UNSOLVED

bizkid10

updated

17 years ago

B

bizkid10

52 Posts

0

2481

March 6th, 2010 19:00

Malware effecting MSN contacts

Hello,


My computer is sending random messages to my msn contacts, I think  its contracted a virus.

 

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 11:49:55 PM, on 06/03/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Users\mike lee\AppData\Roaming\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.shoptoshiba.ca/welcome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [lsass] C:\Users\mike lee\AppData\Roaming\WindowsLogin\winlogin.exe.exe
O4 - HKCU\..\Run: [toscdspd] TOSCDSPD.EXE
O4 - HKCU\..\Run: [Winlogon] C:\Users\mike lee\AppData\Roaming\sys\lsass.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe

--
End of file - 4269 bytes

  • 699

    0

    Posted March 8th, 2010 17:00

    A quick fix for your problem is to change your MSN password.

  • bamajim

    10376 Posts

    699

    1

    Posted March 8th, 2010 17:00

     

    bizkid10

    1. Go HERE and download File Lister.
    • Save it to your Desktop
    • Rt Click ->> Extract all ->> And extract it to your Desktop
    • Additional help on extracting zip files can be found HERE
    • Open the File Lister Folder.
    • Note: Leave the FileLister.vbe file in the folder and run it from there.
    • Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
    • As the program runs, it will appear that nothing is happening.
    • When the program is fnished it will produce a log for you C:\Files.txt

    Copy and paste the contents of that log in your reply.

     

  • bizkid10

    52 Posts

    699

    0

    Posted March 8th, 2010 17:00

    It asks if it should create a C:\Files.txt and I click yes but I still get a blank notepad..

    But heres some stuff inside the folder

    C:\hiberfil.sys
    C:\IO.SYS
    C:\MSDOS.SYS
    C:\pagefile.sys
    C:\$Recycle.Bin\S-1-5-21-2502432022-3678871241-3420521490-1000\desktop.ini
    C:\Boot\bootstat.dat
    C:\Program Files\desktop.ini
    C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini
    C:\Program Files\Microsoft Games\Chess\desktop.ini
    C:\Program Files\Microsoft Games\FreeCell\desktop.ini
    C:\Program Files\Microsoft Games\Hearts\desktop.ini
    C:\Program Files\Microsoft Games\Mahjong\desktop.ini
    C:\Program Files\Microsoft Games\Purble Place\desktop.ini
    C:\Program Files\Microsoft Games\Solitaire\desktop.ini
    C:\Program Files\Microsoft Games\SpiderSolitaire\desktop.ini
    C:\Program Files\Windows Mail\WinMail.exe
    C:\ProgramData\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\PlayTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\1\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\2\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\PlayTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\1\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\2\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\PlayTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\SupportTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\SupportTasks\1\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\PlayTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\1\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\2\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\PlayTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\1\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\2\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\PlayTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\1\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\2\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\PlayTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\1\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\2\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\PlayTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\1\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\2\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\PlayTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\0\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\1\desktop.ini
    C:\ProgramData\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\2\desktop.ini
    C:\ProgramData\Microsoft\Windows\Ringtones\desktop.ini
    C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Desktop.ini
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Desktop.ini
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC\Desktop.ini
    C:\Users\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\PlayTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\1\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\2\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\PlayTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\1\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\2\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\PlayTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\SupportTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\SupportTasks\1\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\PlayTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\1\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\2\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\PlayTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\1\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\2\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\PlayTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\1\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\2\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\PlayTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\1\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\2\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\PlayTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\1\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\2\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\PlayTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\0\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\1\desktop.ini
    C:\Users\All Users\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\2\desktop.ini
    C:\Users\All Users\Microsoft\Windows\Ringtones\desktop.ini
    C:\Users\All Users\Microsoft\Windows\Start Menu\desktop.ini
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\desktop.ini
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Desktop.ini
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games\Desktop.ini
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Tablet PC\Desktop.ini
    C:\Users\Default\NTUSER.DAT
    C:\Users\Default\AppData\Local\Microsoft\Windows\History\desktop.ini
    C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
    C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
    C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
    C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2LWRLL5O\desktop.ini
    C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\515GRBWV\desktop.ini
    C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6O1C4XR1\desktop.ini
    C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WBGN4O8H\desktop.ini
    C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Desktop.ini
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
    C:\Users\mike lee\NTUSER.DAT
    C:\Users\mike lee\ntuser.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Feeds Cache\index.dat
    C:\Users\mike lee\AppData\Local\Microsoft\Feeds Cache\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Feeds Cache\31HHR6L7\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Feeds Cache\97K75FNZ\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Feeds Cache\9NU3H7XQ\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Feeds Cache\J62MP141\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\UsrClass.dat
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\History\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\History\Low\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\History\Low\History.IE5\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1Q14F643\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\319L77R6\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I6ERNJW6\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W05QI0J1\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6HWM0DMT\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\K4GY71UY\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OJQEPAEG\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UG1VSNLY\desktop.ini
    C:\Users\mike lee\AppData\Local\Microsoft\Windows Mail\Stationery\Desktop.ini
    C:\Users\mike lee\AppData\LocalLow\desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat
    C:\Users\mike lee\AppData\Roaming\Microsoft\Office\Recent\index.dat
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\IECompatCache\index.dat
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\IECompatCache\Low\index.dat
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\IETldCache\Low\index.dat
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Libraries\desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\PrivacIE\Low\index.dat
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\SendTo\Desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
    C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Themes\slideshow.ini
    C:\Users\mike lee\AppData\Roaming\sys\lsass.exe
    C:\Users\mike lee\Contacts\desktop.ini
    C:\Users\mike lee\Desktop\desktop.ini
    C:\Users\mike lee\Documents\desktop.ini
    C:\Users\mike lee\Downloads\desktop.ini
    C:\Users\mike lee\Favorites\desktop.ini
    C:\Users\mike lee\Favorites\Links\desktop.ini
    C:\Users\mike lee\Favorites\Links for United States\desktop.ini
    C:\Users\mike lee\Links\desktop.ini
    C:\Users\mike lee\Music\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Beyonce\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Beyonce\I Am Sasha Fierce\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Buckcherry\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Buckcherry\Fifteen\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\David Archuleta\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\David Archuleta\David Archuleta\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Dr. Dre\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Dr. Dre\2001\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Dr. Dre\Napster\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Green Day\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Green Day\Nimrod\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Jason Mraz\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Jason Mraz\Waiting for My Rocket to Come\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Jonas Brothers\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Jonas Brothers\A Little Bit Longer\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Lindsay Lohan\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Lindsay Lohan\Speak\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Pink\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Pink\Funhouse\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Taylor Swift\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Taylor Swift\Fearless\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\The Fray\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\The Fray\How To Save A Life\desktop.ini
    C:\Users\mike lee\Music\iTunes\iTunes Media\Music\The Fray\The Fray\desktop.ini
    C:\Users\mike lee\Pictures\desktop.ini
    C:\Users\mike lee\Saved Games\desktop.ini
    C:\Users\mike lee\Searches\desktop.ini
    C:\Users\mike lee\Videos\desktop.ini
    C:\Users\Public\desktop.ini
    C:\Users\Public\Desktop\desktop.ini
    C:\Users\Public\Documents\desktop.ini
    C:\Users\Public\Downloads\desktop.ini
    C:\Users\Public\Libraries\desktop.ini
    C:\Users\Public\Music\desktop.ini
    C:\Users\Public\Music\Sample Music\desktop.ini
    C:\Users\Public\Pictures\desktop.ini
    C:\Users\Public\Pictures\Sample Pictures\desktop.ini
    C:\Users\Public\Recorded TV\desktop.ini
    C:\Users\Public\Recorded TV\Sample Media\desktop.ini
    C:\Users\Public\Videos\desktop.ini
    C:\Users\Public\Videos\Sample Videos\desktop.ini
    C:\Windows\assembly\pubpol22.dat
    C:\Windows\assembly\Desktop.ini
    C:\Windows\assembly\NativeImages_v2.0.50727_32\indexdf.dat
    C:\Windows\assembly\NativeImages_v2.0.50727_32\indexe0.dat
    C:\Windows\BitLockerDiscoveryVolumeContents\autorun.inf
    C:\Windows\Downloaded Program Files\desktop.ini
    C:\Windows\Fonts\StaticCache.dat
    C:\Windows\Globalization\MCT\MCT-AU\Wallpaper\desktop.ini
    C:\Windows\Globalization\MCT\MCT-CA\Wallpaper\desktop.ini
    C:\Windows\Globalization\MCT\MCT-GB\Link\desktop.ini
    C:\Windows\Globalization\MCT\MCT-GB\Wallpaper\desktop.ini
    C:\Windows\Globalization\MCT\MCT-US\Link\desktop.ini
    C:\Windows\Globalization\MCT\MCT-US\Wallpaper\desktop.ini
    C:\Windows\Globalization\MCT\MCT-ZA\Wallpaper\desktop.ini
    C:\Windows\Media\Desktop.ini
    C:\Windows\Media\Afternoon\Desktop.ini
    C:\Windows\Media\Calligraphy\Desktop.ini
    C:\Windows\Media\Characters\Desktop.ini
    C:\Windows\Media\Cityscape\Desktop.ini
    C:\Windows\Media\Delta\Desktop.ini
    C:\Windows\Media\Festival\Desktop.ini
    C:\Windows\Media\Garden\Desktop.ini
    C:\Windows\Media\Heritage\Desktop.ini
    C:\Windows\Media\Landscape\Desktop.ini
    C:\Windows\Media\Quirky\Desktop.ini
    C:\Windows\Media\Raga\Desktop.ini
    C:\Windows\Media\Savanna\Desktop.ini
    C:\Windows\Media\Sonata\Desktop.ini
    C:\Windows\Offline Web Pages\desktop.ini
    C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
    C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
    C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
    C:\Windows\System32\api-ms-win-security-lsalookup-l1-1-0.dll
    C:\Windows\System32\api-ms-win-security-sddl-l1-1-0.dll
    C:\Windows\System32\api-ms-win-service-core-l1-1-0.dll
    C:\Windows\System32\api-ms-win-service-management-l1-1-0.dll
    C:\Windows\System32\api-ms-win-service-management-l2-1-0.dll
    C:\Windows\System32\api-ms-win-service-winsvc-l1-1-0.dll
    C:\Windows\System32\desktop.ini
    C:\Windows\Tasks\SA.DAT
    C:\Windows\Web\Wallpaper\Architecture\Desktop.ini
    C:\Windows\Web\Wallpaper\Characters\Desktop.ini
    C:\Windows\Web\Wallpaper\Landscapes\Desktop.ini
    C:\Windows\Web\Wallpaper\Nature\Desktop.ini
    C:\Windows\Web\Wallpaper\Scenes\Desktop.ini
    C:\Windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
    C:\Windows\winsxs\x86_microsoft-windows-minioapinamespace_31bf3856ad364e35_6.1.7600.16385_none_6c9a1ef812f0bb30\api-ms-win-security-lsalookup-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minioapinamespace_31bf3856ad364e35_6.1.7600.16385_none_6c9a1ef812f0bb30\api-ms-win-security-sddl-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minioapinamespace_31bf3856ad364e35_6.1.7600.16385_none_6c9a1ef812f0bb30\api-ms-win-service-core-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minioapinamespace_31bf3856ad364e35_6.1.7600.16385_none_6c9a1ef812f0bb30\api-ms-win-service-management-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minioapinamespace_31bf3856ad364e35_6.1.7600.16385_none_6c9a1ef812f0bb30\api-ms-win-service-management-l2-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minioapinamespace_31bf3856ad364e35_6.1.7600.16385_none_6c9a1ef812f0bb30\api-ms-win-service-winsvc-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-console-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-datetime-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-debug-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-delayload-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-errorhandling-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-fibers-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-file-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-handle-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-heap-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-interlocked-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-io-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-localization-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-localregistry-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-memory-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-misc-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-namedpipe-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-processenvironment-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-processthreads-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-profile-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-rtlsupport-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-string-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-synch-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-sysinfo-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-threadpool-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-util-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-xstate-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-security-base-l1-1-0.dll
    C:\Windows\winsxs\x86_microsoft-windows-s..ccessagent-binaries_31bf3856ad364e35_6.1.7600.16385_none_de06b4fbd5b45f78\autorun.inf

    ANDDDDDD~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`

     

    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    BitTorrent
    Microsoft Office Enterprise 2007
    TOSHIBA Extended Tiles for Windows Mobility Center
    Messenger Plus! Live
    Mozilla Firefox (3.6)
    OnlinePlay 1.0
    Synaptics Pointing Device Driver
    VLC media player 1.0.5
    Windows Live Essentials
    TOSHIBA Speech System SR Engine(U.S.) Version1.0
    Bonjour
    HiJackThis
    TOSHIBA ConfigFree
    TOSHIBA Assist
    QuickTime
    Windows Live Upload Tool
    MSVCRT
    Java(TM) 6 Update 18
    TOSHIBA Hardware Setup
    Java(TM) 6 Update 3
    Apple Application Support
    TOSHIBA Speech System TTS Engine(U.S.) Version1.0
    Cisco EAP-FAST Module
    Windows Live Sign-in Assistant
    TOSHIBA Supervisor Password
    TOSHIBA Disc Creator
    Cisco PEAP Module
    Apple Software Update
    Catalyst Control Center - Branding
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    iTunes
    Windows Live Essentials
    Cisco LEAP Module
    MSXML 4.0 SP2 (KB954430)
    Realtek 8169 8168 8101E 8102E Ethernet Driver
    REALTEK RTL8187B Wireless LAN Driver
    Microsoft Silverlight
    Microsoft Office Access MUI (English) 2007
    Microsoft Office 2007 Service Pack 2 (SP2)
    Update for Microsoft Office Access 2007 Help (KB963663)
    Microsoft Office Excel MUI (English) 2007
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office 2007 Service Pack 2 (SP2)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Microsoft Office Publisher MUI (English) 2007
    Update for Microsoft Office Publisher 2007 Help (KB963667)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Outlook MUI (English) 2007
    Update for Microsoft Office Outlook 2007 Help (KB963677)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Word MUI (English) 2007
    Microsoft Office 2007 Service Pack 2 (SP2)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Microsoft Office Proof (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Proof (French) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Proofing (English) 2007
    Microsoft Office Enterprise 2007
    Microsoft Office 2007 Service Pack 2 (SP2)
    Update for Microsoft Office Word 2007 (KB974561)
    Security Update for Microsoft Office Outlook 2007 (KB972363)
    Security Update for Microsoft Office system 2007 (972581)
    Update for Microsoft Office InfoPath 2007 (KB976416)
    Security Update for Microsoft Office system 2007 (KB969613)
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Microsoft Office PowerPoint 2007 (KB957789)
    Security Update for Microsoft Office Publisher 2007 (KB969693)
    Security Update for Microsoft Office Excel 2007 (KB973593)
    Update for Outlook 2007 Junk Email Filter (kb977719)
    Update for 2007 Microsoft Office System (KB967642)
    Security Update for 2007 Microsoft Office System (KB973704)
    Security Update for Microsoft Office system 2007 (KB974234)
    Microsoft Office InfoPath MUI (English) 2007
    Microsoft Office 2007 Service Pack 2 (SP2)
    Update for Microsoft Office Infopath 2007 Help (KB963662)
    Microsoft Office Shared MUI (English) 2007
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Script Editor Help (KB963671)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office OneNote MUI (English) 2007
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Groove MUI (English) 2007
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Groove Setup Metadata MUI (English) 2007
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office 2007 Service Pack 2 (SP2)
    CD/DVD Drive Acoustic Silencer
    Windows Live Messenger
    Apple Mobile Device Support
    Windows 7 Upgrade Advisor
    Adobe Reader 8.1.2
    TOSHIBA Recovery Disc Creator
    Atheros Driver Installation Program
    MSXML 4.0 SP2 (KB941833)
    WinZip 14.0
    Realtek USB 2.0 Card Reader
    Windows Live Communications Platform
    TOSHIBA Speech System Applications
    Microsoft Choice Guard
    MSXML 4.0 SP2 (KB973688)
    Windows Live Call

  • bamajim

    10376 Posts

    699

    0

    Posted March 8th, 2010 17:00

     

    bizkid10

    1. Please download The Avenger by Swandog46 to your Desktop.
    • Click on Avenger.zip to open the file
    • Extract avenger.exe to your desktop(How to extract (decompress) zipped or compressed files, help in the link here: )

    2. Copy all the text contained in the bold below to your Clipboard by highlighting it and pressing (Ctrl+C):

    Files to delete:
    C:\Users\mike lee\AppData\Roaming\svchost.exe
    C:\Users\mike lee\AppData\Roaming\WindowsLogin\winlogin.exe.exe
    C:\Users\mike lee\AppData\Roaming\sys\lsass.exe


    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

    3. Now, start The Avenger program by clicking on its icon on your desktop.
    • Select Load Script
    • Select Paste from Clipboard
    • The information should now appear in the Open window
    • Select Execute
    • Answer Yes When prompted "Are you sure you want to execute the current script?"

    4. The Avenger will automatically do the following:
    • It will Restart your computer.
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

    5. Please copy/paste the content of c:\avenger.txt into your reply

     

  • bizkid10

    52 Posts

    699

    0

    Posted March 8th, 2010 18:00

    //////////////////////////////////////////
      Avenger Pre-Processor log
    //////////////////////////////////////////

    Platform: Windows NT 6.1 (build 7600)
    Mon Mar 08 20:56:24 2010

    20:56:24: Error: Invalid script.  A valid script must begin with a command directive.
    Aborting execution!


    //////////////////////////////////////////


    //////////////////////////////////////////
      Avenger Pre-Processor log
    //////////////////////////////////////////

    Platform: Windows NT 6.1 (build 7600)
    Mon Mar 08 20:56:31 2010

    20:56:31: Error: Invalid script.  A valid script must begin with a command directive.
    Aborting execution!


    //////////////////////////////////////////


    //////////////////////////////////////////
      Avenger Pre-Processor log
    //////////////////////////////////////////

    Platform: Windows NT 6.1 (build 7600)
    Mon Mar 08 20:57:09 2010

    20:57:09: Error: Invalid script.  A valid script must begin with a command directive.
    Aborting execution!


    //////////////////////////////////////////


    Logfile of The Avenger Version 2.0, (c) by Swandog46
    http://swandog46.geekstogo.com

    Platform:  Windows Vista

    *******************

    Script file opened successfully.
    Script file read successfully.

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Rootkit scan active.
    No rootkits found!

    File "C:\Users\mike lee\AppData\Roaming\svchost.exe" deleted successfully.

    Error:  file "C:\Users\mike lee\AppData\Roaming\WindowsLogin\winlogin.exe.exe" not found!
    Deletion of file "C:\Users\mike lee\AppData\Roaming\WindowsLogin\winlogin.exe.exe" failed!
    Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
      --> the object does not exist

    File "C:\Users\mike lee\AppData\Roaming\sys\lsass.exe" deleted successfully.

    Completed script processing.

    *******************

    Finished!  Terminate.

  • bamajim

    10376 Posts

    699

    0

    Posted March 8th, 2010 18:00

    bizkid10

    Rerun Hijackthis and post a fresh Hijackthis log

  • bizkid10

    52 Posts

    699

    0

    Posted March 8th, 2010 20:00

    Logfile of Trend Micro HijackThis v2.0.3 (BETA)
    Scan saved at 11:07:17 PM, on 08/03/2010
    Platform: Unknown Windows (WinNT 6.01.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16385)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskhost.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
    C:\Program Files\Messenger Plus! Live\Log Viewer.exe
    C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.shoptoshiba.ca/welcome
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [lsass] C:\Users\mike lee\AppData\Roaming\WindowsLogin\winlogin.exe.exe
    O4 - HKCU\..\Run: [toscdspd] TOSCDSPD.EXE
    O4 - HKCU\..\Run: [Winlogon] C:\Users\mike lee\AppData\Roaming\sys\lsass.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe

    --
    End of file - 4180 bytes

  • bamajim

    10376 Posts

    699

    0

    Posted March 9th, 2010 16:00

     

    bizkid10

    1. Rerun Hijackthis (scan only) and place checks beside the following entries

    • O4 - HKCU\..\Run: [lsass] C:\Users\mike lee\AppData\Roaming\WindowsLogin\winlogin.exe.exe
      O4 - HKCU\..\Run: [Winlogon] C:\Users\mike lee\AppData\Roaming\sys\lsass.exe

    Close all other open windows except Hijackthis and Select " Fix checked"

    Close Hijackthis ->> Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log

     

  • bizkid10

    52 Posts

    699

    0

    Posted March 11th, 2010 23:00

    Sorry for the late reply:

     

    Logfile of Trend Micro HijackThis v2.0.3 (BETA)
    Scan saved at 2:53:42 AM, on 12/03/2010
    Platform: Unknown Windows (WinNT 6.01.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16385)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.shoptoshiba.ca/welcome
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [toscdspd] TOSCDSPD.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe

    --
    End of file - 3905 bytes

  • bamajim

    10376 Posts

    143

    0

    Posted March 19th, 2010 09:00

    bizkid10

    Sorry for the delay. You still require help with this?