
UNSOLVED
Malware effecting MSN contacts
Hello,
My computer is sending random messages to my msn contacts, I think its contracted a virus.
Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 11:49:55 PM, on 06/03/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Users\mike lee\AppData\Roaming\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.shoptoshiba.ca/welcome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [lsass] C:\Users\mike lee\AppData\Roaming\WindowsLogin\winlogin.exe.exe
O4 - HKCU\..\Run: [toscdspd] TOSCDSPD.EXE
O4 - HKCU\..\Run: [Winlogon] C:\Users\mike lee\AppData\Roaming\sys\lsass.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
--
End of file - 4269 bytes
Responses (11)
Solutions (0)
- bizkid10
1. Go HERE and download File Lister.
- Save it to your Desktop
- Rt Click ->> Extract all ->> And extract it to your Desktop
- Additional help on extracting zip files can be found HERE
- Open the File Lister Folder.
- Note: Leave the FileLister.vbe file in the folder and run it from there.
- Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
- As the program runs, it will appear that nothing is happening.
- When the program is fnished it will produce a log for you C:\Files.txt
Copy and paste the contents of that log in your reply.Reply It asks if it should create a C:\Files.txt and I click yes but I still get a blank notepad..
But heres some stuff inside the folder
C:\hiberfil.sys
C:\IO.SYS
C:\MSDOS.SYS
C:\pagefile.sys
C:\$Recycle.Bin\S-1-5-21-2502432022-3678871241-3420521490-1000\desktop.ini
C:\Boot\bootstat.dat
C:\Program Files\desktop.ini
C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini
C:\Program Files\Microsoft Games\Chess\desktop.ini
C:\Program Files\Microsoft Games\FreeCell\desktop.ini
C:\Program Files\Microsoft Games\Hearts\desktop.ini
C:\Program Files\Microsoft Games\Mahjong\desktop.ini
C:\Program Files\Microsoft Games\Purble Place\desktop.ini
C:\Program Files\Microsoft Games\Solitaire\desktop.ini
C:\Program Files\Microsoft Games\SpiderSolitaire\desktop.ini
C:\Program Files\Windows Mail\WinMail.exe
C:\ProgramData\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\Ringtones\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC\Desktop.ini
C:\Users\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\Ringtones\desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Tablet PC\Desktop.ini
C:\Users\Default\NTUSER.DAT
C:\Users\Default\AppData\Local\Microsoft\Windows\History\desktop.ini
C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2LWRLL5O\desktop.ini
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\515GRBWV\desktop.ini
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6O1C4XR1\desktop.ini
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WBGN4O8H\desktop.ini
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Desktop.ini
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
C:\Users\mike lee\NTUSER.DAT
C:\Users\mike lee\ntuser.ini
C:\Users\mike lee\AppData\Local\Microsoft\Feeds Cache\index.dat
C:\Users\mike lee\AppData\Local\Microsoft\Feeds Cache\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Feeds Cache\31HHR6L7\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Feeds Cache\97K75FNZ\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Feeds Cache\9NU3H7XQ\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Feeds Cache\J62MP141\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\UsrClass.dat
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\History\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\mike lee\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\History\Low\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
C:\Users\mike lee\AppData\Local\Microsoft\Windows\History\Low\History.IE5\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1Q14F643\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\319L77R6\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I6ERNJW6\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W05QI0J1\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\6HWM0DMT\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\K4GY71UY\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OJQEPAEG\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UG1VSNLY\desktop.ini
C:\Users\mike lee\AppData\Local\Microsoft\Windows Mail\Stationery\Desktop.ini
C:\Users\mike lee\AppData\LocalLow\desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat
C:\Users\mike lee\AppData\Roaming\Microsoft\Office\Recent\index.dat
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\IECompatCache\index.dat
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\IECompatCache\Low\index.dat
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\IETldCache\Low\index.dat
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Libraries\desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\PrivacIE\Low\index.dat
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\SendTo\Desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
C:\Users\mike lee\AppData\Roaming\Microsoft\Windows\Themes\slideshow.ini
C:\Users\mike lee\AppData\Roaming\sys\lsass.exe
C:\Users\mike lee\Contacts\desktop.ini
C:\Users\mike lee\Desktop\desktop.ini
C:\Users\mike lee\Documents\desktop.ini
C:\Users\mike lee\Downloads\desktop.ini
C:\Users\mike lee\Favorites\desktop.ini
C:\Users\mike lee\Favorites\Links\desktop.ini
C:\Users\mike lee\Favorites\Links for United States\desktop.ini
C:\Users\mike lee\Links\desktop.ini
C:\Users\mike lee\Music\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Beyonce\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Beyonce\I Am Sasha Fierce\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Buckcherry\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Buckcherry\Fifteen\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\David Archuleta\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\David Archuleta\David Archuleta\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Dr. Dre\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Dr. Dre\2001\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Dr. Dre\Napster\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Green Day\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Green Day\Nimrod\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Jason Mraz\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Jason Mraz\Waiting for My Rocket to Come\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Jonas Brothers\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Jonas Brothers\A Little Bit Longer\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Lindsay Lohan\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Lindsay Lohan\Speak\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Pink\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Pink\Funhouse\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Taylor Swift\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\Taylor Swift\Fearless\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\The Fray\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\The Fray\How To Save A Life\desktop.ini
C:\Users\mike lee\Music\iTunes\iTunes Media\Music\The Fray\The Fray\desktop.ini
C:\Users\mike lee\Pictures\desktop.ini
C:\Users\mike lee\Saved Games\desktop.ini
C:\Users\mike lee\Searches\desktop.ini
C:\Users\mike lee\Videos\desktop.ini
C:\Users\Public\desktop.ini
C:\Users\Public\Desktop\desktop.ini
C:\Users\Public\Documents\desktop.ini
C:\Users\Public\Downloads\desktop.ini
C:\Users\Public\Libraries\desktop.ini
C:\Users\Public\Music\desktop.ini
C:\Users\Public\Music\Sample Music\desktop.ini
C:\Users\Public\Pictures\desktop.ini
C:\Users\Public\Pictures\Sample Pictures\desktop.ini
C:\Users\Public\Recorded TV\desktop.ini
C:\Users\Public\Recorded TV\Sample Media\desktop.ini
C:\Users\Public\Videos\desktop.ini
C:\Users\Public\Videos\Sample Videos\desktop.ini
C:\Windows\assembly\pubpol22.dat
C:\Windows\assembly\Desktop.ini
C:\Windows\assembly\NativeImages_v2.0.50727_32\indexdf.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\indexe0.dat
C:\Windows\BitLockerDiscoveryVolumeContents\autorun.inf
C:\Windows\Downloaded Program Files\desktop.ini
C:\Windows\Fonts\StaticCache.dat
C:\Windows\Globalization\MCT\MCT-AU\Wallpaper\desktop.ini
C:\Windows\Globalization\MCT\MCT-CA\Wallpaper\desktop.ini
C:\Windows\Globalization\MCT\MCT-GB\Link\desktop.ini
C:\Windows\Globalization\MCT\MCT-GB\Wallpaper\desktop.ini
C:\Windows\Globalization\MCT\MCT-US\Link\desktop.ini
C:\Windows\Globalization\MCT\MCT-US\Wallpaper\desktop.ini
C:\Windows\Globalization\MCT\MCT-ZA\Wallpaper\desktop.ini
C:\Windows\Media\Desktop.ini
C:\Windows\Media\Afternoon\Desktop.ini
C:\Windows\Media\Calligraphy\Desktop.ini
C:\Windows\Media\Characters\Desktop.ini
C:\Windows\Media\Cityscape\Desktop.ini
C:\Windows\Media\Delta\Desktop.ini
C:\Windows\Media\Festival\Desktop.ini
C:\Windows\Media\Garden\Desktop.ini
C:\Windows\Media\Heritage\Desktop.ini
C:\Windows\Media\Landscape\Desktop.ini
C:\Windows\Media\Quirky\Desktop.ini
C:\Windows\Media\Raga\Desktop.ini
C:\Windows\Media\Savanna\Desktop.ini
C:\Windows\Media\Sonata\Desktop.ini
C:\Windows\Offline Web Pages\desktop.ini
C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
C:\Windows\System32\api-ms-win-security-lsalookup-l1-1-0.dll
C:\Windows\System32\api-ms-win-security-sddl-l1-1-0.dll
C:\Windows\System32\api-ms-win-service-core-l1-1-0.dll
C:\Windows\System32\api-ms-win-service-management-l1-1-0.dll
C:\Windows\System32\api-ms-win-service-management-l2-1-0.dll
C:\Windows\System32\api-ms-win-service-winsvc-l1-1-0.dll
C:\Windows\System32\desktop.ini
C:\Windows\Tasks\SA.DAT
C:\Windows\Web\Wallpaper\Architecture\Desktop.ini
C:\Windows\Web\Wallpaper\Characters\Desktop.ini
C:\Windows\Web\Wallpaper\Landscapes\Desktop.ini
C:\Windows\Web\Wallpaper\Nature\Desktop.ini
C:\Windows\Web\Wallpaper\Scenes\Desktop.ini
C:\Windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
C:\Windows\winsxs\x86_microsoft-windows-minioapinamespace_31bf3856ad364e35_6.1.7600.16385_none_6c9a1ef812f0bb30\api-ms-win-security-lsalookup-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minioapinamespace_31bf3856ad364e35_6.1.7600.16385_none_6c9a1ef812f0bb30\api-ms-win-security-sddl-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minioapinamespace_31bf3856ad364e35_6.1.7600.16385_none_6c9a1ef812f0bb30\api-ms-win-service-core-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minioapinamespace_31bf3856ad364e35_6.1.7600.16385_none_6c9a1ef812f0bb30\api-ms-win-service-management-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minioapinamespace_31bf3856ad364e35_6.1.7600.16385_none_6c9a1ef812f0bb30\api-ms-win-service-management-l2-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minioapinamespace_31bf3856ad364e35_6.1.7600.16385_none_6c9a1ef812f0bb30\api-ms-win-service-winsvc-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-console-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-datetime-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-debug-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-delayload-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-errorhandling-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-fibers-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-file-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-handle-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-heap-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-interlocked-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-io-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-localization-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-localregistry-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-memory-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-misc-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-namedpipe-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-processenvironment-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-processthreads-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-profile-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-rtlsupport-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-string-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-synch-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-sysinfo-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-threadpool-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-util-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-xstate-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-security-base-l1-1-0.dll
C:\Windows\winsxs\x86_microsoft-windows-s..ccessagent-binaries_31bf3856ad364e35_6.1.7600.16385_none_de06b4fbd5b45f78\autorun.infANDDDDDD~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
BitTorrent
Microsoft Office Enterprise 2007
TOSHIBA Extended Tiles for Windows Mobility Center
Messenger Plus! Live
Mozilla Firefox (3.6)
OnlinePlay 1.0
Synaptics Pointing Device Driver
VLC media player 1.0.5
Windows Live Essentials
TOSHIBA Speech System SR Engine(U.S.) Version1.0
Bonjour
HiJackThis
TOSHIBA ConfigFree
TOSHIBA Assist
QuickTime
Windows Live Upload Tool
MSVCRT
Java(TM) 6 Update 18
TOSHIBA Hardware Setup
Java(TM) 6 Update 3
Apple Application Support
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
Cisco EAP-FAST Module
Windows Live Sign-in Assistant
TOSHIBA Supervisor Password
TOSHIBA Disc Creator
Cisco PEAP Module
Apple Software Update
Catalyst Control Center - Branding
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
iTunes
Windows Live Essentials
Cisco LEAP Module
MSXML 4.0 SP2 (KB954430)
Realtek 8169 8168 8101E 8102E Ethernet Driver
REALTEK RTL8187B Wireless LAN Driver
Microsoft Silverlight
Microsoft Office Access MUI (English) 2007
Microsoft Office 2007 Service Pack 2 (SP2)
Update for Microsoft Office Access 2007 Help (KB963663)
Microsoft Office Excel MUI (English) 2007
Update for Microsoft Office Excel 2007 Help (KB963678)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office 2007 Service Pack 2 (SP2)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Microsoft Office Publisher MUI (English) 2007
Update for Microsoft Office Publisher 2007 Help (KB963667)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Outlook MUI (English) 2007
Update for Microsoft Office Outlook 2007 Help (KB963677)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Word MUI (English) 2007
Microsoft Office 2007 Service Pack 2 (SP2)
Update for Microsoft Office Word 2007 Help (KB963665)
Microsoft Office Proof (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proof (French) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office 2007 Service Pack 2 (SP2)
Update for Microsoft Office Word 2007 (KB974561)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office system 2007 (972581)
Update for Microsoft Office InfoPath 2007 (KB976416)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office Excel 2007 (KB973593)
Update for Outlook 2007 Junk Email Filter (kb977719)
Update for 2007 Microsoft Office System (KB967642)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office system 2007 (KB974234)
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office 2007 Service Pack 2 (SP2)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Microsoft Office Shared MUI (English) 2007
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Script Editor Help (KB963671)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office OneNote MUI (English) 2007
Update for Microsoft Office OneNote 2007 Help (KB963670)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Groove MUI (English) 2007
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office 2007 Service Pack 2 (SP2)
CD/DVD Drive Acoustic Silencer
Windows Live Messenger
Apple Mobile Device Support
Windows 7 Upgrade Advisor
Adobe Reader 8.1.2
TOSHIBA Recovery Disc Creator
Atheros Driver Installation Program
MSXML 4.0 SP2 (KB941833)
WinZip 14.0
Realtek USB 2.0 Card Reader
Windows Live Communications Platform
TOSHIBA Speech System Applications
Microsoft Choice Guard
MSXML 4.0 SP2 (KB973688)
Windows Live CallReply - bizkid10
1. Please download The Avenger by Swandog46 to your Desktop.
- Click on Avenger.zip to open the file
- Extract avenger.exe to your desktop(How to extract (decompress) zipped or compressed files, help in the link here: )
2. Copy all the text contained in the bold below to your Clipboard by highlighting it and pressing (Ctrl+C):
Files to delete:
C:\Users\mike lee\AppData\Roaming\svchost.exe
C:\Users\mike lee\AppData\Roaming\WindowsLogin\winlogin.exe.exe
C:\Users\mike lee\AppData\Roaming\sys\lsass.exe
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
3. Now, start The Avenger program by clicking on its icon on your desktop.
- Select Load Script
- Select Paste from Clipboard
- The information should now appear in the Open window
- Select Execute
- Answer Yes When prompted "Are you sure you want to execute the current script?"
4. The Avenger will automatically do the following:
- It will Restart your computer.
- On reboot, it will briefly open a black command window on your desktop, this is normal.
- After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
- The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your replyReply //////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows NT 6.1 (build 7600)
Mon Mar 08 20:56:24 2010
20:56:24: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
//////////////////////////////////////////
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows NT 6.1 (build 7600)
Mon Mar 08 20:56:31 2010
20:56:31: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
//////////////////////////////////////////
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows NT 6.1 (build 7600)
Mon Mar 08 20:57:09 2010
20:57:09: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
//////////////////////////////////////////
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows Vista
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
File "C:\Users\mike lee\AppData\Roaming\svchost.exe" deleted successfully.
Error: file "C:\Users\mike lee\AppData\Roaming\WindowsLogin\winlogin.exe.exe" not found!
Deletion of file "C:\Users\mike lee\AppData\Roaming\WindowsLogin\winlogin.exe.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
File "C:\Users\mike lee\AppData\Roaming\sys\lsass.exe" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.Reply Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 11:07:17 PM, on 08/03/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Messenger Plus! Live\Log Viewer.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.shoptoshiba.ca/welcome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [lsass] C:\Users\mike lee\AppData\Roaming\WindowsLogin\winlogin.exe.exe
O4 - HKCU\..\Run: [toscdspd] TOSCDSPD.EXE
O4 - HKCU\..\Run: [Winlogon] C:\Users\mike lee\AppData\Roaming\sys\lsass.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
--
End of file - 4180 bytesReply - bizkid10
1. Rerun Hijackthis (scan only) and place checks beside the following entries
O4 - HKCU\..\Run: [lsass] C:\Users\mike lee\AppData\Roaming\WindowsLogin\winlogin.exe.exe
O4 - HKCU\..\Run: [Winlogon] C:\Users\mike lee\AppData\Roaming\sys\lsass.exe
Close all other open windows except Hijackthis and Select " Fix checked"
Close Hijackthis ->> Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log
Reply Sorry for the late reply:
Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 2:53:42 AM, on 12/03/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.shoptoshiba.ca/welcome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [toscdspd] TOSCDSPD.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
--
End of file - 3905 bytesReply

billyboica
2 Posts
699
0
Posted March 8th, 2010 17:00
A quick fix for your problem is to change your MSN password.