Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

I don't know what I have[RESOLVED]


  • This topic is locked This topic is locked

#1
calgooda1323

calgooda1323

    Member

  • Member
  • PipPip
  • 57 posts
I am having a serious problem with my computer. It is extremely slow and some pages such as my college website page could take 15 minutes to load (this is not normal). I have tried to run some of the programs that were suggested to other people but am not having any luck. I have THOUSANDS of POS files in my documents. Can anyone help me?

I ran the HiJacker thing like other people... Does this help at all??

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:14:14 PM, on 3/14/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
C:\WINDOWS\System32\TPSMain.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\TFNF5.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\WINDOWS\System32\TPSBattM.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [PadTouch] "C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [zzzHPSETUP] D:\Setup.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,[email protected]
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [BMbfc81020] Rundll32.exe "C:\WINDOWS\System32\sekyrpqt.dll",s
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O12 - Plugin for .csm: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .emb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .spt: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.co...GenXInstall.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgree...eensActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by19fd.bay19....es/MsnPUpld.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinn...ck/bjattack.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1141762598718
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinn...ed/wwlaunch.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.co...nstallAsst2.cab
O16 - DPF: {A30FBBDC-FA29-4606-8565-14AADCCA6708} (Rite Aid One Hour Photo Online Control) - https://photos.ritea...PhotoOnline.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinn...v45/wof/wof.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart...ploadClient.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.co...GameManager.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.co.../MathPlayer.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinn...ool/h2hpool.cab
O20 - Winlogon Notify: dmidicuq - dmidicuq.dll (file missing)
O20 - Winlogon Notify: fawrqdzp - fawrqdzp.dll (file missing)
O20 - Winlogon Notify: fbpmvkvo - fbpmvkvo.dll (file missing)
O20 - Winlogon Notify: fcccyaw - fcccyaw.dll (file missing)
O20 - Winlogon Notify: fflknyls - fflknyls.dll (file missing)
O20 - Winlogon Notify: gkooxraf - gkooxraf.dll (file missing)
O20 - Winlogon Notify: gpjynzzk - gpjynzzk.dll (file missing)
O20 - Winlogon Notify: hkxiswhs - hkxiswhs.dll (file missing)
O20 - Winlogon Notify: itdsloxu - itdsloxu.dll (file missing)
O20 - Winlogon Notify: ppczfhff - ppczfhff.dll (file missing)
O20 - Winlogon Notify: qiwnoror - qiwnoror.dll (file missing)
O20 - Winlogon Notify: qmmpamfc - qmmpamfc.dll (file missing)
O20 - Winlogon Notify: rhzjydjr - rhzjydjr.dll (file missing)
O20 - Winlogon Notify: rnnbyhpu - rnnbyhpu.dll (file missing)
O20 - Winlogon Notify: xhivjxsx - xhivjxsx.dll (file missing)
O20 - Winlogon Notify: zggoajgl - zggoajgl.dll (file missing)
O20 - Winlogon Notify: zxdwicxn - zxdwicxn.dll (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbtcoms.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 10649 bytes

Edited by calgooda1323, 14 March 2008 - 11:14 PM.

  • 0

Advertisements


#2
RatHat

RatHat

    Ex Malware Expert

  • Expert
  • 7,829 posts
Hi there,

Welcome to GeeksToGo. My name is RatHat, and I will help you get through the process of cleaning the malware from your computer.


OK firstly, I need you to print out each post I make so that you can refer to it while we fix your computer. This is because there will be times when you are unable to be online to read my instructions, and I will want you to do everything very carefully. I also need you to follow my instructions in the order that they are given. If however, you cannot carry out one of them, please continue on with the next and let me know what you were unsuccessful with. Please ensure you turn off word wrap in Notepad. To do this, open Notepad, choose Format, then Un-check Word Wrap. (Word Wrap makes reading your log difficult).

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O20 - Winlogon Notify: dmidicuq - dmidicuq.dll (file missing)
O20 - Winlogon Notify: fawrqdzp - fawrqdzp.dll (file missing)
O20 - Winlogon Notify: fbpmvkvo - fbpmvkvo.dll (file missing)
O20 - Winlogon Notify: fcccyaw - fcccyaw.dll (file missing)
O20 - Winlogon Notify: fflknyls - fflknyls.dll (file missing)
O20 - Winlogon Notify: gkooxraf - gkooxraf.dll (file missing)
O20 - Winlogon Notify: gpjynzzk - gpjynzzk.dll (file missing)
O20 - Winlogon Notify: hkxiswhs - hkxiswhs.dll (file missing)
O20 - Winlogon Notify: itdsloxu - itdsloxu.dll (file missing)
O20 - Winlogon Notify: ppczfhff - ppczfhff.dll (file missing)
O20 - Winlogon Notify: qiwnoror - qiwnoror.dll (file missing)
O20 - Winlogon Notify: qmmpamfc - qmmpamfc.dll (file missing)
O20 - Winlogon Notify: rhzjydjr - rhzjydjr.dll (file missing)
O20 - Winlogon Notify: rnnbyhpu - rnnbyhpu.dll (file missing)
O20 - Winlogon Notify: xhivjxsx - xhivjxsx.dll (file missing)
O20 - Winlogon Notify: zggoajgl - zggoajgl.dll (file missing)
O20 - Winlogon Notify: zxdwicxn - zxdwicxn.dll (file missing)

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Download OTScanIt.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanIt folder and double-click on OTScanIt.exe to start the program.
  • Check the box that says Scan All User Accounts
  • Check the box that says Include MD5
  • Check the Radio buttons for Files/Folders Created Within 90 Days and Files/Folders Modified Within 90 Days
  • Check the radio button under Rootkit Search for Yes
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.

If the log is too large to post, please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on Posted Image to insert the attachment into your post
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


So in your next post, please include:
  • The contents of Combofix.txt
  • The OTScanIt log

Regards,
RatHat
  • 0

#3
calgooda1323

calgooda1323

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts
Here are the results of combofix.

ComboFix 08-03-14.4 - Cortney 2008-03-20 10:48:44.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.146 [GMT -6:00]
Running from: C:\Documents and Settings\Cortney\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\salesmonitor
C:\Documents and Settings\All Users\Application Data\storageprotector
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\em
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\oid
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\user
C:\Documents and Settings\Cortney\Application Data\AVSystemCare
C:\Documents and Settings\Cortney\Application Data\AVSystemCare\Logs\threats.log
C:\Documents and Settings\Cortney\Application Data\SEMBLY~1
C:\Documents and Settings\Cortney\Application Data\SEMBLY~1\??oolsv.exe
C:\Documents and Settings\Cortney\Application Data\SMBOLS~1
C:\Documents and Settings\Cortney\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Cortney\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Cortney\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Program Files\Common Files\sks~1
C:\Program Files\Common Files\sks~1\??sks\
C:\Program Files\Common Files\sks~1\chkdsk.exe
C:\Program Files\fehy89104.dll
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\isgTi19
C:\Temp\isgTi19\lPig.log
C:\Temp\sanR24
C:\Temp\sanR24\lDii.log
C:\UGA6P
C:\WINDOWS\BMbfc81020.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\a1
C:\WINDOWS\system32\a1\tliamdll2.exe
C:\WINDOWS\system32\aflcxvbq.dll
C:\WINDOWS\system32\ashgmtmw.dll
C:\WINDOWS\system32\axatjjhn.dll
C:\WINDOWS\system32\bgpqhrnc.dll
C:\WINDOWS\system32\bhyqsara.dll
C:\WINDOWS\system32\bifetaej.dll
C:\WINDOWS\system32\bjwik.dll
C:\WINDOWS\system32\bqnuljlj.dll
C:\WINDOWS\system32\bsmkvxii.ini
C:\WINDOWS\system32\cfpdfokx.dll
C:\WINDOWS\system32\cjhrlxjt.dll
C:\WINDOWS\system32\cokyusgy.ini
C:\WINDOWS\system32\dcbeg.ini
C:\WINDOWS\system32\dcbeg.ini2
C:\WINDOWS\system32\dlvquuqi.dll
C:\WINDOWS\system32\dysonejc.ini
C:\WINDOWS\system32\fbktktuc.dll
C:\WINDOWS\system32\fcccyvu.dll
C:\WINDOWS\system32\fccyaww.dll
C:\WINDOWS\system32\fibdymww.dll
C:\WINDOWS\system32\fiyhuwpo.dll
C:\WINDOWS\system32\fomgpneg.dll
C:\WINDOWS\system32\frdskswl.ini
C:\WINDOWS\system32\fuwjktpa.dll
C:\WINDOWS\system32\ggjehuhr.dll
C:\WINDOWS\system32\gtssfxgj.dll
C:\WINDOWS\system32\gwwjsrji.dll
C:\WINDOWS\system32\hcjgfyda.dll
C:\WINDOWS\system32\hgaflsxk.dll
C:\WINDOWS\system32\hjkkj.ini
C:\WINDOWS\system32\hjkkj.ini2
C:\WINDOWS\system32\hknscqwt.ini
C:\WINDOWS\system32\icroso~1.net
C:\WINDOWS\system32\iDlo01
C:\WINDOWS\system32\iDlo01\iDlo011065.exe
C:\WINDOWS\system32\iphqammu.ini
C:\WINDOWS\system32\ivlekjmu.ini
C:\WINDOWS\system32\jkcvmgdv.ini
C:\WINDOWS\system32\jkkjh.dll
C:\WINDOWS\system32\jkkkkli.dll
C:\WINDOWS\system32\jovjaorn.dll
C:\WINDOWS\system32\jwbaknuk.dll
C:\WINDOWS\system32\kegjpurm.dll
C:\WINDOWS\system32\koeqjkbp.dll
C:\WINDOWS\system32\kpkqckss.dll
C:\WINDOWS\system32\kqsusvak.dll
C:\WINDOWS\system32\kxretiry.ini
C:\WINDOWS\system32\ldmktydf.dll
C:\WINDOWS\system32\lendwaev.ini
C:\WINDOWS\system32\ljjkhgd.dll
C:\WINDOWS\system32\lknbbodh.dll
C:\WINDOWS\system32\mclrmshp.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nhjjtaxa.ini
C:\WINDOWS\system32\nkpiixwv.dll
C:\WINDOWS\system32\nksdfhex.dll
C:\WINDOWS\system32\nlhalllr.dll
C:\WINDOWS\system32\nvwjmxiw.dll
C:\WINDOWS\system32\odflxbag.ini
C:\WINDOWS\system32\okilponr.dll
C:\WINDOWS\system32\oubcphhq.dll
C:\WINDOWS\system32\owsksqtm.dll
C:\WINDOWS\system32\oxgvdbic.dll
C:\WINDOWS\system32\p9
C:\WINDOWS\system32\p9\liopud89104.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pcdmnpwy.ini
C:\WINDOWS\system32\qaltupwr.dll
C:\WINDOWS\system32\qpcyygdn.dll
C:\WINDOWS\system32\quetpppp.dll
C:\WINDOWS\system32\rbbhuxdc.dll
C:\WINDOWS\system32\rpaftxlo.ini
C:\WINDOWS\system32\sekyrpqt.dll
C:\WINDOWS\system32\sfxttcpy.ini
C:\WINDOWS\system32\sgdbynum.dll
C:\WINDOWS\system32\skaycfty.dll
C:\WINDOWS\system32\skqdmvrs.dll
C:\WINDOWS\system32\svxxckbr.dll
C:\WINDOWS\system32\tfrerwqo.dll
C:\WINDOWS\system32\tivwfvkv.dll
C:\WINDOWS\system32\tqhbdaht.dll
C:\WINDOWS\system32\ttyawwvn.dll
C:\WINDOWS\system32\twmroiql.dll
C:\WINDOWS\system32\urnapyov.dll
C:\WINDOWS\system32\vdgmvckj.dll
C:\WINDOWS\system32\vgaybjel.ini
C:\WINDOWS\system32\vjdqrtoo.ini
C:\WINDOWS\system32\vujsribl.dll
C:\WINDOWS\system32\vyeqtcyr.dll
C:\WINDOWS\system32\w11
C:\WINDOWS\system32\w11\hiba3133.exe
C:\WINDOWS\system32\wctieesm.dll
C:\WINDOWS\system32\wmjawdvr.dll
C:\WINDOWS\system32\wnrtiwwb.ini
C:\WINDOWS\system32\wshbmtuh.dll
C:\WINDOWS\system32\xerkbrwe.dll
C:\WINDOWS\system32\xmvhcjbp.dll
C:\WINDOWS\system32\ynkehxbn.dll
C:\WINDOWS\system32\yundcmou.dll
C:\WINDOWS\system32\ywpnmdcp.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\LEGACY_FMTR


((((((((((((((((((((((((( Files Created from 2008-02-20 to 2008-03-20 )))))))))))))))))))))))))))))))
.

2008-03-19 22:23 . 2008-03-19 22:23 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-03-19 11:50 . 2008-03-19 11:50 41,723 ---hs---- C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
2008-03-14 23:36 . 2008-03-14 23:36 <DIR> d-------- C:\Documents and Settings\Cortney\Application Data\Grisoft
2008-03-14 23:36 . 2008-03-14 23:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-14 23:36 . 2007-05-30 06:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-14 21:00 . 2008-03-14 22:26 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-14 21:00 . 2008-03-14 22:27 <DIR> d-------- C:\Documents and Settings\Cortney\Application Data\SUPERAntiSpyware.com
2008-03-14 21:00 . 2008-03-14 21:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-13 11:22 . 2008-03-14 11:23 1,315,182 ---hs---- C:\WINDOWS\system32\xmckfhre.ini
2008-03-11 10:13 . 2008-03-20 10:56 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-11 10:13 . 2008-03-20 10:54 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-10 10:14 . 2008-03-11 10:14 1,316,096 ---hs---- C:\WINDOWS\system32\rcjhdvam.ini
2008-03-08 23:35 . 2008-03-10 10:09 1,319,169 ---hs---- C:\WINDOWS\system32\jqxdcveb.ini
2008-03-07 23:40 . 2008-03-08 21:56 1,308,941 ---hs---- C:\WINDOWS\system32\phyirirs.ini
2008-03-06 23:37 . 2008-03-07 23:38 1,308,521 ---hs---- C:\WINDOWS\system32\dyqosxhi.ini
2008-03-05 23:42 . 2008-03-06 22:02 654 ---hs---- C:\WINDOWS\system32\hsvjpgfy.ini
2008-03-05 23:35 . 2008-03-14 21:08 43,550 ---hs---- C:\WINDOWS\system32\zggoajgl.dllbox
2008-03-04 23:30 . 2008-03-05 01:42 20,944 ---hs---- C:\WINDOWS\system32\gpjynzzk.dllbox
2008-03-03 23:31 . 2008-03-04 10:04 20,176 ---hs---- C:\WINDOWS\system32\ppczfhff.dllbox
2008-03-02 23:30 . 2008-03-02 23:37 23,094 ---hs---- C:\WINDOWS\system32\qmmpamfc.dllbox
2008-03-01 15:41 . 2008-03-01 18:09 20,684 ---hs---- C:\WINDOWS\system32\zxdwicxn.dllbox
2008-02-29 15:39 . 2008-02-29 16:54 34,602 ---hs---- C:\WINDOWS\system32\dmidicuq.dllbox
2008-02-28 15:38 . 2008-02-28 15:50 19,458 ---hs---- C:\WINDOWS\system32\itdsloxu.dllbox
2008-02-27 15:38 . 2008-02-27 15:45 19,458 ---hs---- C:\WINDOWS\system32\qiwnoror.dllbox
2008-02-25 19:37 . 2008-02-25 20:30 20,942 ---hs---- C:\WINDOWS\system32\fbpmvkvo.dllbox
2008-02-24 19:36 . 2008-02-24 19:50 19,458 ---hs---- C:\WINDOWS\system32\fawrqdzp.dllbox
2008-02-23 15:32 . 2008-02-23 16:35 20,942 ---hs---- C:\WINDOWS\system32\xhivjxsx.dllbox
2008-02-22 12:20 . 2008-02-23 09:54 20,732 ---hs---- C:\WINDOWS\system32\gkooxraf.dllbox
2008-02-21 12:16 . 2008-02-22 09:27 20,612 ---hs---- C:\WINDOWS\system32\rhzjydjr.dllbox
2008-02-20 12:12 . 2008-02-20 14:53 24,850 ---hs---- C:\WINDOWS\system32\fflknyls.dllbox

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-19 17:54 37,376 ----a-w C:\WINDOWS\mrofinu572.exe
2008-03-15 03:59 --------- d-----w C:\Program Files\Trend Micro
2008-03-15 02:18 --------- d-----w C:\Program Files\Java
2008-03-12 18:54 37,376 ----a-r C:\WINDOWS\mrofinu572.exe.tmp
2008-03-11 15:40 --------- d-----w C:\Program Files\Lx_cats
2008-02-22 15:51 --------- d-----w C:\Program Files\Diet Analysis Plus 8.0
2008-02-19 17:00 --------- d-----r C:\Documents and Settings\All Users\Application Data\SalesMon
2008-02-15 02:24 --------- d-----w C:\Program Files\Roguescanfix
2008-02-15 02:24 --------- d-----w C:\Program Files\Alfa & Ariss
2008-02-15 01:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-15 01:12 36,864 ----a-w C:\WINDOWS\mrofinu1000106.exe
2008-02-04 15:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-04 15:23 --------- d-----w C:\Program Files\Yahoo!
2008-01-15 21:52 140,800 --sh--w C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
2007-09-27 17:11 82,864 ----a-w C:\Documents and Settings\Cortney\Application Data\GDIPFONTCACHEV1.DAT
2004-07-18 06:55 460,728 ----a-w C:\WINDOWS\Fonts\SET5FF.tmp
2004-07-18 06:55 460,728 ----a-w C:\WINDOWS\Fonts\SET50E.tmp
2004-07-18 06:55 383,140 ----a-w C:\WINDOWS\Fonts\SET5FE.tmp
2004-07-18 06:55 383,140 ----a-w C:\WINDOWS\Fonts\SET50D.tmp
2004-07-18 06:55 355,436 ----a-w C:\WINDOWS\Fonts\SET5FD.tmp
2004-07-18 06:55 355,436 ----a-w C:\WINDOWS\Fonts\SET50C.tmp
2004-07-17 19:39 409,280 ----a-w C:\WINDOWS\Fonts\SET5FC.tmp
2004-07-17 19:39 409,280 ----a-w C:\WINDOWS\Fonts\SET50B.tmp
2004-07-17 19:39 398,372 ----a-w C:\WINDOWS\Fonts\SET5FB.tmp
2004-07-17 19:39 398,372 ----a-w C:\WINDOWS\Fonts\SET50A.tmp
2004-07-17 19:39 367,112 ----a-w C:\WINDOWS\Fonts\SET602.tmp
2004-07-17 19:39 367,112 ----a-w C:\WINDOWS\Fonts\SET511.tmp
2004-07-17 19:39 352,224 ----a-w C:\WINDOWS\Fonts\SET601.tmp
2004-07-17 19:39 352,224 ----a-w C:\WINDOWS\Fonts\SET510.tmp
2004-07-17 19:39 127,596 ----a-w C:\WINDOWS\Fonts\SET600.tmp
2004-07-17 19:39 127,596 ----a-w C:\WINDOWS\Fonts\SET50F.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 05:24 65536]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2003-03-31 06:00 13312]
"Osus"="C:\PROGRA~1\COMMON~1\SKS~1\chkdsk.exe" [ ]
"Bihfqwe"="C:\Documents and Settings\Cortney\Application Data\??sembly\??oolsv.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-04-07 02:19 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-04-07 02:07 114688]
"AGRSMMSG"="AGRSMMSG.exe" [2003-04-18 13:20 88363 C:\WINDOWS\agrsmmsg.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-07-17 19:38 159744]
"TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [2003-01-21 20:00 126976]
"PadTouch"="C:\Program Files\TOSHIBA\PadTouch\PadExe.exe" [2003-10-31 17:01 1019904]
"TPSMain"="TPSMain.exe" [2003-11-19 23:15 278528 C:\WINDOWS\system32\TPSMain.exe]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2003-10-20 11:39 159744]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2003-01-02 18:16 172032]
"00THotkey"="C:\WINDOWS\System32\00THotkey.exe" [2003-04-15 22:01 258048]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 12:29 40960]
"TFNF5"="TFNF5.exe" [2003-10-15 18:03 73728 C:\WINDOWS\system32\TFNF5.exe]
"TFncKy"="TFncKy.exe" []
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [ ]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2003-11-20 19:24 26112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2003-11-20 19:25 77824]
"Lexmark 5200 series"="C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe" [2004-03-25 07:30 57344]
"000StTHK"="000StTHK.exe" [2001-06-23 22:28 24576 C:\WINDOWS\system32\000StTHK.exe]
"zzzHPSETUP"="D:\Setup.exe" [ ]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 12:42 69632]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-05-06 23:56 188416]
"LXBTCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll" [2004-03-17 10:30 65536]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 19:09 842584]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]
"bm(1)"="C:\Program Files\Common Files\AVSystemCare\bm.exe" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2003-08-06 15:23:32 51776]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-12 23:01:04 83360]
Trend Micro Anti-Spyware.lnk - C:\Program Files\Trend Micro\Tmas\Tmas.exe [2006-03-07 19:42:20 1306624]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{03A80B1D-5C6A-42c2-9DFB-81B6005D8023}"= C:\Program Files\Trend Micro\Tmas\sshook.dll [2006-05-26 16:17 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dmidicuq]
dmidicuq.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fawrqdzp]
fawrqdzp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fbpmvkvo]
fbpmvkvo.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fcccyaw]
fcccyaw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fflknyls]
fflknyls.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gkooxraf]
gkooxraf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gpjynzzk]
gpjynzzk.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hkxiswhs]
hkxiswhs.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\itdsloxu]
itdsloxu.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ppczfhff]
ppczfhff.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qiwnoror]
qiwnoror.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qmmpamfc]
qmmpamfc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rhzjydjr]
rhzjydjr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rnnbyhpu]
rnnbyhpu.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xhivjxsx]
xhivjxsx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\zggoajgl]
zggoajgl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\zxdwicxn]
zxdwicxn.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli

R0 BsStor;B.H.A Storage Helper Driver;C:\WINDOWS\System32\drivers\BsStor.sys [2002-06-06 03:07]
S3 pciSd;pciSd;C:\WINDOWS\System32\DRIVERS\tossdpci.sys [2003-02-12 11:03]
S3 tsdhd;TOSHIBA SD Card Host Controller Driver;C:\WINDOWS\System32\DRIVERS\tsdhd.sys [2003-05-14 19:38]

.
Contents of the 'Scheduled Tasks' folder
"2006-12-14 07:45:35 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job"
- c:\Program Files\Microsoft IntelliPoint\ipoint.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-20 10:56:47
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\System32\TPSBattM.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
.
**************************************************************************
.
Completion time: 2008-03-20 11:00:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-20 17:00:27
  • 0

#4
calgooda1323

calgooda1323

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts
Here is Hijackthis. I hope I did ok!


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:38 AM, on 3/20/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
C:\WINDOWS\System32\TPSMain.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\TFNF5.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\System32\TPSBattM.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [PadTouch] "C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [zzzHPSETUP] D:\Setup.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,[email protected]
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [bm(1)] "C:\Program Files\Common Files\AVSystemCare\bm.exe" dm=http://avsystemcare.com ad=http://avsystemcare.com sd=http://ykeeper.avsystemcare.com
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Osus] "C:\PROGRA~1\COMMON~1\SKS~1\chkdsk.exe" -vt yazb
O4 - HKCU\..\Run: [Bihfqwe] "C:\Documents and Settings\Cortney\Application Data\??sembly\??oolsv.exe"
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O12 - Plugin for .csm: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .emb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .spt: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.co...GenXInstall.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgree...eensActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail....es/MSNPUpld.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinn...ck/bjattack.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1141762598718
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinn...ed/wwlaunch.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.co...nstallAsst2.cab
O16 - DPF: {A30FBBDC-FA29-4606-8565-14AADCCA6708} (Rite Aid One Hour Photo Online Control) - https://photos.ritea...PhotoOnline.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinn...v45/wof/wof.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart...ploadClient.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.co...GameManager.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.co.../MathPlayer.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinn...ool/h2hpool.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbtcoms.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 10147 bytes
  • 0

#5
RatHat

RatHat

    Ex Malware Expert

  • Expert
  • 7,829 posts
Can you attach the OTScanIt log for me please.

Regards,
RatHat
  • 0

#6
calgooda1323

calgooda1323

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts
Sorry, I stopped to have lunch. here is the last thing you asked for. Thanks so much. I appreciate it!

[code=auto:0]OTScanIt logfile created on: 3/20/2008 12:46:22 PM
OTScanIt by OldTimer - Version 1.0.6.0 Folder = C:\Documents and Settings\Cortney\Desktop\OTScanIt
Windows XP Home Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

494.79 Mb Total Physical Memory | 189.40 Mb Available Physical Memory | 38.28% Memory free
1.13 Gb Paging File | 0.92 Gb Available in Paging File | 81.18% Paging File free
Paging file location(s): C:\pagefile.sys 744 1488;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 44.53 Gb Free Space | 79.67% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TOSHIBA-USER
Current User Name: Cortney
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users

[Processes - Non-Microsoft Only]
guard.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> MD5 = 5DCD235C061022BCDA9AA48670B64211 | GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 5/30/2007 6:31:10 AM | Attr = ]
dvdramsv.exe -> %SystemRoot%\system32\DVDRAMSV.exe -> MD5 = 77C4901986FC7A83E853B300E80D234B | Matsushita Electric Industrial Co., Ltd. [Ver = 2, 0, 7, 0 | Size = 106496 bytes | Modified Date = 5/23/2003 3:38:26 PM | Attr = ]
smagent.exe -> %ProgramFiles%\Analog Devices\SoundMAX\SMAgent.exe -> MD5 = 3978F082274F723AD5A0A8058C2417DD | Analog Devices, Inc. [Ver = 3, 2, 6, 0 | Size = 45056 bytes | Modified Date = 9/20/2002 6:50:10 PM | Attr = ]
igfxtray.exe -> %SystemRoot%\system32\igfxtray.exe -> MD5 = 095B56D71D4C6AF017712B0E59C66166 | Intel Corporation [Ver = 3,0,0,2104 | Size = 155648 bytes | Modified Date = 4/7/2003 2:19:52 AM | Attr = ]
hkcmd.exe -> %SystemRoot%\system32\hkcmd.exe -> MD5 = EE2AC08BE7024A781DF6F40870ED748D | Intel Corporation [Ver = 3,0,0,2104 | Size = 114688 bytes | Modified Date = 4/7/2003 2:07:38 AM | Attr = ]
agrsmmsg.exe -> %SystemRoot%\agrsmmsg.exe -> MD5 = 5EC78CA9B6DEB482211C39EAF32F4C8D | Agere Systems [Ver = 2.1.28.2 2.1.28.2 04/18/2003 11:20:08 | Size = 88363 bytes | Modified Date = 4/18/2003 1:20:00 PM | Attr = ]
apoint.exe -> %ProgramFiles%\Apoint2K\Apoint.exe -> MD5 = 0855E62B649AD268BCC265A074766ABE | Alps Electric Co., Ltd. [Ver = 6.0.2.171 | Size = 159744 bytes | Modified Date = 7/17/2003 7:38:54 PM | Attr = ]
touched.exe -> %ProgramFiles%\Toshiba\TouchED\TouchED.exe -> MD5 = 276684C9BA66189D43E4FA109F8F1471 | TOSHIBA Corporation [Ver = 2, 5, 0, 0 | Size = 126976 bytes | Modified Date = 1/21/2003 8:00:06 PM | Attr = ]
padexe.exe -> %ProgramFiles%\Toshiba\PadTouch\PadExe.exe -> MD5 = EB00DB4A50E1ED587313F94A575D89FC | TOSHIBA [Ver = 1, 2, 0, 0 | Size = 1019904 bytes | Modified Date = 10/31/2003 5:01:18 PM | Attr = ]
tpsmain.exe -> %SystemRoot%\system32\TPSMain.exe -> MD5 = CB1CB3B90F8351522AA847F0447D67E2 | TOSHIBA Corporation [Ver = 1, 0, 9, 0 | Size = 278528 bytes | Modified Date = 11/19/2003 11:15:38 PM | Attr = ]
pinger.exe -> %SystemDrive%\TOSHIBA\Ivp\ISM\pinger.exe -> MD5 = EB3C8C07A1C1286BAA3A676E1D16394D | TOSHIBA Corporation [Ver = 3.3 | Size = 159744 bytes | Modified Date = 10/20/2003 11:39:26 AM | Attr = ]
ltmoh.exe -> %ProgramFiles%\ltmoh\ltmoh.exe -> MD5 = FF1FEF8D3CCB479D1476AD9357505314 | Agere Systems [Ver = 1.69 | Size = 172032 bytes | Modified Date = 1/2/2003 6:16:00 PM | Attr = ]
00thotkey.exe -> %SystemRoot%\system32\00THotkey.exe -> MD5 = AF222D17FE557AF0828FF909C2F8EC72 | TOSHIBA Corp. [Ver = 1, 0, 0, 21 | Size = 258048 bytes | Modified Date = 4/15/2003 10:01:28 PM | Attr = ]
ezsp_px.exe -> %SystemRoot%\system32\ezSP_Px.exe -> MD5 = 2849ED071A0D83406BDA342AA767F24E | Easy Systems Japan Ltd. [Ver = 1, 0, 0, 0 | Size = 40960 bytes | Modified Date = 8/20/2002 12:29:26 PM | Attr = ]
tfnf5.exe -> %SystemRoot%\system32\TFNF5.exe -> MD5 = 6747A5E7AEC9C40F187E97A3140B80FB | TOSHIBA Corp. [Ver = 2, 4, 1, 0 | Size = 73728 bytes | Modified Date = 10/15/2003 6:03:38 PM | Attr = ]
apntex.exe -> %ProgramFiles%\Apoint2K\ApntEx.exe -> MD5 = CCA1B81492B40890E44B2B20A780EE1F | Alps Electric Co., Ltd. [Ver = 5.0.1.15 | Size = 45056 bytes | Modified Date = 2/26/2003 1:08:42 PM | Attr = ]
tpsbattm.exe -> %SystemRoot%\system32\TPSBattM.exe -> MD5 = 3C15A759FA351364DE76DC4F6D5913E6 | TOSHIBA Corporation [Ver = 1, 0, 2, 0 | Size = 45056 bytes | Modified Date = 11/19/2003 11:13:54 PM | Attr = ]
tfncky.exe -> %ProgramFiles%\Toshiba\TOSHIBA Controls\TFncKy.exe -> MD5 = F5140B1309A2A275F1200D07A67BA263 | TOSHIBA Corporation [Ver = 3.01.01 | Size = 102400 bytes | Modified Date = 8/18/2003 11:51:02 AM | Attr = ]
realplay.exe -> %ProgramFiles%\Real\RealPlayer\realplay.exe -> MD5 = 849D97FE4CC09CFC2772D10F641E1BAF | RealNetworks, Inc. [Ver = 6.0.9.584 | Size = 26112 bytes | Modified Date = 11/20/2003 7:24:42 PM | Attr = ]
qttask.exe -> %ProgramFiles%\QuickTime\qttask.exe -> MD5 = C9128AE6036CDF67873A516E1A00ED4B | Apple Computer, Inc. [Ver = 6.3 | Size = 77824 bytes | Modified Date = 11/20/2003 7:25:11 PM | Attr = ]
lxbtbmgr.exe -> %ProgramFiles%\Lexmark 5200 Series\lxbtbmgr.exe -> MD5 = AD421290A70C4F95C1AC9547B6D07046 | Lexmark International, Inc. [Ver = 1.0.8.2 | Size = 57344 bytes | Modified Date = 3/25/2004 7:30:30 AM | Attr = ]
lxbtbmon.exe -> %ProgramFiles%\Lexmark 5200 Series\lxbtbmon.exe -> MD5 = 3D0ACCAF97F2AEFD450A6187F02C5CBA | Lexmark International, Inc. [Ver = 1.0.8.2 | Size = 94208 bytes | Modified Date = 3/25/2004 7:44:28 AM | Attr = ]
hpgs2wnd.exe -> %ProgramFiles%\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe -> MD5 = D5BC63D2822B8E244E53D2FF8078CC6B | Hewlett-Packard [Ver = 2,3,0,0\ 162 | Size = 69632 bytes | Modified Date = 4/17/2002 12:42:56 PM | Attr = ]
hpztsb09.exe -> %SystemRoot%\system32\spool\drivers\w32x86\3\hpztsb09.exe -> MD5 = 76B130090C789ECBDE63CA5E4423020F | HP [Ver = 2.229.1.0 | Size = 188416 bytes | Modified Date = 5/6/2003 11:56:22 PM | Attr = ]
hpgs2wnf.exe -> %ProgramFiles%\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe -> MD5 = 59380D1808A83AA4150F550F45BEE3A9 | [Ver = 2, 6, 0, 162 | Size = 77824 bytes | Modified Date = 4/17/2002 12:49:16 PM | Attr = ]
avgas.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> MD5 = CC6BC45DD5A58158645E7FB2953604FE | GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 6/11/2007 3:25:42 AM | Attr = ]
toscdspd.exe -> %ProgramFiles%\Toshiba\TOSCDSPD\TOSCDSPD.exe -> MD5 = 383B71DCB691CCAEEA445ACB9150DDD3 | TOSHIBA [Ver = 1, 0, 5, 0 | Size = 65536 bytes | Modified Date = 9/5/2003 5:24:46 AM | Attr = ]
otscanit.exe -> %UserProfile%\Desktop\OTScanIt\OTScanIt.exe -> MD5 = D2F9EA5E3BC08D02039790C593A623EA | OldTimer Tools [Ver = 1.0.6.0 | Size = 311808 bytes | Modified Date = 3/19/2008 6:01:26 PM | Attr = ]

[Win32 Services - Non-Microsoft Only]

[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
!AVG Anti-Spyware -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> MD5 = CC6BC45DD5A58158645E7FB2953604FE | GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 6/11/2007 3:25:42 AM | Attr = ]
000StTHK -> %SystemRoot%\system32\000StTHK.exe -> MD5 = CCB1A96002F0888DA70964781C742A82 | [Ver = | Size = 24576 bytes | Modified Date = 6/23/2001 10:28:06 PM | Attr = ]
00THotkey -> %SystemRoot%\system32\00THotkey.exe -> MD5 = AF222D17FE557AF0828FF909C2F8EC72 | TOSHIBA Corp. [Ver = 1, 0, 0, 21 | Size = 258048 bytes | Modified Date = 4/15/2003 10:01:28 PM | Attr = ]
AGRSMMSG -> %SystemRoot%\agrsmmsg.exe -> MD5 = 5EC78CA9B6DEB482211C39EAF32F4C8D | Agere Systems [Ver = 2.1.28.2 2.1.28.2 04/18/2003 11:20:08 | Size = 88363 bytes | Modified Date = 4/18/2003 1:20:00 PM | Attr = ]
Apoint -> %ProgramFiles%\Apoint2K\Apoint.exe -> MD5 = 0855E62B649AD268BCC265A074766ABE | Alps Electric Co., Ltd. [Ver = 6.0.2.171 | Size = 159744 bytes | Modified Date = 7/17/2003 7:38:54 PM | Attr = ]
bm(1) -> %CommonProgramFiles%\AVSystemCare\bm.exe -> File not found
ezShieldProtector for Px -> %SystemRoot%\system32\ezSP_Px.exe -> MD5 = 2849ED071A0D83406BDA342AA767F24E | Easy Systems Japan Ltd. [Ver = 1, 0, 0, 0 | Size = 40960 bytes | Modified Date = 8/20/2002 12:29:26 PM | Attr = ]
HotKeysCmds -> %SystemRoot%\system32\hkcmd.exe -> MD5 = EE2AC08BE7024A781DF6F40870ED748D | Intel Corporation [Ver = 3,0,0,2104 | Size = 114688 bytes | Modified Date = 4/7/2003 2:07:38 AM | Attr = ]
HPDJ Taskbar Utility -> %SystemRoot%\system32\spool\drivers\w32x86\3\hpztsb09.exe -> MD5 = 76B130090C789ECBDE63CA5E4423020F | HP [Ver = 2.229.1.0 | Size = 188416 bytes | Modified Date = 5/6/2003 11:56:22 PM | Attr = ]
IgfxTray -> %SystemRoot%\system32\igfxtray.exe -> MD5 = 095B56D71D4C6AF017712B0E59C66166 | Intel Corporation [Ver = 3,0,0,2104 | Size = 155648 bytes | Modified Date = 4/7/2003 2:19:52 AM | Attr = ]
Lexmark 5200 series -> %ProgramFiles%\Lexmark 5200 Series\lxbtbmgr.exe -> MD5 = AD421290A70C4F95C1AC9547B6D07046 | Lexmark International, Inc. [Ver = 1.0.8.2 | Size = 57344 bytes | Modified Date = 3/25/2004 7:30:30 AM | Attr = ]
LtMoh -> %ProgramFiles%\ltmoh\ltmoh.exe -> MD5 = FF1FEF8D3CCB479D1476AD9357505314 | Agere Systems [Ver = 1.69 | Size = 172032 bytes | Modified Date = 1/2/2003 6:16:00 PM | Attr = ]
LXBTCATS -> %SystemRoot%\system32\spool\drivers\w32x86\3\lxbttime.dll -> MD5 = 0D86B9CEED7B4D146BFDCA9FC12342B8 | Lexmark International, Inc. [Ver = 0.1.11.5 | Size = 65536 bytes | Modified Date = 3/17/2004 10:30:06 AM | Attr = ]
PadTouch -> %ProgramFiles%\Toshiba\PadTouch\PadExe.exe -> MD5 = EB00DB4A50E1ED587313F94A575D89FC | TOSHIBA [Ver = 1, 2, 0, 0 | Size = 1019904 bytes | Modified Date = 10/31/2003 5:01:18 PM | Attr = ]
Pinger -> %SystemDrive%\TOSHIBA\Ivp\ISM\pinger.exe -> MD5 = EB3C8C07A1C1286BAA3A676E1D16394D | TOSHIBA Corporation [Ver = 3.3 | Size = 159744 bytes | Modified Date = 10/20/2003 11:39:26 AM | Attr = ]
QuickTime Task -> %ProgramFiles%\QuickTime\qttask.exe -> MD5 = C9128AE6036CDF67873A516E1A00ED4B | Apple Computer, Inc. [Ver = 6.3 | Size = 77824 bytes | Modified Date = 11/20/2003 7:25:11 PM | Attr = ]
RealTray -> %ProgramFiles%\Real\RealPlayer\realplay.exe -> MD5 = 849D97FE4CC09CFC2772D10F641E1BAF | RealNetworks, Inc. [Ver = 6.0.9.584 | Size = 26112 bytes | Modified Date = 11/20/2003 7:24:42 PM | Attr = ]
Share-to-Web Namespace Daemon -> %ProgramFiles%\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe -> MD5 = D5BC63D2822B8E244E53D2FF8078CC6B | Hewlett-Packard [Ver = 2,3,0,0\ 162 | Size = 69632 bytes | Modified Date = 4/17/2002 12:42:56 PM | Attr = ]
Symantec NetDriver Monitor -> %SystemDrive%\PROGRA~1\SYMNET~1\SNDMon.exe -> File not found
TFncKy -> -> File not found
TFNF5 -> %SystemRoot%\system32\TFNF5.exe -> MD5 = 6747A5E7AEC9C40F187E97A3140B80FB | TOSHIBA Corp. [Ver = 2, 4, 1, 0 | Size = 73728 bytes | Modified Date = 10/15/2003 6:03:38 PM | Attr = ]
TouchED -> %ProgramFiles%\Toshiba\TouchED\TouchED.exe -> MD5 = 276684C9BA66189D43E4FA109F8F1471 | TOSHIBA Corporation [Ver = 2, 5, 0, 0 | Size = 126976 bytes | Modified Date = 1/21/2003 8:00:06 PM | Attr = ]
TPSMain -> %SystemRoot%\system32\TPSMain.exe -> MD5 = CB1CB3B90F8351522AA847F0447D67E2 | TOSHIBA Corporation [Ver = 1, 0, 9, 0 | Size = 278528 bytes | Modified Date = 11/19/2003 11:15:38 PM | Attr = ]
zzzHPSETUP -> D:\Setup.exe -> File not found
< OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ ->
IMAIL-> Installed = 1 ->
MAPI-> Installed = 1 ->
MSFS-> Installed = 1 ->
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
Bihfqwe -> %AppData%\??sembly\??oolsv.exe -> File not found
Osus -> %SystemDrive%\PROGRA~1\COMMON~1\SKS~1\chkdsk.exe -> File not found
TOSCDSPD -> %ProgramFiles%\Toshiba\TOSCDSPD\TOSCDSPD.exe -> MD5 = 383B71DCB691CCAEEA445ACB9150DDD3 | TOSHIBA [Ver = 1, 0, 5, 0 | Size = 65536 bytes | Modified Date = 9/5/2003 5:24:46 AM | Attr = ]
< Run [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
Bihfqwe -> %AppData%\??sembly\??oolsv.exe -> File not found
Osus -> %SystemDrive%\PROGRA~1\COMMON~1\SKS~1\chkdsk.exe -> File not found
TOSCDSPD -> %ProgramFiles%\Toshiba\TOSCDSPD\TOSCDSPD.exe -> MD5 = 383B71DCB691CCAEEA445ACB9150DDD3 | TOSHIBA [Ver = 1, 0, 5, 0 | Size = 65536 bytes | Modified Date = 9/5/2003 5:24:46 AM | Attr = ]
< Administrator.TOSHIBA-USER Startup Folder > -> C:\Documents and Settings\Administrator.TOSHIBA-USER\Start Menu\Programs\Startup ->
< Administrator.TOSHIBA-USER.000 Startup Folder > -> C:\Documents and Settings\Administrator.TOSHIBA-USER.000\Start Menu\Programs\Startup ->
< Administrator.TOSHIBA-USER.001 Startup Folder > -> C:\Documents and Settings\Administrator.TOSHIBA-USER.001\Start Menu\Programs\Startup ->
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersProfile%\Start Menu\Programs\Startup\Trend Micro Anti-Spyware.lnk -> %ProgramFiles%\Trend Micro\Tmas\Tmas.exe -> MD5 = 1236495A7A4C48067AB03A4D63A5F39E | Trend Micro Incorporated [Ver = 3, 0, 1, 22 | Size = 1306624 bytes | Modified Date = 5/26/2006 4:17:03 PM | Attr = ]
< Cortney Startup Folder > -> C:\Documents and Settings\Cortney\Start Menu\Programs\Startup ->
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup ->
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
{03A80B1D-5C6A-42c2-9DFB-81B6005D8023} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Trend Micro\Tmas\sshook.dll [Trend Micro Anti-Spyware Shell Extension] -> MD5 = 495BE3A7300929FEA1C064599861E33D | Trend Micro Incorporated [Ver = 3, 0, 1, 22 | Size = 77824 bytes | Modified Date = 5/26/2006 4:17:03 PM | Attr = ]
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> MD5 = 3FD0B984601D65C6DA8E891A0D5905D1 | GRISOFT s.r.o. [Ver = 7, 5, 1, 36 | Size = 79408 bytes | Modified Date = 5/30/2007 6:29:58 AM | Attr = ]
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
igfxcui -> %SystemRoot%\system32\igfxsrvc.dll -> MD5 = 6474AF152CD6025F781D7A5F2B8B6084 | Intel Corporation [Ver = 3,0,0,2104 | Size = 315392 bytes | Modified Date = 4/7/2003 2:06:48 AM | Attr = ]
WRNotifier -> -> File not found
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoCDBurning -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoDriveAutoRun -> 67108863 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoDriveTypeAutoRun -> 255 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.comcast.net/ ->
HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\System32\blank.htm ->
HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_CURRENT_USER\: Main\\Start Page -> http://www.comcast.net/ ->
HKEY_CURRENT_USER\: Search\\SearchAssistant -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_CURRENT_USER\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: Main\\Local Page -> C:\WINDOWS\System32\blank.htm ->
HKEY_USERS\.DEFAULT\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\.DEFAULT\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome ->
HKEY_USERS\.DEFAULT\: URLSearchHooks\\{DF944EA8-F762-80BE-4DF7-F25A654D40E0} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
HKEY_USERS\.DEFAULT\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: Main\\Local Page -> C:\WINDOWS\System32\blank.htm ->
HKEY_USERS\S-1-5-18\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-18\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome ->
HKEY_USERS\S-1-5-18\: URLSearchHooks\\{DF944EA8-F762-80BE-4DF7-F25A654D40E0} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
HKEY_USERS\S-1-5-18\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
HKEY_USERS\S-1-5-19\: Main\\Search Bar -> http://www.toshiba.com/search ->
HKEY_USERS\S-1-5-19\: Main\\Start Page -> http://www.toshiba.com ->
HKEY_USERS\S-1-5-19\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
HKEY_USERS\S-1-5-20\: Main\\Search Bar -> http://www.toshiba.com/search ->
HKEY_USERS\S-1-5-20\: Main\\Start Page -> http://www.toshiba.com ->
HKEY_USERS\S-1-5-20\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\] > -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\: Main\\Local Page -> C:\WINDOWS\System32\blank.htm ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\: Main\\Start Page -> http://www.comcast.net/ ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\: Search\\SearchAssistant -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\: ProxyEnable -> 0 ->
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
.[msn] -> My Computer ->
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
.[msn] -> My Computer ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. ->
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [AcroIEHlprObj Class] -> MD5 = 8394ABFC1BE196A62C9F532511936DF7 | [Ver = 1, 0, 0, 1 | Size = 37808 bytes | Modified Date = 3/2/2001 2:02:04 PM | Attr = ]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{8E718888-423F-11D2-876E-00A0C9082467} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\msdxm.ocx [&Radio] -> MD5 = D4EB4DD8ABD6B75B86F169F6572B8FF7 | [Ver = | Size = 842268 bytes | Modified Date = 3/31/2003 6:00:00 AM | Attr = ]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MSN Toolbar\01.01.2607.0\en-us\msntb.dll [MSN Toolbar] -> File not found
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MSN Toolbar\01.01.2607.0\en-us\msntb.dll [MSN Toolbar] -> File not found
< Internet Explorer ToolBars [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MSN Toolbar\01.01.2607.0\en-us\msntb.dll [MSN Toolbar] -> File not found
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MSN Toolbar\01.01.2607.0\en-us\msntb.dll [MSN Toolbar] -> File not found
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MSN Toolbar\01.01.2607.0\en-us\msntb.dll [MSN Toolbar] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\j2re1.4.2\bin\NPJPI142.dll [Sun Java Console] -> MD5 = 4ACFBF6AB1BBE79DBD665C186B3B5AFD | JavaSoft / Sun Microsystems, Inc. [Ver = 1, 4, 2, 0 | Size = 65636 bytes | Modified Date = 11/20/2003 6:41:51 PM | Attr = ]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\j2re1.4.2\bin\NPJPI142.dll [Sun Java Console] -> MD5 = 4ACFBF6AB1BBE79DBD665C186B3B5AFD | JavaSoft / Sun Microsystems, Inc. [Ver = 1, 4, 2, 0 | Size = 65636 bytes | Modified Date = 11/20/2003 6:41:51 PM | Attr = ]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\j2re1.4.2\bin\NPJPI142.dll [Sun Java Console] -> MD5 = 4ACFBF6AB1BBE79DBD665C186B3B5AFD | JavaSoft / Sun Microsystems, Inc. [Ver = 1, 4, 2, 0 | Size = 65636 bytes | Modified Date = 11/20/2003 6:41:51 PM | Attr = ]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\j2re1.4.2\bin\NPJPI142.dll [Sun Java Console] -> MD5 = 4ACFBF6AB1BBE79DBD665C186B3B5AFD | JavaSoft / Sun Microsystems, Inc. [Ver = 1, 4, 2, 0 | Size = 65636 bytes | Modified Date = 11/20/2003 6:41:51 PM | Attr = ]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\j2re1.4.2\bin\NPJPI142.dll [Sun Java Console] -> MD5 = 4ACFBF6AB1BBE79DBD665C186B3B5AFD | JavaSoft / Sun Microsystems, Inc. [Ver = 1, 4, 2, 0 | Size = 65636 bytes | Modified Date = 11/20/2003 6:41:51 PM | Attr = ]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s ->
Extension\.csm -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.csml -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.cub -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.cube -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.dx -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.emb -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.embl -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.gau -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.jdx -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.mol -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.mop -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.pdb -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.rxn -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.scr -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.skc -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.spop -> %ProgramFiles%\Internet Explorer\Plugins\NPDocBox.dll [] -> File not found
Extension\.spt -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.tgf -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.xyz -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{6613F300-8483-491B-A626-E114A0FB6021} -> (Intel(R) PRO/100 VE Network Connection) ->
{EACB5FB4-6033-4169-A880-A47961BBD358} -> (Atheros AR5001X+ Wireless Network Adapter) ->
< Default Protocols [HKEY_USERS\.DEFAULT\] - Select to Repair > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Default Protocols [HKEY_USERS\S-1-5-18\] - Select to Repair > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Default Protocols [HKEY_USERS\S-1-5-19\] - Select to Repair > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Default Protocols [HKEY_USERS\S-1-5-20\] - Select to Repair > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found
msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found
vnd.ms.radio:{3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\msdxm.ocx[AsyncPProt Class] -> MD5 = D4EB4DD8ABD6B75B86F169F6572B8FF7 | [Ver = | Size = 842268 bytes | Modified Date = 3/31/2003 6:00:00 AM | Attr = ]
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{166B1BCA-3F9C-11CF-8075-444553540000}[HKEY_LOCAL_MACHINE] -> http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab[Shockwave ActiveX Control] ->
{37A273C2-5129-11D5-BF37-00A0CCE8754B}[HKEY_LOCAL_MACHINE] -> http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab[TTestGenXInstallObject] ->
{406B5949-7190-4245-91A9-30A17DE16AD0}[HKEY_LOCAL_MACHINE] -> http://photo.walgreens.com/WalgreensActivia.cab[Snapfish Activia] ->
{4F1E5B1A-2A80-42CA-8532-2D05CB959537}[HKEY_LOCAL_MACHINE] -> http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab[MSN Photo Upload Tool] ->
{58FC4C77-71C2-4972-A8CD-78691AD85158}[HKEY_LOCAL_MACHINE] -> http://www.worldwinner.com/games/v49/bjattack/bjattack.cab[BJA Control] ->
{6414512B-B978-451D-A0D8-FCFDF33E833C}[HKEY_LOCAL_MACHINE] -> http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1141762598718[WUWebControl Class] ->
{8A94C905-FF9D-43B6-8708-F0F22D22B1CB}[HKEY_LOCAL_MACHINE] -> http://www.worldwinner.com/games/shared/wwlaunch.cab[Wwlaunch Control] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.4.2/jinstall-1_4_2-windows-i586.cab[Java Plug-in 1.4.2] ->
{95D88B35-A521-472B-A182-BB1A98356421}[HKEY_LOCAL_MACHINE] -> http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab[Pearson Installation Assistant 2] ->
{A30FBBDC-FA29-4606-8565-14AADCCA6708}[HKEY_LOCAL_MACHINE] -> https://photos.riteaid.com/control/RiteAidOneHourPhotoOnline.cab[Rite Aid One Hour Photo Online Control] ->
{A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F}[HKEY_LOCAL_MACHINE] -> http://www.worldwinner.com/games/v45/wof/wof.cab[WoF Control] ->
{A8683C98-5341-421B-B23C-8514C05354F1}[HKEY_LOCAL_MACHINE] -> http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab[FujifilmUploader Class] ->
{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}[HKEY_LOCAL_MACHINE] -> http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab[MsnMessengerSetupDownloadControl Class] ->
{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.4.2/jinstall-1_4_2-windows-i586.cab[Java Plug-in 1.4.2] ->
{CC32D4D8-2A0B-4CEB-B105-C9B968379105}[HKEY_LOCAL_MACHINE] -> https://disney.go.com/games/downloads/gamemanager/DIGGameManager.cab[CGameManagerCtrl Object] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] ->
{E6D23284-0E9B-417D-A782-03E4487FC947}[HKEY_LOCAL_MACHINE] -> http://asp.mathxl.com/books/_Players/MathPlayer.cab[Pearson MathXL Player] ->
{FAE74270-E5EE-49C3-B816-EA8B4D55F38F}[HKEY_LOCAL_MACHINE] -> http://www.worldwinner.com/games/v51/h2hpool/h2hpool.cab[H2hPool Control] ->



[Files/Folders - Created Within 90 days]
AVSystemCare -> %SystemDrive%\AVSystemCare -> [Folder | Created Date = 3/19/2008 11:56:53 AM | Attr = HS]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Created Date = 3/14/2008 10:26:55 PM | Attr = HS]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> Unable to obtain MD5 | [Ver = | Size = 518901760 bytes | Created Date = 3/15/2008 10:34:22 AM | Attr = HS]
QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 3/20/2008 10:47:47 AM | Attr = ]
sqmdata07.sqm -> %SystemDrive%\sqmdata07.sqm -> MD5 = 108B06B4BEA5E62E2968256C310E4AED | [Ver = | Size = 268 bytes | Created Date = 12/28/2007 1:34:42 PM | Attr = H ]
sqmdata08.sqm -> %SystemDrive%\sqmdata08.sqm -> MD5 = 29C2D0DCC74BBC5FCB6A08DB60A923BF | [Ver = | Size = 268 bytes | Created Date = 12/31/2007 12:10:52 AM | Attr = H ]
sqmdata09.sqm -> %SystemDrive%\sqmdata09.sqm -> MD5 = F265233E8CC05ED7A510EC621F4EA65F | [Ver = | Size = 268 bytes | Created Date = 1/1/2008 12:10:01 AM | Attr = H ]
sqmdata10.sqm -> %SystemDrive%\sqmdata10.sqm -> MD5 = BCF67B2379D3D178C7036E93595A9B90 | [Ver = | Size = 232 bytes | Created Date = 2/14/2008 4:38:51 PM | Attr = H ]
sqmdata11.sqm -> %SystemDrive%\sqmdata11.sqm -> MD5 = B4B24A51DE4878913A158B9A70C9209B | [Ver = | Size = 268 bytes | Created Date = 2/14/2008 7:54:16 PM | Attr = H ]
sqmdata12.sqm -> %SystemDrive%\sqmdata12.sqm -> MD5 = 8B7C2CA016409B662BEC477215014A54 | [Ver = | Size = 268 bytes | Created Date = 2/14/2008 8:02:18 PM | Attr = H ]
sqmdata13.sqm -> %SystemDrive%\sqmdata13.sqm -> MD5 = 2512A9A927BF3F0D8393D5AF62BF7796 | [Ver = | Size = 268 bytes | Created Date = 2/14/2008 8:24:27 PM | Attr = H ]
sqmnoopt07.sqm -> %SystemDrive%\sqmnoopt07.sqm -> MD5 = 21B789C114568BF5BEDDF8EC78177E58 | [Ver = | Size = 244 bytes | Created Date = 12/28/2007 1:34:41 PM | Attr = H ]
sqmnoopt08.sqm -> %SystemDrive%\sqmnoopt08.sqm -> MD5 = 17A78D8E3D7C9D6F6711BB79D04755DE | [Ver = | Size = 244 bytes | Created Date = 12/31/2007 12:10:52 AM | Attr = H ]
sqmnoopt09.sqm -> %SystemDrive%\sqmnoopt09.sqm -> MD5 = 087B1FE3D014D699720351099457CB0B | [Ver = | Size = 244 bytes | Created Date = 1/1/2008 12:10:01 AM | Attr = H ]
sqmnoopt10.sqm -> %SystemDrive%\sqmnoopt10.sqm -> MD5 = 11D07E12D1BCEEA6FB7B828D03C5ED21 | [Ver = | Size = 244 bytes | Created Date = 2/14/2008 4:38:50 PM | Attr = H ]
sqmnoopt11.sqm -> %SystemDrive%\sqmnoopt11.sqm -> MD5 = 27D4F83158982E1D14CAADF198A0B578 | [Ver = | Size = 244 bytes | Created Date = 2/14/2008 7&
  • 0

#7
calgooda1323

calgooda1323

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts
ok, I don't think the whole thing made it on the last post so I attached it to this one.

Attached Files


  • 0

#8
RatHat

RatHat

    Ex Malware Expert

  • Expert
  • 7,829 posts
Start OTScanIt.exe Copy/Paste the information in the codebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Unregister Dlls]
[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> bm(1) -> %CommonProgramFiles%\AVSystemCare\bm.exe
YN -> Symantec NetDriver Monitor -> %SystemDrive%\PROGRA~1\SYMNET~1\SNDMon.exe
YN -> zzzHPSETUP -> D:\Setup.exe
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> Bihfqwe -> %AppData%\??sembly\??oolsv.exe
YN -> Osus -> %SystemDrive%\PROGRA~1\COMMON~1\SKS~1\chkdsk.exe
< Run [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> Bihfqwe -> %AppData%\??sembly\??oolsv.exe
YN -> Osus -> %SystemDrive%\PROGRA~1\COMMON~1\SKS~1\chkdsk.exe
[Files/Folders - Created Within 90 days]
NY -> dmidicuq.dllbox -> %SystemRoot%\System32\dmidicuq.dllbox
NY -> dyqosxhi.ini -> %SystemRoot%\System32\dyqosxhi.ini
NY -> fawrqdzp.dllbox -> %SystemRoot%\System32\fawrqdzp.dllbox
NY -> fbpmvkvo.dllbox -> %SystemRoot%\System32\fbpmvkvo.dllbox
NY -> fflknyls.dllbox -> %SystemRoot%\System32\fflknyls.dllbox
NY -> gkooxraf.dllbox -> %SystemRoot%\System32\gkooxraf.dllbox
NY -> gpjynzzk.dllbox -> %SystemRoot%\System32\gpjynzzk.dllbox
NY -> hkxiswhs.dllbox -> %SystemRoot%\System32\hkxiswhs.dllbox
NY -> hsvjpgfy.ini -> %SystemRoot%\System32\hsvjpgfy.ini
NY -> itdsloxu.dllbox -> %SystemRoot%\System32\itdsloxu.dllbox
NY -> jqxdcveb.ini -> %SystemRoot%\System32\jqxdcveb.ini
NY -> lejbyagv.dll -> %SystemRoot%\System32\lejbyagv.dll
NY -> phyirirs.ini -> %SystemRoot%\System32\phyirirs.ini
NY -> ppczfhff.dllbox -> %SystemRoot%\System32\ppczfhff.dllbox
NY -> qiwnoror.dllbox -> %SystemRoot%\System32\qiwnoror.dllbox
NY -> qmmpamfc.dllbox -> %SystemRoot%\System32\qmmpamfc.dllbox
NY -> rcjhdvam.ini -> %SystemRoot%\System32\rcjhdvam.ini
NY -> rhzjydjr.dllbox -> %SystemRoot%\System32\rhzjydjr.dllbox
NY -> rnnbyhpu.dllbox -> %SystemRoot%\System32\rnnbyhpu.dllbox
NY -> sed.exe -> %SystemRoot%\System32\sed.exe
NY -> xhivjxsx.dllbox -> %SystemRoot%\System32\xhivjxsx.dllbox
NY -> xmckfhre.ini -> %SystemRoot%\System32\xmckfhre.ini
NY -> zggoajgl.dllbox -> %SystemRoot%\System32\zggoajgl.dllbox
NY -> zip.exe -> %SystemRoot%\System32\zip.exe
NY -> zxdwicxn.dllbox -> %SystemRoot%\System32\zxdwicxn.dllbox
NY -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> mrofinu1000106.exe -> %SystemRoot%\mrofinu1000106.exe
NY -> mrofinu572.exe -> %SystemRoot%\mrofinu572.exe
[Files/Folders - Modified Within 90 days]
NY -> 479 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> dyqosxhi.ini -> %SystemRoot%\System32\dyqosxhi.ini
NY -> fawrqdzp.dllbox -> %SystemRoot%\System32\fawrqdzp.dllbox
NY -> fbpmvkvo.dllbox -> %SystemRoot%\System32\fbpmvkvo.dllbox
NY -> fflknyls.dllbox -> %SystemRoot%\System32\fflknyls.dllbox
NY -> gkooxraf.dllbox -> %SystemRoot%\System32\gkooxraf.dllbox
NY -> gpjynzzk.dllbox -> %SystemRoot%\System32\gpjynzzk.dllbox
NY -> hkxiswhs.dllbox -> %SystemRoot%\System32\hkxiswhs.dllbox
NY -> hsvjpgfy.ini -> %SystemRoot%\System32\hsvjpgfy.ini
NY -> itdsloxu.dllbox -> %SystemRoot%\System32\itdsloxu.dllbox
NY -> jqxdcveb.ini -> %SystemRoot%\System32\jqxdcveb.ini
NY -> lejbyagv.dll -> %SystemRoot%\System32\lejbyagv.dll
NY -> phyirirs.ini -> %SystemRoot%\System32\phyirirs.ini
NY -> ppczfhff.dllbox -> %SystemRoot%\System32\ppczfhff.dllbox
NY -> qiwnoror.dllbox -> %SystemRoot%\System32\qiwnoror.dllbox
NY -> qmmpamfc.dllbox -> %SystemRoot%\System32\qmmpamfc.dllbox
NY -> rcjhdvam.ini -> %SystemRoot%\System32\rcjhdvam.ini
NY -> rhzjydjr.dllbox -> %SystemRoot%\System32\rhzjydjr.dllbox
NY -> rnnbyhpu.dllbox -> %SystemRoot%\System32\rnnbyhpu.dllbox
NY -> xhivjxsx.dllbox -> %SystemRoot%\System32\xhivjxsx.dllbox
NY -> xmckfhre.ini -> %SystemRoot%\System32\xmckfhre.ini
NY -> zggoajgl.dllbox -> %SystemRoot%\System32\zggoajgl.dllbox
NY -> zxdwicxn.dllbox -> %SystemRoot%\System32\zxdwicxn.dllbox
NY -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> mrofinu1000106.exe -> %SystemRoot%\mrofinu1000106.exe
NY -> mrofinu572.exe -> %SystemRoot%\mrofinu572.exe
[Extra Files]
Purity
[Empty Temp Folders]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new OTScanIt scan.

Let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Please run an online scan with Kaspersky WebScanner. Note: You must use Internet Explorer to run this scan.

Click the Accept button.

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display the results if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop as Kaspersky.txt.
  • Copy and paste that information in your next post.

Regards,
RatHat
  • 0

#9
calgooda1323

calgooda1323

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts
Ok, I ran that fix from OTScanIt and nothing happens after I run it. It asks me if I want to reboot I have said yes and no and no box comes up that gives me thing to post. Am I doing something wrong? It acts like the fix did run though.
  • 0

#10
RatHat

RatHat

    Ex Malware Expert

  • Expert
  • 7,829 posts
Could you run OTScanIt again, and post me the log, then I will be able to see what it has deleted.

Regards,
RatHat
  • 0

Advertisements


#11
calgooda1323

calgooda1323

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts
Ok here is the thing from Kapersky

Attached Files


  • 0

#12
calgooda1323

calgooda1323

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts
OK, here is the OtscanIT again! How does it look?

[code=auto:0]OTScanIt logfile created on: 3/20/2008 3:11:08 PM
OTScanIt by OldTimer - Version 1.0.6.0 Folder = C:\Documents and Settings\Cortney\Desktop\OTScanIt
Windows XP Home Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

494.79 Mb Total Physical Memory | 192.09 Mb Available Physical Memory | 38.82% Memory free
1.13 Gb Paging File | 0.76 Gb Available in Paging File | 67.50% Paging File free
Paging file location(s): C:\pagefile.sys 744 1488;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 44.61 Gb Free Space | 79.82% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TOSHIBA-USER
Current User Name: Cortney
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users

[Processes - Non-Microsoft Only]
igfxtray.exe -> %SystemRoot%\system32\igfxtray.exe -> MD5 = 095B56D71D4C6AF017712B0E59C66166 | Intel Corporation [Ver = 3,0,0,2104 | Size = 155648 bytes | Modified Date = 4/7/2003 2:19:52 AM | Attr = ]
hkcmd.exe -> %SystemRoot%\system32\hkcmd.exe -> MD5 = EE2AC08BE7024A781DF6F40870ED748D | Intel Corporation [Ver = 3,0,0,2104 | Size = 114688 bytes | Modified Date = 4/7/2003 2:07:38 AM | Attr = ]
agrsmmsg.exe -> %SystemRoot%\agrsmmsg.exe -> MD5 = 5EC78CA9B6DEB482211C39EAF32F4C8D | Agere Systems [Ver = 2.1.28.2 2.1.28.2 04/18/2003 11:20:08 | Size = 88363 bytes | Modified Date = 4/18/2003 1:20:00 PM | Attr = ]
apoint.exe -> %ProgramFiles%\Apoint2K\Apoint.exe -> MD5 = 0855E62B649AD268BCC265A074766ABE | Alps Electric Co., Ltd. [Ver = 6.0.2.171 | Size = 159744 bytes | Modified Date = 7/17/2003 7:38:54 PM | Attr = ]
touched.exe -> %ProgramFiles%\Toshiba\TouchED\TouchED.exe -> MD5 = 276684C9BA66189D43E4FA109F8F1471 | TOSHIBA Corporation [Ver = 2, 5, 0, 0 | Size = 126976 bytes | Modified Date = 1/21/2003 8:00:06 PM | Attr = ]
guard.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> MD5 = 5DCD235C061022BCDA9AA48670B64211 | GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 5/30/2007 6:31:10 AM | Attr = ]
padexe.exe -> %ProgramFiles%\Toshiba\PadTouch\PadExe.exe -> MD5 = EB00DB4A50E1ED587313F94A575D89FC | TOSHIBA [Ver = 1, 2, 0, 0 | Size = 1019904 bytes | Modified Date = 10/31/2003 5:01:18 PM | Attr = ]
apntex.exe -> %ProgramFiles%\Apoint2K\ApntEx.exe -> MD5 = CCA1B81492B40890E44B2B20A780EE1F | Alps Electric Co., Ltd. [Ver = 5.0.1.15 | Size = 45056 bytes | Modified Date = 2/26/2003 1:08:42 PM | Attr = ]
dvdramsv.exe -> %SystemRoot%\system32\DVDRAMSV.exe -> MD5 = 77C4901986FC7A83E853B300E80D234B | Matsushita Electric Industrial Co., Ltd. [Ver = 2, 0, 7, 0 | Size = 106496 bytes | Modified Date = 5/23/2003 3:38:26 PM | Attr = ]
tpsmain.exe -> %SystemRoot%\system32\TPSMain.exe -> MD5 = CB1CB3B90F8351522AA847F0447D67E2 | TOSHIBA Corporation [Ver = 1, 0, 9, 0 | Size = 278528 bytes | Modified Date = 11/19/2003 11:15:38 PM | Attr = ]
pinger.exe -> %SystemDrive%\TOSHIBA\Ivp\ISM\pinger.exe -> MD5 = EB3C8C07A1C1286BAA3A676E1D16394D | TOSHIBA Corporation [Ver = 3.3 | Size = 159744 bytes | Modified Date = 10/20/2003 11:39:26 AM | Attr = ]
ltmoh.exe -> %ProgramFiles%\ltmoh\ltmoh.exe -> MD5 = FF1FEF8D3CCB479D1476AD9357505314 | Agere Systems [Ver = 1.69 | Size = 172032 bytes | Modified Date = 1/2/2003 6:16:00 PM | Attr = ]
00thotkey.exe -> %SystemRoot%\system32\00THotkey.exe -> MD5 = AF222D17FE557AF0828FF909C2F8EC72 | TOSHIBA Corp. [Ver = 1, 0, 0, 21 | Size = 258048 bytes | Modified Date = 4/15/2003 10:01:28 PM | Attr = ]
ezsp_px.exe -> %SystemRoot%\system32\ezSP_Px.exe -> MD5 = 2849ED071A0D83406BDA342AA767F24E | Easy Systems Japan Ltd. [Ver = 1, 0, 0, 0 | Size = 40960 bytes | Modified Date = 8/20/2002 12:29:26 PM | Attr = ]
tfnf5.exe -> %SystemRoot%\system32\TFNF5.exe -> MD5 = 6747A5E7AEC9C40F187E97A3140B80FB | TOSHIBA Corp. [Ver = 2, 4, 1, 0 | Size = 73728 bytes | Modified Date = 10/15/2003 6:03:38 PM | Attr = ]
tfncky.exe -> %ProgramFiles%\Toshiba\TOSHIBA Controls\TFncKy.exe -> MD5 = F5140B1309A2A275F1200D07A67BA263 | TOSHIBA Corporation [Ver = 3.01.01 | Size = 102400 bytes | Modified Date = 8/18/2003 11:51:02 AM | Attr = ]
realplay.exe -> %ProgramFiles%\Real\RealPlayer\realplay.exe -> MD5 = 849D97FE4CC09CFC2772D10F641E1BAF | RealNetworks, Inc. [Ver = 6.0.9.584 | Size = 26112 bytes | Modified Date = 11/20/2003 7:24:42 PM | Attr = ]
qttask.exe -> %ProgramFiles%\QuickTime\qttask.exe -> MD5 = C9128AE6036CDF67873A516E1A00ED4B | Apple Computer, Inc. [Ver = 6.3 | Size = 77824 bytes | Modified Date = 11/20/2003 7:25:11 PM | Attr = ]
lxbtbmgr.exe -> %ProgramFiles%\Lexmark 5200 Series\lxbtbmgr.exe -> MD5 = AD421290A70C4F95C1AC9547B6D07046 | Lexmark International, Inc. [Ver = 1.0.8.2 | Size = 57344 bytes | Modified Date = 3/25/2004 7:30:30 AM | Attr = ]
hpgs2wnd.exe -> %ProgramFiles%\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe -> MD5 = D5BC63D2822B8E244E53D2FF8078CC6B | Hewlett-Packard [Ver = 2,3,0,0\ 162 | Size = 69632 bytes | Modified Date = 4/17/2002 12:42:56 PM | Attr = ]
hpztsb09.exe -> %SystemRoot%\system32\spool\drivers\w32x86\3\hpztsb09.exe -> MD5 = 76B130090C789ECBDE63CA5E4423020F | HP [Ver = 2.229.1.0 | Size = 188416 bytes | Modified Date = 5/6/2003 11:56:22 PM | Attr = ]
avgas.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> MD5 = CC6BC45DD5A58158645E7FB2953604FE | GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 6/11/2007 3:25:42 AM | Attr = ]
smagent.exe -> %ProgramFiles%\Analog Devices\SoundMAX\SMAgent.exe -> MD5 = 3978F082274F723AD5A0A8058C2417DD | Analog Devices, Inc. [Ver = 3, 2, 6, 0 | Size = 45056 bytes | Modified Date = 9/20/2002 6:50:10 PM | Attr = ]
toscdspd.exe -> %ProgramFiles%\Toshiba\TOSCDSPD\TOSCDSPD.exe -> MD5 = 383B71DCB691CCAEEA445ACB9150DDD3 | TOSHIBA [Ver = 1, 0, 5, 0 | Size = 65536 bytes | Modified Date = 9/5/2003 5:24:46 AM | Attr = ]
tmas.exe -> %ProgramFiles%\Trend Micro\Tmas\Tmas.exe -> MD5 = 1236495A7A4C48067AB03A4D63A5F39E | Trend Micro Incorporated [Ver = 3, 0, 1, 22 | Size = 1306624 bytes | Modified Date = 5/26/2006 4:17:03 PM | Attr = ]
lxbtbmon.exe -> %ProgramFiles%\Lexmark 5200 Series\lxbtbmon.exe -> MD5 = 3D0ACCAF97F2AEFD450A6187F02C5CBA | Lexmark International, Inc. [Ver = 1.0.8.2 | Size = 94208 bytes | Modified Date = 3/25/2004 7:44:28 AM | Attr = ]
tpsbattm.exe -> %SystemRoot%\system32\TPSBattM.exe -> MD5 = 3C15A759FA351364DE76DC4F6D5913E6 | TOSHIBA Corporation [Ver = 1, 0, 2, 0 | Size = 45056 bytes | Modified Date = 11/19/2003 11:13:54 PM | Attr = ]
hpgs2wnf.exe -> %ProgramFiles%\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe -> MD5 = 59380D1808A83AA4150F550F45BEE3A9 | [Ver = 2, 6, 0, 162 | Size = 77824 bytes | Modified Date = 4/17/2002 12:49:16 PM | Attr = ]
firefox.exe -> %ProgramFiles%\Mozilla Firefox\firefox.exe -> MD5 = B8E1B08FD736DBAB8DBC850CC078E5CE | Mozilla Corporation [Ver = 1.8.0.12: 2007050813 | Size = 7209069 bytes | Modified Date = 7/19/2007 10:11:38 PM | Attr = ]
otscanit.exe -> %UserProfile%\Desktop\OTScanIt\OTScanIt.exe -> MD5 = D2F9EA5E3BC08D02039790C593A623EA | OldTimer Tools [Ver = 1.0.6.0 | Size = 311808 bytes | Modified Date = 3/19/2008 6:01:26 PM | Attr = ]

[Win32 Services - Non-Microsoft Only]

[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
!AVG Anti-Spyware -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> MD5 = CC6BC45DD5A58158645E7FB2953604FE | GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 6/11/2007 3:25:42 AM | Attr = ]
000StTHK -> %SystemRoot%\system32\000StTHK.exe -> MD5 = CCB1A96002F0888DA70964781C742A82 | [Ver = | Size = 24576 bytes | Modified Date = 6/23/2001 10:28:06 PM | Attr = ]
00THotkey -> %SystemRoot%\system32\00THotkey.exe -> MD5 = AF222D17FE557AF0828FF909C2F8EC72 | TOSHIBA Corp. [Ver = 1, 0, 0, 21 | Size = 258048 bytes | Modified Date = 4/15/2003 10:01:28 PM | Attr = ]
AGRSMMSG -> %SystemRoot%\agrsmmsg.exe -> MD5 = 5EC78CA9B6DEB482211C39EAF32F4C8D | Agere Systems [Ver = 2.1.28.2 2.1.28.2 04/18/2003 11:20:08 | Size = 88363 bytes | Modified Date = 4/18/2003 1:20:00 PM | Attr = ]
Apoint -> %ProgramFiles%\Apoint2K\Apoint.exe -> MD5 = 0855E62B649AD268BCC265A074766ABE | Alps Electric Co., Ltd. [Ver = 6.0.2.171 | Size = 159744 bytes | Modified Date = 7/17/2003 7:38:54 PM | Attr = ]
ezShieldProtector for Px -> %SystemRoot%\system32\ezSP_Px.exe -> MD5 = 2849ED071A0D83406BDA342AA767F24E | Easy Systems Japan Ltd. [Ver = 1, 0, 0, 0 | Size = 40960 bytes | Modified Date = 8/20/2002 12:29:26 PM | Attr = ]
HotKeysCmds -> %SystemRoot%\system32\hkcmd.exe -> MD5 = EE2AC08BE7024A781DF6F40870ED748D | Intel Corporation [Ver = 3,0,0,2104 | Size = 114688 bytes | Modified Date = 4/7/2003 2:07:38 AM | Attr = ]
HPDJ Taskbar Utility -> %SystemRoot%\system32\spool\drivers\w32x86\3\hpztsb09.exe -> MD5 = 76B130090C789ECBDE63CA5E4423020F | HP [Ver = 2.229.1.0 | Size = 188416 bytes | Modified Date = 5/6/2003 11:56:22 PM | Attr = ]
IgfxTray -> %SystemRoot%\system32\igfxtray.exe -> MD5 = 095B56D71D4C6AF017712B0E59C66166 | Intel Corporation [Ver = 3,0,0,2104 | Size = 155648 bytes | Modified Date = 4/7/2003 2:19:52 AM | Attr = ]
Lexmark 5200 series -> %ProgramFiles%\Lexmark 5200 Series\lxbtbmgr.exe -> MD5 = AD421290A70C4F95C1AC9547B6D07046 | Lexmark International, Inc. [Ver = 1.0.8.2 | Size = 57344 bytes | Modified Date = 3/25/2004 7:30:30 AM | Attr = ]
LtMoh -> %ProgramFiles%\ltmoh\ltmoh.exe -> MD5 = FF1FEF8D3CCB479D1476AD9357505314 | Agere Systems [Ver = 1.69 | Size = 172032 bytes | Modified Date = 1/2/2003 6:16:00 PM | Attr = ]
LXBTCATS -> %SystemRoot%\system32\spool\drivers\w32x86\3\lxbttime.dll -> MD5 = 0D86B9CEED7B4D146BFDCA9FC12342B8 | Lexmark International, Inc. [Ver = 0.1.11.5 | Size = 65536 bytes | Modified Date = 3/17/2004 10:30:06 AM | Attr = ]
PadTouch -> %ProgramFiles%\Toshiba\PadTouch\PadExe.exe -> MD5 = EB00DB4A50E1ED587313F94A575D89FC | TOSHIBA [Ver = 1, 2, 0, 0 | Size = 1019904 bytes | Modified Date = 10/31/2003 5:01:18 PM | Attr = ]
Pinger -> %SystemDrive%\TOSHIBA\Ivp\ISM\pinger.exe -> MD5 = EB3C8C07A1C1286BAA3A676E1D16394D | TOSHIBA Corporation [Ver = 3.3 | Size = 159744 bytes | Modified Date = 10/20/2003 11:39:26 AM | Attr = ]
QuickTime Task -> %ProgramFiles%\QuickTime\qttask.exe -> MD5 = C9128AE6036CDF67873A516E1A00ED4B | Apple Computer, Inc. [Ver = 6.3 | Size = 77824 bytes | Modified Date = 11/20/2003 7:25:11 PM | Attr = ]
RealTray -> %ProgramFiles%\Real\RealPlayer\realplay.exe -> MD5 = 849D97FE4CC09CFC2772D10F641E1BAF | RealNetworks, Inc. [Ver = 6.0.9.584 | Size = 26112 bytes | Modified Date = 11/20/2003 7:24:42 PM | Attr = ]
Share-to-Web Namespace Daemon -> %ProgramFiles%\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe -> MD5 = D5BC63D2822B8E244E53D2FF8078CC6B | Hewlett-Packard [Ver = 2,3,0,0\ 162 | Size = 69632 bytes | Modified Date = 4/17/2002 12:42:56 PM | Attr = ]
TFncKy -> -> File not found
TFNF5 -> %SystemRoot%\system32\TFNF5.exe -> MD5 = 6747A5E7AEC9C40F187E97A3140B80FB | TOSHIBA Corp. [Ver = 2, 4, 1, 0 | Size = 73728 bytes | Modified Date = 10/15/2003 6:03:38 PM | Attr = ]
TouchED -> %ProgramFiles%\Toshiba\TouchED\TouchED.exe -> MD5 = 276684C9BA66189D43E4FA109F8F1471 | TOSHIBA Corporation [Ver = 2, 5, 0, 0 | Size = 126976 bytes | Modified Date = 1/21/2003 8:00:06 PM | Attr = ]
TPSMain -> %SystemRoot%\system32\TPSMain.exe -> MD5 = CB1CB3B90F8351522AA847F0447D67E2 | TOSHIBA Corporation [Ver = 1, 0, 9, 0 | Size = 278528 bytes | Modified Date = 11/19/2003 11:15:38 PM | Attr = ]
< OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ ->
IMAIL-> Installed = 1 ->
MAPI-> Installed = 1 ->
MSFS-> Installed = 1 ->
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
TOSCDSPD -> %ProgramFiles%\Toshiba\TOSCDSPD\TOSCDSPD.exe -> MD5 = 383B71DCB691CCAEEA445ACB9150DDD3 | TOSHIBA [Ver = 1, 0, 5, 0 | Size = 65536 bytes | Modified Date = 9/5/2003 5:24:46 AM | Attr = ]
< Run [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
TOSCDSPD -> %ProgramFiles%\Toshiba\TOSCDSPD\TOSCDSPD.exe -> MD5 = 383B71DCB691CCAEEA445ACB9150DDD3 | TOSHIBA [Ver = 1, 0, 5, 0 | Size = 65536 bytes | Modified Date = 9/5/2003 5:24:46 AM | Attr = ]
< Administrator.TOSHIBA-USER Startup Folder > -> C:\Documents and Settings\Administrator.TOSHIBA-USER\Start Menu\Programs\Startup ->
< Administrator.TOSHIBA-USER.000 Startup Folder > -> C:\Documents and Settings\Administrator.TOSHIBA-USER.000\Start Menu\Programs\Startup ->
< Administrator.TOSHIBA-USER.001 Startup Folder > -> C:\Documents and Settings\Administrator.TOSHIBA-USER.001\Start Menu\Programs\Startup ->
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersProfile%\Start Menu\Programs\Startup\Trend Micro Anti-Spyware.lnk -> %ProgramFiles%\Trend Micro\Tmas\Tmas.exe -> MD5 = 1236495A7A4C48067AB03A4D63A5F39E | Trend Micro Incorporated [Ver = 3, 0, 1, 22 | Size = 1306624 bytes | Modified Date = 5/26/2006 4:17:03 PM | Attr = ]
< Cortney Startup Folder > -> C:\Documents and Settings\Cortney\Start Menu\Programs\Startup ->
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup ->
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
{03A80B1D-5C6A-42c2-9DFB-81B6005D8023} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Trend Micro\Tmas\sshook.dll [Trend Micro Anti-Spyware Shell Extension] -> MD5 = 495BE3A7300929FEA1C064599861E33D | Trend Micro Incorporated [Ver = 3, 0, 1, 22 | Size = 77824 bytes | Modified Date = 5/26/2006 4:17:03 PM | Attr = ]
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> MD5 = 3FD0B984601D65C6DA8E891A0D5905D1 | GRISOFT s.r.o. [Ver = 7, 5, 1, 36 | Size = 79408 bytes | Modified Date = 5/30/2007 6:29:58 AM | Attr = ]
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
igfxcui -> %SystemRoot%\system32\igfxsrvc.dll -> MD5 = 6474AF152CD6025F781D7A5F2B8B6084 | Intel Corporation [Ver = 3,0,0,2104 | Size = 315392 bytes | Modified Date = 4/7/2003 2:06:48 AM | Attr = ]
WRNotifier -> -> File not found
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoCDBurning -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoDriveAutoRun -> 67108863 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoDriveTypeAutoRun -> 255 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 0 ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.comcast.net/ ->
HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\System32\blank.htm ->
HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_CURRENT_USER\: Main\\Start Page -> http://www.comcast.net/ ->
HKEY_CURRENT_USER\: Search\\SearchAssistant -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_CURRENT_USER\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: Main\\Local Page -> C:\WINDOWS\System32\blank.htm ->
HKEY_USERS\.DEFAULT\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\.DEFAULT\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome ->
HKEY_USERS\.DEFAULT\: URLSearchHooks\\{DF944EA8-F762-80BE-4DF7-F25A654D40E0} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
HKEY_USERS\.DEFAULT\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: Main\\Local Page -> C:\WINDOWS\System32\blank.htm ->
HKEY_USERS\S-1-5-18\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-18\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome ->
HKEY_USERS\S-1-5-18\: URLSearchHooks\\{DF944EA8-F762-80BE-4DF7-F25A654D40E0} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
HKEY_USERS\S-1-5-18\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
HKEY_USERS\S-1-5-19\: Main\\Search Bar -> http://www.toshiba.com/search ->
HKEY_USERS\S-1-5-19\: Main\\Start Page -> http://www.toshiba.com ->
HKEY_USERS\S-1-5-19\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
HKEY_USERS\S-1-5-20\: Main\\Search Bar -> http://www.toshiba.com/search ->
HKEY_USERS\S-1-5-20\: Main\\Start Page -> http://www.toshiba.com ->
HKEY_USERS\S-1-5-20\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\] > -> ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\: Main\\Local Page -> C:\WINDOWS\System32\blank.htm ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\: Main\\Start Page -> http://www.comcast.net/ ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\: Search\\SearchAssistant -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\: ProxyEnable -> 0 ->
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
.[msn] -> My Computer ->
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
.[msn] -> My Computer ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. ->
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [AcroIEHlprObj Class] -> MD5 = 8394ABFC1BE196A62C9F532511936DF7 | [Ver = 1, 0, 0, 1 | Size = 37808 bytes | Modified Date = 3/2/2001 2:02:04 PM | Attr = ]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{8E718888-423F-11D2-876E-00A0C9082467} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\msdxm.ocx [&Radio] -> MD5 = D4EB4DD8ABD6B75B86F169F6572B8FF7 | [Ver = | Size = 842268 bytes | Modified Date = 3/31/2003 6:00:00 AM | Attr = ]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MSN Toolbar\01.01.2607.0\en-us\msntb.dll [MSN Toolbar] -> File not found
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MSN Toolbar\01.01.2607.0\en-us\msntb.dll [MSN Toolbar] -> File not found
< Internet Explorer ToolBars [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MSN Toolbar\01.01.2607.0\en-us\msntb.dll [MSN Toolbar] -> File not found
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MSN Toolbar\01.01.2607.0\en-us\msntb.dll [MSN Toolbar] -> File not found
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MSN Toolbar\01.01.2607.0\en-us\msntb.dll [MSN Toolbar] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\j2re1.4.2\bin\NPJPI142.dll [Sun Java Console] -> MD5 = 4ACFBF6AB1BBE79DBD665C186B3B5AFD | JavaSoft / Sun Microsystems, Inc. [Ver = 1, 4, 2, 0 | Size = 65636 bytes | Modified Date = 11/20/2003 6:41:51 PM | Attr = ]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\j2re1.4.2\bin\NPJPI142.dll [Sun Java Console] -> MD5 = 4ACFBF6AB1BBE79DBD665C186B3B5AFD | JavaSoft / Sun Microsystems, Inc. [Ver = 1, 4, 2, 0 | Size = 65636 bytes | Modified Date = 11/20/2003 6:41:51 PM | Attr = ]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\j2re1.4.2\bin\NPJPI142.dll [Sun Java Console] -> MD5 = 4ACFBF6AB1BBE79DBD665C186B3B5AFD | JavaSoft / Sun Microsystems, Inc. [Ver = 1, 4, 2, 0 | Size = 65636 bytes | Modified Date = 11/20/2003 6:41:51 PM | Attr = ]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\j2re1.4.2\bin\NPJPI142.dll [Sun Java Console] -> MD5 = 4ACFBF6AB1BBE79DBD665C186B3B5AFD | JavaSoft / Sun Microsystems, Inc. [Ver = 1, 4, 2, 0 | Size = 65636 bytes | Modified Date = 11/20/2003 6:41:51 PM | Attr = ]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\] > -> HKEY_USERS\S-1-5-21-3517883528-2686717980-3099971625-1006\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\j2re1.4.2\bin\NPJPI142.dll [Sun Java Console] -> MD5 = 4ACFBF6AB1BBE79DBD665C186B3B5AFD | JavaSoft / Sun Microsystems, Inc. [Ver = 1, 4, 2, 0 | Size = 65636 bytes | Modified Date = 11/20/2003 6:41:51 PM | Attr = ]
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s ->
Extension\.csm -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.csml -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.cub -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.cube -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.dx -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.emb -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.embl -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.gau -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.jdx -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.mol -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.mop -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.pdb -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.rxn -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.scr -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.skc -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.spop -> %ProgramFiles%\Internet Explorer\Plugins\NPDocBox.dll [] -> File not found
Extension\.spt -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.tgf -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
Extension\.xyz -> %ProgramFiles%\Internet Explorer\Plugins\npchime.dll [MDL Chime 2.6 SP5] -> File not found
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{6613F300-8483-491B-A626-E114A0FB6021} -> (Intel(R) PRO/100 VE Network Connection) ->
{EACB5FB4-6033-4169-A880-A47961BBD358} -> (Atheros AR5001X+ Wireless Network Adapter) ->
< Default Protocols [HKEY_USERS\.DEFAULT\] - Select to Repair > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Default Protocols [HKEY_USERS\S-1-5-18\] - Select to Repair > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Default Protocols [HKEY_USERS\S-1-5-19\] - Select to Repair > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Default Protocols [HKEY_USERS\S-1-5-20\] - Select to Repair > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found
msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found
vnd.ms.radio:{3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\msdxm.ocx[AsyncPProt Class] -> MD5 = D4EB4DD8ABD6B75B86F169F6572B8FF7 | [Ver = | Size = 842268 bytes | Modified Date = 3/31/2003 6:00:00 AM | Attr = ]
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}[HKEY_LOCAL_MACHINE] -> http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab[CKAVWebScan Object] ->
{166B1BCA-3F9C-11CF-8075-444553540000}[HKEY_LOCAL_MACHINE] -> http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab[Shockwave ActiveX Control] ->
{37A273C2-5129-11D5-BF37-00A0CCE8754B}[HKEY_LOCAL_MACHINE] -> http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab[TTestGenXInstallObject] ->
{406B5949-7190-4245-91A9-30A17DE16AD0}[HKEY_LOCAL_MACHINE] -> http://photo.walgreens.com/WalgreensActivia.cab[Snapfish Activia] ->
{4F1E5B1A-2A80-42CA-8532-2D05CB959537}[HKEY_LOCAL_MACHINE] -> http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab[MSN Photo Upload Tool] ->
{58FC4C77-71C2-4972-A8CD-78691AD85158}[HKEY_LOCAL_MACHINE] -> http://www.worldwinner.com/games/v49/bjattack/bjattack.cab[BJA Control] ->
{6414512B-B978-451D-A0D8-FCFDF33E833C}[HKEY_LOCAL_MACHINE] -> http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1141762598718[WUWebControl Class] ->
{8A94C905-FF9D-43B6-8708-F0F22D22B1CB}[HKEY_LOCAL_MACHINE] -> http://www.worldwinner.com/games/shared/wwlaunch.cab[Wwlaunch Control] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.4.2/jinstall-1_4_2-windows-i586.cab[Java Plug-in 1.4.2] ->
{95D88B35-A521-472B-A182-BB1A98356421}[HKEY_LOCAL_MACHINE] -> http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab[Pearson Installation Assistant 2] ->
{A30FBBDC-FA29-4606-8565-14AADCCA6708}[HKEY_LOCAL_MACHINE] -> https://photos.riteaid.com/control/RiteAidOneHourPhotoOnline.cab[Rite Aid One Hour Photo Online Control] ->
{A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F}[HKEY_LOCAL_MACHINE] -> http://www.worldwinner.com/games/v45/wof/wof.cab[WoF Control] ->
{A8683C98-5341-421B-B23C-8514C05354F1}[HKEY_LOCAL_MACHINE] -> http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab[FujifilmUploader Class] ->
{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}[HKEY_LOCAL_MACHINE] -> http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab[MsnMessengerSetupDownloadControl Class] ->
{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.4.2/jinstall-1_4_2-windows-i586.cab[Java Plug-in 1.4.2] ->
{CC32D4D8-2A0B-4CEB-B105-C9B968379105}[HKEY_LOCAL_MACHINE] -> https://disney.go.com/games/downloads/gamemanager/DIGGameManager.cab[CGameManagerCtrl Object] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] ->
{E6D23284-0E9B-417D-A782-03E4487FC947}[HKEY_LOCAL_MACHINE] -> http://asp.mathxl.com/books/_Players/MathPlayer.cab[Pearson MathXL Player] ->
{FAE74270-E5EE-49C3-B816-EA8B4D55F38F}[HKEY_LOCAL_MACHINE] -> http://www.worldwinner.com/games/v51/h2hpool/h2hpool.cab[H2hPool Control] ->



[Files/Folders - Created Within 90 days]
AVSystemCare -> %SystemDrive%\AVSystemCare -> [Folder | Created Date = 3/19/2008 11:56:53 AM | Attr = HS]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Created Date = 3/14/2008 10:26:55 PM | Attr = HS]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> Unable to obtain MD5 | [Ver = | Size = 518901760 bytes | Created Date = 3/15/2008 10:34:22 AM | Attr = HS]
QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 3/20/2008 10:47:47 AM | Attr = ]
sqmdata07.sqm -> %SystemDrive%\sqmdata07.sqm -> MD5 = 108B06B4BEA5E62E2968256C310E4AED | [Ver = | Size = 268 bytes | Created Date = 12/28/2007 1:34:42 PM | Attr = H ]
sqmdata08.sqm -> %SystemDrive%\sqmdata08.sqm -> MD5 = 29C2D0DCC74BBC5FCB6A08DB60A923BF | [Ver = | Size = 268 bytes | Created Date = 12/31/2007 12:10:52 AM | Attr = H ]
sqmdata09.sqm -> %SystemDrive%\sqmdata09.sqm -> MD5 = F265233E8CC05ED7A510EC621F4EA65F | [Ver = | Size = 268 bytes | Created Date = 1/1/2008 12:10:01 AM | Attr = H ]
sqmdata10.sqm -> %SystemDrive%\sqmdata10.sqm -> MD5 = BCF67B2379D3D178C7036E93595A9B90 | [Ver = | Size = 232 bytes | Created Date = 2/14/2008 4:38:51 PM | Attr = H ]
sqmdata11.sqm -> %SystemDrive%\sqmdata11.sqm -> MD5 = B4B24A51DE4878913A158B9A70C9209B | [Ver = | Size = 268 bytes | Created Date = 2/14/2008 7:54:16 PM | Attr = H ]
sqmdata12.sqm -> %SystemDrive%\sqmdata12.sqm -> MD5 = 8B7C2CA016409B662BEC477215014A54 | [Ver = | Size = 268 bytes | Created Date = 2/14/2008 8:02:18 PM | Attr = H ]
sqmdata13.sqm -> %SystemDrive%\sqmdata13.sqm -> MD5 = 2512A9A927BF3F0D8393D5AF62BF7796 | [Ver = | Size = 268 bytes | Created Date = 2/14/2008 8:24:27 PM | Attr = H ]
sqmnoopt07.sqm -> %SystemDrive%\sqmnoopt07.sqm -> MD5 = 21B789C114568BF5BEDDF8EC78177E58 | [Ver = | Size = 244 bytes | Created Date = 12/28/2007 1:34:41 PM | Attr = H ]
sqmnoopt08.sqm -> %SystemDrive%\sqmnoopt08.sqm -> MD5 = 17A78D8E3D7C9D6F6711BB79D04755DE | [Ver = | Size = 244 bytes | Created Date = 12/31/2007 12:10:52 AM | Attr = H ]
sqmnoopt09.sqm -> %SystemDrive%\sqmnoopt09.sqm -> MD5 = 087B1FE3D014D699720351099457CB0B | [Ver = | Size = 244 bytes | Created Date = 1/1/2008 12:10:01 AM | Attr = H ]
sqmnoopt10.sqm
  • 0

#13
calgooda1323

calgooda1323

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts
shoot.. the whole thing didn't fit again! Here is the attachment

Attached Files


  • 0

#14
calgooda1323

calgooda1323

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts
Oh, and I thought I would ask you why all the sudden my dektop picture is half gone. I tried changing it because I didn't know if maybe it just needed to be refreshed but it still stays half gone. I am sending the print screen so you can see what I mean. Thanks for all your time. You don't know how much I appreciate this.

Attached Files


  • 0

#15
RatHat

RatHat

    Ex Malware Expert

  • Expert
  • 7,829 posts
OK, the problem with your desktop could just be from the malware and fixes we have run, especially seeing as how we have had some problems. Could you try changing your desktop wallpaper, and let me know how it goes:
  • Right click on your desktop, then choose Properties
  • Choose the Desktop tab, then choose any of teh available windows bacgrounds
  • Make sure you choose Stretch, then click Apply
  • If the deskyop appears normally, go to your My Pictures, and find the picture you want as a background
  • Right click on that, and choose Set as Desktop Background
Let me know how it goes.

Now lets get rid of what I hope is the remainder of the malware on your system.

Please download OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Double-click OTMoveIt2.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\Documents and Settings\Cortney\Desktop\OTScanIt\MovedFiles\03202008_134456\WINDOWS\mrofinu1000106.exe
C:\Documents and Settings\Cortney\Desktop\OTScanIt\MovedFiles\03202008_134456\WINDOWS\mrofinu572.exe
C:\Documents and Settings\Cortney\Desktop\OTScanIt\MovedFiles\03202008_134456\WINDOWS\System32\lejbyagv.dll
C:\pj.exe
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\gdnUS2335.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\gdnUS2335.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\gdnUS2335.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\gdnUS2335.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.5\gdnUS2335.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.6\gdnUS2335.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.7\gdnUS2335.exe
C:\WINDOWS\Downloaded Program Files\gdnUS2335.exe
C:\WINDOWS\Downloaded Program Files\UGA6P_0001_N122M0611NetInstaller.exe
C:\WINDOWS\system32\4e3807ee.exe
C:\WINDOWS\system32\etmt2.exe
C:\WINDOWS\system32\nsg1E2.dll
C:\WINDOWS\system32\nwinorai.exe
C:\WINDOWS\system32\qndsregj.exe


Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Open Notepad, and copy everything in the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy).
  • Save the Notepad file to your Desktop as OTM.txt.
  • Close OTMoveIt
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please include the contents of OTM.txt in your next reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Post me the logs from OTMoveIt and MBAM, and let me know how your computer is behaving now.

Regards,
RatHat
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP