This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Baseline

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Everyone!
I hope that I did everything you require to fix my pop up problem. Nothing like porn popping up on your computer with a 9 year old looking over your shoulder. :blush: I have run the Erunt, ATF Cleaner, and Malwawarbytes Anti-Malware.

Here is my Malwarebytes log:

Malwarebytes' Anti-Malware 1.39
Database version: 2529
Windows 6.0.6001 Service Pack 1

7/29/2009 9:25:36 PM
mbam-log-2009-07-29 (21-25-36).txt

Scan type: Quick Scan
Objects scanned: 81935
Time elapsed: 10 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 29
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 9
Files Infected: 16

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\NPIEAddOn.dll (Adware.DoubleD) -> Delete on reboot.
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\NPCommon.dll (Adware.DoubleD) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\explorerbar.funexplorer (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\explorerbar.funexplorer.1 (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\explorerbar.funredirector (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\explorerbar.funredirector.1 (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{480098c6-f6ad-4c61-9b5c-2bae228a34d1} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6160f76a-1992-4b17-a32d-0c706d159105} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{877f3eab-4462-44df-8475-6064eafd7fbf} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{25b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{35b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c28a0312-c403-417b-a425-a915bc0519cd} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a84e835e-1b9c-4fc0-980f-4b2da3c6a2a7} (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bf0a1ff4-bbaf-487f-bc85-a24ef8f443a8} (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{883dfc00-8a21-411d-956c-73a4e4b7d16f} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{ac5ab953-ed25-4f9c-87f0-b086b0178ffa} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{cdbfb47b-58a8-4111-bf95-06178dce326d} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5617eca9-488d-4ba2-8562-9710b9ab78d2} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f919fbd3-a96b-4679-af26-f551439bb5fd} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a84e835e-1b9c-4fc0-980f-4b2da3c6a2a7} (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Media Access Startup (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1fb52ab3-5987-45a2-85e0-f3ec30dddc29}}_is1 (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{16b6279b-9ff5-41fb-8bf9-404324f5dd1f}}_is1 (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{c5096216-7703-409e-b85a-8a6ee7395128}}_is1 (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\{0ba0192d-94a5-45e3-b2b8-3ec5a1a0b5ec} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\{2224e955-00e9-4613-a844-ce69fccaae91} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{5617eca9-488d-4ba2-8562-9710b9ab78d2} (Adware.DoubleD) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\DoubleD (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\DoubleD\GamingHarbor Toolbar (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Program Files\Internet Saving Optimizer (Adware.DoubleD) -> Delete on reboot.
c:\program files\internet saving optimizer\3.4.0.4340 (Adware.DoubleD) -> Delete on reboot.
c:\program files\internet saving optimizer\3.4.0.4340\Data (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\FF (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\FF\chrome (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\FF\chrome\content (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\FF\components (Adware.DoubleD) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\Internet Saving Optimizer\3.4.0.4340\NPIEAddOn.dll (Adware.DoubleD) -> Delete on reboot.
c:\program files\outlook\v.tmp (Worm.P2P) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\adwpx.exe (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\NPCommon.dll (Adware.DoubleD) -> Delete on reboot.
c:\program files\internet saving optimizer\3.4.0.4340\unins000.dat (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\unins000.exe (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\Data\config.md (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\FF\chrome.manifest (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\FF\install.rdf (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\FF\chrome\NPAddOn.jar (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\FF\chrome\content\NPAddOn.js (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\FF\chrome\content\NPAddOn.xul (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\FF\components\NPFFAddOn.dll (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\FF\components\NPFFAddOn.xpt (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.4.0.4340\FF\components\NPFFHelperComponent.js (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\outlook\p.zip (Worm.Alcra) -> Quarantined and deleted successfully.

Here is my hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:43:26 PM, on 7/29/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\ltmoh\ltmoh.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ATT Internet Tools\blsloader.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchProtocolHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:/Users/Holly/Music/Temp/RT/WebRip/profile/rrproxy_ie_48e4e80c.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\ATT Internet Tools\blspc.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AT&&T Toolbar - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [blspcloader] C:\Program Files\ATT Internet Tools\blsloader.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to AMV Converter… - C:\Program Files\MP3 Player Utilities 4.19\AMVConverter\grab.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\Program Files\McAfee\VirusScan\Mcshield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 9596 bytes

I appreciate any help that I can get. Thanks so much!
Holly
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thank you so much. Here are the 3 things you asked for:

DDS Log:
DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 22:42:02.30 on Fri 07/31/2009
Internet Explorer: 8.0.6001.18813 BrowserJavaVersion: 1.6.0_07
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.445.80 [GMT -7:00]

SP: Spyware Doctor *enabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Windows\system32\svchost.exe -k imgsvc
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\ltmoh\ltmoh.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ATT Internet Tools\blsloader.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Holly\Desktop\dds.pif
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://att.net
uWindow Title = Windows Internet Explorer provided by Yahoo!
uDefault_Page_URL = hxxp://att.net
mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: BlspcHlpr Class: {15c9938f-cb96-496d-800a-b827f2e34ea1} - c:\program files\att internet tools\blspc.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No File
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\TOSCDSPD.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun: [HWSetup] c:\program files\toshiba\utilities\HWSetup.exe hwSetUP
mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe
mRun: [LtMoh] c:\program files\ltmoh\Ltmoh.exe
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [SVPWUTIL] c:\program files\toshiba\utilities\SVPWUTIL.exe SVPwUTIL
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [MSConfig] "c:\windows\system32\msconfig.exe" /auto
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [blspcloader] c:\program files\att internet tools\blsloader.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: turbotax.com
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2009-07-29 21:37 –d—– c:\program files\Trend Micro
2009-07-29 21:03 –d—– c:\users\holly\appdata\roaming\Malwarebytes
2009-07-29 21:03 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-29 21:03 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-29 21:03 –d—– c:\programdata\Malwarebytes
2009-07-29 21:03 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-07-29 21:03 –d—– c:\progra~2\Malwarebytes
2009-07-27 09:17 9,062 a——- c:\windows\system32\small1.ico
2009-07-27 09:17 9,062 a——- c:\windows\system32\small.ico
2009-07-27 09:16 –d—– c:\program files\ATT Internet Tools
2009-07-27 09:07 –d—– c:\program files\ATTToolbar
2009-07-27 03:43 56 a—h— c:\programdata\ezsidmv.dat
2009-07-27 03:43 56 a—h— c:\progra~2\ezsidmv.dat
2009-07-27 02:26 –d–r– c:\program files\Skype
2009-07-27 02:26 –d—– c:\programdata\Skype
2009-07-14 20:54 156,672 a——- c:\windows\system32\t2embed.dll
2009-07-14 20:54 289,792 a——- c:\windows\system32\atmfd.dll
2009-07-14 20:54 72,704 a——- c:\windows\system32\fontsub.dll
2009-07-14 20:54 10,240 a——- c:\windows\system32\dciman32.dll
2009-07-12 15:46 327,680 a—-r– c:\windows\system32\AegisE2.dll
2009-07-12 15:46 651,264 a—-r– c:\windows\system32\libeay32.dll
2009-07-12 15:46 450,560 a—-r– c:\windows\system32\AegisE5.dll
2009-07-12 15:46 114,688 a——- c:\windows\system32\athcfg10.dll
2009-07-12 15:45 147,456 a—-r– c:\windows\system32\ssleay32.dll
2009-07-10 22:17 11,776 a——- c:\windows\system32\drivers\afc.sys
2009-07-10 22:16 212,480 a——- c:\windows\PCDLIB32.DLL
2009-07-10 21:58 48,128 ——– c:\windows\system32\Remove.exe
2009-07-10 21:58 399 ——– c:\windows\system32\Remover.ini
2009-07-10 21:58 618,112 a——- c:\windows\system32\drivers\PFC027.SYS
2009-07-10 21:58 6,656 a——- c:\windows\system32\CoInst_080213.dll
2009-07-10 21:58 –d—– c:\program files\Salix
2009-07-10 21:58 129,024 a——- c:\windows\system32\SP207.ax
2009-07-10 21:58 566 a——- c:\windows\system32\SP207.ini
2009-07-10 21:58 14,336 a——- c:\windows\system32\P207USD.dll
2009-07-10 21:58 –d—– c:\windows\PixArt
2009-07-10 21:58 –d—– c:\program files\common files\PAC207

==================== Find3M ====================

2009-07-21 14:52 915,456 a——- c:\windows\system32\wininet.dll
2009-07-21 14:47 109,056 a——- c:\windows\system32\iesysprep.dll
2009-07-21 14:47 71,680 a——- c:\windows\system32\iesetup.dll
2009-07-21 13:13 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-07-10 21:59 86,016 a——- c:\windows\inf\infstrng.dat
2009-07-10 21:59 86,016 a——- c:\windows\inf\infstor.dat
2009-07-10 21:59 51,200 a——- c:\windows\inf\infpub.dat
2008-09-10 14:58 115,969 a——- c:\users\holly\a.zip
2008-07-03 09:51 174 a–sh— c:\program files\desktop.ini
2008-07-03 09:36 665,600 a——- c:\windows\inf\drvindex.dat
2008-01-30 09:27 2,276 a——- c:\users\holly\appdata\roaming\wklnhst.dat
2007-02-22 01:00 1,117,491 a——- c:\users\holly\dvdshrink32setup.exe
2006-11-02 05:39 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:39 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:39 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:39 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 22:48:02.02 ===============

Attach.txt
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft® Windows Vista™ Home Basic
Boot Device: \Device\HarddiskVolume2
Install Date: 3/8/2007 2:20:41 PM
System Uptime: 7/31/2009 8:28:30 AM (14 hours ago)

Motherboard: TOSHIBA | | IAYAA
Processor: Intel® Celeron® M CPU 430 @ 1.73GHz | U1 | 1733/mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 73 GiB total, 22.9 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================


==== Installed Programs ======================

2007 Microsoft Office Suite Service Pack 1 (SP1)
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.2
Adobe Shockwave Player
AnswerWorks 4.0 Runtime - English
Apple Mobile Device Support
Apple Software Update
ArcSoft VideoImpression 2
AT&T Pop-Up Catcher
Atheros Driver Installation Program
ATI Catalyst Control Center Ex
ATI Catalyst Install Manager
AutoUpdate
Bejeweled 2 Deluxe 1.1
CD/DVD Drive Acoustic Silencer
Desktop Dialer
DivX Codec
DivX Version Checker
Dragon Flame (désinstalation seulement)
DVD Decrypter (Remove Only)
DVD MovieFactory for TOSHIBA
DVD Shrink 3.2
ERUNT 1.1j
Google Toolbar for Internet Explorer
Graboid Video 1.65
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
IrfanView (remove only)
Java™ 6 Update 13
Java™ 6 Update 6
Java™ 6 Update 7
Java™ SE Runtime Environment 6
LimeWire 5.0.11
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft .NET Framework 3.5 SP1
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007 Trial
Microsoft Office Live Small Business Image Uploader
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Microsoft XML Parser
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
oggcodecs 0.71.0946
PC Camer@
Peggle Deluxe 1.0
Personal Ancestral File 5
Personal Ancestral File Companion 5.1.5
PixiePack Codec Pack
QuickBooks Simple Start 2008
QuickBooks Simple Start Edition
QuickBooks Simple Start Free Starter Edition
QuickTime
Realtek 8139 and 8139C+ Ethernet Network Card Driver for Windows Vista
Realtek High Definition Audio Driver
Rhapsody Player Engine
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB969679)
Security Update for Microsoft Office Excel 2007 (KB969682)
Security Update for Microsoft Office OneNote 2007 (KB950130)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office Word 2007 (KB969604)
Skype web features
Skype™ 4.1
SUPERAntiSpyware Free Edition
SupportSoft Assisted Service
Synaptics Pointing Device Driver
The Learning Tool 1.2.2
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Disc Creator
TOSHIBA Extended Tiles for Windows Mobility Center
TOSHIBA Flash Cards Support Utility
TOSHIBA Game Console
TOSHIBA Hardware Setup
Toshiba Registration
TOSHIBA Software Modem
TOSHIBA Software Upgrades
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Utility Common Driver
VC80CRTRedist - 8.0.50727.762
WinDVD for TOSHIBA

==== End Of File ===========================
GMER
GMER 1.0.15.15011 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-01 16:22:33
Windows 6.0.6001 Service Pack 1


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    c:\users\holly\a.zip

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • Virscan Log
  • MBAM Log
  • Kaspersky report
Here is my Virscan log:

VirSCAN.org Scanned Report :
Scanned time : 2009/08/01 22:31:11 (PDT)
Scanner results: 97% Scanner(36/37) found malware!
File Name : a.zip
File Size : 115969 byte
File Type : Zip archive data, at least v2.0 to extract
MD5 : 16bc3a9dbb5abaa3fffb12b4367b7831
SHA1 : 7c309fdbcc0c22a37915be99ad10f851949b1da8
Online report : http://virscan.org/report/676f88aa03418d70…86fc5071c0.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.3 20090731163245 2009-07-31 0.49 Virus.Win32.VB.FXE!IK
AhnLab V3 2009.08.01.00 2009.08.01 2009-08-01 0.76 Win-Trojan/Xema.variant
AntiVir 8.2.0.238 7.1.5.57 2009-07-31 0.43 TR/Agent.tvb
Antiy 2.0.18 20090802.2666756 2009-08-02 0.13 Trojan/Win32.VB.dck[Downloader]
Arcavir 2009 200908011537 2009-08-01 0.06 Downloader.Vb.Dck
Authentium 5.1.1 200908011301 2009-08-01 1.16 W32/Downldr2.BGJC (Exact)
AVAST! 4.7.4 090801-0 2009-08-01 0.03 Win32:VB-FXE [Trj]
AVG 8.5.288 270.13.40/2276 2009-08-02 0.32 Dropper.Generic.VUZ
BitDefender 7.81008.3870725 7.26946 2009-08-02 3.41 Trojan.Generic.2128081
CA (VET) 9.0.0.143 31.6.6649 2009-08-01 8.17 Win32/Fonhos.B trojan.
ClamAV 0.95.2 9641 2009-08-01 0.10 Trojan.Downloader-26456
Comodo 3.10 1836 2009-08-01 0.71 TrojWare.Win32.TrojanDropper.VB.NAI
CP Secure 1.1.0.715 2009.08.01 2009-08-01 11.77 Troj.Downloader.W32.VB.dck
Dr.Web 4.44.0.9170 2009.08.02 2009-08-02 4.96 Trojan.DownLoad.6032
F-Prot 4.4.4.56 20090801 2009-08-01 1.16 W32/Downldr2.BGJC (exact)
F-Secure 7.02.73807 2009.07.29.10 2009-07-29 0.07 Trojan:W32/VB.BJQ [FSE]
Fortinet 2.81-3.120 10.669 2009-08-01 0.21 W32/VB.DCK!tr.dldr
GData 19.6816/19.422 20090802 2009-08-02 4.49 Trojan-Downloader.Win32.VB.dck [Engine:A]
ViRobot 20090730 2009.07.30 2009-07-30 0.41 -
Ikarus T3.1.01.64 2009.08.02.73141 2009-08-02 4.62 Virus.Win32.VB.FXE
JiangMin 11.0.800 2009.08.01 2009-08-01 4.00 TrojanDownloader.VB.ijy
Kaspersky 5.5.10 2009.08.02 2009-08-02 0.03 Trojan-Downloader.Win32.VB.dck
KingSoft 2009.2.5.15 2009.8.1.15 2009-08-01 0.47 Win32.TrojDownloader.VB.282653
McAfee 5.3.00 5695 2009-08-01 2.98 Generic BackDoor.f
Microsoft 1.4903 2009.08.01 2009-08-01 5.17 TrojanDownloader:Win32/Tonick.gen
Norman 6.01.09 6.01.00 2009-07-31 4.00 W32/DLoader.GBUP
Panda 9.05.01 2009.08.01 2009-08-01 1.98 Bck/VB.ABN
Trend Micro 8.700-1004 6.336.29 2009-08-01 0.02 TROJ_VB.CEO
Quick Heal 10.00 2009.07.30 2009-07-30 1.06 TrojanDownloader.VB.dck
Rising 20.0 21.40.44.00 2009-07-31 0.83 Trojan.DL.Win32.VB.zan
Sophos 2.89.1 4.44 2009-08-02 2.73 W32/Zipwire-A
Sunbelt 5306 5306 2009-08-01 1.02 Bulk Trojan
Symantec 1.3.0.24 20090801.003 2009-08-01 0.07 Backdoor.IRC.Bot
nProtect 20090802.01 4993276 2009-08-02 6.06 Trojan-Downloader/W32.Agent.282636
The Hacker 6.3.4.3 v00375 2009-07-31 0.64 Trojan/Downloader.VB.dck
VBA32 3.12.10.9 20090801.1132 2009-08-01 1.80 Trojan-Downloader.Win32.VB.dck
VirusBuster 4.5.11.10 10.110.1/1825217 2009-07-31 2.21 Worm.Pizbot.A

Here is my mbam log:
Malwarebytes' Anti-Malware 1.39
Database version: 2544
Windows 6.0.6001 Service Pack 1

8/1/2009 10:53:15 PM
mbam-log-2009-08-01 (22-53-15).txt

Scan type: Quick Scan
Objects scanned: 81351
Time elapsed: 14 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Here is my Kaspersky Report:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Sunday, August 2, 2009
Operating System: Microsoft Windows Vista Home Basic Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Sunday, August 02, 2009 08:08:25
Records in database: 2572489
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 119310
Threat name: 11
Infected objects: 28
Suspicious objects: 0
Duration of the scan: 03:35:49


File name / Threat name / Threats count
C:\Users\Holly\a.zip Infected: Trojan-Downloader.Win32.VB.dck 1
C:\Users\Holly\AppData\Local\VirtualStore\Program Files\LimeWire\lost in this mome CD quality.mp3 Infected: Trojan-Downloader.WMA.GetCodec.f 1
C:\Users\Holly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\74018dd6-48583716 Infected: Trojan-Downloader.Java.OpenStream.ac 1
C:\Users\Holly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\2dcb5a6f-2644b31b Infected: Trojan-Downloader.Java.OpenConnection.ao 1
C:\Users\Holly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\2dcb5a6f-2644b31b Infected: Trojan.Java.ClassLoader.au 1
C:\Users\Holly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\2dcb5a6f-2644b31b Infected: Trojan-Downloader.Java.Agent.a 1
C:\Users\Holly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\4d13647b-500eb7dd Infected: Exploit.Java.ByteVerify 1
C:\Users\Holly\Music\artist vs poet - greatest hits.wma Infected: Trojan-Downloader.WMA.Wimad.n 1
C:\Users\Holly\Music\Billy Idol - Billy Idol - Cradle of love - Copy.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Users\Holly\Music\Billy Idol - Billy Idol - Cradle of love.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Users\Holly\Music\boston cool the engines.mp3 Infected: Trojan-Downloader.WMA.GetCodec.r 1
C:\Users\Holly\Music\boston third stage - greatest hits.mp3 Infected: Trojan-Downloader.WMA.GetCodec.n 1
C:\Users\Holly\Music\boston third stage.mp3 Infected: Trojan-Downloader.WMA.GetCodec.r 1
C:\Users\Holly\Music\britney fox long way to love.mp3 Infected: Trojan-Downloader.WMA.GetCodec.r 1
C:\Users\Holly\Music\Compilado - David Lee Roth - California girls.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Users\Holly\Music\fooling yourself styx.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Users\Holly\Music\ho ho hopefully CD quality.mp3 Infected: Trojan-Downloader.WMA.GetCodec.f 1
C:\Users\Holly\Music\ho ho hopefully.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Users\Holly\Music\lisa marie artist vs MTV.mp3 Infected: Trojan-Downloader.WMA.GetCodec.f 1
C:\Users\Holly\Music\lisa marie artist vs.mp3 Infected: Trojan-Downloader.WMA.GetCodec.n 1
C:\Users\Holly\Music\long way to love.mp3 Infected: Trojan-Downloader.WMA.GetCodec.n 1
C:\Users\Holly\Music\scorpions and berlin philharmo (hot remix).mp3 Infected: Trojan-Downloader.WMA.GetCodec.r 1
C:\Users\Holly\Music\scorpions and berlin philharmo.mp3 Infected: Trojan-Downloader.WMA.GetCodec.r 1
C:\Users\Holly\Music\scorpions berlin philharmonc r.mp3 Infected: Trojan-Downloader.WMA.GetCodec.r 1
C:\Users\Holly\Music\So in Love - Firehouse - When i look into your eyes.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Users\Holly\Music\Steelheart - Can�t stop me lovin�you.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Users\Holly\Music\tnt 10000 lovers (hot remix).mp3 Infected: Trojan-Downloader.WMA.GetCodec.r 1
C:\Users\Holly\Music\White Lion - Radar love.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1

The selected area was scanned.
Hi,

Please do the following:

Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please click OTM and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Files
C:\Users\Holly\a.zip 
C:\Users\Holly\AppData\Local\VirtualStore\Program Files\LimeWire\lost in this mome CD quality.mp3 
C:\Users\Holly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\74018dd6-48583716 
C:\Users\Holly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\2dcb5a6f-2644b31b
C:\Users\Holly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\4d13647b-500eb7dd 
C:\Users\Holly\Music\artist vs poet - greatest hits.wma 
C:\Users\Holly\Music\Billy Idol - Billy Idol - Cradle of love - Copy.mp3
C:\Users\Holly\Music\Billy Idol - Billy Idol - Cradle of love.mp3 
C:\Users\Holly\Music\boston cool the engines.mp3 
C:\Users\Holly\Music\boston third stage - greatest hits.mp3 
C:\Users\Holly\Music\boston third stage.mp3 
C:\Users\Holly\Music\britney fox long way to love.mp3 
C:\Users\Holly\Music\Compilado - David Lee Roth - California girls.mp3 
C:\Users\Holly\Music\fooling yourself styx.mp3 
C:\Users\Holly\Music\ho ho hopefully CD quality.mp3 
C:\Users\Holly\Music\ho ho hopefully.mp3 
C:\Users\Holly\Music\lisa marie artist vs MTV.mp3 
C:\Users\Holly\Music\lisa marie artist vs.mp3 
C:\Users\Holly\Music\long way to love.mp3 
C:\Users\Holly\Music\scorpions and berlin philharmo (hot remix).mp3
C:\Users\Holly\Music\scorpions and berlin philharmo.mp3 
C:\Users\Holly\Music\scorpions berlin philharmonc r.mp3 
C:\Users\Holly\Music\So in Love - Firehouse - When i look into your eyes.mp3 
C:\Users\Holly\Music\Steelheart - Can�t stop me lovin�you.mp3 
C:\Users\Holly\Music\tnt 10000 lovers (hot remix).mp3
C:\Users\Holly\Music\White Lion - Radar love.mp3 

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



NEXT


P2P - I see you have P2P software Limewire installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.


Please post a fresh DDS log
Please advise how your computer is running now and if there are any outstanding issues
Here is my OTM log:

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder C:\Users\Holly\a.zip not found.
File/Folder C:\Users\Holly\AppData\Local\VirtualStore\Program Files\LimeWire\lost in this mome CD quality.mp3 not found.
File/Folder C:\Users\Holly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\74018dd6-48583716 not found.
File/Folder C:\Users\Holly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\2dcb5a6f-2644b31b not found.
File/Folder C:\Users\Holly\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59\4d13647b-500eb7dd not found.
File/Folder C:\Users\Holly\Music\artist vs poet - greatest hits.wma not found.
File/Folder C:\Users\Holly\Music\Billy Idol - Billy Idol - Cradle of love - Copy.mp3 not found.
File/Folder C:\Users\Holly\Music\Billy Idol - Billy Idol - Cradle of love.mp3 not found.
File/Folder C:\Users\Holly\Music\boston cool the engines.mp3 not found.
File/Folder C:\Users\Holly\Music\boston third stage - greatest hits.mp3 not found.
File/Folder C:\Users\Holly\Music\boston third stage.mp3 not found.
File/Folder C:\Users\Holly\Music\britney fox long way to love.mp3 not found.
File/Folder C:\Users\Holly\Music\Compilado - David Lee Roth - California girls.mp3 not found.
File/Folder C:\Users\Holly\Music\fooling yourself styx.mp3 not found.
File/Folder C:\Users\Holly\Music\ho ho hopefully CD quality.mp3 not found.
File/Folder C:\Users\Holly\Music\ho ho hopefully.mp3 not found.
File/Folder C:\Users\Holly\Music\lisa marie artist vs MTV.mp3 not found.
File/Folder C:\Users\Holly\Music\lisa marie artist vs.mp3 not found.
File/Folder C:\Users\Holly\Music\long way to love.mp3 not found.
File/Folder C:\Users\Holly\Music\scorpions and berlin philharmo (hot remix).mp3 not found.
File/Folder C:\Users\Holly\Music\scorpions and berlin philharmo.mp3 not found.
File/Folder C:\Users\Holly\Music\scorpions berlin philharmonc r.mp3 not found.
File/Folder C:\Users\Holly\Music\So in Love - Firehouse - When i look into your eyes.mp3 not found.
File/Folder C:\Users\Holly\Music\Steelheart - Can�t stop me lovin�you.mp3 not found.
File/Folder C:\Users\Holly\Music\tnt 10000 lovers (hot remix).mp3 not found.
File/Folder C:\Users\Holly\Music\White Lion - Radar love.mp3 not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Holly
->Temp folder emptied: 71912703 bytes
->Temporary Internet Files folder emptied: 266601667 bytes
->Java cache emptied: 217864968 bytes
->FireFox cache emptied: 64885918 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
Folder delete failed. C:\Windows\msdownld.tmp scheduled to be deleted on reboot.
%systemroot% .tmp files removed: 351933 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 592.82 mb


OTM by OldTimer - Version 3.0.0.5 log created on 08022009_093648

Files moved on Reboot…
Folder move failed. C:\Windows\msdownld.tmp scheduled to be moved on reboot.

Registry entries deleted on Reboot…

I took your advice and removed limewire. Here are my DDS log:

DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 10:13:24.63 on Sun 08/02/2009
Internet Explorer: 8.0.6001.18813 BrowserJavaVersion: 1.6.0_07
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.445.89 [GMT -7:00]

SP: Spyware Doctor *enabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Windows\system32\svchost.exe -k imgsvc
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\ltmoh\ltmoh.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\RAM Idle LE\RAM_XP.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Holly\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8643XSP\dds[1].pif
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://att.net
uWindow Title = Windows Internet Explorer provided by Yahoo!
uDefault_Page_URL = hxxp://att.net
mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No File
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\TOSCDSPD.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun: [HWSetup] c:\program files\toshiba\utilities\HWSetup.exe hwSetUP
mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe
mRun: [LtMoh] c:\program files\ltmoh\Ltmoh.exe
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [SVPWUTIL] c:\program files\toshiba\utilities\SVPWUTIL.exe SVPwUTIL
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [MSConfig] "c:\windows\system32\msconfig.exe" /auto
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [RAM Idle Professional] c:\program files\ram idle le\RAM_XP.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: turbotax.com
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

============= SERVICES / DRIVERS ===============

R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2006-10-10 5632]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2007-2-27 32256]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2006-2-16 4096]

=============== Created Last 30 ================

2009-08-02 09:24 –d—– C:\_OTM
2009-08-01 21:27 17,408 a——- c:\windows\Shortcut.exe
2009-08-01 21:26 –d—– c:\program files\RAM Idle LE
2009-07-29 21:37 –d—– c:\program files\Trend Micro
2009-07-29 21:03 –d—– c:\users\holly\appdata\roaming\Malwarebytes
2009-07-29 21:03 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-29 21:03 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-29 21:03 –d—– c:\programdata\Malwarebytes
2009-07-29 21:03 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-07-29 21:03 –d—– c:\progra~2\Malwarebytes
2009-07-27 09:07 –d—– c:\program files\ATTToolbar
2009-07-27 03:43 56 a—h— c:\programdata\ezsidmv.dat
2009-07-27 03:43 56 a—h— c:\progra~2\ezsidmv.dat
2009-07-27 02:26 –d—– c:\programdata\Skype
2009-07-14 20:54 156,672 a——- c:\windows\system32\t2embed.dll
2009-07-14 20:54 289,792 a——- c:\windows\system32\atmfd.dll
2009-07-14 20:54 72,704 a——- c:\windows\system32\fontsub.dll
2009-07-14 20:54 10,240 a——- c:\windows\system32\dciman32.dll
2009-07-12 15:46 327,680 a—-r– c:\windows\system32\AegisE2.dll
2009-07-12 15:46 651,264 a—-r– c:\windows\system32\libeay32.dll
2009-07-12 15:46 450,560 a—-r– c:\windows\system32\AegisE5.dll
2009-07-12 15:46 114,688 a——- c:\windows\system32\athcfg10.dll
2009-07-12 15:45 147,456 a—-r– c:\windows\system32\ssleay32.dll
2009-07-10 22:17 11,776 a——- c:\windows\system32\drivers\afc.sys
2009-07-10 22:16 212,480 a——- c:\windows\PCDLIB32.DLL
2009-07-10 21:58 6,656 a——- c:\windows\system32\CoInst_080213.dll

==================== Find3M ====================

2009-08-01 19:27 86,016 a——- c:\windows\inf\infstor.dat
2009-08-01 19:27 51,200 a——- c:\windows\inf\infpub.dat
2009-08-01 19:27 86,016 a——- c:\windows\inf\infstrng.dat
2009-07-21 14:52 915,456 a——- c:\windows\system32\wininet.dll
2009-07-21 14:47 109,056 a——- c:\windows\system32\iesysprep.dll
2009-07-21 14:47 71,680 a——- c:\windows\system32\iesetup.dll
2009-07-21 13:13 133,632 a——- c:\windows\system32\ieUnatt.exe
2008-07-03 09:51 174 a–sh— c:\program files\desktop.ini
2008-07-03 09:36 665,600 a——- c:\windows\inf\drvindex.dat
2008-01-30 09:27 2,276 a——- c:\users\holly\appdata\roaming\wklnhst.dat
2007-02-22 01:00 1,117,491 a——- c:\users\holly\dvdshrink32setup.exe
2006-11-02 05:39 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:39 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:39 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:39 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 10:15:14.77 ===============

The pop-ups have stopped and I can't thank you enough. You've been a great help! :notworthy:
Hi,

File/Folder C:\Users\Holly\a.zip not found.


did you manually delete all those infected files?

Just some house keeping to do now:

Please download JavaRa to your desktop and unzip it to its own folder.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Scroll down to the Java SE Runtime Environment (JRE) option.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer.(version 6, update 14)

NEXT

Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT


Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

NEXT


Now we need to create a new clean SYSTEM RESTORE point.

  • Close and save any documents that you may have open.
  • Open up the Start Menu and right-click on "Computer", and then select "Properties"
  • This will take you into the System area of Control Panel. Click on the "Advanced system settings" on the left hand side.
  • Now select the "System Protection" tab to get to the System Restore section.
  • Click the "Create" button to create a new restore point. You'll be prompted for a name, and you might want to give it a useful name that you'll be able to easily identify later.
  • Click the Create button, and then the system will create the restore point.
  • When it's all finished, you'll get a message saying it's completed successfully.
  • You will now have a new restore point

Then remove all previous Restore Points
  • Click Start Menu > Run > copy and paste
  • cleanmgr into the run box
  • At the top, click on the More Options tab, under System Restore and Shadow Copies group,
  • Click the Clean up button,
  • Vista will ask you if you’re sure, click on Yes button.
  • When finished, click on Cancel button to exit.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI