Spyware / Malware / Virus Removal
2 week old laptop notebook...trojan infected
5 min read
Snow
Topic Starter
Hello
Help…I have a brand new Toshiba notbook with windows 7 starter, well for the past 2 days my security manager (anti virus) keeps catching a trojan, it says it couldnt be quarantined and deletes it instead only for it to come back…
gen.trojan.heur.FU.gqz@auDupre
i dont have much installed on here, i havent downloaded HJT or anything else to help…
am i stuck with this trojan forever or is it possible to get rid of it.
thank you for your time
snow
ken545
Download DDS by sUBs from one of the following links. Save it to your desktop.
- DDS.com
- DDS.scr
- Double click on the DDS icon, allow it to run.
- A small box will open, with an explaination about the tool. No input is needed, the scan is running.
- Notepad will open with the results, click no to the Optional_Scan
- Follow the instructions that pop up for posting the results.
- Close the program window, and delete the program from your desktop.
Information on A/V control Here
Snow
Hello Ken…thank you for the fast reply…here is the log
Snow
DDS (Ver_09-09-29.01) - NTFSx86
Run by [removed] at 19:57:33.00 on 15/09/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Starter 6.1.7600.0.1252.2.1033.18.1013.317 [GMT -4:00]
============== Running Processes ===============
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\Program Files\Bell\Bell Internet Security Services\Fws.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton Internet Security\Engine\17.5.0.127\ccSvcHst.exe
C:\Program Files\Bell\Bell Internet Security Services\RpsSecurityAwareR.exe
C:\Program Files\Bell\Internet Service Advisor\ServicepointService.exe
C:\windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Personal Vault Backup Manager\VaultClientSRV.exe
C:\Program Files\Personal Vault Backup Manager\VaultClientUpgrade.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\taskhost.exe
C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS\A5E82D02\17.5.0.127\InstStub.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Bell\Bell Internet Security Services\rps.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
C:\Program Files\Bell\Internet Service Advisor\BISAComHandler.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\Bin\AVGIDSMonitor.exe
C:\windows\system32\conhost.exe
C:\Program Files\Bell\Internet Service Advisor\BISA.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\windows\system32\igfxext.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Users\Diane\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Users\Diane\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Diane\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\Users\Diane\Desktop\dds.com
C:\windows\system32\conhost.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.toshiba.ca/welcome
uWindow Title = Presented by TOSHIBA Leading Innovation >>>
uDefault_Page_URL = hxxp://www.toshiba.ca/welcome
mDefault_Page_URL = hxxp://www.toshiba.ca/welcome
mStart Page = hxxp://www.toshiba.ca/welcome
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\17.5.0.127\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\17.5.0.127\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\17.5.0.127\coIEPlg.dll
uRun: [Google Update] "c:\users\diane\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: []
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [RtHDVBg] c:\program files\realtek\audio\hda\RtHDVBg.exe /FORPCEE3
mRun: [HWSetup] c:\program files\toshiba\utilities\HWSetup.exe hwSetUP
mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe
mRun: [SVPWUTIL] c:\program files\toshiba\utilities\SVPWUTIL.exe SVPwUTIL
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [TWebCamera] "c:\program files\toshiba\toshiba web camera application\TWebCamera.exe" autorun
mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [TosVolRegulator] c:\program files\toshiba\tosvolregulator\TosVolRegulator.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
mRun: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
mRun: [BISA.exe] "c:\program files\bell\internet service advisor\BISA.exe" /AUTORUN
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
============= SERVICES / DRIVERS ===============
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2010-4-19 18432]
=============== Created Last 30 ================
2010-09-14 18:43 316,928 a——- c:\windows\system32\spoolsv.exe
2010-09-12 19:22 56 a—h— c:\programdata\ezsidmv.dat
2010-09-12 19:22 56 a—h— c:\progra~2\ezsidmv.dat
2010-09-12 19:19 –d–r– c:\program files\Skype
2010-09-12 19:19 –d—– c:\programdata\Skype
2010-09-04 13:31 0 a—h— c:\windows\system32\drivers\Msft_Kernel_netaapl_01009.Wdf
2010-09-04 13:25 107,368 a——- c:\windows\system32\GEARAspi.dll
2010-09-04 13:25 26,600 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-09-04 13:23 –d—– c:\program files\iPod
2010-09-04 13:23 –d—– c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-09-04 13:23 –d—– c:\program files\iTunes
2010-09-04 13:23 –d—– c:\progra~2\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-09-04 13:20 –d—– c:\programdata\Apple Computer
2010-09-04 13:18 –d—– c:\program files\Bonjour
2010-09-04 13:18 –d—– c:\programdata\Apple
2010-09-01 18:52 0 a—h— c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2010-08-31 17:06 1,130,824 a——- c:\windows\system32\dfshim.dll
2010-08-31 17:06 297,808 a——- c:\windows\system32\mscoree.dll
2010-08-31 17:06 295,264 a——- c:\windows\system32\PresentationHost.exe
2010-08-31 17:06 99,176 a——- c:\windows\system32\PresentationHostProxy.dll
2010-08-31 17:06 49,472 a——- c:\windows\system32\netfxperf.dll
2010-08-31 06:23 1,286,016 a——- c:\windows\system32\drivers\tcpip.sys
2010-08-31 06:22 194,488 a——- c:\windows\system32\drivers\fvevol.sys
2010-08-31 06:22 571,904 a——- c:\windows\system32\oleaut32.dll
2010-08-31 06:22 82,944 a——- c:\windows\system32\iccvid.dll
2010-08-31 06:22 197,632 a——- c:\windows\system32\ir32_32.dll
2010-08-31 06:22 2,614,272 a——- c:\windows\explorer.exe
2010-08-31 06:22 285,696 a——- c:\windows\system32\winlogon.exe
2010-08-31 06:19 369,152 a——- c:\windows\system32\secproc.dll
2010-08-29 21:56 –d—– c:\program files\GiMeSpace Desktop Extender
2010-08-29 18:28 –d—– c:\users\diane\Tracing
2010-08-29 17:11 25,608 a——- c:\windows\system32\drivers\AVGIDSEH.sys
2010-08-29 17:11 –d—– c:\program files\Personal Vault Backup Manager
2010-08-29 17:10 285,704 a——- c:\windows\system32\drivers\bdfsfltr.sys
2010-08-29 17:10 53,192 a——- c:\windows\system32\drivers\rp_skt32.sys
2010-08-29 17:10 48,384 a——- c:\windows\system32\drivers\rp_pkt32.sys
2010-08-29 17:09 –d—– c:\programdata\Raxco
2010-08-29 17:09 –d—– c:\program files\Raxco
2010-08-29 17:01 –d—– c:\users\diane\appdata\roaming\Bell
2010-08-29 17:01 –d—– c:\programdata\Radialpoint
2010-08-29 17:01 –d—– c:\progra~2\Radialpoint
2010-08-29 17:01 –d—– c:\programdata\Bell
2010-08-29 17:01 –d—– c:\program files\Bell
2010-08-29 17:01 –d—– c:\progra~2\Bell
2010-08-29 16:33 221,568 ——– c:\windows\system32\MpSigStub.exe
2010-08-29 16:06 172,032 a——- c:\windows\system32\wintrust.dll
2010-08-29 16:06 132,608 a——- c:\windows\system32\cabview.dll
2010-08-29 15:10 –d—– c:\users\Diane
==================== Find3M ====================
2010-07-27 18:44 197,920 a——- c:\windows\system32\dnssdX.dll
2010-07-27 18:44 107,808 a——- c:\windows\system32\dns-sd.exe
2010-07-27 18:44 91,424 a——- c:\windows\system32\dnssd.dll
2010-07-27 18:44 75,040 a——- c:\windows\system32\jdns_sd.dll
2010-06-30 02:25 978,432 a——- c:\windows\system32\wininet.dll
2010-06-19 02:33 3,955,080 a——- c:\windows\system32\ntkrnlpa.exe
2010-06-19 02:33 3,899,784 a——- c:\windows\system32\ntoskrnl.exe
2010-06-19 02:23 37,376 a——- c:\windows\system32\rtutils.dll
2010-06-19 00:07 2,326,016 a——- c:\windows\system32\win32k.sys
2009-07-14 00:56 291,294 a——- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 00:56 291,294 a——- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 00:56 31,548 a——- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 00:56 31,548 a——- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 00:41 174 a–sh— c:\program files\desktop.ini
2009-07-13 20:34 291,294 a——- c:\windows\inf\perflib\0000\perfi.dat
2009-07-13 20:34 291,294 a——- c:\windows\inf\perflib\0000\perfh.dat
2009-07-13 20:34 31,548 a——- c:\windows\inf\perflib\0000\perfd.dat
2009-07-13 20:34 31,548 a——- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 17:26 9,633,792 a–shr– c:\windows\fonts\StaticCache.dat
2009-07-13 21:14 396,800 a–sh— c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 20:00:38.74 ===============
ken545
Hi,
Looks you you installed Bell Internet Security which uses AVG as your Antivirus program, you also have Norton installed, this is the way I read it unless I am reading it wrong. If your happy with the software from Bell than you should uninstall Norton as more than one AV is overkill and will just slow down your system and cause other problems.
Nothing earth shattering on your log, lets do this.
Please download ATF Cleaner by Atribune to your desktop.
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.
Please download Malwarebytes from Here or Here
Looks you you installed Bell Internet Security which uses AVG as your Antivirus program, you also have Norton installed, this is the way I read it unless I am reading it wrong. If your happy with the software from Bell than you should uninstall Norton as more than one AV is overkill and will just slow down your system and cause other problems.
Nothing earth shattering on your log, lets do this.
Please download ATF Cleaner by Atribune to your desktop.
- Double-click ATF-Cleaner.exe to run the program.
- Under Main choose: Select All
- Click the Empty Selected button.
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.
Please download Malwarebytes from Here or Here
- Double-click mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan.
[external image: Posted Image] - When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected .
- When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
- Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Snow
The Norton came with this laptop, its only 3 weeks old…so i uninstalled Norton now
here is the malware log
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4624
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
15/09/2010 9:26:08 PM
mbam-log-2010-09-15 (21-26-08).txt
Scan type: Quick scan
Objects scanned: 133714
Time elapsed: 14 minute(s), 51 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
ken545
Looks good.
Please run this free online virus scanner from ESET
Then when done, reboot and post a new DDS log please
Please run this free online virus scanner from ESET
- Note: You will need to use Internet explorer for this scan
- Tick the box next to YES, I accept the Terms of Use.
- Click Start
- When asked, allow the activex control to install
- Click Start
- Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
- Click Scan
- Wait for the scan to finish
- Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
- Copy and paste that log as a reply to this topic
Then when done, reboot and post a new DDS log please
Snow
i did everything right except when i used IE it would give me an error for the scanner…so i used my default browser, the result of the scan says no threats found 0 no infected files found 0 and when i pasted the file path…it said it wasnt found, is it due to the scan using my browser?
Snow
DDS (Ver_09-09-29.01) - NTFSx86
Run by [removed] at 9:01:06.84 on 16/09/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Starter 6.1.7600.0.1252.2.1033.18.1013.245 [GMT -4:00]
============== Running Processes ===============
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\Program Files\Bell\Bell Internet Security Services\Fws.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Bell\Bell Internet Security Services\RpsSecurityAwareR.exe
C:\Program Files\Bell\Internet Service Advisor\ServicepointService.exe
C:\windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Personal Vault Backup Manager\VaultClientSRV.exe
C:\Program Files\Personal Vault Backup Manager\VaultClientUpgrade.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Bell\Bell Internet Security Services\rps.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\Bell\Internet Service Advisor\BISAComHandler.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
C:\windows\system32\igfxext.exe
C:\Program Files\Bell\Internet Service Advisor\BISA.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\taskeng.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Bell\Bell Internet Security Services\AVG\Identity Protection\agent\Bin\AVGIDSMonitor.exe
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Users\Diane\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Diane\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\Users\Diane\Desktop\dds.com
C:\windows\system32\conhost.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.toshiba.ca/welcome
uWindow Title = Presented by TOSHIBA Leading Innovation >>>
uDefault_Page_URL = hxxp://www.toshiba.ca/welcome
mDefault_Page_URL = hxxp://www.toshiba.ca/welcome
mStart Page = hxxp://www.toshiba.ca/welcome
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [Google Update] "c:\users\diane\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: []
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [RtHDVBg] c:\program files\realtek\audio\hda\RtHDVBg.exe /FORPCEE3
mRun: [HWSetup] c:\program files\toshiba\utilities\HWSetup.exe hwSetUP
mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe
mRun: [SVPWUTIL] c:\program files\toshiba\utilities\SVPWUTIL.exe SVPwUTIL
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [TWebCamera] "c:\program files\toshiba\toshiba web camera application\TWebCamera.exe" autorun
mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [TosVolRegulator] c:\program files\toshiba\tosvolregulator\TosVolRegulator.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
mRun: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
mRun: [BISA.exe] "c:\program files\bell\internet service advisor\BISA.exe" /AUTORUN
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
============= SERVICES / DRIVERS ===============
R0 RadialpointIDSEH;RadialpointIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-8-29 25608]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2010-1-28 185712]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
R2 Radialpoint Security Services;Bell Internet Security Services;c:\program files\bell\bell internet security services\RpsSecurityAwareR.exe [2010-8-29 166944]
R2 RadialpointIDSAgent;RadialpointIDSAgent;c:\program files\bell\bell internet security services\avg\identity protection\agent\bin\AVGIDSAgent.exe [2010-8-29 5832712]
R2 ServicepointService;ServicepointService;c:\program files\bell\internet service advisor\ServicepointService.exe [2010-8-29 689392]
R2 VaultClientSRV;Personal Vault Backup Manager Service;c:\program files\personal vault backup manager\VaultClientSRV.exe [2010-1-17 1051728]
R2 VaultClientUpgrade;Personal Vault Backup Manager Upgrade Service;c:\program files\personal vault backup manager\VaultClientUpgrade.exe [2010-1-17 56400]
R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2010-6-29 24064]
R3 RadialpointIDSDriver;RadialpointIDSDriver;c:\program files\bell\bell internet security services\avg\identity protection\agent\drivers\AVGIDSDriver.sys [2010-8-29 122376]
R3 RadialpointIDSFilter;RadialpointIDSFilter;c:\program files\bell\bell internet security services\avg\identity protection\agent\drivers\AVGIDSfilter.sys [2010-8-29 30216]
R3 RadialpointIDSShim;RadialpointIDSShim;c:\program files\bell\bell internet security services\avg\identity protection\agent\drivers\AVGIDSShim.sys [2010-8-29 21208]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-6-29 277536]
R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2010-6-29 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2010-2-5 111960]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2010-4-19 18432]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2010-6-29 189984]
=============== Created Last 30 ================
2010-09-16 07:07 –d—– c:\program files\ESET
2010-09-15 21:10 –d—– c:\users\diane\appdata\roaming\Malwarebytes
2010-09-15 21:09 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-15 21:09 20,952 a——- c:\windows\system32\drivers\mbam.sys
2010-09-15 21:09 –d—– c:\programdata\Malwarebytes
2010-09-15 21:09 –d—– c:\progra~2\Malwarebytes
2010-09-15 21:09 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-09-14 18:43 316,928 a——- c:\windows\system32\spoolsv.exe
2010-09-12 19:22 56 a—h— c:\programdata\ezsidmv.dat
2010-09-12 19:22 56 a—h— c:\progra~2\ezsidmv.dat
2010-09-12 19:19 –d–r– c:\program files\Skype
2010-09-12 19:19 –d—– c:\programdata\Skype
2010-09-04 13:31 0 a—h— c:\windows\system32\drivers\Msft_Kernel_netaapl_01009.Wdf
2010-09-04 13:25 107,368 a——- c:\windows\system32\GEARAspi.dll
2010-09-04 13:25 26,600 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-09-04 13:23 –d—– c:\program files\iPod
2010-09-04 13:23 –d—– c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-09-04 13:23 –d—– c:\program files\iTunes
2010-09-04 13:23 –d—– c:\progra~2\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-09-04 13:20 –d—– c:\programdata\Apple Computer
2010-09-04 13:18 –d—– c:\program files\Bonjour
2010-09-04 13:18 –d—– c:\programdata\Apple
2010-09-01 18:52 0 a—h— c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2010-08-31 17:06 1,130,824 a——- c:\windows\system32\dfshim.dll
2010-08-31 17:06 297,808 a——- c:\windows\system32\mscoree.dll
2010-08-31 17:06 295,264 a——- c:\windows\system32\PresentationHost.exe
2010-08-31 17:06 99,176 a——- c:\windows\system32\PresentationHostProxy.dll
2010-08-31 17:06 49,472 a——- c:\windows\system32\netfxperf.dll
2010-08-31 06:23 1,286,016 a——- c:\windows\system32\drivers\tcpip.sys
2010-08-31 06:22 194,488 a——- c:\windows\system32\drivers\fvevol.sys
2010-08-31 06:22 571,904 a——- c:\windows\system32\oleaut32.dll
2010-08-31 06:22 82,944 a——- c:\windows\system32\iccvid.dll
2010-08-31 06:22 197,632 a——- c:\windows\system32\ir32_32.dll
2010-08-31 06:22 2,614,272 a——- c:\windows\explorer.exe
2010-08-31 06:22 285,696 a——- c:\windows\system32\winlogon.exe
2010-08-31 06:19 369,152 a——- c:\windows\system32\secproc.dll
2010-08-29 21:56 –d—– c:\program files\GiMeSpace Desktop Extender
2010-08-29 18:28 –d—– c:\users\diane\Tracing
2010-08-29 17:11 25,608 a——- c:\windows\system32\drivers\AVGIDSEH.sys
2010-08-29 17:11 –d—– c:\program files\Personal Vault Backup Manager
2010-08-29 17:10 285,704 a——- c:\windows\system32\drivers\bdfsfltr.sys
2010-08-29 17:10 53,192 a——- c:\windows\system32\drivers\rp_skt32.sys
2010-08-29 17:10 48,384 a——- c:\windows\system32\drivers\rp_pkt32.sys
2010-08-29 17:09 –d—– c:\programdata\Raxco
2010-08-29 17:09 –d—– c:\program files\Raxco
2010-08-29 17:01 –d—– c:\users\diane\appdata\roaming\Bell
2010-08-29 17:01 –d—– c:\programdata\Radialpoint
2010-08-29 17:01 –d—– c:\progra~2\Radialpoint
2010-08-29 17:01 –d—– c:\programdata\Bell
2010-08-29 17:01 –d—– c:\program files\Bell
2010-08-29 17:01 –d—– c:\progra~2\Bell
2010-08-29 16:33 221,568 ——– c:\windows\system32\MpSigStub.exe
2010-08-29 16:06 172,032 a——- c:\windows\system32\wintrust.dll
2010-08-29 16:06 132,608 a——- c:\windows\system32\cabview.dll
2010-08-29 15:10 –d—– c:\users\Diane
==================== Find3M ====================
2010-07-27 18:44 197,920 a——- c:\windows\system32\dnssdX.dll
2010-07-27 18:44 107,808 a——- c:\windows\system32\dns-sd.exe
2010-07-27 18:44 91,424 a——- c:\windows\system32\dnssd.dll
2010-07-27 18:44 75,040 a——- c:\windows\system32\jdns_sd.dll
2010-06-30 02:25 978,432 a——- c:\windows\system32\wininet.dll
2010-06-19 02:33 3,955,080 a——- c:\windows\system32\ntkrnlpa.exe
2010-06-19 02:33 3,899,784 a——- c:\windows\system32\ntoskrnl.exe
2010-06-19 02:23 37,376 a——- c:\windows\system32\rtutils.dll
2010-06-19 00:07 2,326,016 a——- c:\windows\system32\win32k.sys
2009-07-14 00:56 291,294 a——- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 00:56 291,294 a——- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 00:56 31,548 a——- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 00:56 31,548 a——- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 00:41 174 a–sh— c:\program files\desktop.ini
2009-07-13 20:34 291,294 a——- c:\windows\inf\perflib\0000\perfi.dat
2009-07-13 20:34 291,294 a——- c:\windows\inf\perflib\0000\perfh.dat
2009-07-13 20:34 31,548 a——- c:\windows\inf\perflib\0000\perfd.dat
2009-07-13 20:34 31,548 a——- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 17:26 9,633,792 a–shr– c:\windows\fonts\StaticCache.dat
2009-07-13 21:14 396,800 a–sh— c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 9:03:36.04 ===============
ken545
No, I think your good to go, how are things running now ?
Snow
Working better and a little faster and that trojan hasnt reappeared
looks like everythings good to go now !
thank you Ken for all your help!
Snow
ken545
Your very welcome
Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community
Safe Surfn
Ken
- How did I get infected in the first place ?
Read these links and find out how to prevent getting infected again. - Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
- WhattheTech
- Grinler BleepingComputer
- GeeksTo Go
- Dslreports
Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster and Spyware Guard, they will conflict with the TeaTimer in Spybot , you can still install Spybot Search and Destroy but do not enable the TeaTimer .
Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community
- Spybot Search and Destroy 1.6
Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.
- WinPatrol Keep this fine program activated to block a lot of threats
- Spyware Blaster It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.
- Spyware Guard It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.
- IE-Spyad
IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
- Firefox 3 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
Safe Surfn
Ken
ken545
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI