This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Vista - Smitfraud-C & alot more

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm working on a friend's Toshiba Laptop that has Windows Vista.. The main symptoms were error stops (Memory_Management, Page_Fault_In_Nonpaged_Area, general Windows error in the a blue screen), inability to open internet explorer, loss of permissions to install or uninstall programs, no administrator tools, Task Scheduler failure (on startup), Open Office warning "Either another instance of OpenOffice.org is accessing your personal settins or your personal settings are locked. Simultaneous access can lead to inconsistencies in your personal settings. Before continuing, you should make sure "user" closes OpenOffice.org on host. Do you really want to continue?" (on startup), a notification message window that said "Host Process for Windows Services stopped working and was closed. A problem caused the application to stop working correctly. Windows will notify you if a solution is available.", and java.exe was missing. I've done numerous scans with Malwarebytes and Spybot Searcy & Destoy in safemode (couldn't run them in normal mode). They detected & removed Smitfraud-C, Funwebproducts, Right media, Double click, My websearch, Iwon, Fast click, and win32.autorun.tmp. A message window kept poppin up while running Spybot that said the following file is corrupt: Windows\system32\tbs.dll. Right media and Double click have reappeared several times. Since the scans, I now have Administrative tools and was able to install java but I still cannot run Internet Explore and I continue to get the Task scheduler & Open Office error and periodic blue screen errors. Please help me get rid of the remaining viruses/malware. The HijackThis log is attached. Thanks
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

โ€ขRefrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
โ€ขIf you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
โ€ขEven if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
โ€ขPlease reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post










Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)









Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thanks for the quick reply. TDSSKiller didn't find anything. The logs you requested are below and attached. 2010/12/23 18:22:24.0086 TDSS rootkit removing tool 2.4.12.0 Dec 16 2010 09:46:46 2010/12/23 18:22:24.0086 ================================================================================ 2010/12/23 18:22:24.0086 SystemInfo: 2010/12/23 18:22:24.0086 2010/12/23 18:22:24.0086 OS Version: 6.0.6001 ServicePack: 1.0 2010/12/23 18:22:24.0086 Product type: Workstation 2010/12/23 18:22:24.0086 ComputerName: BEN-PC 2010/12/23 18:22:24.0087 UserName: Ben 2010/12/23 18:22:24.0087 Windows directory: C:\Windows 2010/12/23 18:22:24.0087 System windows directory: C:\Windows 2010/12/23 18:22:24.0087 Processor architecture: Intel x86 2010/12/23 18:22:24.0087 Number of processors: 2 2010/12/23 18:22:24.0087 Page size: 0x1000 2010/12/23 18:22:24.0087 Boot type: Normal boot 2010/12/23 18:22:24.0087 ================================================================================ 2010/12/23 18:22:24.0382 Initialize success 2010/12/23 18:22:42.0802 ================================================================================ 2010/12/23 18:22:42.0802 Scan started 2010/12/23 18:22:42.0802 Mode: Manual; 2010/12/23 18:22:42.0802 ================================================================================ 2010/12/23 18:22:43.0725 ACPI (fcb8c7210f0135e24c6580f7f649c73c) C:\Windows\system32\drivers\acpi.sys 2010/12/23 18:22:43.0863 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 2010/12/23 18:22:44.0052 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 2010/12/23 18:22:44.0186 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 2010/12/23 18:22:44.0303 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 2010/12/23 18:22:44.0502 AFD (763e172a55177e478cb419f88fd0ba03) C:\Windows\system32\drivers\afd.sys 2010/12/23 18:22:44.0842 AgereSoftModem (ce91b158fa490cf4c4d487a4130f4660) C:\Windows\system32\DRIVERS\AGRSM.sys 2010/12/23 18:22:44.0976 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 2010/12/23 18:22:45.0007 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2010/12/23 18:22:45.0224 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 2010/12/23 18:22:45.0359 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 2010/12/23 18:22:45.0480 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 2010/12/23 18:22:45.0652 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 2010/12/23 18:22:45.0902 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\DRIVERS\amdk8.sys 2010/12/23 18:22:46.0040 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 2010/12/23 18:22:46.0121 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 2010/12/23 18:22:46.0192 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 2010/12/23 18:22:46.0270 atapi (2d9c903dc76a66813d350a562de40ed9) C:\Windows\system32\drivers\atapi.sys 2010/12/23 18:22:46.0544 athr (ca6078dda7cf80fec230d9478bbe6c1b) C:\Windows\system32\DRIVERS\athr.sys 2010/12/23 18:22:47.0203 atikmdag (22d300f835600c9c634860cf2912f9cf) C:\Windows\system32\DRIVERS\atikmdag.sys 2010/12/23 18:22:47.0546 AtiPcie (4aa1eb65481c392955939e735d27118b) C:\Windows\system32\DRIVERS\AtiPcie.sys 2010/12/23 18:22:47.0653 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 2010/12/23 18:22:47.0706 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 2010/12/23 18:22:47.0772 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys 2010/12/23 18:22:48.0003 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2010/12/23 18:22:48.0053 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2010/12/23 18:22:48.0127 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2010/12/23 18:22:48.0225 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2010/12/23 18:22:48.0478 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2010/12/23 18:22:48.0634 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2010/12/23 18:22:48.0750 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 2010/12/23 18:22:48.0852 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 2010/12/23 18:22:49.0018 cdrom (1ec25cea0de6ac4718bf89f9e1778b57) C:\Windows\system32\DRIVERS\cdrom.sys 2010/12/23 18:22:49.0212 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 2010/12/23 18:22:49.0314 CLFS (465745561c832b29f7c48b488aab3842) C:\Windows\system32\CLFS.sys 2010/12/23 18:22:49.0564 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 2010/12/23 18:22:49.0759 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 2010/12/23 18:22:49.0865 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 2010/12/23 18:22:49.0922 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 2010/12/23 18:22:49.0979 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 2010/12/23 18:22:50.0062 DfsC (9e635ae5e8ad93e2b5989e2e23679f97) C:\Windows\system32\Drivers\dfsc.sys 2010/12/23 18:22:50.0167 disk (64109e623abd6955c8fb110b592e68b7) C:\Windows\system32\drivers\disk.sys 2010/12/23 18:22:50.0360 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 2010/12/23 18:22:50.0697 DXGKrnl (85f33880b8cfb554bd3d9ccdb486845a) C:\Windows\System32\drivers\dxgkrnl.sys 2010/12/23 18:22:50.0773 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 2010/12/23 18:22:50.0945 Ecache (dd2cd259d83d8b72c02c5f2331ff9d68) C:\Windows\system32\drivers\ecache.sys 2010/12/23 18:22:51.0156 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 2010/12/23 18:22:51.0252 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 2010/12/23 18:22:51.0373 exfat (0d858eb20589a34efb25695acaa6aa2d) C:\Windows\system32\drivers\exfat.sys 2010/12/23 18:22:51.0460 fastfat (3c489390c2e2064563727752af8eab9e) C:\Windows\system32\drivers\fastfat.sys 2010/12/23 18:22:51.0705 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 2010/12/23 18:22:51.0874 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 2010/12/23 18:22:52.0009 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 2010/12/23 18:22:52.0254 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 2010/12/23 18:22:52.0334 FltMgr (05ea53afe985443011e36dab07343b46) C:\Windows\system32\drivers\fltmgr.sys 2010/12/23 18:22:52.0484 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 2010/12/23 18:22:52.0593 FwLnk (cbc22823628544735625b280665e434e) C:\Windows\system32\DRIVERS\FwLnk.sys 2010/12/23 18:22:52.0784 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 2010/12/23 18:22:52.0811 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2010/12/23 18:22:52.0863 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys 2010/12/23 18:22:53.0009 HDAudBus (c87b1ee051c0464491c1a7b03fa0bc99) C:\Windows\system32\DRIVERS\HDAudBus.sys 2010/12/23 18:22:53.0149 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2010/12/23 18:22:53.0412 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2010/12/23 18:22:53.0545 HidUsb (854ca287ab7faf949617a788306d967e) C:\Windows\system32\DRIVERS\hidusb.sys 2010/12/23 18:22:53.0724 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 2010/12/23 18:22:53.0975 HTTP (96e241624c71211a79c84f50a8e71cab) C:\Windows\system32\drivers\HTTP.sys 2010/12/23 18:22:54.0070 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 2010/12/23 18:22:54.0278 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 2010/12/23 18:22:54.0462 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 2010/12/23 18:22:54.0569 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2010/12/23 18:22:54.0787 IntcAzAudAddService (8a4341616976e47712b60f18c7049dcc) C:\Windows\system32\drivers\RTKVHDA.sys 2010/12/23 18:22:54.0969 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 2010/12/23 18:22:55.0328 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 2010/12/23 18:22:55.0503 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2010/12/23 18:22:55.0621 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 2010/12/23 18:22:55.0869 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 2010/12/23 18:22:56.0017 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 2010/12/23 18:22:56.0223 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 2010/12/23 18:22:56.0550 iScsiPrt (f247eec28317f6c739c16de420097301) C:\Windows\system32\DRIVERS\msiscsi.sys 2010/12/23 18:22:56.0648 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2010/12/23 18:22:56.0728 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2010/12/23 18:22:56.0809 jswpslwf (7e72514a3a1c5a9f3bff0660b3866c2b) C:\Windows\system32\DRIVERS\jswpslwf.sys 2010/12/23 18:22:57.0160 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 2010/12/23 18:22:57.0242 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\drivers\kbdhid.sys 2010/12/23 18:22:57.0357 KR10I (e8ca038f51f7761bd6e3a3b0b8014263) C:\Windows\system32\drivers\kr10i.sys 2010/12/23 18:22:57.0493 KR10N (6a4adb9186dd0e114e623daf57e42b31) C:\Windows\system32\drivers\kr10n.sys 2010/12/23 18:22:57.0784 KSecDD (7a0cf7908b6824d6a2a1d313e5ae3dca) C:\Windows\system32\Drivers\ksecdd.sys 2010/12/23 18:22:57.0881 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 2010/12/23 18:22:57.0940 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 2010/12/23 18:22:58.0009 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 2010/12/23 18:22:58.0084 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 2010/12/23 18:22:58.0376 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 2010/12/23 18:22:58.0473 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 2010/12/23 18:22:58.0604 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 2010/12/23 18:22:58.0736 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 2010/12/23 18:22:58.0849 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 2010/12/23 18:22:59.0035 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 2010/12/23 18:22:59.0161 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 2010/12/23 18:22:59.0236 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 2010/12/23 18:22:59.0473 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 2010/12/23 18:22:59.0572 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 2010/12/23 18:22:59.0676 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2010/12/23 18:22:59.0826 MRxDAV (ae3de84536b6799d2267443cec8edbb9) C:\Windows\system32\drivers\mrxdav.sys 2010/12/23 18:22:59.0920 mrxsmb (7afc42e60432fd1014f5342f2b1b1f74) C:\Windows\system32\DRIVERS\mrxsmb.sys 2010/12/23 18:23:00.0029 mrxsmb10 (8a75752ae17924f65452746674b14b78) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2010/12/23 18:23:00.0090 mrxsmb20 (f4d0f3252e651f02be64984ffa738394) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2010/12/23 18:23:00.0131 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys 2010/12/23 18:23:00.0164 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 2010/12/23 18:23:00.0385 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 2010/12/23 18:23:00.0524 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 2010/12/23 18:23:00.0725 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 2010/12/23 18:23:00.0844 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 2010/12/23 18:23:00.0880 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 2010/12/23 18:23:01.0086 MsRPC (b5614aecb05a9340aa0fb55bf561cc63) C:\Windows\system32\drivers\MsRPC.sys 2010/12/23 18:23:01.0262 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 2010/12/23 18:23:01.0507 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 2010/12/23 18:23:01.0670 Mup (6dfd1d322de55b0b7db7d21b90bec49c) C:\Windows\system32\Drivers\mup.sys 2010/12/23 18:23:01.0813 NativeWifiP (3c21ce48ff529bb73dadb98770b54025) C:\Windows\system32\DRIVERS\nwifi.sys 2010/12/23 18:23:02.0037 NDIS (9bdc71790fa08f0a0b5f10462b1bd0b1) C:\Windows\system32\drivers\ndis.sys 2010/12/23 18:23:02.0238 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 2010/12/23 18:23:02.0446 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 2010/12/23 18:23:02.0653 NdisWan (3d14c3b3496f88890d431e8aa022a411) C:\Windows\system32\DRIVERS\ndiswan.sys 2010/12/23 18:23:02.0796 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 2010/12/23 18:23:02.0881 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 2010/12/23 18:23:02.0926 netbt (7c5fee5b1c5728507cd96fb4a13e7a02) C:\Windows\system32\DRIVERS\netbt.sys 2010/12/23 18:23:03.0135 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2010/12/23 18:23:03.0205 Npfs (ecb5003f484f9ed6c608d6d6c7886cbb) C:\Windows\system32\drivers\Npfs.sys 2010/12/23 18:23:03.0341 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 2010/12/23 18:23:03.0590 Ntfs (b4effe29eb4f15538fd8a9681108492d) C:\Windows\system32\drivers\Ntfs.sys 2010/12/23 18:23:03.0798 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2010/12/23 18:23:03.0836 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 2010/12/23 18:23:03.0906 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 2010/12/23 18:23:03.0938 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 2010/12/23 18:23:04.0016 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 2010/12/23 18:23:04.0415 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys 2010/12/23 18:23:04.0558 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2010/12/23 18:23:04.0636 partmgr (3b38467e7c3daed009dfe359e17f139f) C:\Windows\system32\drivers\partmgr.sys 2010/12/23 18:23:04.0779 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2010/12/23 18:23:04.0995 pci (01b94418deb235dff777cc80076354b4) C:\Windows\system32\drivers\pci.sys 2010/12/23 18:23:05.0062 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys 2010/12/23 18:23:05.0130 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2010/12/23 18:23:05.0416 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2010/12/23 18:23:05.0675 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 2010/12/23 18:23:05.0792 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 2010/12/23 18:23:05.0979 PSched (bfef604508a0ed1eae2a73e872555ffb) C:\Windows\system32\DRIVERS\pacer.sys 2010/12/23 18:23:06.0147 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 2010/12/23 18:23:06.0342 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2010/12/23 18:23:06.0417 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 2010/12/23 18:23:06.0671 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 2010/12/23 18:23:06.0849 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 2010/12/23 18:23:06.0989 RasPppoe (3e9d9b048107b40d87b97df2e48e0744) C:\Windows\system32\DRIVERS\raspppoe.sys 2010/12/23 18:23:07.0078 RasSstp (a7d141684e9500ac928a772ed8e6b671) C:\Windows\system32\DRIVERS\rassstp.sys 2010/12/23 18:23:07.0344 rdbss (6e1c5d0457622f9ee35f683110e93d14) C:\Windows\system32\DRIVERS\rdbss.sys 2010/12/23 18:23:07.0458 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 2010/12/23 18:23:07.0588 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 2010/12/23 18:23:07.0745 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 2010/12/23 18:23:08.0052 RDPWD (e1c18f4097a5abcec941dc4b2f99db7e) C:\Windows\system32\drivers\RDPWD.sys 2010/12/23 18:23:08.0178 rimmptsk (355aac141b214bef1dbc1483afd9bd50) C:\Windows\system32\DRIVERS\rimmptsk.sys 2010/12/23 18:23:08.0215 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\Windows\system32\DRIVERS\rimsptsk.sys 2010/12/23 18:23:08.0378 rismxdp (d231b577024aa324af13a42f3a807d10) C:\Windows\system32\DRIVERS\rixdptsk.sys 2010/12/23 18:23:08.0543 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 2010/12/23 18:23:08.0675 RTL8169 (8cca591019216e9523e3cb385ce643e6) C:\Windows\system32\DRIVERS\Rtlh86.sys 2010/12/23 18:23:08.0768 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2010/12/23 18:23:08.0950 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys 2010/12/23 18:23:09.0005 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2010/12/23 18:23:09.0053 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2010/12/23 18:23:09.0094 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2010/12/23 18:23:09.0122 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 2010/12/23 18:23:09.0261 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 2010/12/23 18:23:09.0346 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 2010/12/23 18:23:09.0395 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 2010/12/23 18:23:09.0444 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2010/12/23 18:23:09.0541 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 2010/12/23 18:23:09.0610 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 2010/12/23 18:23:09.0665 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 2010/12/23 18:23:09.0719 Smb (031e6bcd53c9b2b9ace111eafec347b6) C:\Windows\system32\DRIVERS\smb.sys 2010/12/23 18:23:09.0790 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 2010/12/23 18:23:09.0881 srv (9a0163e7fbe59da0591bb1ad77d92e63) C:\Windows\system32\DRIVERS\srv.sys 2010/12/23 18:23:09.0976 srv2 (c7da26d2c7d480b1dd38ca19cc90b821) C:\Windows\system32\DRIVERS\srv2.sys 2010/12/23 18:23:10.0057 srvnet (f9c65e1e00a6bbf7c57d9b8ea068c525) C:\Windows\system32\DRIVERS\srvnet.sys 2010/12/23 18:23:10.0292 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 2010/12/23 18:23:10.0376 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2010/12/23 18:23:10.0436 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2010/12/23 18:23:10.0479 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2010/12/23 18:23:10.0533 SynTP (55f6e55cc2430ca8713387106fa79817) C:\Windows\system32\DRIVERS\SynTP.sys 2010/12/23 18:23:10.0687 Tcpip (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\drivers\tcpip.sys 2010/12/23 18:23:10.0776 Tcpip6 (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\DRIVERS\tcpip.sys 2010/12/23 18:23:10.0871 tcpipreg (d4a2e4a4b011f3a883af77315a5ae76b) C:\Windows\system32\drivers\tcpipreg.sys 2010/12/23 18:23:10.0947 tdcmdpst (1825bceb47bf41c5a9f0e44de82fc27a) C:\Windows\system32\DRIVERS\tdcmdpst.sys 2010/12/23 18:23:11.0018 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 2010/12/23 18:23:11.0085 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 2010/12/23 18:23:11.0135 tdx (d09276b1fab033ce1d40dcbdf303d10f) C:\Windows\system32\DRIVERS\tdx.sys 2010/12/23 18:23:11.0198 TermDD (a048056f5e1a96a9bf3071b91741a5aa) C:\Windows\system32\DRIVERS\termdd.sys 2010/12/23 18:23:11.0396 tosrfec (5c4103544612e5011ef46301b93d1aa6) C:\Windows\system32\DRIVERS\tosrfec.sys 2010/12/23 18:23:11.0487 tos_sps32 (1ea5f27c29405bf49799feca77186da9) C:\Windows\system32\DRIVERS\tos_sps32.sys 2010/12/23 18:23:11.0560 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 2010/12/23 18:23:11.0616 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 2010/12/23 18:23:11.0668 tunnel (6042505ff6fa9ac1ef7684d0e03b6940) C:\Windows\system32\DRIVERS\tunnel.sys 2010/12/23 18:23:11.0744 TVALZ (792a8b80f8188aba4b2be271583f3e46) C:\Windows\system32\DRIVERS\TVALZ_O.SYS 2010/12/23 18:23:11.0812 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 2010/12/23 18:23:11.0863 udfs (8b5088058fa1d1cd897a2113ccff6c58) C:\Windows\system32\DRIVERS\udfs.sys 2010/12/23 18:23:11.0989 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 2010/12/23 18:23:12.0064 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 2010/12/23 18:23:12.0131 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2010/12/23 18:23:12.0197 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2010/12/23 18:23:12.0277 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 2010/12/23 18:23:12.0371 USBAAPL (e8c1b9ebac65288e1b51e8a987d98af6) C:\Windows\system32\Drivers\usbaapl.sys 2010/12/23 18:23:12.0431 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 2010/12/23 18:23:12.0491 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2010/12/23 18:23:12.0544 usbehci (cebe90821810e76320155beba722fcf9) C:\Windows\system32\DRIVERS\usbehci.sys 2010/12/23 18:23:12.0619 usbhub (cc6b28e4ce39951357963119ce47b143) C:\Windows\system32\DRIVERS\usbhub.sys 2010/12/23 18:23:12.0688 usbohci (7bdb7b0e7d45ac0402d78b90789ef47c) C:\Windows\system32\DRIVERS\usbohci.sys 2010/12/23 18:23:12.0759 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 2010/12/23 18:23:12.0814 USBSTOR (87ba6b83c5d19b69160968d07d6e2982) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2010/12/23 18:23:12.0873 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 2010/12/23 18:23:12.0956 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 2010/12/23 18:23:13.0003 UVCFTR (8c5094a8ab24de7496c7c19942f2df04) C:\Windows\system32\Drivers\UVCFTR_S.SYS 2010/12/23 18:23:13.0079 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 2010/12/23 18:23:13.0135 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 2010/12/23 18:23:13.0208 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 2010/12/23 18:23:13.0296 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 2010/12/23 18:23:13.0496 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 2010/12/23 18:23:13.0694 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 2010/12/23 18:23:13.0781 volmgrx (98f5ffe6316bd74e9e2c97206c190196) C:\Windows\system32\drivers\volmgrx.sys 2010/12/23 18:23:14.0004 volsnap (d8b4a53dd2769f226b3eb374374987c9) C:\Windows\system32\drivers\volsnap.sys 2010/12/23 18:23:14.0153 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 2010/12/23 18:23:14.0437 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2010/12/23 18:23:14.0614 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2010/12/23 18:23:14.0649 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 2010/12/23 18:23:14.0742 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 2010/12/23 18:23:14.0793 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 2010/12/23 18:23:15.0019 WMDrive (216de264b2adde579153ae028ecb453f) C:\Windows\system32\drivers\WMDrive.sys 2010/12/23 18:23:15.0100 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys 2010/12/23 18:23:15.0203 WpdUsb (0cec23084b51b8288099eb710224e955) C:\Windows\system32\DRIVERS\wpdusb.sys 2010/12/23 18:23:15.0347 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 2010/12/23 18:23:15.0653 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 2010/12/23 18:23:15.0804 ================================================================================ 2010/12/23 18:23:15.0804 Scan finished 2010/12/23 18:23:15.0804 ================================================================================ 2010/12/23 18:24:13.0806 Deinitialize success DDS (Ver_10-12-12.02) - NTFSx86 Run by [removed] at 18:26:40.14 on Thu 12/23/2010 Internet Explorer: 7.0.6001.18000 Microsoftยฎ Windows Vistaโ„ข Home Premium 6.0.6001.1.1252.1.1033.18.2941.2043 [GMT -6:00] SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\agrsmsvc.exe C:\Toshiba\IVP\ISM\pinger.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc c:\Toshiba\IVP\swupdate\swupdtmr.exe C:\Windows\system32\TODDSrv.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\Dwm.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\found.000\dir0001.chk\FrostWire\FrostWire.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Ben\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/?ilc=1 uDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart mStart Page = hxxp://www.att.net mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Javaโ„ข Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: The Weather Channel Toolbar: {2e5e800e-6ac0-411e-940a-369530a35e43} - c:\windows\system32\TwcToolbarIe7.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [TOSCDSPD] TOSCDSPD.EXE uRun: [1040749826] c:\program files\toshiba registration\registration.exe /r "c:\program files\toshiba registration\Registration.rpd" uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe" uRun: [AROReminder] c:\found.000\dir0001.chk\advanced registry optimizer\ARO.exe -rem mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [TRCMan] c:\program files\toshiba\trcman\TRCMan.exe mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe mRun: [jswtrayutil] "c:\program files\jumpstart\jswtrayutil.exe" mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [NDSTray.exe] NDSTray.exe mRun: [PCMAgent] "c:\program files\cyberlink\powercinema for toshiba\PCMAgent.exe" mRun: [CLMLServer] "c:\program files\cyberlink\powercinema for toshiba\kernel\clml\CLMLSvc.exe" mRun: [00TCrdMain] c:\program files\toshiba\flashcards\TCrdMain.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\users\ben\appdata\roaming\micros~1\windows\startm~1\programs\startup\frostw~1.lnk - c:\found.000\dir0001.chk\frostwire\FrostWire.exe StartupFolder: c:\users\ben\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\found.000\dir0001.chk\openoffice.org 3\program\quickstart.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab Hosts: 127.0.0.1 www.spywareinfo.com ============= SERVICES / DRIVERS =============== R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\drivers\jswpslwf.sys [2008-6-6 20352] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-12-22 1153368] R2 WMDrive;WMDrive;c:\windows\system32\drivers\WMDrive.sys [2008-12-1 189952] R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008-2-12 7168] S2 ConfigFree Service;ConfigFree Service;"c:\program files\toshiba\configfree\cfsvcs.exe" โ€“> c:\program files\toshiba\configfree\CFSvcs.exe [?] S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;"c:\program files\toshiba\smartlogservice\tosipcsrv.exe" โ€“> c:\program files\toshiba\smartlogservice\TosIPCSrv.exe [?] S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\jumpstart\jswpsapi.exe โ€“> c:\program files\jumpstart\jswpsapi.exe [?] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] =============== Created Last 30 ================ 2010-12-23 20:38:58 472808 โ€”-a-w- c:\windows\system32\deployJava1.dll 2010-12-23 19:54:35 388096 โ€”-a-r- c:\users\ben\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2010-12-23 19:54:34 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Trend Micro 2010-12-23 15:07:11 38224 โ€”-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-12-23 15:07:08 20952 โ€”-a-w- c:\windows\system32\drivers\mbam.sys 2010-12-23 15:07:08 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Malwarebytes' Anti-Malware 2010-12-23 13:55:47 โ€”โ€”โ€“ dโ€”โ€“w- C:\85fae879bc2c681552a9c8880211 2010-12-23 05:05:32 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Spybot - Search & Destroy 2010-12-23 05:05:32 โ€”โ€”โ€“ dโ€”โ€“w- c:\progra~2\Spybot - Search & Destroy 2010-12-23 04:18:24 โ€”โ€”โ€“ dโ€”โ€“w- C:\Program Files 2010-12-22 23:59:56 โ€”โ€”โ€“ d-shโ€“w- C:\found.000 2010-12-18 01:28:07 6273872 โ€”-a-w- c:\progra~2\microsoft\windows defender\definition updates\{85c879da-ffdc-4212-9118-b87d33b87937}\mpengine.dll ==================== Find3M ==================== 2010-10-19 16:41:44 222080 โ€”โ€”w- c:\windows\system32\MpSigStub.exe 2010-09-26 00:20:15 266455793 โ€”-a-w- c:\windows\DUMP4f47.tmp ============= FINISH: 18:27:33.37 ===============
Are you running any antivirus?



Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
I ran Combofix in safemode. I hope that's OK. I can only access the internet in safemode with networking. The other two scans were done in normal mode. Also, Combofix displayed this message: "Access denied. Administrator permissions are needed to use the selected options: Use an administrator command prompt to complete these tasks." I don't use Vista too often & forgot to run this as the administrator. It did run and create a log (see below). Let me know if I need to run it again.

ComboFix 10-12-23.02 - Ben 12/23/2010 18:51:36.1.2 - x86 NETWORK
Microsoftยฎ Windows Vistaโ„ข Home Premium 6.0.6001.1.1252.1.1033.18.2941.2502 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-11-24 to 2010-12-24 )))))))))))))))))))))))))))))))
.

2010-12-24 00:56 . 2010-12-24 00:56 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Ben\AppData\Local\temp
2010-12-24 00:56 . 2010-12-24 00:56 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp
2010-12-23 20:43 . 2010-12-23 20:43 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\Sun
2010-12-23 20:38 . 2010-12-23 20:38 472808 โ€”-a-w- c:\windows\system32\deployJava1.dll
2010-12-23 19:54 . 2010-12-23 19:54 388096 โ€”-a-r- c:\users\Ben\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-12-23 15:07 . 2010-12-21 00:09 38224 โ€”-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 15:07 . 2010-12-21 00:08 20952 โ€”-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-23 13:55 . 2010-12-23 13:55 โ€”โ€”โ€“ dโ€”โ€“w- C:\85fae879bc2c681552a9c8880211
2010-12-23 05:05 . 2010-12-23 05:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Spybot - Search & Destroy
2010-12-23 04:18 . 2010-12-23 20:39 โ€”โ€”โ€“ dโ€”โ€“w- C:\Program Files
2010-12-22 23:59 . 2010-12-22 23:59 โ€”โ€”โ€“ dโ€”โ€“w- C:\found.000
2010-12-18 01:28 . 2010-11-16 18:01 6273872 โ€”-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{85C879DA-FFDC-4212-9118-B87D33B87937}\mpengine.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 16:41 . 2010-02-15 04:58 222080 โ€”โ€”w- c:\windows\system32\MpSigStub.exe
2010-09-26 00:20 . 2008-06-06 18:41 266455793 โ€”-a-w- c:\windows\DUMP4f47.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AROReminder"="c:\found.000\dir0001.chk\Advanced Registry Optimizer\ARO.exe" [2010-01-20 2137600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-30 4911104]
"NDSTray.exe"="NDSTray.exe" [BU]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-21 963976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]

c:\users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
FrostWire On Startup.lnk - c:\found.000\dir0001.chk\FrostWire\FrostWire.exe [2010-2-10 114688]
OpenOffice.org 3.0.lnk - c:\found.000\dir0001.chk\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [x]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [x]
R3 IO_Memory;IO_Memory;c:\windows\SYSTEM32\SYSPREP\Drivers\ioport.sys [x]
R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [x]
R3 SVRPEDRV;SVRPEDRV;c:\windows\System32\sysprep\UP_date\PEDrv.sys [x]
S1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwf.sys [2007-09-01 20352]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]


โ€” Other Services/Drivers In Memory โ€”

*NewlyCreated* - ECACHE
.
.
โ€”โ€”- Supplementary Scan โ€”โ€”-
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
mStart Page = hxxp://www.att.net
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
HKCU-Run-DW6 - c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe
HKLM-Run-StartCCC - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
HKLM-Run-TRCMan - c:\program files\TOSHIBA\TRCMan\TRCMan.exe
HKLM-Run-TPwrMain - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - %ProgramFiles%\TOSHIBA\TBS\HSON.exe
HKLM-Run-SmoothView - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-jswtrayutil - c:\program files\Jumpstart\jswtrayutil.exe
HKLM-Run-ITSecMng - %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe
HKLM-Run-SynTPEnh - c:\program files\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-PCMAgent - c:\program files\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe
HKLM-Run-CLMLServer - c:\program files\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe
HKLM-Run-00TCrdMain - c:\program files\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-QuickTime Task - c:\program files\QuickTime\QTTask.exe
HKLM-Run-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
HKLM-RunOnce- - (no file)
AddRemove-Adobe AIR - c:\program files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe
AddRemove-Advanced Registry Optimizer_is1 - c:\program files\Advanced Registry Optimizer\unins000.exe
AddRemove-ALUpdate_is1 - c:\program files\ESTsoft\ALUpdate\unins000.exe
AddRemove-AT&T Yahoo! Browser Configuration - c:\program files\SBC Yahoo!\Connection Manager\uninstATTConfig.exe
AddRemove-FrostWire - c:\program files\FrostWire\Uninstall.exe
AddRemove-Hardware Helper_is1 - c:\program files\Driver-Soft\HardwareHelper\unins000.exe
AddRemove-InstallShield_{03240EBA-04F2-4652-BC7F-B055902BDCD3} - c:\program files\InstallShield Installation Information\{03240EBA-04F2-4652-BC7F-B055902BDCD3}\setup.exe
AddRemove-InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761} - c:\program files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\setup.exe
AddRemove-InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF} - c:\program files\InstallShield Installation Information\{617C36FD-0CBE-4600-84B2-441CEB12FADF}\setup.exe
AddRemove-The Weather Channel Toolbar - c:\progra~1\THEWEA~2\UNWISE.EXE
AddRemove-{12B3A009-A080-4619-9A2A-C6DB151D8D67} - c:\program files\InstallShield Installation Information\{12B3A009-A080-4619-9A2A-C6DB151D8D67}\setup.exe
AddRemove-{37C866E4-AA67-4725-9E95-A39968DD7960} - c:\program files\InstallShield Installation Information\{37C866E4-AA67-4725-9E95-A39968DD7960}\setup.exe
AddRemove-{6C5F3BDC-0A1B-4436-A696-5939629D5C31} - c:\program files\InstallShield Installation Information\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}\setup.exe
AddRemove-{8833FFB6-5B0C-4764-81AA-06DFEED9A476} - c:\program files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe
AddRemove-{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D} - c:\program files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\setup.exe
AddRemove-{A644254B-92F6-4970-8635-AB0775371E72} - c:\program files\InstallShield Installation Information\{A644254B-92F6-4970-8635-AB0775371E72}\setup.exe
AddRemove-{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13} - c:\program files\InstallShield Installation Information\{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}\setup.exe
AddRemove-{FEB650EB-7639-444E-9FC2-C33EE6ED1A37} - c:\program files\InstallShield Installation Information\{FEB650EB-7639-444E-9FC2-C33EE6ED1A37}\setup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-23 18:56
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes โ€ฆ

scanning hidden autostart entries โ€ฆ

scanning hidden files โ€ฆ

scan completed successfully
hidden files: 0

**************************************************************************
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€”

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2010-12-23 18:58:52
ComboFix-quarantined-files.txt 2010-12-24 00:58

Pre-Run: 157,865,172,992 bytes free
Post-Run: 157,781,688,320 bytes free

- - End Of File - - 11599DCB098F8ABEEB8E83F894398702
I ran Combofix in safemode. I hope that's OK. I can only access the internet in safemode with networking. The other two scans were done in normal mode. Also, Combofix displayed this message: "Access denied. Administrator permissions are needed to use the selected options: Use an administrator command prompt to complete these tasks." I don't use Vista too often & forgot to run this as the administrator. It did run and create a log (see below). Let me know if I need to run it again.

ComboFix 10-12-23.02 - Ben 12/23/2010 18:51:36.1.2 - x86 NETWORK
Microsoftยฎ Windows Vistaโ„ข Home Premium 6.0.6001.1.1252.1.1033.18.2941.2502 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-11-24 to 2010-12-24 )))))))))))))))))))))))))))))))
.

2010-12-24 00:56 . 2010-12-24 00:56 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Ben\AppData\Local\temp
2010-12-24 00:56 . 2010-12-24 00:56 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp
2010-12-23 20:43 . 2010-12-23 20:43 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\Sun
2010-12-23 20:38 . 2010-12-23 20:38 472808 โ€”-a-w- c:\windows\system32\deployJava1.dll
2010-12-23 19:54 . 2010-12-23 19:54 388096 โ€”-a-r- c:\users\Ben\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-12-23 15:07 . 2010-12-21 00:09 38224 โ€”-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 15:07 . 2010-12-21 00:08 20952 โ€”-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-23 13:55 . 2010-12-23 13:55 โ€”โ€”โ€“ dโ€”โ€“w- C:\85fae879bc2c681552a9c8880211
2010-12-23 05:05 . 2010-12-23 05:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Spybot - Search & Destroy
2010-12-23 04:18 . 2010-12-23 20:39 โ€”โ€”โ€“ dโ€”โ€“w- C:\Program Files
2010-12-22 23:59 . 2010-12-22 23:59 โ€”โ€”โ€“ dโ€”โ€“w- C:\found.000
2010-12-18 01:28 . 2010-11-16 18:01 6273872 โ€”-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{85C879DA-FFDC-4212-9118-B87D33B87937}\mpengine.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 16:41 . 2010-02-15 04:58 222080 โ€”โ€”w- c:\windows\system32\MpSigStub.exe
2010-09-26 00:20 . 2008-06-06 18:41 266455793 โ€”-a-w- c:\windows\DUMP4f47.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AROReminder"="c:\found.000\dir0001.chk\Advanced Registry Optimizer\ARO.exe" [2010-01-20 2137600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-30 4911104]
"NDSTray.exe"="NDSTray.exe" [BU]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-21 963976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]

c:\users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
FrostWire On Startup.lnk - c:\found.000\dir0001.chk\FrostWire\FrostWire.exe [2010-2-10 114688]
OpenOffice.org 3.0.lnk - c:\found.000\dir0001.chk\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [x]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [x]
R3 IO_Memory;IO_Memory;c:\windows\SYSTEM32\SYSPREP\Drivers\ioport.sys [x]
R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [x]
R3 SVRPEDRV;SVRPEDRV;c:\windows\System32\sysprep\UP_date\PEDrv.sys [x]
S1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwf.sys [2007-09-01 20352]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]


โ€” Other Services/Drivers In Memory โ€”

*NewlyCreated* - ECACHE
.
.
โ€”โ€”- Supplementary Scan โ€”โ€”-
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
mStart Page = hxxp://www.att.net
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
HKCU-Run-DW6 - c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe
HKLM-Run-StartCCC - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
HKLM-Run-TRCMan - c:\program files\TOSHIBA\TRCMan\TRCMan.exe
HKLM-Run-TPwrMain - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - %ProgramFiles%\TOSHIBA\TBS\HSON.exe
HKLM-Run-SmoothView - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-jswtrayutil - c:\program files\Jumpstart\jswtrayutil.exe
HKLM-Run-ITSecMng - %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe
HKLM-Run-SynTPEnh - c:\program files\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-PCMAgent - c:\program files\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe
HKLM-Run-CLMLServer - c:\program files\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe
HKLM-Run-00TCrdMain - c:\program files\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-QuickTime Task - c:\program files\QuickTime\QTTask.exe
HKLM-Run-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
HKLM-RunOnce- - (no file)
AddRemove-Adobe AIR - c:\program files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe
AddRemove-Advanced Registry Optimizer_is1 - c:\program files\Advanced Registry Optimizer\unins000.exe
AddRemove-ALUpdate_is1 - c:\program files\ESTsoft\ALUpdate\unins000.exe
AddRemove-AT&T Yahoo! Browser Configuration - c:\program files\SBC Yahoo!\Connection Manager\uninstATTConfig.exe
AddRemove-FrostWire - c:\program files\FrostWire\Uninstall.exe
AddRemove-Hardware Helper_is1 - c:\program files\Driver-Soft\HardwareHelper\unins000.exe
AddRemove-InstallShield_{03240EBA-04F2-4652-BC7F-B055902BDCD3} - c:\program files\InstallShield Installation Information\{03240EBA-04F2-4652-BC7F-B055902BDCD3}\setup.exe
AddRemove-InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761} - c:\program files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\setup.exe
AddRemove-InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF} - c:\program files\InstallShield Installation Information\{617C36FD-0CBE-4600-84B2-441CEB12FADF}\setup.exe
AddRemove-The Weather Channel Toolbar - c:\progra~1\THEWEA~2\UNWISE.EXE
AddRemove-{12B3A009-A080-4619-9A2A-C6DB151D8D67} - c:\program files\InstallShield Installation Information\{12B3A009-A080-4619-9A2A-C6DB151D8D67}\setup.exe
AddRemove-{37C866E4-AA67-4725-9E95-A39968DD7960} - c:\program files\InstallShield Installation Information\{37C866E4-AA67-4725-9E95-A39968DD7960}\setup.exe
AddRemove-{6C5F3BDC-0A1B-4436-A696-5939629D5C31} - c:\program files\InstallShield Installation Information\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}\setup.exe
AddRemove-{8833FFB6-5B0C-4764-81AA-06DFEED9A476} - c:\program files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe
AddRemove-{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D} - c:\program files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\setup.exe
AddRemove-{A644254B-92F6-4970-8635-AB0775371E72} - c:\program files\InstallShield Installation Information\{A644254B-92F6-4970-8635-AB0775371E72}\setup.exe
AddRemove-{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13} - c:\program files\InstallShield Installation Information\{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}\setup.exe
AddRemove-{FEB650EB-7639-444E-9FC2-C33EE6ED1A37} - c:\program files\InstallShield Installation Information\{FEB650EB-7639-444E-9FC2-C33EE6ED1A37}\setup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-23 18:56
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes โ€ฆ

scanning hidden autostart entries โ€ฆ

scanning hidden files โ€ฆ

scan completed successfully
hidden files: 0

**************************************************************************
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€”

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2010-12-23 18:58:52
ComboFix-quarantined-files.txt 2010-12-24 00:58

Pre-Run: 157,865,172,992 bytes free
Post-Run: 157,781,688,320 bytes free

- - End Of File - - 11599DCB098F8ABEEB8E83F894398702
Sorry for posting twice. I was trying to edit the first post. Opps! I wanted to add, there isn't any antivirus software on this laptop. That will be the first order of business when I'm finished fixing this mess.
Download Avira free antivirus from the link below,run a full scan and remove anything it finds.

http://www.avira.com/en/avira-free-antivirus
I tried to install Avira but I got this error: "Installation of the Microsoft Runtime Redistributable Kit has failed. The probable cause is a Windows update runnin in parallel. Please check whether a Windows update is in progress and run Avira AntiVir Personal - Free Antivirus setup again a little later." Windows update is not running to my knowledge. Please advise.
I was able to install the Microsoft anti-virus. However, it needed to be updated before I could run the scan. So, since I can only access the internet in safemode, I rebooted to safemode and ran the updates. When I did, it went to a blue screen which said "A problem has been detected and window has been shut down to prevent damage to you computer." So, I rebooted to safe mode and tried again. This time I got the blue screen but this time it said page_fault_in_nonpaged_area. I rebooted to safemode one more time and tried it again. Yes, I got the blue screen again but his time it said Memory_Management. Please advise.
I opened Windows Security Essentials and saw the update completed before the last crash happened. I'm going to go ahead and run the scan. I'll let you know the results.
I tried to run a quick scan and got the blue screen again. This time the error was IRQL_NOT_LESS_OR_EQUAL. Let me know what I should do next.
Lets see if this scan will run,this could take a very long time.

Print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

Please download Dr.Web CureIt and save it to your desktop. DO NOT perform a scan yet.
alternate download link
Note: The file will be randomly named (i.e. 5mkuvc4z.exe).

Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with Dr.Web CureIt as follows:
  • Double-click on the randomly named file to open the program and click Start. (There is no need to update if you just downloaded the most current version
  • Read the anti-virus check by DrWeb scanner prompt and click Ok where asked to Start scan now? Allow the setup.exe to load if asked by any of your security programs.
  • The Express scan will automatically begin.
    (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
  • If prompted to dowload the Full version Free Trial, ignore and click the X to close the window.
  • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All. (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
  • After the Express Scan is finished, put a check next to Complete scan to scan all local disks and removable media.
  • In the top menu, click Settings > Change settings, and uncheck "Heuristic analysis" under the "Scanning" tab, then click Apply, Ok.
  • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
  • Please be patient as this scan could take a long time to complete.
  • When the scan has finished, a message will be displayed at the bottom indicating if any viruses were found.
  • Click Select All, then choose Cure > Move incurable.
  • In the top menu, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
The first Dr. Web CureIt link downloaded OK but i won't run (I click it and it asks if I want to run it. I click run and nothing happens). The second link will run however it is 205 days out of date and does not download an updated version when I click OK to get an update. Note: Neither icon shows up on the desktop however they to appear in the Desktop tool bar. This is where I tried to run them from. Please advise.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI