This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Major Problem

43 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A few days ago, I started noticing a few random problems with my computer. I showed it to my friend, he did everything he could, and then when he couldn't figure it out, he told me to post it on here, so here it goes.

I have a Toshiba Tecra A9-S9019X laptop.

- The sound isn't working. The volume control window says it's unmuted and all of that jazz, but nothing comes out. I plugged in headphones and those didn't work either; I didn't even get the "the speakers are on" background static noise. Also, the external volume control doesn't work (the scrolling wheel on the front).
- The "Toshiba Power Saver" application (it tells you your battery/power status, lets you set up what happens when you close the lid or hit the button, etc.) is no longer available; it is not in the taskbar and when I click on it in the control panel it gives me an error message saying that it isn't "turned on" and to go through the control panel power options menu to turn it back on. I've checked multiple times, it is set to be on via said menu. I also looked in the Program Files folder for it and there was no .exe file or anything there (only TPSTrace.log and TPwrSetup.$$$).
- The "Pointer" application that controls which mouse you use (the blue dot in the middle of the keyboard or the touchpad) and other mouse settings is also not available. It is not in the taskbar and I can't find it anywhere (it's not the same as the "Mouse" menu in the control panel).
- The function keys aren't working either (where you hold the "FN" key and use the F# keys to do some shortcut). Nothing happens when I hit them. The little light still turns on to tell me I'm pushing down the FN key, but nothing happens when I hit the F# keys.

As far as I can tell, that's it. Everything else seems to work fine. There could me more problems I haven't noticed, though. I got a virus recently (just before these things started happening), but I've run multiple scanners multiple times and they say it's all gone, and my friend said that couldn't have done this anyways, so I don't know if that has any relevance or not, but I thought I should mention it.

I ran the hijackthis application. The results are below.

Thank you for your help!
Tracie

———-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:04:55 PM, on 2/10/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\system32\ThpSrv.exe
C:\WINDOWS\system32\TODDSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\thpsrv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\MsiExec.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O1 - Hosts: HPED0E53 HP0019BBED0E53
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [ThpSrv] C:\WINDOWS\system32\thpsrv /logon
O4 - HKLM\..\Run: [TOSDCR] TOSDCR.EXE
O4 - HKLM\..\Run: [TPSODDCtl] TPSODDCtl.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-21-1035245195-802469093-380302000-1005\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User '?')
O4 - S-1-5-21-1035245195-802469093-380302000-1005 Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe (User '?')
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O15 - Trusted Zone: http://*.buy-internetsecurity10.com
O15 - Trusted Zone: http://*.buy-is2010.com
O15 - Trusted Zone: http://*.is-software-download.com
O15 - Trusted Zone: http://*.is-software-download25.com
O15 - Trusted Zone: http://*.is10-soft-download.com
O15 - Trusted Zone: http://*.buy-internetsecurity10.com (HKLM)
O15 - Trusted Zone: http://*.buy-is2010.com (HKLM)
O16 - DPF: Yahoo! Dots - http://origin.games.yahoo.net/games/clients/y/dtt1_x.cab
O16 - DPF: Yahoo! Fleet - http://origin.games.yahoo.net/games/clients/y/fltt3_x.cab
O16 - DPF: Yahoo! Poker - http://origin.games.yahoo.net/games/clients/y/pt3_x.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…k.cab102118.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\iEvony\Skype4COM.dll
O18 - Filter hijack: text/html - {d7edfc7d-ac90-4a7d-9e78-a238f270a8aa} - (no file)
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - (no file)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,62~1.DLL, ,mutejiri.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Purdue University VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA HDD Protection (Thpsrv) - TOSHIBA Corporation - C:\WINDOWS\system32\ThpSrv.exe
O23 - Service: Tmesrv3 (Tmesrv) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe (file missing)
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

–
End of file - 10031 bytes
I almost forgot another problem I'm having. I can't download IE8. I try to download it and it tells me I need a microsoft update, but when I go to get that I get an error message saying I already have a newer version of the update and don't need to download it. It's an endless cycle.
Hi,

Please do the following:

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):


O1 - Hosts: HPED0E53 HP0019BBED0E53
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O15 - Trusted Zone: http://*.buy-internetsecurity10.com
O15 - Trusted Zone: http://*.buy-is2010.com
O15 - Trusted Zone: http://*.is-software-download.com
O15 - Trusted Zone: http://*.is-software-download25.com
O15 - Trusted Zone: http://*.is10-soft-download.com
O15 - Trusted Zone: http://*.buy-internetsecurity10.com (HKLM)
O15 - Trusted Zone: http://*.buy-is2010.com (HKLM)
O18 - Filter hijack: text/html - {d7edfc7d-ac90-4a7d-9e78-a238f270a8aa} - (no file)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,62~1.DLL, ,mutejiri.dll

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.


NEXT


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thank you very much for your help. I deleted the mentioned entries from hijack this, and attached are the log .txt files for DDS. I download/extracted the gmer program, and when I try to run it, it takes up almost all of my CPU usage, and freezes up my computer. I had to restart three times before I could even get it to run the scan because it kept freezing up my computer. Once I got it to run, I waited (and did nothing else on the computer) for about an hour and a half or more, but it froze up yet again when I clicked the "save" button to try to save the log. I don't know what else to do. Any ideas on how to make it work? Thank you, again.
Uncheck the box beside "files" as well as the other boxes in the instructions and try running it in safe mode. Make sure all your security programs are disabled and close all other programs
I can't start in safe mode (I didn't remember that it didn't work until just now when I tried to do so again.). Whenever I get to the menu and select to do so, it loads all of the drivers and stuff correctly, but instead it just flashes a blue screen and restarts. I tried to run the scan without the "files" box checked in normal startup mode and it still froze everything up. I apologize, and thank you again for all you're doing.
Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Here's the log from ComboFix.

ComboFix 10-02-12.01 - Tracie Borror 02/13/2010 10:18:18.1.2 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Tracie Borror\Application Data\iniasd.txt
c:\documents and settings\Tracie Borror\Favorites\Translator.url
c:\documents and settings\Tracie Borror\Local Settings\Application Data\{2DE85B80-910D-471B-85D3-748CA975C6DC}
c:\documents and settings\Tracie Borror\Local Settings\Application Data\{2DE85B80-910D-471B-85D3-748CA975C6DC}\chrome.manifest
c:\documents and settings\Tracie Borror\Local Settings\Application Data\{2DE85B80-910D-471B-85D3-748CA975C6DC}\chrome\content\_cfg.js
c:\documents and settings\Tracie Borror\Local Settings\Application Data\{2DE85B80-910D-471B-85D3-748CA975C6DC}\chrome\content\c.js
c:\documents and settings\Tracie Borror\Local Settings\Application Data\{2DE85B80-910D-471B-85D3-748CA975C6DC}\chrome\content\overlay.xul
c:\documents and settings\Tracie Borror\Local Settings\Application Data\{2DE85B80-910D-471B-85D3-748CA975C6DC}\install.rdf
c:\program files\Shared
c:\recycler\S-1-5-21-4112135756-3610005543-3973500291-500
C:\s
c:\windows\AegisP.inf
c:\windows\system32\_003048_.tmp.dll
c:\windows\system32\_003049_.tmp.dll
c:\windows\system32\_003050_.tmp.dll
c:\windows\system32\_003051_.tmp.dll
c:\windows\system32\_003058_.tmp.dll
c:\windows\system32\_003059_.tmp.dll
c:\windows\system32\_003060_.tmp.dll
c:\windows\system32\_003061_.tmp.dll
c:\windows\system32\_003063_.tmp.dll
c:\windows\system32\_003064_.tmp.dll
c:\windows\system32\_003065_.tmp.dll
c:\windows\system32\_003067_.tmp.dll
c:\windows\system32\_003068_.tmp.dll
c:\windows\system32\_003070_.tmp.dll
c:\windows\system32\_003071_.tmp.dll
c:\windows\system32\_003072_.tmp.dll
c:\windows\system32\_003074_.tmp.dll
c:\windows\system32\_003077_.tmp.dll
c:\windows\system32\_003078_.tmp.dll
c:\windows\system32\_003082_.tmp.dll
c:\windows\system32\_003083_.tmp.dll
c:\windows\system32\_003085_.tmp.dll
c:\windows\system32\_003088_.tmp.dll
c:\windows\system32\_003090_.tmp.dll
c:\windows\system32\_003091_.tmp.dll
c:\windows\system32\_003092_.tmp.dll
c:\windows\system32\_003093_.tmp.dll
c:\windows\system32\_003094_.tmp.dll
c:\windows\system32\_003097_.tmp.dll
c:\windows\system32\_003098_.tmp.dll
c:\windows\system32\_003099_.tmp.dll
c:\windows\system32\_003100_.tmp.dll
c:\windows\system32\_003101_.tmp.dll
c:\windows\system32\_003106_.tmp.dll
c:\windows\system32\_003108_.tmp.dll
c:\windows\system32\_003109_.tmp.dll
c:\windows\system32\000stthk .exe
c:\windows\system32\00thotkey .exe
c:\windows\system32\hkcmd .exe
c:\windows\system32\igfxpers .exe
c:\windows\system32\igfxtray .exe
c:\windows\system32\rundll32 .exe
c:\windows\system32\SET68C.tmp
c:\windows\system32\tfnf5 .exe
c:\windows\system32\tosdcr .exe
c:\windows\system32\tpsmain .exe
c:\windows\system32\tpsoddctl .exe

c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe

.
((((((((((((((((((((((((( Files Created from 2010-01-13 to 2010-02-13 )))))))))))))))))))))))))))))))
.

2010-02-13 15:21 . 2008-04-14 00:12 50176 -c–a-w- c:\windows\system32\dllcache\proquota.exe
2010-02-13 15:21 . 2008-04-14 00:12 50176 —-a-w- c:\windows\system32\proquota.exe
2010-02-13 07:14 . 2010-02-13 07:15 ——– d—–w- c:\windows\system32\NtmsData
2010-02-10 23:57 . 2010-02-10 23:57 ——– d—–w- c:\program files\Trend Micro
2010-02-10 23:44 . 2006-11-02 13:09 1419232 —-a-w- c:\windows\system32\WdfCoinstaller01005.dll
2010-02-10 23:44 . 2010-02-10 23:44 ——– d—–w- C:\temp.alps
2010-02-10 23:31 . 2005-05-03 23:43 69632 —-a-w- c:\windows\Alcmtr.exe
2010-02-10 23:23 . 2010-02-10 23:23 ——– d—–w- C:\temp.toshiba
2010-02-10 23:21 . 2010-02-10 23:21 ——– d—–w- c:\documents and settings\All Users\Application Data\UAB
2010-02-10 23:21 . 2010-02-10 23:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Driver Whiz
2010-02-10 23:21 . 2010-02-10 23:21 ——– d—–w- c:\documents and settings\Tracie Borror\Local Settings\Application Data\PC_Drivers_Headquarters
2010-02-10 23:20 . 2010-02-10 23:20 ——– d—–w- c:\program files\Driver Whiz
2010-02-10 14:06 . 2010-02-10 14:06 ——– d—–w- c:\program files\BillP Studios
2010-02-07 22:29 . 2010-02-07 22:29 ——– d—–w- c:\program files\GPLGS
2010-02-07 22:28 . 2009-11-05 13:39 87552 —-a-w- c:\windows\system32\cpwmon2k.dll
2010-02-07 22:28 . 2010-02-07 22:28 ——– d—–w- c:\program files\Acro Software
2010-01-26 23:01 . 2010-01-26 23:01 ——– d—–w- c:\documents and settings\Tracie Borror\Application Data\SanDisk
2010-01-25 19:30 . 2010-01-25 19:30 ——– d—–w- c:\program files\Microsoft Silverlight

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-13 15:25 . 2008-07-02 23:22 ——– d—–w- c:\program files\Trillian
2010-02-12 22:51 . 2008-07-07 19:42 ——– d—–w- c:\documents and settings\Tracie Borror\Application Data\MSN6
2010-02-12 19:18 . 2008-07-24 21:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-02-10 23:45 . 2010-02-10 23:45 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-02-10 23:45 . 2010-02-10 23:45 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_Apfiltr_01005.Wdf
2010-02-10 23:44 . 2008-01-10 19:59 ——– d—–w- c:\program files\Apoint2K
2010-02-10 23:31 . 2008-04-25 00:58 ——– d—–w- c:\program files\Realtek
2010-02-10 23:23 . 2008-01-10 19:59 ——– d—–w- c:\program files\Toshiba
2010-02-10 23:23 . 2008-01-10 19:59 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-10 23:22 . 2009-09-19 13:58 ——– d—–w- c:\program files\Windows Live
2010-02-10 21:57 . 2008-07-03 02:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-10 14:11 . 2009-03-25 05:04 117760 —-a-w- c:\documents and settings\Tracie Borror\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-09 04:27 . 2008-09-04 01:14 ——– d—–w- c:\program files\WinPatrol
2010-02-09 04:27 . 2008-04-25 01:04 ——– d—–w- c:\program files\ltmoh
2010-02-09 03:50 . 2009-03-06 02:08 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-09 03:47 . 2008-04-25 01:00 55808 —-a-w- c:\windows\system32\igfxpers.exe
2010-02-09 03:47 . 2008-04-25 01:02 ——– d—–w- c:\program files\Protector Suite QL
2010-02-09 02:47 . 2009-11-30 18:51 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-02-09 02:47 . 2008-07-03 02:13 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-02-09 02:46 . 2010-02-09 02:46 8 —-a-w- c:\documents and settings\All Users\Application Data\mswintmp.dat
2010-02-07 19:52 . 2009-08-23 05:53 ——– d—–w- c:\documents and settings\Tracie Borror\Application Data\HPAppData
2010-02-03 07:01 . 2008-04-25 01:04 72384 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-26 23:01 . 2010-01-26 23:01 79872 —-a-w- c:\documents and settings\Tracie Borror\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
2010-01-26 23:01 . 2010-01-26 23:01 354744 —-a-w- c:\documents and settings\Tracie Borror\Application Data\SanDisk\Sansa Updater\SansaUpdaterInstall.exe
2010-01-26 23:01 . 2010-01-26 23:01 574344 —-a-w- c:\documents and settings\Tracie Borror\Application Data\SanDisk\Sansa Updater\SansaUpdater.exe
2010-01-13 00:17 . 2009-03-30 23:17 5115824 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-13 00:17 . 2009-12-23 18:55 52224 —-a-w- c:\documents and settings\Tracie Borror\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-07 21:07 . 2009-03-06 02:08 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-03-06 02:08 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-19 00:31 . 2008-07-03 02:51 ——– d—–w- c:\documents and settings\Tracie Borror\Application Data\LimeWire
2009-12-18 21:38 . 2008-01-10 20:12 ——– d—–w- c:\program files\Google
2009-11-30 14:00 . 2009-11-30 14:00 117760 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2008-08-16 21:42 . 2008-08-16 21:42 13112 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-08-16 21:42 . 2008-08-16 21:42 70456 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-08-16 21:42 . 2008-08-16 21:42 91448 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2008-08-16 21:42 . 2008-08-16 21:42 20800 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-08-16 21:43 . 2008-08-16 21:43 206136 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-08-16 21:42 . 2008-08-16 21:42 31032 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2008-08-16 21:42 . 2008-08-16 21:42 40248 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2008-05-21 12:41 . 2008-05-21 12:41 479232 —-a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
2008-05-21 12:41 . 2008-05-21 12:41 548864 —-a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
2008-05-21 12:41 . 2008-05-21 12:41 626688 —-a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-06-05 17:58 . 2008-06-05 17:58 648504 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-08-16 21:42 . 2008-08-16 21:42 23864 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2008-07-02 12:13 . 2004-08-03 23:00 1598029824 –sha-w- c:\windows\system32\drivers\_003022_.tmp.dll
.
c:\program files\Apoint2K\apoint .exe
c:\program files\HP\Digital Imaging\bin\hpqsrmon .exe
c:\program files\HP\HP Software Update\hpwuschd2 .exe
c:\program files\Intel\Wireless\Bin\ifrmewrk .exe
c:\program files\Intel\Wireless\Bin\zcfgsvc .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\ltmoh\ltmoh .exe
c:\program files\Protector Suite QL\launcher .exe
c:\program files\Spybot - Search & Destroy\teatimer .exe
c:\program files\SUPERAntiSpyware\superantispyware .exe
c:\program files\The Weather Channel FW\Desktop\desktopweather .exe
c:\program files\Toshiba\TAudEffect\taudeff .exe
c:\program files\Toshiba\TME3\tmerzctl .exe
c:\program files\Toshiba\TME3\tmesrv31 .exe
c:\program files\Toshiba\TOSCDSPD\toscdspd .exe
c:\program files\Toshiba\TOSHIBA Direct Disc Writer\ddwmon .exe
c:\program files\Toshiba\TOSHIBA Zooming Utility\smoothview .exe
c:\program files\Toshiba\Wireless Hotkey\toshkcw .exe
c:\program files\WinPatrol\winpatrol .exe
c:\windows\pchealth\helpctr\binaries\msconfig .exe

——- Sigcheck ——-

[7] 2008-04-14 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\rpcss.dll
[-] 2005-07-26 . C369DF215D352B6F3A0B8C3469AA34F8 . 398336 . . [5.1.2600.2726] . . c:\windows\$NtServicePackUninstall$\rpcss.dll
[-] 2005-07-26 . C369DF215D352B6F3A0B8C3469AA34F8 . 398336 . . [5.1.2600.2726] . . c:\windows\system32\rpcss.dll
[-] 2005-04-28 . DA383FB39A6F1C445F3AFC94B3EB1248 . 396288 . . [5.1.2600.2665] . . c:\windows\$hf_mig$\KB894391\SP2QFE\rpcss.dll
[-] 2005-04-28 . DA383FB39A6F1C445F3AFC94B3EB1248 . 396288 . . [5.1.2600.2665] . . c:\windows\$NtUninstallKB902400$\rpcss.dll
[-] 2005-04-28 . C8061F289E000703E7672916B7FE1571 . 395776 . . [5.1.2600.2665] . . c:\windows\$NtUninstallKB894391$\rpcss.dll
[7] 2004-08-03 . 5C83A4408604F737717AB96371201680 . 395776 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB894391_0$\rpcss.dll

[7] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
[-] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe
[-] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\system32\spoolsv.exe
[7] 2004-08-03 . 7435B108B935E42EA92CA94F59C8E717 . 57856 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB896423$\spoolsv.exe

[7] 2008-04-14 00:11 . 19A799805B24990867B00C120D300C3A . 246272 . . [2001.12.4414.701] . . c:\windows\ServicePackFiles\i386\es.dll
[-] 2005-07-26 04:20 . 95F5FEA4C6DE2C3F28784D0DCC8F0DD3 . 243200 . . [2001.12.4414.308] . . c:\windows\$NtServicePackUninstall$\es.dll
[-] 2005-07-26 04:20 . 95F5FEA4C6DE2C3F28784D0DCC8F0DD3 . 243200 . . [2001.12.4414.308] . . c:\windows\system32\es.dll
[-] 2005-03-09 17:18 . 87D45DE924F9DEAE3886A270DE0097AA . 243200 . . [2001.12.4414.301] . . c:\windows\$NtUninstallKB902400$\es.dll
[7] 2004-08-03 21:00 . ACD36A2DD7D1E9D8A060AA651DC07E63 . 243200 . . [2001.12.4414.258] . . c:\windows\$NtUninstallKB895200$\es.dll

[7] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\linkinfo.dll
[-] 2005-09-01 . 648BF0B4DDE4F7A1156DAE7174D36EFA . 19968 . . [5.1.2600.2751] . . c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\$NtServicePackUninstall$\linkinfo.dll
[-] 2005-09-01 . A1A688EE56CF3BBD24EDEB815D48E9BA . 19968 . . [5.1.2600.2751] . . c:\windows\system32\linkinfo.dll
[7] 2004-08-03 . C2BBD044C741EA4292016C36F718D2E4 . 18944 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB900725$\linkinfo.dll

[7] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tapisrv.dll
[-] 2005-07-08 . 1418A3A6E76E5A2E3F5E43866E793A8B . 249344 . . [5.1.2600.2716] . . c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll
[-] 2005-07-08 . FB78839B36025AA286A51289ED28B73E . 249344 . . [5.1.2600.2716] . . c:\windows\system32\tapisrv.dll
[7] 2004-08-03 . EB4A4187D74A8EFDCBEA3EA2CB1BDFBD . 246272 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB893756$\tapisrv.dll

[7] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
[-] 2005-03-02 . 1800F293BCCC8EDE8A70E12B88D80036 . 577024 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
[-] 2005-03-02 . DE2DB164BBB35DB061AF0997E4499054 . 577024 . . [5.1.2600.2622] . . c:\windows\$NtServicePackUninstall$\user32.dll
[-] 2005-03-02 . DE2DB164BBB35DB061AF0997E4499054 . 577024 . . [5.1.2600.2622] . . c:\windows\system32\user32.dll
[7] 2004-08-03 . C72661F8552ACE7C5C85E16A3CF505C4 . 577024 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB890859$\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ThpSrv"="c:\windows\system32\thpsrv" [X]
"CFSServ.exe"="CFSServ.exe -NoClient" [X]
"TFNF5"="TFNF5.exe" [N/A]
"000StTHK"="000StTHK.exe" [N/A]
"NDSTray.exe"="NDSTray.exe" [N/A]
"TFncKy"="TFncKy.exe" [N/A]
"TOSDCR"="TOSDCR.EXE" [N/A]
"TPSODDCtl"="TPSODDCtl.exe" [N/A]
"TPSMain"="TPSMain.exe" [N/A]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"TouchED"="c:\program files\TOSHIBA\TouchED\TouchED.exe" [2005-06-29 126976]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-12 16125440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-12-15 184320]

c:\documents and settings\Tracie Borror\Start Menu\Programs\Startup\
Trillian.lnk - c:\program files\Trillian\trillian.exe [2010-2-10 1930592]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\HPBOID.EXE"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxs08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

R1 SASKUTIL;SASKUTIL;c:\documents and settings\Tracie Borror\My Documents\SUPERAntiSpyware\SASKUTIL.sys [x]
R2 Tmesrv;Tmesrv3;c:\program files\TOSHIBA\TME3\Tmesrv31.exe [x]
R3 SASENUM;SASENUM;c:\documents and settings\Tracie Borror\My Documents\SUPERAntiSpyware\SASENUM.SYS [x]
R3 TEchoCan;Toshiba Audio Effect;c:\windows\system32\DRIVERS\TEchoCan.sys [2007-02-22 435072]
R4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-18 135664]
S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [2007-04-27 21120]
S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [2007-03-09 6528]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-27 9968]
S1 TMEI3E;TMEI3E;c:\windows\system32\Drivers\TMEI3E.SYS [2004-06-16 5888]
S2 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\DRIVERS\tdudf.sys [2007-03-26 105856]
S2 trudf;TOSHIBA DVD-RAM UDF File System Driver;c:\windows\system32\DRIVERS\trudf.sys [2007-02-19 134016]
S3 IFXTPM;IFXTPM;c:\windows\system32\DRIVERS\IFXTPM.SYS [2007-01-23 36608]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-02-13 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-24 04:25]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: purdue.edu\blackboard
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: Yahoo! Dots - hxxp://origin.games.yahoo.net/games/clients/y/dtt1_x.cab
DPF: Yahoo! Fleet - hxxp://origin.games.yahoo.net/games/clients/y/fltt3_x.cab
DPF: Yahoo! Poker - hxxp://origin.games.yahoo.net/games/clients/y/pt3_x.cab
FF - ProfilePath - c:\documents and settings\Tracie Borror\Application Data\Mozilla\Firefox\Profiles\d8080f37.default\
FF - prefs.js: browser.search.selectedEngine - Zybez Item Database
FF - prefs.js: browser.startup.homepage - hxxp://www.emilstefanov.net/Projects/PurdueCourses/
FF - component: c:\program files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\components\SEPsearchhelperff.dll
FF - plugin: c:\documents and settings\Tracie Borror\Application Data\Mozilla\Firefox\Profiles\d8080f37.default\extensions\[removed]\plugins\npTVUAx.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\MSN Toolbar\Platform\4.0.0205.2\npwinext.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-13 10:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}]
@DACL=(02 0000)
@="802.3 Group Policy"
"DisplayName"=expand:"@dot3gpclnt.dll,-100"
"ProcessGroupPolicyEx"="ProcessLANPolicyEx"
"GenerateGroupPolicy"="GenerateLANPolicy"
"DllName"=expand:"dot3gpclnt.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
@DACL=(02 0000)
"Asynchronous"=dword:00000001
"DllName"=expand:"%SystemRoot%\\System32\\dimsntfy.dll"
"Startup"="WlDimsStartup"
"Shutdown"="WlDimsShutdown"
"Logon"="WlDimsLogon"
"Logoff"="WlDimsLogoff"
"StartShell"="WlDimsStartShell"
"Lock"="WlDimsLock"
"Unlock"="WlDimsUnlock"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
@DACL=(02 0000)
@=""
"DLLName"="igfxdev.dll"
"Asynchronous"=dword:00000001
"Impersonate"=dword:00000001
"Unlock"="WinlogonUnlockEvent"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\TosBtNP]
@DACL=(02 0000)
@SACL=
"Asynchronous"=dword:00000000
"DllName"="TosBtNP.dll"
"Impersonate"=dword:00000000
"Shutdown"="TBNP_Event_Shutdown"
"Startup"="TBNP_Event_Startup"
"Lock"="TBNP_Event_Lock"
"Unlock"="TBNP_Event_Unlock"
"Logon"="TBNP_Event_Logon"
"Logoff"="TBNP_Event_Logoff"
"StartScreenSaver"="TBNP_Event_StartScreenSaver"
"StopScreenSaver"="TBNP_Event_StopScreenSaver"
"StartShell"="TBNP_Event_StartShell"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts]
@DACL=(02 0000)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2608)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\System32\SCardSvr.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\windows\system32\ThpSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\windows\system32\thpsrv.exe
c:\windows\RTHDCPL.EXE
c:\program files\Apoint2K\HidFind.exe
c:\program files\Apoint2K\Apntex.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\MsiExec.exe
.
**************************************************************************
.
Completion time: 2010-02-13 10:31:11 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-13 15:31

Pre-Run: 87,789,273,088 bytes free
Post-Run: 87,651,586,048 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - FDE3FE252C98211FFC9BDF47F3A2B838

Attachments:

Hi,

Please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

RenV::
c:\program files\Apoint2K\apoint .exe
c:\program files\HP\Digital Imaging\bin\hpqsrmon .exe
c:\program files\HP\HP Software Update\hpwuschd2 .exe
c:\program files\Intel\Wireless\Bin\ifrmewrk .exe
c:\program files\Intel\Wireless\Bin\zcfgsvc .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\ltmoh\ltmoh .exe
c:\program files\Protector Suite QL\launcher .exe
c:\program files\Spybot - Search & Destroy\teatimer .exe
c:\program files\SUPERAntiSpyware\superantispyware .exe
c:\program files\The Weather Channel FW\Desktop\desktopweather .exe
c:\program files\Toshiba\TAudEffect\taudeff .exe
c:\program files\Toshiba\TME3\tmerzctl .exe
c:\program files\Toshiba\TME3\tmesrv31 .exe
c:\program files\Toshiba\TOSCDSPD\toscdspd .exe
c:\program files\Toshiba\TOSHIBA Direct Disc Writer\ddwmon .exe
c:\program files\Toshiba\TOSHIBA Zooming Utility\smoothview .exe
c:\program files\Toshiba\Wireless Hotkey\toshkcw .exe
c:\program files\WinPatrol\winpatrol .exe
c:\windows\pchealth\helpctr\binaries\msconfig .exe

FCopy::
c:\windows\ServicePackFiles\i386\rpcss.dll | c:\windows\system32\rpcss.dll
c:\windows\ServicePackFiles\i386\spoolsv.exe | c:\windows\system32\spoolsv.exe
c:\windows\ServicePackFiles\i386\es.dll | c:\windows\system32\es.dll
c:\windows\ServicePackFiles\i386\linkinfo.dll | c:\windows\system32\linkinfo.dll
c:\windows\ServicePackFiles\i386\tapisrv.dll | c:\windows\system32\tapisrv.dll
c:\windows\ServicePackFiles\i386\user32.dll | c:\windows\system32\user32.dll

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Dragging and dropping the txt file onto the exe file didn't do anything. As far as I know, all protection and script-blocking stuff is off.
Go to Start > Run > copy / paste the following into the open run box

"%userprofile%\desktop\combofix.exe" "%userprofile%\Desktop\CFscript.txt"


hit OK
I did that, and it ran the scan and restarted my computer. Upon the restart, after the screen with the Windows XP logo and loading bar, it went to a black screen, then it blue screened and restarted. It does this every time I try to start up the computer in any mode.
Is the computer back now? Can you post the log from Combofix the log should be located at C:\combofix.txt or c:\combofix\combofix.txt
I'm on a friend's computer because mine won't load windows anymore. I'm able to select an operating system (MW Recovery Console or MW XP Pro). When I select recovery console, it loads the recovery console and blue screens with the following error message after a full completion bar "Please wait…" "A problem has been detected and Windows has been shut down to prevent further damage to your computer." Blah blah blah. "Check for viruses on your computer. Remove any newly installed hard drives or hard drive controllers. Check your hard drive to make sure it is properly configured and terminated. Run CHKDSK /F to check for hard driver corruption, and then restart your computer." Technical information: *** STOP: 0x0000007B (0xF78D2524, 0xC0000034, 0x00000000, 0x00000000) If I select my usual operating system, it loads XP (finishes with the windows logo and the three blue dot scroll bar) and then goes black for a few seconds, and displays a blue screen with three lines of text that flash too briefly to read, and then restarts.
OK reboot the computer….tap F8 repeatedly on startup to get to the option screen… then select Last Know Good Configuration see if it will boot up with that.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI