This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Shutdown taking too long........

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a problem shutting down my computer. It takes a very long time for me to turn off my laptop. After clicking turn off computer, it takes about 5 mins. for Logging Off window to come, another 3-4 mins. to log off, and another 3 mins. for the computer to actually shut down. It wasn't taking this much time before. What could be wrong? Below is the HiJack This and Combo Fix logs. I have ran virus scan, ad-ware scan to improve the shutdown process but nothing helped. Please advice.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:47:05 PM, on 7/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TDispVol.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\DLACTRLW.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\RAMASST.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AdAwarePortable\AdAwarePortable.exe
C:\Program Files\AdAwarePortable\App\AdAware\AAWService.exe
C:\Program Files\AdAwarePortable\App\AdAware\AAWTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.toshibadirect.com/dpdstart
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\DLACTRLW.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1246734084437
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\AdAwarePortable\App\AdAware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe

–
End of file - 10407 bytes
—————————————————————————————————————————————————————————-

ComboFix 09-07-09.08 - Jignesh Mehta 07/11/2009 12:42.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.561 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Updated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
FW: Norton 360 *enabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-3868997124-911790988-508925577-500
c:\windows\iwinsysb.dll
c:\windows\kb913800.exe
c:\windows\system32\536165616.dll
c:\windows\system32\drivers\hjgruitlkrnodo.sys
c:\windows\system32\drivers\smss.exe
c:\windows\system32\hjgruidxexcnpg.dat
c:\windows\system32\hjgruigutuuyfi.dll
c:\windows\system32\hjgruihhlirkcg.dat
c:\windows\system32\hjgruiymktnmql.dll
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lowsec\user.ds.lll
c:\windows\system32\microday08.dll
c:\windows\system32\msxml71.dll
c:\windows\system32\MTX0CI.dll
c:\windows\system32\mypath0079.dll
c:\windows\system32\net.net
c:\windows\system32\sdra64.exe
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
c:\windows\system32\drivers\str.sys . . . . failed to delete

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_hjgruiowbiqqal


((((((((((((((((((((((((( Files Created from 2009-06-11 to 2009-07-11 )))))))))))))))))))))))))))))))
.

2009-07-11 05:48 . 2009-07-11 05:48 ——– d—–w- c:\documents and settings\Jignesh Mehta\Local Settings\Application Data\Symantec
2009-07-11 00:47 . 2009-07-11 00:47 ——– d—–w- c:\windows\RestoreSafeDeleted
2009-07-11 00:43 . 2009-07-03 14:49 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-07-11 00:38 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-11 00:37 . 2009-07-11 00:37 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-07-11 00:37 . 2009-07-08 17:28 2920112 -c–a-w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
2009-07-11 00:37 . 2009-07-11 00:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-07-11 00:37 . 2009-07-11 00:37 ——– d—–w- c:\program files\Lavasoft
2009-07-11 00:26 . 2009-07-11 00:26 2 –shatr- c:\windows\winstart.bat
2009-07-11 00:26 . 2009-07-11 00:26 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\Regrun
2009-07-11 00:26 . 2009-07-11 00:26 ——– d—–w- C:\backreg
2009-07-11 00:25 . 2009-07-11 00:25 ——– d—–w- c:\program files\Greatis
2009-07-10 23:48 . 2009-07-10 23:49 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\MalwareRemovalBot
2009-07-10 22:12 . 2009-07-10 22:12 ——– d—–w- c:\windows\Sun
2009-07-10 04:11 . 2009-07-11 01:32 ——– d—–w- c:\program files\Fast AVI MPEG Splitter
2009-07-10 00:59 . 2009-07-10 00:59 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\AdobeUM
2009-07-09 03:59 . 2009-07-09 03:59 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-07-09 03:59 . 2009-07-09 03:59 ——– d—–w- c:\windows\SHELLNEW
2009-07-09 03:59 . 2009-07-09 03:59 ——– d—–w- c:\program files\Microsoft.NET
2009-07-08 00:02 . 2009-07-08 00:02 ——– d—–w- c:\windows\system32\scripting
2009-07-08 00:02 . 2009-07-08 00:02 ——– d—–w- c:\windows\l2schemas
2009-07-08 00:02 . 2009-07-08 00:02 ——– d—–w- c:\windows\system32\en
2009-07-08 00:02 . 2009-07-08 00:02 ——– d—–w- c:\windows\system32\bits
2009-07-07 23:58 . 2009-07-08 00:03 ——– d—–w- c:\windows\ServicePackFiles
2009-07-07 00:48 . 2009-07-07 00:48 ——– d—–w- c:\program files\ImTOO
2009-07-07 00:03 . 2009-07-07 00:03 7168 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Thinstall\iPhoneRingToneMaker 2.5.1\4000003f00003i\faac.exe
2009-07-07 00:01 . 2009-07-07 00:01 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\Thinstall
2009-07-06 23:42 . 2009-03-24 19:43 43008 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metricsloader.dll
2009-07-06 23:42 . 2009-03-24 19:43 43008 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-07-06 23:42 . 2009-03-24 19:43 235520 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\metrics-ff2.dll
2009-07-06 23:42 . 2009-03-24 19:43 338432 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-07-06 23:42 . 2009-03-24 19:42 345088 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-07-06 23:42 . 2009-03-24 19:42 235008 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\metrics-ff3.dll
2009-07-06 03:30 . 2009-07-06 03:31 ——– d-sh–w- c:\windows\system32\asd
2009-07-06 03:30 . 2009-07-06 03:30 ——– d—–w- c:\program files\Accurate Shutdown
2009-07-06 03:17 . 2009-07-06 03:17 ——– d—–w- c:\program files\AC3Filter
2009-07-06 00:45 . 2007-10-23 14:27 110592 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\U3\temp\cleanup.exe
2009-07-06 00:39 . 2007-10-23 14:22 3350528 —ha-w- c:\documents and settings\Jignesh Mehta\Application Data\U3\temp\Launchpad Removal.exe
2009-07-06 00:39 . 2009-07-11 01:50 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\U3
2009-07-05 19:55 . 2008-10-16 19:06 268648 —-a-w- c:\windows\system32\mucltui.dll
2009-07-04 22:20 . 2009-07-04 22:20 ——– d—–w- c:\program files\MSXML 4.0
2009-07-04 22:16 . 2009-07-04 22:16 ——– d—–w- c:\program files\SopCast
2009-07-04 22:15 . 2009-07-04 22:15 ——– d—–w- c:\documents and settings\Jignesh Mehta\Local Settings\Application Data\TVU Networks
2009-07-04 22:15 . 2009-07-04 22:15 ——– d—–w- c:\documents and settings\All Users\Application Data\TVU Networks
2009-07-04 22:15 . 2009-07-04 22:15 ——– d—–w- c:\documents and settings\Jignesh Mehta\LocalLow
2009-07-04 22:15 . 2009-07-04 22:15 ——– d—–w- c:\program files\TVUPlayer
2009-07-04 20:43 . 2009-07-04 18:07 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\McAfee.com Personal Firewall
2009-07-04 20:42 . 2006-02-16 09:18 ——– d—–w- c:\windows\system32\config\systemprofile\WINDOWS
2009-07-04 20:42 . 2009-07-04 20:42 21275 —-a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-04 20:42 . 2009-07-04 20:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Intel
2009-07-04 20:42 . 2009-07-04 20:42 ——– d—–w- c:\documents and settings\Administrator\Application Data\Intel
2009-07-04 20:41 . 2009-07-11 00:38 ——– dc—-w- c:\windows\system32\DRVSTORE
2009-07-04 20:41 . 2006-02-16 09:18 ——– d—–w- c:\documents and settings\Default User\WINDOWS
2009-07-04 20:39 . 2009-07-04 20:39 ——– d—–w- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-07-04 20:34 . 2009-07-04 20:34 ——– d—–w- c:\program files\AVerMedia
2009-07-04 20:33 . 2009-07-04 20:33 ——– d—–w- c:\program files\Common Files\InterVideo
2009-07-04 20:33 . 2005-11-28 05:51 135168 —-a-w- c:\windows\system32\igfxres.dll
2009-07-04 20:28 . 2009-07-04 20:28 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-07-04 20:16 . 2009-07-04 20:57 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\Symantec
2009-07-04 20:13 . 2009-07-04 20:13 ——– d—–w- c:\program files\Windows Sidebar
2009-07-04 20:12 . 2009-07-08 00:13 ——– d—–w- c:\program files\Norton 360
2009-07-04 20:11 . 2009-07-04 20:44 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2009-07-04 20:11 . 2009-07-04 20:44 124464 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-07-04 20:11 . 2009-07-09 23:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-04 20:11 . 2009-07-04 20:44 ——– d—–w- c:\program files\Symantec
2009-07-04 20:10 . 2009-07-11 17:50 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-07-04 20:06 . 2009-07-04 20:06 ——– d—–w- C:\Jigs
2009-07-04 20:06 . 2009-07-09 23:37 ——– d—–w- C:\Downloads
2009-07-04 20:06 . 2009-07-04 20:06 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\AVS4YOU
2009-07-04 20:06 . 2009-07-04 20:06 ——– d—–w- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-07-04 20:05 . 2009-07-04 20:05 ——– d—–w- c:\program files\Common Files\AVSMedia
2009-07-04 20:05 . 2009-01-29 00:49 974848 —-a-w- c:\windows\system32\mfc70.dll
2009-07-04 20:05 . 2009-01-29 00:49 487424 —-a-w- c:\windows\system32\msvcp70.dll
2009-07-04 20:05 . 2009-01-29 00:49 344064 —-a-w- c:\windows\system32\msvcr70.dll
2009-07-04 20:05 . 2009-07-04 20:05 ——– d—–w- c:\program files\AVS4YOU
2009-07-04 20:05 . 2009-01-29 00:49 1700352 —-a-w- c:\windows\system32\GdiPlus.dll
2009-07-04 20:05 . 2009-01-29 00:49 24576 —-a-w- c:\windows\system32\msxml3a.dll
2009-07-04 19:50 . 2009-07-04 19:50 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\DivX
2009-07-04 19:49 . 2009-07-11 16:23 ——– d—–w- c:\program files\Disk Cleaner
2009-07-04 19:47 . 2008-04-14 00:12 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-07-04 19:39 . 2009-07-04 19:39 ——– d—–w- c:\program files\Windows Media Connect 2
2009-07-04 19:36 . 2009-07-04 19:38 ——– d—–w- c:\windows\system32\drivers\UMDF
2009-07-04 19:36 . 2009-07-04 19:36 ——– d—–w- c:\windows\system32\LogFiles
2009-07-04 19:26 . 2009-07-04 19:26 ——– d-sh–w- c:\documents and settings\Jignesh Mehta\PrivacIE
2009-07-04 19:20 . 2009-07-04 19:20 ——– d-sh–w- c:\documents and settings\Jignesh Mehta\IETldCache
2009-07-04 19:18 . 2009-07-04 19:18 ——– d—–w- c:\windows\ie8updates
2009-07-04 19:16 . 2009-07-04 19:17 ——– dc-h–w- c:\windows\ie8
2009-07-04 19:01 . 2009-07-04 19:01 ——– d-sh–w- c:\documents and settings\Jignesh Mehta\UserData
2009-07-04 18:53 . 2009-06-02 10:12 102912 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2009-07-04 18:53 . 2009-04-30 21:22 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-07-04 18:53 . 2009-04-30 21:22 1985024 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2009-07-04 18:53 . 2009-04-30 21:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-04 18:53 . 2009-04-30 21:22 11064832 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2009-07-04 18:42 . 2009-05-01 21:03 9464 ——w- c:\windows\system32\drivers\cdralw2k.sys
2009-07-04 18:42 . 2009-05-01 21:03 9336 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2009-07-04 18:42 . 2009-05-01 21:03 129784 ——w- c:\windows\system32\pxafs.dll
2009-07-04 18:41 . 2009-07-04 18:42 ——– d—–w- c:\program files\DivX
2009-07-04 18:41 . 2009-07-04 18:41 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-07-04 18:39 . 2008-04-14 00:12 20992 ——w- c:\windows\system32\spupdwxp.exe
2009-07-04 18:38 . 2008-04-14 00:11 61440 ——w- c:\windows\system32\kmsvc.dll
2009-07-04 18:12 . 2008-06-13 11:05 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2009-07-04 18:12 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2009-07-04 18:10 . 2009-07-04 18:10 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-04 18:08 . 2008-05-08 14:02 203136 -c—-w- c:\windows\system32\dllcache\rmcast.sys
2009-07-04 18:08 . 2008-10-24 11:21 455296 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2009-07-04 18:07 . 2008-12-11 10:57 333952 -c—-w- c:\windows\system32\dllcache\srv.sys
2009-07-04 18:07 . 2008-05-01 14:33 331776 -c—-w- c:\windows\system32\dllcache\msadce.dll
2009-07-04 18:07 . 2008-04-11 19:04 691712 -c—-w- c:\windows\system32\dllcache\inetcomm.dll
2009-07-04 18:07 . 2009-07-04 18:07 ——– d—–w- c:\documents and settings\Jignesh Mehta\Local Settings\Application Data\Mozilla
2009-07-04 18:03 . 2008-10-03 10:02 247326 -c—-w- c:\windows\system32\dllcache\strmdll.dll
2009-07-04 18:03 . 2008-10-15 16:34 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll
2009-07-04 18:03 . 2008-09-04 17:15 1106944 -c—-w- c:\windows\system32\dllcache\msxml3.dll
2009-07-04 18:02 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-07-04 18:02 . 2008-04-21 12:08 215552 -c—-w- c:\windows\system32\dllcache\wordpad.exe
2009-07-04 17:55 . 2009-07-04 17:55 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee.com Personal Firewall

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-11 17:50 . 2009-07-11 17:50 213024 ——w- c:\windows\system32\drivers\str.sys
2009-07-09 23:32 . 2006-02-16 16:59 35848 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-08 00:05 . 2006-02-15 15:37 87931 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-07 00:59 . 2009-07-04 21:28 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\Apple Computer
2009-07-07 00:58 . 2009-07-04 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-07-04 22:30 . 2006-02-16 10:39 ——– d—–w- c:\program files\Microsoft Works
2009-07-04 21:58 . 2006-02-18 15:56 ——– d—–w- c:\program files\Google
2009-07-04 21:36 . 2009-07-04 21:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-04 21:28 . 2009-07-04 21:28 ——– d—–w- c:\program files\iTunes
2009-07-04 21:28 . 2009-07-04 21:28 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-04 21:28 . 2009-07-04 21:28 ——– d—–w- c:\program files\iPod
2009-07-04 21:28 . 2009-07-04 21:26 ——– d—–w- c:\program files\Common Files\Apple
2009-07-04 21:27 . 2009-07-04 21:27 ——– d—–w- c:\program files\Bonjour
2009-07-04 21:27 . 2009-07-04 21:27 ——– d—–w- c:\program files\QuickTime
2009-07-04 21:26 . 2009-07-04 21:26 ——– d—–w- c:\program files\Apple Software Update
2009-07-04 20:44 . 2009-07-04 20:11 10635 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-07-04 20:44 . 2009-07-04 20:11 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-07-04 20:42 . 2006-02-15 16:18 ——– d—–w- c:\program files\Intel
2009-07-04 20:42 . 2009-07-04 20:43 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\Intel
2009-07-04 20:33 . 2006-02-16 09:25 ——– d—–w- c:\program files\InterVideo
2009-07-04 20:33 . 2006-02-15 16:20 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-04 19:02 . 2006-05-13 23:44 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2009-07-04 18:18 . 2006-02-16 10:14 ——– d—–w- c:\program files\Yahoo!
2009-07-04 18:18 . 2006-05-13 23:35 ——– d—–w- c:\documents and settings\All Users\Application Data\YAHOO
2009-07-04 17:53 . 2006-02-16 09:55 ——– d—–w- c:\program files\Pure Networks
2009-07-04 17:53 . 2006-02-16 09:55 ——– d—–w- c:\program files\Common Files\AOL
2009-07-04 17:52 . 2006-02-16 09:55 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2009-06-05 18:57 . 2009-06-05 18:57 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-05 16:42 . 2009-07-04 21:26 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-05 16:42 . 2009-07-04 21:26 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-05-13 05:15 . 2006-02-15 14:04 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-08 06:52 . 2009-05-08 06:52 2082104 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\[removed]\plugins\npTVUAx.dll
2009-05-07 15:32 . 2006-02-15 14:02 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-01 21:03 . 2006-02-16 09:50 120056 ——w- c:\windows\system32\pxcpyi64.exe
2009-05-01 21:03 . 2006-02-16 09:50 118520 ——w- c:\windows\system32\pxinsi64.exe
2009-05-01 21:03 . 2005-10-26 20:12 43528 ——w- c:\windows\system32\drivers\pxhelp20.sys
2009-05-01 21:02 . 2009-05-01 21:02 90112 —-a-w- c:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 —-a-w- c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 —-a-w- c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 —-a-w- c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 —-a-w- c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 —-a-w- c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 —-a-w- c:\windows\system32\DivX.dll
2009-04-17 12:26 . 2006-02-15 14:04 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2006-02-15 14:03 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-04 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 761945]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-12-16 82009]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 73728]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-27 122880]
"dla"="c:\windows\system32\dla\DLACTRLW.exe" [2005-10-06 122940]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-18 151552]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-07-04 122368]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-03-11 73728]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-10-15 88203]
"NDSTray.exe"="NDSTray.exe" [BU]
"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-06-01 282624]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-2-15 155648]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/10/2009 7:38 PM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1029456]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/18/2008 9:37 PM 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [7/4/2009 3:46 PM 101936]
S0 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys –> c:\windows\system32\drivers\Partizan.sys [?]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [1/13/2008 4:32 AM 23888]
S3 SVRPEDRV;SVRPEDRV;\??\c:\sysprep\PEDrv.sys –> c:\sysprep\PEDrv.sys [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]

2009-07-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-MalwareRemovalBot - c:\program files\MalwareRemovalBot\MalwareRemovalBot.exe
HKLM-Run-PadTouch - c:\program files\TOSHIBA\Touch and Launch\PadExe.exe
HKLM-Run-net - c:\windows\system32\net.net
HKLM-Run-ats - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = hxxp://www.toshibadirect.com/dpdstart
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJPI150_04.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-11 12:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\system32\drivers\tcqckxqbjamq.sys 77312 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\bxyjilwa]
"ImagePath"="\??\c:\windows\system32\drivers\tcqckxqbjamq.sys"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(5080)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
c:\windows\system32\TDispVol.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Synaptics\SynTP\Toshiba.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\TPSBattM.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2009-07-11 13:00 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-11 18:00

Pre-Run: 14,851,907,584 bytes free
Post-Run: 14,801,371,136 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

414 — E O F — 2009-07-10 04:16


Thanks,
Jigs

Why we don't ask you to run ComboFix from the onset
As stated by the author of ComboFix:
ComboFix is a very powerful tool which when improperly used may render your machine to a doorstop.
We first need to verify if there's any rootkits present and how they could affect our tools. DDS & GMER are preliminary scans. We use their logs to map our strategy for attack.
With these logs we can determine the infections present & decide whether to deploy ComboFix.


Please do the following:

STEP #1

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi, Thanks for your reply. Attached are DDS.txt, Attach.txt and Gmer.zip (Gmer.txt) documents. Sorry I had to create a zip file for Gmer.txt since the document is 2MB and wasn't able to attached it due to the limit. Please let me know if you need anything else. Thanks, Jigs

Attachments:

Hi,

One or more of the identified infections is a rootkit.

This type of infection may have the ability to compromise the personal information on your machine.
If you do any banking or other financial transactions on the PC or if it contains any other sensitive information, then from a clean computer, change all passwords where applicable.
It would also be wise to contact those same financial institutions to appraise them of your situation.
Please read this: How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?


Please do the following:

Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

Below is the contents from Combo-Fix.txt document. Also please tell me how to uninstall Combo-Fix from my laptop. Thanks for your help.

Jigs

ComboFix 09-07-14.08 - Jignesh Mehta 07/15/2009 19:30.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.495 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: Norton 360 *On-access scanning disabled* (Updated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
FW: Norton 360 *enabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\str.sys
c:\windows\system32\drivers\tcqckxqbjamq.sys
c:\windows\system32\microday08.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_BXYJILWA


((((((((((((((((((((((((( Files Created from 2009-06-16 to 2009-07-16 )))))))))))))))))))))))))))))))
.

2009-07-15 23:51 . 2009-07-15 23:55 ——– d—–w- c:\program files\Fast AVI MPEG Joiner
2009-07-15 03:08 . 2009-07-15 03:08 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-07-15 03:07 . 2009-07-15 03:07 152576 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-15 00:14 . 2009-07-15 00:14 ——– d–h–w- c:\windows\PIF
2009-07-14 01:51 . 2009-07-14 01:51 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\Malwarebytes
2009-07-14 01:51 . 2009-07-13 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-14 01:51 . 2009-07-14 01:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-14 01:51 . 2009-07-13 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-14 01:51 . 2009-07-14 01:51 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-11 19:42 . 2009-07-11 19:42 ——– d—–w- c:\program files\Trend Micro
2009-07-11 19:30 . 2009-07-11 19:30 348496 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-07-11 19:17 . 2009-07-11 19:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-07-11 18:42 . 2009-07-11 18:42 ——– d—–w- c:\program files\AdAwarePortable
2009-07-11 18:28 . 2009-07-11 18:28 ——– d—–w- c:\program files\UPHClean
2009-07-11 05:48 . 2009-07-11 05:48 ——– d—–w- c:\documents and settings\Jignesh Mehta\Local Settings\Application Data\Symantec
2009-07-11 00:47 . 2009-07-11 00:47 ——– d—–w- c:\windows\RestoreSafeDeleted
2009-07-11 00:37 . 2009-07-11 18:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft-BackupByAdAwarePortable
2009-07-11 00:26 . 2009-07-11 00:26 2 –shatr- c:\windows\winstart.bat
2009-07-11 00:26 . 2009-07-11 00:26 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\Regrun
2009-07-11 00:26 . 2009-07-11 00:26 ——– d—–w- C:\backreg
2009-07-10 23:48 . 2009-07-10 23:49 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\MalwareRemovalBot
2009-07-10 22:12 . 2009-07-10 22:12 ——– d—–w- c:\windows\Sun
2009-07-10 04:11 . 2009-07-11 01:32 ——– d—–w- c:\program files\Fast AVI MPEG Splitter
2009-07-10 00:59 . 2009-07-10 00:59 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\AdobeUM
2009-07-09 03:59 . 2009-07-09 03:59 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-07-09 03:59 . 2009-07-09 03:59 ——– d—–w- c:\windows\SHELLNEW
2009-07-09 03:59 . 2009-07-09 03:59 ——– d—–w- c:\program files\Microsoft.NET
2009-07-08 00:02 . 2009-07-08 00:02 ——– d—–w- c:\windows\system32\scripting
2009-07-08 00:02 . 2009-07-08 00:02 ——– d—–w- c:\windows\l2schemas
2009-07-08 00:02 . 2009-07-08 00:02 ——– d—–w- c:\windows\system32\en
2009-07-08 00:02 . 2009-07-08 00:02 ——– d—–w- c:\windows\system32\bits
2009-07-07 23:58 . 2009-07-08 00:03 ——– d—–w- c:\windows\ServicePackFiles
2009-07-07 00:48 . 2009-07-07 00:48 ——– d—–w- c:\program files\ImTOO
2009-07-07 00:03 . 2009-07-07 00:03 7168 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Thinstall\iPhoneRingToneMaker 2.5.1\4000003f00003i\faac.exe
2009-07-07 00:01 . 2009-07-07 00:01 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\Thinstall
2009-07-06 23:42 . 2009-03-24 19:43 43008 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metricsloader.dll
2009-07-06 23:42 . 2009-03-24 19:43 43008 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-07-06 23:42 . 2009-03-24 19:43 235520 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\metrics-ff2.dll
2009-07-06 23:42 . 2009-03-24 19:43 338432 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-07-06 23:42 . 2009-03-24 19:42 345088 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-07-06 23:42 . 2009-03-24 19:42 235008 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\metrics-ff3.dll
2009-07-06 03:30 . 2009-07-06 03:31 ——– d-sh–w- c:\windows\system32\asd
2009-07-06 03:30 . 2009-07-06 03:30 ——– d—–w- c:\program files\Accurate Shutdown
2009-07-06 03:17 . 2009-07-06 03:17 ——– d—–w- c:\program files\AC3Filter
2009-07-06 00:45 . 2007-10-23 14:27 110592 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\U3\temp\cleanup.exe
2009-07-06 00:39 . 2007-10-23 14:22 3350528 —ha-w- c:\documents and settings\Jignesh Mehta\Application Data\U3\temp\Launchpad Removal.exe
2009-07-06 00:39 . 2009-07-11 01:50 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\U3
2009-07-05 19:55 . 2008-10-16 19:06 268648 —-a-w- c:\windows\system32\mucltui.dll
2009-07-04 22:20 . 2009-07-04 22:20 ——– d—–w- c:\program files\MSXML 4.0
2009-07-04 22:16 . 2009-07-04 22:16 ——– d—–w- c:\program files\SopCast
2009-07-04 22:15 . 2009-07-04 22:15 ——– d—–w- c:\documents and settings\Jignesh Mehta\Local Settings\Application Data\TVU Networks
2009-07-04 22:15 . 2009-07-04 22:15 ——– d—–w- c:\documents and settings\All Users\Application Data\TVU Networks
2009-07-04 22:15 . 2009-07-04 22:15 ——– d—–w- c:\documents and settings\Jignesh Mehta\LocalLow
2009-07-04 22:15 . 2009-07-04 22:15 ——– d—–w- c:\program files\TVUPlayer
2009-07-04 20:43 . 2009-07-04 20:43 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\McAfee.com Personal Firewall
2009-07-04 20:42 . 2006-05-13 23:19 3774 —-a-r- c:\windows\system32\config\systemprofile\Application Data\Microsoft\Installer\{F21B28BF-8A4D-4F1A-A61B-69DD5B4A9BBA}\_644366bb.exe
2009-07-04 20:42 . 2006-05-13 22:56 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\AOL
2009-07-04 20:42 . 2006-02-16 09:56 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\You've Got Pictures Screensaver
2009-07-04 20:42 . 2006-02-16 09:18 ——– d—–w- c:\windows\system32\config\systemprofile\WINDOWS
2009-07-04 20:42 . 2006-02-16 09:18 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\toshiba
2009-07-04 20:42 . 2009-07-04 20:42 21275 —-a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-04 20:42 . 2009-07-04 20:42 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Intel
2009-07-04 20:42 . 2009-07-04 20:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Intel
2009-07-04 20:42 . 2009-07-04 20:42 ——– d—–w- c:\documents and settings\Administrator\Application Data\Intel
2009-07-04 20:41 . 2009-07-11 18:33 ——– dc—-w- c:\windows\system32\DRVSTORE
2009-07-04 20:41 . 2006-02-16 09:18 ——– d—–w- c:\documents and settings\Default User\WINDOWS
2009-07-04 20:39 . 2009-07-04 20:39 ——– d—–w- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-07-04 20:34 . 2009-07-04 20:34 ——– d—–w- c:\program files\AVerMedia
2009-07-04 20:33 . 2009-07-04 20:33 ——– d—–w- c:\program files\Common Files\InterVideo
2009-07-04 20:33 . 2005-11-28 05:51 135168 —-a-w- c:\windows\system32\igfxres.dll
2009-07-04 20:28 . 2009-07-04 20:28 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-07-04 20:16 . 2009-07-04 20:57 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\Symantec
2009-07-04 20:13 . 2009-07-04 20:13 ——– d—–w- c:\program files\Windows Sidebar
2009-07-04 20:12 . 2009-07-08 00:13 ——– d—–w- c:\program files\Norton 360
2009-07-04 20:11 . 2009-07-04 20:44 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2009-07-04 20:11 . 2009-07-04 20:44 124464 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-07-04 20:11 . 2009-07-09 23:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-04 20:11 . 2009-07-04 20:44 ——– d—–w- c:\program files\Symantec
2009-07-04 20:10 . 2009-07-16 00:40 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-07-04 20:06 . 2009-07-04 20:06 ——– d—–w- C:\Jigs
2009-07-04 20:06 . 2009-07-14 23:54 ——– d—–w- C:\Downloads
2009-07-04 20:06 . 2009-07-04 20:06 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\AVS4YOU
2009-07-04 20:06 . 2009-07-04 20:06 ——– d—–w- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-07-04 20:05 . 2009-07-04 20:05 ——– d—–w- c:\program files\Common Files\AVSMedia
2009-07-04 20:05 . 2009-01-29 00:49 974848 —-a-w- c:\windows\system32\mfc70.dll
2009-07-04 20:05 . 2009-01-29 00:49 487424 —-a-w- c:\windows\system32\msvcp70.dll
2009-07-04 20:05 . 2009-01-29 00:49 344064 —-a-w- c:\windows\system32\msvcr70.dll
2009-07-04 20:05 . 2009-07-04 20:05 ——– d—–w- c:\program files\AVS4YOU
2009-07-04 20:05 . 2009-01-29 00:49 1700352 —-a-w- c:\windows\system32\GdiPlus.dll
2009-07-04 20:05 . 2009-01-29 00:49 24576 —-a-w- c:\windows\system32\msxml3a.dll
2009-07-04 19:50 . 2009-07-04 19:50 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\DivX
2009-07-04 19:49 . 2009-07-11 16:23 ——– d—–w- c:\program files\Disk Cleaner
2009-07-04 19:47 . 2008-04-14 00:12 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-07-04 19:39 . 2009-07-04 19:39 ——– d—–w- c:\program files\Windows Media Connect 2
2009-07-04 19:36 . 2009-07-04 19:38 ——– d—–w- c:\windows\system32\drivers\UMDF
2009-07-04 19:36 . 2009-07-04 19:36 ——– d—–w- c:\windows\system32\LogFiles
2009-07-04 19:26 . 2009-07-04 19:26 ——– d-sh–w- c:\documents and settings\Jignesh Mehta\PrivacIE
2009-07-04 19:20 . 2009-07-04 19:20 ——– d-sh–w- c:\documents and settings\Jignesh Mehta\IETldCache
2009-07-04 19:18 . 2009-07-04 19:18 ——– d—–w- c:\windows\ie8updates
2009-07-04 19:16 . 2009-07-04 19:17 ——– dc-h–w- c:\windows\ie8
2009-07-04 19:01 . 2009-07-04 19:01 ——– d-sh–w- c:\documents and settings\Jignesh Mehta\UserData
2009-07-04 18:53 . 2009-06-02 10:12 102912 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2009-07-04 18:53 . 2009-04-30 21:22 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-07-04 18:53 . 2009-04-30 21:22 1985024 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2009-07-04 18:53 . 2009-04-30 21:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-04 18:53 . 2009-04-30 21:22 11064832 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2009-07-04 18:42 . 2009-05-01 21:03 9464 ——w- c:\windows\system32\drivers\cdralw2k.sys
2009-07-04 18:42 . 2009-05-01 21:03 9336 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2009-07-04 18:42 . 2009-05-01 21:03 129784 ——w- c:\windows\system32\pxafs.dll
2009-07-04 18:41 . 2009-07-04 18:42 ——– d—–w- c:\program files\DivX
2009-07-04 18:41 . 2009-07-04 18:41 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-07-04 18:39 . 2008-04-14 00:12 20992 ——w- c:\windows\system32\spupdwxp.exe
2009-07-04 18:38 . 2008-04-14 00:11 61440 ——w- c:\windows\system32\kmsvc.dll
2009-07-04 18:12 . 2008-06-13 11:05 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2009-07-04 18:12 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2009-07-04 18:10 . 2009-07-04 18:10 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-04 18:08 . 2008-05-08 14:02 203136 -c—-w- c:\windows\system32\dllcache\rmcast.sys
2009-07-04 18:08 . 2008-10-24 11:21 455296 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2009-07-04 18:07 . 2008-12-11 10:57 333952 -c—-w- c:\windows\system32\dllcache\srv.sys
2009-07-04 18:07 . 2008-05-01 14:33 331776 -c—-w- c:\windows\system32\dllcache\msadce.dll
2009-07-04 18:07 . 2008-04-11 19:04 691712 -c—-w- c:\windows\system32\dllcache\inetcomm.dll
2009-07-04 18:07 . 2009-07-04 18:07 ——– d—–w- c:\documents and settings\Jignesh Mehta\Local Settings\Application Data\Mozilla
2009-07-04 18:03 . 2008-10-03 10:02 247326 -c—-w- c:\windows\system32\dllcache\strmdll.dll
2009-07-04 18:03 . 2008-10-15 16:34 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll
2009-07-04 18:03 . 2008-09-04 17:15 1106944 -c—-w- c:\windows\system32\dllcache\msxml3.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-15 03:08 . 2006-02-16 09:28 ——– d—–w- c:\program files\Java
2009-07-09 23:32 . 2006-02-16 16:59 35848 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-08 00:05 . 2006-02-15 15:37 87931 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-07 00:59 . 2009-07-04 21:28 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\Apple Computer
2009-07-07 00:58 . 2009-07-04 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-07-04 22:30 . 2006-02-16 10:39 ——– d—–w- c:\program files\Microsoft Works
2009-07-04 21:58 . 2006-02-18 15:56 ——– d—–w- c:\program files\Google
2009-07-04 21:36 . 2009-07-04 21:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-04 21:28 . 2009-07-04 21:28 ——– d—–w- c:\program files\iTunes
2009-07-04 21:28 . 2009-07-04 21:28 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-04 21:28 . 2009-07-04 21:28 ——– d—–w- c:\program files\iPod
2009-07-04 21:28 . 2009-07-04 21:26 ——– d—–w- c:\program files\Common Files\Apple
2009-07-04 21:27 . 2009-07-04 21:27 ——– d—–w- c:\program files\Bonjour
2009-07-04 21:26 . 2009-07-04 21:26 ——– d—–w- c:\program files\Apple Software Update
2009-07-04 20:44 . 2009-07-04 20:11 10635 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-07-04 20:44 . 2009-07-04 20:11 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-07-04 20:42 . 2006-02-15 16:18 ——– d—–w- c:\program files\Intel
2009-07-04 20:42 . 2009-07-04 20:43 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\Intel
2009-07-04 20:33 . 2006-02-16 09:25 ——– d—–w- c:\program files\InterVideo
2009-07-04 20:33 . 2006-02-15 16:20 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-04 19:02 . 2006-05-13 23:44 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2009-07-04 18:18 . 2006-02-16 10:14 ——– d—–w- c:\program files\Yahoo!
2009-07-04 18:18 . 2006-05-13 23:35 ——– d—–w- c:\documents and settings\All Users\Application Data\YAHOO
2009-07-04 18:07 . 2009-07-04 20:43 ——– d—–w- c:\documents and settings\Jignesh Mehta\Application Data\McAfee.com Personal Firewall
2009-07-04 17:53 . 2006-02-16 09:55 ——– d—–w- c:\program files\Pure Networks
2009-07-04 17:53 . 2006-02-16 09:55 ——– d—–w- c:\program files\Common Files\AOL
2009-07-04 17:52 . 2006-02-16 09:55 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2009-06-05 18:57 . 2009-06-05 18:57 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-05 16:42 . 2009-07-04 21:26 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-05 16:42 . 2009-07-04 21:26 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-05-13 05:15 . 2006-02-15 14:04 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-08 06:52 . 2009-05-08 06:52 2082104 —-a-w- c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\extensions\[removed]\plugins\npTVUAx.dll
2009-05-07 15:32 . 2006-02-15 14:02 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-01 21:03 . 2006-02-16 09:50 120056 ——w- c:\windows\system32\pxcpyi64.exe
2009-05-01 21:03 . 2006-02-16 09:50 118520 ——w- c:\windows\system32\pxinsi64.exe
2009-05-01 21:03 . 2005-10-26 20:12 43528 ——w- c:\windows\system32\drivers\pxhelp20.sys
2009-05-01 21:02 . 2009-05-01 21:02 90112 —-a-w- c:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 —-a-w- c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 —-a-w- c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 —-a-w- c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 —-a-w- c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 —-a-w- c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 —-a-w- c:\windows\system32\DivX.dll
2009-04-17 12:26 . 2006-02-15 14:04 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-06-24 13:26 . 2009-07-04 18:07 137208 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-04 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 761945]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-12-16 82009]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 73728]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-27 122880]
"dla"="c:\windows\system32\dla\DLACTRLW.exe" [2005-10-06 122940]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-18 151552]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-07-04 122368]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-15 148888]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-03-11 73728]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-10-15 88203]
"NDSTray.exe"="NDSTray.exe" [BU]
"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-06-01 282624]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-2-15 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AdAwarePortable\\App\\AdAware\\Ad-Aware.exe"=

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\AdAwarePortable\App\AdAware\AAWService.exe [7/3/2009 9:49 AM 1029456]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/18/2008 9:37 PM 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [7/4/2009 3:46 PM 101936]
S0 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys –> c:\windows\system32\drivers\Partizan.sys [?]
S2 bxyjilwa;bxyjilwa;\??\c:\windows\system32\drivers\tcqckxqbjamq.sys –> c:\windows\system32\drivers\tcqckxqbjamq.sys [?]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [1/13/2008 4:32 AM 23888]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [7/13/2009 8:51 PM 38160]
S3 SVRPEDRV;SVRPEDRV;\??\c:\sysprep\PEDrv.sys –> c:\sysprep\PEDrv.sys [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - COMHOST
*Deregistered* - uphcleanhlp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\AdAwarePortable\App\AdAware\Ad-AwareAdmin.exe [2009-07-03 14:49]

2009-07-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-ats - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = hxxp://www.toshibadirect.com/dpdstart
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jignesh Mehta\Application Data\Mozilla\Firefox\Profiles\4dd0dgbr.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-15 19:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3600)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
c:\windows\system32\TDispVol.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
c:\program files\UPHClean\uphclean.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Synaptics\SynTP\Toshiba.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\TPSBattM.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\AdAwarePortable\App\AdAware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2009-07-16 19:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-16 00:45

Pre-Run: 14,235,426,816 bytes free
Post-Run: 14,205,566,976 bytes free

387 — E O F — 2009-07-10 04:16

please tell me how to uninstall Combo-Fix from my laptop


There is a special removal routine which we will implement once the computer is totally clean, right now, we still need it.

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

KillAll::

Folder::
c:\documents and settings\Jignesh Mehta\Application Data\MalwareRemovalBot

File::
c:\windows\system32\drivers\tcqckxqbjamq.sys

Driver::
bxyjilwa

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.

NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report


Also, Please describe how your computer is running now and if there are any outstanding issues.
Hi, I lost my Internet connection after I performed the first step with ComboFix. Now my wireless connection keep saying "limited or no connectivity". I am not able to go on Internet any more. I am using my iPhone to reply here. Please help me get back online. Thanks jigs
Hi,

A reboot should fix the problem, if not, try the following:


if your network icon appears on the Windows taskbar, then you can repair it by right-clicking on the icon and selecting Repair.

[external image: Posted Image]

If you have no task bar icon do this:

  • Click on the Start button.
  • Click on the Settings menu option.
  • Click on the Control Panel option.
  • When the Control Panel opens, double-click on the Network Connections icon. If your Control Panel is set to Category View, then double-click on Network and Internet Connections and then click on Network Connections at the bottom.
  • You will now see a list of available network connections. Locate the connection for your Wireless or Lan adapter and right-click on it.
  • click on the Repair menu option.

[external image: Posted Image]

Let the repair process perform its tasks and when it has finished, your Internet connection should be working again.
Thanks for the reply. I did do repair as you mentioned but nothing seems to be helping. I am still getting Limited or No connectivity message. Please advice.
Hi,

Please try the following:

First - Flush your DNS

  • Go to Start > Run > type: cmd
  • Press OK or Hit Enter.
  • At the command prompt, type or copy/paste: ipconfig /flushdns (note the space between “..g /f…” it needs to be there)
  • Hit Enter.
  • You will get a confirmation that the flush was successful.
  • Close the command box.


NEXT


Please reset IE

  • Go to Start > Control Panel, and choose Network Connections.
  • Right click on your default connection, usually Local Area Connection for cable and DSL or Dial-up Connection if you are using Dial-up, and choose Properties.
  • Click the Networking tab
  • Double-click on the Internet Protocol (TCP/IP) item.
  • Write down the settings in case you should need to change them back.
  • Select the radio button that says "Obtain DNS servers automatically".
  • Click OK twice to get out of the properties screen and restart your computer.
  • If not prompted to reboot go ahead and reboot manually.

In I.E.
  • Check internet options settings.
  • Tools > Internet Options > Connections
  • LAN settings
  • Choose "automatically detect settings"
  • uncheck both proxy settings boxes

In FireFox
  • Click on Advanced -> Network -> Setttings…
  • the No Proxy option should be selected
Hi, can you also post a fresh DDS log in case there is something there shutting you down. If nothing in my above post gets the connection restarted - Try logging into the "Last Known Good Configuration" Tap F8 repeatedly on bootup until a windows option screen appears - arrow up to "last Known Good configuration" and select… see if you can now connect. - Let me know what worked (if anything)
Hi, That did do anything good. I have tried everything you mentioned and still couldn't get connect to internet. When I do view available wireless networks, I get a message saying "Windows cannot configure the wireless connection." Also about he DDS log, when I run the DDS.pif I get a message saying "The system cannot find the file specified." I have attached the new Combo-Fix log that created all this issues. Please advice. Thanks, Jigs

Attachments:

Hi,

Try this one last thing, if that doesn't connect you then please start a new topic in out Internet forum to let the expert techs figure out what's causing the connection issues as I'm out of ideas.

Link back to this topic so they can see what has gone on and what we have done so far.

then come back here so we can finish cleaning:

try this first:

Please download and run Winsock Fix. Before you choose the Fix option, please backup your registry (you can do this from within the program). Once you have backed up your registry,
choose the Fix option and then restart your computer; try to connect to the Internet
I tried that and that didn't work either so I have decided to format my hard drive and re-image it. I just wanted to thank you for all your help that you provided. Thanks a lot and you can close this topic. Jigs
That's probably the best idea, you were seriously infected with a rootkit, at least this way, you can be certain you have a trustworthy machine once again. Sorry I couldn't help you more. cheers ~CB

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI