Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Spyware eats all my CPU [RESOLVED]


  • This topic is locked This topic is locked

#61
Egwene

Egwene

    Member 2k

  • Visiting Consultant
  • 2,141 posts
Hello,

Reboot your computer and scan again with combofix... Great new okucu, it seems we manage to remove the malware from your computer :) I just want to do a final check.

I really don't know why i didn't follow my first opinion... This could have been taken only 2 or 3 days to resolve... It took more than 20. My only mistake.

Thanks for your patience and sorry for this.

Regards,
Egwene.
  • 0

Advertisements


#62
okucu

okucu

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
Hi Ewgene ,

I am not sure it is all gone even though it is not happening as often and as " strong " as it was before .
After the last cure last night , I saw again after checking with HiJackThis that I had about +100 host O1's . My CPU was not 100% gone but again connection was extremely slow . See HiJack log below . Combofix log follows :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:10:45, on 20/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\System.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O1 - Hosts: 127.1 localhost
O1 - Hosts: 127.1 fffff8888fsgfbghj88.cn
O1 - Hosts: 127.1 61.134.37.12
O1 - Hosts: 127.1 ko.ssa387.cn
O1 - Hosts: 127.1 www.ndxrr.cn
O1 - Hosts: 127.1 12345.ssa387.cn
O1 - Hosts: 127.1 lihai88.com
O1 - Hosts: 127.1 wwwwhf.cn
O1 - Hosts: 127.1 a89369093.sq.u9idc.com
O1 - Hosts: 127.1 www.mmd178.cn
O1 - Hosts: 127.1 www.178mmd.cn
O1 - Hosts: 127.1 www.wenzhuoyyy.cn
O1 - Hosts: 127.1 tw.lovechina.tw.cn
O1 - Hosts: 127.1 222.189.238.151
O1 - Hosts: 127.1 222.179.185.78
O1 - Hosts: 127.1 www.wq9q.cn
O1 - Hosts: 127.1 593ffcey.cn
O1 - Hosts: 127.1 set.yay520.cn
O1 - Hosts: 127.1 tenmoc999.cn
O1 - Hosts: 127.1 lihai88.com
O1 - Hosts: 127.1 121.kcuf-01.com
O1 - Hosts: 127.1 www.ew1q.cn
O1 - Hosts: 127.1 www.b3sk.cn
O1 - Hosts: 127.1 up.bizmd.cn
O1 - Hosts: 127.1 www.ms2a.cn
O1 - Hosts: 127.1 www.wo9188.cn
O1 - Hosts: 127.1 www.fgetchr.cn
O1 - Hosts: 127.1 www.e6zx.cn
O1 - Hosts: 127.1 hai067.com
O1 - Hosts: 127.1 hai088.com
O1 - Hosts: 127.1 778899.jd8j.cn
O1 - Hosts: 127.1 sql.78-11.net
O1 - Hosts: 127.1 www.bbbirdy.com
O1 - Hosts: 127.1 www.s1na1.com.cn
O1 - Hosts: 127.1 www.dianyinjzd.cn
O1 - Hosts: 127.1 www.dj5201314dj.com
O1 - Hosts: 127.1 max-2.cn
O1 - Hosts: 127.1 a.asp-o.cn
O1 - Hosts: 127.1 b.asp-o.cn
O1 - Hosts: 127.1 c.asp-o.cn
O1 - Hosts: 127.1 x.kprobb.cn
O1 - Hosts: 127.1 js.php-k.cn
O1 - Hosts: 127.1 max-1.cn
O1 - Hosts: 127.1 max-3.cn
O1 - Hosts: 127.1 max-4.cn
O1 - Hosts: 127.1 max-5.cn
O1 - Hosts: 127.1 max-6.cn
O1 - Hosts: 127.1 max-7.cn
O1 - Hosts: 127.1 max-8.cn
O1 - Hosts: 127.1 max-9.cn
O1 - Hosts: 127.1 max-10.cn
O1 - Hosts: 127.1 max-11.cn
O1 - Hosts: 127.1 max-12.cn
O1 - Hosts: 127.1 twocannon250.com.cn
O1 - Hosts: 127.1 www.133mm.cn
O1 - Hosts: 127.1 www.51vmm.cn
O1 - Hosts: 127.1 www.7mmoo.cn
O1 - Hosts: 127.1 www.99mmm.org.cn
O1 - Hosts: 127.1 www.hdec.cn
O1 - Hosts: 127.1 www.picc18.com
O1 - Hosts: 127.1 www.kissdh.com
O1 - Hosts: 127.1 www.x7v.cn
O1 - Hosts: 127.1 biqulu.cn
O1 - Hosts: 127.1 2008.qq2006.com.cn
O1 - Hosts: 127.1 giaitrisex.com
O1 - Hosts: 127.1 www.giaitrisex.com
O1 - Hosts: 127.1 www.giaitrituoitre.net
O1 - Hosts: 127.1 mekiep.com
O1 - Hosts: 127.1 www.1sex1day.com
O1 - Hosts: 127.1 a.9ymm.com
O1 - Hosts: 127.1 bobo.7wyt.com
O1 - Hosts: 127.1 www.591caobi.cn
O1 - Hosts: 127.1 www.hrz008.cn
O1 - Hosts: 127.1 asp-15.cn
O1 - Hosts: 127.1 asp-12.cn
O1 - Hosts: 127.1 www.jb88.net
O1 - Hosts: 127.1 6.a88a.com
O1 - Hosts: 127.1 w.b2c3.cn
O1 - Hosts: 127.1 m.c5x8.com
O1 - Hosts: 127.1 www.518sfw.cn
O1 - Hosts: 127.1 www.jjyyzmj.cn
O1 - Hosts: 127.1 u.cnmrx.net
O1 - Hosts: 127.1 duowan.czm.cn
O1 - Hosts: 127.1 xccxcxcxcxcx.cn
O1 - Hosts: 127.1 google-yahoo.org.cn
O1 - Hosts: 127.1 tudou-net.org.cn
O1 - Hosts: 127.1 downloads.zango.com
O1 - Hosts: 127.1 ftp.surfnet.nl
O1 - Hosts: 127.1 bis.180solutions.com
O1 - Hosts: 127.1 installs.hotbar.com
O1 - Hosts: 127.1 www.hbdownloads.com
O1 - Hosts: 127.1 static.zangocash.com
O1 - Hosts: 127.1 www.qq-songli.cn
O1 - Hosts: 127.1 aa.9234.net
O1 - Hosts: 127.1 www.97love.info
O1 - Hosts: 127.1 97love.info
O1 - Hosts: 127.1 www.zyzhuiku.cn
O1 - Hosts: 127.1 zyzhuiku.cn
O1 - Hosts: 127.1 www.lang18.com
O1 - Hosts: 127.1 lang18.com
O1 - Hosts: 127.1 sao6666.com
O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [MPKrnl] rundll32 "C:\WINDOWS\MPKrnl.dll",KrnlMsgProc
O4 - HKLM\..\Run: [3PMmUpdate] rundll32 "C:\WINDOWS\Update.dll",Main
O4 - HKLM\..\Run: [HBService32] System.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKLM\..\Policies\Explorer\Run: [MPMKrnl] rundll32 "C:\WINDOWS\MKMKrnl.dll",KMainProc
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll/search.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Microsoft Excel'e Gö&nder - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O16 - DPF: {3B36B017-7E49-426B-95B0-B5CECD83C2E2} (IfolorUploader Control) - http://chkr-web.ifol...loader_chkr.cab
O16 - DPF: {4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49} (Silverwire Image Uploader 3.0 Control) - http://www.klickonli...geUploader3.cab
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://static.photob...ploader_uni.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: 01AFE3DC.dll,HBmhly.dll,HBZHUXIAN.dll
O21 - SSODL: msnmsg - {DA191DE0-AA86-4ED0-4B87-293D48B2AE99} - C:\Program Files\Messenger\msgmr.dll
O21 - SSODL: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit (mi-raysat_3dsMax2008_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SolidPDFConverterReadSpool (ScReadSpool) - VoyagerSoft, LLC - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

--
End of file - 16922 bytes


------------------------
ComboFix 08-11-19.08 - OKUCU 2008-11-20 10:45:54.16 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1254.90.1033.18.988 [GMT -8:00]
Running from: c:\documents and settings\OKUCU\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Messenger\msgmr.dll
c:\windows\AppPatch\AcSpecf.dll
c:\windows\AppPatch\AcXtrnel.sdb
c:\windows\Downloaded Program Files\ThunderAdvise.dll
c:\windows\Fonts\Framdee.ttf
c:\windows\MSVB50CHS.dll
c:\windows\system32\01AFE3DC.dll
c:\windows\system32\08223B03.cfg
c:\windows\system32\08223B03.dll
c:\windows\system32\122B901E.cfg
c:\windows\system32\122B901E.dll
c:\windows\system32\16AF66EB.dll
c:\windows\system32\201476D0.dll
c:\windows\system32\2EF0D734.cfg
c:\windows\system32\2EF0D734.dll
c:\windows\system32\34A25F04.dll
c:\windows\system32\3B8DA919.dll
c:\windows\system32\4D023DE9.cfg
c:\windows\system32\4D023DE9.dll
c:\windows\system32\4FBFD5A4.dll
c:\windows\system32\58FF3024.cfg
c:\windows\system32\58FF3024.dll
c:\windows\system32\5934EA2B.dll
c:\windows\system32\66AFCB56.cfg
c:\windows\system32\66AFCB56.dll
c:\windows\system32\8566F82E.cfg
c:\windows\system32\8566F82E.dll
c:\windows\system32\93DEE065.dll
c:\windows\system32\9CA963CA.cfg
c:\windows\system32\9CA963CA.dll
c:\windows\system32\9F684DE8.cfg
c:\windows\system32\9F684DE8.dll
c:\windows\system32\A1A6BC2E.dll
c:\windows\system32\AD794E6B.dll
c:\windows\system32\B3721C07.cfg
c:\windows\system32\B3721C07.dll
c:\windows\system32\B8E83D3C.dll
c:\windows\system32\BA7EDF54.cfg
c:\windows\system32\BA7EDF54.dll
c:\windows\system32\DA63E650.cfg
c:\windows\system32\DA63E650.dll
c:\windows\system32\DFEC5CB7.cfg
c:\windows\system32\DFEC5CB7.dll
c:\windows\system32\drivers\HBKernel32.sys
c:\windows\system32\E0D39066.cfg
c:\windows\system32\E0D39066.dll
c:\windows\system32\E1D19FCC.dll
c:\windows\system32\F8E07BB2.dll
c:\windows\system32\HBmhly.dll
c:\windows\system32\HBZHUXIAN.dll
c:\windows\system32\system.exe
c:\windows\system32\unxxx.bat
c:\windows\temp\wmsetup.dll
c:\windows\Update.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_HBKernel32


((((((((((((((((((((((((( Files Created from 2008-10-20 to 2008-11-20 )))))))))))))))))))))))))))))))
.

2008-11-19 20:35 . 2008-11-19 20:50 20,480 --a------ c:\windows\MPKrnl.dll
2008-11-19 20:35 . 2008-11-19 20:35 152 --ahs---- c:\windows\system32\01AFE3DC.cfg
2008-11-19 20:33 . 2008-11-19 20:33 5,504 --a------ c:\windows\system32\f35ee9e.sys
2008-11-19 20:33 . 2008-11-19 20:33 5,504 --a------ c:\windows\system32\b160485.sys
2008-11-19 20:33 . 2008-11-19 20:33 296 --ahs---- c:\windows\system32\16AF66EB.cfg
2008-11-12 08:27 . 2008-11-12 08:30 <DIR> d-------- C:\Lop SD
2008-11-12 07:53 . 2008-11-12 07:53 <DIR> d-------- c:\windows\ERUNT
2008-11-12 07:47 . 2008-11-06 02:03 <DIR> d-------- C:\SDFix
2008-11-10 11:53 . 2008-11-10 11:53 2,306,113 --a------ c:\windows\system32\GPhotos.scr
2008-11-02 18:25 . 2008-11-02 18:25 <DIR> d-------- c:\documents and settings\OKUCU\DoctorWeb
2008-11-02 17:46 . 2008-11-02 18:24 250 --a------ c:\windows\gmer.ini
2008-10-27 09:43 . 2008-11-05 23:48 54,156 --ah----- c:\windows\QTFont.qfn
2008-10-27 09:43 . 2008-10-27 09:43 1,409 --a------ c:\windows\QTFont.for
2008-10-26 18:12 . 2008-10-26 18:12 <DIR> d-------- C:\rsit
2008-10-25 05:09 . 2008-10-25 05:09 <DIR> d-------- c:\program files\SDHelper (Spybot - Search & Destroy)
2008-10-24 19:55 . 2008-10-24 19:55 <DIR> d-------- C:\_OTScanIt

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-20 18:56 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-20 17:38 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-11-20 04:50 10,240 ----a-w c:\windows\MKMKrnl.dll
2008-11-19 08:18 --------- d-----w c:\documents and settings\OKUCU\Application Data\SolidDocuments
2008-11-12 06:16 --------- d-----w c:\documents and settings\OKUCU\Application Data\Skype
2008-11-04 02:16 --------- d-----w c:\windows\system32\config\systemprofile\Application Data\SolidDocuments
2008-10-31 15:27 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-26 04:12 76,856 ----a-w c:\documents and settings\OKUCU\Application Data\GDIPFONTCACHEV1.DAT
2008-10-25 13:09 --------- d-----w c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-10-25 12:51 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-10-22 23:10 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 23:10 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-18 15:47 --------- d-----w c:\documents and settings\OKUCU\Application Data\LimeWire
2008-10-15 09:49 --------- d-----w c:\program files\Visage
2008-10-15 09:49 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-15 09:49 --------- d-----w c:\program files\Common Files\Visage Software
2008-10-15 08:10 --------- d-----w c:\program files\SolidDocuments
2008-10-15 08:09 --------- d-----w c:\documents and settings\All Users\Application Data\SolidDocuments
2008-10-15 07:38 --------- d-----w c:\program files\PDFCreator
2008-10-15 07:38 --------- d-----w c:\documents and settings\OKUCU\Application Data\PDFCreator
2008-10-14 05:17 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-13 20:55 --------- d-----w c:\program files\MathType
2008-10-12 11:08 --------- d-----w c:\documents and settings\OKUCU\Application Data\Autodesk
2008-10-12 11:08 --------- d-----w c:\documents and settings\All Users\Application Data\Autodesk
2008-10-11 09:25 --------- d-----w c:\program files\MSXML 6.0
2008-10-10 08:32 --------- d-----w c:\program files\Nikon_Capture_NX2_v2.1.0
2008-10-10 08:13 --------- d-----w c:\program files\AutoCAD 2008
2008-10-10 08:12 --------- d-----w c:\program files\Common Files\Autodesk Shared
2008-10-09 18:42 --------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
2008-10-09 18:30 --------- d-----w c:\program files\Common Files\Adobe
2008-10-09 18:30 --------- d-----w c:\program files\Bonjour
2008-10-09 18:17 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-10-09 17:00 --------- d-----w c:\program files\turbo squid tentacles
2008-10-09 16:54 --------- d-----w c:\program files\Autodesk
2008-10-05 06:22 --------- d-----w c:\program files\Google
2008-10-02 06:33 --------- d-----w c:\program files\eMule
2008-10-02 06:31 --------- d-----w c:\program files\Swiss International Air Lines TravelDesk
2008-10-02 06:29 --------- d-----w c:\program files\Netopia
2008-09-29 05:52 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2008-09-29 05:47 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdw.DAT
2008-09-25 07:44 --------- d-----w c:\documents and settings\OKUCU\Application Data\U3
2008-08-10 06:58 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLbz.DAT
.

((((((((((((((((((((((((((((( snapshot_2008-11-18_ 8.08.27.35 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-18 16:03:11 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-11-19 05:54:06 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-11-18 16:03:11 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-19 05:54:06 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-11-18 16:03:11 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-19 05:54:06 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-11-17 03:19:13 5,504 ----a-w c:\windows\system32\d435fd4.sys
+ 2008-11-20 04:34:08 5,504 ----a-w c:\windows\system32\d435fd4.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-19 68856]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 1207080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"SVPWUTIL"="c:\program files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2004-05-01 65536]
"Tvs"="c:\program files\TOSHIBA\Tvs\TvsTray.exe" [2005-04-05 73728]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2005-09-06 671744]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2005-08-25 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-28 286720]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-03-23 196608]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-30 122941]
"HWSetup"="c:\program files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 28672]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-19 48752]
"URLLSTCK.exe"="c:\program files\Norton Internet Security\UrlLstCk.exe" [2005-05-05 22656]
"MPKrnl"="c:\windows\MPKrnl.dll" [2008-11-19 20480]
"TFncKy"="TFncKy.exe" [BU]
"CFSServ.exe"="CFSServ.exe" [BU]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-03-28 c:\windows\KHALMNPR.Exe]
"TCtryIOHook"="TCtrlIOHook.exe" [2005-08-22 c:\windows\system32\TCtrlIOHook.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-22 c:\windows\agrsmmsg.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"MPMKrnl"="c:\windows\MKMKrnl.dll" [2008-11-19 10240]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2005-12-28 155648]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{16AF66EB-93C8-49F9-BB09-B4F87CEDCE46}"= "16AF66EB.dll" [BU]
"{4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96}"= "4FBFD5A4.dll" [BU]
"{E1D19FCC-4777-4D71-B863-6A0A5B4E59BC}"= "E1D19FCC.dll" [BU]
"{F8E07BB2-7A19-4057-80F1-E14646E630B4}"= "F8E07BB2.dll" [BU]
"{AD794E6B-90B7-4F9D-8FD6-0C16E3298FF2}"= "AD794E6B.dll" [BU]
"{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8}"= "A1A6BC2E.dll" [BU]
"{5934EA2B-B2C4-4BE7-BF7A-FBA781A12E40}"= "5934EA2B.dll" [BU]
"{201476D0-2B18-462E-AB9F-3E2B0CC8732B}"= "201476D0.dll" [BU]
"{3B8DA919-1139-4B10-AD8F-91E8FBCFD375}"= "3B8DA919.dll" [BU]
"{93DEE065-EC9B-4505-ADD3-19880AD3C38F}"= "93DEE065.dll" [BU]
"{B8E83D3C-9466-4091-9AD1-1F89418A6EB7}"= "B8E83D3C.dll" [BU]
"{01AFE3DC-2242-436E-9B44-6DD1C664E828}"= "01AFE3DC.dll" [BU]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=c:\windows\pss\Picture Package Menu.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=c:\windows\pss\Picture Package VCD Maker.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Google Web Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Run Google Web Accelerator.lnk
backup=c:\windows\pss\Run Google Web Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=c:\windows\pss\Windows Desktop Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^OKUCU^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\documents and settings\OKUCU\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^OKUCU^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\OKUCU\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^OKUCU^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=c:\documents and settings\OKUCU\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^OKUCU^Start Menu^Programs^Startup^Nikon Monitor.lnk]
path=c:\documents and settings\OKUCU\Start Menu\Programs\Startup\Nikon Monitor.lnk
backup=c:\windows\pss\Nikon Monitor.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-09-03 09:11 29744 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-06-20 12:36 1207080 c:\program files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2005-10-18 03:58 278528 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
--a------ 2007-02-27 01:18 67128 c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
--a------ 2003-08-19 06:43 57344 c:\program files\Lexmark X1100 Series\lxbkbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a------ 2005-06-08 05:44 196608 c:\program files\Logitech\Video\ManifestEngine.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a------ 2005-06-08 06:24 458752 c:\program files\Logitech\Video\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a------ 2005-06-08 06:14 217088 c:\program files\Logitech\Video\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PadTouch]
--a------ 2005-08-30 02:53 1077329 c:\program files\Toshiba\Touch and Launch\PadExe.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
--a------ 2006-10-13 08:20 20058152 c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
--a------ 2005-05-12 01:31 118784 c:\program files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2006-03-10 09:45 35328 c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zooming]
--a------ 2005-06-06 00:58 24576 c:\windows\system32\ZoomingHook.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2008\\3dsmax.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

S3 b160485;b160485;\??\c:\windows\system32\b160485.sys [2008-11-19 5504]
S3 d435fd4;d435fd4;\??\c:\windows\system32\d435fd4.sys [2008-11-19 5504]
S3 f35ee9e;f35ee9e;\??\c:\windows\system32\f35ee9e.sys [2008-11-19 5504]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;"c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-08-07 29744]
.
Contents of the 'Scheduled Tasks' folder

2008-11-20 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2004-12-14 03:24]
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{34A25F04-008D-403E-8EE6-2307BC02FA2E} - 34A25F04.dll


.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\OKUCU\Application Data\Mozilla\Firefox\Profiles\c4f6pgvi.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-20 10:55:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Norton Internet Security\ISSVC.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
c:\program files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\fxssvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\Toshiba\TOSHIBA Controls\TFncKy.exe
c:\program files\Toshiba\ConfigFree\CFSServ.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\program files\Apoint2K\ApntEx.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\progra~1\MICROS~4\rapimgr.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Messenger\msmsgs.exe
.
**************************************************************************
.
Completion time: 2008-11-20 11:02:25 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-20 19:02:13
ComboFix2.txt 2008-11-19 19:26:31
ComboFix3.txt 2008-11-19 16:36:42
ComboFix4.txt 2008-11-19 06:23:32
ComboFix5.txt 2008-11-20 18:44:14

Pre-Run: 14,244,139,008 bytes free
Post-Run: 14,273,413,120 bytes free

353 --- E O F --- 2008-10-16 20:32:25
  • 0

#63
Egwene

Egwene

    Member 2k

  • Visiting Consultant
  • 2,141 posts
Hello,

You're right.

Please tell me when the issue appears for the first time... i'm sure there is one file that our scanner didn't see ONLY because it is too old.

Answer my question please and my next instruction will follow.

:)
  • 0

#64
okucu

okucu

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
Ok,here is how it started ....

Sometime in August this summer , I searched for a name - let's say " John Smith " in google . When I clicked on one of the items found , I had a window like " Active Sync needs to update , etc ... " and my computer froze . I knew from previous experiences that a spyware entered .

I immediately did some HiJackThis and Malware Byte's Antimalware and it was gone .

All was clean until Oct 23 or Oct 24 , when I saw an e-mail from " John Smith " . I clicked on it without thinking and there I HAD IT AGAIN . And you know the rest of the story .

Very clever spyware - as it noted 2 months ago what I searched ,and sent me an e-mail with the same searched name ! !

I believe this was how it started .

I sometimes get a flash of small black screen - just for one second or so - I can not read what it says because it goes away immediately . But I know then that my CPU is 100% taken and there are +100 or so O1 hosts .


However , it can also be that my computer was loaded by someone with some cracked pirate programs . That took place between 10 - 17 October . I was also highly suspicious of the guy who seemed to help me load soma Autocad and 3D pirate programs . He , at one stage , mixed everything up and took him a few hours to put the programs in correct place .

So 2 possibilities , all within last month .

I don't know if it makes any difference or if it is related but I also have following issues :

- I can not see/show HIDDEN programs even if I want to . "Show hidden files " does not work
- I can not store/name a program if I can't add " .txt" , " .doc" or " .xls" to the name . It no longer does it automatically .

Any opinions ??
  • 0

#65
Egwene

Egwene

    Member 2k

  • Visiting Consultant
  • 2,141 posts
Hello,

Ok thanks. Maybe a format will be the only solution to get rid of this malware. I'm afraid that the malware is entered on your computer for a long time. If it has been more than 3 months, it will be very difficult to remove it.

But before, i would like to try something else.

Now download OTScanIt.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.

Note: You must be logged on to the system with an account that has Administrator privileges to run this program.

  • Close ALL OTHER PROGRAMS.
  • Open the OTScanIt folder and double-click on OTScanIt.exe to start the program (if you are running on Vista then right-click the program and choose Run as Administrator).
  • In the Drivers section click on Non-Microsoft.
  • Under File Created within and File modified within change it from 30 days to 90 days
  • Under Additional Scans click the checkboxes in front of the following items to select them:
    • Reg - BotCheck
      File - Additional Folder Scans
  • Do not change any other settings.
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Save the repport on your desktop.

Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on Posted Image to insert the attachment into your post

Regards,
Egwene.
  • 0

#66
okucu

okucu

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
There you go ....I uploaded it

Attached Files


  • 0

#67
Egwene

Egwene

    Member 2k

  • Visiting Consultant
  • 2,141 posts
Hello,

I'm sorry, i'm very busy the past few days, again...

Do you have your windows CD ? To be honnest with you, i think that a format would be the best way to solve your issue. I've already asked some advices to people more skilled than me and we are really stuck with your log. Please notice it's the first time i recommand a format to someone.

But, as i told you, we can try a last thing.

If you can do this :

Please run Combofix, then OtscanIT as bellow, attache me OtscanIt repport and please do not turn off your computer untill i give you a fix. I will promise you to answer as soon as i will see your answer with OTscanIT log. Explanations : if you reboot your computer, the log you give me is outdated and my fix may not be efficient.

Regards,
Egwene.
  • 0

#68
okucu

okucu

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
I have been trying for the past 2 hours but my computer keeps locking- has not lasted long enough to complete two scan and posts . I cleaned and rebooted and will try once more from scratch . If you don't see a log in the next 2 hours , it means I am unable to do it . Let's hope I can do it
  • 0

#69
okucu

okucu

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
I was lucky ...Here they are ...
I will not reboot until I hear from you ( within 24 hours ) . But please hurry,my computer is useless without vrebooting every hour .

ComboFix 08-11-19.08 - OKUCU 2008-11-24 23:26:20.21 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1254.90.1033.18.1025 [GMT -8:00]
Running from: c:\documents and settings\OKUCU\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Messenger\msgmr.dll
c:\windows\AppPatch\AcSpecf.dll
c:\windows\AppPatch\AcSpecf.sdb
c:\windows\AppPatch\AcXtrnel.sdb
c:\windows\Downloaded Program Files\ThunderAdvise.dll
c:\windows\Fonts\Framdee.ttf
c:\windows\MSVB50CHS.dll
c:\windows\system32\01AFE3DC.dll
c:\windows\system32\08223B03.cfg
c:\windows\system32\122B901E.cfg
c:\windows\system32\201476D0.dll
c:\windows\system32\29EA67E0.dll
c:\windows\system32\2EF0D734.cfg
c:\windows\system32\2EF0D734.dll
c:\windows\system32\34A25F04.dll
c:\windows\system32\4D023DE9.cfg
c:\windows\system32\4FBFD5A4.dll
c:\windows\system32\56BC86C7.dll
c:\windows\system32\5934EA2B.dll
c:\windows\system32\66AFCB56.cfg
c:\windows\system32\66AFCB56.dll
c:\windows\system32\8566F82E.cfg
c:\windows\system32\8566F82E.dll
c:\windows\system32\93DEE065.dll
c:\windows\system32\950D1600.dll
c:\windows\system32\9CA963CA.cfg
c:\windows\system32\9CA963CA.dll
c:\windows\system32\A1A6BC2E.dll
c:\windows\system32\A55F538E.dll
c:\windows\system32\AD794E6B.dll
c:\windows\system32\B3721C07.cfg
c:\windows\system32\B3721C07.dll
c:\windows\system32\B8E83D3C.dll
c:\windows\system32\BA7EDF54.cfg
c:\windows\system32\BA7EDF54.dll
c:\windows\system32\DA63E650.cfg
c:\windows\system32\DFB3DAC5.dll
c:\windows\system32\DFEC5CB7.cfg
c:\windows\system32\DFEC5CB7.dll
c:\windows\system32\E0D39066.cfg
c:\windows\system32\E0D39066.dll
c:\windows\system32\E1D19FCC.dll
c:\windows\system32\F8E07BB2.dll
c:\windows\temp\wmsetup.dll

.
((((((((((((((((((((((((( Files Created from 2008-10-25 to 2008-11-25 )))))))))))))))))))))))))))))))
.

2008-11-23 17:26 . 2008-11-23 19:35 59 --a------ c:\windows\system32\i
2008-11-22 11:40 . 2008-11-22 11:40 344 --ahs---- c:\windows\system32\950D1600.cfg
2008-11-22 11:40 . 2008-11-22 11:40 180 --ahs---- c:\windows\system32\A55F538E.cfg
2008-11-22 09:32 . 2008-11-22 09:32 <DIR> d-------- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2008-11-22 09:32 . 2008-11-22 09:32 <DIR> d-------- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2008-11-21 17:32 . 2008-11-21 17:32 196 --ahs---- c:\windows\system32\29EA67E0.cfg
2008-11-21 17:26 . 2008-11-21 17:26 208 --ahs---- c:\windows\system32\DFB3DAC5.cfg
2008-11-21 14:26 . 2008-11-21 14:26 5,504 --a------ c:\windows\system32\d812a079.sys
2008-11-20 21:15 . 2008-11-20 21:15 184 --ahs---- c:\windows\system32\56BC86C7.cfg
2008-11-19 20:35 . 2008-11-19 20:50 20,480 --a------ c:\windows\MPKrnl.dll
2008-11-19 20:35 . 2008-11-19 20:35 152 --ahs---- c:\windows\system32\01AFE3DC.cfg
2008-11-19 20:33 . 2008-11-19 20:33 5,504 --a------ c:\windows\system32\f35ee9e.sys
2008-11-19 20:33 . 2008-11-19 20:33 5,504 --a------ c:\windows\system32\b160485.sys
2008-11-19 20:33 . 2008-11-19 20:33 296 --ahs---- c:\windows\system32\16AF66EB.cfg
2008-11-17 12:04 . 2008-11-17 12:04 2,306,113 --a------ c:\windows\system32\GPhotos.scr
2008-11-12 08:27 . 2008-11-12 08:30 <DIR> d-------- C:\Lop SD
2008-11-12 07:53 . 2008-11-12 07:53 <DIR> d-------- c:\windows\ERUNT
2008-11-12 07:47 . 2008-11-06 02:03 <DIR> d-------- C:\SDFix
2008-11-02 18:25 . 2008-11-02 18:25 <DIR> d-------- c:\documents and settings\OKUCU\DoctorWeb
2008-11-02 17:46 . 2008-11-02 18:24 250 --a------ c:\windows\gmer.ini
2008-10-27 09:43 . 2008-11-20 20:53 54,156 --ah----- c:\windows\QTFont.qfn
2008-10-27 09:43 . 2008-10-27 09:43 1,409 --a------ c:\windows\QTFont.for
2008-10-26 18:12 . 2008-10-26 18:12 <DIR> d-------- C:\rsit
2008-10-25 05:09 . 2008-10-25 05:09 <DIR> d-------- c:\program files\SDHelper (Spybot - Search & Destroy)

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-25 07:31 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-25 02:31 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-11-24 05:59 --------- d-----w c:\windows\system32\config\systemprofile\Application Data\SolidDocuments
2008-11-22 17:29 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-21 18:04 --------- d-----w c:\documents and settings\OKUCU\Application Data\SolidDocuments
2008-11-20 04:50 10,240 ----a-w c:\windows\MKMKrnl.dll
2008-11-12 06:16 --------- d-----w c:\documents and settings\OKUCU\Application Data\Skype
2008-10-26 04:12 76,856 ----a-w c:\documents and settings\OKUCU\Application Data\GDIPFONTCACHEV1.DAT
2008-10-25 13:09 --------- d-----w c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-10-25 12:51 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-10-22 23:10 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 23:10 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-18 15:47 --------- d-----w c:\documents and settings\OKUCU\Application Data\LimeWire
2008-10-15 09:49 --------- d-----w c:\program files\Visage
2008-10-15 09:49 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-15 09:49 --------- d-----w c:\program files\Common Files\Visage Software
2008-10-15 08:10 --------- d-----w c:\program files\SolidDocuments
2008-10-15 08:09 --------- d-----w c:\documents and settings\All Users\Application Data\SolidDocuments
2008-10-15 07:38 --------- d-----w c:\program files\PDFCreator
2008-10-15 07:38 --------- d-----w c:\documents and settings\OKUCU\Application Data\PDFCreator
2008-10-14 05:17 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-13 20:55 --------- d-----w c:\program files\MathType
2008-10-12 11:08 --------- d-----w c:\documents and settings\OKUCU\Application Data\Autodesk
2008-10-12 11:08 --------- d-----w c:\documents and settings\All Users\Application Data\Autodesk
2008-10-11 09:25 --------- d-----w c:\program files\MSXML 6.0
2008-10-10 08:32 --------- d-----w c:\program files\Nikon_Capture_NX2_v2.1.0
2008-10-10 08:13 --------- d-----w c:\program files\AutoCAD 2008
2008-10-10 08:12 --------- d-----w c:\program files\Common Files\Autodesk Shared
2008-10-09 18:42 --------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
2008-10-09 18:30 --------- d-----w c:\program files\Common Files\Adobe
2008-10-09 18:30 --------- d-----w c:\program files\Bonjour
2008-10-09 18:17 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-10-09 17:00 --------- d-----w c:\program files\turbo squid tentacles
2008-10-09 16:54 --------- d-----w c:\program files\Autodesk
2008-10-05 06:22 --------- d-----w c:\program files\Google
2008-10-02 06:33 --------- d-----w c:\program files\eMule
2008-10-02 06:31 --------- d-----w c:\program files\Swiss International Air Lines TravelDesk
2008-10-02 06:29 --------- d-----w c:\program files\Netopia
2008-09-29 05:52 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2008-09-29 05:47 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdw.DAT
2008-09-25 07:44 --------- d-----w c:\documents and settings\OKUCU\Application Data\U3
2008-08-10 06:58 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLbz.DAT
.

((((((((((((((((((((((((((((( snapshot_2008-11-18_ 8.08.27.35 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-18 16:03:11 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-11-19 05:54:06 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-11-18 16:03:11 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-19 05:54:06 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-11-18 16:03:11 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-19 05:54:06 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-11-17 03:19:13 5,504 ----a-w c:\windows\system32\d435fd4.sys
+ 2008-11-20 04:34:08 5,504 ----a-w c:\windows\system32\d435fd4.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-19 68856]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 1207080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"SVPWUTIL"="c:\program files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2004-05-01 65536]
"Tvs"="c:\program files\TOSHIBA\Tvs\TvsTray.exe" [2005-04-05 73728]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2005-09-06 671744]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2005-08-25 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-28 286720]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-03-23 196608]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-30 122941]
"HWSetup"="c:\program files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 28672]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-19 48752]
"URLLSTCK.exe"="c:\program files\Norton Internet Security\UrlLstCk.exe" [2005-05-05 22656]
"MPKrnl"="c:\windows\MPKrnl.dll" [2008-11-19 20480]
"TFncKy"="TFncKy.exe" [BU]
"CFSServ.exe"="CFSServ.exe" [BU]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-03-28 c:\windows\KHALMNPR.Exe]
"TCtryIOHook"="TCtrlIOHook.exe" [2005-08-22 c:\windows\system32\TCtrlIOHook.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-22 c:\windows\agrsmmsg.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"MPMKrnl"="c:\windows\MKMKrnl.dll" [2008-11-19 10240]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2005-12-28 155648]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{16AF66EB-93C8-49F9-BB09-B4F87CEDCE46}"= "16AF66EB.dll" [BU]
"{4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96}"= "4FBFD5A4.dll" [BU]
"{E1D19FCC-4777-4D71-B863-6A0A5B4E59BC}"= "E1D19FCC.dll" [BU]
"{F8E07BB2-7A19-4057-80F1-E14646E630B4}"= "F8E07BB2.dll" [BU]
"{AD794E6B-90B7-4F9D-8FD6-0C16E3298FF2}"= "AD794E6B.dll" [BU]
"{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8}"= "A1A6BC2E.dll" [BU]
"{5934EA2B-B2C4-4BE7-BF7A-FBA781A12E40}"= "5934EA2B.dll" [BU]
"{201476D0-2B18-462E-AB9F-3E2B0CC8732B}"= "201476D0.dll" [BU]
"{3B8DA919-1139-4B10-AD8F-91E8FBCFD375}"= "3B8DA919.dll" [BU]
"{93DEE065-EC9B-4505-ADD3-19880AD3C38F}"= "93DEE065.dll" [BU]
"{B8E83D3C-9466-4091-9AD1-1F89418A6EB7}"= "B8E83D3C.dll" [BU]
"{01AFE3DC-2242-436E-9B44-6DD1C664E828}"= "01AFE3DC.dll" [BU]
"{34A25F04-008D-403E-8EE6-2307BC02FA2E}"= "34A25F04.dll" [BU]
"{56BC86C7-0692-4F94-A2C1-6CF1DBF8096C}"= "56BC86C7.dll" [BU]
"{950D1600-DE4A-448D-93B4-7BAE5A7A8052}"= "950D1600.dll" [BU]
"{DFB3DAC5-B0B5-4B05-BFCF-FB42737778FA}"= "DFB3DAC5.dll" [BU]
"{A55F538E-9E65-4706-9458-852BF6592063}"= "A55F538E.dll" [BU]
"{29EA67E0-9EE5-4D1A-A056-5B7BDAC4CF97}"= "29EA67E0.dll" [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"Upnp"= {DE01DA19-A6A8-EB80-4D47-248DEB2A9399} - c:\windows\system32\upnpsrv.dll [2007-04-16 20480]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=c:\windows\pss\Picture Package Menu.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=c:\windows\pss\Picture Package VCD Maker.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Google Web Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Run Google Web Accelerator.lnk
backup=c:\windows\pss\Run Google Web Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=c:\windows\pss\Windows Desktop Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^OKUCU^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\documents and settings\OKUCU\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^OKUCU^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\OKUCU\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^OKUCU^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=c:\documents and settings\OKUCU\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^OKUCU^Start Menu^Programs^Startup^Nikon Monitor.lnk]
path=c:\documents and settings\OKUCU\Start Menu\Programs\Startup\Nikon Monitor.lnk
backup=c:\windows\pss\Nikon Monitor.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-09-03 09:11 29744 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-06-20 12:36 1207080 c:\program files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2005-10-18 03:58 278528 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
--a------ 2007-02-27 01:18 67128 c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
--a------ 2003-08-19 06:43 57344 c:\program files\Lexmark X1100 Series\lxbkbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a------ 2005-06-08 05:44 196608 c:\program files\Logitech\Video\ManifestEngine.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a------ 2005-06-08 06:24 458752 c:\program files\Logitech\Video\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a------ 2005-06-08 06:14 217088 c:\program files\Logitech\Video\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PadTouch]
--a------ 2005-08-30 02:53 1077329 c:\program files\Toshiba\Touch and Launch\PadExe.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
--a------ 2006-10-13 08:20 20058152 c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
--a------ 2005-05-12 01:31 118784 c:\program files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2006-03-10 09:45 35328 c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zooming]
--a------ 2005-06-06 00:58 24576 c:\windows\system32\ZoomingHook.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2008\\3dsmax.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

S2 SVCHOSTS32;Windows Host Services ;"c:\windows\system\svchost.exe" []
S3 b160485;b160485;\??\c:\windows\system32\b160485.sys [2008-11-19 5504]
S3 d435fd4;d435fd4;\??\c:\windows\system32\d435fd4.sys [2008-11-19 5504]
S3 d812a079;d812a079;\??\c:\windows\system32\d812a079.sys [2008-11-21 5504]
S3 f35ee9e;f35ee9e;\??\c:\windows\system32\f35ee9e.sys [2008-11-19 5504]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;"c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-08-07 29744]
.
Contents of the 'Scheduled Tasks' folder

2008-11-25 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2004-12-14 03:24]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\OKUCU\Application Data\Mozilla\Firefox\Profiles\c4f6pgvi.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-24 23:31:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Norton Internet Security\ISSVC.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
c:\program files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\fxssvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\Toshiba\TOSHIBA Controls\TFncKy.exe
c:\program files\Toshiba\ConfigFree\CFSServ.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\program files\Apoint2K\ApntEx.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\progra~1\MICROS~4\rapimgr.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Messenger\msmsgs.exe
c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
.
**************************************************************************
.
Completion time: 2008-11-24 23:37:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-25 07:37:38
ComboFix2.txt 2008-11-25 05:17:12
ComboFix3.txt 2008-11-24 05:25:09
ComboFix4.txt 2008-11-24 01:30:36
ComboFix5.txt 2008-11-25 07:25:58

Pre-Run: 14,109,081,600 bytes free
Post-Run: 14,103,904,256 bytes free

356 --- E O F --- 2008-10-16 20:32:25

[code=auto:0]OTScanIt logfile created on: 24/11/2008 23:39:11
OTScanIt by OldTimer - Version 1.0.19.0 Folder = C:\Documents and Settings\OKUCU\Desktop\OTScanIt
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.49 Gb Total Physical Memory | 1.01 Gb Available Physical Memory | 68.05% Memory free
2.09 Gb Paging File | 1.77 Gb Available in Paging File | 84.82% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 13.15 Gb Free Space | 35.30% Space Free | Partition Type: NTFS
Drive D: | 37.23 Gb Total Space | 10.19 Gb Free Space | 27.37% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-C36CAA9C21
Current User Name: OKUCU
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On

[Processes - Non-Microsoft Only]
adskscsrv.exe -> %CommonProgramFiles%\Autodesk Shared\Service\AdskScSrv.exe -> Autodesk [Ver = 2.80.011 | Size = 79360 bytes | Modified Date = 09/10/2008 08:54:38 | Attr = ]
cfsvcs.exe -> %ProgramFiles%\Toshiba\ConfigFree\CFSvcs.exe -> TOSHIBA CORPORATION [Ver = 6, 0, 0, 1 | Size = 40960 bytes | Modified Date = 17/01/2005 15:38:38 | Attr = ]
dvdramsv.exe -> %SystemRoot%\system32\DVDRAMSV.exe -> Matsushita Electric Industrial Co., Ltd. [Ver = 3, 0, 0, 0 | Size = 110592 bytes | Modified Date = 27/08/2004 23:33:00 | Attr = ]
raysat_3dsmax2008_32server.exe -> %ProgramFiles%\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe -> [Ver = | Size = 65536 bytes | Modified Date = 24/09/2007 06:05:26 | Attr = ]
solidpdfservice.exe -> %ProgramFiles%\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe -> VoyagerSoft, LLC [Ver = 3.1.437.0 | Size = 184320 bytes | Modified Date = 02/11/2006 04:24:32 | Attr = ]
tfncky.exe -> %ProgramFiles%\Toshiba\TOSHIBA Controls\TFncKy.exe -> TOSHIBA Corporation [Ver = 3.19.00 | Size = 184320 bytes | Modified Date = 17/05/2005 01:14:12 | Attr = ]
tvstray.exe -> %ProgramFiles%\Toshiba\Tvs\TvsTray.exe -> TOSHIBA Corporation [Ver = 1, 0, 0, 4 | Size = 73728 bytes | Modified Date = 05/04/2005 07:25:34 | Attr = ]
cfsserv.exe -> %ProgramFiles%\Toshiba\ConfigFree\CFSServ.exe -> TOSHIBA CORPORATION [Ver = 6, 0, 0, 115 | Size = 798720 bytes | Modified Date = 29/07/2005 13:31:56 | Attr = ]
ceekey.exe -> %ProgramFiles%\Toshiba\E-KEY\CeEKey.exe -> COMPAL ELECTRONIC INC. [Ver = 1, 0, 0, 31 | Size = 671744 bytes | Modified Date = 06/09/2005 05:04:52 | Attr = ]
tptray.exe -> %ProgramFiles%\Toshiba\TouchPad\TPTray.exe -> COMPAL ELECTRONIC INC. [Ver = 1, 0, 0, 7 | Size = 53248 bytes | Modified Date = 25/08/2005 10:11:58 | Attr = ]
tctrliohook.exe -> %SystemRoot%\system32\TCtrlIOHook.exe -> TOSHIBA [Ver = 1, 0, 0, 4 | Size = 28672 bytes | Modified Date = 22/08/2005 07:49:28 | Attr = ]
ndstray.exe -> %ProgramFiles%\Toshiba\ConfigFree\NDSTray.exe -> TOSHIBA CORPORATION [Ver = 6, 0, 0, 17 | Size = 978944 bytes | Modified Date = 06/08/2005 01:18:38 | Attr = ]
lvcomsx.exe -> %SystemRoot%\system32\LVCOMSX.EXE -> Logitech Inc. [Ver = 8.4.7.1036 | Size = 221184 bytes | Modified Date = 19/07/2005 08:32:18 | Attr = ]
agrsmmsg.exe -> %SystemRoot%\agrsmmsg.exe -> Agere Systems [Ver = 2.1.49 2.1.49 12/20/2004 15:10:02 | Size = 88358 bytes | Modified Date = 22/12/2004 00:10:04 | Attr = ]
toscdspd.exe -> %ProgramFiles%\Toshiba\TOSCDSPD\TOSCDSPD.exe -> TOSHIBA [Ver = 1, 0, 6, 0 | Size = 65536 bytes | Modified Date = 11/04/2005 02:26:06 | Attr = ]
ramasst.exe -> %SystemRoot%\system32\RAMASST.exe -> Matsushita Electric Industrial Co., Ltd. [Ver = 1, 1, 0, 0 | Size = 155648 bytes | Modified Date = 27/08/2004 23:37:00 | Attr = ]

[Win32 Services - Non-Microsoft Only]
(Autodesk Licensing Service) Autodesk Licensing Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Autodesk Shared\Service\AdskScSrv.exe -> Autodesk [Ver = 2.80.011 | Size = 79360 bytes | Modified Date = 09/10/2008 08:54:38 | Attr = ]
(CFSvcs) ConfigFree Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Toshiba\ConfigFree\CFSvcs.exe -> TOSHIBA CORPORATION [Ver = 6, 0, 0, 1 | Size = 40960 bytes | Modified Date = 17/01/2005 15:38:38 | Attr = ]
(DVD-RAM_Service) DVD-RAM_Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\DVDRAMSV.exe -> Matsushita Electric Industrial Co., Ltd. [Ver = 3, 0, 0, 0 | Size = 110592 bytes | Modified Date = 27/08/2004 23:33:00 | Attr = ]
(FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> Macrovision Europe Ltd. [Ver = 11.03.005 | Size = 654848 bytes | Modified Date = 09/10/2008 10:17:55 | Attr = ]
(mi-raysat_3dsMax2008_32) mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit [Win32_Own | Auto | Running] -> %ProgramFiles%\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe -> [Ver = | Size = 65536 bytes | Modified Date = 24/09/2007 06:05:26 | Attr = ]
(ScReadSpool) SolidPDFConverterReadSpool [Win32_Shared | Auto | Running] -> %ProgramFiles%\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe -> VoyagerSoft, LLC [Ver = 3.1.437.0 | Size = 184320 bytes | Modified Date = 02/11/2006 04:24:32 | Attr = ]
(SVCHOSTS32) Windows Host Services [Win32_Own | Auto | Stopped] -> %SystemRoot%\system\svchost.exe -> File not found

[Driver Services - Non-Microsoft Only]
(AgereSoftModem) TOSHIBA V92 Software Modem [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\AGRSM.sys -> Agere Systems [Ver = 2.1.51 2.1.51 03/04/2005 12:02:18 | Size = 1066278 bytes | Modified Date = 05/03/2005 04:02:20 | Attr = ]
(b160485) b160485 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\b160485.sys -> [Ver = | Size = 5504 bytes | Modified Date = 19/11/2008 20:33:54 | Attr = ]
(cdrbsdrv) cdrbsdrv [Kernel | System | Running] -> %SystemRoot%\System32\drivers\CDRBSDRV.SYS -> B.H.A Corporation [Ver = 7. 0. 0. 5 | Size = 13567 bytes | Modified Date = 08/03/2004 02:55:50 | Attr = ]
(d435fd4) d435fd4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\d435fd4.sys -> [Ver = | Size = 5504 bytes | Modified Date = 19/11/2008 20:34:08 | Attr = ]
(d812a079) d812a079 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\d812a079.sys -> [Ver = | Size = 5504 bytes | Modified Date = 21/11/2008 14:26:05 | Attr = ]
(f35ee9e) f35ee9e [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\f35ee9e.sys -> [Ver = | Size = 5504 bytes | Modified Date = 19/11/2008 20:33:49 | Attr = ]
(FTDIBUS) USB Serial Converter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ftdibus.sys -> FTDI Ltd. [Ver = 1.00.2154 | Size = 24209 bytes | Modified Date = 20/04/2004 02:04:56 | Attr = ]
(FTSER2K) USB Serial Port Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ftser2k.sys -> FTDI Ltd. [Ver = 1.00.2154 | Size = 57404 bytes | Modified Date = 20/04/2004 02:05:10 | Attr = ]
(gmer) gmer [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\gmer.sys -> GMER [Ver = 1, 0, 14, 4401 | Size = 85969 bytes | Modified Date = 02/11/2008 17:46:16 | Attr = ]
(hardlock) hardlock [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\hardlock.sys -> [Ver = | Size = 420000 bytes | Modified Date = 31/01/2004 09:14:32 | Attr = ]
(haspnt) haspnt [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\haspnt.sys -> Aladdin Knowledge Systems [Ver = 4.65 | Size = 47616 bytes | Modified Date = 18/12/2003 07:53:06 | Attr = ]
(Iviaspi) IVI ASPI Shell [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\iviaspi.sys -> InterVideo, Inc. [Ver = 1, 0, 0, 0 | Size = 21060 bytes | Modified Date = 10/09/2003 14:36:54 | Attr = ]
(LHidKe) Logitech SetPoint HID Mouse Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LHidKE.Sys -> Logitech, Inc. [Ver = 2.60.570.00 | Size = 27008 bytes | Modified Date = 28/03/2006 07:56:06 | Attr = ]
(LHidUsbK) Logitech SetPoint USB Receiver device driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LHidUsbK.sys -> Logitech, Inc. [Ver = 2.60.570.00 | Size = 36736 bytes | Modified Date = 28/03/2006 07:55:20 | Attr = ]
(LMouKE) Logitech SetPoint Mouse Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LMouKE.Sys -> Logitech, Inc. [Ver = 2.60.570.00 | Size = 69760 bytes | Modified Date = 28/03/2006 07:55:58 | Attr = ]
(LVUSBSta) Logitech USB Monitor Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LVUSBSta.sys -> Logitech Inc. [Ver = 8.4.7.1032 | Size = 22016 bytes | Modified Date = 27/05/2005 01:31:28 | Attr = R ]
(meiudf) meiudf [File_System | System | Running] -> %SystemRoot%\system32\drivers\meiudf.sys -> Matsushita Electric Industrial Co.,Ltd. [Ver = 4.0.7.0 | Size = 102384 bytes | Modified Date = 02/06/2005 02:33:00 | Attr = ]
(Netdevio) TOSHIBA Network Device Usermode I/O Protocol [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\Netdevio.sys -> TOSHIBA Corporation. [Ver = Version 5.00.01.00 built by: WinDDK | Size = 12032 bytes | Modified Date = 29/01/2003 13:35:00 | Attr = ]
(PalmUSBD) PalmUSBD [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\PalmUSBD.sys -> Palm, Inc. [Ver = 1, 4, 0, 0 | Size = 16509 bytes | Modified Date = 13/04/2004 08:03:46 | Attr = ]
(pepifilter) Volume Adapter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\lv302af.sys -> Logitech Inc. [Ver = 8.4.7.1032 | Size = 7136 bytes | Modified Date = 27/05/2005 01:38:00 | Attr = R ]
(PID_08A0) QuickCam IM(PID_08A0) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LV302AV.SYS -> Logitech Inc. [Ver = 8.4.7.1032 | Size = 913280 bytes | Modified Date = 27/05/2005 01:46:22 | Attr = R ]
(RTL8023xp) Realtek 10/100/1000 NIC Family all in one NDIS XP Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Rtlnicxp.sys -> Realtek Semiconductor Corporation [Ver = 5.621.0304.2005 built by: WinDDK | Size = 74496 bytes | Modified Date = 04/03/2005 10:10:26 | Attr = ]
(rtl8139) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\RTL8139.sys -> Realtek Semiconductor Corporation [Ver = 5.398.613.2003 built by: WinDDK | Size = 20992 bytes | Modified Date = 03/08/2004 14:31:34 | Attr = ]
(SrvcSSIOMngr) SrvcSSIOMngr [Kernel | System | Running] -> %SystemRoot%\system32\drivers\SSIOMngr.sys -> COMPAL ELECTRONIC INC. [Ver = 1, 0, 0, 7 | Size = 6400 bytes | Modified Date = 30/07/2004 06:05:08 | Attr = ]
(tifm21) tifm21 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\tifm21.sys -> Texas Instruments [Ver = 2.0.0.1 | Size = 162176 bytes | Modified Date = 23/06/2005 08:16:08 | Attr = ]
(toshidpt) TOSHIBA Bluetooth HID port driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\Toshidpt.sys -> TOSHIBA Corporation. [Ver = Version 1.00.00 | Size = 2851 bytes | Modified Date = 16/10/2002 03:55:48 | Attr = ]
(tosporte) Bluetooth Port Driver from Toshiba [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Tosporte.sys -> TOSHIBA Corporation [Ver = 1.02.00 | Size = 47230 bytes | Modified Date = 30/03/2005 02:42:54 | Attr = ]
(Tosrfbd) Bluetooth RFBUS from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\TosRfbd.sys -> TOSHIBA CORPORATION [Ver = 01.03.34 | Size = 98048 bytes | Modified Date = 22/04/2005 11:11:30 | Attr = ]
(Tosrfbnp) Bluetooth RFBNEP from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\tosrfbnp.sys -> TOSHIBA Corporation [Ver = 1.00 | Size = 36531 bytes | Modified Date = 08/07/2004 07:07:34 | Attr = ]
(Tosrfcom) Bluetooth RFCOMM from TOSHIBA [Kernel | System | Running] -> %SystemRoot%\system32\drivers\tosrfcom.sys -> TOSHIBA Corporation [Ver = 1.02 | Size = 62799 bytes | Modified Date = 04/10/2004 00:33:02 | Attr = ]
(tosrfec) Bluetooth ACPI from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\Tosrfec.sys -> TOSHIBA Corporation [Ver = 1.02.00 | Size = 8573 bytes | Modified Date = 17/05/2004 05:18:26 | Attr = ]
(Tosrfhid) Bluetooth RFHID from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\TosRfhid.sys -> TOSHIBA Corporation. [Ver = Version 1.03.14 | Size = 52608 bytes | Modified Date = 22/04/2005 12:34:56 | Attr = ]
(tosrfnds) Bluetooth Personal Area Network from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\tosrfnds.sys -> TOSHIBA Corporation. [Ver = Version 1.00.03 | Size = 18612 bytes | Modified Date = 06/01/2005 03:42:42 | Attr = ]
(TosRfSnd) Bluetooth Audio Device (WDM) from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\TosRfSnd.sys -> TOSHIBA Corporation [Ver = 1.0.0.0 | Size = 50048 bytes | Modified Date = 05/04/2005 23:54:44 | Attr = ]
(Tosrfusb) Bluetooth USB Controller [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\tosrfusb.sys -> TOSHIBA CORPORATION [Ver = 02.00.11 | Size = 34816 bytes | Modified Date = 21/12/2004 01:38:12 | Attr = ]
(TPwSav) Common Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\TPwSav.sys -> TOSHIBA [Ver = 1, 0, 2, 3 | Size = 9600 bytes | Modified Date = 03/06/2005 10:49:42 | Attr = ]
(Tvs) Toshiba Virtual Sound with SRS technologies [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Tvs.sys -> TOSHIBA Corporation [Ver = 1, 0, 1, 6 | Size = 30592 bytes | Modified Date = 29/07/2005 00:55:46 | Attr = ]

[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
AGRSMMSG -> %SystemRoot%\agrsmmsg.exe [AGRSMMSG.exe] -> Agere Systems [Ver = 2.1.49 2.1.49 12/20/2004 15:10:02 | Size = 88358 bytes | Modified Date = 22/12/2004 00:10:04 | Attr = ]
Apoint -> %ProgramFiles%\Apoint2K\Apoint.exe [C:\Program Files\Apoint2K\Apoint.exe] -> Alps Electric Co., Ltd. [Ver = 6.0.2.186 | Size = 196608 bytes | Modified Date = 23/03/2004 21:40:42 | Attr = ]
ccApp -> %CommonProgramFiles%\Symantec Shared\ccApp.exe ["C:\Program Files\Common Files\Symantec Shared\ccApp.exe"] -> Symantec Corporation [Ver = 103.5.2.3 | Size = 48752 bytes | Modified Date = 19/04/2005 16:28:48 | Attr = ]
CeEKEY -> %ProgramFiles%\Toshiba\E-KEY\CeEKey.exe [C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe] -> COMPAL ELECTRONIC INC. [Ver = 1, 0, 0, 31 | Size = 671744 bytes | Modified Date = 06/09/2005 05:04:52 | Attr = ]
CFSServ.exe -> [CFSServ.exe -NoClient] -> File not found
dla -> %SystemRoot%\system32\dla\tfswctrl.exe [C:\WINDOWS\system32\dla\tfswctrl.exe] -> Sonic Solutions [Ver = 1.04.08a | Size = 122941 bytes | Modified Date = 30/05/2005 20:33:00 | Attr = ]
HWSetup -> %ProgramFiles%\Toshiba\TOSHIBA Applet\HWSetup.exe [C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP] -> TOSHIBA CO.,LTD. [Ver = 1, 0, 0, 18 | Size = 28672 bytes | Modified Date = 01/05/2004 04:45:30 | Attr = ]
igfxhkcmd -> %SystemRoot%\system32\hkcmd.exe [C:\WINDOWS\system32\hkcmd.exe] -> Intel Corporation [Ver = 3.0.0.4363 | Size = 77824 bytes | Modified Date = 19/07/2005 10:06:12 | Attr = ]
igfxpers -> %SystemRoot%\system32\igfxpers.exe [C:\WINDOWS\system32\igfxpers.exe] -> Intel Corporation [Ver = 3.0.0.4363 | Size = 114688 bytes | Modified Date = 19/07/2005 10:10:06 | Attr = ]
igfxtray -> %SystemRoot%\system32\igfxtray.exe [C:\WINDOWS\system32\igfxtray.exe] -> Intel Corporation [Ver = 3.0.0.4363 | Size = 94208 bytes | Modified Date = 19/07/2005 10:09:26 | Attr = ]
Logitech Hardware Abstraction Layer -> %SystemRoot%\KHALMNPR.Exe [KHALMNPR.EXE] -> Logitech Inc. [Ver = 2.60.570 | Size = 94208 bytes | Modified Date = 28/03/2006 07:38:32 | Attr = ]
LVCOMSX -> %SystemRoot%\system32\LVCOMSX.EXE [C:\WINDOWS\system32\LVCOMSX.EXE] -> Logitech Inc. [Ver = 8.4.7.1036 | Size = 221184 bytes | Modified Date = 19/07/2005 08:32:18 | Attr = ]
MPKrnl -> %SystemRoot%\MPKrnl.dll [rundll32 "C:\WINDOWS\MPKrnl.dll",KrnlMsgProc] -> [Ver = | Size = 20480 bytes | Modified Date = 19/11/2008 20:50:38 | Attr = ]
NDSTray.exe -> [NDSTray.exe] -> File not found
QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> Apple Inc. [Ver = 7.2 | Size = 286720 bytes | Modified Date = 28/06/2007 20:24:52 | Attr = ]
SVPWUTIL -> %ProgramFiles%\Toshiba\Windows Utilities\SVPWUTIL.exe [C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL] -> TOSHIBA [Ver = 1, 0, 0, 15 | Size = 65536 bytes | Modified Date = 01/05/2004 04:45:40 | Attr = ]
TCtryIOHook -> %SystemRoot%\system32\TCtrlIOHook.exe [TCtrlIOHook.exe] -> TOSHIBA [Ver = 1, 0, 0, 4 | Size = 28672 bytes | Modified Date = 22/08/2005 07:49:28 | Attr = ]
TFncKy -> [TFncKy.exe] -> File not found
TPNF -> %ProgramFiles%\Toshiba\TouchPad\TPTray.exe [C:\Program Files\TOSHIBA\TouchPad\TPTray.exe] -> COMPAL ELECTRONIC INC. [Ver = 1, 0, 0, 7 | Size = 53248 bytes | Modified Date = 25/08/2005 10:11:58 | Attr = ]
Tvs -> %ProgramFiles%\Toshiba\Tvs\TvsTray.exe [C:\Program Files\TOSHIBA\Tvs\TvsTray.exe] -> TOSHIBA Corporation [Ver = 1, 0, 0, 4 | Size = 73728 bytes | Modified Date = 05/04/2005 07:25:34 | Attr = ]
URLLSTCK.exe -> %ProgramFiles%\Norton Internet Security\UrlLstCk.exe [C:\Program Files\Norton Internet Security\UrlLstCk.exe] -> Symantec Corporation [Ver = 8.5.0.113 | Size = 22656 bytes | Modified Date = 05/05/2005 19:27:14 | Attr = ]
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
swg -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 19/06/2007 13:47:22 | Attr = ]
TOSCDSPD -> %ProgramFiles%\Toshiba\TOSCDSPD\TOSCDSPD.exe [C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe] -> TOSHIBA [Ver = 1, 0, 6, 0 | Size = 65536 bytes | Modified Date = 11/04/2005 02:26:06 | Attr = ]
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersProfile%\Start Menu\Programs\Startup\RAMASST.lnk -> %SystemRoot%\system32\RAMASST.exe -> Matsushita Electric Industrial Co., Ltd. [Ver = 1, 1, 0, 0 | Size = 155648 bytes | Modified Date = 27/08/2004 23:37:00 | Attr = ]
< OKUCU Startup Folder > -> C:\Documents and Settings\OKUCU\Start Menu\Programs\Startup ->
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
{01AFE3DC-2242-436E-9B44-6DD1C664E828} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{16AF66EB-93C8-49F9-BB09-B4F87CEDCE46} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{201476D0-2B18-462E-AB9F-3E2B0CC8732B} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{29EA67E0-9EE5-4D1A-A056-5B7BDAC4CF97} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{34A25F04-008D-403E-8EE6-2307BC02FA2E} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{3B8DA919-1139-4B10-AD8F-91E8FBCFD375} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{56BC86C7-0692-4F94-A2C1-6CF1DBF8096C} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{5934EA2B-B2C4-4BE7-BF7A-FBA781A12E40} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{93DEE065-EC9B-4505-ADD3-19880AD3C38F} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{950D1600-DE4A-448D-93B4-7BAE5A7A8052} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{A55F538E-9E65-4706-9458-852BF6592063} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{AD794E6B-90B7-4F9D-8FD6-0C16E3298FF2} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{B8E83D3C-9466-4091-9AD1-1F89418A6EB7} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{DFB3DAC5-B0B5-4B05-BFCF-FB42737778FA} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{E1D19FCC-4777-4D71-B863-6A0A5B4E59BC} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{F8E07BB2-7A19-4057-80F1-E14646E630B4} [HKEY_LOCAL_MACHINE] -> [] -> File not found
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> %SystemRoot%\explorer.exe -> Microsoft Corporation [Ver = 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234) | Size = 1033216 bytes | Modified Date = 13/06/2007 02:23:07 | Attr = ]
*MultiFile Done* -> ->
*UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit ->
C:\WINDOWS\system32\userinit.exe -> %SystemRoot%\system32\userinit.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 24576 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
*MultiFile Done* -> ->
*UIHost* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost ->
logonui.exe -> %SystemRoot%\system32\logonui.exe -> Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 514560 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
*MultiFile Done* -> ->
*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
rundll32 shell32 -> %SystemRoot%\system32\shell32.dll -> Microsoft Corporation [Ver = 6.00.2900.3241 (xpsp_sp2_qfe.071025-1245) | Size = 8460288 bytes | Modified Date = 25/10/2007 19:34:01 | Attr = ]
Control_RunDLL "sysdm.cpl" -> %SystemRoot%\system32\sysdm.cpl -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 298496 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
*MultiFile Done* -> ->
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
igfxcui -> %SystemRoot%\system32\igfxdev.dll -> Intel Corporation [Ver = 3.0.0.4363 | Size = 135168 bytes | Modified Date = 19/07/2005 10:05:16 | Attr = ]
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoCDBurning -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 227 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> 67108863 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
*MPMKrnl* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\
  • 0

#70
okucu

okucu

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
OTScan once more - I guess it did not fit in last time ...

[code=auto:0]OTScanIt logfile created on: 24/11/2008 23:39:11
OTScanIt by OldTimer - Version 1.0.19.0 Folder = C:\Documents and Settings\OKUCU\Desktop\OTScanIt
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.49 Gb Total Physical Memory | 1.01 Gb Available Physical Memory | 68.05% Memory free
2.09 Gb Paging File | 1.77 Gb Available in Paging File | 84.82% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 13.15 Gb Free Space | 35.30% Space Free | Partition Type: NTFS
Drive D: | 37.23 Gb Total Space | 10.19 Gb Free Space | 27.37% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-C36CAA9C21
Current User Name: OKUCU
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On

[Processes - Non-Microsoft Only]
adskscsrv.exe -> %CommonProgramFiles%\Autodesk Shared\Service\AdskScSrv.exe -> Autodesk [Ver = 2.80.011 | Size = 79360 bytes | Modified Date = 09/10/2008 08:54:38 | Attr = ]
cfsvcs.exe -> %ProgramFiles%\Toshiba\ConfigFree\CFSvcs.exe -> TOSHIBA CORPORATION [Ver = 6, 0, 0, 1 | Size = 40960 bytes | Modified Date = 17/01/2005 15:38:38 | Attr = ]
dvdramsv.exe -> %SystemRoot%\system32\DVDRAMSV.exe -> Matsushita Electric Industrial Co., Ltd. [Ver = 3, 0, 0, 0 | Size = 110592 bytes | Modified Date = 27/08/2004 23:33:00 | Attr = ]
raysat_3dsmax2008_32server.exe -> %ProgramFiles%\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe -> [Ver = | Size = 65536 bytes | Modified Date = 24/09/2007 06:05:26 | Attr = ]
solidpdfservice.exe -> %ProgramFiles%\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe -> VoyagerSoft, LLC [Ver = 3.1.437.0 | Size = 184320 bytes | Modified Date = 02/11/2006 04:24:32 | Attr = ]
tfncky.exe -> %ProgramFiles%\Toshiba\TOSHIBA Controls\TFncKy.exe -> TOSHIBA Corporation [Ver = 3.19.00 | Size = 184320 bytes | Modified Date = 17/05/2005 01:14:12 | Attr = ]
tvstray.exe -> %ProgramFiles%\Toshiba\Tvs\TvsTray.exe -> TOSHIBA Corporation [Ver = 1, 0, 0, 4 | Size = 73728 bytes | Modified Date = 05/04/2005 07:25:34 | Attr = ]
cfsserv.exe -> %ProgramFiles%\Toshiba\ConfigFree\CFSServ.exe -> TOSHIBA CORPORATION [Ver = 6, 0, 0, 115 | Size = 798720 bytes | Modified Date = 29/07/2005 13:31:56 | Attr = ]
ceekey.exe -> %ProgramFiles%\Toshiba\E-KEY\CeEKey.exe -> COMPAL ELECTRONIC INC. [Ver = 1, 0, 0, 31 | Size = 671744 bytes | Modified Date = 06/09/2005 05:04:52 | Attr = ]
tptray.exe -> %ProgramFiles%\Toshiba\TouchPad\TPTray.exe -> COMPAL ELECTRONIC INC. [Ver = 1, 0, 0, 7 | Size = 53248 bytes | Modified Date = 25/08/2005 10:11:58 | Attr = ]
tctrliohook.exe -> %SystemRoot%\system32\TCtrlIOHook.exe -> TOSHIBA [Ver = 1, 0, 0, 4 | Size = 28672 bytes | Modified Date = 22/08/2005 07:49:28 | Attr = ]
ndstray.exe -> %ProgramFiles%\Toshiba\ConfigFree\NDSTray.exe -> TOSHIBA CORPORATION [Ver = 6, 0, 0, 17 | Size = 978944 bytes | Modified Date = 06/08/2005 01:18:38 | Attr = ]
lvcomsx.exe -> %SystemRoot%\system32\LVCOMSX.EXE -> Logitech Inc. [Ver = 8.4.7.1036 | Size = 221184 bytes | Modified Date = 19/07/2005 08:32:18 | Attr = ]
agrsmmsg.exe -> %SystemRoot%\agrsmmsg.exe -> Agere Systems [Ver = 2.1.49 2.1.49 12/20/2004 15:10:02 | Size = 88358 bytes | Modified Date = 22/12/2004 00:10:04 | Attr = ]
toscdspd.exe -> %ProgramFiles%\Toshiba\TOSCDSPD\TOSCDSPD.exe -> TOSHIBA [Ver = 1, 0, 6, 0 | Size = 65536 bytes | Modified Date = 11/04/2005 02:26:06 | Attr = ]
ramasst.exe -> %SystemRoot%\system32\RAMASST.exe -> Matsushita Electric Industrial Co., Ltd. [Ver = 1, 1, 0, 0 | Size = 155648 bytes | Modified Date = 27/08/2004 23:37:00 | Attr = ]

[Win32 Services - Non-Microsoft Only]
(Autodesk Licensing Service) Autodesk Licensing Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Autodesk Shared\Service\AdskScSrv.exe -> Autodesk [Ver = 2.80.011 | Size = 79360 bytes | Modified Date = 09/10/2008 08:54:38 | Attr = ]
(CFSvcs) ConfigFree Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Toshiba\ConfigFree\CFSvcs.exe -> TOSHIBA CORPORATION [Ver = 6, 0, 0, 1 | Size = 40960 bytes | Modified Date = 17/01/2005 15:38:38 | Attr = ]
(DVD-RAM_Service) DVD-RAM_Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\DVDRAMSV.exe -> Matsushita Electric Industrial Co., Ltd. [Ver = 3, 0, 0, 0 | Size = 110592 bytes | Modified Date = 27/08/2004 23:33:00 | Attr = ]
(FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> Macrovision Europe Ltd. [Ver = 11.03.005 | Size = 654848 bytes | Modified Date = 09/10/2008 10:17:55 | Attr = ]
(mi-raysat_3dsMax2008_32) mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit [Win32_Own | Auto | Running] -> %ProgramFiles%\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe -> [Ver = | Size = 65536 bytes | Modified Date = 24/09/2007 06:05:26 | Attr = ]
(ScReadSpool) SolidPDFConverterReadSpool [Win32_Shared | Auto | Running] -> %ProgramFiles%\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe -> VoyagerSoft, LLC [Ver = 3.1.437.0 | Size = 184320 bytes | Modified Date = 02/11/2006 04:24:32 | Attr = ]
(SVCHOSTS32) Windows Host Services [Win32_Own | Auto | Stopped] -> %SystemRoot%\system\svchost.exe -> File not found

[Driver Services - Non-Microsoft Only]
(AgereSoftModem) TOSHIBA V92 Software Modem [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\AGRSM.sys -> Agere Systems [Ver = 2.1.51 2.1.51 03/04/2005 12:02:18 | Size = 1066278 bytes | Modified Date = 05/03/2005 04:02:20 | Attr = ]
(b160485) b160485 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\b160485.sys -> [Ver = | Size = 5504 bytes | Modified Date = 19/11/2008 20:33:54 | Attr = ]
(cdrbsdrv) cdrbsdrv [Kernel | System | Running] -> %SystemRoot%\System32\drivers\CDRBSDRV.SYS -> B.H.A Corporation [Ver = 7. 0. 0. 5 | Size = 13567 bytes | Modified Date = 08/03/2004 02:55:50 | Attr = ]
(d435fd4) d435fd4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\d435fd4.sys -> [Ver = | Size = 5504 bytes | Modified Date = 19/11/2008 20:34:08 | Attr = ]
(d812a079) d812a079 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\d812a079.sys -> [Ver = | Size = 5504 bytes | Modified Date = 21/11/2008 14:26:05 | Attr = ]
(f35ee9e) f35ee9e [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\f35ee9e.sys -> [Ver = | Size = 5504 bytes | Modified Date = 19/11/2008 20:33:49 | Attr = ]
(FTDIBUS) USB Serial Converter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ftdibus.sys -> FTDI Ltd. [Ver = 1.00.2154 | Size = 24209 bytes | Modified Date = 20/04/2004 02:04:56 | Attr = ]
(FTSER2K) USB Serial Port Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ftser2k.sys -> FTDI Ltd. [Ver = 1.00.2154 | Size = 57404 bytes | Modified Date = 20/04/2004 02:05:10 | Attr = ]
(gmer) gmer [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\gmer.sys -> GMER [Ver = 1, 0, 14, 4401 | Size = 85969 bytes | Modified Date = 02/11/2008 17:46:16 | Attr = ]
(hardlock) hardlock [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\hardlock.sys -> [Ver = | Size = 420000 bytes | Modified Date = 31/01/2004 09:14:32 | Attr = ]
(haspnt) haspnt [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\haspnt.sys -> Aladdin Knowledge Systems [Ver = 4.65 | Size = 47616 bytes | Modified Date = 18/12/2003 07:53:06 | Attr = ]
(Iviaspi) IVI ASPI Shell [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\iviaspi.sys -> InterVideo, Inc. [Ver = 1, 0, 0, 0 | Size = 21060 bytes | Modified Date = 10/09/2003 14:36:54 | Attr = ]
(LHidKe) Logitech SetPoint HID Mouse Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LHidKE.Sys -> Logitech, Inc. [Ver = 2.60.570.00 | Size = 27008 bytes | Modified Date = 28/03/2006 07:56:06 | Attr = ]
(LHidUsbK) Logitech SetPoint USB Receiver device driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LHidUsbK.sys -> Logitech, Inc. [Ver = 2.60.570.00 | Size = 36736 bytes | Modified Date = 28/03/2006 07:55:20 | Attr = ]
(LMouKE) Logitech SetPoint Mouse Filter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LMouKE.Sys -> Logitech, Inc. [Ver = 2.60.570.00 | Size = 69760 bytes | Modified Date = 28/03/2006 07:55:58 | Attr = ]
(LVUSBSta) Logitech USB Monitor Filter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LVUSBSta.sys -> Logitech Inc. [Ver = 8.4.7.1032 | Size = 22016 bytes | Modified Date = 27/05/2005 01:31:28 | Attr = R ]
(meiudf) meiudf [File_System | System | Running] -> %SystemRoot%\system32\drivers\meiudf.sys -> Matsushita Electric Industrial Co.,Ltd. [Ver = 4.0.7.0 | Size = 102384 bytes | Modified Date = 02/06/2005 02:33:00 | Attr = ]
(Netdevio) TOSHIBA Network Device Usermode I/O Protocol [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\Netdevio.sys -> TOSHIBA Corporation. [Ver = Version 5.00.01.00 built by: WinDDK | Size = 12032 bytes | Modified Date = 29/01/2003 13:35:00 | Attr = ]
(PalmUSBD) PalmUSBD [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\PalmUSBD.sys -> Palm, Inc. [Ver = 1, 4, 0, 0 | Size = 16509 bytes | Modified Date = 13/04/2004 08:03:46 | Attr = ]
(pepifilter) Volume Adapter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\lv302af.sys -> Logitech Inc. [Ver = 8.4.7.1032 | Size = 7136 bytes | Modified Date = 27/05/2005 01:38:00 | Attr = R ]
(PID_08A0) QuickCam IM(PID_08A0) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\LV302AV.SYS -> Logitech Inc. [Ver = 8.4.7.1032 | Size = 913280 bytes | Modified Date = 27/05/2005 01:46:22 | Attr = R ]
(RTL8023xp) Realtek 10/100/1000 NIC Family all in one NDIS XP Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Rtlnicxp.sys -> Realtek Semiconductor Corporation [Ver = 5.621.0304.2005 built by: WinDDK | Size = 74496 bytes | Modified Date = 04/03/2005 10:10:26 | Attr = ]
(rtl8139) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\RTL8139.sys -> Realtek Semiconductor Corporation [Ver = 5.398.613.2003 built by: WinDDK | Size = 20992 bytes | Modified Date = 03/08/2004 14:31:34 | Attr = ]
(SrvcSSIOMngr) SrvcSSIOMngr [Kernel | System | Running] -> %SystemRoot%\system32\drivers\SSIOMngr.sys -> COMPAL ELECTRONIC INC. [Ver = 1, 0, 0, 7 | Size = 6400 bytes | Modified Date = 30/07/2004 06:05:08 | Attr = ]
(tifm21) tifm21 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\tifm21.sys -> Texas Instruments [Ver = 2.0.0.1 | Size = 162176 bytes | Modified Date = 23/06/2005 08:16:08 | Attr = ]
(toshidpt) TOSHIBA Bluetooth HID port driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\Toshidpt.sys -> TOSHIBA Corporation. [Ver = Version 1.00.00 | Size = 2851 bytes | Modified Date = 16/10/2002 03:55:48 | Attr = ]
(tosporte) Bluetooth Port Driver from Toshiba [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Tosporte.sys -> TOSHIBA Corporation [Ver = 1.02.00 | Size = 47230 bytes | Modified Date = 30/03/2005 02:42:54 | Attr = ]
(Tosrfbd) Bluetooth RFBUS from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\TosRfbd.sys -> TOSHIBA CORPORATION [Ver = 01.03.34 | Size = 98048 bytes | Modified Date = 22/04/2005 11:11:30 | Attr = ]
(Tosrfbnp) Bluetooth RFBNEP from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\tosrfbnp.sys -> TOSHIBA Corporation [Ver = 1.00 | Size = 36531 bytes | Modified Date = 08/07/2004 07:07:34 | Attr = ]
(Tosrfcom) Bluetooth RFCOMM from TOSHIBA [Kernel | System | Running] -> %SystemRoot%\system32\drivers\tosrfcom.sys -> TOSHIBA Corporation [Ver = 1.02 | Size = 62799 bytes | Modified Date = 04/10/2004 00:33:02 | Attr = ]
(tosrfec) Bluetooth ACPI from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\Tosrfec.sys -> TOSHIBA Corporation [Ver = 1.02.00 | Size = 8573 bytes | Modified Date = 17/05/2004 05:18:26 | Attr = ]
(Tosrfhid) Bluetooth RFHID from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\TosRfhid.sys -> TOSHIBA Corporation. [Ver = Version 1.03.14 | Size = 52608 bytes | Modified Date = 22/04/2005 12:34:56 | Attr = ]
(tosrfnds) Bluetooth Personal Area Network from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\tosrfnds.sys -> TOSHIBA Corporation. [Ver = Version 1.00.03 | Size = 18612 bytes | Modified Date = 06/01/2005 03:42:42 | Attr = ]
(TosRfSnd) Bluetooth Audio Device (WDM) from TOSHIBA [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\TosRfSnd.sys -> TOSHIBA Corporation [Ver = 1.0.0.0 | Size = 50048 bytes | Modified Date = 05/04/2005 23:54:44 | Attr = ]
(Tosrfusb) Bluetooth USB Controller [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\tosrfusb.sys -> TOSHIBA CORPORATION [Ver = 02.00.11 | Size = 34816 bytes | Modified Date = 21/12/2004 01:38:12 | Attr = ]
(TPwSav) Common Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\TPwSav.sys -> TOSHIBA [Ver = 1, 0, 2, 3 | Size = 9600 bytes | Modified Date = 03/06/2005 10:49:42 | Attr = ]
(Tvs) Toshiba Virtual Sound with SRS technologies [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Tvs.sys -> TOSHIBA Corporation [Ver = 1, 0, 1, 6 | Size = 30592 bytes | Modified Date = 29/07/2005 00:55:46 | Attr = ]

[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
AGRSMMSG -> %SystemRoot%\agrsmmsg.exe [AGRSMMSG.exe] -> Agere Systems [Ver = 2.1.49 2.1.49 12/20/2004 15:10:02 | Size = 88358 bytes | Modified Date = 22/12/2004 00:10:04 | Attr = ]
Apoint -> %ProgramFiles%\Apoint2K\Apoint.exe [C:\Program Files\Apoint2K\Apoint.exe] -> Alps Electric Co., Ltd. [Ver = 6.0.2.186 | Size = 196608 bytes | Modified Date = 23/03/2004 21:40:42 | Attr = ]
ccApp -> %CommonProgramFiles%\Symantec Shared\ccApp.exe ["C:\Program Files\Common Files\Symantec Shared\ccApp.exe"] -> Symantec Corporation [Ver = 103.5.2.3 | Size = 48752 bytes | Modified Date = 19/04/2005 16:28:48 | Attr = ]
CeEKEY -> %ProgramFiles%\Toshiba\E-KEY\CeEKey.exe [C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe] -> COMPAL ELECTRONIC INC. [Ver = 1, 0, 0, 31 | Size = 671744 bytes | Modified Date = 06/09/2005 05:04:52 | Attr = ]
CFSServ.exe -> [CFSServ.exe -NoClient] -> File not found
dla -> %SystemRoot%\system32\dla\tfswctrl.exe [C:\WINDOWS\system32\dla\tfswctrl.exe] -> Sonic Solutions [Ver = 1.04.08a | Size = 122941 bytes | Modified Date = 30/05/2005 20:33:00 | Attr = ]
HWSetup -> %ProgramFiles%\Toshiba\TOSHIBA Applet\HWSetup.exe [C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP] -> TOSHIBA CO.,LTD. [Ver = 1, 0, 0, 18 | Size = 28672 bytes | Modified Date = 01/05/2004 04:45:30 | Attr = ]
igfxhkcmd -> %SystemRoot%\system32\hkcmd.exe [C:\WINDOWS\system32\hkcmd.exe] -> Intel Corporation [Ver = 3.0.0.4363 | Size = 77824 bytes | Modified Date = 19/07/2005 10:06:12 | Attr = ]
igfxpers -> %SystemRoot%\system32\igfxpers.exe [C:\WINDOWS\system32\igfxpers.exe] -> Intel Corporation [Ver = 3.0.0.4363 | Size = 114688 bytes | Modified Date = 19/07/2005 10:10:06 | Attr = ]
igfxtray -> %SystemRoot%\system32\igfxtray.exe [C:\WINDOWS\system32\igfxtray.exe] -> Intel Corporation [Ver = 3.0.0.4363 | Size = 94208 bytes | Modified Date = 19/07/2005 10:09:26 | Attr = ]
Logitech Hardware Abstraction Layer -> %SystemRoot%\KHALMNPR.Exe [KHALMNPR.EXE] -> Logitech Inc. [Ver = 2.60.570 | Size = 94208 bytes | Modified Date = 28/03/2006 07:38:32 | Attr = ]
LVCOMSX -> %SystemRoot%\system32\LVCOMSX.EXE [C:\WINDOWS\system32\LVCOMSX.EXE] -> Logitech Inc. [Ver = 8.4.7.1036 | Size = 221184 bytes | Modified Date = 19/07/2005 08:32:18 | Attr = ]
MPKrnl -> %SystemRoot%\MPKrnl.dll [rundll32 "C:\WINDOWS\MPKrnl.dll",KrnlMsgProc] -> [Ver = | Size = 20480 bytes | Modified Date = 19/11/2008 20:50:38 | Attr = ]
NDSTray.exe -> [NDSTray.exe] -> File not found
QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> Apple Inc. [Ver = 7.2 | Size = 286720 bytes | Modified Date = 28/06/2007 20:24:52 | Attr = ]
SVPWUTIL -> %ProgramFiles%\Toshiba\Windows Utilities\SVPWUTIL.exe [C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL] -> TOSHIBA [Ver = 1, 0, 0, 15 | Size = 65536 bytes | Modified Date = 01/05/2004 04:45:40 | Attr = ]
TCtryIOHook -> %SystemRoot%\system32\TCtrlIOHook.exe [TCtrlIOHook.exe] -> TOSHIBA [Ver = 1, 0, 0, 4 | Size = 28672 bytes | Modified Date = 22/08/2005 07:49:28 | Attr = ]
TFncKy -> [TFncKy.exe] -> File not found
TPNF -> %ProgramFiles%\Toshiba\TouchPad\TPTray.exe [C:\Program Files\TOSHIBA\TouchPad\TPTray.exe] -> COMPAL ELECTRONIC INC. [Ver = 1, 0, 0, 7 | Size = 53248 bytes | Modified Date = 25/08/2005 10:11:58 | Attr = ]
Tvs -> %ProgramFiles%\Toshiba\Tvs\TvsTray.exe [C:\Program Files\TOSHIBA\Tvs\TvsTray.exe] -> TOSHIBA Corporation [Ver = 1, 0, 0, 4 | Size = 73728 bytes | Modified Date = 05/04/2005 07:25:34 | Attr = ]
URLLSTCK.exe -> %ProgramFiles%\Norton Internet Security\UrlLstCk.exe [C:\Program Files\Norton Internet Security\UrlLstCk.exe] -> Symantec Corporation [Ver = 8.5.0.113 | Size = 22656 bytes | Modified Date = 05/05/2005 19:27:14 | Attr = ]
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
swg -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 19/06/2007 13:47:22 | Attr = ]
TOSCDSPD -> %ProgramFiles%\Toshiba\TOSCDSPD\TOSCDSPD.exe [C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe] -> TOSHIBA [Ver = 1, 0, 6, 0 | Size = 65536 bytes | Modified Date = 11/04/2005 02:26:06 | Attr = ]
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersProfile%\Start Menu\Programs\Startup\RAMASST.lnk -> %SystemRoot%\system32\RAMASST.exe -> Matsushita Electric Industrial Co., Ltd. [Ver = 1, 1, 0, 0 | Size = 155648 bytes | Modified Date = 27/08/2004 23:37:00 | Attr = ]
< OKUCU Startup Folder > -> C:\Documents and Settings\OKUCU\Start Menu\Programs\Startup ->
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
{01AFE3DC-2242-436E-9B44-6DD1C664E828} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{16AF66EB-93C8-49F9-BB09-B4F87CEDCE46} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{201476D0-2B18-462E-AB9F-3E2B0CC8732B} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{29EA67E0-9EE5-4D1A-A056-5B7BDAC4CF97} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{34A25F04-008D-403E-8EE6-2307BC02FA2E} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{3B8DA919-1139-4B10-AD8F-91E8FBCFD375} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{56BC86C7-0692-4F94-A2C1-6CF1DBF8096C} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{5934EA2B-B2C4-4BE7-BF7A-FBA781A12E40} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{93DEE065-EC9B-4505-ADD3-19880AD3C38F} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{950D1600-DE4A-448D-93B4-7BAE5A7A8052} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{A55F538E-9E65-4706-9458-852BF6592063} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{AD794E6B-90B7-4F9D-8FD6-0C16E3298FF2} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{B8E83D3C-9466-4091-9AD1-1F89418A6EB7} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{DFB3DAC5-B0B5-4B05-BFCF-FB42737778FA} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{E1D19FCC-4777-4D71-B863-6A0A5B4E59BC} [HKEY_LOCAL_MACHINE] -> [] -> File not found
{F8E07BB2-7A19-4057-80F1-E14646E630B4} [HKEY_LOCAL_MACHINE] -> [] -> File not found
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> %SystemRoot%\explorer.exe -> Microsoft Corporation [Ver = 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234) | Size = 1033216 bytes | Modified Date = 13/06/2007 02:23:07 | Attr = ]
*MultiFile Done* -> ->
*UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit ->
C:\WINDOWS\system32\userinit.exe -> %SystemRoot%\system32\userinit.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 24576 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
*MultiFile Done* -> ->
*UIHost* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost ->
logonui.exe -> %SystemRoot%\system32\logonui.exe -> Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 514560 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
*MultiFile Done* -> ->
*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
rundll32 shell32 -> %SystemRoot%\system32\shell32.dll -> Microsoft Corporation [Ver = 6.00.2900.3241 (xpsp_sp2_qfe.071025-1245) | Size = 8460288 bytes | Modified Date = 25/10/2007 19:34:01 | Attr = ]
Control_RunDLL "sysdm.cpl" -> %SystemRoot%\system32\sysdm.cpl -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 298496 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
*MultiFile Done* -> ->
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
igfxcui -> %SystemRoot%\system32\igfxdev.dll -> Intel Corporation [Ver = 3.0.0.4363 | Size = 135168 bytes | Modified Date = 19/07/2005 10:05:16 | Attr = ]
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoCDBurning -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 227 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> 67108863 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
*MPMKrnl* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\MPMKrnl ->
rundll32 "C:\WINDOWS\MKMKrnl.dll" -> %SystemRoot%\MKMKrnl.dll -> [Ver = | Size = 10240 bytes | Modified Date = 19/11/2008 20:50:16 | Attr = ]
KMainProc -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\undockwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLegacyLogonScripts -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLogoffScripts -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunLogonScriptSync -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunStartupScriptSync -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideStartupScripts -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 0 ->
< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLegacyLogonScripts -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLogoffScripts -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunLogonScriptSync -> 1 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunStartupScriptSync -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideStartupScripts -> 0 ->
< CDROM Autorun Setting > [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\ -> ->
*DependOnGroup* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DependOnGroup ->
SCSI miniport -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ErrorControl -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Group -> SCSI CDROM Class ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Start -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Tag -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Type -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DisplayName -> CD-ROM Driver ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ImagePath -> %SystemRoot%\system32\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 49536 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun -> 1 ->
*AutoRunAlwaysDisable* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRunAlwaysDisable ->
NEC MBR-7 -> -> File not found
NEC MBR-7.4 -> -> File not found
PIONEER CHANGR DRM-1804X -> -> File not found
PIONEER CD-ROM DRM-6324X -> -> File not found
PIONEER CD-ROM DRM-624X -> -> File not found
TORiSAN CD-ROM CDR_C36 -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\ -> ->
< Drives with AutoRun files > -> ->
AUTOEXEC.BAT [PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | ] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [Ver = | Size = 50 bytes | Modified Date = 19/04/2006 12:00:30 | Attr = ]
AutoCad [] -> D:\AutoCad [ NTFS ] -> [Folder | Modified Date = 27/10/2008 19:46:44 | Attr = ]
< HOSTS File > (27 bytes and 1 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
127.0.0.1 localhost
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\Search Bar -> http://www.google.com/ ->
HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.msn.com/ ->
HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\Default_Search_URL -> http://www.google.com/ie ->
HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\Default_Search_URL -> http://www.google.com/ie ->
HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm ->
HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_CURRENT_USER\: Main\\Start Page -> http://www.google.com/ig?hl=en&amp;gl= ->
HKEY_CURRENT_USER\: SearchURL\\ -> http://www.google.com/search?q=%s[Reg Error: Value provider does not exist or could not be read.] ->
HKEY_CURRENT_USER\: ProxyEnable -> 0 ->
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4311 domain(s) found. ->
36 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 78 range(s) found. ->
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{259F616C-A300-44F5-B04A-ED001A26C85C} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll [Solid Converter PDF] -> VoyagerSoft, LLC [Ver = 3.1.437.0 | Size = 259584 bytes | Modified Date = 02/11/2006 04:09:42 | Attr = ]
{53707962-6F74-2D53-2644-206D7942484F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [] -> Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Modified Date = 30/05/2005 17:04:00 | Attr = ]
{5CA3D70E-1895-11CF-8E15-001234567890} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\dla\tfswshx.dll [DriveLetterAccess] -> Sonic Solutions [Ver = 1.04.08a | Size = 118844 bytes | Modified Date = 30/05/2005 20:33:00 | Attr = ]
{69A87B7D-DE56-4136-9655-716BA50C19C7} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\Web Accelerator\GoogleWebAccToolbar.dll [&Google Web Accelerator Helper] -> [Ver = | Size = 311296 bytes | Modified Date = 09/07/2007 12:24:38 | Attr = ]
{9ECB9560-04F9-4bbc-943D-298DDF1699E1} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Symantec Shared\AdBlocking\NISShExt.dll [CNisExtBho Class] -> Symantec Corporation [Ver = 8.5.0.113 | Size = 104064 bytes | Modified Date = 05/05/2005 19:27:30 | Attr = ]
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [Google Toolbar Helper] -> [Ver = | Size = 193136 bytes | Modified Date = 04/10/2008 22:21:59 | Attr = ]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll [Google Toolbar Notifier BHO] -> Google Inc. [Ver = 4, 1, 805, 4472 | Size = 652784 bytes | Modified Date = 24/10/2008 21:34:45 | Attr = ]
{BDF3E430-B101-42AD-A544-FADC6B084872} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Norton Internet Security\Norton AntiVirus\NAVShExt.dll [CNavExtBho Class] -> Symantec Corporation [Ver = 11.5.6.14 | Size = 218736 bytes | Modified Date = 05/05/2005 15:15:10 | Attr = ]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Symantec Shared\AdBlocking\NISShExt.dll [Norton Internet Security] -> Symantec Corporation [Ver = 8.5.0.113 | Size = 104064 bytes | Modified Date = 05/05/2005 19:27:30 | Attr = ]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [Ver = | Size = 193136 bytes | Modified Date = 04/10/2008 22:21:59 | Attr = ]
{259F616C-A300-44F5-B04A-ED001A26C85C} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll [Solid Converter PDF] -> VoyagerSoft, LLC [Ver = 3.1.437.0 | Size = 259584 bytes | Modified Date = 02/11/2006 04:09:42 | Attr = ]
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Norton Internet Security\Norton AntiVirus\NAVShExt.dll [Norton AntiVirus] -> Symantec Corporation [Ver = 11.5.6.14 | Size = 218736 bytes | Modified Date = 05/05/2005 15:15:10 | Attr = ]
{DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\Web Accelerator\GoogleWebAccToolbar.dll [Google Web Accelerator] -> [Ver = | Size = 311296 bytes | Modified Date = 09/07/2007 12:24:38 | Attr = ]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Norton Internet Security\Norton AntiVirus\NAVShExt.dll [Norton AntiVirus] -> Symantec Corporation [Ver = 11.5.6.14 | Size = 218736 bytes | Modified Date = 05/05/2005 15:15:10 | Attr = ]
WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Symantec Shared\AdBlocking\NISShExt.dll [Norton Internet Security] -> Symantec Corporation [Ver = 8.5.0.113 | Size = 104064 bytes | Modified Date = 05/05/2005 19:27:30 | Attr = ]
WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\Google Toolbar\GoogleToolbar.dll [&Google Toolbar] -> [Ver = | Size = 193136 bytes | Modified Date = 04/10/2008 22:21:59 | Attr = ]
WebBrowser\\{DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\Web Accelerator\GoogleWebAccToolbar.dll [Google Web Accelerator] -> [Ver = | Size = 311296 bytes | Modified Date = 09/07/2007 12:24:38 | Attr = ]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.5.0_03\bin\NPJPI150_03.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 5.0.30.7 | Size = 69746 bytes | Modified Date = 12/04/2005 19:06:32 | Attr = ]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.5.0_03\bin\NPJPI150_03.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 5.0.30.7 | Size = 69746 bytes | Modified Date = 12/04/2005 19:06:32 | Attr = ]
CmdMapping\\{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
Add to Google Photos Screensa&ver -> %SystemRoot%\system32\GPhotos.scr -> Google Inc. [Ver = 3.0.57.53 | Size = 2306113 bytes | Modified Date = 17/11/2008 12:04:25 | Attr = ]
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s ->
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{07F5BE3C-7AA0-4AE2-B1D7-179C773190A2} -> (Windows Mobile-based Internet Sharing Device) ->
{1D86C26B-ACCF-4647-8E11-D3206B79F89D} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) ->
{2B1B36BA-E162-4F17-85A2-16E3875C0312} -> (Intel(R) PRO/Wireless 2200BG Network Connection) ->
{3D1312DB-B356-4F0E-9C77-6DD016816073} -> (1394 Net Adapter) ->
{5754DD42-D22D-433E-8CFE-B7BFAD15B061} -> () ->
{62555848-763D-43CE-B858-C526D49BB7B0} -> () ->
{E2569D2C-BDFF-4058-AD76-CBFD7BC6DFD1} -> (Windows Mobile-based Device) ->
{FB73F84D-73CE-4749-B74A-84EF73235EE5} -> () ->
< Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ ->
NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] -> %ProgramFiles%\Bonjour\mdnsNSP.dll -> Apple Computer, Inc. [Ver = 1,0,3,1 | Size = 94208 bytes | Modified Date = 28/02/2006 01:42:30 | Attr = ]
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
bwfile-8876480:{9462A756-7B47-47BC-8C80-C34B9B80B32B} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll[BackWeb GA Pluggable Protocol] -> Logitech Inc. [Ver = Version 8.1.1 (Build 50R) | Size = 28711 bytes | Modified Date = 27/02/2007 01:18:37 | Attr = ]
ipp: [HKEY_LOCAL_MACHINE] -> No CLSID value
msdaipp: [HKEY_LOCAL_MACHINE] -> No CLSID value
vnd.ms.radio:{3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\MSDXM.OCX[AsyncPProt Class] -> [Ver = | Size = 842268 bytes | Modified Date = 29/08/2002 10:00:00 | Attr = ]
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}[HKEY_LOCAL_MACHINE] -> http://www.apple.com/qtactivex/qtplugin.cab[QuickTime Object] ->
{3B36B017-7E49-426B-95B0-B5CECD83C2E2}[HKEY_LOCAL_MACHINE] -> http://chkr-web.ifolor.net/ORDERINGGENERAL/LowRes/app_support/ActiveX/IfolorUploader_chkr.cab[IfolorUploader Control] ->
{4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49}[HKEY_LOCAL_MACHINE] -> http://www.klickonline.com/INCLUDE/ImageUploader3.cab[Silverwire Image Uploader 3.0 Control] ->
{CE3409C4-9E26-4F8E-83E4-778498F9E7B4}[HKEY_LOCAL_MACHINE] -> http://static.photobox.co.uk/sg/common/uploader_uni.cab[PB_Uploader Class] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab[Shockwave Flash Object] ->
< Module Usage Keys [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/IfolorUploader.ocx\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/IfolorUploader.ocx\\.Owner -> {3B36B017-7E49-426B-95B0-B5CECD83C2E2} ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/IfolorUploader.ocx\\{3B36B017-7E49-426B-95B0-B5CECD83C2E2} -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader3.ocx\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader3.ocx\\.Owner -> {4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49} ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ImageUploader3.ocx\\{4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49} -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/uploader.ocx\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/uploader.ocx\\.Owner -> {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/uploader.ocx\\{CE3409C4-9E26-4F8E-83E4-778498F9E7B4} -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/uploader_uni.ocx\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/uploader_uni.ocx\\.Owner -> Unknown Owner ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/uploader_uni.ocx\\{CE3409C4-9E26-4F8E-83E4-778498F9E7B4} -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\\.Owner -> Unknown Owner ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/unicows.dll\\{4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49} -> ->


[Registry - Additional Scans - Non-Microsoft Only]
< BotCheck > -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\DefaultLaunchPermission -> [Binary data over 100 bytes] ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineLaunchRestriction -> [Binary data over 100 bytes] ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineAccessRestriction -> [Binary data over 100 bytes] ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\EnableDCOM -> Y ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{A50398B8-9075-4FBF-A7A1-456BF21937AD} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{AD65A69D-3831-40D7-9629-9B0B50A93843} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{0040D221-54A1-11D1-9DE0-006097042D69} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\\System.EnterpriseServices.Thunk.dll -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirstRunDisabled -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\\DisableMonitoring -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\\DisableMonitoring -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ -> ->
*Authentication Packages* -> HK
  • 0

Advertisements


#71
okucu

okucu

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
This time by uploading but it still wasn't enough ....So I am continuing from where it cut - AUTHENTICATION PACKAGES

*Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages ->
msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Bounds -> 0 [binary data] ->
*Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages ->
kerberos -> %SystemRoot%\system32\kerberos.dll -> Microsoft Corporation [Ver = 5.1.2600.2698 (xpsp_sp2_gdr.050614-1522) | Size = 295936 bytes | Modified Date = 15/06/2005 09:49:30 | Attr = ]
msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
schannel -> %SystemRoot%\system32\schannel.dll -> Microsoft Corporation [Ver = 5.1.2600.3126 (xpsp_sp2_gdr.070425-0226) | Size = 144896 bytes | Modified Date = 25/04/2007 06:21:15 | Attr = ]
wdigest -> %SystemRoot%\system32\wdigest.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 49152 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\ImpersonatePrivilegeUpgradeToolHasRun -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\LsaPid -> 768 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\SecureBoot -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\auditbaseobjects -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\crashonauditfail -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\disabledomaincreds -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\everyoneincludesanonymous -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fipsalgorithmpolicy -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\forceguest -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fullprivilegeauditing -> [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\limitblankpassworduse -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\lmcompatibilitylevel -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nodefaultadminowner -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nolmhash -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymous -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymoussam -> 1 ->
*Notification Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Notification Packages ->
scecli -> %SystemRoot%\system32\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 180224 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\enabledcom -> y ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\ -> ->
*ProviderOrder* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\\ProviderOrder ->
Windows NT Access Provider -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\\ProviderPath -> %SystemRoot%\system32\ntmarta.dll [%SystemRoot%\system32\ntmarta.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 118784 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\\Pattern -> BB 1A D7 E8 8D 50 C6 DC 9D D7 ED 6A 66 B9 DE F4 65 34 36 32 65 31 62 63 00 00 00 00 35 94 00 00 18 CA 06 00 99 D0 BF 71 04 CA 06 00 10 00 00 00 00 00 00 00 75 17 9F 0A 0E F5 62 4A 41 C8 44 E4 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\\GrafBlumGroup -> A2 69 3F 74 02 C3 06 20 73 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\\Lookup -> 12 42 7F A8 0F E8 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminclientsec -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminserversec -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\\SkewMatrix -> 0B 97 D5 BE 9A 6F EB 9F 76 21 8C B2 ED 76 EA 3F [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\\SSOURL -> http://www.passport.com ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\\Time -> E2 98 80 49 CF FD C8 01 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Name -> Digest ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Comment -> Digest SSPI Authentication Package ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Capabilities -> 16464 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\RpcId -> 65535 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Version -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\TokenSize -> 65535 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Time -> 00 E0 60 91 1A 7A C4 01 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Type -> 49 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Name -> DPA ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Comment -> DPA Security Package ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Capabilities -> 55 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\RpcId -> 17 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Version -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\TokenSize -> 768 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Time -> 00 E0 60 91 1A 7A C4 01 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Type -> 49 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Name -> MSN ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Comment -> MSN Security Package ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Capabilities -> 55 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\RpcId -> 18 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Version -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\TokenSize -> 768 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Time -> 00 E0 60 91 1A 7A C4 01 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Type -> 49 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\system32\svchost.exe [%SystemRoot%\System32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 11477 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\system32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 331264 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %SystemRoot%\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe -> %ProgramFiles%\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger] -> Logitech Inc. [Ver = 2.52.21.16 | Size = 67128 bytes | Modified Date = 27/02/2007 01:18:37 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\msnmsgr.exe -> %ProgramFiles%\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> Microsoft Corporation [Ver = 8.1.0178.00 | Size = 5674352 bytes | Modified Date = 19/01/2007 02:54:56 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\livecall.exe -> %ProgramFiles%\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> Microsoft Corporation [Ver = 1.1.161.0 | Size = 297752 bytes | Modified Date = 04/01/2007 06:10:02 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\Microsoft ActiveSync\rapimgr.exe -> %ProgramFiles%\Microsoft ActiveSync\rapimgr.exe [C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager] -> Microsoft Corporation [Ver = 4.2.4875.0 | Size = 187176 bytes | Modified Date = 20/06/2006 12:36:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\Microsoft ActiveSync\wcescomm.exe -> %ProgramFiles%\Microsoft ActiveSync\wcescomm.exe [C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager] -> Microsoft Corporation [Ver = 4.2.4875.0 | Size = 1207080 bytes | Modified Date = 20/06/2006 12:36:22 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\Microsoft ActiveSync\WCESMgr.exe -> %ProgramFiles%\Microsoft ActiveSync\WCESMgr.exe [C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application] -> Microsoft Corporation [Ver = 4.2.4875.0 | Size = 1977128 bytes | Modified Date = 20/06/2006 12:36:24 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\26675:TCP -> 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DisableNotifications -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %SystemRoot%\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\iTunes\iTunes.exe -> %ProgramFiles%\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> Apple Computer, Inc. [Ver = 6.0.1.3 | Size = 12116480 bytes | Modified Date = 18/10/2005 04:50:24 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Messenger\msmsgs.exe -> %ProgramFiles%\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> Microsoft Corporation [Ver = 4.7.3001 | Size = 1694208 bytes | Modified Date = 13/10/2004 08:24:37 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\LimeWire\LimeWire.exe -> %ProgramFiles%\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] -> Lime Wire, LLC [Ver = 1, 0, 0, 2 | Size = 147456 bytes | Modified Date = 18/04/2008 11:21:09 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe -> %ProgramFiles%\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger] -> Logitech Inc. [Ver = 2.52.21.16 | Size = 67128 bytes | Modified Date = 27/02/2007 01:18:37 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\msnmsgr.exe -> %ProgramFiles%\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> Microsoft Corporation [Ver = 8.1.0178.00 | Size = 5674352 bytes | Modified Date = 19/01/2007 02:54:56 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\livecall.exe -> %ProgramFiles%\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> Microsoft Corporation [Ver = 1.1.161.0 | Size = 297752 bytes | Modified Date = 04/01/2007 06:10:02 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Microsoft ActiveSync\rapimgr.exe -> %ProgramFiles%\Microsoft ActiveSync\rapimgr.exe [C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager] -> Microsoft Corporation [Ver = 4.2.4875.0 | Size = 187176 bytes | Modified Date = 20/06/2006 12:36:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Microsoft ActiveSync\wcescomm.exe -> %ProgramFiles%\Microsoft ActiveSync\wcescomm.exe [C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager] -> Microsoft Corporation [Ver = 4.2.4875.0 | Size = 1207080 bytes | Modified Date = 20/06/2006 12:36:22 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Microsoft ActiveSync\WCESMgr.exe -> %ProgramFiles%\Microsoft ActiveSync\WCESMgr.exe [C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application] -> Microsoft Corporation [Ver = 4.2.4875.0 | Size = 1977128 bytes | Modified Date = 20/06/2006 12:36:24 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Autodesk\Backburner\monitor.exe -> %ProgramFiles%\Autodesk\Backburner\monitor.exe [C:\Program Files\Autodesk\Backburner\monitor.exe:*:Enabled:backburner 2.3 monitor] -> Autodesk, Inc. [Ver = 2007.1.1.235 | Size = 425984 bytes | Modified Date = 03/07/2007 03:21:38 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Autodesk\Backburner\manager.exe -> %ProgramFiles%\Autodesk\Backburner\manager.exe [C:\Program Files\Autodesk\Backburner\manager.exe:*:Enabled:backburner 2.3 manager] -> Autodesk, Inc. [Ver = 2007.1.1.235 | Size = 507904 bytes | Modified Date = 03/07/2007 03:21:36 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Autodesk\Backburner\server.exe -> %ProgramFiles%\Autodesk\Backburner\server.exe [C:\Program Files\Autodesk\Backburner\server.exe:*:Enabled:backburner 2.3 server] -> Autodesk, Inc. [Ver = 2007.1.1.235 | Size = 110592 bytes | Modified Date = 03/07/2007 03:21:38 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Autodesk\3ds Max 2008\3dsmax.exe -> %ProgramFiles%\Autodesk\3ds Max 2008\3dsmax.exe [C:\Program Files\Autodesk\3ds Max 2008\3dsmax.exe:*:Enabled:Autodesk 3ds Max 2008 32-bit] -> Autodesk, Inc. [Ver = 10.0.0.86 | Size = 6518272 bytes | Modified Date = 24/09/2007 07:24:22 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Bonjour\mDNSResponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> Apple Computer, Inc. [Ver = 1,0,3,1 | Size = 229376 bytes | Modified Date = 28/02/2006 01:42:38 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Skype\Phone\Skype.exe -> %ProgramFiles%\Skype\Phone\Skype.exe [C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype] -> [Ver = | Size = 20058152 bytes | Modified Date = 13/10/2006 08:20:08 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\1900:UDP -> 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\2869:TCP -> 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\26675:TCP -> 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %SystemRoot%\system32\svchost.exe [%systemroot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> %SystemRoot%\system32\wuauserv.dll [C:\WINDOWS\system32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6656 bytes | Modified Date = 04/08/2004 04:00:00 | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> [Binary data over 100 bytes] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 ->
Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\ not found. -> ->
Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\ not found. -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\ProxyEnable -> 0 ->


[Files/Folders - Created Within 90 days]
HaspEmulPE.XP -> %SystemDrive%\HaspEmulPE.XP -> [Folder | Created Date = 14/10/2008 23:29:04 | Attr = ]
Lop SD -> %SystemDrive%\Lop SD -> [Folder | Created Date = 12/11/2008 08:27:36 | Attr = ]
RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Created Date = 24/11/2008 23:38:32 | Attr = HS]
rsit -> %SystemDrive%\rsit -> [Folder | Created Date = 26/10/2008 18:12:42 | Attr = ]
SDFix -> %SystemDrive%\SDFix -> [Folder | Created Date = 12/11/2008 07:47:20 | Attr = ]
STA4 -> %SystemDrive%\STA4 -> [Folder | Created Date = 14/10/2008 23:47:57 | Attr = ]
Sta4v11 -> %SystemDrive%\Sta4v11 -> [Folder | Created Date = 14/10/2008 23:41:10 | Attr = ]
STA4V12 -> %SystemDrive%\STA4V12 -> [Folder | Created Date = 14/10/2008 23:47:57 | Attr = ]
_OTScanIt -> %SystemDrive%\_OTScanIt -> [Folder | Created Date = 24/10/2008 19:55:37 | Attr = ]
gmer.sys -> %SystemRoot%\System32\drivers\gmer.sys -> GMER [Ver = 1, 0, 14, 4401 | Size = 85969 bytes | Created Date = 02/11/2008 17:46:16 | Attr = ]
hardlock.sys -> %SystemRoot%\System32\drivers\hardlock.sys -> [Ver = | Size = 420000 bytes | Created Date = 14/10/2008 23:30:28 | Attr = ]
haspnt.sys -> %SystemRoot%\System32\drivers\haspnt.sys -> Aladdin Knowledge Systems [Ver = 4.65 | Size = 47616 bytes | Created Date = 14/10/2008 23:30:28 | Attr = ]
01AFE3DC.cfg -> %SystemRoot%\System32\01AFE3DC.cfg -> [Ver = | Size = 152 bytes | Created Date = 19/11/2008 20:35:00 | Attr = HS]
16AF66EB.cfg -> %SystemRoot%\System32\16AF66EB.cfg -> [Ver = | Size = 296 bytes | Created Date = 19/11/2008 20:33:50 | Attr = HS]
201476D0.cfg -> %SystemRoot%\System32\201476D0.cfg -> [Ver = | Size = 220 bytes | Created Date = 19/11/2008 20:34:19 | Attr = HS]
29EA67E0.cfg -> %SystemRoot%\System32\29EA67E0.cfg -> [Ver = | Size = 196 bytes | Created Date = 21/11/2008 17:32:15 | Attr = HS]
34A25F04.cfg -> %SystemRoot%\System32\34A25F04.cfg -> [Ver = | Size = 204 bytes | Created Date = 19/11/2008 20:34:42 | Attr = HS]
3B8DA919.cfg -> %SystemRoot%\System32\3B8DA919.cfg -> [Ver = | Size = 180 bytes | Created Date = 19/11/2008 20:34:21 | Attr = HS]
3dsmax.ini -> %SystemRoot%\System32\3dsmax.ini -> [Ver = | Size = 231 bytes | Created Date = 09/10/2008 08:54:30 | Attr = ]
4FBFD5A4.cfg -> %SystemRoot%\System32\4FBFD5A4.cfg -> [Ver = | Size = 212 bytes | Created Date = 19/11/2008 20:34:00 | Attr = HS]
56BC86C7.cfg -> %SystemRoot%\System32\56BC86C7.cfg -> [Ver = | Size = 184 bytes | Created Date = 20/11/2008 21:15:14 | Attr = HS]
5934EA2B.cfg -> %SystemRoot%\System32\5934EA2B.cfg -> [Ver = | Size = 204 bytes | Created Date = 19/11/2008 20:34:15 | Attr = HS]
93DEE065.cfg -> %SystemRoot%\System32\93DEE065.cfg -> [Ver = | Size = 180 bytes | Created Date = 19/11/2008 20:34:32 | Attr = HS]
950D1600.cfg -> %SystemRoot%\System32\950D1600.cfg -> [Ver = | Size = 344 bytes | Created Date = 22/11/2008 11:40:15 | Attr = HS]
A1A6BC2E.cfg -> %SystemRoot%\System32\A1A6BC2E.cfg -> [Ver = | Size = 208 bytes | Created Date = 19/11/2008 20:34:12 | Attr = HS]
A55F538E.cfg -> %SystemRoot%\System32\A55F538E.cfg -> [Ver = | Size = 180 bytes | Created Date = 22/11/2008 11:40:57 | Attr = HS]
AD794E6B.cfg -> %SystemRoot%\System32\AD794E6B.cfg -> [Ver = | Size = 228 bytes | Created Date = 19/11/2008 20:34:09 | Attr = HS]
b160485.sys -> %SystemRoot%\System32\b160485.sys -> [Ver = | Size = 5504 bytes | Created Date = 19/11/2008 20:33:54 | Attr = ]
B8E83D3C.cfg -> %SystemRoot%\System32\B8E83D3C.cfg -> [Ver = | Size = 220 bytes | Created Date = 19/11/2008 20:34:57 | Attr = HS]
CatRoot_bak -> %SystemRoot%\System32\CatRoot_bak -> [Folder | Created Date = 03/09/2008 22:24:51 | Attr = ]
1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
config.hsp -> %SystemRoot%\System32\config.hsp -> [Ver = | Size = 2682 bytes | Created Date = 13/10/2008 22:45:34 | Attr = ]
d435fd4.sys -> %SystemRoot%\System32\d435fd4.sys -> [Ver = | Size = 5504 bytes | Created Date = 19/11/2008 20:34:08 | Attr = ]
d812a079.sys -> %SystemRoot%\System32\d812a079.sys -> [Ver = | Size = 5504 bytes | Created Date = 21/11/2008 14:26:05 | Attr = ]
DFB3DAC5.cfg -> %SystemRoot%\System32\DFB3DAC5.cfg -> [Ver = | Size = 208 bytes | Created Date = 21/11/2008 17:26:43 | Attr = HS]
dopdf6.ctm -> %SystemRoot%\System32\dopdf6.ctm -> [Ver = | Size = 7477 bytes | Created Date = 14/10/2008 23:58:07 | Attr = ]
E1D19FCC.cfg -> %SystemRoot%\System32\E1D19FCC.cfg -> [Ver = | Size = 244 bytes | Created Date = 19/11/2008 20:34:02 | Attr = HS]
f35ee9e.sys -> %SystemRoot%\System32\f35ee9e.sys -> [Ver = | Size = 5504 bytes | Created Date = 19/11/2008 20:33:49 | Attr = ]
F8E07BB2.cfg -> %SystemRoot%\System32\F8E07BB2.cfg -> [Ver = | Size = 220 bytes | Created Date = 19/11/2008 20:34:05 | Attr = HS]
HARDLOCK.SYS -> %SystemRoot%\System32\HARDLOCK.SYS -> Aladdin Knowledge Systems [Ver = 3.25 | Size = 665600 bytes | Created Date = 14/10/2008 23:19:01 | Attr = ]
HARDLOCK.VXD -> %SystemRoot%\System32\HARDLOCK.VXD -> [Ver = | Size = 434252 bytes | Created Date = 14/10/2008 23:19:01 | Attr = ]
HASP95.VXD -> %SystemRoot%\System32\HASP95.VXD -> [Ver = | Size = 45664 bytes | Created Date = 14/10/2008 23:19:02 | Attr = ]
HASP95DL.VXD -> %SystemRoot%\System32\HASP95DL.VXD -> [Ver = | Size = 49750 bytes | Created Date = 14/10/2008 23:19:02 | Attr = ]
haspdos.sys -> %SystemRoot%\System32\haspdos.sys -> [Ver = | Size = 383 bytes | Created Date = 14/10/2008 23:19:05 | Attr = ]
HASPVB32.DLL -> %SystemRoot%\System32\HASPVB32.DLL -> Aladdin Knowledge Systems [Ver = 8.01 | Size = 148992 bytes | Created Date = 14/10/2008 23:19:02 | Attr = ]
haspvdd.dll -> %SystemRoot%\System32\haspvdd.dll -> Aladdin Knowledge Systems. [Ver = 4.65 | Size = 6656 bytes | Created Date = 14/10/2008 23:19:05 | Attr = ]
hlvdd.dll -> %SystemRoot%\System32\hlvdd.dll -> Aladdin Knowledge Systems [Ver = 2.17 | Size = 291328 bytes | Created Date = 14/10/2008 23:19:06 | Attr = ]
i -> %SystemRoot%\System32\i -> [Ver = | Size = 59 bytes | Created Date = 23/11/2008 17:26:30 | Attr = ]
InstallSettings.ini -> %SystemRoot%\System32\InstallSettings.ini -> [Ver = | Size = 43 bytes | Created Date = 09/10/2008 08:54:30 | Attr = ]
IOSUBSYS -> %SystemRoot%\System32\IOSUBSYS -> [Folder | Created Date = 04/10/2008 22:06:39 | Attr = ]
novap5.ctm -> %SystemRoot%\System32\novap5.ctm -> [Ver = | Size = 7477 bytes | Created Date = 15/10/2008 00:00:09 | Attr = ]
STALOCK.DLL -> %SystemRoot%\System32\STALOCK.DLL -> Aladdin Knowledge Systems [Ver = 8.01 | Size = 148992 bytes | Created Date = 13/10/2008 22:53:34 | Attr = ]
tsccvid.dll -> %SystemRoot%\System32\tsccvid.dll -> TechSmith Corporation [Ver = 2.0.1 | Size = 110592 bytes | Created Date = 13/10/2008 22:43:26 | Attr = ]
amcompat.tlb -> %SystemRoot%\amcompat.tlb -> [Ver = | Size = 16832 bytes | Created Date = 13/10/2008 22:45:08 | Attr = ]
ConverterCore.INI -> %SystemRoot%\ConverterCore.INI -> [Ver = | Size = 167 bytes | Created Date = 15/10/2008 00:12:58 | Attr = ]
ERUNT -> %SystemRoot%\ERUNT -> [Folder | Created Date = 12/11/2008 07:53:00 | Attr = ]
fdsv.exe -> %SystemRoot%\fdsv.exe -> Smallfrogs Studio [Ver = 1, 2, 0, 22 | Size = 89504 bytes | Created Date = 18/11/2008 07:55:39 | Attr = ]
gmer.dll -> %SystemRoot%\gmer.dll -> [Ver = 1, 0, 14, 14536 | Size = 884736 bytes | Created Date = 02/11/2008 17:46:16 | Attr = ]
gmer.exe -> %SystemRoot%\gmer.exe -> [Ver = 1, 0, 14, 14536 | Size = 811008 bytes | Created Date = 02/11/2008 17:46:16 | Attr = ]
gmer.ini -> %SystemRoot%\gmer.ini -> [Ver = | Size = 250 bytes | Created Date = 02/11/2008 17:46:17 | Attr = ]
gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [Ver = | Size = 80 bytes | Created Date = 02/11/2008 17:46:16 | Attr = ]
grep.exe -> %SystemRoot%\grep.exe -> [Ver = | Size = 80412 bytes | Created Date = 18/11/2008 07:55:39 | Attr = ]
MKMKrnl.dll -> %SystemRoot%\MKMKrnl.dll -> [Ver = | Size = 10240 bytes | Created Date = 19/11/2008 20:34:52 | Attr = ]
MPKrnl.dll -> %SystemRoot%\MPKrnl.dll -> [Ver = | Size = 20480 bytes | Created Date = 19/11/2008 20:35:02 | Attr = ]
MSVB50CHS.dll -> %SystemRoot%\MSVB50CHS.dll -> Matrix [Ver = 1.00 | Size = 24625 bytes | Created Date = 24/11/2008 23:34:23 | Attr = ]
nscompat.tlb -> %SystemRoot%\nscompat.tlb -> [Ver = | Size = 23392 bytes | Created Date = 13/10/2008 22:45:08 | Attr = ]
pss -> %SystemRoot%\pss -> [Folder | Created Date = 10/10/2008 01:12:03 | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Created Date = 27/10/2008 09:43:13 | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Created Date = 27/10/2008 09:43:13 | Attr = H ]
sed.exe -> %SystemRoot%\sed.exe -> [Ver = | Size = 98816 bytes | Created Date = 18/11/2008 07:55:39 | Attr = ]
SWREG.exe -> %SystemRoot%\SWREG.exe -> SteelWerX [Ver = 3.0.0.0 | Size = 161792 bytes | Created Date = 18/11/2008 07:55:39 | Attr = ]
SWSC.exe -> %SystemRoot%\SWSC.exe -> SteelWerX [Ver = 2.0.0.5 | Size = 136704 bytes | Created Date = 18/11/2008 07:55:39 | Attr = ]
SWXCACLS.exe -> %SystemRoot%\SWXCACLS.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 18/11/2008 07:55:39 | Attr = ]
temp -> %SystemRoot%\temp -> [Folder | Created Date = 24/11/2008 23:37:53 | Attr = ]
VFIND.exe -> %SystemRoot%\VFIND.exe -> [Ver = | Size = 49152 bytes | Created Date = 18/11/2008 07:55:39 | Attr = ]
zip.exe -> %SystemRoot%\zip.exe -> [Ver = | Size = 68096 bytes | Created Date = 18/11/2008 07:55:39 | Attr = ]
Symantec NetDetect.job -> %SystemRoot%\tasks\Symantec NetDetect.job -> [Ver = | Size = 366 bytes | Created Date = 11/10/2008 02:28:20 | Attr = ]
[Files Created - Additional Folder Scans - Non-Microsoft Only]
Autodesk -> %AllUsersProfile%\Application Data\Autodesk -> [Folder | Created Date = 09/10/2008 08:52:03 | Attr = ]
FLEXnet -> %AllUsersProfile%\Application Data\FLEXnet -> [Folder | Created Date = 09/10/2008 10:42:10 | Attr = ]
Piano Med -> %AllUsersProfile%\Application Data\Piano Med -> [Folder | Created Date = 08/09/2008 23:08:45 | Attr = ]
Profiles -> %AllUsersProfile%\Application Data\Profiles -> [Ver = | Size = 0 bytes | Created Date = 08/09/2008 23:05:08 | Attr = ]
Robot -> %AllUsersProfile%\Application Data\Robot -> [Ver = | Size = 0 bytes | Created Date = 08/09/2008 23:05:08 | Attr = ]
Sampler -> %AllUsersProfile%\Application Data\Sampler -> [Ver = | Size = 268 bytes | Created Date = 08/09/2008 23:08:45 | Attr = RH ]
SolidDocuments -> %AllUsersProfile%\Application Data\SolidDocuments -> [Folder | Created Date = 15/10/2008 00:09:45 | Attr = ]
Autodesk -> %AppData%\Autodesk -> [Folder | Created Date = 09/10/2008 10:53:42 | Attr = ]
PDFCreator -> %AppData%\PDFCreator -> [Folder | Created Date = 14/10/2008 23:38:45 | Attr = ]
SolidDocuments -> %AppData%\SolidDocuments -> [Folder | Created Date = 15/10/2008 00:10:07 | Attr = ]
U3 -> %AppData%\U3 -> [Folder | Created Date = 24/09/2008 23:43:05 | Attr = ]
ABBYY -> %UserProfile%\Local Settings\Application Data\ABBYY -> [Folder | Created Date = 16/10/2008 11:26:05 | Attr = ]
Autodesk -> %UserProfile%\Local Settings\Application Data\Autodesk -> [Folder | Created Date = 09/10/2008 08:15:32 | Attr = ]
Zattoo -> %UserProfile%\Local Settings\Application Data\Zattoo -> [Folder | Created Date = 06/09/2008 09:20:31 | Attr = ]
10251.doc -> %UserProfile%\My Documents\10251.doc -> [Ver = | Size = 84480 bytes | Created Date = 01/11/2008 20:15:46 | Attr = ]
10251.pdf -> %UserProfile%\My Documents\10251.pdf -> [Ver = | Size = 96336 bytes | Created Date = 01/11/2008 20:14:45 | Attr = ]
3dsmax -> %UserProfile%\My Documents\3dsmax -> [Folder | Created Date = 09/10/2008 10:53:43 | Attr = ]
Adlm -> %UserProfile%\My Documents\Adlm -> [Folder | Created Date = 10/10/2008 00:19:20 | Attr = R ]
AdobeStockPhotos -> %UserProfile%\My Documents\AdobeStockPhotos -> [Folder | Created Date = 10/10/2008 00:17:53 | Attr = ]
AutoCAD 2008.lnk -> %UserProfile%\My Documents\AutoCAD 2008.lnk -> [Ver = | Size = 1690 bytes | Created Date = 10/10/2008 00:12:45 | Attr = ]
AutoCad Drawings -> %UserProfile%\My Documents\AutoCad Drawings -> [Folder | Created Date = 15/10/2008 05:23:54 | Attr = ]
BALIKTAKVİMİ.xls -> %UserProfile%\My Documents\BALIKTAKVİMİ.xls -> [Ver = | Size = 133120 bytes | Created Date = 07/09/2008 23:15:52 | Attr = ]
BASEL TRAMS -> %UserProfile%\My Documents\BASEL TRAMS -> [Folder | Created Date = 16/10/2008 02:34:23 | Attr = ]
Car Payment.xls -> %UserProfile%\My Documents\Car Payment.xls -> [Ver = | Size = 23040 bytes | Created Date = 07/11/2008 17:51:28 | Attr = ]
CH - Documents (Departing) -> %UserProfile%\My Documents\CH - Documents (Departing) -> [Folder | Created Date = 08/11/2008 11:53:36 | Attr = ]
Coquitlam Bus Lines -> %UserProfile%\My Documents\Coquitlam Bus Lines -> [Folder | Created Date = 06/11/2008 22:24:03 | Attr = ]
gmer.zip -> %UserProfile%\My Documents\gmer.zip -> [Ver = | Size = 747873 bytes | Created Date = 02/11/2008 17:42:15 | Attr = ]
hpsc1088 (1).pdf -> %UserProfile%\My Documents\hpsc1088 (1).pdf -> [Ver = | Size = 1249462 bytes | Created Date = 01/11/2008 17:00:43 | Attr = ]
Ins.application.jpg -> %UserProfile%\My Documents\Ins.application.jpg -> [Ver = | Size = 266921 bytes | Created Date = 03/11/2008 20:20:36 | Attr = ]
Invoice-Melda Okucu - Swiss Moving Service.pdf -> %UserProfile%\My Documents\Invoice-Melda Okucu - Swiss Moving Service.pdf -> [Ver = | Size = 432007 bytes | Created Date = 15/10/2008 07:07:42 | Attr = ]
Lexmark X1190 User Guide.doc -> %UserProfile%\My Documents\Lexmark X1190 User Guide.doc -> [Ver = | Size = 1333248 bytes | Created Date = 15/10/2008 01:28:16 | Attr = ]
LimeWire -> %UserProfile%\My Documents\LimeWire -> [Folder | Created Date = 18/10/2008 07:24:19 | Attr = ]
Melda - CH tax scans -> %UserProfile%\My Documents\Melda - CH tax scans -> [Folder | Created Date = 21/10/2008 07:15:39 | Attr = ]
Money.xls -> %UserProfile%\My Documents\Money.xls -> [Ver = | Size = 24064 bytes | Created Date = 06/11/2008 10:50:50 | Attr = ]
Nikon D80 Settings - Excel sheet.xls -> %UserProfile%\My Documents\Nikon D80 Settings - Excel sheet.xls -> [Ver = | Size = 59904 bytes | Created Date = 06/10/2008 04:21:46 | Attr = ]
Tenancy Application - Windflower 2835.BMP -> %UserProfile%\My Documents\Tenancy Application - Windflower 2835.BMP -> [Ver = | Size = 6603354 bytes | Created Date = 01/11/2008 20:31:43 | Attr = ]
USA & Canada Immigration Docs - OLD -> %UserProfile%\My Documents\USA & Canada Immigration Docs - OLD -> [Folder | Created Date = 08/11/2008 11:51:43 | Attr = ]
VANCOUVER - IST SAATLERI.xls -> %UserProfile%\My Documents\VANCOUVER - IST SAATLERI.xls -> [Ver = | Size = 15872 bytes | Created Date = 19/10/2008 23:17:38 | Attr = ]
Vancouver - Stick -> %UserProfile%\My Documents\Vancouver - Stick -> [Folder | Created Date = 28/10/2008 09:23:02 | Attr = ]
Westwood Plateau House BY COLDWELL BANKER.mht -> %UserProfile%\My Documents\Westwood Plateau House BY COLDWELL BANKER.mht -> [Ver = | Size = 178282 bytes | Created Date = 04/11/2008 08:11:21 | Attr = ]
ComboFix.exe -> %UserProfile%\Desktop\ComboFix.exe -> [Ver = | Size = 3051198 bytes | Created Date = 18/11/2008 07:54:40 | Attr = R ]
drweb-cureit.exe -> %UserProfile%\Desktop\drweb-cureit.exe -> Doctor Web, Ltd. [Ver = 4, 44, 0, 0 | Size = 11947096 bytes | Created Date = 02/11/2008 17:44:04 | Attr = ]
gmer.exe -> %UserProfile%\Desktop\gmer.exe -> [Ver = 1, 0, 14, 14536 | Size = 811008 bytes | Created Date = 02/11/2008 17:42:41 | Attr = ]
HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [Ver = | Size = 1734 bytes | Created Date = 26/10/2008 08:01:18 | Attr = ]
IceSword122en -> %UserProfile%\Desktop\IceSword122en -> [Folder | Created Date = 19/11/2008 07:32:15 | Attr = ]
LopSD.exe -> %UserProfile%\Desktop\LopSD.exe -> [Ver = | Size = 529069 bytes | Created Date = 12/11/2008 08:27:18 | Attr = ]
OTScanIt -> %UserProfile%\Desktop\OTScanIt -> [Folder | Created Date = 20/11/2008 13:02:59 | Attr = ]
qkTest.sys -> %UserProfile%\Desktop\qkTest.sys -> [Ver = | Size = 61440 bytes | Created Date = 19/11/2008 07:59:37 | Attr = ]
r351.pdf -> %UserProfile%\Desktop\r351.pdf -> [Ver = | Size = 1138546 bytes | Created Date = 24/11/2008 06:43:02 | Attr = ]
RSIT.exe -> %UserProfile%\Desktop\RSIT.exe -> [Ver = 3, 2, 12, 1 | Size = 305705 bytes | Created Date = 27/10/2008 17:22:45 | Attr = ]
SDFix -> %UserProfile%\Desktop\SDFix -> [Folder | Created Date = 12/11/2008 07:52:26 | Attr = ]
tt351.pdf -> %UserProfile%\Desktop\tt351.pdf -> [Ver = | Size = 55419 bytes | Created Date = 23/11/2008 19:39:10 | Attr = ]
Vancouver Furniture Expense - new.xls -> %UserProfile%\Desktop\Vancouver Furniture Expense - new.xls -> [Ver = | Size = 26624 bytes | Created Date = 08/11/2008 09:45:39 | Attr = ]
Microsoft Office.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Microsoft Office.lnk -> [Ver = | Size = 1730 bytes | Created Date = 07/11/2008 16:20:21 | Attr = ]
RAMASST.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\RAMASST.lnk -> [Ver = | Size = 1497 bytes | Created Date = 24/10/2008 03:59:32 | Attr = ]
Autodesk Shared -> %CommonProgramFiles%\Autodesk Shared -> [Folder | Created Date = 09/10/2008 08:15:32 | Attr = ]
Macrovision Shared -> %CommonProgramFiles%\Macrovision Shared -> [Folder | Created Date = 09/10/2008 10:17:55 | Attr = ]
Visage Software -> %CommonProgramFiles%\Visage Software -> [Folder | Created Date = 15/10/2008 01:49:42 | Attr = ]
Wise Installation Wizard -> %CommonProgramFiles%\Wise Installation Wizard -> [Folder | Created Date = 15/10/2008 01:49:24 | Attr = ]
AutoCAD 2008 -> %ProgramFiles%\AutoCAD 2008 -> [Folder | Created Date = 10/10/2008 00:10:17 | Attr = ]
Autodesk -> %ProgramFiles%\Autodesk -> [Folder | Created Date = 09/10/2008 08:15:32 | Attr = ]
Bonjour -> %ProgramFiles%\Bonjour -> [Folder | Created Date = 09/10/2008 10:30:51 | Attr = ]
File Scanner Library (Spybot - Search & Destroy) -> %ProgramFiles%\File Scanner Library (Spybot - Search & Destroy) -> [Folder | Created Date = 22/11/2008 09:32:17 | Attr = ]
Misc. Support Library (Spybot - Search & Destroy) -> %ProgramFiles%\Misc. Support Library (Spybot - Search & Destroy) -> [Folder | Created Date = 22/11/2008 09:32:17 | Attr = ]
MSXML 6.0 -> %ProgramFiles%\MSXML 6.0 -> [Folder | Created Date = 11/10/2008 01:25:29 | Attr = ]
Nikon_Capture_NX2_v2.1.0 -> %ProgramFiles%\Nikon_Capture_NX2_v2.1.0 -> [Folder | Created Date = 10/10/2008 00:32:18 | Attr = ]
PDFCreator -> %ProgramFiles%\PDFCreator -> [Folder | Created Date = 14/10/2008 23:38:41 | Attr = ]
SDHelper (Spybot - Search & Destroy) -> %ProgramFiles%\SDHelper (Spybot - Search & Destroy) -> [Folder | Created Date = 25/10/2008 05:09:20 | Attr = ]
SolidDocuments -> %ProgramFiles%\SolidDocuments -> [Folder | Created Date = 15/10/2008 00:10:00 | Attr = ]
TeaTimer (Spybot - Search & Destroy) -> %ProgramFiles%\TeaTimer (Spybot - Search & Destroy) -> [Folder | Created Date = 23/09/2008 23:20:40 | Attr = ]
turbo squid tentacles -> %ProgramFiles%\turbo squid tentacles -> [Folder | Created Date = 09/10/2008 09:00:45 | Attr = ]
Visage -> %ProgramFiles%\Visage -> [Folder | Created Date = 15/10/2008 01:49:42 | Attr = ]

[Files/Folders - Modified Within 90 days]
boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 211 bytes | Modified Date = 07/11/2008 16:20:23 | Attr = HS]
hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [Ver = | Size = 27 bytes | Modified Date = 24/11/2008 23:30:46 | Attr = ]
hosts.new -> %SystemRoot%\System32\drivers\etc\hosts.new -> [Ver = | Size = 2 bytes | Modified Date = 24/11/2008 21:49:14 | Attr = ]
services -> %SystemRoot%\System32\drivers\etc\services -> [Ver = | Size = 7241 bytes | Modified Date = 09/10/2008 08:51:56 | Attr = ]
gmer.sys -> %SystemRoot%\System32\drivers\gmer.sys -> GMER [Ver = 1, 0, 14, 4401 | Size = 85969 bytes | Modified Date = 02/11/2008 17:46:16 | Attr = ]
01AFE3DC.cfg -> %SystemRoot%\System32\01AFE3DC.cfg -> [Ver = | Size = 152 bytes | Modified Date = 19/11/2008 20:35:00 | Attr = HS]
16AF66EB.cfg -> %SystemRoot%\System32\16AF66EB.cfg -> [Ver = | Size = 296 bytes | Modified Date = 19/11/2008 20:33:50 | Attr = HS]
201476D0.cfg -> %SystemRoot%\System32\201476D0.cfg -> [Ver = | Size = 220 bytes | Modified Date = 19/11/2008 20:34:19 | Attr = HS]
29EA67E0.cfg -> %SystemRoot%\System32\29EA67E0.cfg -> [Ver = | Size = 196 bytes | Modified Date = 21/11/2008 17:32:15 | Attr = HS]
34A25F04.cfg -> %SystemRoot%\System32\34A25F04.cfg -> [Ver = | Size = 204 bytes | Modified Date = 19/11/2008 20:34:42 | Attr = HS]
3B8DA919.cfg -> %SystemRoot%\System32\3B8DA919.cfg -> [Ver = | Size = 180 bytes | Modified Date = 19/11/2008 20:34:21 | Attr = HS]
3dsmax.ini -> %SystemRoot%\System32\3dsmax.ini -> [Ver = | Size = 231 bytes | Modified Date = 09/10/2008 08:54:30 | Attr = ]
4FBFD5A4.cfg -> %SystemRoot%\System32\4FBFD5A4.cfg -> [Ver = | Size = 212 bytes | Modified Date = 19/11/2008 20:34:00 | Attr = HS]
56BC86C7.cfg -> %SystemRoot%\System32\56BC86C7.cfg -> [Ver = | Size = 184 bytes | Modified Date = 20/11/2008 21:15:14 | Attr = HS]
5934EA2B.cfg -> %SystemRoot%\System32\5934EA2B.cfg -> [Ver = | Size = 204 bytes | Modified Date = 19/11/2008 20:34:15 | Attr = HS]
93DEE065.cfg -> %SystemRoot%\System32\93DEE065.cfg -> [Ver = | Size = 180 bytes | Modified Date = 19/11/2008 20:34:32 | Attr = HS]
950D1600.cfg -> %SystemRoot%\System32\950D1600.cfg -> [Ver = | Size = 344 bytes | Modified Date = 22/11/2008 11:40:15 | Attr = HS]
A1A6BC2E.cfg -> %SystemRoot%\System32\A1A6BC2E.cfg -> [Ver = | Size = 208 bytes | Modified Date = 19/11/2008 20:34:12 | Attr = HS]
A55F538E.cfg -> %SystemRoot%\System32\A55F538E.cfg -> [Ver = | Size = 180 bytes | Modified Date = 22/11/2008 11:40:57 | Attr = HS]
AD794E6B.cfg -> %SystemRoot%\System32\AD794E6B.cfg -> [Ver = | Size = 228 bytes | Modified Date = 19/11/2008 20:34:09 | Attr = HS]
b160485.sys -> %SystemRoot%\System32\b160485.sys -> [Ver = | Size = 5504 bytes | Modified Date = 19/11/2008 20:33:54 | Attr = ]
B8E83D3C.cfg -> %SystemRoot%\System32\B8E83D3C.cfg -> [Ver = | Size = 220 bytes | Modified Date = 19/11/2008 20:34:57 | Attr = HS]
1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
config.hsp -> %SystemRoot%\System32\config.hsp -> [Ver = | Size = 2682 bytes | Modified Date = 13/10/2008 22:53:21 | Attr = ]
config.nt -> %SystemRoot%\System32\config.nt -> [Ver = | Size = 2686 bytes | Modified Date = 14/10/2008 23:10:54 | Attr = ]
d435fd4.sys -> %SystemRoot%\System32\d435fd4.sys -> [Ver = | Size = 5504 bytes | Modified Date = 19/11/2008 20:34:08 | Attr = ]
d812a079.sys -> %SystemRoot%\System32\d812a079.sys -> [Ver = | Size = 5504 bytes | Modified Date = 21/11/2008 14:26:05 | Attr = ]
DFB3DAC5.cfg -> %SystemRoot%\System32\DFB3DAC5.cfg -> [Ver = | Size = 208 bytes | Modified Date = 21/11/2008 17:26:43 | Attr = HS]
E1D19FCC.cfg -> %SystemRoot%\System32\E1D19FCC.cfg -> [Ver = | Size = 244 bytes | Modified Date = 19/11/2008 20:34:02 | Attr = HS]
f35ee9e.sys -> %SystemRoot%\System32\f35ee9e.sys -> [Ver = | Size = 5504 bytes | Modified Date = 19/11/2008 20:33:49 | Attr = ]
F8E07BB2.cfg -> %SystemRoot%\System32\F8E07BB2.cfg -> [Ver = | Size = 220 bytes | Modified Date = 19/11/2008 20:34:05 | Attr = HS]
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [Ver = | Size = 1585576 bytes | Modified Date = 25/10/2008 08:21:30 | Attr = ]
i -> %SystemRoot%\System32\i -> [Ver = | Size = 59 bytes | Modified Date = 23/11/2008 19:35:34 | Attr = ]
InstallSettings.ini -> %SystemRoot%\System32\InstallSettings.ini -> [Ver = | Size = 43 bytes | Modified Date = 09/10/2008 08:54:30 | Attr = ]
perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [Ver = | Size = 63350 bytes | Modified Date = 02/11/2008 07:11:33 | Attr = ]
perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [Ver = | Size = 402740 bytes | Modified Date = 02/11/2008 07:11:33 | Attr = ]
PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [Ver = | Size = 474132 bytes | Modified Date = 02/11/2008 07:11:33 | Attr = ]
wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [Ver = | Size = 1158 bytes | Modified Date = 23/10/2008 20:19:26 | Attr = ]
amcompat.tlb -> %SystemRoot%\amcompat.tlb -> [Ver = | Size = 16832 bytes | Modified Date = 13/10/2008 22:45:08 | Attr = ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 24/11/2008 23:30:29 | Attr = S]
ConverterCore.INI -> %SystemRoot%\ConverterCore.INI -> [Ver = | Size = 167 bytes | Modified Date = 01/11/2008 20:24:36 | Attr = ]
gmer.dll -> %SystemRoot%\gmer.dll -> [Ver = 1, 0, 14, 14536 | Size = 884736 bytes | Modified Date = 02/11/2008 17:46:16 | Attr = ]
gmer.ini -> %SystemRoot%\gmer.ini -> [Ver = | Size = 250 bytes | Modified Date = 02/11/2008 18:24:26 | Attr = ]
gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [Ver = | Size = 80 bytes | Modified Date = 02/11/2008 17:46:16 | Attr = ]
MKMKrnl.dll -> %SystemRoot%\MKMKrnl.dll -> [Ver = | Size = 10240 bytes | Modified Date = 19/11/2008 20:50:16 | Attr = ]
MPKrnl.dll -> %SystemRoot%\MPKrnl.dll -> [Ver = | Size = 20480 bytes | Modified Date = 19/11/2008 20:50:38 | Attr = ]
MSVB50CHS.dll -> %SystemRoot%\MSVB50CHS.dll -> Matrix [Ver = 1.00 | Size = 24625 bytes | Modified Date = 24/

Attached Files


  • 0

#72
Egwene

Egwene

    Member 2k

  • Visiting Consultant
  • 2,141 posts
Hello,

I found anything new in your last repport.

You can reboot your computer and use combofix when it starts being slow.

You didn't answer me : do you have your windows CD ?

Someone more skilled than me will jump in here to give us a hand.

On my side, i will go on searching about your issue.

Regards,
Egwene.

Edited by Egwene, 25 November 2008 - 04:03 AM.

  • 0

#73
okucu

okucu

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
Hi Ewgene,

I bought this computer from an official dealer 3 yrs ago and it came with a "PRODUCT RECOVERY" CD . I do remember asking the Toshiba dealer why there is no Windows CD like it used to be, and they said notebooks come with recovery CD's and I wouldn't need a Windows XP CD.

On the CD it says " FOR DISTRIBUTION ONLY WITH A NEW TOSHIBA PC " .On the front cover , it says " PRODUCT RECOVERY - This media contains software for backup purposes only ". On the back of the cover , it has a Microsoft sticker which says "Toshiba Microsoft office one note 2003 ". I guess this is the Windows CD in this case , right ??

Ugur
  • 0

#74
Egwene

Egwene

    Member 2k

  • Visiting Consultant
  • 2,141 posts
Hello,

On the CD it says " FOR DISTRIBUTION ONLY WITH A NEW TOSHIBA PC " .On the front cover , it says " PRODUCT RECOVERY - This media contains software for backup purposes only ". On the back of the cover , it has a Microsoft sticker which says "Toshiba Microsoft office one note 2003 ". I guess this is the Windows CD in this case , right ??


Sounds like yes it is, i have this kind of CD too. But let's check :)

Enter your CD room in, reboot your computer, and boot on the CD.

Let the computer working and normally, you should get a screen with : three options ( if my memory doesn't fail :) ) : "Repair", "Install", and "exit". Do you have this screen ? If yes, click on exit and it means it's the good CD :wave:

I assume your already save all your important files ? If not, please do it immadiately.

Regards,
Egwene.
  • 0

#75
okucu

okucu

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
Does this mean the last Combofix and OTScanIt is no help as well ?? Remember I haven't rebooted since running them .
Are we formatting now or is this just another reboot ??..
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP