This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Vista taskbar "ghost/grey/copied toolbar"

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Up loading again, did not see the upload in my last updateโ€ฆ ComboFix 11-04-01.01 - Stafford_2 04/01/2011 18:16:14.1.2 - x64 Microsoftยฎ Windows Vistaโ„ข Home Premium 6.0.6001.1.1252.1.1033.18.3963.1258 [GMT -7:00] Running from: c:\users\[removed]\Documents\Download\Download\HiJack This\ComboFix.exe AV: Norton AntiVirus *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Norton AntiVirus *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\FunWebProducts c:\program files (x86)\FunWebProducts\Installr\1.bin\F3EZSETP.DLL c:\program files (x86)\FunWebProducts\Installr\1.bin\F3PLUGIN.DLL c:\program files (x86)\FunWebProducts\Installr\1.bin\NPFUNWEB.DLL . . ((((((((((((((((((((((((( Files Created from 2011-03-02 to 2011-04-02 ))))))))))))))))))))))))))))))) . . 2011-04-02 01:32 . 2011-04-02 01:32 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp 2011-04-02 01:32 . 2011-04-02 01:32 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Administrator.ToshibaLaptop\AppData\Local\temp 2011-04-02 01:32 . 2011-04-02 01:32 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Stafford\AppData\Local\temp 2011-03-26 05:55 . 2011-03-26 05:55 388096 โ€”-a-r- c:\users\Stafford_2\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-03-26 05:55 . 2011-03-26 05:55 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Trend Micro 2011-03-26 02:47 . 2011-03-26 02:47 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Stafford_2\AppData\Roaming\PCTools 2011-03-26 02:42 . 2010-12-31 16:36 74824 โ€“sโ€”w- c:\windows\system32\drivers\TfSysMon.sys 2011-03-26 02:42 . 2010-12-31 16:36 41888 โ€“sโ€”w- c:\windows\system32\drivers\TfNetMon.sys 2011-03-26 02:42 . 2010-12-31 16:36 65072 โ€“sโ€”w- c:\windows\system32\drivers\TfFsMon.sys 2011-03-26 02:30 . 2011-03-26 02:30 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Stafford_2\AppData\Local\Threat Expert 2011-03-26 02:17 . 2011-01-07 21:54 149456 โ€”-a-w- c:\windows\SGDetectionTool.dll 2011-03-26 02:17 . 2011-01-07 21:54 2000848 โ€”-a-w- c:\windows\PCTBDCore.dll 2011-03-26 02:17 . 2011-01-07 21:54 767952 โ€”-a-w- c:\windows\BDTSupport.dll 2011-03-26 02:17 . 2011-01-07 21:54 1533904 โ€”-a-w- c:\windows\PCTBDRes.dll 2011-03-26 02:15 . 2010-07-16 21:53 816016 โ€”-a-w- c:\windows\system32\drivers\pctEFA64.sys 2011-03-26 02:15 . 2010-06-29 17:35 452872 โ€”-a-w- c:\windows\system32\drivers\pctDS64.sys 2011-03-26 02:15 . 2011-01-17 16:09 334976 โ€”-a-w- c:\windows\system32\drivers\pctgntdi64.sys 2011-03-26 02:15 . 2010-12-16 15:43 137704 โ€”-a-w- c:\windows\system32\drivers\pctwfpfilter64.sys 2011-03-26 02:15 . 2010-12-10 20:24 257232 โ€”-a-w- c:\windows\system32\drivers\PCTCore64.sys 2011-03-26 02:15 . 2010-12-16 15:46 92896 โ€”-a-w- c:\windows\system32\drivers\pctplsg64.sys 2011-03-26 02:15 . 2011-03-30 22:36 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\PC Tools Security 2011-03-26 02:15 . 2011-03-28 18:38 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Common Files\PC Tools 2011-03-25 15:42 . 2011-03-25 15:42 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Stafford_2\AppData\Roaming\KSOL 2011-03-25 15:28 . 2011-03-25 15:28 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\KSOL 2011-03-22 22:49 . 2011-03-22 22:51 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Stafford_2\AppData\Local\Xobni 2011-03-22 22:48 . 2011-03-22 22:49 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Xobni 2011-03-15 02:43 . 2011-03-15 02:44 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Stafford_2\AppData\Roaming\Apple Computer 2011-03-15 02:43 . 2011-03-15 02:43 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Stafford_2\AppData\Local\Apple Computer 2011-03-15 02:43 . 2011-03-15 02:43 โ€”โ€”โ€“ dcโ€”-w- c:\windows\system32\DRVSTORE 2011-03-15 02:43 . 2009-05-18 20:17 34152 โ€”-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2011-03-15 02:43 . 2008-04-17 19:12 126312 โ€”-a-w- c:\windows\system32\GEARAspi64.dll 2011-03-15 02:43 . 2008-04-17 19:12 107368 โ€”-a-w- c:\windows\SysWow64\GEARAspi.dll 2011-03-15 02:40 . 2011-03-15 02:40 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Stafford_2\AppData\Local\Apple 2011-03-15 02:40 . 2011-03-15 02:40 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Apple Software Update 2011-03-15 02:37 . 2011-03-15 02:37 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Common Files\Apple 2011-03-15 02:36 . 2011-03-15 02:36 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Bonjour 2011-03-15 02:36 . 2011-03-15 02:36 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Bonjour 2011-03-15 02:36 . 2011-03-15 02:43 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Apple 2011-03-15 02:36 . 2011-03-15 02:42 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Common Files\Apple 2011-03-14 16:14 . 2011-03-14 16:14 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Oracle 2011-03-14 16:00 . 2011-03-14 16:01 โ€”โ€”โ€“ dโ€”โ€“w- C:\Oracle 2011-03-14 15:55 . 2011-03-14 15:55 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Stafford_2\.oracle 2011-03-12 19:28 . 2011-03-12 19:28 103864 โ€”-a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll 2011-03-10 21:55 . 2011-03-10 21:55 โ€”โ€”โ€“ dโ€”โ€“w- C:\HP Universal Print Driver 2011-03-10 01:44 . 2011-03-10 01:44 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Stafford_2\Oracle 2011-03-09 21:55 . 2011-03-15 19:37 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Stafford_2\AppData\Local\Google 2011-03-06 02:51 . 2011-03-06 02:52 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\JpegSizer 2011-03-03 21:06 . 2008-05-24 00:46 32864 โ€”-a-w- c:\windows\SysWow64\dsgrab_01cbd9e6dcdcabd0.dll 2011-03-03 21:06 . 2008-05-24 00:46 10848 โ€”-a-w- c:\windows\SysWow64\drivers\dsload.sys 2011-03-03 21:06 . 2011-03-03 21:06 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Stafford_2\AppData\Local\Oracle 2011-03-03 21:06 . 2011-03-03 21:06 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files (x86)\Common Files\Oracle 2011-03-03 21:05 . 2011-03-03 21:05 226656 โ€”โ€”w- c:\users\Stafford_2\cnsload_1299186308700.tmp . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-02-23 00:28 . 2011-02-23 00:28 335872 โ€”-a-w- c:\windows\SysWow64\DMGeneral.dll 2011-02-18 23:36 . 2011-02-18 23:36 51712 โ€”-a-w- c:\windows\system32\drivers\usbaapl64.sys 2011-02-18 23:36 . 2011-02-18 23:36 4184352 โ€”-a-w- c:\windows\system32\usbaaplrc.dll 2011-02-15 18:37 . 2011-02-15 18:37 3035136 โ€”-a-w- c:\windows\SysWow64\kgantt32.ocx 2011-02-06 01:39 . 2011-02-06 01:39 174640 โ€”-a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS 2011-02-04 22:28 . 2011-02-04 22:28 86016 โ€”-a-w- c:\windows\SysWow64\ktxt32.ocx 2011-02-04 19:57 . 2011-02-04 19:57 364544 โ€”-a-w- c:\windows\SysWow64\kgrid32.ocx 2011-02-04 17:49 . 2011-02-04 17:49 5795840 โ€”-a-w- c:\windows\SysWow64\KMspEngine.dll 2011-01-13 10:20 . 2011-02-01 20:02 7844688 โ€”-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{26AEF9E5-1B46-480B-9490-A213717D5D06}\mpengine.dll 2011-01-06 18:54 . 2011-03-26 02:17 2125 โ€”-a-w- c:\windows\UDB.zip . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green] @="{95A27763-F62A-4114-9072-E81D87DE3B68}" [HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}] 2010-09-21 02:25 731280 โ€”-a-r- c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial] @="{E300CD91-100F-4E67-9AF3-1384A6124015}" [HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}] 2010-09-21 02:25 731280 โ€”-a-r- c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow] @="{5E529433-B50E-4bef-A63B-16A6B71B071A}" [HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}] 2010-09-21 02:25 731280 โ€”-a-r- c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-05-19 432640] "Messenger (Yahoo!)"="c:\program files (x86)\Yahoo!\Messenger\YahooMessenger.exe" [2010-03-03 5244216] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2010-11-29 1294712] "SunJavaUpdateSched"="c:\program files (x86)\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "Carbonite Backup"="c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe" [2010-09-21 913552] "Everything"="c:\program files (x86)\Everything\Everything.exe" [2009-03-13 602624] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-30 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-03-07 421160] "PCTools FGuard"="c:\program files (x86)\PC Tools Security\BDT\FGuard.exe" [2011-01-07 108496] . c:\users\Stafford_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ DING!.lnk - c:\program files (x86)\Southwest Airlines\Ding\Ding.exe [2006-6-22 462848] ScreenHunter 5.1 Free.lnk - c:\program files (x86)\Wisdom-soft ScreenHunter 5 Free\ScreenHunter.exe [2010-10-14 5324800] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ QuickBooks Update Agent.lnk - c:\program files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2010-8-25 1156384] QuickBooks_Standard_21.lnk - c:\program files (x86)\Intuit\QuickBooks 2008\QBW32.EXE [2010-8-25 1178400] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "HideFastUserSwitching"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-09 136176] R3 Amazon Download Agent;Amazon Download Agent;c:\program files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2009-10-23 401920] R3 Pcouffin64;Low level access layer for CD devices;c:\windows\system32\Drivers\pcouffin64a.sys [x] R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg64.sys [x] R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\PC Tools Security\pctsAuxs.exe [2010-03-15 366840] R3 SVRPEDRV;SVRPEDRV;c:\windows\SysWOW64\sysprep\UP_date\PEDrv.sys [x] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [x] R3 ThreatFire;ThreatFire;c:\program files (x86)\PC Tools Security\TFEngine\TFService.exe service [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [x] R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys [x] R4 KR10I64;KR10I64;c:\windows\system32\drivers\kr10i64.sys [x] R4 KR10N64;KR10N64;c:\windows\system32\drivers\kr10n64.sys [x] S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [x] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [x] S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NAVx64\1205000.07D\SYMDS64.SYS [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAVx64\1205000.07D\SYMEFA64.SYS [x] S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [x] S0 TFSysMon;TFSysMon;c:\windows\system32\drivers\TfSysMon.sys [x] S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.5.0.125\Definitions\BASHDefs\20110309.001\BHDrvx64.sys [2011-02-25 1124472] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.5.0.125\Definitions\IPSDefs\20110330.001\IDSvia64.sys [2011-03-14 476792] S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi64.sys [x] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NAVx64\1205000.07D\Ironx64.SYS [x] S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\NAVx64\1205000.07D\SYMTDIV.SYS [x] S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312] S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\PC Tools Security\BDT\BDTUpdateService.exe [2011-01-07 247760] S2 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2008-04-04 36864] S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2008-04-17 40960] S2 HPM1210RcvFaxSrvc;HP LaserJet Professional M1210 MFP Series Receive Fax Service;c:\program files\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe [2009-11-18 355840] S2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [x] S2 NAV;Norton AntiVirus;c:\program files (x86)\Norton AntiVirus\Engine\18.5.0.125\ccSvcHst.exe [2010-11-24 130000] S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-04 175104] S2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [2010-05-06 583360] S2 XobniService;XobniService;c:\program files (x86)\Xobni\XobniService.exe [2011-02-11 62184] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-02-05 132656] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x] S3 NETw5v64;Intelยฎ Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit ;c:\windows\system32\DRIVERS\NETw5v64.sys [x] S3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe [2008-04-25 84992] S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-11-29 54136] . . Contents of the 'Scheduled Tasks' folder . 2011-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-09 21:55] . 2011-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-03-09 21:55] . . โ€”โ€”โ€” x86-64 โ€”โ€”โ€”โ€“ . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green] @="{95A27763-F62A-4114-9072-E81D87DE3B68}" [HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}] 2010-09-21 02:13 1112208 โ€”-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial] @="{E300CD91-100F-4E67-9AF3-1384A6124015}" [HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}] 2010-09-21 02:13 1112208 โ€”-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow] @="{5E529433-B50E-4bef-A63B-16A6B71B071A}" [HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}] 2010-09-21 02:13 1112208 โ€”-a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide" [X] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-25 151064] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-25 209432] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-25 181784] "RtHDVCpl"="RAVCpl64.exe" [2008-04-08 6156288] "Skytel"="Skytel.exe" [2007-11-21 1826816] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-07 1216808] "CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2007-10-26 652624] "WrtMon.exe"="c:\windows\system32\spool\drivers\x64\3\WrtMon.exe" [2006-09-20 20480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . โ€”โ€”- Supplementary Scan โ€”โ€”- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = %SystemRoot%\system32\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewikiโ€ฆ - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll Trusted Zone: idhasoft.com Trusted Zone: plxtech.com\stargate Trusted Zone: powis.com\maple Trusted Zone: sierraapps.com\plxdev Trusted Zone: trid.com\tricrp1 Handler: intu-help-qb4 - {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - c:\program files (x86)\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 - vpnweb.cab DPF: {00191E4B-49C2-48E2-A548-8F702D75622A} - hxxps://strtc.oracle.com/imtapp/res/jar/cnsload.cab DPF: {4F29DE54-5EB7-4D76-B610-A86B5CD2A234} - hxxp://archives.gametap.com/static/cab_headless/GameTapWebPlayer.cab DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} - hxxps://dcvpn.idhasoft.com/CACHE/stc/1/binaries/vpnweb.cab DPF: {9E889A8A-738E-4F6C-892E-6121063F9FB6} - hxxp://swarren.myphotoalbum.com/MyPhotoAlbumEasyUploader.cab . - - - - ORPHANS REMOVED - - - - . WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file) HKLM-Run-TPwrMain - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE HKLM-Run-HSON - %ProgramFiles%\TOSHIBA\TBS\HSON.exe HKLM-Run-SmoothView - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe HKLM-Run-00TCrdMain - %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NAV] "ImagePath"="\"c:\program files (x86)\Norton AntiVirus\Engine\18.5.0.125\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files (x86)\Norton AntiVirus\Engine\18.5.0.125\diMaster.dll\" /prefetch:1" . โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€” . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}] @Denied: (A) (Everyone) "Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane\0] "Key"="ActionsPane" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . Completion time: 2011-04-01 18:42:13 ComboFix-quarantined-files.txt 2011-04-02 01:42 . Pre-Run: 181,852,131,328 bytes free Post-Run: 183,573,745,664 bytes free . - - End Of File - - 300EB469D5745114B7763CDDAB06D201
Hi - I am now getting an error when I go to run Quickbooks, from Intuit: Intuit Technical Support error codes (-6094,0) When I google on this, I find hits related to the use of the AVG antivirus software. Did any of the scans I did do put anything related to AVG on my system? Why would I be getting this type of security error otherwise? thanks - Stafford
:welcome:

We prefer that you copy and paste the logs directly into this thread in lew of attaching them, its easier for us to analyze.

Combofix is a very powerful tool, what it can fix on one system it can damage another , this forum, myself and sUbs will not be responsible if you run this program on your own and damage your system

Its best with an infected computer to just leave it be and post in the forum for help and not run any tools on your own, you may damage your system and are also removing clues as to what may be infecting your system

Lastly, our helpers look for posts with ZERO replies and by replying as many times you have it took you out of that category as it makes it look like your already being helped.

Lets start from the beginning


Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.





Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please





Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI