ComboFix 09-09-23.02 - Sarah 09/24/2009 13:55.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1526.1154 [GMT -5:00]
Running from: E:\Combo-Fix.exe
AV: Webroot AntiVirus with AntiSpyware *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597}
FW: Webroot AntiVirus with AntiSpyware *disabled* {63671000-11A2-46DD-BADD-A084CABCDEAE}
FW: Webroot Desktop Firewall *disabled* {AF0CFAAE-AAB5-450a-8C74-0DEEB429DF50}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-3868997124-911790988-508925577-500
c:\windows\ppp3.dat
c:\windows\ppp4.dat
c:\windows\system32\bennuar.old
c:\windows\system32\dddesot.dll
c:\windows\system32\desot.exe
c:\windows\system32\drivers\gasfkyhkgojwlv.sys
c:\windows\system32\gasfkydkqvfasv.dll
c:\windows\system32\gasfkyjoeuhhde.dat
c:\windows\system32\gasfkyljkccwxd.dat
c:\windows\system32\gasfkylscjmpcn.dll
c:\windows\system32\gasfkytecvjxao.dll
c:\windows\system32\sonhelp.htm
c:\windows\system32\sysnet.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gasfkyopyxypnp
-------\Legacy_gasfkyopyxypnp
((((((((((((((((((((((((( Files Created from 2009-08-24 to 2009-09-24 )))))))))))))))))))))))))))))))
.
2009-09-24 18:44 . 2009-09-24 18:44 -------- d-----w- c:\documents and settings\Administrator\Application Data\Webroot
2009-09-24 14:23 . 2009-09-24 14:23 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-09-24 14:19 . 2009-09-24 14:19 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-09-24 13:57 . 2009-09-24 13:57 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-09-24 02:45 . 2009-09-24 02:47 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-24 02:45 . 2009-09-24 02:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-23 01:36 . 2009-09-23 01:36 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-09-22 18:24 . 2009-09-22 18:24 135 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\fusioncache.dat
2009-09-22 18:24 . 2009-09-22 18:24 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ApplicationHistory
2009-09-22 13:35 . 2008-10-16 19:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-09-22 13:35 . 2008-10-16 19:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-09-22 03:18 . 2009-09-22 03:18 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-09-22 01:05 . 2009-09-22 01:05 -------- d-----w- c:\program files\CASIO
2009-09-22 00:40 . 2001-08-18 03:36 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2009-09-22 00:36 . 2009-09-22 00:36 -------- d-----w- c:\program files\Common Files\xing shared
2009-09-22 00:36 . 2009-09-22 00:36 -------- d-----w- c:\program files\real
2009-09-22 00:28 . 2009-09-22 00:28 -------- d-----w- c:\program files\GIMP-2.0
2009-09-22 00:22 . 2009-09-22 00:47 -------- d-----w- c:\program files\Matroska Pack
2009-09-22 00:21 . 2009-09-22 00:21 -------- d-----w- c:\documents and settings\Sarah\Application Data\vlc
2009-09-22 00:20 . 2009-09-22 00:20 -------- d-----w- c:\program files\VideoLAN
2009-09-21 23:48 . 2009-09-23 12:51 -------- d-----w- c:\documents and settings\Sarah\Tracing
2009-09-21 23:47 . 2009-09-21 23:47 -------- d-----w- c:\program files\Microsoft
2009-09-21 23:47 . 2009-09-21 23:47 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-21 23:46 . 2009-09-21 23:47 -------- d-----w- c:\program files\Windows Live
2009-09-21 23:43 . 2009-09-21 23:43 -------- d-----w- c:\program files\Common Files\Windows Live
2009-09-21 23:42 . 2009-09-21 23:42 -------- d-----w- c:\documents and settings\Sarah\Application Data\HP
2009-09-21 23:41 . 2009-09-21 23:41 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-09-21 23:39 . 2009-09-21 23:41 -------- d-----w- c:\program files\Common Files\HP
2009-09-21 23:37 . 2009-09-21 23:38 -------- d-----w- c:\program files\Hewlett-Packard
2009-09-21 23:36 . 2009-09-21 23:36 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-09-21 23:32 . 2009-09-21 23:42 117157 ----a-w- c:\windows\hpoins11.dat
2009-09-21 23:28 . 2006-05-05 23:17 11634 ----a-w- c:\windows\hpomdl11.dat
2009-09-21 22:26 . 2009-09-21 22:26 -------- d-----w- c:\program files\MSECache
2009-09-21 22:21 . 2006-04-10 19:03 38400 ----a-w- c:\windows\system32\hpz3l054.dll
2009-09-21 22:21 . 2008-04-13 18:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2009-09-21 22:21 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-09-21 22:20 . 2007-08-09 07:27 73728 ----a-w- c:\windows\system32\HPZipm12.exe
2009-09-21 22:20 . 2006-03-04 02:02 204800 ----a-w- c:\windows\system32\HPZipr12.dll
2009-09-21 22:20 . 2006-03-04 02:02 94208 ----a-w- c:\windows\system32\HPZipt12.dll
2009-09-21 22:20 . 2006-03-04 02:02 57344 ----a-w- c:\windows\system32\HPZisn12.dll
2009-09-21 22:20 . 2006-03-04 02:03 282680 ----a-w- c:\windows\system32\HPZidr12.dll
2009-09-21 22:20 . 2006-03-04 02:03 65536 ----a-w- c:\windows\system32\HPZinw12.exe
2009-09-21 22:20 . 2009-09-21 23:40 -------- d-----w- c:\program files\HP
2009-09-21 22:15 . 2006-04-13 00:04 49664 ----a-w- c:\windows\system32\drivers\HPZid412.sys
2009-09-21 22:14 . 2006-04-13 00:04 21568 ----a-w- c:\windows\system32\drivers\HPZius12.sys
2009-09-21 22:14 . 2006-04-13 00:04 16496 ----a-w- c:\windows\system32\drivers\HPZipr12.sys
2009-09-21 22:13 . 2006-04-13 00:02 827392 ----a-w- c:\windows\system32\hpotiop2.dll
2009-09-21 22:13 . 2006-04-13 00:02 659456 ----a-w- c:\windows\system32\hpowiax2.dll
2009-09-21 22:13 . 2006-04-13 00:04 282624 ----a-w- c:\windows\system32\HPZc3212.dll
2009-09-21 22:13 . 2006-04-13 00:02 254026 ----a-w- c:\windows\system32\hpovst09.dll
2009-09-21 22:13 . 2005-07-19 01:38 98304 ----a-w- c:\windows\system32\hpzjsn01.dll
2009-09-21 22:13 . 2006-01-04 08:12 77824 ----a-w- c:\windows\system32\HPZIDS01.dll
2009-09-21 21:55 . 2008-04-13 18:47 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2009-09-21 21:55 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-09-21 21:49 . 2008-04-13 18:45 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-09-21 21:49 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-09-21 21:49 . 2009-09-21 21:49 -------- d-----w- c:\documents and settings\Sarah\Application Data\FUJIFILM
2009-09-21 18:13 . 2009-09-21 18:13 -------- d-----w- c:\program files\PIXELA
2009-09-21 18:12 . 2004-02-05 06:29 380928 ----a-w- c:\windows\system32\FE05F3D7.dll
2009-09-21 18:12 . 2003-12-10 00:45 401408 ----a-w- c:\windows\system32\FE05F3D6.dll
2009-09-21 18:12 . 2003-08-26 15:54 401408 ----a-w- c:\windows\system32\FE05EFED.dll
2009-09-21 18:12 . 2003-06-25 22:24 299008 ----a-w- c:\windows\system32\FE05F051.dll
2009-09-21 18:12 . 2003-06-10 05:37 299008 ----a-w- c:\windows\system32\FE05F3D5.dll
2009-09-21 18:12 . 2003-06-03 03:50 299008 ----a-w- c:\windows\system32\FE05DA0D.dll
2009-09-21 18:12 . 2002-04-07 09:26 106496 ----a-w- c:\windows\system32\FPXS2Pro.dll
2009-09-21 18:12 . 2003-09-06 12:57 159744 ----a-w- c:\windows\system32\FFRAFLIB.DLL
2009-09-21 18:12 . 2003-09-03 12:45 274432 ----a-w- c:\windows\system32\FFTIFF16.dll
2009-09-21 18:11 . 2009-09-21 18:12 -------- d-----w- c:\program files\FinePixViewer
2009-09-21 18:11 . 2001-11-25 11:11 81924 ------w- c:\windows\system32\drivers\VC4CB104.SYS
2009-09-21 18:11 . 2009-09-21 18:11 -------- d-----w- c:\program files\REGSHAVE
2009-09-21 18:11 . 2002-06-25 15:06 45056 ------w- c:\windows\system32\FINFCOPY.dll
2009-09-21 18:11 . 2002-02-27 11:27 65536 ------w- c:\windows\system32\FINFCHECK.dll
2009-09-21 18:11 . 2002-02-13 10:00 45056 ------w- c:\windows\system32\FCLKBTN.DLL
2009-09-21 18:11 . 2002-02-05 16:33 69632 ------w- c:\windows\system32\FREGSHEX.DLL
2009-09-21 18:01 . 2009-09-22 00:22 -------- d-----w- c:\documents and settings\Sarah\Application Data\Apple Computer
2009-09-21 18:01 . 2009-05-18 19:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-21 18:01 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-09-21 18:00 . 2009-09-21 18:00 -------- d-----w- c:\program files\iPod
2009-09-21 18:00 . 2009-09-21 18:01 -------- d-----w- c:\program files\iTunes
2009-09-21 18:00 . 2009-09-21 18:01 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-21 17:59 . 2009-09-21 17:59 -------- d-----w- c:\program files\Bonjour
2009-09-21 17:58 . 2009-09-21 17:59 -------- d-----w- c:\program files\QuickTime
2009-09-21 17:58 . 2009-09-21 18:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-09-21 17:57 . 2009-09-21 17:57 -------- d-----w- c:\documents and settings\Sarah\Local Settings\Application Data\Apple
2009-09-21 17:57 . 2009-09-21 17:57 -------- d-----w- c:\program files\Apple Software Update
2009-09-21 15:12 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-09-21 15:12 . 2009-07-03 17:09 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-09-21 15:12 . 2009-07-03 17:09 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-09-21 15:12 . 2009-07-19 23:48 11067392 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-09-21 15:12 . 2009-07-03 17:09 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-09-21 15:12 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-09-21 15:10 . 2009-09-21 15:11 -------- dc-h--w- c:\windows\ie8
2009-09-21 15:02 . 2009-09-21 15:02 -------- d-----w- c:\program files\MSXML 4.0
2009-09-21 13:49 . 2009-09-21 13:49 -------- d-----w- c:\windows\system32\scripting
2009-09-21 13:49 . 2009-09-21 13:49 -------- d-----w- c:\windows\l2schemas
2009-09-21 13:48 . 2009-09-21 13:48 -------- d-----w- c:\windows\system32\en
2009-09-21 13:48 . 2009-09-21 13:48 -------- d-----w- c:\windows\system32\bits
2009-09-21 13:43 . 2009-09-21 13:43 -------- d-----w- c:\windows\ServicePackFiles
2009-09-21 13:21 . 2009-09-21 13:22 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-09-21 13:21 . 2009-09-21 13:21 -------- d-----w- c:\program files\NOS
2009-09-21 13:17 . 2008-04-14 00:12 276992 ------w- c:\windows\system32\wmphoto.dll
2009-09-21 13:17 . 2008-04-14 00:12 69120 ------w- c:\windows\system32\wlanapi.dll
2009-09-21 13:15 . 2008-04-14 00:12 33792 ------w- c:\windows\system32\mmcperf.exe
2009-09-21 13:14 . 2008-04-14 00:11 3775 ------w- c:\windows\system32\drivers\adv11nt5.dll
2009-09-21 13:14 . 2008-04-14 00:11 3711 ------w- c:\windows\system32\drivers\adv09nt5.dll
2009-09-21 13:14 . 2008-04-14 00:11 3647 ------w- c:\windows\system32\drivers\adv07nt5.dll
2009-09-21 13:14 . 2008-04-14 00:11 3615 ------w- c:\windows\system32\drivers\adv05nt5.dll
2009-09-21 13:14 . 2008-04-14 00:11 3135 ------w- c:\windows\system32\drivers\adv08nt5.dll
2009-09-21 13:14 . 2008-04-13 18:36 44928 ------w- c:\windows\system32\drivers\agpcpq.sys
2009-09-21 13:14 . 2008-04-13 18:36 42368 ------w- c:\windows\system32\drivers\agp440.sys
2009-09-21 13:14 . 2007-04-02 18:26 19456 -c--a-w- c:\windows\system32\dllcache\agt040d.dll
2009-09-21 13:14 . 2007-04-02 18:25 19456 -c--a-w- c:\windows\system32\dllcache\agt0404.dll
2009-09-21 13:14 . 2007-04-02 18:25 19456 -c--a-w- c:\windows\system32\dllcache\agt0401.dll
2009-09-21 13:14 . 2008-04-14 00:11 4255 ------w- c:\windows\system32\drivers\adv01nt5.dll
2009-09-21 13:14 . 2008-04-14 00:11 3967 ------w- c:\windows\system32\drivers\adv02nt5.dll
2009-09-21 13:14 . 2008-04-14 00:11 136192 ------w- c:\windows\system32\aaclient.dll
2009-09-21 12:57 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-09-21 12:57 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2009-09-21 12:57 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-09-21 12:55 . 2008-10-03 10:02 247326 -c----w- c:\windows\system32\dllcache\strmdll.dll
2009-09-21 12:55 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-09-21 12:55 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-09-21 12:55 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-09-21 12:55 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-09-21 07:11 . 2009-09-21 07:11 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-23 03:54 . 2006-02-16 10:39 -------- d-----w- c:\program files\Microsoft Works
2009-09-22 18:33 . 2006-02-15 16:25 -------- d-----w- c:\program files\TOSHIBA
2009-09-22 18:27 . 2006-02-16 09:42 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-09-22 02:20 . 2006-02-16 16:59 62224 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-22 00:53 . 2006-02-15 16:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-22 00:47 . 2006-02-16 09:55 -------- d-----w- c:\program files\Pure Networks
2009-09-22 00:47 . 2006-02-16 09:55 -------- d-----w- c:\program files\Common Files\AOL
2009-09-22 00:43 . 2006-02-25 04:32 -------- d-----w- c:\program files\Toshiba Games
2009-09-22 00:38 . 2006-02-16 09:55 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-09-22 00:37 . 2006-02-16 09:56 -------- d-----w- c:\program files\Common Files\Real
2009-09-22 00:34 . 2009-09-21 07:12 -------- d-----w- c:\documents and settings\Sarah\Application Data\AOL
2009-09-22 00:34 . 2009-09-21 07:11 -------- d-----w- c:\documents and settings\Default User\Application Data\AOL
2009-09-22 00:34 . 2006-02-16 09:59 -------- d-----w- c:\documents and settings\Administrator\Application Data\AOL
2009-09-21 18:09 . 2006-02-16 10:41 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-09-21 18:00 . 2009-09-21 17:56 -------- d-----w- c:\program files\Common Files\Apple
2009-09-21 17:56 . 2009-09-21 17:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-09-21 07:11 . 2009-09-21 07:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel
2009-09-21 07:11 . 2006-02-15 16:18 -------- d-----w- c:\program files\Intel
2009-09-21 07:11 . 2009-09-21 07:12 -------- d-----w- c:\documents and settings\Sarah\Application Data\Intel
2009-09-21 07:11 . 2009-09-21 07:11 -------- d-----w- c:\documents and settings\Default User\Application Data\Intel
2009-09-21 07:11 . 2009-09-21 07:11 -------- d-----w- c:\documents and settings\Administrator\Application Data\Intel
2009-09-21 06:59 . 2006-02-16 09:25 -------- d-----w- c:\program files\InterVideo
2009-09-21 04:25 . 2009-09-21 07:12 128 ----a-w- c:\documents and settings\Sarah\Local Settings\Application Data\fusioncache.dat
2009-08-05 09:01 . 2006-02-15 14:03 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:37 . 2006-02-15 14:04 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2006-02-15 14:02 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-26 21:44 . 2009-07-26 21:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-17 19:01 . 2006-02-15 14:02 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 15:08 . 2006-02-15 14:05 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2006-02-15 14:04 915456 ----a-w- c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2009-05-13 22:34 238968 ----a-w- c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingD5611"="del" [X]
"SpybotDeletingD2667"="del" [X]
"SpybotDeletingD5306"="del" [X]
"SpybotDeletingD8699"="del" [X]
"SpybotDeletingD8588"="del" [X]
"SpybotDeletingD4299"="del" [X]
"SpybotDeletingD8173"="del" [X]
"SpybotDeletingD3352"="del" [X]
"SpybotDeletingD2326"="del" [X]
"SpybotDeletingD9371"="del" [X]
"SpybotDeletingD3452"="del" [X]
"SpybotDeletingD9225"="del" [X]
"SpybotDeletingD418"="del" [X]
"SpybotDeletingD6012"="del" [X]
"SpybotDeletingD3297"="del" [X]
"SpybotDeletingD1863"="del" [X]
"SpybotDeletingD5358"="del" [X]
"SpybotDeletingD7801"="del" [X]
"SpybotDeletingD5770"="del" [X]
"SpybotDeletingD3198"="del" [X]
"SpybotDeletingD2861"="del" [X]
"SpybotDeletingD5678"="del" [X]
"SpybotDeletingD6176"="del" [X]
"SpybotDeletingD703"="del" [X]
"SpybotDeletingD8828"="del" [X]
"SpybotDeletingD9451"="del" [X]
"SpybotDeletingD298"="del" [X]
"SpybotDeletingD8484"="del" [X]
"SpybotDeletingD1435"="del" [X]
"SpybotDeletingD4328"="del" [X]
"SpybotDeletingD203"="del" [X]
"SpybotDeletingD9333"="del" [X]
"SpybotDeletingD3751"="del" [X]
"SpybotDeletingD1294"="del" [X]
"SpybotDeletingD7162"="del" [X]
"SpybotDeletingD19"="del" [X]
"SpybotDeletingD7853"="del" [X]
"SpybotDeletingD1096"="del" [X]
"SpybotDeletingD1371"="del" [X]
"SpybotDeletingD553"="del" [X]
"SpybotDeletingD2204"="del" [X]
"SpybotDeletingD265"="del" [X]
"SpybotDeletingD5816"="del" [X]
"SpybotDeletingD4260"="del" [X]
"SpybotDeletingD6729"="del" [X]
"SpybotDeletingD410"="del" [X]
"SpybotDeletingD8206"="del" [X]
"SpybotDeletingD1315"="del" [X]
"SpybotDeletingD356"="del" [X]
"SpybotDeletingD4314"="del" [X]
"SpybotDeletingD2917"="del" [X]
"SpybotDeletingD1133"="del" [X]
"SpybotDeletingD6207"="del" [X]
"SpybotDeletingD9876"="del" [X]
"SpybotDeletingD9942"="del" [X]
"SpybotDeletingD2118"="del" [X]
"SpybotDeletingD564"="del" [X]
"SpybotDeletingD6263"="del" [X]
"SpybotDeletingD6115"="del" [X]
"SpybotDeletingD3904"="del" [X]
"SpybotDeletingD7417"="del" [X]
"SpybotDeletingD8084"="del" [X]
"SpybotDeletingD2457"="del" [X]
"SpybotDeletingD9450"="del" [X]
"SpybotDeletingD9343"="del" [X]
"SpybotDeletingD8646"="del" [X]
"SpybotDeletingD8929"="del" [X]
"SpybotDeletingD2075"="del" [X]
"SpybotDeletingD8331"="del" [X]
"SpybotDeletingD895"="del" [X]
"SpybotDeletingD9320"="del" [X]
"SpybotDeletingD7299"="del" [X]
"SpybotDeletingD4801"="del" [X]
"SpybotDeletingD9489"="del" [X]
"SpybotDeletingD8492"="del" [X]
"SpybotDeletingD610"="del" [X]
"SpybotDeletingB6422"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB5647"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB8389"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB9197"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB1206"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB9437"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB7692"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB3203"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB2531"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB868"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB6865"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB5803"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB3021"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB9511"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB6192"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB8704"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB5830"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB6218"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB4099"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB592"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB5233"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB2539"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB3030"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB9897"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB3456"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB6683"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB8443"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB4886"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB4373"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB193"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB273"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB5023"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB8910"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB2560"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB6352"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB9864"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB6354"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB5342"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB5367"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB4528"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB3220"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB9181"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB2198"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB8694"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB7846"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB3656"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB490"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB5590"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB1711"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB4777"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB6351"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB5866"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB7731"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB3128"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB5242"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB2470"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB6019"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB9109"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB7043"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB5229"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB247"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB9365"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB984"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB8149"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB7021"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB477"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB2398"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB1729"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB292"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB352"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB8020"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB9726"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB9094"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB9088"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB3423"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingB2465"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-12-16 82009]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 761945]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2004-08-18 184320]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 73728]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-27 122880]
"dla"="c:\windows\system32\dla\DLACTRLW.exe" [2005-10-06 122940]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-18 151552]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"Webroot Desktop Firewall"="c:\program files\Webroot\Webroot Desktop Firewall\WDF.exe" [2008-07-31 2401672]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-22 198160]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2009-05-13 6345840]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-03-11 73728]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-10-15 88203]
"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-06-01 282624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingC2229"="del" [X]
"SpybotDeletingC1984"="del" [X]
"SpybotDeletingC9948"="del" [X]
"SpybotDeletingC9369"="del" [X]
"SpybotDeletingC8085"="del" [X]
"SpybotDeletingC5760"="del" [X]
"SpybotDeletingC4716"="del" [X]
"SpybotDeletingC2661"="del" [X]
"SpybotDeletingC9260"="del" [X]
"SpybotDeletingC6241"="del" [X]
"SpybotDeletingC7790"="del" [X]
"SpybotDeletingC3435"="del" [X]
"SpybotDeletingC5006"="del" [X]
"SpybotDeletingC5646"="del" [X]
"SpybotDeletingC4696"="del" [X]
"SpybotDeletingC5479"="del" [X]
"SpybotDeletingC6142"="del" [X]
"SpybotDeletingC7"="del" [X]
"SpybotDeletingC4048"="del" [X]
"SpybotDeletingC7052"="del" [X]
"SpybotDeletingC3553"="del" [X]
"SpybotDeletingC8503"="del" [X]
"SpybotDeletingC8210"="del" [X]
"SpybotDeletingC2762"="del" [X]
"SpybotDeletingC9976"="del" [X]
"SpybotDeletingC2464"="del" [X]
"SpybotDeletingC7246"="del" [X]
"SpybotDeletingC1933"="del" [X]
"SpybotDeletingC88"="del" [X]
"SpybotDeletingC6910"="del" [X]
"SpybotDeletingC3412"="del" [X]
"SpybotDeletingC143"="del" [X]
"SpybotDeletingC8311"="del" [X]
"SpybotDeletingC371"="del" [X]
"SpybotDeletingC7760"="del" [X]
"SpybotDeletingC6971"="del" [X]
"SpybotDeletingC1745"="del" [X]
"SpybotDeletingC2667"="del" [X]
"SpybotDeletingC229"="del" [X]
"SpybotDeletingC6193"="del" [X]
"SpybotDeletingC5752"="del" [X]
"SpybotDeletingC9507"="del" [X]
"SpybotDeletingC5820"="del" [X]
"SpybotDeletingC8654"="del" [X]
"SpybotDeletingC4681"="del" [X]
"SpybotDeletingC9010"="del" [X]
"SpybotDeletingC7476"="del" [X]
"SpybotDeletingC7878"="del" [X]
"SpybotDeletingC656"="del" [X]
"SpybotDeletingC2724"="del" [X]
"SpybotDeletingC7271"="del" [X]
"SpybotDeletingC4407"="del" [X]
"SpybotDeletingC8897"="del" [X]
"SpybotDeletingC2478"="del" [X]
"SpybotDeletingC3120"="del" [X]
"SpybotDeletingC545"="del" [X]
"SpybotDeletingC5137"="del" [X]
"SpybotDeletingC2729"="del" [X]
"SpybotDeletingC9074"="del" [X]
"SpybotDeletingC5254"="del" [X]
"SpybotDeletingC8419"="del" [X]
"SpybotDeletingC3856"="del" [X]
"SpybotDeletingC7093"="del" [X]
"SpybotDeletingC8207"="del" [X]
"SpybotDeletingC7785"="del" [X]
"SpybotDeletingC8384"="del" [X]
"SpybotDeletingC1069"="del" [X]
"GrpConv"="grpconv -o" [X]
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2009-01-26 5365592]
"SpybotDeletingA1457"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA1597"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA8470"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA8280"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA6833"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA2619"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA6480"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA4670"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA5230"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA4265"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA2254"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA1099"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA1277"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA7259"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA7349"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA2035"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA2997"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA7236"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA862"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA8458"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA8673"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA4594"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA8752"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA513"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA2618"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA9361"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA5778"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA5072"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA4532"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA5751"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA6100"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA1841"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA6262"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA8289"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA1368"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA6813"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA2216"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA8008"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA365"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA2995"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA5539"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA7842"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA3919"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA4858"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA5582"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA9292"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA5690"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA6599"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA2205"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA9016"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA9284"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA8847"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA9544"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA4161"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA4819"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA3770"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA2007"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA9372"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA2934"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA8380"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA5417"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA7932"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA4491"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA5158"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA8463"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA6964"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
"SpybotDeletingA2484"="command.com" - c:\windows\system32\command.com [2004-08-10 50620]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-2-15 155648]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:DCOM(135)
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [4/21/2009 8:27 PM 29808]
R1 pwipf6;pwipf6;c:\windows\system32\drivers\pwipf6.sys [7/31/2008 5:19 PM 103304]
R2 WDFNet;Webroot Desktop Firewall network service;c:\program files\Webroot\Webroot Desktop Firewall\wdfsvc.exe [7/31/2008 5:19 PM 353672]
R2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [9/20/2009 11:26 PM 1205760]
S2 AntipPolice_;AntiPol;c:\windows\svchast.exe --> c:\windows\svchast.exe [?]
S3 getPlusHelper;getPlus(R) Helper;c:\windows\System32\svchost.exe -k getPlusHelper [2/15/2006 9:04 AM 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-09-21 c:\windows\Tasks\Registration reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2006-02-15 00:12]
2009-09-21 c:\windows\Tasks\WebReg psc C3100 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2006-02-19 21:45]
2009-09-22 c:\windows\Tasks\wrSpySweeper_LDE481C42A9454328AF58D83B911233AB.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-09-21 22:40]
2009-09-22 c:\windows\Tasks\wrSpySweeper_LDE481C42A9454328AF58D83B911233AB.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-09-21 22:40]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext =
hxxp://www.toshibadirect.com/dpdstartuInternet Settings,ProxyOverride = *.local
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\Sarah\Application Data\Mozilla\Firefox\Profiles\hzjjhdyu.default\
FF - prefs.js: browser.startup.homepage -
hxxp://go.microsoft.com/fwlink/?LinkId=69157FF - plugin: c:\documents and settings\Sarah\Application Data\Mozilla\Firefox\Profiles\hzjjhdyu.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJPI150_04.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-PadTouch - c:\program files\TOSHIBA\Touch and Launch\PadExe.exe
HKLM-RunOnce-
- (no file)
AddRemove-HijackThis - E:\HijackThis.exe
AddRemove-Matroska Pack - c:\program files\Matroska Pack\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-24 13:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(920)
c:\windows\system32\wdfproc.dll
- - - - - - - > 'lsass.exe'(976)
c:\windows\system32\wdfproc.dll
.
Completion time: 2009-09-24 14:00
ComboFix-quarantined-files.txt 2009-09-24 19:00
Pre-Run: 74,203,693,056 bytes free
Post-Run: 75,362,426,880 bytes free
632 --- E O F --- 2009-09-24 03:46