HI Shaba,
Thank you for your reply. While I was waiting for your reply, my laptop's conditioned deteiorated significantally and I did some researh and took some steps on my own.
I believe I was affected by personal antivitus. I found PAV.exe and other related folders on my machine and deleted them. Also I fixed one Hijack this entry (winexplorer.dll). I read that this is caused by the same virus. I also scanned my PC online. Most of the scans do no complete as the browser (or sometimes whole system) crashes. It however did indicate that I have various infections like DNS Changer and Zlob. My fake alerts have come down after I deleted PAV from my system but as son as I reboot, I get various dialog box messages saying "Google installer / Internet explorer has stopped working"and they continue to appear. Also my system has started restarting on its own after showing a blue screen.
Please see below the contents of
log.txt Logfile of random's system information tool 1.06 (written by random/random)
Run by Narwal at 2009-05-21 08:01:32
Microsoft® Windows Vista™ Home Premium
System drive C: has 13 GB (18%) free of 75 GB
Total RAM: 1014 MB (27% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:01:43 AM, on 5/21/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\McAfee\MSK\mskagent.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Users\Narwal\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Windows\system32\WerFault.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Windows\system32\wbem\unsecapp.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\WerFault.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\WerFault.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Narwal\Pictures\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Narwal.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.toshibadirect.com/dpdstartR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.toshibadirect.com/dpdstartR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.toshibadirect.com/dpdstartR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Google Update] "C:\Users\Narwal\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"http://www.bodymindandmodem.com/Basics/posture.html"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver -
res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoftware.com/activescan ... stubie.cabO16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) -
http://picasaweb.google.com/s/v/29.55/uploader2.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resourc ... oscan8.cabO16 - DPF: {6FE79ACA-A498-45E5-8BC4-1B9F380CE468} (Abx(gh) Control) -
http://aolsvc.aol.com/onlinegames/ghadv ... /abxgh.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-l ... cfscan.cabO23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: pinger - Unknown owner - C:\TOSHIBA\IVP\ISM\pinger.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
--
End of file - 8941 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2307070536-2186033536-3377706424-1000.job
C:\Windows\tasks\McDefragTask.job
C:\Windows\tasks\McQcTask.job
C:\Windows\tasks\PAV.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{089FD14D-132B-48FC-8861-0048AE113215}]
C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll [2007-06-25 67136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-19 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0BF43445-2F28-4351-9252-17FE6E806AA0} - McAfee SiteAdvisor - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll [2007-12-04 927008]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2006-11-28 98304]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2006-11-28 106496]
"Persistence"=C:\Windows\system32\igfxpers.exe [2006-11-28 81920]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2007-08-29 1006264]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2006-11-09 3784704]
"MskAgentexe"=C:\Program Files\McAfee\MSK\MskAgent.exe [2007-01-17 152144]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2007-08-03 582992]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-19 148888]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"=C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe [2006-11-10 417792]
"msnmsgr"=C:\Program Files\MSN Messenger\msnmsgr.exe [2007-01-19 5674352]
"Yahoo! Pager"=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2007-08-27 4670704]
"Google Update"=C:\Users\Narwal\AppData\Local\Google\Update\GoogleUpdate.exe [2008-10-18 133104]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"=C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE [2009-01-16 460216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2006-11-28 212992]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\TOSHIBA\ivp\NetInt\Netint.exe"="C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine"
"C:\TOSHIBA\Ivp\ISM\pinger.exe"="C:\TOSHIBA\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{85626e29-c300-11dc-8d7e-001b38134f9c}]
shell\AutoRun\command - G:\wd_windows_tools\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b17ec773-9769-11dc-b4e6-001b38134f9c}]
shell\AutoRun\command - wscript.exe VirusRemoval.vbs
shell\open\command - wscript.exe VirusRemoval.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b17ec778-9769-11dc-b4e6-001b38134f9c}]
shell\AutoRun\command - E:\LaunchU3.exe -a
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2009-05-21 08:01:32 ----D---- C:\rsit
2009-05-19 19:11:03 ----D---- C:\ProgramData\Malwarebytes
2009-05-19 19:11:03 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-05-19 08:25:11 ----A---- C:\Windows\ntbtlog.txt
2009-05-19 00:33:31 ----D---- C:\Windows\McAfee.com
2009-05-18 19:17:30 ----D---- C:\Windows\BDOSCAN8
2009-05-16 15:42:05 ----D---- C:\Program Files\Trend Micro
2009-05-15 19:37:44 ----D---- C:\Program Files\Panda Security
2009-05-09 11:44:48 ----D---- C:\Windows\Sun
2009-05-05 08:15:04 ----A---- C:\Hello.exe
2009-05-04 23:06:00 ----D---- C:\Program Files\Microsoft SDKs
2009-05-04 22:58:21 ----D---- C:\Program Files\Debugging Tools for Windows
2009-05-04 22:46:11 ----D---- C:\Program Files\Microsoft Visual Studio 8
2009-05-03 21:31:28 ----D---- C:\Test
2009-05-02 15:07:11 ----A---- C:\Windows\system32\mshtmled.dll
2009-05-02 15:07:11 ----A---- C:\Windows\system32\icardie.dll
2009-05-02 15:07:10 ----A---- C:\Windows\system32\mshtmler.dll
2009-05-02 15:07:10 ----A---- C:\Windows\system32\jsproxy.dll
2009-05-02 15:07:10 ----A---- C:\Windows\system32\ieui.dll
2009-05-02 15:07:10 ----A---- C:\Windows\system32\admparse.dll
2009-05-02 15:07:09 ----A---- C:\Windows\system32\msls31.dll
2009-05-02 15:07:09 ----A---- C:\Windows\system32\iernonce.dll
2009-05-02 15:07:09 ----A---- C:\Windows\system32\corpol.dll
2009-05-02 15:07:08 ----A---- C:\Windows\system32\imgutil.dll
2009-05-02 15:07:08 ----A---- C:\Windows\system32\ieakeng.dll
2009-05-02 15:07:08 ----A---- C:\Windows\system32\dxtrans.dll
2009-05-02 15:07:08 ----A---- C:\Windows\system32\dxtmsft.dll
2009-05-02 15:07:07 ----A---- C:\Windows\system32\occache.dll
2009-05-02 15:07:07 ----A---- C:\Windows\system32\msrating.dll
2009-05-02 15:07:07 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-05-02 15:07:07 ----A---- C:\Windows\system32\licmgr10.dll
2009-05-02 15:07:07 ----A---- C:\Windows\system32\inseng.dll
2009-05-02 15:07:07 ----A---- C:\Windows\system32\iepeers.dll
2009-05-02 15:07:07 ----A---- C:\Windows\system32\ieaksie.dll
2009-05-02 15:07:06 ----A---- C:\Windows\system32\WinFXDocObj.exe
2009-05-02 15:07:06 ----A---- C:\Windows\system32\wextract.exe
2009-05-02 15:07:06 ----A---- C:\Windows\system32\webcheck.dll
2009-05-02 15:07:06 ----A---- C:\Windows\system32\mstime.dll
2009-05-02 15:07:06 ----A---- C:\Windows\system32\msfeedssync.exe
2009-05-02 15:07:06 ----A---- C:\Windows\system32\iesetup.dll
2009-05-02 15:07:06 ----A---- C:\Windows\system32\ieakui.dll
2009-05-02 15:07:05 ----A---- C:\Windows\system32\pngfilt.dll
2009-05-02 15:07:05 ----A---- C:\Windows\system32\msfeeds.dll
2009-05-02 15:07:05 ----A---- C:\Windows\system32\advpack.dll
2009-05-02 15:07:04 ----A---- C:\Windows\system32\ieapfltr.dll
2009-05-02 15:07:03 ----A---- C:\Windows\system32\vbscript.dll
2009-05-02 15:07:03 ----A---- C:\Windows\system32\jscript.dll
2009-05-02 15:07:02 ----A---- C:\Windows\system32\url.dll
2009-05-02 15:07:02 ----A---- C:\Windows\system32\iedkcs32.dll
2009-05-02 15:06:58 ----A---- C:\Windows\system32\mshta.exe
2009-05-02 15:06:58 ----A---- C:\Windows\system32\iexpress.exe
2009-05-02 15:06:58 ----A---- C:\Windows\system32\iesysprep.dll
2009-05-02 15:06:57 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2009-05-02 15:06:57 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2009-05-02 15:06:57 ----A---- C:\Windows\system32\PDMSetup.exe
2009-05-02 15:06:57 ----A---- C:\Windows\system32\ieUnatt.exe
2009-05-02 15:06:56 ----A---- C:\Windows\system32\wininet.dll
2009-05-02 15:06:56 ----A---- C:\Windows\system32\iertutil.dll
2009-05-02 15:06:56 ----A---- C:\Windows\system32\ie4uinit.exe
2009-05-02 15:06:55 ----A---- C:\Windows\system32\urlmon.dll
2009-05-02 15:06:53 ----A---- C:\Windows\system32\ieframe.dll
2009-05-02 15:06:51 ----A---- C:\Windows\system32\mshtml.dll
2009-05-02 13:24:58 ----D---- C:\perflogs
2009-05-02 13:01:17 ----D---- C:\Downloads
2009-05-02 10:15:41 ----D---- C:\Users\Narwal\AppData\Roaming\MusicNet
======List of files/folders modified in the last 1 months======
2009-05-21 08:01:43 ----D---- C:\Windows\Prefetch
2009-05-21 08:01:29 ----D---- C:\Windows\Temp
2009-05-21 07:25:27 ----D---- C:\Users\Narwal\AppData\Roaming\SiteAdvisor
2009-05-20 07:31:14 ----AD---- C:\Windows\System32
2009-05-19 22:51:36 ----D---- C:\Program Files\Common Files
2009-05-19 20:24:10 ----SD---- C:\Windows\Downloaded Program Files
2009-05-19 19:11:07 ----D---- C:\Windows\system32\drivers
2009-05-19 19:11:03 ----RD---- C:\Program Files
2009-05-19 19:11:03 ----HD---- C:\ProgramData
2009-05-19 08:25:11 ----D---- C:\Windows
2009-05-18 18:43:14 ----D---- C:\Windows\inf
2009-05-18 18:43:14 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-05-18 13:25:35 ----SHD---- C:\System Volume Information
2009-05-16 20:25:20 ----D---- C:\Program Files\LimeWire
2009-05-16 20:24:56 ----D---- C:\Users\Narwal\AppData\Roaming\LimeWire
2009-05-15 12:28:14 ----D---- C:\Windows\system32\Tasks
2009-05-15 12:28:12 ----D---- C:\Windows\Tasks
2009-05-15 12:01:28 ----D---- C:\Windows\winsxs
2009-05-14 03:03:21 ----D---- C:\Windows\system32\catroot
2009-05-14 03:02:57 ----D---- C:\Program Files\Windows Mail
2009-05-13 20:08:02 ----D---- C:\Program Files\Internet Explorer
2009-05-13 07:19:26 ----D---- C:\Windows\system32\catroot2
2009-05-04 23:28:51 ----SHD---- C:\Windows\Installer
2009-05-04 23:28:17 ----D---- C:\ProgramData\Microsoft Help
2009-05-04 23:22:09 ----D---- C:\Windows\Microsoft.NET
2009-05-04 23:21:01 ----RSD---- C:\Windows\assembly
2009-05-04 23:06:00 ----D---- C:\Program Files\Common Files\microsoft shared
2009-05-04 22:50:25 ----SD---- C:\Users\Narwal\AppData\Roaming\Microsoft
2009-05-04 22:50:25 ----SD---- C:\ProgramData\Microsoft
2009-05-04 22:46:15 ----D---- C:\Program Files\Microsoft Office
2009-05-02 15:11:00 ----D---- C:\Windows\system32\migration
2009-05-02 15:11:00 ----D---- C:\Windows\system32\en-US
2009-05-02 15:11:00 ----D---- C:\Windows\PolicyDefinitions
2009-05-02 14:57:54 ----D---- C:\Program Files\Google
2009-05-02 14:36:58 ----D---- C:\Program Files\TOSHIBA Games
2009-05-02 14:33:24 ----D---- C:\Program Files\InterVideo
2009-05-02 14:33:17 ----D---- C:\ProgramData\Ulead Systems
2009-05-02 14:33:17 ----D---- C:\Program Files\Common Files\Ulead Systems
2009-05-02 14:30:32 ----HD---- C:\Program Files\InstallShield Installation Information
2009-05-02 14:26:36 ----D---- C:\Users\Narwal\AppData\Roaming\Mozilla
2009-05-02 14:24:42 ----D---- C:\ProgramData\Google
2009-05-02 14:22:27 ----D---- C:\ProgramData\Napster
2009-05-02 14:15:46 ----D---- C:\Program Files\TotalImageConverter
2009-05-02 14:15:16 ----D---- C:\Users\Narwal\AppData\Roaming\yahoo!
2009-05-02 14:15:16 ----D---- C:\ProgramData\Yahoo!
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 MPFP;MPFP; C:\Windows\System32\Drivers\Mpfp.sys [2007-03-02 120360]
R3 AgereSoftModem;TOSHIBA V92 Software Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2006-08-31 1161152]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2007-02-28 694784]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2007-11-16 14208]
R3 GEARAspiWDM;GEARAspiWDM; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-29 1476096]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2006-11-08 1647976]
R3 mfeavfk;McAfee Inc.; C:\Windows\system32\drivers\mfeavfk.sys [2007-06-25 71496]
R3 mfebopk;McAfee Inc.; C:\Windows\system32\drivers\mfebopk.sys [2007-06-25 34184]
R3 mfehidk;McAfee Inc.; C:\Windows\system32\drivers\mfehidk.sys [2007-06-25 171240]
R3 mfesmfk;McAfee Inc.; C:\Windows\system32\drivers\mfesmfk.sys [2007-06-25 37480]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-04 59392]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2007-08-29 82432]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2006-10-27 179896]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 16128]
R3 tifm21;tifm21; C:\Windows\system32\drivers\tifm21.sys [2006-07-06 168448]
S1 Tosrfcom;Tosrfcom; C:\Windows\system32\drivers\Tosrfcom.sys [2005-08-01 64896]
S3 ALSysIO;ALSysIO; \??\C:\Users\Narwal\AppData\Local\Temp\ALSysIO.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-29 1476096]
S3 mferkdk;McAfee Inc.; C:\Windows\system32\drivers\mferkdk.sys [2007-06-25 32008]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2006-11-02 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2006-11-02 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 1781760]
S3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2006-10-23 9216]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2008-02-18 30464]
S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2006-11-02 71552]
S3 V0250Dev;Live! Cam Notebook Pro; C:\Windows\system32\DRIVERS\V0250Dev.sys [2007-08-30 169696]
S3 V0250Vfx;V0250Vfx; C:\Windows\system32\DRIVERS\V0250Vfx.sys [2006-03-24 6272]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2006-11-02 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2006-11-02 82560]
S4 KR10I;KR10I; C:\Windows\system32\drivers\kr10i.sys [2007-02-19 219520]
S4 KR10N;KR10N; C:\Windows\system32\drivers\kr10n.sys [2007-02-19 211072]
S4 KR3NPXP;KR3NPXP; C:\Windows\system32\drivers\kr3npxp.sys [2006-09-27 479488]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2006-09-12 9216]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-02-18 110592]
R2 CFSvcs;ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [2006-11-14 40960]
R2 McAfee HackerWatch Service;McAfee HackerWatch Service; C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe [2007-02-13 540776]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-01-09 767976]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-01-25 2458128]
R2 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2007-01-16 362064]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2007-04-12 353368]
R2 McRedirector;McAfee Redirector Service; c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe [2007-03-08 256096]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2007-06-25 144960]
R2 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2007-01-25 643664]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2007-06-19 841256]
R2 MPS9;McAfee Privacy Service; C:\PROGRA~1\McAfee\MPS\mps.exe [2007-04-18 906792]
R2 MSK80Service;McAfee SpamKiller Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2007-01-17 29264]
R2 pinger;pinger; C:\TOSHIBA\IVP\ISM\pinger.exe [2007-01-25 136816]
R2 Swupdtmr;Swupdtmr; c:\TOSHIBA\IVP\swupdate\swupdtmr.exe [2007-01-25 63096]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2006-05-25 114688]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe [2006-12-20 428152]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2006-11-01 77824]
S3 Emproxy;McAfee E-mail Proxy; C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe [2007-10-05 341328]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-05-22 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-02-19 504104]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
-----------------EOF-----------------