OTMoveIt3 log:
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\ProgramData\geponupu moved successfully.
C:\ProgramData\zaduzuhe moved successfully.
C:\ProgramData\ginimayu moved successfully.
C:\ProgramData\wujosoje moved successfully.
C:\ProgramData\wuhaweta moved successfully.
C:\ProgramData\fibunulo moved successfully.
========== COMMANDS ==========
File delete failed. C:\Users\Nikki\AppData\Local\Temp\Low\~DF32B2.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Nikki\AppData\Local\Temp\~DFC36E.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Nikki\AppData\Local\Temp\~DFC377.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Windows Temp folder emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05032009_100130
Files moved on Reboot...
C:\Users\Nikki\AppData\Local\Temp\Low\~DF32B2.tmp moved successfully.
C:\Users\Nikki\AppData\Local\Temp\~DFC36E.tmp moved successfully.
File C:\Users\Nikki\AppData\Local\Temp\~DFC377.tmp not found!
RSIT log:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Nikki at 2009-05-03 10:13:14
Microsoft® Windows Vista™ Home Premium
System drive C: has 26 GB (23%) free of 113 GB
Total RAM: 1014 MB (31% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:13:23 AM, on 5/3/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16830)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ltmoh\ltmoh.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Toshiba\IVP\ISM\pinger.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Windows\system32\wuauclt.exe
C:\WINDOWS\notepad.exe
C:\Users\Nikki\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Nikki.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://att.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.toshibadirect.com/dpdstartR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) -
http://upload.facebook.com/controls/2008.1...toUploader5.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://www1.snapfish.com/SnapfishActivia.cabO16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace.com/upload/MySpaceUploader1006.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx.com/player/DivXBrowserPlugin.cabO16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) -
http://h20264.www2.hp.com/ediags/dd/instal...osticsVista.cabO16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} (RockYou Image Uploader Control) -
http://rockyou.com/RockYouImageUploader.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/flas...ent/swflash.cabO16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) -
http://imikimi.com/download/imikimi_plugin_0.5.1.cabO23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 9643 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\RegCure Program Check.job
C:\Windows\tasks\RegCure.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{089FD14D-132B-48FC-8861-0048AE113215}]
C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{145B29F4-A56B-4b90-BBAC-45784EBEBBB7}]
StumbleUpon Launcher - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll [2007-10-24 987832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0\bin\ssv.dll [2007-01-05 501384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-04-30 668656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0BF43445-2F28-4351-9252-17FE6E806AA0} - McAfee SiteAdvisor - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]
{D0943516-5076-4020-A3B5-AEFAF26AB263} - Veoh Browser Plug-in - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [2007-05-03 358528]
{5093EB4C-3E93-40AB-9266-B607BA87BDC8} - StumbleUpon Toolbar - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll [2007-10-24 987832]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-10-27 815104]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2007-06-12 1006264]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2006-11-09 3784704]
"LtMoh"=C:\Program Files\ltmoh\Ltmoh.exe [2005-12-16 188416]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2006-12-20 411768]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2006-12-07 55416]
"SmoothView"=C:\Program Files\Toshiba\SmoothView\SmoothView.exe [2006-12-11 448632]
"00TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2006-12-15 530552]
"NDSTray.exe"=NDSTray.exe []
"HWSetup"=C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [2006-11-01 413696]
"SVPWUTIL"=C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe [2006-01-18 421888]
"KeNotify"=C:\Program Files\TOSHIBA\Utilities\KeNotify.exe [2006-11-06 34352]
"PINGER"=C:\TOSHIBA\IVP\ISM\pinger.exe [2006-07-20 151552]
"SiteAdvisor"=C:\Program Files\SiteAdvisor\6253\SiteAdv.exe [2006-10-18 35928]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-11 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-02-11 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-11 133656]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-01-05 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-04-02 342312]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"=C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [2006-11-10 417792]
""= []
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2006-11-02 125440]
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [2004-11-22 307200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\TOSHIBA\ivp\NetInt\Netint.exe"="C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine"
"C:\TOSHIBA\Ivp\ISM\pinger.exe"="C:\TOSHIBA\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 3 months======
2009-05-03 10:01:30 ----D---- C:\_OTMoveIt
2009-05-02 09:24:16 ----D---- C:\rsit
2009-05-01 20:17:04 ----D---- C:\Users\Nikki\AppData\Roaming\Malwarebytes
2009-05-01 20:16:57 ----D---- C:\ProgramData\Malwarebytes
2009-05-01 20:16:57 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-05-01 20:12:45 ----D---- C:\Windows\ERDNT
2009-05-01 20:12:22 ----D---- C:\Program Files\ERUNT
2009-05-01 08:18:29 ----D---- C:\Program Files\Trend Micro
2009-05-01 07:58:33 ----D---- C:\Program Files\RegCure
2009-04-27 08:35:18 ----D---- C:\Users\Nikki\AppData\Roaming\AVG8
2009-04-19 15:36:18 ----A---- C:\Windows\system32\GEARAspi.dll
2009-04-19 15:35:52 ----D---- C:\Program Files\iPod
2009-04-19 15:35:43 ----D---- C:\ProgramData\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-19 15:32:06 ----D---- C:\Program Files\QuickTime
2009-04-15 16:31:27 ----A---- C:\Windows\system32\winhttp.dll
2009-04-15 16:31:20 ----A---- C:\Windows\system32\xolehlp.dll
2009-04-15 16:31:20 ----A---- C:\Windows\system32\msdtcprx.dll
2009-04-15 16:30:59 ----A---- C:\Windows\system32\rpcss.dll
2009-04-15 16:30:55 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-04-15 16:30:54 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-04-15 16:30:53 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-04-15 16:30:52 ----A---- C:\Windows\system32\sdohlp.dll
2009-04-15 16:30:51 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2009-04-15 16:30:50 ----A---- C:\Windows\system32\iasrecst.dll
2009-04-15 16:30:50 ----A---- C:\Windows\system32\iasdatastore.dll
2009-04-15 16:30:50 ----A---- C:\Windows\system32\iasads.dll
2009-04-15 16:30:32 ----A---- C:\Windows\system32\secur32.dll
2009-04-15 16:30:32 ----A---- C:\Windows\system32\lsasrv.dll
2009-04-15 16:30:32 ----A---- C:\Windows\system32\kernel32.dll
2009-04-15 16:30:30 ----A---- C:\Windows\system32\lsass.exe
2009-04-15 16:30:29 ----A---- C:\Windows\system32\apilogen.dll
2009-04-15 16:30:29 ----A---- C:\Windows\system32\amxread.dll
2009-04-15 16:30:19 ----A---- C:\Windows\system32\mshtml.dll
2009-04-15 16:30:18 ----A---- C:\Windows\system32\ieframe.dll
2009-04-15 16:30:16 ----A---- C:\Windows\system32\iedkcs32.dll
2009-04-15 16:30:15 ----A---- C:\Windows\system32\urlmon.dll
2009-04-15 16:30:14 ----A---- C:\Windows\system32\occache.dll
2009-04-15 16:30:14 ----A---- C:\Windows\system32\msfeeds.dll
2009-04-15 16:30:14 ----A---- C:\Windows\system32\iertutil.dll
2009-04-15 16:30:14 ----A---- C:\Windows\system32\dxtmsft.dll
2009-04-15 16:30:13 ----A---- C:\Windows\system32\wininet.dll
2009-04-15 16:30:13 ----A---- C:\Windows\system32\ieaksie.dll
2009-04-15 16:30:11 ----A---- C:\Windows\system32\ieencode.dll
2009-04-15 16:30:11 ----A---- C:\Windows\system32\dxtrans.dll
2009-04-15 16:30:10 ----A---- C:\Windows\system32\mshtmled.dll
2009-04-15 16:30:09 ----A---- C:\Windows\system32\jsproxy.dll
2009-04-15 16:30:09 ----A---- C:\Windows\system32\admparse.dll
2009-04-15 16:30:08 ----A---- C:\Windows\system32\mstime.dll
2009-04-15 16:30:08 ----A---- C:\Windows\system32\ieui.dll
2009-04-15 16:30:08 ----A---- C:\Windows\system32\advpack.dll
2009-04-15 16:30:07 ----A---- C:\Windows\system32\iesetup.dll
2009-04-15 16:30:07 ----A---- C:\Windows\system32\iernonce.dll
2009-04-15 16:30:07 ----A---- C:\Windows\system32\icardie.dll
2009-04-15 16:30:05 ----A---- C:\Windows\system32\pngfilt.dll
2009-04-15 16:30:05 ----A---- C:\Windows\system32\ieUnatt.exe
2009-04-15 16:30:05 ----A---- C:\Windows\system32\ie4uinit.exe
2009-04-15 16:30:02 ----A---- C:\Windows\system32\mshtmler.dll
2009-04-15 16:30:02 ----A---- C:\Windows\system32\ieapfltr.dll
2009-04-15 16:30:02 ----A---- C:\Windows\system32\ieakui.dll
2009-04-11 14:21:00 ----D---- C:\Program Files\Yahoo!
2009-03-26 15:23:46 ----A---- C:\Windows\system32\usbaaplrc.dll
2009-03-11 15:09:50 ----A---- C:\Windows\system32\wmp.dll
2009-03-11 15:09:44 ----A---- C:\Windows\system32\spwmp.dll
2009-03-11 15:09:44 ----A---- C:\Windows\system32\dxmasf.dll
2009-03-11 15:09:43 ----A---- C:\Windows\system32\wmploc.DLL
2009-03-11 15:09:32 ----A---- C:\Windows\system32\schannel.dll
2009-02-24 19:52:46 ----A---- C:\Windows\system32\EncDec.dll
2009-02-24 19:52:43 ----A---- C:\Windows\system32\psisdecd.dll
2009-02-24 19:52:42 ----A---- C:\Windows\system32\mcmde.dll
======List of files/folders modified in the last 3 months======
2009-05-03 10:13:16 ----D---- C:\Windows\Temp
2009-05-03 10:10:05 ----AD---- C:\Windows\System32
2009-05-03 10:10:05 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-05-03 10:10:04 ----D---- C:\Windows\inf
2009-05-03 10:08:01 ----D---- C:\Windows\Prefetch
2009-05-03 10:06:21 ----D---- C:\Windows\Tasks
2009-05-03 10:06:13 ----D---- C:\ProgramData\Google Updater
2009-05-03 10:01:31 ----HD---- C:\ProgramData
2009-05-02 19:52:00 ----SHD---- C:\System Volume Information
2009-05-02 19:49:48 ----D---- C:\Users\Nikki\AppData\Roaming\SiteAdvisor
2009-05-02 15:35:45 ----SHD---- C:\Windows\Installer
2009-05-02 15:35:45 ----HD---- C:\Config.Msi
2009-05-02 15:35:35 ----RD---- C:\Program Files
2009-05-02 14:07:09 ----D---- C:\Users\Nikki\AppData\Roaming\StumbleUpon
2009-05-02 09:18:31 ----D---- C:\Windows\system32\drivers
2009-05-01 20:12:45 ----D---- C:\Windows
2009-05-01 08:33:17 ----D---- C:\Windows\Logs
2009-05-01 07:58:41 ----D---- C:\Windows\system32\Tasks
2009-05-01 03:02:23 ----D---- C:\ProgramData\Microsoft Help
2009-04-30 23:06:15 ----SD---- C:\Windows\Downloaded Program Files
2009-04-27 18:09:57 ----D---- C:\ProgramData\McAfee
2009-04-27 18:09:57 ----D---- C:\Program Files\Common Files
2009-04-27 09:02:55 ----D---- C:\Program Files\Common Files\Adobe
2009-04-27 09:02:40 ----D---- C:\Windows\winsxs
2009-04-27 09:01:06 ----D---- C:\Program Files\Adobe
2009-04-27 08:46:09 ----D---- C:\Users\Nikki\AppData\Roaming\Adobe
2009-04-27 08:44:52 ----D---- C:\ProgramData\Adobe
2009-04-27 08:39:11 ----SD---- C:\Users\Nikki\AppData\Roaming\Microsoft
2009-04-20 08:06:26 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-04-19 15:36:22 ----D---- C:\Windows\system32\catroot
2009-04-19 15:36:17 ----DC---- C:\Windows\system32\DRVSTORE
2009-04-19 15:36:15 ----D---- C:\Program Files\iTunes
2009-04-19 15:35:51 ----D---- C:\Program Files\Common Files\Apple
2009-04-19 15:33:49 ----D---- C:\Program Files\Bonjour
2009-04-17 03:14:58 ----D---- C:\Windows\system32\wbem
2009-04-17 03:14:58 ----D---- C:\Program Files\Windows Mail
2009-04-17 03:14:56 ----D---- C:\Windows\system32\manifeststore
2009-04-17 03:14:55 ----D---- C:\Windows\AppPatch
2009-04-17 03:14:54 ----D---- C:\Windows\system32\migration
2009-04-17 03:14:54 ----D---- C:\Program Files\Internet Explorer
2009-04-15 16:29:20 ----D---- C:\Windows\system32\catroot2
2009-04-06 10:57:24 ----A---- C:\Windows\system32\mrt.exe
2009-03-12 03:11:39 ----D---- C:\Program Files\Microsoft Silverlight
2009-03-12 03:10:06 ----D---- C:\Program Files\Windows Media Player
2009-02-25 04:18:51 ----D---- C:\Windows\Microsoft.NET
2009-02-25 04:18:50 ----RSD---- C:\Windows\assembly
2009-02-25 04:10:30 ----D---- C:\Windows\ehome
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R3 AgereSoftModem;TOSHIBA V92 Software Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2006-08-31 1161152]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2007-01-24 689664]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2007-11-14 14208]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2009-03-19 23400]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2006-11-08 1647976]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-01-25 106496]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2007-06-12 82432]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2006-10-27 179896]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 16128]
R3 tifm21;tifm21; C:\Windows\system32\drivers\tifm21.sys [2006-07-06 168448]
S1 Tosrfcom;Tosrfcom; C:\Windows\system32\drivers\Tosrfcom.sys [2005-08-01 64896]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
S3 motmodem;Motorola USB CDC ACM Driver; C:\Windows\system32\DRIVERS\motmodem.sys [2007-02-27 21504]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 NETw3v32;Intel® PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 1781760]
S3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2006-10-23 9216]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-03-26 36864]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2006-11-02 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]
S4 KR10I;KR10I; C:\Windows\system32\drivers\kr10i.sys [2006-02-14 216320]
S4 KR10N;KR10N; C:\Windows\system32\drivers\kr10n.sys [2005-09-27 207104]
S4 KR3NPXP;KR3NPXP; C:\Windows\system32\drivers\kr3npxp.sys [2006-09-27 479488]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2006-09-12 9216]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-03-26 132424]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 CFSvcs;ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [2006-11-15 40960]
R2 Swupdtmr;Swupdtmr; c:\Toshiba\IVP\swupdate\swupdtmr.exe [2006-07-20 40960]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2006-05-25 114688]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe [2006-12-20 428152]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2006-11-01 77824]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2006-08-23 49152]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-04-02 656168]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-30 183280]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
systemlook log:
SystemLook v1.0 by jpshortstuff (24.04.09)
Log created at 10:07 on 03/05/2009 by Nikki (Administrator - Elevation successful)
========== file ==========
C:\Windows\system32\drivers\buobjmo.sys - Unable to find/read file.
========== service ==========
buobjmo - Unable to open Service Handle.
========== filefind ==========
Searching for "buobjmo.sys"
No files found.
-=End Of File=-