Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I think I might have some virus


  • This topic is locked This topic is locked
2 replies to this topic

#1 NannyBot

NannyBot

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:07:54 AM

Posted 04 May 2011 - 04:47 AM

There is a program I am trying to run in cmd.exe, and it won't run, it just pops up for half a second and shuts down,



Logfile of random's system information tool 1.08 (written by random/random)
Run by Peter Corduan at 2011-05-04 04:36:04
Microsoft Windows 7 Home Premium
System drive C: has 165 GB (36%) free of 465 GB
Total RAM: 3955 MB (32% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:36:45 AM, on 5/4/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16766)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\SpeedBit Video Accelerator\VideoAccelerator.exe
C:\Program Files (x86)\GameTracker\GTLite.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe
C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files (x86)\Ad Muncher\AdMunch.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
C:\Program Files (x86)\Activision\Call of Duty 2\cod2mp_s.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Peter Corduan\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\Peter Corduan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:64121
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - (no file)
R3 - URLSearchHook: (no name) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - (no file)
O2 - BHO: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL
O2 - BHO: IEHlprObj Class - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files (x86)\iWin Games\iWinGamesHookIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O3 - Toolbar: (no name) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - (no file)
O3 - Toolbar: MediaBar - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - (no file)
O3 - Toolbar: (no name) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - (no file)
O3 - Toolbar: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
O4 - HKLM\..\Run: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
O4 - HKLM\..\Run: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
O4 - HKLM\..\Run: [TRCMan] C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe
O4 - HKLM\..\Run: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [HDD Regenerator] "C:\Program Files (x86)\HDD Regenerator\HDD Regenerator.exe"
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKLM\..\Run: [Ad Muncher] "C:\Program Files (x86)\Ad Muncher\AdMunch.exe" /bt
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SpeedBitVideoAccelerator] C:\Program Files (x86)\SpeedBit Video Accelerator\VideoAccelerator.exe
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [GameTracker] "C:\Program Files (x86)\GameTracker\GTLite.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-551868457-492759081-2139501205-1000\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-551868457-492759081-2139501205-1000\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: Xfire.lnk = C:\Program Files (x86)\Xfire\Xfire.exe
O4 - Global Startup: WhiteSmoke Translator.lnk = Peter Corduan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MHJQ74R0\WhiteSmokeTranslator5060_en[1].exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
O8 - Extra context menu item: Block frame with Ad Muncher - http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&exversion=2.0&pass=167U2189&id=menu_ie_frame
O8 - Extra context menu item: Block image with Ad Muncher - http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&exversion=2.0&pass=167U2189&id=menu_ie_image
O8 - Extra context menu item: Block link with Ad Muncher - http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&exversion=2.0&pass=167U2189&id=menu_ie_link
O8 - Extra context menu item: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&exversion=2.0&pass=167U2189&id=menu_ie_exclude
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_be_intercepted_by/Ad_Muncher/browserextensions.pl?exbrowser=ie&exversion=2.0&pass=167U2189&id=menu_ie_report
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: @C:\windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\windows\WindowsMobile\INetRepl.dll
O9 - Extra button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~2\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~2\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~2\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~2\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~2\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~2\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~2\speedb~1\sblsp.dll
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.3.1.0.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: TeknoGods.dll,C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: GS In-Game Service - ClanServers Hosting LLC - C:\Program Files (x86)\GameTracker\GSInGameService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iWinTrusted - iWin Inc. - C:\Program Files (x86)\iWin Games\iWinTrusted.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Toshiba Laptop Checkup Application Launcher (Norton PC Checkup Application Launcher) - Symantec Corporation - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\SymcPCCULaunchSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\windows\SysWOW64\nvSCPAPISvr.exe
O23 - Service: TOSHIBA HDD Protection (Thpsrv) - Unknown owner - C:\windows\system32\ThpSrv.exe (file missing)
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~2\SPEEDB~1\VideoAcceleratorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 17974 bytes

======Scheduled tasks folder======

C:\windows\tasks\AdsGone.job
C:\windows\tasks\At1.job
C:\windows\tasks\MyCleanPC Registry Cleaner.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0974BA1E-64EC-11DE-B2A5-E43756D89593}]
MediaBar

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~2\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll [2010-10-05 68280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8CA5ED52-F3FB-4414-A105-2E3491156990}]
IEHlprObj Class - C:\Program Files (x86)\iWin Games\iWinGamesHookIE.dll [2011-03-25 141312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL [2010-01-16 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-05-06 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
FilterBHO Class - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll [2010-10-05 191160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
{0974BA1E-64EC-11DE-B2A5-E43756D89593} -
{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
{30F9B915-B755-4826-820B-08FBA6BD249D}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"KeNotify"=C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [2009-12-25 34160]
"HWSetup"=C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [2010-03-04 423936]
"SVPWUTIL"=C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [2010-02-22 352256]
"ToshibaServiceStation"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [2010-11-29 1294712]
"TWebCamera"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2010-02-24 2454840]
"TRCMan"=C:\Program Files (x86)\TOSHIBA\TRCMan\TRCMan.exe [2009-07-21 701752]
"TSleepSrv"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe [2010-03-17 252728]
"NortonOnlineBackupReminder"=C:\Program Files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe [2009-08-10 529256]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-01-21 91520]
"BrMfcWnd"=C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [2009-05-26 1159168]
"ControlCenter3"=C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [2008-12-24 114688]
"TrueImageMonitor.exe"=C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2007-10-30 2595616]
"AcronisTimounterMonitor"=C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe [2007-10-30 909208]
"HDD Regenerator"=C:\Program Files (x86)\HDD Regenerator\HDD Regenerator.exe [2011-03-17 1656696]
"SpybotSnD"=C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe [2009-01-26 5365592]
"Ad Muncher"=C:\Program Files (x86)\Ad Muncher\AdMunch.exe [2011-03-31 535752]
"PWRISOVM.EXE"=C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
"AVP"=C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe [2010-11-02 365336]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-13 1475072]
"SpeedBitVideoAccelerator"=C:\Program Files (x86)\SpeedBit Video Accelerator\VideoAccelerator.exe [2010-08-28 1607272]
"Pando Media Booster"=C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2010-09-20 2969496]
"GameTracker"=C:\Program Files (x86)\GameTracker\GTLite.exe [2010-11-09 4018984]
"SpybotSD TeaTimer"=C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2011-05-03 1242448]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
WhiteSmoke Translator.lnk - C:\Users\Peter Corduan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MHJQ74R0\WhiteSmokeTranslator5060_en[1].exe

C:\Users\Peter Corduan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Xfire.lnk - C:\Program Files (x86)\Xfire\Xfire.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="TeknoGods.dll,C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MIF5BA~1\Office14\GROOVEEX.DLL [2010-01-21 4222864]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2011-05-04 04:36:06 ----D---- C:\Program Files (x86)\trend micro
2011-05-04 04:36:04 ----D---- C:\rsit
2011-05-04 02:05:26 ----D---- C:\ProgramData\Kaspersky Lab
2011-05-04 02:05:26 ----D---- C:\Program Files (x86)\Kaspersky Lab
2011-05-04 00:49:43 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2011-05-03 23:17:39 ----D---- C:\Program Files (x86)\Steam
2011-05-03 00:31:31 ----D---- C:\Editing Tools
2011-05-03 00:31:26 ----D---- C:\Users\Peter Corduan\AppData\Roaming\REDitor II
2011-05-02 20:16:32 ----A---- C:\windows\game.ini
2011-05-02 05:23:24 ----D---- C:\IFF CDF Studio
2011-04-29 21:21:17 ----SD---- C:\Program Files (x86)\HLSW
2011-04-29 21:21:17 ----D---- C:\Users\Peter Corduan\AppData\Roaming\HLSW
2011-04-29 19:31:52 ----D---- C:\0067534a5eeb328eed
2011-04-28 23:34:43 ----A---- C:\windows\explorer.exe
2011-04-28 23:34:42 ----A---- C:\windows\SysWOW64\explorer.exe
2011-04-28 23:34:41 ----A---- C:\windows\SysWOW64\XpsPrint.dll
2011-04-28 23:34:30 ----A---- C:\windows\SysWOW64\esent.dll
2011-04-28 23:34:29 ----A---- C:\windows\SysWOW64\fsutil.exe
2011-04-28 23:34:24 ----A---- C:\windows\SysWOW64\prevhost.exe
2011-04-20 03:29:40 ----D---- C:\Program Files (x86)\PowerISO
2011-04-15 13:45:01 ----A---- C:\windows\SysWOW64\XpsGdiConverter.dll
2011-04-15 13:45:01 ----A---- C:\windows\SysWOW64\jscript.dll
2011-04-15 13:45:00 ----A---- C:\windows\SysWOW64\vbscript.dll
2011-04-15 13:44:54 ----A---- C:\windows\SysWOW64\mfc42u.dll
2011-04-15 13:44:54 ----A---- C:\windows\SysWOW64\mfc42.dll
2011-04-15 13:44:51 ----A---- C:\windows\SysWOW64\atmlib.dll
2011-04-15 13:44:51 ----A---- C:\windows\SysWOW64\atmfd.dll
2011-04-15 13:44:49 ----A---- C:\windows\SysWOW64\mshtml.dll
2011-04-15 13:44:46 ----A---- C:\windows\SysWOW64\ieframe.dll
2011-04-15 13:44:42 ----A---- C:\windows\SysWOW64\urlmon.dll
2011-04-15 13:44:40 ----A---- C:\windows\SysWOW64\wininet.dll
2011-04-15 13:44:39 ----A---- C:\windows\SysWOW64\mstime.dll
2011-04-15 13:44:39 ----A---- C:\windows\SysWOW64\mshtmled.dll
2011-04-15 13:44:39 ----A---- C:\windows\SysWOW64\msfeedsbs.dll
2011-04-15 13:44:39 ----A---- C:\windows\SysWOW64\msfeeds.dll
2011-04-15 13:44:39 ----A---- C:\windows\SysWOW64\ieui.dll
2011-04-15 13:44:39 ----A---- C:\windows\SysWOW64\iertutil.dll
2011-04-15 13:44:39 ----A---- C:\windows\SysWOW64\iepeers.dll
2011-04-15 13:44:39 ----A---- C:\windows\SysWOW64\iedkcs32.dll
2011-04-15 13:44:38 ----A---- C:\windows\SysWOW64\msfeedssync.exe
2011-04-15 13:44:38 ----A---- C:\windows\SysWOW64\licmgr10.dll
2011-04-15 13:44:38 ----A---- C:\windows\SysWOW64\jsproxy.dll
2011-04-15 13:44:35 ----A---- C:\windows\SysWOW64\dnscacheugc.exe
2011-04-15 13:44:35 ----A---- C:\windows\SysWOW64\dnsapi.dll
2011-04-15 13:44:32 ----A---- C:\windows\SysWOW64\inetcomm.dll
2011-04-10 04:00:10 ----A---- C:\windows\SysWOW64\pbsvc.exe
2011-04-09 15:23:39 ----A---- C:\windows\SysWOW64\LMRTREND.dll
2011-04-09 15:23:39 ----A---- C:\windows\SysWOW64\LMRT.dll
2011-04-09 15:23:38 ----A---- C:\windows\SysWOW64\dxtmsft3.dll
2011-04-09 15:23:33 ----A---- C:\windows\SysWOW64\strmdll.dll
2011-04-09 15:23:32 ----A---- C:\windows\SysWOW64\unam4ie.exe
2011-04-09 15:23:25 ----A---- C:\windows\SysWOW64\vidx16.dll
2011-04-09 15:23:25 ----A---- C:\windows\SysWOW64\danim.dll
2011-04-09 15:23:24 ----A---- C:\windows\SysWOW64\qcut.dll
2011-04-09 15:23:21 ----A---- C:\windows\SysWOW64\w95inf32.dll
2011-04-09 15:23:21 ----A---- C:\windows\SysWOW64\w95inf16.dll
2011-04-09 15:23:07 ----D---- C:\Program Files (x86)\LEGO Media
2011-04-08 06:28:58 ----A---- C:\windows\SysWOW64\xfcodec.dll
2011-04-08 05:03:19 ----D---- C:\ProgramData\WorldWinner.com
2011-04-08 05:01:40 ----D---- C:\ProgramData\WorldWinner
2011-04-08 04:59:03 ----D---- C:\Users\Peter Corduan\AppData\Roaming\Worldwinner
2011-04-08 04:59:03 ----D---- C:\Program Files (x86)\WorldWinner.com, Inc
2011-04-08 04:54:58 ----D---- C:\Program Files (x86)\iWin Games
2011-04-05 23:47:43 ----D---- C:\Program Files (x86)\PFPortChecker
2011-04-05 20:46:25 ----D---- C:\Program Files (x86)\ConduitEngine
2011-04-05 20:46:19 ----D---- C:\Program Files (x86)\XfireXO
2011-04-05 20:45:59 ----D---- C:\Users\Peter Corduan\AppData\Roaming\Xfire
2011-04-05 20:45:56 ----D---- C:\ProgramData\Xfire
2011-04-05 20:45:56 ----D---- C:\Program Files (x86)\Xfire
2011-03-31 23:25:06 ----D---- C:\Users\Peter Corduan\AppData\Roaming\FrostWire
2011-03-31 23:22:26 ----D---- C:\Program Files (x86)\FrostWire
2011-03-31 16:21:05 ----A---- C:\windows\COD.INI
2011-03-31 16:03:25 ----D---- C:\ProgramData\Ad Muncher
2011-03-31 16:03:25 ----D---- C:\Program Files (x86)\Ad Muncher
2011-03-28 23:32:21 ----D---- C:\Users\Peter Corduan\AppData\Roaming\Audacity
2011-03-28 23:32:08 ----D---- C:\Program Files (x86)\Audacity 1.3 Beta (Unicode)
2011-03-28 03:14:01 ----D---- C:\windows\Back to the Future Episode 1
2011-03-28 03:14:01 ----D---- C:\Program Files (x86)\Back to the Future Episode 1
2011-03-28 03:13:41 ----A---- C:\windows\Back to the Future Episode 1 Setup Log.txt
2011-03-26 01:34:35 ----D---- C:\ProgramData\Driver Boost
2011-03-26 01:17:09 ----D---- C:\windows\WindowsMobile
2011-03-26 01:15:34 ----D---- C:\ProgramData\Windows Genuine Advantage
2011-03-26 01:07:55 ----D---- C:\Program Files (x86)\Samsung
2011-03-26 00:56:29 ----A---- C:\windows\ODBC.INI
2011-03-25 12:46:16 ----A---- C:\windows\SysWOW64\d3d10_1.dll
2011-03-20 23:12:52 ----D---- C:\Users\Peter Corduan\AppData\Roaming\Apple Computer
2011-03-20 23:12:35 ----D---- C:\ProgramData\Apple Computer
2011-03-20 23:11:45 ----D---- C:\Program Files (x86)\Common Files\Apple
2011-03-20 23:11:33 ----D---- C:\ProgramData\Apple
2011-03-20 23:11:33 ----D---- C:\Program Files (x86)\Apple Software Update
2011-03-17 22:06:48 ----D---- C:\Program Files (x86)\HDD Regenerator
2011-03-17 16:51:07 ----SHD---- C:\windows\SysWOW64\%APPDATA%
2011-03-12 03:15:35 ----D---- C:\Users\Peter Corduan\AppData\Roaming\Registry Mechanic
2011-03-12 03:10:48 ----D---- C:\Program Files (x86)\Registry Mechanic
2011-03-12 03:10:48 ----AD---- C:\ProgramData\TEMP
2011-03-12 02:57:24 ----D---- C:\Users\Peter Corduan\AppData\Roaming\Trillian
2011-03-10 22:18:44 ----D---- C:\windows\Minidump
2011-03-08 23:49:35 ----D---- C:\Program Files (x86)\Broderbund
2011-03-08 23:39:33 ----A---- C:\windows\SysWOW64\DWrite.dll
2011-03-08 23:39:32 ----A---- C:\windows\SysWOW64\d2d1.dll
2011-03-08 23:39:30 ----A---- C:\windows\SysWOW64\sbe.dll
2011-03-08 23:39:30 ----A---- C:\windows\SysWOW64\EncDec.dll
2011-03-08 23:39:30 ----A---- C:\windows\SysWOW64\CPFilters.dll
2011-03-08 23:39:29 ----A---- C:\windows\SysWOW64\mstscax.dll
2011-03-08 23:39:29 ----A---- C:\windows\SysWOW64\mstsc.exe
2011-03-08 04:06:22 ----A---- C:\windows\SysWOW64\wcncsvc.dll
2011-03-07 23:16:27 ----A---- C:\windows\ntbtlog.txt
2011-03-07 22:20:58 ----D---- C:\windows\pss
2011-03-07 17:21:03 ----D---- C:\ProgramData\Lavasoft
2011-03-07 17:21:03 ----D---- C:\Program Files (x86)\Lavasoft
2011-03-07 17:18:03 ----HDC---- C:\ProgramData\{A5847AFF-A1FE-4929-A3C0-16C23AB1D29D}
2011-03-07 16:55:35 ----D---- C:\ProgramData\Spybot - Search & Destroy
2011-03-07 16:55:35 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy
2011-02-16 21:45:52 ----D---- C:\Users\Peter Corduan\AppData\Roaming\MiniDm
2011-02-09 09:02:41 ----A---- C:\windows\SysWOW64\kerberos.dll
2011-02-09 09:02:14 ----A---- C:\windows\SysWOW64\upnp.dll
2011-02-09 09:02:13 ----A---- C:\windows\SysWOW64\msxml6.dll
2011-02-09 09:02:13 ----A---- C:\windows\SysWOW64\msxml3.dll
2011-02-09 09:02:12 ----A---- C:\windows\SysWOW64\WebClnt.dll
2011-02-09 09:02:11 ----A---- C:\windows\SysWOW64\wscapi.dll
2011-02-09 09:02:11 ----A---- C:\windows\SysWOW64\winhttp.dll
2011-02-09 09:02:11 ----A---- C:\windows\SysWOW64\slwga.dll
2011-02-09 09:02:11 ----A---- C:\windows\SysWOW64\davclnt.dll
2011-02-09 09:02:03 ----A---- C:\windows\SysWOW64\ntdll.dll
2011-02-09 09:02:02 ----A---- C:\windows\SysWOW64\ntoskrnl.exe
2011-02-09 09:02:02 ----A---- C:\windows\SysWOW64\ntkrnlpa.exe
2011-02-05 00:39:21 ----D---- C:\Users\Peter Corduan\AppData\Roaming\GameTracker
2011-02-05 00:38:42 ----D---- C:\Program Files (x86)\GameTracker

======List of files/folders modified in the last 3 months======

2011-05-04 04:36:40 ----D---- C:\windows\Temp
2011-05-04 04:36:06 ----D---- C:\Program Files (x86)
2011-05-04 04:13:11 ----AD---- C:\Windows
2011-05-04 02:59:52 ----SHD---- C:\System Volume Information
2011-05-04 02:28:42 ----D---- C:\windows\Prefetch
2011-05-04 02:07:35 ----SHD---- C:\windows\Installer
2011-05-04 02:07:21 ----D---- C:\windows\System32
2011-05-04 02:06:59 ----D---- C:\windows\inf
2011-05-04 02:05:26 ----HD---- C:\ProgramData
2011-05-04 02:03:23 ----D---- C:\Program Files (x86)\Common Files
2011-05-04 02:00:24 ----D---- C:\windows\SysWOW64
2011-05-04 01:55:31 ----SHD---- C:\$Recycle.Bin
2011-05-04 01:55:26 ----RD---- C:\Users
2011-05-04 01:51:35 ----D---- C:\Program Files (x86)\Norton PC Checkup
2011-05-04 01:19:00 ----A---- C:\windows\SysWOW64\log.txt
2011-05-04 01:15:51 ----D---- C:\ProgramData\BitDefender
2011-05-04 01:13:53 ----A---- C:\bdlog.txt
2011-05-04 01:10:57 ----D---- C:\Program Files (x86)\Common Files\Steam
2011-05-02 20:16:39 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-05-02 20:07:47 ----D---- C:\Program Files (x86)\Activision
2011-05-01 23:24:23 ----D---- C:\Program Files (x86)\Call of Duty
2011-04-30 07:29:38 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-04-30 07:23:51 ----D---- C:\windows\winsxs
2011-04-30 06:36:32 ----D---- C:\Users\Peter Corduan\AppData\Roaming\uTorrent
2011-04-30 04:29:34 ----D---- C:\windows\Tasks
2011-04-30 04:29:34 ----D---- C:\windows\SysWOW64\wbem
2011-04-30 04:29:34 ----D---- C:\windows\SysWOW64\migwiz
2011-04-30 04:29:33 ----D---- C:\windows\SysWOW64\manifeststore
2011-04-30 04:29:33 ----D---- C:\windows\SysWOW64\Dism
2011-04-30 04:29:32 ----RSD---- C:\windows\Fonts
2011-04-30 04:29:32 ----D---- C:\windows\ehome
2011-04-30 04:29:32 ----D---- C:\windows\AppPatch
2011-04-30 04:29:32 ----D---- C:\Program Files (x86)\Windows Portable Devices
2011-04-30 04:29:32 ----D---- C:\Program Files (x86)\Windows Media Player
2011-04-30 04:29:32 ----D---- C:\Program Files (x86)\Internet Explorer
2011-04-30 04:29:31 ----D---- C:\windows\SysWOW64\sppui
2011-04-30 04:29:31 ----D---- C:\windows\SysWOW64\Setup
2011-04-30 04:29:31 ----D---- C:\windows\SysWOW64\oobe
2011-04-30 04:29:31 ----D---- C:\windows\SysWOW64\migration
2011-04-30 04:29:31 ----D---- C:\windows\SysWOW64\es-ES
2011-04-30 04:29:31 ----D---- C:\windows\SysWOW64\en-US
2011-04-30 04:29:31 ----D---- C:\windows\SysWOW64\en
2011-04-30 04:29:30 ----D---- C:\windows\SysWOW64\da-DK
2011-04-30 04:29:30 ----D---- C:\windows\SysWOW64\cs-CZ
2011-04-30 04:29:30 ----D---- C:\windows\SysWOW64\AdvancedInstallers
2011-04-30 04:29:25 ----RSD---- C:\windows\Media
2011-04-30 04:29:25 ----D---- C:\windows\servicing
2011-04-30 04:29:25 ----D---- C:\windows\PolicyDefinitions
2011-04-30 04:29:25 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-04-30 04:29:25 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-04-30 04:29:25 ----D---- C:\Program Files (x86)\Windows Mail
2011-04-30 04:29:05 ----D---- C:\windows\SysWOW64\Speech
2011-04-30 04:27:33 ----D---- C:\windows\registration
2011-04-30 04:23:34 ----D---- C:\windows\Microsoft.NET
2011-04-30 04:22:49 ----D---- C:\ProgramData\NVIDIA
2011-04-29 19:58:50 ----D---- C:\windows\Logs
2011-04-29 19:10:17 ----RD---- C:\Program Files
2011-04-29 08:06:28 ----D---- C:\windows\rescache
2011-04-24 01:46:24 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-04-20 03:35:45 ----D---- C:\windows\SysWOW64\drivers
2011-04-19 20:51:14 ----D---- C:\windows\SysWOW64\Macromed
2011-04-16 13:26:32 ----RSD---- C:\windows\assembly
2011-04-16 03:10:50 ----D---- C:\ProgramData\Microsoft Help
2011-04-16 03:08:10 ----D---- C:\windows\debug
2011-04-09 15:23:33 ----D---- C:\windows\Help
2011-04-08 04:56:31 ----D---- C:\Program Files (x86)\iWin.com
2011-04-07 14:03:12 ----SD---- C:\ProgramData\Microsoft
2011-03-31 15:27:48 ----D---- C:\Program Files (x86)\Windows Live
2011-03-27 23:58:19 ----SD---- C:\Users\Peter Corduan\AppData\Roaming\Microsoft
2011-03-26 01:21:49 ----D---- C:\Program Files (x86)\Microsoft Office
2011-03-26 01:21:47 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2011-03-26 01:21:43 ----D---- C:\Program Files (x86)\Common Files\System
2011-03-26 00:56:18 ----A---- C:\windows\win.ini
2011-03-26 00:55:49 ----D---- C:\windows\IME
2011-03-26 00:51:43 ----D---- C:\windows\system
2011-03-21 13:28:42 ----D---- C:\Users\Peter Corduan\AppData\Roaming\Uniblue
2011-03-20 23:22:23 ----D---- C:\Program Files (x86)\TOSHIBA Games
2011-03-20 23:22:22 ----D---- C:\ProgramData\WildTangent
2011-03-20 23:21:18 ----D---- C:\Program Files (x86)\Trillian
2011-03-20 23:17:43 ----D---- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2011-03-16 00:20:16 ----D---- C:\ProgramData\Norton
2011-03-13 00:04:52 ----D---- C:\windows\Downloaded Program Files
2011-03-12 02:55:42 ----D---- C:\Program Files (x86)\AviSynth 2.5
2011-03-12 02:55:14 ----D---- C:\Users\Peter Corduan\AppData\Roaming\OnLive App
2011-03-10 23:22:24 ----D---- C:\ProgramData\PMB Files
2011-03-10 23:22:10 ----D---- C:\windows\AppCompat
2011-03-08 01:00:17 ----D---- C:\ProgramData\Acronis
2011-03-07 22:17:48 ----D---- C:\Users\Peter Corduan\AppData\Roaming\Mozilla
2011-03-07 22:17:19 ----D---- C:\Program Files (x86)\TOSHIBA
2011-03-07 22:17:05 ----RHD---- C:\MSOCache

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys []
R0 KL1;kl1; C:\windows\system32\DRIVERS\kl1.sys []
R0 Lbd;Lbd; C:\windows\system32\DRIVERS\Lbd.sys []
R0 LPCFilter;LPC Lower Filter Driver; C:\windows\system32\DRIVERS\LPCFilter.sys []
R0 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys []
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys []
R0 snapman;Acronis Snapshots Manager; C:\windows\system32\DRIVERS\snapman.sys []
R0 tdrpman;Acronis Try&Decide and Restore Points filter; C:\windows\system32\DRIVERS\tdrpman.sys []
R0 Thpdrv;TOSHIBA HDD Protection Driver; C:\windows\system32\DRIVERS\thpdrv.sys []
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver; C:\windows\system32\DRIVERS\Thpevm.SYS []
R0 timounter;Acronis True Image Backup Archive Explorer; C:\windows\system32\DRIVERS\timntr.sys []
R0 tos_sps64;TOSHIBA tos_sps64 Service; C:\windows\system32\DRIVERS\tos_sps64.sys []
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\windows\system32\DRIVERS\TVALZ_O.SYS []
R1 kl2;kl2; C:\windows\system32\DRIVERS\kl2.sys []
R1 KLIF;Kaspersky Lab Driver; C:\windows\system32\DRIVERS\klif.sys []
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\windows\system32\DRIVERS\klim6.sys []
R1 SBRE;SBRE; \??\C:\windows\system32\drivers\SBREdrv.sys []
R1 SCDEmu;SCDEmu; C:\windows\SysWOW64\drivers\SCDEmu.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys []
R2 tifsfilter;Acronis True Image FS Filter; C:\windows\system32\DRIVERS\tifsfilt.sys []
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\windows\system32\DRIVERS\TVALZFL.sys []
R3 enecir;ENE CIR Receiver; C:\windows\system32\DRIVERS\enecir.sys []
R3 enecirhid;ENE CIR HID Receiver; C:\windows\system32\DRIVERS\enecirhid.sys []
R3 enecirhidma;ENE CIR HIDmini Filter; C:\windows\system32\DRIVERS\enecirhidma.sys []
R3 HECIx64;Intel® Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys []
R3 Impcd;Impcd; C:\windows\system32\DRIVERS\Impcd.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys []
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\windows\system32\drivers\nvhda64v.sys []
R3 PGEffect;Pangu effect driver; C:\windows\system32\DRIVERS\pgeffect.sys []
R3 Point64;Microsoft IntelliPoint Filter Driver; C:\windows\system32\DRIVERS\point64.sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys []
R3 StillCam;Still Serial Digital Camera Driver; C:\windows\system32\DRIVERS\serscan.sys []
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys []
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\windows\system32\DRIVERS\tdcmdpst.sys []
S1 SABKUTIL;SABKUTIL; \??\C:\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys []
S3 acpials;ALS Sensor Filter; C:\windows\system32\DRIVERS\acpials.sys []
S3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys []
S3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys []
S3 klmouflt;Kaspersky Lab KLMOUFLT; C:\windows\system32\DRIVERS\klmouflt.sys []
S3 Lavasoft Kernexplorer;Lavasoft helper driver; \??\C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys []
S3 lmimirr;lmimirr; C:\windows\system32\DRIVERS\lmimirr.sys []
S3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\windows\system32\DRIVERS\mcdbus.sys []
S3 PSTRIP;PSTRIP; \??\C:\windows\system32\DRIVERS\PSTRIP.SYS []
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\windows\system32\DRIVERS\rtl8192se.sys []
S3 SABProcEnum;SABProcEnum; \??\C:\Program Files (x86)\SuperAdBlocker.com\Super Ad Blocker\SABProcEnum.sys []
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys []
S3 usb_rndisx;USB RNDIS Adapter; C:\windows\system32\DRIVERS\usb8023x.sys []
S3 usbscan;USB Scanner Driver; C:\windows\system32\DRIVERS\usbscan.sys []
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2007-09-07 599320]
R2 AVP;Kaspersky Anti-Virus Service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe [2010-11-02 365336]
R2 GS In-Game Service;GS In-Game Service; C:\Program Files (x86)\GameTracker\GSInGameService.exe [2010-11-09 1677096]
R2 iWinTrusted;iWinTrusted; C:\Program Files (x86)\iWin Games\iWinTrusted.exe [2011-03-25 176848]
R2 LMS;Intel® Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe [2010-03-03 268824]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\SymcPCCULaunchSvc.exe [2011-03-17 123320]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2010-05-05 1604200]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\windows\system32\svchost.exe [2009-07-13 20992]
R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\windows\SysWOW64\nvSCPAPISvr.exe [2009-04-30 213504]
R2 Thpsrv;TOSHIBA HDD Protection; C:\windows\system32\ThpSrv.exe []
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe []
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2009-11-06 489312]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-04-06 258928]
R2 TryAndDecideService;Acronis Try And Decide Service; C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [2007-10-30 492720]
R2 UNS;Intel® Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]
R2 VideoAcceleratorService;VideoAcceleratorService; C:\PROGRA~2\SPEEDB~1\VideoAcceleratorService.exe [2010-08-28 300656]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\windows\system32\svchost.exe [2009-07-13 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-05-03 403240]
R3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-11-29 54136]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
R3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 PCCUJobMgr;Common Client Job Manager Service; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe [2009-08-24 126392]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
S3 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe []
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe []

-----------------EOF-----------------

BC AdBot (Login to Remove)

 


#2 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,785 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:02:54 PM

Posted 12 May 2011 - 10:35 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.
If you are unable to create a log because your computer cannot start up successfully please provide detailed information about the Windows version you are using: What we in particular need to know is version, edition and if it is a 32bit or a 64bit system. [/b]
If you are unsure about any of these caracteristics, just let us know and we'll help you figuring it out. Please also tell us if you have your Windows CD/DVD handy.


Please include a clear description of the problems you're having, along with any steps you may have performed so far.

Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.

Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.
We need to create an OTL Report
  • Please download OTL from one of the following mirrors:
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • In the custom scan box paste the following:
    msconfig
    safebootminimal
    activex
    drivers32
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    wininit.exe
    hlp.dat
    /md5stop
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extra.txt<--Will be minimized

In the upper right hand corner of the topic you will see a button called Watch Topic.I suggest you click it and select Immediate E-Mail notification and click on Proceed. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

After 5 days if a topic is not replied to we assume it has been abandoned and it is closed.

regards myrti

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

animinionsmalltext.gif

Follow BleepingComputer on: Facebook | Twitter | Google+


#3 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,785 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:02:54 PM

Posted 22 May 2011 - 03:27 PM

Due to the lack of feedback, this topic is now closed.In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

animinionsmalltext.gif

Follow BleepingComputer on: Facebook | Twitter | Google+





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users