizard
2008-11-18 12:26:11 —-A—- C:\WINDOWS\ntbtlog.txt
2008-11-18 11:00:16 —-D—- C:\Program Files\Enigma Software Group
2008-11-17 22:24:25 —-SH—- C:\WINDOWS\system32\gvqllrtk.ini
2008-11-17 22:23:24 —-A—- C:\WINDOWS\system32\5714b3ae-.txt
2008-11-17 18:50:47 —-D—- C:\Documents and Settings\Lijanyte & Irmukas\Application Data\BitTorrent
2008-11-17 18:39:36 —-D—- C:\Program Files\DNA
2008-11-17 18:39:36 —-D—- C:\Program Files\BitTorrent
2008-11-17 18:39:36 —-D—- C:\Documents and Settings\Lijanyte & Irmukas\Application Data\DNA
2008-10-29 17:32:05 —-HDC—- C:\WINDOWS\$NtUninstallKB958644_0$
2008-10-27 22:55:46 —-D—- C:\WINDOWS\Minidump
2008-10-27 21:27:55 —-N—- C:\WINDOWS\system32\wmphoto.dll
2008-10-27 21:27:54 —-N—- C:\WINDOWS\system32\wlanapi.dll
2008-10-27 21:27:54 —-N—- C:\WINDOWS\system32\windowscodecsext.dll
2008-10-27 21:27:54 —-N—- C:\WINDOWS\system32\windowscodecs.dll
2008-10-27 21:27:50 —-N—- C:\WINDOWS\system32\tspkg.dll
2008-10-27 21:27:50 —-N—- C:\WINDOWS\system32\tsgqec.dll
2008-10-27 21:27:47 —-N—- C:\WINDOWS\system32\spupdwxp.exe
2008-10-27 21:27:47 —-A—- C:\WINDOWS\system32\spdwnwxp.exe
2008-10-27 21:27:46 —-N—- C:\WINDOWS\system32\slserv.exe
2008-10-27 21:27:46 —-N—- C:\WINDOWS\system32\slrundll.exe
2008-10-27 21:27:46 —-N—- C:\WINDOWS\slrundll.exe
2008-10-27 21:27:45 —-N—- C:\WINDOWS\system32\slgen.dll
2008-10-27 21:27:45 —-N—- C:\WINDOWS\system32\slextspk.dll
2008-10-27 21:27:45 —-N—- C:\WINDOWS\system32\slcoinst.dll
2008-10-27 21:27:45 —-N—- C:\WINDOWS\system32\setupn.exe
2008-10-27 21:27:44 —-N—- C:\WINDOWS\system32\s3gnb.dll
2008-10-27 21:27:44 —-N—- C:\WINDOWS\system32\rhttpaa.dll
2008-10-27 21:27:43 —-N—- C:\WINDOWS\system32\rasqec.dll
2008-10-27 21:27:43 —-N—- C:\WINDOWS\system32\qutil.dll
2008-10-27 21:27:42 —-N—- C:\WINDOWS\system32\qcliprov.dll
2008-10-27 21:27:42 —-N—- C:\WINDOWS\system32\qagentrt.dll
2008-10-27 21:27:42 —-N—- C:\WINDOWS\system32\qagent.dll
2008-10-27 21:27:42 —-N—- C:\WINDOWS\system32\photometadatahandler.dll
2008-10-27 21:27:41 —-N—- C:\WINDOWS\system32\onex.dll
2008-10-27 21:27:39 —-N—- C:\WINDOWS\system32\nv4_disp.dll
2008-10-27 21:27:36 —-N—- C:\WINDOWS\system32\napstat.exe
2008-10-27 21:27:36 —-N—- C:\WINDOWS\system32\napmontr.dll
2008-10-27 21:27:36 —-N—- C:\WINDOWS\system32\napipsec.dll
2008-10-27 21:27:36 —-N—- C:\WINDOWS\system32\mtxparhd.dll
2008-10-27 21:27:35 —-N—- C:\WINDOWS\system32\msxml6r.dll
2008-10-27 21:27:35 —-N—- C:\WINDOWS\system32\msxml6.dll
2008-10-27 21:27:34 —-N—- C:\WINDOWS\system32\msshavmsg.dll
2008-10-27 21:27:34 —-N—- C:\WINDOWS\system32\mssha.dll
2008-10-27 21:27:27 —-N—- C:\WINDOWS\system32\mmcperf.exe
2008-10-27 21:27:27 —-N—- C:\WINDOWS\system32\mmcfxcommon.dll
2008-10-27 21:27:27 —-N—- C:\WINDOWS\system32\mmcex.dll
2008-10-27 21:27:27 —-N—- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-10-27 21:27:22 —-N—- C:\WINDOWS\system32\l2gpstore.dll
2008-10-27 21:27:15 —-N—- C:\WINDOWS\system32\kmsvc.dll
2008-10-27 21:27:15 —-N—- C:\WINDOWS\system32\kbdpash.dll
2008-10-27 21:27:15 —-N—- C:\WINDOWS\system32\kbdnepr.dll
2008-10-27 21:27:15 —-N—- C:\WINDOWS\system32\kbdiultn.dll
2008-10-27 21:27:15 —-N—- C:\WINDOWS\system32\kbdbhc.dll
2008-10-27 21:27:05 —-N—- C:\WINDOWS\system32\smtpapi.dll
2008-10-27 21:27:05 —-N—- C:\WINDOWS\system32\rwnh.dll
2008-10-27 21:27:04 —-N—- C:\WINDOWS\system32\comsdupd.exe
2008-10-27 21:27:03 —-N—- C:\WINDOWS\system32\hsfcisp2.dll
2008-10-27 21:27:00 —-N—- C:\WINDOWS\system32\faxpatch.exe
2008-10-27 21:27:00 —-A—- C:\WINDOWS\002771_.tmp
2008-10-27 21:26:59 —-N—- C:\WINDOWS\system32\eapsvc.dll
2008-10-27 21:26:59 —-N—- C:\WINDOWS\system32\eapqec.dll
2008-10-27 21:26:59 —-N—- C:\WINDOWS\system32\eappprxy.dll
2008-10-27 21:26:59 —-N—- C:\WINDOWS\system32\eapphost.dll
2008-10-27 21:26:59 —-N—- C:\WINDOWS\system32\eappgnui.dll
2008-10-27 21:26:59 —-N—- C:\WINDOWS\system32\eappcfg.dll
2008-10-27 21:26:59 —-N—- C:\WINDOWS\system32\eapp3hst.dll
2008-10-27 21:26:59 —-N—- C:\WINDOWS\system32\eapolqec.dll
2008-10-27 21:26:58 —-N—- C:\WINDOWS\system32\dot3ui.dll
2008-10-27 21:26:58 —-N—- C:\WINDOWS\system32\dot3svc.dll
2008-10-27 21:26:58 —-N—- C:\WINDOWS\system32\dot3msm.dll
2008-10-27 21:26:58 —-N—- C:\WINDOWS\system32\dot3gpclnt.dll
2008-10-27 21:26:58 —-N—- C:\WINDOWS\system32\dot3dlg.dll
2008-10-27 21:26:58 —-N—- C:\WINDOWS\system32\dot3cfg.dll
2008-10-27 21:26:58 —-N—- C:\WINDOWS\system32\dot3api.dll
2008-10-27 21:26:57 —-N—- C:\WINDOWS\system32\dimsroam.dll
2008-10-27 21:26:57 —-N—- C:\WINDOWS\system32\dimsntfy.dll
2008-10-27 21:26:57 —-N—- C:\WINDOWS\system32\dhcpqec.dll
2008-10-27 21:26:56 —-N—- C:\WINDOWS\system32\credssp.dll
2008-10-27 21:26:53 —-N—- C:\WINDOWS\system32\bitsprx4.dll
2008-10-27 21:26:53 —-N—- C:\WINDOWS\system32\azroles.dll
2008-10-27 21:26:53 —-N—- C:\WINDOWS\system32\ativvaxx.dll
2008-10-27 21:26:53 —-N—- C:\WINDOWS\system32\ativtmxx.dll
2008-10-27 21:26:52 —-N—- C:\WINDOWS\system32\ati3duag.dll
2008-10-27 21:26:52 —-N—- C:\WINDOWS\system32\ati3d1ag.dll
2008-10-27 21:26:52 —-N—- C:\WINDOWS\system32\ati2dvag.dll
2008-10-27 21:26:52 —-N—- C:\WINDOWS\system32\ati2dvaa.dll
2008-10-27 21:26:52 —-N—- C:\WINDOWS\system32\ati2cqag.dll
2008-10-27 21:26:50 —-N—- C:\WINDOWS\system32\aaclient.dll
2008-10-27 17:36:19 —-HDC—- C:\WINDOWS\$NtUninstallKB956803_0$
2008-10-27 17:36:15 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-10-27 17:36:11 —-HDC—- C:\WINDOWS\$NtUninstallKB957095_0$
2008-10-27 17:36:06 —-HDC—- C:\WINDOWS\$NtUninstallKB954211_0$
2008-10-27 17:35:55 —-HDC—- C:\WINDOWS\$NtUninstallKB956841_0$

======List of files/folders modified in the last 1 months======

2008-11-19 22:25:45 —-D—- C:\WINDOWS\Temp
2008-11-19 22:23:48 —-RD—- C:\Program Files
2008-11-19 22:06:24 —-A—- C:\WINDOWS\ModemLog_HUAWEI Mobile Connect - 3G Modem #2.txt
2008-11-19 21:46:06 —-AD—- C:\WINDOWS\system32
2008-11-19 21:46:06 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-11-19 21:44:16 —-D—- C:\Documents and Settings\Lijanyte & Irmukas\Application Data\Skype
2008-11-19 21:44:14 —-D—- C:\WINDOWS\system32\CatRoot
2008-11-19 21:42:54 —-A—- C:\WINDOWS\OEWABLog.txt
2008-11-19 21:42:12 —-D—- C:\WINDOWS\system32\CatRoot2
2008-11-19 21:42:04 —-D—- C:\WINDOWS
2008-11-19 21:41:56 —-A—- C:\WINDOWS\setuplog.txt
2008-11-19 21:41:21 —-D—- C:\WINDOWS\system32\wbem
2008-11-19 21:41:21 —-D—- C:\WINDOWS\system32\Setup
2008-11-19 21:41:21 —-D—- C:\WINDOWS\AppPatch
2008-11-19 21:41:20 —-RSD—- C:\WINDOWS\Fonts
2008-11-19 21:41:17 —-D—- C:\WINDOWS\system32\drivers
2008-11-19 21:40:43 —-D—- C:\WINDOWS\security
2008-11-19 21:40:41 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-11-19 21:40:13 —-HD—- C:\WINDOWS\inf
2008-11-19 21:40:11 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-11-19 21:38:47 —-D—- C:\Program Files\Messenger
2008-11-19 21:31:22 —-D—- C:\WINDOWS\WinSxS
2008-11-19 21:31:15 —-D—- C:\WINDOWS\system32\inetsrv
2008-11-19 21:31:15 —-D—- C:\WINDOWS\network diagnostic
2008-11-19 21:31:15 —-D—- C:\WINDOWS\ime
2008-11-19 21:31:15 —-D—- C:\WINDOWS\Help
2008-11-19 21:31:08 —-D—- C:\WINDOWS\system32\usmt
2008-11-19 21:31:08 —-D—- C:\WINDOWS\system32\en-US
2008-11-19 21:31:07 —-SHD—- C:\WINDOWS\Installer
2008-11-19 21:31:07 —-D—- C:\WINDOWS\PeerNet
2008-11-19 21:31:07 —-D—- C:\Program Files\Movie Maker
2008-11-19 21:29:18 —-D—- C:\WINDOWS\system32\Restore
2008-11-19 21:29:18 —-D—- C:\WINDOWS\system32\npp
2008-11-19 21:29:18 —-D—- C:\WINDOWS\mui
2008-11-19 21:29:18 —-D—- C:\WINDOWS\msagent
2008-11-19 21:29:17 —-D—- C:\WINDOWS\srchasst
2008-11-19 21:29:16 —-D—- C:\WINDOWS\system32\Com
2008-11-19 21:29:16 —-D—- C:\Program Files\NetMeeting
2008-11-19 21:29:14 —-D—- C:\Program Files\Windows NT
2008-11-19 21:29:14 —-D—- C:\Program Files\Windows Media Player
2008-11-19 21:29:14 —-D—- C:\Program Files\Outlook Express
2008-11-19 21:29:12 —-D—- C:\Program Files\Common Files\System
2008-11-19 21:29:06 —-D—- C:\WINDOWS\system32\oobe
2008-11-19 21:29:04 —-D—- C:\WINDOWS\system
2008-11-19 21:27:27 —-D—- C:\WINDOWS\system32\ReinstallBackups
2008-11-19 21:23:58 —-D—- C:\WINDOWS\ehome
2008-11-19 21:21:08 —-HD—- C:\Config.Msi
2008-11-19 21:18:58 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-11-19 21:14:38 —-HD—- C:\WINDOWS\$hf_mig$
2008-11-19 21:05:28 —-D—- C:\Documents and Settings\Lijanyte & Irmukas\Application Data\skypePM
2008-11-18 22:11:57 —-HD—- C:\Program Files\InstallShield Installation Information
2008-11-18 21:01:45 —-D—- C:\Documents and Settings\All Users\Application Data\HP
2008-11-18 19:25:18 —-D—- C:\Program Files\Common Files
2008-11-18 10:25:52 —-SD—- C:\WINDOWS\Tasks
2008-11-18 09:23:13 —-D—- C:\Program Files\Adobe
2008-11-04 00:10:25 —-A—- C:\WINDOWS\system32\MRT.exe
2008-10-29 17:33:23 —-D—- C:\Program Files\Internet Explorer
2008-10-27 20:44:37 —-D—- C:\WINDOWS\Debug
2008-10-27 19:26:12 —-RSD—- C:\WINDOWS\assembly
2008-10-27 19:25:31 —-D—- C:\WINDOWS\Microsoft.NET
2008-10-27 17:39:35 —-SD—- C:\Documents and Settings\Lijanyte & Irmukas\Application Data\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2008-07-18 213008]
R1 Tosrfcom;Bluetooth RFCOMM; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2007-10-02 64128]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-01-15 12032]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 Netdevio;TOSHIBA Network Device Usermode I/O Protocol; C:\WINDOWS\system32\DRIVERS\netdevio.sys [2003-01-29 12032]
R2 tdudf;TOSHIBA UDF File System Driver; C:\WINDOWS\system32\DRIVERS\tdudf.sys [2007-03-26 105856]
R2 trudf;TOSHIBA DVD-RAM UDF File System Driver; C:\WINDOWS\system32\DRIVERS\trudf.sys [2007-02-19 134016]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2007-11-06 101888]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 BoiHwsetup;Access 32bits INT15 routine; C:\WINDOWS\system32\drivers\BoiHwSetup.sys [2005-06-10 5504]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 CnxtHdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\CHDAud.sys [2008-02-01 732160]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2007-11-01 989696]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2007-11-01 211456]
R3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2007-08-17 101120]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-12-19 5854688]
R3 klim5;Kaspersky Anti-Virus NDIS Filter; C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-04-30 24592]
R3 NETw4x32;Intel® Wireless WiFi Link Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw4x32.sys [2007-09-26 2236032]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 O2MDRDR;O2MDRDR; C:\WINDOWS\system32\DRIVERS\o2media.sys [2008-03-04 48600]
R3 QIOMem;Generic IO & Memory Access; C:\WINDOWS\system32\DRIVERS\QIOMem.sys [2007-05-29 6912]
R3 qkbfiltr;Quanta HotKey Keyboard Filter Driver; C:\WINDOWS\system32\drivers\qkbfiltr.sys [2006-01-12 31872]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\WINDOWS\system32\DRIVERS\tdcmdpst.sys [2006-10-18 16128]
R3 tosporte;Bluetooth COM Port; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2006-10-10 41600]
R3 tosrfec;Bluetooth ACPI; C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2006-10-23 9216]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 usbvideo;Chicony USB 2.0 Camera; C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
R3 UVCFTR;UVCFTR; C:\WINDOWS\System32\Drivers\UVCFTR_S.SYS [2007-12-17 18432]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2007-11-01 731520]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2007-12-28 285952]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-13 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-13 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-13 21568]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 Ndisprot;ArcNet NDIS Protocol Driver; \??\C:\WINDOWS\system32\drivers\Ndisprot.sys []
S3 qmofiltr;Quanta HotKey Mouse Filter Driver; C:\WINDOWS\system32\drivers\qmofiltr.sys [2005-05-05 7936]
S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2008-01-15 5888]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 tosrfbd;Bluetooth RFBUS; C:\WINDOWS\system32\DRIVERS\tosrfbd.sys [2007-12-26 131584]
S3 tosrfbnp;Bluetooth RFBNEP; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2007-11-29 36608]
S3 Tosrfhid;Bluetooth RFHID; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2007-11-29 74240]
S3 tosrfnds;Bluetooth Personal Area Network; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-07 18612]
S3 Tosrfusb;Bluetooth USB Controller; C:\WINDOWS\system32\DRIVERS\tosrfusb.sys [2007-10-18 41856]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-11 18944]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-09-10 611664]
R2 AVP;Kaspersky Anti-Virus; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe [2008-07-29 206088]
R2 CFSvcs;ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [2005-01-17 40960]
R2 o2flash;O2Micro Flash Memory Card Service; c:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe [2007-02-12 65536]
R2 Thpsrv;TOSHIBA HDD Protection; C:\WINDOWS\system32\ThpSrv.exe [2008-01-18 558392]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\WINDOWS\system32\TODDSrv.exe [2007-11-21 129632]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-09-28 128360]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2006-03-03 69632]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-10-14 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-12 138168]
S3 IDriverT;InstallDriver Table Manager; c:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]

—————–EOF—————–

as i understood from Malwarebytes' Anti-Malware results there are no bad files in my pc, but maybe i can't see something
But i must say at the moment my pc working quit good, windows automatic updates are working properly, that blue window didn't appear after i run these programs.

But as i'm saying maybe you will see something what i need to do more.

Thanks
Hi fragolla,

Not looking to bad, but I see you are using BitTorrent, so that will get you my P2P warning

P2P Warning!

Please note that as long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur. Once upon a time, P2P file sharing was fairly safe. That is no longer true. You may continue to use P2P sharing at your own risk; however, please keep in mind that this practice may be the source of your current problem/infection. I would strongly suggest you remove BitTorrent . Removing can be done through Add/Remove Programs.

===============================================

OTMoveIt3 by OldTimer

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy everything inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Files
    C:\MSI83dc0.tmp
    C:\MSI64183.tmp
    C:\WINDOWS\system32\gvqllrtk.ini
    C:\WINDOWS\system32\5714b3ae-.txt
    C:\WINDOWS\system32\kdglf.exe
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLS"=-
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b4d7873-6887-11dd-b6a7-806d6172696f}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d3bd4e86-8251-11dd-b6c9-001f3c649932}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d3bd4e87-8251-11dd-b6c9-001f3c649932}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dcf8a648-6891-11dd-b6aa-001f3c649932}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dcf8a649-6891-11dd-b6aa-001f3c649932}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1509106-688e-11dd-b6a9-001f3c649932}]
    :Commands
    [purity]
    [emptytemp]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3

Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

===============================================

Kaspersky WebScanner

Please do an online scan with Kaspersky WebScanner

Kaspersky online scanner uses JAVA tecnology to perform the scan. If you do not have the latest JAVA version, follow the instrutions below under Upgrading Java, to download and install the latest vesion.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure the following is checked.
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Upgrading Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 7.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u7-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right cklick on the jre-6u7-windows-i586-p.exe and select "Run as an Administrator.")

===============================================


Needed in your next reply:

OTMoveIt3 log
Kaspersky WebScanner results

And as always let me know how things are running :thumbup:
Good evening, Today i done one of thing which you asked me to do so here is my OTMoveIt3 by OldTimer file: ========== FILES ========== C:\MSI83dc0.tmp moved successfully. C:\MSI64183.tmp moved successfully. C:\WINDOWS\system32\gvqllrtk.ini moved successfully. C:\WINDOWS\system32\5714b3ae-.txt moved successfully. File/Folder C:\WINDOWS\system32\kdglf.exe not found. ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLS deleted successfully. Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b4d7873-6887-11dd-b6a7-806d6172696f}\\ deleted successfully. Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d3bd4e86-8251-11dd-b6c9-001f3c649932}\\ deleted successfully. Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d3bd4e87-8251-11dd-b6c9-001f3c649932}\\ deleted successfully. Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dcf8a648-6891-11dd-b6aa-001f3c649932}\\ deleted successfully. Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dcf8a649-6891-11dd-b6aa-001f3c649932}\\ deleted successfully. Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1509106-688e-11dd-b6a9-001f3c649932}\\ deleted successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\LIJANY~1\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\LIJANY~1\LOCALS~1\Temp\Perflib_Perfdata_ed0.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\LIJANY~1\LOCALS~1\Temp\~DFA942.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\cch~26666b7b7.htp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\cch~26666bd55.htp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\cch~26666cfba.htp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\cch~26666d4b0.htp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\cch~266c380f3.htp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\cch~266c38613.htp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\cch~26dd2a373.htp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\cch~26dd2a801.htp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\cch~27666590a.htp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\cch~276665dc2.htp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\cch~2766e0dca.htp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\cch~2766e143a.htp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\cch~2766e2b95.htp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\cch~2766e3c62.htp scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11202008_183351 Files moved on Reboot… C:\DOCUME~1\LIJANY~1\LOCALS~1\Temp\hpodvd09.log moved successfully. File C:\DOCUME~1\LIJANY~1\LOCALS~1\Temp\Perflib_Perfdata_ed0.dat not found! C:\DOCUME~1\LIJANY~1\LOCALS~1\Temp\~DFA942.tmp moved successfully. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat moved successfully. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat moved successfully. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat moved successfully. File C:\WINDOWS\temp\cch~26666b7b7.htp not found! File C:\WINDOWS\temp\cch~26666bd55.htp not found! File C:\WINDOWS\temp\cch~26666cfba.htp not found! File C:\WINDOWS\temp\cch~26666d4b0.htp not found! File C:\WINDOWS\temp\cch~266c380f3.htp not found! File C:\WINDOWS\temp\cch~266c38613.htp not found! File C:\WINDOWS\temp\cch~26dd2a373.htp not found! File C:\WINDOWS\temp\cch~26dd2a801.htp not found! File C:\WINDOWS\temp\cch~27666590a.htp not found! File C:\WINDOWS\temp\cch~276665dc2.htp not found! File C:\WINDOWS\temp\cch~2766e0dca.htp not found! File C:\WINDOWS\temp\cch~2766e143a.htp not found! File C:\WINDOWS\temp\cch~2766e2b95.htp not found! File C:\WINDOWS\temp\cch~2766e3c62.htp not found! but i had some problems with scanning with kaspersky web scanner, because my internet is very slow, i can't even update properly so i desided to take my laptop to my work and i will scan there and post the results tomorow. Basicly everything is going ok.
hello, Just to today had time to write to you. And i have nort very good news about my pc, as you recomended i was trying to scan my pc using kaspersky web scanner, but i couldn't do this because, all the time when the scanner was finishing to update, my pc was restarting, before that he for few seconds showed a blue window, in which was something about: "…make sure that the new device is properly installed…" and something else, but i was not able to read till the end, because it disapeared and the windouws were restarting. As I said before, i have kaspersky antu-virus 2009 installed in my pc, so today i had updated my kaspersky, to make sure that all the files and everything is in my pc, and made a full scan. The results I put as attachment. I hope it will work for you will be able to help me Regards Lijana

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI