Author Topic: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove  (Read 4180 times)

0 Members and 1 Guest are viewing this topic.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6366
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #15 on: March 04, 2012, 01:04:16 AM »
If Java 6 update 26 is your current version then we need to update to 31, do the following:

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version.
For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system.
The most current version of Sun Java is: Java Runtime Environment Version 6 Update 31.

  • Go to Sun Java
  • Select Windows 7/XP/Vista/2000/2003/2008 If using 64 bit OS Select Information about the 64-bit Java plug-in and follow prompts
  • Install the new version by running the newly-downloaded file with the java icon which will be at your desktop, and follow the on-screen instructions.
  • Reboot your computer

Let me know if any other issues..

Kevin

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6366
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #16 on: March 07, 2012, 08:13:36 AM »
Are you still with us Armaneus?

Offline Armaneus

  • Bronze Member
  • Posts: 15
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #17 on: March 09, 2012, 12:18:52 AM »
Still with you all, just been busy with work. Downloading java now.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6366
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #18 on: March 09, 2012, 01:17:44 AM »
OK, give me an update when you`re ready.... :)1

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6366
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #19 on: March 13, 2012, 03:19:03 AM »
What`s happening  :sd

Offline Armaneus

  • Bronze Member
  • Posts: 15
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #20 on: March 15, 2012, 04:22:49 PM »
Scanning now. I'm really sorry about the long wait, getting used to work schedule and not been on the computer as much.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6366
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #21 on: March 15, 2012, 04:30:39 PM »
OK, give me an update when you`re ready, also post ESET log if it completes...

Offline Armaneus

  • Bronze Member
  • Posts: 15
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #22 on: March 16, 2012, 08:32:09 PM »
Still scanning, hung up at 64% on a java update.
It's saying it's scanning C:\Program Files\Java\jdk1.6.0_21\lib

Gonna let it continue, but I'm guessing I may have to remove that update as well.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6366
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #23 on: March 17, 2012, 01:12:44 AM »
That appears to be Java 6 update 21 you are showing as the sticking point. try the following:

Step 1

Download and Run JavaRA
Please download JavaRa and save the file to your desktop.
  • Right click and Extract All and a new folder called "JavaRa" will be extracted
  • Once extracted, open that folder and run JavaRa.exe with the picture.
  • Select your Language which is English I assume.
  • Click Search For Updates
  • Select Update Using jucheck.exe
  • Click Search
  • If a newer version is found, allow it to be installed
  • Uncheck the Google Toolbar option, if offered. (if you don't want the Google tool bar)
  • When complete, click Remove Older Versions in the JavaRa interface and allow it to proceed
  • When that is complete, click Additional Tasks, then select Remove Useless JRE Files and click Go
  • It will now begin to remove older versions.
  • Exit the tool when complete.
Reboot Your Computer.

Step 2

Download TFC  to your desktop, from either of the following links
 Link 1
 Link 2
  • Save any open work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program. Vista or Windows 7 users right click and select “Run as Administartor”
  • If prompted, click "Yes" to reboot.
TFC will automatically close any open programs, including your Desktop. Let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds.  TFC may re-boot your system, if not Re-boot it yourself to  complete cleaning process <---- Very Important

Keep TFC it is an excellent utility to keep your system optimized, it empties all user temp folders, Java cache etc etc.  Always remember to re-boot after a run, even if not prompted

Step 3

Run this online Quickscan by BitDefender, available here http://quickscan.bitdefender.com/#  hit the Scan Now tab, when finished there is an option to "view report" do that, Hover your cursor over "view report" and it will open, copy and paste to next reply....

Let me see the log from BitDefender, also give an update on any remaining issues or concerns....

Thanks,

Kevin

Offline Armaneus

  • Bronze Member
  • Posts: 15
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #24 on: March 18, 2012, 08:34:11 PM »
The link for JavaRa did not work. I did remove the java updates using the Uninstall programs on the Control Panel. I then ran TFC and scanned with bitdefender. It did not find anything. Here's the log:




QuickScan 32-bit v0.9.9.111
---------------------------
Scan date:  Sun Mar 18 19:28:08 2012
Machine ID: BC40D758



No infection found.
-------------------



Processes
---------
            Ad-Aware Tray Application                5928    C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
            Boingo Wi-Fi                             4324    C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
            Brother ControlCenter                    4632    C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
            Brother ControlCenter                    4092    C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
            Brother Status Monitor Application       2760    C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
            ConfigFree(TM)                           5052    C:\Program Files (x86)\Toshiba\ConfigFree\CFSwMgr.exe
            ConfigFree(TM)                           4676    C:\Program Files (x86)\Toshiba\ConfigFree\NDSTray.exe
            CovenantEyes.exe                         4328    C:\Program Files (x86)\CE\CovenantEyes.exe
            CovenantEyesHelper.exe                   4024    C:\Program Files (x86)\CE\CovenantEyesHelper.exe
            CyberLink MediaLibray Service            4700    C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe
            CyberLink PowerCinema                    4692    C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe
            Google Chrome                            3636    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            Google Chrome                            3984    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            Google Chrome                            4172    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            Google Chrome                            4340    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            Google Chrome                            4456    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            Google Chrome                            4952    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            Google Chrome                            5172    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            Google Chrome                            5712    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            Google Chrome                            5880    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
            Impulse Now                              4544    C:\Program Files (x86)\Stardock\Impulse\Now\ImpulseNow.exe
            Microsoft Office OneNote                 4560    C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
            Microsoft® Windows® Operating System     5376    C:\Windows\SysWOW64\rundll32.exe
            Nuance PDF Products                      2464    C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
            PaperPort                                4216    C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
            RealPlayer (32-bit)                      3988    C:\Program Files (x86)\Real\realplayer\Update\realsched.exe
            Secunia PSI Tray                         4532    C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
            Software Manager                         2072    C:\ProgramData\FLEXnet\Connect\11\agent.exe
            Software Manager                         4488    C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
            usbnotify.exe                            4256    C:\Program Files\TrueSuite Access Manager\usbnotify.exe


Network activity
----------------
Process chrome.exe (4172) connected on port 80 (HTTP) --> 74.125.224.243
Process chrome.exe (4172) connected on port 80 (HTTP) --> 209.107.203.122
Process chrome.exe (4172) connected on port 80 (HTTP) --> 209.107.203.122
Process chrome.exe (4172) connected on port 80 (HTTP) --> 205.168.236.219
Process chrome.exe (4172) connected on port 80 (HTTP) --> 205.168.236.219
Process chrome.exe (4172) connected on port 80 (HTTP) --> 205.168.236.219
Process chrome.exe (4172) connected on port 80 (HTTP) --> 205.168.236.219
Process chrome.exe (4172) connected on port 80 (HTTP) --> 205.168.236.219
Process chrome.exe (4172) connected on port 80 (HTTP) --> 98.124.248.70
Process chrome.exe (4172) connected on port 80 (HTTP) --> 72.246.244.119
Process chrome.exe (4172) connected on port 80 (HTTP) --> 74.125.224.229
Process chrome.exe (4172) connected on port 80 (HTTP) --> 69.22.151.80
Process chrome.exe (4172) connected on port 80 (HTTP) --> 205.168.236.219
Process chrome.exe (4172) connected on port 80 (HTTP) --> 8.12.226.191
Process chrome.exe (4172) connected on port 80 (HTTP) --> 74.125.224.251
Process chrome.exe (4172) connected on port 80 (HTTP) --> 74.125.224.251
Process chrome.exe (4172) connected on port 80 (HTTP) --> 74.125.224.251
Process chrome.exe (4172) connected on port 80 (HTTP) --> 72.246.245.231
Process chrome.exe (4172) connected on port 80 (HTTP) --> 74.125.224.217
Process chrome.exe (4172) connected on port 80 (HTTP) --> 8.12.226.191
Process chrome.exe (4172) connected on port 80 (HTTP) --> 184.27.199.231
Process chrome.exe (4172) connected on port 80 (HTTP) --> 208.71.125.131
Process chrome.exe (4172) connected on port 80 (HTTP) --> 184.27.199.231
Process chrome.exe (4172) connected on port 80 (HTTP) --> 205.168.236.195
Process chrome.exe (4172) connected on port 80 (HTTP) --> 207.171.189.81
Process chrome.exe (4172) connected on port 80 (HTTP) --> 96.17.70.81
Process chrome.exe (4172) connected on port 80 (HTTP) --> 66.220.146.94
Process chrome.exe (4172) connected on port 443 (HTTP over SSL) --> 23.11.93.177
Process chrome.exe (4172) connected on port 443 (HTTP over SSL) --> 74.125.224.168
Process chrome.exe (4172) connected on port 80 (HTTP) --> 74.125.224.239
Process chrome.exe (4172) connected on port 80 (HTTP) --> 96.17.70.35
Process chrome.exe (4172) connected on port 443 (HTTP over SSL) --> 74.125.224.235
Process chrome.exe (4172) connected on port 80 (HTTP) --> 188.165.220.204



Autoruns and critical files
---------------------------
            Adobe Reader and Acrobat Manager         C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
            Boingo.lnk                               C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk
            Brother ControlCenter                    C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe
            Brother Status Monitor Application       C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
            Chicony traybar                          C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
            CovenantEyes.exe                         C:\Program Files (x86)\CE\CovenantEyes.exe
            CyberLink MediaLibray Service            C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe
            CyberLink PowerCinema                    C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe
            Impulse Now                              C:\Program Files (x86)\Stardock\Impulse\Now\ImpulseNow.exe
            Microsoft Office OneNote                 C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
            Microsoft® Windows® Operating System     C:\Windows\ehome\ehTray.exe
            Microsoft® Windows® Operating System     C:\Windows\system32\BROWSEUI.dll
            Microsoft® Windows® Operating System     C:\Windows\system32\cmd.exe
            Microsoft® Windows® Operating System     C:\Windows\system32\logon.scr
            Nuance PDF Products                      C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
            Nuance PDF Products                      C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe
            PaperPort                                C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe
            PaperPort                                C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
            RealPlayer (32-bit)                      C:\Program Files (x86)\Real\realplayer\Update\realsched.exe
            Secunia PSI Tray                         C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
            Software Manager                         C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
            SSEreg                                   C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe
            TOSHIBA Service Station                  C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(verified)  Google Update                            C:\Users\Josh\AppData\Local\Google\Update\GoogleUpdate.exe
(verified)  GoogleToolbarNotifier                    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(verified)  Microsoft® Windows® Operating System     c:\windows\system32\userinit.exe
(verified)  Windows® Internet Explorer               c:\windows\syswow64\webcheck.dll


Browser plugins
---------------
            2007 Microsoft Office system             C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
            AcroIEHelperShim Library                 c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll
            Adobe Acrobat                            C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
            Adobe Acrobat                            C:\Program Files (x86)\Internet Explorer\plugins\nppdf32.dll
            Adobe Acrobat                            C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
            Bitdefender QuickScan                    C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.111_0\npqscan.dll
            CESpy.dll                                C:\Windows\system32\CESpy.dll
            Facebook Photo Uploader 5                C:\Windows\Downloaded Program Files\PhotoUploader55.ocx
            Facebook Plugin                          C:\Users\Josh\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
            Facebook Plugin                          C:\Users\Josh\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
            Google Talk Plugin                       C:\Users\Josh\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
            Google Talk Plugin Video Accelerator     C:\Users\Josh\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
            Google Toolbar for Internet Explorer     c:\program files (x86)\google\google toolbar\googletoolbar_32.dll
            Google Update                            C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
            Google Update                            C:\Users\Josh\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
            GoogleToolbarNotifier                    c:\program files (x86)\google\googletoolbarnotifier\5.7.7227.1100\swg.dll
            IE Tab Plug-in                           C:\Users\Josh\AppData\Roaming\Mozilla\Firefox\Profiles\pwglhhij.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll
            Java Deployment Toolkit 6.0.310.5        C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
            Java(TM) Platform SE 6 U31               c:\program files (x86)\java\jre6\bin\jp2ssv.dll
            Java(TM) Platform SE 6 U31               C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
            Java(TM) Platform SE 6 U31               c:\program files (x86)\java\jre6\bin\ssv.dll
            Microsoft Office Live Plug-in for Firef  C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
            Microsoft® CoReXT                        c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll
            Move Streaming Media Player              C:\Users\Josh\AppData\Roaming\Move Networks\plugins\npqmp071505000011.dll
            Mozilla Default Plug-in                  C:\Program Files (x86)\Mozilla Firefox\plugins\npnul32.dll
            nmNsp.dll                                C:\Windows\System32\nmNsp.dll
            nmNsp.dll                                C:\Windows\SysWOW64\nmNsp.dll
            NPSWF32.dll                              C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
            Pando Web Plugin                         C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
            PlusIEContextMenu                        c:\program files (x86)\nuance\pdf viewer plus\bin\plusiecontextmenu.dll
            RealJukebox NS Plugin                    C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
            RealJukebox NS Plugin                    c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
            RealNetworks(tm) Chrome Background Exte  C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
            RealPlayer Download and Record Plugin    c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
            RealPlayer Version Plugin                C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
            RealPlayer Version Plugin                c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll
            RealPlayer(tm) G2 LiveConnect-Enabled P  C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
            RealPlayer(tm) G2 LiveConnect-Enabled P  c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
            RealPlayer(tm) HTML5VideoShim Plug-In (  C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
            Shockwave for Director                   C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
            Silverlight Plug-In                      c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
            Skype Toolbars                           c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
            Skype Toolbars                           C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll
            Windows Live™ Photo Gallery              C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
            Windows Presentation Foundation          c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
            Windows® Internet Explorer               C:\Windows\SysWOW64\ieframe.dll
(verified)  Microsoft® Windows® Operating System     C:\Windows\system32\mswsock.dll
(verified)  Microsoft® Windows® Operating System     C:\Windows\system32\napinsp.dll
(verified)  Microsoft® Windows® Operating System     C:\Windows\system32\NLAapi.dll
(verified)  Microsoft® Windows® Operating System     C:\Windows\system32\pnrpnsp.dll
(verified)  Microsoft® Windows® Operating System     C:\Windows\System32\winrnr.dll


Missing files
-------------
File not found: NDSTray.exe
  --> HKLM\Software\Microsoft\Windows\CurrentVersion\Run\"NDSTray.exe"


Scan
----
MD5: 8082f66dc9c8167ff1aa548736f58457  C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
MD5: 5a347432947f3db4849a8589e92f7cc4  C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
MD5: 43772c2a04d5d57a5bd20c07615bdc40  C:\Program Files (x86)\Boingo\Boingo Wi-Fi\ClientLite.dll
MD5: 1fb32003ad0871f19df7abc772e02ab4  C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Res.dll
MD5: b11f7db91e12bbca71be88bfb2120faf  C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
MD5: b907641b954b7c8c7f81ea8679314bfd  C:\Program Files (x86)\Browny02\Brother\BrFirmUpdateCheck.dll
MD5: 7f42ffcd6ff7ca558c2d95dadcd5efa9  C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
MD5: caa5e8de421c5875731cd3ba5233f162  C:\Program Files (x86)\Browny02\Brother\BrStMonWRes.dll
MD5: ea7e57f87d6fee5fd6c5f813c04e8cd2  C:\Program Files (x86)\Browny02\BrYNSvc.exe
MD5: 3e14daedace4a99d243471ce36f2a67d  C:\Program Files (x86)\CE\CovenantEyes.exe
MD5: bdfd5aadfd834d6ad012ece0b5c0656f  C:\Program Files (x86)\CE\CovenantEyesHelper.exe
MD5: 962191ca6f97eb855c217ac6da868f81  C:\Program Files (x86)\CE\nmsvc.dll
MD5: 3ede249174a5687fddbcd7cc6e62bfe1  C:\Program Files (x86)\CE\nmsvTree.dll
MD5: 86dbee659a24636096d99834b60368de  C:\Program Files (x86)\CE\zlib.dll
MD5: 8a3ba48b5be893e1d81bfac17a3c1b1f  c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll
MD5: b8e421c0890356cd4a793d8a346d9096  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
MD5: 62b7936f9036dd6ed36e6a7efa805dc0  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
MD5: 2424231bbd703a677d115c29983b4293  C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL
MD5: 785f487a64950f3cb8e9f16253ba3b7b  C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
MD5: cf39a105cd553eed31e2255aff4c6742  c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll
MD5: 332d341d92b933600d41953b08360dfb  C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
MD5: dee58aeef984a13d6923326444caed6d  C:\Program Files (x86)\ControlCenter4\BrCcAssoc.dll
MD5: 27bf45e6900ae1056daf0b5647e2e266  C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe
MD5: 6aa7883986d3b351cb068919daf2f309  C:\Program Files (x86)\ControlCenter4\BrCcDlgRc.dll
MD5: 649b5aa7a518cf14b128d73059c3a55a  C:\Program Files (x86)\ControlCenter4\BrCcGrImg.dll
MD5: 00afc59555c605a006c6a11ed42a65d1  C:\Program Files (x86)\ControlCenter4\BrCcLUsa.dll
MD5: ddf441f9c40507d582a7d09ab46c6f98  C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
MD5: 50fb420dedf67926910e3b869bb243a1  C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
MD5: 9bd27cf2d12298b7b213c3870cce155e  C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMediaLibrary.dll
MD5: 800ec812a834e8bd2d54c28c470bc145  C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe
MD5: e6bd860c6f7dc2208e334e70aeed8012  C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvcPS.dll
MD5: d32ffceb504030e4a462d56bd3e5fd07  C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\Kernel\Common\CLRCEngine3.dll
MD5: 9b271ead0ae5907eabc3a7be072c323e  C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe
MD5: a68fad0bc6662ee17192683cdefd9858  C:\Program Files (x86)\Google\Chrome\Application\17.0.963.79\avcodec-53.dll
MD5: 4f544fadb1b4ec2f925c8af369467c7d  C:\Program Files (x86)\Google\Chrome\Application\17.0.963.79\avformat-53.dll
MD5: 6f942303666f5aaf5316eceb1edb1531  C:\Program Files (x86)\Google\Chrome\Application\17.0.963.79\avutil-51.dll
MD5: e87ed7359ea0aa0647858d2b8da42304  C:\Program Files (x86)\Google\Chrome\Application\17.0.963.79\chrome.dll
MD5: ed8920a3d0052a303739843df867df23  C:\Program Files (x86)\Google\Chrome\Application\17.0.963.79\gcswf32.dll
MD5: d0c7e4b77237a8b93573106fe37aa5e6  C:\Program Files (x86)\Google\Chrome\Application\17.0.963.79\icudt.dll
MD5: c6a08402f686dedd0e18a29996184173  C:\Program Files (x86)\Google\Chrome\Application\17.0.963.79\pdf.dll
MD5: 19ae70d6e1de32b36725fc6926965915  C:\Program Files (x86)\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
MD5: 56292fdbef6889dbc0c55169a335ece3  C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
MD5: 5b97ab550022b2783894c558fa2e1310  c:\program files (x86)\google\google toolbar\googletoolbar_32.dll
MD5: ab3668c159e1cfea184f72650bd66807  c:\program files (x86)\google\googletoolbarnotifier\5.7.7227.1100\swg.dll
MD5: 27626506e07795bb6357f7f2ef78a90b  C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
MD5: 53fe2d34b143efdb80685281e751b91c  C:\Program Files (x86)\Internet Explorer\plugins\nppdf32.dll
MD5: a9770771b622a871643ea2a4a3983e95  c:\program files (x86)\java\jre6\bin\jp2ssv.dll
MD5: 34e3709244736b8976820f730e5a8815  C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
MD5: 8e6c86726b67d3faa3144849b9aac06c  c:\program files (x86)\java\jre6\bin\ssv.dll
MD5: 4d99fca201b72e0f2ca996e357baa170  C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
MD5: 4566bbe928ef23e1c5a55d02d64c2872  C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
MD5: 9a7fa6371f68335fd3c3d6488bc5a9f8  C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys
MD5: 2a66bb1f9d9ed7a8bcd58e505bb3ed3c  C:\Program Files (x86)\Lavasoft\Ad-Aware\Resources.dll
MD5: 1843e81fa7acfff4344a7dd4328d7da0  C:\Program Files (x86)\Microsoft Office\Office12\1033\ONINTL.DLL
MD5: ed327201724ea05d509b7939abe49e98  c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
MD5: a878453a1714870eaada83e6434bdb77  C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
MD5: 5e70b9feae08c91510655d80f258909a  C:\Program Files (x86)\Mozilla Firefox\plugins\npnul32.dll
MD5: 9a6101f29e2e9d41b99cbcc8f106e8fe  C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
MD5: 53fe2d34b143efdb80685281e751b91c  C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
MD5: 1b0afe3cafeb40f0bfd632f70264f82d  C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
MD5: ba6bf673832b3212aac8426a344ae972  C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
MD5: 8c5463bbf6451367eea8c0f6947645cb  C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
MD5: 992776dd978494547dd1ce211d978868  C:\Program Files (x86)\Nuance\PaperPort\BindRes.dll
MD5: e2bf206e5164569500742637b5459402  C:\Program Files (x86)\Nuance\PaperPort\blicectr.dll
MD5: 0d1d2fbae112bddb9f77b7bc7a956d3a  C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe
MD5: 07c4ebd3107799774fa3103956cd1c40  C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe
MD5: 519835d8c5215b09dc6d60f356625a66  C:\Program Files (x86)\Nuance\PaperPort\MaxRes.dll
MD5: c1c3baf078be5a14384a4ba2d730817d  C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
MD5: e5f1d2c7d51c816437bbe2306828bc4b  C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
MD5: 874650bf7c7063fb2455e0498456d29c  C:\Program Files (x86)\Nuance\PaperPort\XMAXUTIL.dll
MD5: 198e148b007b7a14a4d2e5efffc6f2cc  c:\program files (x86)\nuance\pdf viewer plus\bin\plusiecontextmenu.dll
MD5: 9f0acaa725cf5a391af7e2067ae45746  C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
MD5: 154420a93e4f676aa33a055a116255d9  C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe
MD5: ccf523b951afaa0147f22e2a7aae4976  C:\Program Files (x86)\NXP\FM Radio\OpenLibSysX64.sys
MD5: 8530b9736917e2a86384a9a837bf518a  C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
MD5: 1b0afe3cafeb40f0bfd632f70264f82d  c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
MD5: ba6bf673832b3212aac8426a344ae972  c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
MD5: 8c5463bbf6451367eea8c0f6947645cb  c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll
MD5: 0ec18f61e86f87c0ade782920b403d9a  C:\Program Files (x86)\Real\realplayer\Update\realsched.exe
MD5: 8e6c1915eddd719c4bfe99eccd7216a7  C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
MD5: 2d0599dd0124764fc939c59985c860de  C:\Program Files (x86)\Secunia\PSI\PSIA.exe
MD5: 20b9e1adbc58958b480933e4da005dfb  C:\Program Files (x86)\Secunia\PSI\sua.exe
MD5: bad6a333613786540454044d8cd94524  c:\program files (x86)\skype\toolbars\internet explorer\skypeieplugin.dll
MD5: db0405d9aad62f0762e0876ac142b7e1  C:\Program Files (x86)\Skype\Updater\Updater.exe
MD5: 8d7cfa9f2d6e210569c0f6ba10afcbbe  C:\Program Files (x86)\Stardock\Impulse\Now\ImpulseNow.exe
MD5: 447ff2b8a45efd9a0838eb623fd72f26  C:\Program Files (x86)\Stardock\Impulse\Now\SDSecurity.dll
MD5: 2efc57463dcacde623a66153489a3c89  C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
MD5: b9d3d216c66e0cd37478f5e5778aa35b  C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
MD5: c508b28b9da7563634a2a2b2eef4395d  C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
MD5: 9a815510679c7ecd04ed194a9c9c25e5  C:\Program Files (x86)\Toshiba\ConfigFree\CFSwMgr.exe
MD5: 8f565b8e9c6bd15a08ef14b7b8358c6c  C:\Program Files (x86)\Toshiba\ConfigFree\CFWLAPI.dll
MD5: c57d10709b80343afcb69b32ea65afd3  C:\Program Files (x86)\Toshiba\ConfigFree\IpAdrSet.dll
MD5: ecb3f203d4bd3cad793cabcac10c7295  C:\Program Files (x86)\Toshiba\ConfigFree\NDSAPI.dll
MD5: 358b1855a10190d48fc594ea140537d5  C:\Program Files (x86)\Toshiba\ConfigFree\NDSNLS.dll
MD5: 0bae09f93b961fa396e4c146b2a06c4b  C:\Program Files (x86)\Toshiba\ConfigFree\NDSParts.dll
MD5: 5400b11ee108730786c110842aea3a27  C:\Program Files (x86)\Toshiba\ConfigFree\NDSTray.exe
MD5: 4e66089e01c2bff08708e0ffc9bd87a5  C:\Program Files (x86)\Toshiba\ConfigFree\OpenProp.dll
MD5: 87f95cb3e11b42e62654488ffb6c5ad8  C:\Program Files (x86)\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
MD5: fb8448d1b0da00d70c28adf9282b31bb  C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
MD5: 33e636e9cdf2b12af756f4410622918b  C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
MD5: b7dc98f6f4e7611a9c0849945fb28fb9  C:\Program Files (x86)\Windows Defender\MpOav.dll
MD5: 0a1ff0b674e2f268799442a434a63bb3  C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
MD5: b7b942092b80dbef8ec13ec279233db1  C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
MD5: a60a9f1720f5da1431a3dec14d8833f4  C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
MD5: 2bacd71123f42cea603f4e205e1ae337  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
MD5: deb2b067745d92ff17a5068dfd2360bc  C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
MD5: 191d8eccc40f05b52fac0513f35ba01d  C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
MD5: 3777aec8cb30251e43bf0a2b4fec07d5  C:\Program Files\Intel\WiFi\bin\EvtEng.exe
MD5: d86598755bd7c025989f4d860af72280  C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
MD5: 10851a70dd21039144177786361d9ce6  C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe
MD5: eb3d29e6d3b744f4b0f523dec971bf34  C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
MD5: 761148b8436bae3a7f5d0cfecd23954f  C:\Program Files\TrueSuite Access Manager\usbnotify.exe
MD5: 0cc32256f89f156ceb9129e5bd8a5fc9  C:\ProgramData\FLEXnet\Connect\11\_ispmres.dll
MD5: b8fcab4e83c20a970af4f7739482f6d0  C:\ProgramData\FLEXnet\Connect\11\_isusres.dll
MD5: e970929b7fc9ce646a78b5ecabaf9136  C:\ProgramData\FLEXnet\Connect\11\agent.exe
MD5: 6bf7676296d5359afc135a5397000053  C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
MD5: 0536b0dcfe440cb15bb24cf315c07044  C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchrome150browserrecordhelper.dll
MD5: 60e5856547cac9c068d7bf865c45f90e  C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Common\rpcommon150browserrecordplugin.dll
MD5: fcfe8d71e8fb68076344755e1e03918c  c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
MD5: 92e874667621a2a475fc8ea91dd763a2  C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
MD5: 94a6e06bf6531d623fe30a7c38e65f61  C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
MD5: c3eef3907c3549200228cd911106091d  C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll
MD5: c48607325e31a0cbb5ef96012a13219e  C:\Users\Josh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.111_0\npqscan.dll
MD5: 27626506e07795bb6357f7f2ef78a90b  C:\Users\Josh\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
MD5: 6d74290856347cf8682277a54b433d4b  C:\Users\Josh\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
MD5: 0bb95cba0d71acebe9d51c68c40bf080  C:\Users\Josh\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
MD5: d94c362e750f8c283bf52537d3df28b5  C:\Users\Josh\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
MD5: e66e9c5d42aa085891a4f67e7b2ca4df  C:\Users\Josh\AppData\Roaming\Move Networks\plugins\npqmp071505000011.dll
MD5: 263a8a44418c7de3d13f74c19a7c4c9c  C:\Users\Josh\AppData\Roaming\Mozilla\Firefox\Profiles\pwglhhij.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll
MD5: 219dc86473745d5a1685d45dd3b491c4  C:\Users\Josh\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
MD5: 6680a91d52ba450498e333e93f87e43d  C:\Users\Josh\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
MD5: d6804f089cbb6749e95124e7c4d80900  C:\Windows\AppPatch\AcLayers.DLL
MD5: ce1b8c59da1e6eb97516de5aa5d37d49  C:\Windows\AppPatch\AcWow64.DLL
MD5: 90ae19ea17001f8b2cf9545618e5dffa  C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6310a2050033b0b567428ca55bda4a1b\Microsoft.VisualBasic.ni.dll
MD5: ce45722a3393b63843de48f314cf6b3f  C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll
MD5: e60cd8df35eb4a9c952af381fef51af3  C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c50133cb67d7c013fa31e1ffb942060b\System.ni.dll
MD5: 14ce384d2e27b64c256bda4dc39c312d  C:\Windows\ehome\ehRecvr.exe
MD5: b93159c1313d66fdfbbe876f5189cd52  C:\Windows\ehome\ehsched.exe
MD5: f5ee2527d74449868e3c3227a59bcd28  C:\Windows\ehome\ehstart.dll
MD5: 65437dad4f238ea9549408a783002222  C:\Windows\ehome\ehTray.exe
MD5: ce07a466201096f021cd09d631b21540  C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
MD5: 749f5f8cedca70f2a512945325fc489d  C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
MD5: 74751dda198165947fd7454d83f49825  C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
MD5: bc5b0be5af3510b0fd8c140ee42c6d3e  C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
MD5: 6717ae12e326dd1e39f6ee183a37dc0f  C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
MD5: ee59d3cdfab2e808551084165c7887bf  C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
MD5: ab87eeffd18f2baafc274e7075ea6c67  c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
MD5: f5df6846f30e9f54ea60ccaeb3fb2055  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
MD5: 66328b08ef5a9305d8ede36b93930369  C:\Windows\servicing\TrustedInstaller.exe
MD5: e9b9c1b98c8d6d48407e1c1203eac659  C:\Windows\system32\adsldpc.dll
MD5: da7478ba9e41b60b3d5da456e253002a  C:\Windows\system32\audioeng.dll
MD5: 4acf748a8e576761e4c610acab67b1bc  C:\Windows\system32\BCRYPT.dll
MD5: e668959fb52f73e18dff8bc668bb5545  C:\Windows\system32\CESpy.dll
MD5: 74f26fc01b180d4a99a168ed69c30a53  C:\Windows\system32\cmd.exe
MD5: 93e317d7ad783d8eaee2e3500bfe889d  C:\Windows\system32\credui.dll
MD5: 85e861d0b88db2b54acb0839654c09f7  C:\Windows\system32\DNSAPI.dll
MD5: 05b6a5ce1c7767c32df35966107cb1ec  C:\Windows\system32\hhctrl.ocx
MD5: b8fbe5f40b09f5d20e1e5ccfef893d62  C:\Windows\system32\IMM32.DLL
MD5: b17d18fd6594aaa25cbc95e799b1bf40  C:\Windows\system32\logon.scr
MD5: 1b593fbb763150bd225df266c69a9329  C:\Windows\system32\MFC42u.DLL
MD5: 1fd3f9722119bdf7b8cff0ecd1e84ea6  C:\Windows\system32\MFC71.DLL
MD5: 56e315acfb08a177b4d01e42b9044db5  C:\Windows\system32\MPRAPI.dll
MD5: 8e8eaefcff5bf7dde2d3f689ba722c5f  C:\Windows\System32\nmNsp.dll
MD5: 862363973dcbcc31dd161ef41a69153c  C:\Windows\system32\ODBC32.dll
MD5: dc15ab7168c0309d8f04fd95b6240422  C:\Windows\system32\OLEACC.dll
MD5: 2dd6af8e97f59c9d39329bbc2a81f13f  C:\Windows\system32\RASDLG.dll
MD5: 167ac31450c0c53a01fa1491e94d7678  C:\Windows\system32\shdocvw.dll
MD5: c7230fbee14437716701c15be02c27b8  C:\Windows\System32\shsvcs.dll
MD5: 365828e555e9479246efd9090c41c2d7  C:\Windows\System32\sti.dll
MD5: 2cdef39641bc63a337b6ea13e61b32c6  C:\Windows\system32\TosBdAPI.dll
MD5: c385d4d4ec16e637aa4d2d18a06e80c9  C:\Windows\system32\TosBtAPI.dll
MD5: 88b630f6aeb5a11f6ad064930b38c2c0  C:\Windows\system32\uxtheme.dll
MD5: 65283279d4ede387c988f8b753c8f7e5  C:\Windows\system32\wiadss.dll
MD5: dbd02e3e6f061ebbbf9b99a9d7cba30b  C:\Windows\system32\WINHTTP.dll
MD5: 14ff750efe13b0c21e5a06507c3a97b1  C:\Windows\system32\WINMM.dll
MD5: 5ec8fb83f31aa2d6f421f02c3f4f4475  C:\Windows\system32\WINSPOOL.DRV
MD5: 28b9dba6201aeddc65c15fa48939804a  C:\Windows\system32\wmp.dll
MD5: 9441a231c0aa0712f7cf3b10d9cfcf76  C:\Windows\system32\wmploc.dll
MD5: 4676a8e1ee37e71486717ecd1e61c17b  C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
MD5: 68648d1a5272fb640df95bcc0f1df660  C:\Windows\SysWOW64\authServer.exe
MD5: 05c8c8767e29163fc251164ff6839ea5  C:\Windows\syswow64\GDI32.dll
MD5: 5bb1b169530e1d48ab302ed086f5ecf9  C:\Windows\SysWOW64\ieframe.dll
MD5: b86cb6276da2518d3501b4991e9ad4ce  C:\Windows\syswow64\iertutil.dll
MD5: 4ca9275776d204bf25ce2b2561b17e44  C:\Windows\SysWOW64\jscript.dll
MD5: 7f4caeac24592fa9f574e1f8cd1d0604  C:\Windows\syswow64\kernel32.dll
MD5: df37346ea13082e3e1b423b54014e641  C:\Windows\syswow64\LPK.DLL
MD5: 5ad4e19d583fa285f4b5ccb7784a28c2  C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MD5: 6d1e32a3c964baf06b7973e7b18e3212  C:\Windows\SysWOW64\mshtml.dll
MD5: 17af64d727545f2804f6e6d998327e3f  C:\Windows\syswow64\msvcrt.dll
MD5: 8e8eaefcff5bf7dde2d3f689ba722c5f  C:\Windows\SysWOW64\nmNsp.dll
MD5: 6aaf63a85181e39f94ec0641c55a4ef0  C:\Windows\SysWOW64\ntdll.dll
MD5: 9586e7cb2255a8b097a7e4538202585e  C:\Windows\syswow64\ole32.dll
MD5: dc15ab7168c0309d8f04fd95b6240422  C:\Windows\SysWOW64\OLEACC.dll
MD5: b218342214d9bba0f54ea12ba2e9278c  C:\Windows\syswow64\OLEAUT32.dll
MD5: 0ed8727ea0172860f47258456c06caea  C:\Windows\SysWow64\perfhost.exe
MD5: 0abe67004eb4c162f4456e64f90a11fd  C:\Windows\syswow64\RPCRT4.dll
MD5: 4b555106290bd117334e9a08761c035a  C:\Windows\SysWOW64\rundll32.exe
MD5: da61f5c012a646771587a8cb9c0ae590  C:\Windows\SysWOW64\schannel.dll
MD5: 3a5adb89f057cd7b5a229f1ace53fdf6  C:\Windows\syswow64\Secur32.dll
MD5: 33ae914c24f546aabf281ba7b138186d  C:\Windows\syswow64\SHELL32.dll
MD5: 9176285122b7b849fec2aa1b72a8f7a8  C:\Windows\syswow64\SHLWAPI.dll
MD5: 45f40b53ec32daf51aabad4e0cd1fa0b  C:\Windows\syswow64\urlmon.dll
MD5: d29fdb5dedbdc1bd882164dc6dc4dd53  C:\Windows\syswow64\USER32.dll
MD5: 80fff14f1757b9af8be9d314fc1ae88b  C:\Windows\syswow64\USP10.dll
MD5: 88b630f6aeb5a11f6ad064930b38c2c0  C:\Windows\SysWOW64\uxtheme.dll
MD5: 330a25ae6d4bcbf4521c1d69d168aa51  C:\Windows\SysWow64\vbscript.dll
MD5: de4685de5130039fa63da66c0f72f787  C:\Windows\syswow64\wininet.dll
MD5: 14ff750efe13b0c21e5a06507c3a97b1  C:\Windows\SysWOW64\WINMM.dll
MD5: c9564cf4976e7e96b4052737aa2492b4  C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll
MD5: 1f5afd468eb5e09e9ed75a087529eab5  C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_cbf5e994470a1a8f\MFC80.DLL
MD5: 28a09777d2d952122567a8a82f1a2c7b  C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_03ce2c72205943d3\MFC80ENU.DLL
MD5: 4c39358ebdd2ffcd9132a30e1ec31e16  C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCP90.dll
MD5: cdbe9690cf2b8409facad94fac9479c9  C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll
MD5: 35acd5ea63d75e97dd0e9a1629e582b2  C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.18305_none_88f3a38569c2c436\COMCTL32.dll
MD5: be3c082837866c4c291adaf163c10ea6  C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
MD5: b5b09091b0e33c396ceec8995515bd41  C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll


No file uploaded.

Scan finished - communication took 2 sec
Total traffic - 0.01 MB sent, 0.68 KB recvd
Scanned 377 files and modules - 27 seconds

==============================================================================


Thanks very much

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6366
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #25 on: March 19, 2012, 12:56:18 AM »
How is your system responding, do you have any remaining issues or concerns..

Offline Armaneus

  • Bronze Member
  • Posts: 15
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #26 on: March 20, 2012, 10:35:42 PM »
System is working much faster, thanks! I think the original problem has been solved.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6366
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #27 on: March 21, 2012, 01:33:26 AM »
Good to hear that your system is OK and responding weel, if no more issues here are some tips to reduce the potential for malware infection in the future:

Make proper use of your antivirus and firewall

Antivirus and Firewall programs are integral to your computer security. However, just having them installed isn't enough. The definitions of these programs are frequently updated to detect the latest malware, if you don't keep up with these updates then you'll be vulnerable to infection. Many antivirus and firewall programs have automatic update features, make use of those if you can. If your program doesn't, then get in the habit of routinely performing manual updates, because it's important.

You should keep your antivirus and firewall guard enabled at all times, NEVER turn them off unless there's a specific reason to do so. Also, regularly performing a full system scan with your antivirus program is a good idea to make sure you're system remains clean. Once a week should be adequate. You can set the scan to run during a time when you don't plan to use the computer and just leave it to complete on its own.

Install and use WinPatrol  This will inform you of any attempted unauthorized changes to your system.

WinPatrol features explained Here

You will have several programs installed, these maybe outdated and vulnerable to exploits also. To be certain, please run the free online scan by Secunia, available Here   Before clicking the Start scan  button, please check the box for the option Enable thorough system inspection. Just below the "Scan Options:" section, you'll see the status of what's currently processing....
...when the scan completes, the message "Detection completed successfully" will appear in the Programs/Result section. For each problem detected, Secunia will offer a "Solution" option. Please follow those instructions to download updated versions of the programs as recommended by Secunia.

Use a safer web browser

Internet Explorer is not the most secure tool for browsing the web. It has been known to be very susceptible to infection, and there are a few good free alternatives:
 
Firefox,

Opera, and

Chrome.
 
All of these are excellent faster, safer, more powerful and functional free alternatives to Internet Explorer. It's definitely worth the short period of adjustment to start using one of these. If you wish to continue using Internet Explorer, it would be a good idea to follow the tutorial HERE which will help you to make IE MUCH safer.

These browser add-ons will help to make your browser safer:

Web of Trust warns you about risky websites that try to scam visitors, deliver malware or send spam. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous ones:

Available for Firefox and Internet Explorer.

Green to go,
Yellow for caution, and
Red to stop.


Available for Firefox only. NoScript helps to block malicious scripts and in general gives you much better control over what types of things webpages can do to your computer while you're browsing.

These are just a couple of the most popular add-ons, if you're interested in more, take a look at THIS article.

Here a couple of links by two security experts that will give some excellent tips and advice.

So how did I get infected in the first place by Tony Klein

How to prevent Malware by Miekiemoes

Finally this link HERE will give a comprehensive upto date list of free Security programs. To include - Antivirus, Antispyware, Firewall, Antimalware, Online scanners and rescue CD`s.

Don`t forget, the best form of defense is common sense. If you don`t recognize it, don`t open it. If something looks to good to be true, then it aint.

Let me when you are OK to close out your thread,

Take care,

Kevin

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6366
Re: [Resolved K]Probable unknown TSR.BOOT virus, ESET unable to remove
« Reply #28 on: March 26, 2012, 01:27:48 AM »
Since this issue appears to be resolved the topic has been closed. Glad we could help.   :t

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

The fixes and advice in this thread are for this System only. Do not apply the instructions from this thread to your own System. Please start a new thread describing your issue and someone will be along to assist you.