OTL:
OTL logfile created on: 6/6/2011 4:13:34 PM - Run 2
OTL by OldTimer - Version 3.2.23.0 Folder = E:\
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 1.76 Gb Available Physical Memory | 61.36% Memory free
5.95 Gb Paging File | 4.88 Gb Available in Paging File | 82.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 184.84 Gb Total Space | 138.56 Gb Free Space | 74.96% Space Free | Partition Type: NTFS
Drive E: | 3.73 Gb Total Space | 3.33 Gb Free Space | 89.26% Space Free | Partition Type: FAT32
Computer Name: LOVYNA-PC | User Name: Lovyna | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/06/05 16:27:38 | 000,580,096 | ---- | M] (OldTimer Tools) -- E:\OTL.exe
PRC - [2011/05/25 17:29:54 | 001,951,112 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2011/05/25 17:29:48 | 001,336,712 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2011/05/01 23:02:44 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/01/17 19:37:40 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2011/01/17 19:37:40 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2011/01/01 10:57:54 | 000,110,352 | ---- | M] (www.motioninjoy.com) -- C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe
PRC - [2009/04/11 01:28:15 | 000,117,248 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE
PRC - [2009/04/11 01:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/02/14 14:08:30 | 000,184,320 | ---- | M] (CyberLink) -- C:\Program Files\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe
PRC - [2008/01/29 21:51:52 | 004,911,104 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008/01/29 19:00:40 | 000,430,080 | ---- | M] () -- C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
PRC - [2008/01/22 17:25:26 | 000,712,704 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
PRC - [2008/01/22 14:00:30 | 004,624,384 | ---- | M] () -- C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
PRC - [2008/01/21 19:54:46 | 000,083,312 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
PRC - [2008/01/20 21:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/17 19:27:52 | 000,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
PRC - [2008/01/17 19:27:34 | 000,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
PRC - [2008/01/09 17:02:08 | 001,056,768 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
PRC - [2007/12/25 16:07:14 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
PRC - [2007/12/25 16:06:52 | 000,405,504 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
PRC - [2007/12/13 22:52:00 | 000,143,360 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe
PRC - [2007/12/03 20:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe
PRC - [2007/11/21 20:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2007/10/25 20:41:18 | 000,413,696 | ---- | M] (Chicony) -- C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
PRC - [2007/10/23 19:27:16 | 000,066,928 | ---- | M] () -- c:\Toshiba\IVP\swupdate\swupdtmr.exe
PRC - [2007/09/28 19:05:16 | 000,128,360 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
PRC - [2007/06/16 00:01:58 | 000,448,080 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\SmoothView\SmoothView.exe
PRC - [2007/01/25 21:47:50 | 000,136,816 | ---- | M] () -- C:\Toshiba\IVP\ISM\pinger.exe
PRC - [2006/10/05 15:10:12 | 000,009,216 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2006/08/23 19:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
========== Modules (SafeList) ========== MOD - [2011/06/05 16:27:38 | 000,580,096 | ---- | M] (OldTimer Tools) -- E:\OTL.exe
MOD - [2010/08/31 10:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - [2011/05/25 17:29:48 | 001,336,712 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2008/01/21 19:54:46 | 000,083,312 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2008/01/20 21:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/17 19:27:34 | 000,431,456 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2007/12/25 16:07:14 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2007/12/03 20:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe -- (TOSHIBA SMART Log Service)
SRV - [2007/11/21 20:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2007/10/30 03:35:40 | 000,937,984 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files\Jumpstart\jswpsapi.exe -- (jswpsapi)
SRV - [2007/10/23 19:27:16 | 000,066,928 | ---- | M] () [Auto | Running] -- c:\Toshiba\IVP\swupdate\swupdtmr.exe -- (Swupdtmr)
SRV - [2007/09/28 19:05:16 | 000,128,360 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2007/09/24 20:38:00 | 000,181,784 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2007/01/25 21:47:50 | 000,136,816 | ---- | M] () [Auto | Running] -- C:\Toshiba\IVP\ISM\pinger.exe -- (pinger)
SRV - [2006/10/05 15:10:12 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2006/08/23 19:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
========== Driver Services (SafeList) ========== DRV - [2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011/01/01 10:12:18 | 000,081,168 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV - [2010/02/11 02:42:22 | 004,450,816 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2009/04/11 00:06:26 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDScan.sys -- (WSDScan)
DRV - [2009/03/18 17:35:40 | 000,026,176 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008/01/25 19:24:56 | 000,764,416 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008/01/21 18:42:24 | 000,285,184 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\tos_sps32.sys -- (tos_sps32)
DRV - [2008/01/20 21:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2007/12/28 22:21:54 | 000,104,448 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2007/12/17 14:45:20 | 000,018,432 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\UVCFTR_S.SYS -- (UVCFTR)
DRV - [2007/11/09 17:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS -- (TVALZ)
DRV - [2007/10/02 14:43:22 | 000,064,128 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2007/08/31 20:43:32 | 000,020,352 | ---- | M] (Atheros Communications, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\jswpslwf.sys -- (jswpslwf)
DRV - [2007/06/29 14:47:34 | 000,034,304 | ---- | M] (AMD, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AmdLLD.sys -- (AmdLLD)
DRV - [2007/03/22 01:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/02/24 17:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/01/23 19:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/28 18:11:00 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006/11/20 17:11:14 | 000,007,168 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\FwLnk.sys -- (FwLnk)
DRV - [2006/11/09 01:32:00 | 000,219,264 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\kr10i.sys -- (KR10I)
DRV - [2006/11/09 01:31:00 | 000,211,072 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\kr10n.sys -- (KR10N)
DRV - [2006/10/30 13:23:12 | 000,007,680 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AtiPcie.sys -- (AtiPcie) ATI PCI Express (3GIO)
DRV - [2006/10/23 19:32:20 | 000,009,216 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfec.sys -- (tosrfec)
DRV - [2006/10/18 14:50:04 | 000,016,128 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2006/10/10 22:33:00 | 000,041,600 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosporte.sys -- (tosporte)
DRV - [2005/08/17 08:45:00 | 000,058,352 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.toshibadirect.com/dpdstartIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.toshibadirect.com/dpdstartIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.toshibadirect.com/dpdstartIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
http://www.sbuniv.ed...ySBU/index.htm"FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.81
FF - prefs.js..extensions.enabledItems: {37fa1426-b82d-11db-8314-0800200c9a66}:2.7.5
FF - prefs.js..extensions.enabledItems: {ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}:2.7.1
FF - prefs.js..extensions.enabledItems: {B742AE5D-19CB-777A-B8D6-901079696A93}:1.7
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {4176DFF4-4698-11DE-BEEB-45DA55D89593}:0.8.7
FF - prefs.js..extensions.enabledItems:
[email protected]:0.9.8.0
FF - prefs.js..extensions.enabledItems: showmemore@suskind:1.3
FF - prefs.js..extensions.enabledItems:
[email protected]:3.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - HKLM\software\mozilla\Firefox\Extensions\\{184AA5E6-741D-464a-820E-94B3ABC2F3B4}: C:\Users\Lovyna\AppData\Roaming\5015
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/01 23:02:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/23 15:56:58 | 000,000,000 | ---D | M]
[2011/01/15 14:51:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lovyna\AppData\Roaming\Mozilla\Extensions
[2011/06/05 11:32:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lovyna\AppData\Roaming\Mozilla\Firefox\Profiles\2kmvaeqn.default\extensions
[2011/01/20 12:32:49 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Lovyna\AppData\Roaming\Mozilla\Firefox\Profiles\2kmvaeqn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/05 11:32:34 | 000,000,000 | ---D | M] (WebMail Notifier) -- C:\Users\Lovyna\AppData\Roaming\Mozilla\Firefox\Profiles\2kmvaeqn.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2011/01/15 16:00:52 | 000,000,000 | ---D | M] (CouponFollow) -- C:\Users\Lovyna\AppData\Roaming\Mozilla\Firefox\Profiles\2kmvaeqn.default\extensions\{B742AE5D-19CB-777A-B8D6-901079696A93}
[2011/03/26 11:50:26 | 000,000,000 | ---D | M] (FoxLingo) -- C:\Users\Lovyna\AppData\Roaming\Mozilla\Firefox\Profiles\2kmvaeqn.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2011/02/14 20:54:29 | 000,000,000 | ---D | M] (Autofill Forms) -- C:\Users\Lovyna\AppData\Roaming\Mozilla\Firefox\Profiles\2kmvaeqn.default\extensions\
[email protected][2011/01/15 20:06:10 | 000,000,000 | ---D | M] (Show Me More) -- C:\Users\Lovyna\AppData\Roaming\Mozilla\Firefox\Profiles\2kmvaeqn.default\extensions\showmemore@suskind
[2011/03/23 15:56:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/02/14 19:51:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- C:\USERS\LOVYNA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2KMVAEQN.DEFAULT\EXTENSIONS\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.XPI
() (No name found) -- C:\USERS\LOVYNA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2KMVAEQN.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI
() (No name found) -- C:\USERS\LOVYNA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2KMVAEQN.DEFAULT\EXTENSIONS\{AE93811A-5C9A-4D34-8462-F7B864FC4696}.XPI
() (No name found) -- C:\USERS\LOVYNA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2KMVAEQN.DEFAULT\EXTENSIONS\
[email protected][2011/05/01 23:02:43 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/02/14 19:51:02 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/06/04 13:12:39 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [AMD_Display] File not found
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [PCMAgent] C:\Program Files\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DS3 Tool] C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe (www.motioninjoy.com)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe ()
O4 - Startup: C:\Users\Lovyna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (maliprog @ Geekstogo)
O24 - Desktop BackupWallPaper: C:\Users\Lovyna\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/06/06 16:10:04 | 000,589,632 | ---- | C] (AVAST Software) -- C:\Users\Lovyna\Desktop\aswMBR.exe
[2011/06/06 13:07:50 | 001,431,344 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Lovyna\Desktop\tdsskiller.exe
[2011/06/05 17:43:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/05 17:43:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/06/05 17:43:31 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/06/04 13:20:29 | 000,000,000 | ---D | C] -- C:\Users\Lovyna\Desktop\GooredFix Backups
[2011/06/04 12:11:15 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011/05/30 15:01:54 | 000,026,176 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\System32\hamachi.sys
[2011/05/30 15:01:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2011/05/30 15:01:49 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi
[2011/05/25 17:08:10 | 000,000,000 | ---D | C] -- C:\Users\Lovyna\Desktop\3d analyzer
[2011/05/25 16:27:09 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2011/05/25 11:04:50 | 000,000,000 | ---D | C] -- C:\Users\Lovyna\AppData\Local\GamersFirst LIVE!
[2011/05/25 11:04:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GamersFirst
[2011/05/25 11:04:36 | 000,000,000 | ---D | C] -- C:\Program Files\GamersFirst
[2011/05/24 08:21:05 | 000,236,496 | ---- | C] (Adobe Systems, Incorporated) -- C:\Users\Lovyna\AppData\Roaming\AcroIEHelpe029.dll
[2011/05/23 16:56:02 | 000,000,000 | ---D | C] -- C:\xmldm
[2011/05/23 16:56:02 | 000,000,000 | ---D | C] -- C:\kock
[2011/05/23 16:55:59 | 000,000,000 | ---D | C] -- C:\Users\Lovyna\AppData\Roaming\xmldm
[2011/05/23 16:55:58 | 000,000,000 | ---D | C] -- C:\Users\Lovyna\AppData\Roaming\kock
[2011/05/23 16:42:42 | 000,000,000 | ---D | C] -- C:\ProgramData\cB06511GpIiP06511
[2011/05/22 13:44:11 | 000,000,000 | ---D | C] -- C:\Windows\System32\eu-ES
[2011/05/22 13:44:11 | 000,000,000 | ---D | C] -- C:\Windows\System32\ca-ES
[2011/05/22 13:44:10 | 000,000,000 | ---D | C] -- C:\Windows\System32\vi-VN
[2011/05/19 15:39:55 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch
[2011/05/15 16:40:27 | 000,000,000 | ---D | C] -- C:\Users\Lovyna\Desktop\Disk9.2
[2011/05/12 11:17:59 | 000,000,000 | ---D | C] -- C:\Users\Lovyna\AppData\Roaming\vlc
[2011/05/12 11:17:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/05/12 11:17:37 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2011/05/12 10:28:51 | 000,000,000 | ---D | C] -- C:\Users\Lovyna\Desktop\CATCHING FIRE
[2011/05/08 00:05:46 | 000,000,000 | ---D | C] -- C:\Users\Lovyna\AppData\Roaming\CyberLink
[1 C:\Users\Lovyna\AppData\Roaming\*.tmp files -> C:\Users\Lovyna\AppData\Roaming\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/06/06 16:14:53 | 000,611,788 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/06/06 16:14:53 | 000,106,796 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/06/06 16:12:48 | 000,000,512 | ---- | M] () -- C:\Users\Lovyna\Desktop\MBR.dat
[2011/06/06 16:10:05 | 000,589,632 | ---- | M] (AVAST Software) -- C:\Users\Lovyna\Desktop\aswMBR.exe
[2011/06/06 16:08:05 | 000,007,268 | ---- | M] () -- C:\Users\Lovyna\AppData\Local\d3d9caps.dat
[2011/06/06 16:08:03 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/06 16:07:53 | 000,003,616 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/06 16:07:53 | 000,003,616 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/06 16:07:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/06/06 14:07:17 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/06 13:53:59 | 000,606,105 | ---- | M] () -- C:\Users\Lovyna\Desktop\unhide.exe
[2011/06/06 13:07:54 | 001,431,344 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Lovyna\Desktop\tdsskiller.exe
[2011/06/05 19:43:01 | 000,000,598 | ---- | M] () -- C:\Users\Public\Desktop\Malware Protection.lnk
[2011/06/05 17:43:34 | 000,000,917 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/04 13:12:39 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2011/06/04 12:14:50 | 137,531,273 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/06/04 11:36:34 | 000,000,949 | ---- | M] () -- C:\Users\Lovyna\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/06/04 01:02:38 | 000,000,632 | RHS- | M] () -- C:\Users\Lovyna\ntuser.pol
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/25 16:28:52 | 000,138,056 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011/05/25 16:28:52 | 000,138,056 | ---- | M] () -- C:\Users\Lovyna\AppData\Roaming\PnkBstrK.sys
[2011/05/25 16:27:53 | 000,189,248 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0
[2011/05/25 11:04:42 | 000,001,195 | ---- | M] () -- C:\Users\Lovyna\Desktop\APB Reloaded.lnk
[2011/05/24 08:21:46 | 000,000,036 | ---- | M] () -- C:\Users\Lovyna\AppData\Roaming\urhtps.dat
[2011/05/22 14:10:19 | 000,414,672 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/05/22 12:46:14 | 000,008,746 | ---- | M] () -- C:\Users\Lovyna\Documents\cc_20110522_124610.reg
[2011/05/19 10:37:50 | 000,000,370 | ---- | M] () -- C:\Users\Lovyna\Desktop\Disk9.2 - Shortcut.lnk
[2011/05/12 11:05:06 | 000,001,332 | ---- | M] () -- C:\Windows\System32\Archive.rar
[1 C:\Users\Lovyna\AppData\Roaming\*.tmp files -> C:\Users\Lovyna\AppData\Roaming\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/06/06 16:12:48 | 000,000,512 | ---- | C] () -- C:\Users\Lovyna\Desktop\MBR.dat
[2011/06/06 13:55:59 | 000,000,949 | ---- | C] () -- C:\Users\Lovyna\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/06/06 13:53:59 | 000,606,105 | ---- | C] () -- C:\Users\Lovyna\Desktop\unhide.exe
[2011/06/05 19:43:01 | 000,000,598 | ---- | C] () -- C:\Users\Public\Desktop\Malware Protection.lnk
[2011/06/05 17:43:34 | 000,000,917 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/04 12:11:02 | 137,531,273 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/06/04 01:02:38 | 000,000,632 | RHS- | C] () -- C:\Users\Lovyna\ntuser.pol
[2011/05/25 17:09:07 | 000,001,195 | ---- | C] () -- C:\Users\Lovyna\Desktop\APB Reloaded.lnk
[2011/05/25 17:07:42 | 000,900,944 | ---- | C] () -- C:\Users\Lovyna\Desktop\3danalyzer-v236.exe
[2011/05/25 16:28:53 | 000,138,056 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011/05/25 16:28:52 | 000,138,056 | ---- | C] () -- C:\Users\Lovyna\AppData\Roaming\PnkBstrK.sys
[2011/05/25 16:27:53 | 000,189,248 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011/05/25 16:27:53 | 000,189,248 | ---- | C] () -- C:\Windows\System32\PnkBstrB.ex0
[2011/05/25 16:27:50 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2011/05/23 23:50:46 | 000,000,036 | ---- | C] () -- C:\Users\Lovyna\AppData\Roaming\urhtps.dat
[2011/05/22 12:46:12 | 000,008,746 | ---- | C] () -- C:\Users\Lovyna\Documents\cc_20110522_124610.reg
[2011/05/19 10:37:50 | 000,000,370 | ---- | C] () -- C:\Users\Lovyna\Desktop\Disk9.2 - Shortcut.lnk
[2011/05/12 11:05:06 | 000,001,332 | ---- | C] () -- C:\Windows\System32\Archive.rar
[2011/05/12 10:28:32 | 000,000,044 | ---- | C] () -- C:\Users\Lovyna\Desktop\Track01.cda
[2011/04/23 08:13:15 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/01/19 13:40:07 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011/01/19 13:40:07 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011/01/19 13:39:09 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/01/15 21:09:49 | 000,007,268 | ---- | C] () -- C:\Users\Lovyna\AppData\Local\d3d9caps.dat
[2011/01/15 15:48:19 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini
[2011/01/15 15:48:19 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll
[2011/01/15 15:48:19 | 000,010,150 | ---- | C] () -- C:\Windows\System32\tosmreg.ini
[2011/01/15 15:48:19 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini
[2011/01/15 15:35:02 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2011/01/15 15:35:02 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2011/01/15 15:13:00 | 000,000,004 | RHS- | C] () -- C:\Windows\System32\drivers\taishop.sys
[2011/01/15 14:51:17 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/01/15 14:23:30 | 000,000,016 | RHS- | C] () -- C:\Windows\System32\drivers\fbd.sys
[2009/04/23 17:29:16 | 000,189,051 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2008/12/09 10:23:13 | 000,048,352 | RHS- | C] () -- C:\Users\Lovyna\AppData\Roaming\appconf32.exe
[2008/02/13 01:34:21 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2008/02/13 01:00:09 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2008/02/13 01:00:09 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2008/02/13 01:00:09 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2008/02/13 01:00:09 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2008/02/13 01:00:09 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2008/02/13 01:00:09 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2008/02/13 00:38:47 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2008/02/13 00:35:26 | 000,000,852 | ---- | C] () -- C:\Windows\System32\drivers\RTKHDRC1.dat
[2008/02/13 00:35:26 | 000,000,852 | ---- | C] () -- C:\Windows\System32\drivers\RTKHDRC0.dat
[2008/02/13 00:35:26 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX1.dat
[2008/02/13 00:35:26 | 000,000,520 | ---- | C] () -- C:\Windows\System32\drivers\RTEQEX0.dat
[2008/02/13 00:35:26 | 000,000,176 | ---- | C] () -- C:\Windows\System32\drivers\RTHDAEQ1.dat
[2008/02/13 00:35:26 | 000,000,176 | ---- | C] () -- C:\Windows\System32\drivers\RTHDAEQ0.dat
[2008/02/13 00:12:13 | 000,157,040 | ---- | C] () -- C:\Windows\fdbpinger.exe
[2008/01/28 21:01:42 | 000,057,344 | ---- | C] () -- C:\Windows\System32\SmartFaceVCapt.dll
[2008/01/28 21:01:06 | 000,471,040 | ---- | C] () -- C:\Windows\System32\SmartFaceVCP.dll
[2008/01/28 20:53:02 | 006,701,056 | ---- | C] () -- C:\Windows\System32\FaceHI.dll
[2008/01/28 20:53:02 | 000,995,328 | ---- | C] () -- C:\Windows\System32\FaceRec.dll
[2008/01/28 20:53:02 | 000,126,976 | ---- | C] () -- C:\Windows\System32\SmartFaceVCtrl.dll
[2008/01/28 20:52:28 | 000,094,208 | ---- | C] () -- C:\Windows\System32\IppLib.dll
[2007/12/21 19:46:32 | 000,118,784 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2006/11/02 07:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,414,672 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,611,788 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,106,796 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/03/09 12:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005/07/23 00:30:18 | 000,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll
========== LOP Check ========== [2011/05/02 22:56:47 | 000,000,000 | ---D | M] -- C:\Users\Lovyna\AppData\Roaming\.minecraft
[2011/03/11 20:43:44 | 000,000,000 | ---D | M] -- C:\Users\Lovyna\AppData\Roaming\DragonicaSCB
[2011/04/21 23:37:36 | 000,000,000 | ---D | M] -- C:\Users\Lovyna\AppData\Roaming\IObit
[2011/05/23 16:55:58 | 000,000,000 | ---D | M] -- C:\Users\Lovyna\AppData\Roaming\kock
[2011/04/26 17:14:38 | 000,000,000 | ---D | M] -- C:\Users\Lovyna\AppData\Roaming\MotioninJoy
[2011/03/13 19:02:37 | 000,000,000 | ---D | M] -- C:\Users\Lovyna\AppData\Roaming\OpenOffice.org
[2011/01/15 14:39:54 | 000,000,000 | ---D | M] -- C:\Users\Lovyna\AppData\Roaming\WinBatch
[2011/06/04 13:10:44 | 000,000,000 | ---D | M] -- C:\Users\Lovyna\AppData\Roaming\xmldm
[2011/06/06 14:33:43 | 000,032,620 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== < End of report >
Edited by Daclivont, 06 June 2011 - 03:17 PM.