This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Suddenly the Computer is very slow and applications hang

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Suddenly my computer became very slow within the past week, nothing starts without hanging. I ran Spybot (it fixed some adclick or so entries) and a clean Malware bytes anti malware too.I'm runing a Avast antivirus scan too…but it seems to take forever it is so slow. I'd be grateful for any help. I have a Windows Vista (Home Premium) SP 2 Update: the antivirus scan came clean. CPU usage is showing 100% whether or not I open any apps.
:welcome:

Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Hi Thanks for the prompt response. I tried double clicking it many different times…but all it does is just open up the black screen, nothing else :( Am I doing anything wrong? There was something about disabling script blocking tools, whats a script blocking tool, how do I know if I have one and how do I disable it? Edit: I have the following installed: Malware bytes anti malware Spybot Avast anti virus Comodo firewall Spyware blaster Spyware guard
Good Morning,

I apologize but I missed getting notified when you replied.

Lets try this, I would try disabling all that you listed first then run this program first. Also with Vista you need to right click on DDS and select RUN AS ADMINISTRATOR

  • Please download rkill (Courtesy of Bleepingcomputer.com).
  • There are 5 different versions of this tool. If one of them will not run, please try the next one in the list.
  • Note: Vista and Windows 7 Users must right click and select "Run as Administrator" to run the tool.
  • Note: You only need to get one of the tools to run, not all of them.


1. rkill.exe
2. rkill.com
3. rkill.scr
4. WiNlOgOn.exe
5. uSeRiNiT.exe

Note: You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message.

Run rkill repeatedly until it's able to do it's job. This may take a few tries.

You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.




Then try DDS again, if still a no go then try this one



Scan With RootKitUnHooker

  • Please choose one link and download Rootkit Unhooker and save it to your desktop.
    Link 1
    Link 2
    Link 3
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"




See if you can run them both after running RKIll and post both logs
Hi Just a quick update: I did a system restore like 7-8 days back, and the problems did seem to have gone away, the computer became quite fast like its always been, but that lasted only a few days. I feel the computer slowing down by each passing day and now it become as slow as in the beginning of the thread.Another wierd thing is the simltaneous left clicks…the left mouse button is clicking 5-6 times of it own accord opening/closing many windows. How do I disable all (the things that I listed)? Do I remove (uninstall) them? I only know how to disable Comodo firewall.
__________ rkill log: __________ This log file is located at C:\rkill.log. Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish. Rkill was run on 03/22/2011 at 10:50:19. Operating System: Windows Vista ™ Home Premium Processes terminated by Rkill or while it was running: Rkill completed on 03/22/2011 at 10:50:37. ****************************************************************** DDS.txt _________ . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 10:55:57.20 on Tue 03/22/2011 Internet Explorer: 8.0.6001.19019 BrowserJavaVersion: 1.6.0_22 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3061.1366 [GMT -5:00] . AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA- 47DAD597F308} SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A- 7CA8AE10B9B5} SP: COMODO Defense+ *Enabled/Updated* {DC3D0F8D-B138-AAAA-0339- 560EB3387C28} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44- DA132C1ACF46} FW: COMODO Firewall *Enabled* {5F676F4C-DD6D-A47C-12D6- C449366C71EE} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\Microsoft.Net\Framework\v3.0 \WPF\PresentationFontCache.exe C:\Windows\system32\svchost.exe -k rpcss C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\agrsmsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\system32\taskeng.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe C:\Toshiba\IVP\ISM\pinger.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Windows\system32\svchost.exe -k imgsvc c:\Toshiba\IVP\swupdate\swupdtmr.exe C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Windows\system32\UTSCSI.EXE C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Toshiba\Power Saver\TPwrMain.exe C:\Program Files\Toshiba\SmoothView\SmoothView.exe C:\Program Files\Toshiba\FlashCards\TCrdMain.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Toshiba\ConfigFree\NDSTray.exe C:\Program Files\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe C:\Program Files\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Windows\System32\wpcumi.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe C:\Windows\System32\notepad.exe C:\Program Files\Cisco Systems\VPN Client\ipseclog.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe c:\program files\windows defender\MpCmdRun.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\explorer.exe C:\Windows\system32\notepad.exe C:\Windows\system32\ctfmon.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\explorer.exe C:\Users\AdilSabah\Desktop\wtt forums\dds.scr C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank uDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart uWindow Title = Sabah's Internet Explorer mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d- 784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrec ordplugin.dll BHO: BHOManager Class: {474264bc-9571-47c1-85b9-780f756dc9ce} - c:\windows\system32\BHOManager.dll BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5 -0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644- 206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc- 5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa- ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22- 42b3008e02ff} - c:\progra~1\mi1933~1\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74- 9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [TOSCDSPD] TOSCDSPD.EXE uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [Google Update] "c:\users\adilsabah\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe" uRun: [cdloader] "c:\users\adilsabah\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK uRunOnce: [FlashPlayerUpdate] c:\windows\system32 \macromed\flash\FlashUtil10k_Plugin.exe -update plugin mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe mRun: [SmoothView] %ProgramFiles% \Toshiba\SmoothView\SmoothView.exe mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [NDSTray.exe] NDSTray.exe mRun: [PCMAgent] "c:\program files\cyberlink\powercinema for toshiba\PCMAgent.exe" mRun: [CLMLServer] "c:\program files\cyberlink\powercinema for toshiba\kernel\clml\CLMLSvc.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [avast5] "c:\program files\alwil software\avast5 \avastUI.exe" /nogui mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" - atboottime mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" dRun: [Picasa Media Detector] c:\program files\picasa2 \PicasaMediaDetector.exe StartupFolder: c:\users\adilsa~1\appdata\roaming\micros~1 \windows\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1 \programs\startup\vpncli~1.lnk - c:\windows\installer\{ccbaa1f7- e5e1-48b2-9ed9-a79c6a37ce78}\Icon3E5562ED7.ico mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) dPolicies-explorer: EnableShellExecuteHooks = 1 (0x1) IE: Add to Google Photos Screensa&ver; - c:\windows\system32 \GPhotos.scr/200 IE: E&xport; to Microsoft Excel - c:\progra~1\mi1933~1\office14 \EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll /cmsidewiki.html IE: Se&nd; to OneNote - c:\progra~1\mi1933~1\office14 \ONBttnIE.dll/105 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5- 98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330- 914C-F5F514E3486C} - c:\program files\microsoft office\office14 \ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6- AB38-5D6374584B52} - c:\program files\microsoft office\office14 \ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B- 8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53- 2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll LSP: c:\windows\system32\wpclsp.dll Trusted Zone: magicjack.com\my Trusted Zone: netflix.com\www Trusted Zone: talk4free.com\reg DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - hxxp://www.kaspersky.nl/scanforvirus-en/kavwebscan_unicode.cab DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.com/s/v/56.25/uploader2.cab DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://picasaweb.google.com/s/v/54.16/uploader2.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUplden-us.cab DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/EN-IN/a-UNO1/GAME_UNO1.cab DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} - hxxps://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCt rl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows- i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear /ultrashim.cab DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} - hxxp://www.idesitv.com/livetv.ocx DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab569 07.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows- i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows- i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows- i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows- i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab TCP: {98098E6A-0CE9-43A8-892C-28940937E7FA} = 156.154.70.22,156.154.71.22 TCP: {C26356AB-0B17-4DD2-B7F7-24F7CE13D609} = 156.154.70.22,156.154.71.22 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14 \MSOXMLMF.DLL Handler: HTLFP - {03B7A5D4-96B0-4316-95F8-072D326A58F1} - Handler: skype-ie-addon-data - {91774881-D725-4E58-B298- 07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: vfsp - {E4CB5121-E242-11D4-8ED6-00010219EB22} - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~1\goec62~1.dll c:\windows\system32\guard32.dll SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll SEH: ShHook Class: {a5949e07-8536-4625-a3d0-2dd83f559990} - c:\windows\system32\ShellHook.dll Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\users\adilsa~1 \appdata\roaming\mozilla\firefox\profiles\kf2i0fbv.laddu\ FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\com ponents\nprpffbrowserrecordext.dll FF - plugin: c:\progra~1\mi1933~1\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\mi1933~1\office14\NPSPWRAP.DLL FF - plugin: c:\program files\google\update\1.2.183.39 \npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6 \bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft\web platform installer\NPWPIDetector.dll FF - plugin: c:\program files\picasa2\npPicasa3.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\ nprphtml5videoshim.dll FF - plugin: c:\users\adilsabah\appdata\local\google\update\1.2.183.39 \npGoogleOneClick8.dll FF - plugin: c:\users\adilsabah\appdata\roaming\mozilla\plugins\npgoogletalk.dl l FF - plugin: c:\users\adilsabah\appdata\roaming\mozilla\plugins\npgtpo3dautoplu gin.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474- a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000- 0006-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000- 0007-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000- 0011-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000- 0020-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000- 0022-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed -80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5 \windows presentation foundation\DotNetAssistantExtension FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b- 88E6-365A6E755758} - c:\programdata\real\realplayer\browserrecordplugin\firefox\Ext FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed -80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed- 80e3-08825760534b} . ============= SERVICES / DRIVERS =============== . R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2008-6-26 294608] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-9-11 236600] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-9-11 34744] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-6-26 17744] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2008-6-26 51280] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-10-31 40384] R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2007-12-25 40960] R2 FontCache;Windows Font Cache Service;c:\windows\system32 \svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 paldrv;paldrv;c:\windows\system32\pal_drv.sys [2010-4-17 11107] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-6-26 1153368] R2 TeamViewer5;TeamViewer 5;c:\program files\teamviewer\version5 \TeamViewer_Service.exe [2010-3-18 172328] R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\toshiba\smartlogservice\TosIPCSrv.exe [2007-12-3 126976] R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008 -2-12 7168] R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32 \drivers\teamviewervpn.sys [2010-3-11 25088] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319 \mscorsvw.exe [2010-3-18 130384] S2 gupdate1c9dfab9a16ffd0;Google Update Service (gupdate1c9dfab9a16ffd0);c:\program files\google\update\GoogleUpdate.exe [2009-5-28 133104] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-2-12 30192] S3 McComponentHostService;McAfee Security Scan Component Host Service;"c:\program files\mcafee security scan\2.0.181 \mcchsvc.exe" –> c:\program files\mcafee security scan\2.0.181 \McCHSvc.exe [?] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319 \wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 AutoSyncService;Memeo AutoSync ;c:\program files\memeo\autosync\MemeoService.exe [2007-7-6 31768] . =============== Created Last 30 ================ . 2011-03-22 15:24:22 5943120 —-a-w- c:\progra~2 \microsoft\windows defender\definition updates\{f432af65-fca3- 465a-aee5-dff8b3ee82c1}\mpengine.dll 2011-03-12 03:49:11 429056 —-a-w- c:\windows\system32\EncDec.dll 2011-03-12 03:49:11 322560 —-a-w- c:\windows\system32\sbe.dll 2011-03-12 03:49:11 177664 —-a-w- c:\windows\system32\mpg2splt.ax 2011-03-12 03:49:11 153088 —-a-w- c:\windows\system32\sbeio.dll 2011-03-12 03:48:49 677888 —-a-w- c:\windows\system32\mstsc.exe 2011-03-12 03:48:49 2067968 —-a-w- c:\windows\system32\mstscax.dll 2011-02-23 17:26:55 ——– d—–w- c:\users\adilsa~1\appdata\local\Microsoft Games . ==================== Find3M ==================== . 2011-02-15 18:33:54 285480 —-a-w- c:\windows\system32\guard32.dll 2011-02-02 23:11:20 222080 ——w- c:\windows\system32\MpSigStub.exe 2011-01-20 16:08:16 478720 —-a-w- c:\windows\system32\dxgi.dll 2011-01-20 16:08:06 219648 —-a-w- c:\windows\system32\d3d10_1core.dll 2011-01-20 16:08:06 189952 —-a-w- c:\windows\system32\d3d10core.dll 2011-01-20 16:08:06 160768 —-a-w- c:\windows\system32\d3d10_1.dll 2011-01-20 16:08:06 1029120 —-a-w- c:\windows\system32\d3d10.dll 2011-01-20 16:07:58 37376 —-a-w- c:\windows\system32\cdd.dll 2011-01-20 16:07:42 258048 —-a-w- c:\windows\system32\winspool.drv 2011-01-20 16:07:16 586240 —-a-w- c:\windows\system32\stobject.dll 2011-01-20 16:06:38 2873344 —-a-w- c:\windows\system32\mf.dll 2011-01-20 16:06:35 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll 2011-01-20 16:04:54 98816 —-a-w- c:\windows\system32\mfps.dll 2011-01-20 16:04:54 209920 —-a-w- c:\windows\system32\mfplat.dll 2011-01-20 14:28:38 1554432 —-a-w- c:\windows\system32\xpsservices.dll 2011-01-20 14:27:50 876032 —-a-w- c:\windows\system32\XpsPrint.dll 2011-01-20 14:26:30 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe 2011-01-20 14:25:25 847360 —-a-w- c:\windows\system32\OpcServices.dll 2011-01-20 14:24:32 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-01-20 14:24:26 135680 —-a-w- c:\windows\system32\XpsRasterService.dll 2011-01-20 14:15:10 979456 —-a-w- c:\windows\system32\MFH264Dec.dll 2011-01-20 14:14:39 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll 2011-01-20 14:14:03 302592 —-a-w- c:\windows\system32\mfmp4src.dll 2011-01-20 14:14:03 261632 —-a-w- c:\windows\system32\mfreadwrite.dll 2011-01-20 14:12:46 1172480 —-a-w- c:\windows\system32\d3d10warp.dll 2011-01-20 14:11:34 486400 —-a-w- c:\windows\system32\d3d10level9.dll 2011-01-20 13:47:51 683008 —-a-w- c:\windows\system32\d2d1.dll 2011-01-20 13:44:05 1068544 —-a-w- c:\windows\system32\DWrite.dll 2011-01-20 13:44:03 797184 —-a-w- c:\windows\system32\FntCache.dll 2011-01-13 08:47:35 38848 —-a-w- c:\windows\avastSS.scr 2011-01-08 08:47:50 34304 —-a-w- c:\windows\system32\atmlib.dll 2011-01-08 06:28:49 292352 —-a-w- c:\windows\system32\atmfd.dll 2010-12-31 13:57:01 2039808 —-a-w- c:\windows\system32\win32k.sys 2010-12-31 01:26:37 6275960 -c–a-w- c:\program files\Silverlight.exe 2010-12-28 15:55:03 413696 —-a-w- c:\windows\system32\odbc32.dll 2008-05-31 03:16:51 13288968 -c–a-w- c:\program files\RealPlayer11GOLD.exe . ============= FINISH: 10:58:00.12 =============== ************************************************************************* rootkitunhooker report: ___________________ RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows Vista Version 6.0.6002 (Service Pack 2) Number of processors #2 ============================================== >Drivers ============================================== 0x8F40E000 C:\Windows\system32\DRIVERS\igdkmd32.sys 6516736 bytes (Intel Corporation, Intel Graphics Kernel Mode Driver) 0x82E02000 C:\Windows\system32\ntkrnlpa.exe 3907584 bytes (Microsoft Corporation, NT Kernel & System) 0x82E02000 PnpManager 3907584 bytes 0x82E02000 RAW 3907584 bytes 0x82E02000 WMIxWDM 3907584 bytes 0x8FE0D000 C:\Windows\system32\DRIVERS\NETw4v32.sys 2289664 bytes (Intel Corporation, Intel® Wireless WiFi Link Driver) 0x9B030000 Win32k 2109440 bytes 0x9B030000 C:\Windows\System32\win32k.sys 2109440 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0x90600000 C:\Windows\system32\drivers\RTKVHDA.sys 2052096 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver) 0x90800000 C:\Windows\system32\DRIVERS\AGRSM.sys 1163264 bytes (Agere Systems, SoftModem Device Driver) 0x8B807000 C:\Windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, NT File System Driver) 0x8B477000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver) 0x80694000 PCI_PNP3389 1048576 bytes 0x80694000 C:\Windows\System32\Drivers\spku.sys 1048576 bytes 0x80694000 sptd 1048576 bytes 0x8B607000 C:\Windows\System32\drivers\tcpip.sys 958464 bytes (Microsoft Corporation, TCP/IP Driver) 0x804E0000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module) 0xB4003000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver) 0x8F200000 C:\Windows\System32\Drivers\dump_iaStor.sys 819200 bytes 0x8B313000 C:\Windows\system32\DRIVERS\iaStor.sys 819200 bytes (Intel Corporation, Intel Matrix Storage Manager driver - ia32) 0xAEE0D000 C:\Windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor) 0x8FA45000 C:\Windows\System32\drivers\dxgkrnl.sys 655360 bytes (Microsoft Corporation, DirectX Graphics Kernel) 0xB20EB000 C:\Windows\system32\Drivers\CVPNDRVA.sys 589824 bytes (Cisco Systems, Inc., Cisco Systems VPN Client IPSec Driver) 0x8FB49000 C:\Windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver) 0x8060B000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic) 0x8B406000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0x80416000 C:\Windows\system32\mcupdate_GenuineIntel.dll 458752 bytes (Microsoft Corporation, Intel Microcode Update Library) 0xAEF14000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack) 0x90097000 C:\Windows\system32\DRIVERS\rixdptsk.sys 331776 bytes (REDC, RICOH XD SM Driver) 0xB2099000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver) 0x8B955000 C:\Windows\system32\DRIVERS\tos_sps32.sys 307200 bytes (TOSHIBA Corporation, tos_sps2) 0x8B2A4000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver) 0x90C00000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x90D32000 C:\Windows\System32\Drivers\aswSP.SYS 290816 bytes (AVAST Software, avast! self protection module) 0x8B204000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT) 0x8049F000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver) 0x8F2F9000 C:\Windows\system32\DRIVERS\Rtlh86.sys 266240 bytes (Realtek , Realtek 8136/8168/8169 NDIS6 32-bit Driver ) 0x901BC000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver) 0x8FAFC000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0x90929000 C:\Windows\System32\DRIVERS\cmdguard.sys 249856 bytes (COMODO, COMODO Internet Security Sandbox Driver) 0x90CD5000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0x8B5AD000 C:\Windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem) 0xB2020000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr) 0x8B917000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0x90DBA000 C:\Windows\system32\drivers\aswMonFlt.sys 225280 bytes (AVAST Software, avast! File System Minifilter for Windows 2003/Vista) 0x8B73A000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB) 0x831BC000 ACPI_HAL 208896 bytes 0x831BC000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0x805C0000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0x90C4D000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver) 0x90106000 C:\Windows\system32\DRIVERS\SynTP.sys 196608 bytes (Synaptics, Inc., Synaptics Touchpad Driver) 0x9018D000 C:\Windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver) 0x8B76F000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0x8B582000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider) 0x8F3A5000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library) 0xAEECD000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver) 0xB4170000 C:\Windows\System32\Drivers\fastfat.SYS 163840 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xB2071000 C:\Windows\System32\DRIVERS\srv2.sys 163840 bytes (Microsoft Corporation, Smb 2.0 Server driver) 0x8B9B7000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache) 0x8B252000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0x8079D000 C:\Windows\System32\Drivers\SCSIPORT.SYS 155648 bytes (Microsoft Corporation, SCSI Port Driver) 0x8B79C000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0x8F33A000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0x8B70C000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll) 0xAEFCC000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0x9098B000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver) 0xB2001000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0x807C3000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension) 0x9016F000 C:\Windows\system32\DRIVERS\dne2000.sys 122880 bytes (Deterministic Networks, Inc., Deterministic Network Enhancer) 0xAEF81000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver) 0x8B6F1000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API) 0x90D9F000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver) 0x9005A000 C:\Windows\system32\DRIVERS\sdbus.sys 106496 bytes (Microsoft Corporation, SecureDigital Bus Driver) 0xAEF9E000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver) 0x90147000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xB2059000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector) 0x90D1B000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver) 0x8FBD6000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xB40FC000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver) 0x90C9E000 C:\Windows\system32\DRIVERS\inspect.sys 90112 bytes (COMODO, COMODO Internet Security Firewall Driver) 0x90C88000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler) 0x909DE000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver) 0xAEFB7000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver) 0x8F380000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager) 0x8F36C000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0x90083000 C:\Windows\system32\DRIVERS\rimsptsk.sys 81920 bytes (REDC, RICOH MS Driver) 0x8B5E8000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver) 0x900E8000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042 Port Driver) 0xAEF01000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6) 0x90CC2000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0x8B9DE000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver) 0x8F3E7000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy) 0x80486000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver) 0x8B3ED000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver) 0xAEEBD000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver) 0x8B303000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager) 0x9003C000 C:\Windows\system32\DRIVERS\ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver) 0x8F395000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver) 0x9015F000 C:\Windows\System32\Drivers\tosrfcom.sys 65536 bytes (TOSHIBA Corporation, Bluetooth RFCOMM Driver) 0x8F2E6000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver) 0x90D90000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver) 0x8B9A8000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0x8B279000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver) 0x8F35D000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0x90074000 C:\Windows\system32\DRIVERS\rimmptsk.sys 61440 bytes (REDC, RICOH SD Driver) 0x8FB3A000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0x8B295000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver) 0x9004C000 C:\Windows\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver) 0x9B300000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver) 0x90CB4000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver) 0x909C7000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver) 0x8B2F5000 C:\Windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0x90D79000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver) 0x9091C000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver) 0x8F3CF000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator) 0x80687000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR) 0xB40EB000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver) 0x9097F000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0x8FAE5000 C:\Windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver) 0x907F5000 C:\Windows\System32\DRIVERS\cmdhlp.sys 45056 bytes (COMODO, COMODO Internet Security Helper Driver) 0x900FB000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver) 0x90138000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver) 0x909BC000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver) 0x8FBED000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0x8FE00000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper) 0x8F3DC000 C:\Windows\system32\DRIVERS\tosporte.sys 45056 bytes (TOSHIBA Corporation, TOSHIBA Bluetooth Port Emulation Driver) 0x8FAF1000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0x8F2CA000 C:\Windows\System32\Drivers\aswTdi.SYS 40960 bytes (AVAST Software, avast! TDI Filter Driver) 0x8B28B000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver) 0x90D86000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver) 0x8B3E3000 C:\Windows\system32\drivers\msahci.sys 40960 bytes (Microsoft Corporation, MS AHCI 1.0 Standard Driver) 0x8F400000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver) 0xAEEF7000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver) 0x90D11000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy) 0x807E1000 C:\Windows\System32\Drivers\PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP) 0xB40E1000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0xB4198000 C:\Windows\system32\DRIVERS\asyncmac.sys 36864 bytes (Microsoft Corporation, MS Remote Access serial network driver) 0x8B9EF000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver) 0x90968000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver) 0xB41CB000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0x909D5000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0x9B250000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver) 0x8F2D5000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0x80794000 C:\Windows\System32\Drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0x90C7F000 C:\Windows\system32\drivers\ws2ifsl.sys 36864 bytes (Microsoft Corporation, Winsock2 IFS Layer) 0x8B3DB000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver) 0x80497000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver) 0x8F2DE000 C:\Windows\system32\DRIVERS\FwLnk.sys 32768 bytes (TOSHIBA Corporation, TOSHIBA Firmware Linkage 32-bit Driver) 0x8B24A000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver) 0x909AC000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x909B4000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0x8B9A0000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor) 0x90978000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver) 0xB4169000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0x8B2EE000 C:\Windows\system32\drivers\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver) 0x8040F000 C:\Windows\system32\kdcom.dll 28672 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xB41C4000 C:\Users\ADILSA~1\AppData\Local\Temp\mbr.sys 28672 bytes 0x90971000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver) 0x8FBF8000 C:\Windows\system32\DRIVERS\teamviewervpn.sys 28672 bytes (TeamViewer GmbH, TeamViewerVPN Network Adapter) 0x90C48000 C:\Windows\System32\Drivers\aswRdr.SYS 20480 bytes (AVAST Software, avast! TDI RDR Driver) 0xB40F7000 C:\Windows\system32\DRIVERS\LVPr2Mon.sys 20480 bytes (-, -) 0x8B950000 C:\Windows\system32\DRIVERS\TVALZ_O.SYS 20480 bytes (TOSHIBA Corporation, TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver) 0xB20E7000 C:\Windows\System32\Drivers\Aspi32.SYS 16384 bytes (Adaptec, ASPI for WIN32 Kernel Driver) 0x8F2F5000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver) 0x90143000 C:\Windows\system32\DRIVERS\tdcmdpst.sys 16384 bytes (TOSHIBA Corporation., Toshiba ODD Writing Driver For x86.) 0x90DF1000 C:\Windows\System32\Drivers\aswFsBlk.SYS 12288 bytes (AVAST Software, avast! File System Access Blocking Driver) 0x8B288000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver) 0xB217B000 C:\Windows\system32\pal_drv.sys 12288 bytes (Mercury Interactive Corp., Astra) 0x8FE0B000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0x90136000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0x865171F8 unknown_irp_handler 3592 bytes 0xD7ACB1F8 unknown_irp_handler 3592 bytes 0x865151F8 unknown_irp_handler 3592 bytes 0x87F7C1F8 unknown_irp_handler 3592 bytes 0x89ED51F8 unknown_irp_handler 3592 bytes 0x89F091F8 unknown_irp_handler 3592 bytes 0x8807C1F8 unknown_irp_handler 3592 bytes 0x865121F8 unknown_irp_handler 3592 bytes 0x87EC51F8 unknown_irp_handler 3592 bytes 0x865161F8 unknown_irp_handler 3592 bytes 0x87EEF1F8 unknown_irp_handler 3592 bytes 0x87ECD500 unknown_irp_handler 2816 bytes 0x85E7D500 unknown_irp_handler 2816 bytes ============================================== >Stealth ============================================== WARNING: File locked for read access [C:\Windows\system32\drivers\sptd.sys] 0xB41DA130 Unknown thread object [ ETHREAD 0xDE4A7730 ] , 600 bytes 0x909F5130 Unknown thread object [ ETHREAD 0x89F95020 ] , 600 bytes 0xB412A130 Unknown thread object [ ETHREAD 0x87F00688 ] , 600 bytes 0xB41DA130 Unknown thread object [ ETHREAD 0x8A22E9A0 ] , 600 bytes 0xB41A2130 Unknown thread object [ ETHREAD 0x85D35470 ] , 600 bytes 0xB41DA130 Unknown thread object [ ETHREAD 0x8A29FAC0 ] , 600 bytes 0xB41DA130 Unknown thread object [ ETHREAD 0x81371CA0 ] , 600 bytes 0xB4154130 Unknown thread object [ ETHREAD 0x85F3A5B8 ] , 600 bytes 0xB4113130 Unknown thread object [ ETHREAD 0xAF4C2290 ] , 600 bytes 0xB41DA130 Unknown thread object [ ETHREAD 0xD7A17A90 ] , 600 bytes 0xF41E1130 Unknown thread object [ ETHREAD 0xE18CBAC0 ] , 600 bytes 0xB414B130 Unknown thread object [ ETHREAD 0x8214A290 ] , 600 bytes 0xB41DA130 Unknown thread object [ ETHREAD 0x85FD45F0 ] , 600 bytes 0xB41DA130 Unknown thread object [ ETHREAD 0x85E8F3B8 ] , 600 bytes 0xF41B7130 Unknown thread object [ ETHREAD 0x925A23F8 ] , 600 bytes 0xF4130130 Unknown thread object [ ETHREAD 0x925DB370 ] , 600 bytes 0xB414B130 Unknown thread object [ ETHREAD 0xDE4472C0 ] , 600 bytes 0xB41B9130 Unknown thread object [ ETHREAD 0x82809020 ] , 600 bytes 0xB414B130 Unknown thread object [ ETHREAD 0x86487AA8 ] , 600 bytes 0xB41E3130 Unknown thread object [ ETHREAD 0x8A2AA020 ] , 600 bytes 0xB415F130 Unknown thread object [ ETHREAD 0xAFFE4D78 ] , 600 bytes 0xF4139130 Unknown thread object [ ETHREAD 0x94067D78 ] , 600 bytes 0xB41DA130 Unknown thread object [ ETHREAD 0x860950F0 ] , 600 bytes 0xB41DA130 Unknown thread object [ ETHREAD 0x924CBD78 ] , 600 bytes 0xB41F1130 Unknown thread object [ ETHREAD 0x92B682E8 ] , 600 bytes 0xF4102130 Unknown thread object [ ETHREAD 0x9256CB08 ] , 600 bytes 0xB414B130 Unknown thread object [ ETHREAD 0x874C4858 ] , 600 bytes 0xB41AB130 Unknown thread object [ ETHREAD 0x81C11B08 ] , 600 bytes 0xB414B130 Unknown thread object [ ETHREAD 0x81C22290 ] , 600 bytes 0xF4163130 Unknown thread object [ ETHREAD 0x92AD0480 ] , 600 bytes 0xDF6E9130 Unknown thread object [ ETHREAD 0xAC9CD170 ] , 600 bytes 0xB414B130 Unknown thread object [ ETHREAD 0xD8A0BD78 ] , 600 bytes 0xF415A130 Unknown thread object [ ETHREAD 0x940585C8 ] , 600 bytes 0xB41BE130 Unknown thread object [ ETHREAD 0x8213A898 ] , 600 bytes 0xB41DA130 Unknown thread object [ ETHREAD 0x925DE298 ] , 600 bytes 0xB41D5130 Unknown thread object [ ETHREAD 0x875CC910 ] , 600 bytes 0xF410F130 Unknown thread object [ ETHREAD 0x8AF97930 ] , 600 bytes 0xB414B130 Unknown thread object [ ETHREAD 0x92AA22B8 ] , 600 bytes 0xF40E1130 Unknown thread object [ ETHREAD 0xF4820D78 ] , 600 bytes 0xB414B130 Unknown thread object [ ETHREAD 0x92BFF820 ] , 600 bytes 0xB414B130 Unknown thread object [ ETHREAD 0xBC98A278 ] , 600 bytes 0xB41A2130 Unknown thread object [ ETHREAD 0x8F18ED78 ] , 600 bytes 0xB414B130 Unknown thread object [ ETHREAD 0x8A39C020 ] , 600 bytes 0xB41E3130 Unknown thread object [ ETHREAD 0xCD6A72C8 ] , 600 bytes 0xB414B130 Unknown thread object [ ETHREAD 0xC4AF03F8 ] , 600 bytes 0xB414B130 Unknown thread object [ ETHREAD 0xDD247298 ] , 600 bytes 0xF418D130 Unknown thread object [ ETHREAD 0x94119A90 ] , 600 bytes

Attachments:

Hi,

Cant read your DDS log the way you posted it, do this please

Rerun the program and when it opens in Notepad > Go to Format and make sure Wordwrap is Unchecked
Hi Sorry about the DDS! I hope you find this clear . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 13:14:14.86 on Tue 03/22/2011 Internet Explorer: 8.0.6001.19019 BrowserJavaVersion: 1.6.0_22 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3061.1445 [GMT -5:00] . AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308} SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5} SP: COMODO Defense+ *Enabled/Updated* {DC3D0F8D-B138-AAAA-0339-560EB3387C28} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: COMODO Firewall *Enabled* {5F676F4C-DD6D-A47C-12D6-C449366C71EE} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\svchost.exe -k rpcss C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\agrsmsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\system32\taskeng.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe C:\Toshiba\IVP\ISM\pinger.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Windows\system32\svchost.exe -k imgsvc c:\Toshiba\IVP\swupdate\swupdtmr.exe C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Windows\system32\UTSCSI.EXE C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Toshiba\Power Saver\TPwrMain.exe C:\Program Files\Toshiba\SmoothView\SmoothView.exe C:\Program Files\Toshiba\FlashCards\TCrdMain.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Toshiba\ConfigFree\NDSTray.exe C:\Program Files\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe C:\Program Files\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Windows\System32\wpcumi.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe C:\Program Files\COMODO\COMODO Internet Security\cfpupdat.exe C:\Windows\System32\notepad.exe C:\Program Files\Cisco Systems\VPN Client\ipseclog.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\explorer.exe C:\Windows\System32\mobsync.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\ctfmon.exe C:\Users\AdilSabah\Desktop\wtt forums\dds.scr C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank uDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart uWindow Title = Sabah's Internet Explorer mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: BHOManager Class: {474264bc-9571-47c1-85b9-780f756dc9ce} - c:\windows\system32\BHOManager.dll BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mi1933~1\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [TOSCDSPD] TOSCDSPD.EXE uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [Google Update] "c:\users\adilsabah\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe" uRun: [cdloader] "c:\users\adilsabah\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10k_Plugin.exe -update plugin mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [NDSTray.exe] NDSTray.exe mRun: [PCMAgent] "c:\program files\cyberlink\powercinema for toshiba\PCMAgent.exe" mRun: [CLMLServer] "c:\program files\cyberlink\powercinema for toshiba\kernel\clml\CLMLSvc.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" dRun: [Picasa Media Detector] c:\program files\picasa2\PicasaMediaDetector.exe StartupFolder: c:\users\adilsa~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{ccbaa1f7-e5e1-48b2-9ed9-a79c6a37ce78}\Icon3E5562ED7.ico mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) dPolicies-explorer: EnableShellExecuteHooks = 1 (0x1) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office14\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html IE: Se&nd to OneNote - c:\progra~1\mi1933~1\office14\ONBttnIE.dll/105 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll LSP: c:\windows\system32\wpclsp.dll Trusted Zone: magicjack.com\my Trusted Zone: netflix.com\www Trusted Zone: talk4free.com\reg DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - hxxp://www.kaspersky.nl/scanforvirus-en/kavwebscan_unicode.cab DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.com/s/v/56.25/uploader2.cab DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://picasaweb.google.com/s/v/54.16/uploader2.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUplden-us.cab DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/EN-IN/a-UNO1/GAME_UNO1.cab DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} - hxxps://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} - hxxp://www.idesitv.com/livetv.ocx DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab TCP: {98098E6A-0CE9-43A8-892C-28940937E7FA} = 156.154.70.22,156.154.71.22 TCP: {C26356AB-0B17-4DD2-B7F7-24F7CE13D609} = 156.154.70.22,156.154.71.22 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: HTLFP - {03B7A5D4-96B0-4316-95F8-072D326A58F1} - Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: vfsp - {E4CB5121-E242-11D4-8ED6-00010219EB22} - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~1\goec62~1.dll c:\windows\system32\guard32.dll SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll SEH: ShHook Class: {a5949e07-8536-4625-a3d0-2dd83f559990} - c:\windows\system32\ShellHook.dll Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\users\adilsa~1\appdata\roaming\mozilla\firefox\profiles\kf2i0fbv.laddu\ FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll FF - plugin: c:\progra~1\mi1933~1\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\mi1933~1\office14\NPSPWRAP.DLL FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft\web platform installer\NPWPIDetector.dll FF - plugin: c:\program files\picasa2\npPicasa3.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - plugin: c:\users\adilsabah\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\users\adilsabah\appdata\roaming\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\users\adilsabah\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\real\realplayer\browserrecordplugin\firefox\Ext FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . ============= SERVICES / DRIVERS =============== . R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2008-6-26 294608] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-9-11 236600] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-9-11 34744] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-6-26 17744] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2008-6-26 51280] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-10-31 40384] R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2007-12-25 40960] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 paldrv;paldrv;c:\windows\system32\pal_drv.sys [2010-4-17 11107] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-6-26 1153368] R2 TeamViewer5;TeamViewer 5;c:\program files\teamviewer\version5\TeamViewer_Service.exe [2010-3-18 172328] R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\toshiba\smartlogservice\TosIPCSrv.exe [2007-12-3 126976] R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008-2-12 7168] R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [2010-3-11 25088] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate1c9dfab9a16ffd0;Google Update Service (gupdate1c9dfab9a16ffd0);c:\program files\google\update\GoogleUpdate.exe [2009-5-28 133104] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-2-12 30192] S3 McComponentHostService;McAfee Security Scan Component Host Service;"c:\program files\mcafee security scan\2.0.181\mcchsvc.exe" –> c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [?] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 AutoSyncService;Memeo AutoSync ;c:\program files\memeo\autosync\MemeoService.exe [2007-7-6 31768] . =============== Created Last 30 ================ . 2011-03-22 15:24:22 5943120 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{f432af65-fca3-465a-aee5-dff8b3ee82c1}\mpengine.dll 2011-03-12 03:49:11 429056 —-a-w- c:\windows\system32\EncDec.dll 2011-03-12 03:49:11 322560 —-a-w- c:\windows\system32\sbe.dll 2011-03-12 03:49:11 177664 —-a-w- c:\windows\system32\mpg2splt.ax 2011-03-12 03:49:11 153088 —-a-w- c:\windows\system32\sbeio.dll 2011-03-12 03:48:49 677888 —-a-w- c:\windows\system32\mstsc.exe 2011-03-12 03:48:49 2067968 —-a-w- c:\windows\system32\mstscax.dll 2011-02-23 17:26:55 ——– d—–w- c:\users\adilsa~1\appdata\local\Microsoft Games . ==================== Find3M ==================== . 2011-02-15 18:33:54 285480 —-a-w- c:\windows\system32\guard32.dll 2011-02-02 23:11:20 222080 ——w- c:\windows\system32\MpSigStub.exe 2011-01-20 16:08:16 478720 —-a-w- c:\windows\system32\dxgi.dll 2011-01-20 16:08:06 219648 —-a-w- c:\windows\system32\d3d10_1core.dll 2011-01-20 16:08:06 189952 —-a-w- c:\windows\system32\d3d10core.dll 2011-01-20 16:08:06 160768 —-a-w- c:\windows\system32\d3d10_1.dll 2011-01-20 16:08:06 1029120 —-a-w- c:\windows\system32\d3d10.dll 2011-01-20 16:07:58 37376 —-a-w- c:\windows\system32\cdd.dll 2011-01-20 16:07:42 258048 —-a-w- c:\windows\system32\winspool.drv 2011-01-20 16:07:16 586240 —-a-w- c:\windows\system32\stobject.dll 2011-01-20 16:06:38 2873344 —-a-w- c:\windows\system32\mf.dll 2011-01-20 16:06:35 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll 2011-01-20 16:04:54 98816 —-a-w- c:\windows\system32\mfps.dll 2011-01-20 16:04:54 209920 —-a-w- c:\windows\system32\mfplat.dll 2011-01-20 14:28:38 1554432 —-a-w- c:\windows\system32\xpsservices.dll 2011-01-20 14:27:50 876032 —-a-w- c:\windows\system32\XpsPrint.dll 2011-01-20 14:26:30 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe 2011-01-20 14:25:25 847360 —-a-w- c:\windows\system32\OpcServices.dll 2011-01-20 14:24:32 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-01-20 14:24:26 135680 —-a-w- c:\windows\system32\XpsRasterService.dll 2011-01-20 14:15:10 979456 —-a-w- c:\windows\system32\MFH264Dec.dll 2011-01-20 14:14:39 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll 2011-01-20 14:14:03 302592 —-a-w- c:\windows\system32\mfmp4src.dll 2011-01-20 14:14:03 261632 —-a-w- c:\windows\system32\mfreadwrite.dll 2011-01-20 14:12:46 1172480 —-a-w- c:\windows\system32\d3d10warp.dll 2011-01-20 14:11:34 486400 —-a-w- c:\windows\system32\d3d10level9.dll 2011-01-20 13:47:51 683008 —-a-w- c:\windows\system32\d2d1.dll 2011-01-20 13:44:05 1068544 —-a-w- c:\windows\system32\DWrite.dll 2011-01-20 13:44:03 797184 —-a-w- c:\windows\system32\FntCache.dll 2011-01-13 08:47:35 38848 —-a-w- c:\windows\avastSS.scr 2011-01-08 08:47:50 34304 —-a-w- c:\windows\system32\atmlib.dll 2011-01-08 06:28:49 292352 —-a-w- c:\windows\system32\atmfd.dll 2010-12-31 13:57:01 2039808 —-a-w- c:\windows\system32\win32k.sys 2010-12-31 01:26:37 6275960 -c–a-w- c:\program files\Silverlight.exe 2010-12-28 15:55:03 413696 —-a-w- c:\windows\system32\odbc32.dll 2008-05-31 03:16:51 13288968 -c–a-w- c:\program files\RealPlayer11GOLD.exe . ============= FINISH: 13:15:55.31 =============== Attached is the new attached zip too.

Attachments:

Hi,

Thank you for the new log, much better :)

I am not looking at anything malicious on your log. Read a bit about WinRunner and this program appears to cause some problems, if you dont use it why dont you try uninstalling it via Programs and Features in the Control Panel and see if it makes a difference.


Not convinced there isn't a rootkit afoot, run this quick scan please

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

[external image: Posted Image]
Click the "Scan" button to start scan


[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply
Hi
Now that you mention winrunner, I faintly remember that it probably could be there and went to uninstall it, but strange thing is I dint find it in Programs and Features. If you found it in the logs its got to be there in Programs and Features 0_o

Another weird thing is since yesterday Avast antivirus is issuing alerts of some site containing a Trojan but the only thing I did was open an email from someone which just contained text (the alerts stop if I close the page)…and then the weird mouse clicks.

Well just dont know what to make of it.

Speaking of the other scan, this is the log:

aswMBR version 0.9.4 Copyright© 2011 AVAST Software
Run date: 2011-03-23 09:39:18
—————————–
09:39:18.228 OS Version: Windows 6.0.6002 Service Pack 2
09:39:18.228 Number of processors: 2 586 0xF0D
09:39:18.230 ComputerName: ADILSABAH-PC UserName: AdilSabah
09:39:40.979 Initialize success
09:40:39.210 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
09:40:39.212 Disk 0 Vendor: TOSHIBA_ LB01 Size: 238475MB BusType: 3
09:40:39.228 Disk 0 MBR read error
09:40:39.232 Disk 0 MBR scan
09:40:39.236 MBR BIOS signature not found 0
09:40:39.243 Disk 0 scanning sectors +488395120
09:40:39.249 Disk 0 scanning C:\Windows\system32\drivers
09:40:51.841 Service scanning
09:40:56.547 Disk 0 trace - called modules:
09:40:56.620 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys spku.sys hal.dll >>UNKNOWN [0x864cb938]<<
09:40:56.626 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x876f6498]
09:40:56.635 3 CLASSPNP.SYS[8b7118b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x86596028]
09:40:56.640 Scan finished successfully



Greatly appreciate your help.
Lets see if we can find WinRunner

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    WinRunner
    :folderfind
    WinRunner
    :regfind
    WinRunner
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
This is the systemlook log:


SystemLook 04.09.10 by jpshortstuff
Log created at 11:47 on 23/03/2011 by AdilSabah
Administrator - Elevation successful

========== filefind ==========

Searching for "WinRunner"
No files found.

========== folderfind ==========

Searching for "WinRunner"
No folders found.

========== regfind ==========

Searching for "WinRunner"
[HKEY_CURRENT_USER\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest]
"GenTypeName"="WinRunner object"
[HKEY_CURRENT_USER\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"CallFunc#2"="Call the %a2 WinRunner function from the %a1 module."
[HKEY_CURRENT_USER\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"CallFunc#3+"="Call the %a2 WinRunner function from the %a1 module."
[HKEY_CURRENT_USER\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"CallFuncEx#4"="Call the %a2 WinRunner function from the %a1 module."
[HKEY_CURRENT_USER\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"CallFuncEx#5+"="Call the %a2 WinRunner function from the %a1 module."
[HKEY_CURRENT_USER\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"RunTest#2"="Run the %a1 WinRunner test."
[HKEY_CURRENT_USER\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"RunTest#3+"="Run the %a1 WinRunner test."
[HKEY_CURRENT_USER\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"RunTestEx#3"="Run the %a1 WinRunner test."
[HKEY_CURRENT_USER\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"RunTestEx#4+"="Run the %a1 WinRunner test."
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA4EB561-DA63-11d4-8F81-0050DA3B0421}]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA4EB563-DA63-11d4-8F81-0050DA3B0421}]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA4EB565-DA63-11d4-8F81-0050DA3B0421}]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA4EB567-DA63-11d4-8F81-0050DA3B0421}]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA4EB569-DA63-11d4-8F81-0050DA3B0421}]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Mercury.FPSpreadSupport]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Mercury.FPSpreadSupport.1]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Mercury.MSDBGridSupport]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Mercury.MSDBGridSupport.1]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Mercury.MSGridSupport]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Mercury.MSGridSupport.1]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Mercury.SDataGridSupport]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Mercury.SDataGridSupport.1]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Mercury.TDBGridSupport]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Mercury.TDBGridSupport.1]
@="WinRunner Table Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{DAB07E39-CC6F-11D0-8AE4-0080C8362177}\1.0]
@="WinRunner - VisualBasic Support"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest]
"GenTypeName"="WinRunner object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"CallFunc#2"="Call the %a2 WinRunner function from the %a1 module."
[HKEY_LOCAL_MACHINE\SOFTWARE\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"CallFunc#3+"="Call the %a2 WinRunner function from the %a1 module."
[HKEY_LOCAL_MACHINE\SOFTWARE\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"CallFuncEx#4"="Call the %a2 WinRunner function from the %a1 module."
[HKEY_LOCAL_MACHINE\SOFTWARE\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"CallFuncEx#5+"="Call the %a2 WinRunner function from the %a1 module."
[HKEY_LOCAL_MACHINE\SOFTWARE\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"RunTest#2"="Run the %a1 WinRunner test."
[HKEY_LOCAL_MACHINE\SOFTWARE\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"RunTest#3+"="Run the %a1 WinRunner test."
[HKEY_LOCAL_MACHINE\SOFTWARE\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"RunTestEx#3"="Run the %a1 WinRunner test."
[HKEY_LOCAL_MACHINE\SOFTWARE\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"RunTestEx#4+"="Run the %a1 WinRunner test."
[HKEY_USERS\S-1-5-21-2205181755-865499030-1282754365-1000\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest]
"GenTypeName"="WinRunner object"
[HKEY_USERS\S-1-5-21-2205181755-865499030-1282754365-1000\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"CallFunc#2"="Call the %a2 WinRunner function from the %a1 module."
[HKEY_USERS\S-1-5-21-2205181755-865499030-1282754365-1000\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"CallFunc#3+"="Call the %a2 WinRunner function from the %a1 module."
[HKEY_USERS\S-1-5-21-2205181755-865499030-1282754365-1000\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"CallFuncEx#4"="Call the %a2 WinRunner function from the %a1 module."
[HKEY_USERS\S-1-5-21-2205181755-865499030-1282754365-1000\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"CallFuncEx#5+"="Call the %a2 WinRunner function from the %a1 module."
[HKEY_USERS\S-1-5-21-2205181755-865499030-1282754365-1000\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"RunTest#2"="Run the %a1 WinRunner test."
[HKEY_USERS\S-1-5-21-2205181755-865499030-1282754365-1000\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"RunTest#3+"="Run the %a1 WinRunner test."
[HKEY_USERS\S-1-5-21-2205181755-865499030-1282754365-1000\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"RunTestEx#3"="Run the %a1 WinRunner test."
[HKEY_USERS\S-1-5-21-2205181755-865499030-1282754365-1000\Software\Mercury Interactive\QuickTest Professional\MicTest\SummaryData\Objects\TSLTest\Methods]
"RunTestEx#4+"="Run the %a1 WinRunner test."

-= EOF =-




I ran Spybot just before the systemlook, and here is the snapshot:

[external image: Posted Image]

Seems like there are quite a few spyware entries…I keep removing them everytime, but again they appear at the next scan.Is there a way to permanently get rid of them or knowing why they're infecting my system?
Thats a lot of registry entries that I need to look over. What Spybot found where just tracking cookies, there is a way of blocking them but I need to work on that for you too.

While I am doing that run this Free online virus scanner

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
Ok so I have a few things which I thought I'd let you know if it might matter. 1.My computer is set on auto updates so last night some updates were installed and it was restarted, later when I logged in, many (10-15) IE windows started opening up on its own. 2.The mouse clicks are going on like crazy which makes almost impossible to copy and paste or do anything with right clicking the menu. 3.A few months back I was having problems with the laptop not recognising the DVD drive, it just wouldnt work, so I looked up online and removed some device filters(upper or lower I dont remember) and its been working fine but whenever I start itunes I get an error message in the start.Just wondering if the DVD problem was caused by any virus to start with. These above things might or might not have anything to do with whatever we're trying to fix here but just thought I'd let you know anyway in case it matters. The Eset Scan took a while to finish and here are the results: C:\Program Files\Thomas Special Delivery\Thomas.exe probably a variant of Win32/Spy.Agent.HITIOXG trojan C:\Users\AdilSabah\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\5da228e8-1286d7f0 multiple threats C:\Users\AdilSabah\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\9db59e8-349955e7 multiple threats

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI