This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can you Please Help?

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have had a virus for several weeks and I have been through multiple anit-spywares and other programs have been what seems to have tamed the virus, but now it has escalated to higher needs.. It is telling me i have regestry corruption. I ran HJT and tried to post it but your site told me I have an outdated HJT so I downloaded the newer version adn now can't get it to save to a log file so that I can paste it on here for help. Please help. thanks
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.


IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! :thumbup:
Hi, thanks for help in adv advance. I have been fighting off a virus for several minths now. I have ran "Malwarebytes Anti-Malware" and I also have "Webroot Anti-Spyware with Anti-virus" I have used HJT in the past and did some good on previous viruses but this one seems to be getting the best of me. I recently am having "system error" "corrupted registry" warnings and it would pop up a "system repair screen" and tell me i have bad sectors and etc. I have int he last 2 days had to restore my computer to an earlier date to be able to reboot. I had to restore last night after i posted and in turn i went back to the HJT version 2.0.2 which i am posting below. after downloading the new version 2.0.4 then I was not able to run it as admin. by right clicking on the icon. i have vista if I forgot to mention. Thanks again.

Logfile of Trend Micro HijackThis
Scan saved at 6:36:25 AM, on 8/23/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19120)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10q_ActiveX.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] "C:\Windows\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\Windows\system32\hkcmd.exe"
O4 - HKLM\..\Run: [Persistence] "C:\Windows\system32\igfxpers.exe"
O4 - HKLM\..\Run: [TPwrMain] "C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE"
O4 - HKLM\..\Run: [SmoothView] "C:\Program Files\Toshiba\SmoothView\SmoothView.exe"
O4 - HKLM\..\Run: [00TCrdMain] "C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [jswtrayutil] "C:\Program Files\Jumpstart\jswtrayutil.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] "C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe" SVPwUTIL
O4 - HKLM\..\Run: [KeNotify] "C:\Program Files\TOSHIBA\Utilities\KeNotify.exe"
O4 - HKLM\..\Run: [RtHDVCpl] "C:\Windows\RtHDVCpl.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Mobile Device Center] "%windir%\WindowsMobile\wmdc.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [WebrootTrayApp] "C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe"
O4 - HKCU\..\Run: [TOSCDSPD] "C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe"
O4 - HKCU\..\Run: [ehTray.exe] "C:\Windows\ehome\ehTray.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Update Service (gupdate1c9ae605c644117) (gupdate1c9ae605c644117) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Jumpstart\jswpsapi.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Security\current\plugins\antimalware\AEI.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\Security\Current\Framework\WRConsumerService.exe

–
End of file - 7874 bytes
Hi yksnemeg,

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • If it needs to, DeFogger may ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.
———-

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-


In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)
Thank you again for taking your time to help me. I have done as requested and now posted what was asked. Let me know if I did something wrong and i will do it again. . DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 8.0.6001.19120 Run by [removed] at 16:25:04 on 2011-08-23 . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Program Files\Webroot\Security\Current\Framework\WRConsumerService.exe C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\SLsvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\system32\agrsmsvc.exe C:\Windows\System32\mobsync.exe c:\Toshiba\IVP\swupdate\swupdtmr.exe C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Program Files\Webroot\Security\current\plugins\antimalware\AEI.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Toshiba\Power Saver\TPwrMain.exe C:\Program Files\Toshiba\SmoothView\SmoothView.exe C:\Program Files\Toshiba\FlashCards\TCrdMain.exe C:\Program Files\Apoint2K\Apoint.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Toshiba\ConfigFree\NDSTray.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Toshiba\Utilities\KeNotify.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Apoint2K\ApMsgFwd.exe C:\Windows\WindowsMobile\wmdc.exe C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Webroot\Security\current\plugins\antimalware\SSU.EXE C:\Program Files\Apoint2K\Apntex.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil10q_ActiveX.exe C:\Windows\system32\taskeng.exe C:\Windows\ehome\mcupdate.EXE C:\Windows\system32\taskeng.exe C:\Windows\system32\RacAgent.exe C:\Users\Jessica\Desktop\Defogger.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\vssvc.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Users\Jessica\Desktop\dds.com C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\svchost.exe -k swprv . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.facebook.com/ uDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File uRun: [TOSCDSPD] "c:\program files\toshiba\toscdspd\TOSCDSPD.exe" uRun: [ehTray.exe] "c:\windows\ehome\ehTray.exe" uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [WMPNSCFG] "c:\program files\windows media player\WMPNSCFG.exe" mRun: [IgfxTray] "c:\windows\system32\igfxtray.exe" mRun: [HotKeysCmds] "c:\windows\system32\hkcmd.exe" mRun: [Persistence] "c:\windows\system32\igfxpers.exe" mRun: [TPwrMain] "c:\program files\toshiba\power saver\TPwrMain.EXE" mRun: [SmoothView] "c:\program files\toshiba\smoothview\SmoothView.exe" mRun: [00TCrdMain] "c:\program files\toshiba\flashcards\TCrdMain.exe" mRun: [Apoint] "c:\program files\apoint2k\Apoint.exe" mRun: [jswtrayutil] "c:\program files\jumpstart\jswtrayutil.exe" mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [NDSTray.exe] NDSTray.exe mRun: [HWSetup] \HWSetup.exe hwSetUP mRun: [SVPWUTIL] "c:\program files\toshiba\utilities\SVPWUTIL.exe" SVPwUTIL mRun: [KeNotify] "c:\program files\toshiba\utilities\KeNotify.exe" mRun: [RtHDVCpl] "c:\windows\RtHDVCpl.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Windows Mobile Device Center] "%windir%\WindowsMobile\wmdc.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [WebrootTrayApp] "c:\program files\webroot\security\current\framework\WRTray.exe" mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{38345E4D-9E2C-42F5-AC8A-C5DAC44F2AD7} : DhcpNameServer = 192.168.2.1 TCP: Interfaces\{C731D3F7-418F-474D-8D48-3350BBFC41FE} : DhcpNameServer = 192.168.0.1 TCP: Interfaces\{E3C2285E-83FC-426B-9728-1960F917DBC1} : DhcpNameServer = [removed] [removed] Notify: igfxcui - igfxdev.dll . ============= SERVICES / DRIVERS =============== . R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86 R? ConfigFree Service;ConfigFree Service R? gupdate1c9ae605c644117;Google Update Service (gupdate1c9ae605c644117) R? jswpsapi;Jumpstart Wifi Protected Setup R? RkHit;RkHit R? TpChoice;Touch Pad Detection Filter driver R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0 S? FontCache;Windows Font Cache Service S? jswpslwf;JumpStart Wireless Filter Driver S? ssfmonm;ssfmonm S? TOSHIBA SMART Log Service;TOSHIBA SMART Log Service S? WebrootSpySweeperService;Webroot Spy Sweeper Engine S? WRConsumerService;Webroot Client Service . =============== File Associations =============== . regfile=regedit.exe "%1" %* scrfile="%1" %* . =============== Created Last 30 ================ . 2011-08-23 20:24:26 7152464 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{f9058879-6eb3-438f-b441-711ae7d18b01}\mpengine.dll 2011-08-22 20:38:28 7152464 ——w- c:\programdata\microsoft\windows defender\definition updates\{8b666cfc-5764-4042-8a7e-e19923495572}\mpengine.dll 2011-08-22 01:25:29 876032 —-a-w- c:\windows\system32\XpsPrint.dll 2011-08-21 23:49:03 2048 —-a-w- c:\windows\system32\winrsmgr.dll 2011-08-21 23:47:56 246272 —-a-w- c:\windows\system32\WSManHTTPConfig.exe 2011-08-21 23:47:50 1181696 —-a-w- c:\windows\system32\WsmSvc.dll 2011-08-21 20:47:38 292864 —-a-w- c:\windows\system32\atmfd.dll 2011-08-21 20:47:36 34304 —-a-w- c:\windows\system32\atmlib.dll 2011-08-21 20:47:32 375808 —-a-w- c:\windows\system32\winsrv.dll 2011-08-21 20:47:29 69632 —-a-w- c:\windows\system32\drivers\bowser.sys 2011-08-21 20:47:23 75264 —-a-w- c:\windows\system32\drivers\dfsc.sys 2011-08-21 20:47:17 1205080 —-a-w- c:\windows\system32\ntdll.dll 2011-08-21 20:45:58 305152 —-a-w- c:\windows\system32\drivers\srv.sys 2011-08-21 20:45:51 79872 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-08-21 20:45:51 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-08-21 20:45:50 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-08-21 20:45:41 86528 —-a-w- c:\windows\system32\dnsrslvr.dll 2011-08-21 20:45:41 25088 —-a-w- c:\windows\system32\dnscacheugc.exe 2011-08-21 20:45:33 273408 —-a-w- c:\windows\system32\drivers\afd.sys 2011-08-21 20:43:14 28672 —-a-w- c:\windows\system32\Apphlpdm.dll 2011-08-21 20:43:13 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2011-08-21 20:43:01 429056 —-a-w- c:\windows\system32\EncDec.dll 2011-08-21 20:42:57 322560 —-a-w- c:\windows\system32\sbe.dll 2011-08-21 20:42:55 177664 —-a-w- c:\windows\system32\mpg2splt.ax 2011-08-21 20:42:54 153088 —-a-w- c:\windows\system32\sbeio.dll 2011-08-21 20:41:09 739328 —-a-w- c:\windows\system32\inetcomm.dll 2011-08-21 20:41:04 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2011-08-21 20:39:55 2067968 —-a-w- c:\windows\system32\mstscax.dll 2011-08-21 20:39:54 677888 —-a-w- c:\windows\system32\mstsc.exe 2011-08-21 20:30:15 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-08-21 20:30:10 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-08-21 20:25:11 905104 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-08-09 10:48:03 276992 —-a-w- c:\windows\system32\schannel.dll 2011-08-09 00:29:09 45584 —-a-w- c:\windows\system32\drivers\ssfmonm.sys 2011-08-09 00:29:09 24496 —-a-w- c:\windows\system32\drivers\sshrmd.sys 2011-08-09 00:29:09 181008 —-a-w- c:\windows\system32\drivers\ssidrv.sys 2011-08-09 00:25:46 ——– dc-h–w- c:\programdata\{61D227D1-25DF-4A97-9428-6C9A27015CDA} 2011-08-09 00:25:22 ——– d—–w- c:\program files\Webroot 2011-08-09 00:24:02 ——– d–h–w- c:\programdata\Webroot 2011-08-08 21:17:21 ——– d–h–w- c:\users\jessica\appdata\local\PackageAware 2011-07-31 15:28:07 ——– d—–w- c:\program files\PC Tools Security 2011-07-31 15:28:07 ——– d—–w- c:\program files\common files\PC Tools 2011-07-31 15:26:16 ——– d—–w- c:\programdata\PC Tools . ==================== Find3M ==================== . 2011-07-23 11:04:29 916480 —-a-w- c:\windows\system32\wininet.dll 2011-07-23 11:00:05 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-07-23 10:59:52 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2011-07-23 10:59:34 71680 —-a-w- c:\windows\system32\iesetup.dll 2011-07-23 10:59:34 109056 —-a-w- c:\windows\system32\iesysprep.dll 2011-07-23 10:03:47 385024 —-a-w- c:\windows\system32\html.iec 2011-07-23 09:27:04 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2011-07-23 09:25:38 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-07-06 23:52:42 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-07-06 23:52:42 22712 —-a-w- c:\windows\system32\drivers\mbam.sys . ============= FINISH: 16:37:04.72 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-06-23.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 3/20/2008 3:39:02 AM System Uptime: 8/23/2011 4:01:28 PM (0 hours ago) . Motherboard: TOSHIBA | | ISKAA Processor: Intel® Pentium® Dual CPU T2370 @ 1.73GHz | U2E1 | 1067/mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 110 GiB total, 51.478 GiB free. D: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) 2007 Microsoft Office system Activation Assistant for the 2007 Microsoft Office suites Adobe Flash Player 10 ActiveX Adobe Reader 8.1.3 Adobe Shockwave Player 11.5 ALPS Touch Pad Driver Apple Application Support Apple Mobile Device Support Apple Software Update Atheros Driver Installation Program Atheros Wi-Fi Protected Setup Library AutoUpdate BlackBerry Device Software v4.5.0 for the BlackBerry 8330 smartphone Bluetooth Stack for Windows by Toshiba Bonjour CD/DVD Drive Acoustic Silencer DivX Player DivX Pro Trial DVD MovieFactory for TOSHIBA GearDrvs Google Update Helper HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Product Detection Intel® Graphics Media Accelerator Driver iPAQ 200 Improvement Java™ 6 Update 21 Java™ 6 Update 3 Java™ 6 Update 5 Java™ 6 Update 7 Lexi-CALC Lexi-CALC Calculations (Step 2) Lexi-Comp Analyze (remove only) Lexi-Comp Interact Reader (remove only) Lexi-Comp Reader (remove only) Lexi-CONNECT LiveUpdate 3.2 (Symantec Corporation) LiveUpdate Notice (Symantec Corporation) Malwarebytes' Anti-Malware version 1.51.1.1800 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional Edition 2003 Microsoft Office Professional Hybrid 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft XML Parser Move Media Player MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 and SOAP Toolkit 3.0 Norton 360 OGA Notifier 2.0.0048.0 QuickTime Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista Realtek High Definition Audio Driver Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2509488) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft Office 2007 System (KB2541012) Security Update for Microsoft Office Access 2007 (KB979440) Security Update for Microsoft Office Excel 2007 (KB2541007) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2535818) Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) Security Update for Microsoft Office Publisher 2007 (KB2284697) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Security Update for Windows Media Encoder (KB2447961) Security Update for Windows Media Encoder (KB954156) Security Update for Windows Media Encoder (KB979332) Spelling Dictionaries Support For Adobe Reader 8 Texas Instruments PCIxx21/x515/xx12 drivers. TIPCI TOSHIBA Assist TOSHIBA ConfigFree TOSHIBA Disc Creator TOSHIBA DVD PLAYER TOSHIBA Extended Tiles for Windows Mobility Center TOSHIBA Flash Cards Support Utility TOSHIBA Games TOSHIBA Hardware Setup Toshiba Registration TOSHIBA SD Memory Utilities TOSHIBA Software Modem TOSHIBA Software Upgrades TOSHIBA Speech System Applications TOSHIBA Speech System SR Engine(U.S.) Version1.0 TOSHIBA Speech System TTS Engine(U.S.) Version1.0 TOSHIBA Supervisor Password TOSHIBA Value Added Package TrueCrypt Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 System (KB2539530) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Outlook 2007 (KB2509470) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update for Outlook 2007 Junk Email Filter (KB2586924) Utility Common Driver Webroot Software Windows Live ID Sign-in Assistant Windows Media Encoder 9 Series Windows Mobile Device Center Windows Mobile Device Center Driver Update . ==== Event Viewer Messages From Past Week ======== . 8/23/2011 4:03:46 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Cdr4_xp 8/23/2011 4:03:45 PM, Error: Service Control Manager [7022] - The Webroot Spy Sweeper Engine service hung on starting. 8/23/2011 4:03:29 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 8/23/2011 4:03:29 PM, Error: Service Control Manager [7000] - The Google Update Service (gupdate1c9ae605c644117) service failed to start due to the following error: The system cannot find the path specified. 8/22/2011 9:17:01 PM, Error: Service Control Manager [7043] - The Windows Update service did not shut down properly after receiving a preshutdown control. 8/22/2011 9:11:47 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x800f0816: Security Update for Windows Vista (KB2555917). 8/21/2011 8:59:36 PM, Error: Microsoft-Windows-Kernel-General [5] - {Registry Hive Recovered} Registry hive (file): '\??\C:\PROGRA~1\Webroot\Security\Current\plugins\ANTIMA~1\wrstemp\SST-30~1.TMP' was corrupted and it has been recovered. Some data might have been lost. 8/21/2011 5:09:43 PM, Error: Microsoft-Windows-Windows Defender [2004] - Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted: Current Error Code: 0x8050a001 Error description: The program can't find definition files that help detect unwanted software. Check for updates to the definition files, and then try again. For information on installing updates, see Help and Support. Signatures loading: Backup Loading signature version: 1.111.35.0 Loading engine version: 1.1.7104.0 8/21/2011 4:28:57 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Windows Defender - KB915597 (Definition 1.111.216.0). 8/21/2011 3:49:37 PM, Error: Service Control Manager [7022] - The KtmRm for Distributed Transaction Coordinator service hung on starting. 8/21/2011 3:46:38 PM, Error: Service Control Manager [7022] - The Background Intelligent Transfer Service service hung on starting. 8/21/2011 3:46:37 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service. 8/21/2011 2:48:16 PM, Error: Service Control Manager [7022] - The Windows Update service hung on starting. 8/21/2011 2:16:46 PM, Error: Service Control Manager [7038] - The wscsvc service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: A system shutdown is in progress. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC). 8/21/2011 2:16:46 PM, Error: Service Control Manager [7000] - The Security Center service failed to start due to the following error: The service did not start due to a logon failure. 8/21/2011 2:16:44 PM, Error: Service Control Manager [7043] - The Group Policy Client service did not shut down properly after receiving a preshutdown control. 8/18/2011 9:06:05 PM, Error: EventLog [6008] - The previous system shutdown at 9:03:30 PM on 8/18/2011 was unexpected. . ==== End Of File =========================== aswMBR version 0.9.8.978 Copyright© 2011 AVAST Software Run date: 2011-08-23 16:54:50 —————————– 16:54:50.528 OS Version: Windows 6.0.6002 Service Pack 2 16:54:50.528 Number of processors: 2 586 0xF0D 16:54:50.528 ComputerName: JESSICA-PC UserName: Jessica 16:54:58.484 Initialize success 16:56:19.703 AVAST engine defs: 11082300 16:56:24.898 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4 16:56:24.898 Disk 0 Vendor: TOSHIBA_MK1246GSX LB213M Size: 114473MB BusType: 3 16:56:28.408 Disk 0 MBR read successfully 16:56:28.408 Disk 0 MBR scan 16:56:29.172 Disk 0 Windows VISTA default MBR code 16:56:29.235 Disk 0 scanning sectors +234440704 16:56:29.453 Disk 0 scanning C:\Windows\system32\drivers 16:57:05.380 Service scanning 16:57:08.281 Modules scanning 16:57:18.655 Disk 0 trace - called modules: 16:57:18.671 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll PCIIDEX.SYS msahci.sys dxgkrnl.sys igdkmd32.sys watchdog.sys tcpip.sys NETIO.SYS NDIS.SYS athr.sys 16:57:18.687 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85667808] 16:57:18.687 3 CLASSPNP.SYS[8317f8b3] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-4[0x84f33b98] 16:57:19.981 AVAST engine scan C:\Windows 16:57:29.544 AVAST engine scan C:\Windows\system32 17:02:12.981 AVAST engine scan C:\Windows\system32\drivers 17:02:37.457 AVAST engine scan C:\Users\Jessica 17:03:29.717 Disk 0 MBR has been saved successfully to "C:\Users\Jessica\Desktop\MBR.dat" 17:03:29.733 The log file has been saved successfully to "C:\Users\Jessica\Desktop\aswMBR.txt" Thanks again.
Hi yksnemeg,

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :dir
    c:\programdata\{61D227D1-25DF-4A97-9428-6C9A27015CDA}
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
———-

I notice that you have Malwarebytes on your system already. :) Please open this program, perform and Update and then run a Quick Scan.
It will create a log that I will need in your next reply.
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply I will need the logs created by SystemLook, Malwarebytes and ESET Online Scanner. :)
Ok, I believe to have done what is asked, let me know if I haven't. I would like to mention that before i had to restore my computer to a previous date, that Malware found 3 trojan viruses but as you can see now there are none found. Let me know what the next steps are and thanks again. Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7551 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.19120 8/24/2011 8:52:36 AM mbam-log-2011-08-24 (08-52-35).txt Scan type: Quick scan Objects scanned: 162991 Time elapsed: 8 minute(s), 18 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) From the ESETScan.txt: C:\Users\Jessica\AppData\Local\Temp\tmp5D5D.tmp a variant of Win32/Kryptik.RYO trojan SystemLook 30.07.11 by jpshortstuff Log created at 08:42 on 24/08/2011 by Jessica Administrator - Elevation successful ========== dir ========== c:\programdata\{61D227D1-25DF-4A97-9428-6C9A27015CDA} - Parameters: "(none)" —Files— instance.dat –a–c- 98 bytes [00:26 09/08/2011] [00:26 09/08/2011] mia.lib –a–c- 575060 bytes [00:26 09/08/2011] [22:01 21/07/2011] WRInstall.dat –a–c- 231 bytes [00:26 09/08/2011] [00:26 09/08/2011] WRInstall.exe –a–c- 3329056 bytes [00:26 09/08/2011] [22:01 21/07/2011] WRInstall.lan –a–c- 9 bytes [00:26 09/08/2011] [00:26 09/08/2011] WRInstall.lnk –a–c- 0 bytes [00:26 09/08/2011] [00:26 09/08/2011] WRInstall.msi –a–c- 412160 bytes [00:26 09/08/2011] [22:01 21/07/2011] WRInstall.par –a–c- 2787 bytes [00:26 09/08/2011] [00:26 09/08/2011] WRInstall.res –a–c- 16536190 bytes [00:26 09/08/2011] [22:01 21/07/2011] {8B287B75-DF8D-40C8-9620-8E4492C38EF1} –a–c- 0 bytes [00:26 09/08/2011] [00:26 09/08/2011] —Folders— OFFLINE d—-c- [00:25 09/08/2011] -= EOF =- I hope this helps. Thanks
Hi yksnemeg,

Things are looking pretty good regarding malware. What remaining issues do you have?
———-

First open an elevated command prompt > Click Start and type cmd in Start Search.
When cmd.exe populates above, right click it and select Run as Administrator to open an elevated command prompt.
Copy and paste the bolded line below into the command prompt and press Enter.

del C:\Users\Jessica\AppData\Local\Temp\tmp5D5D.tmp /f /q
———-

Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
    Java Runtime Environment (JRE) version for your computer.
———-


You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe 8 first. Be sure to move any PDF documents to another folder first though.
———-

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
———-

Please download HD Tune (the free version not the trial), run an error scan on your primary harddrive (full not quick) and report back if any blocks aren't green. It tests your hard drive for bad sectors.
I have done as requested and here is the results. Microsoft Windows [Version 6.0.6002] Copyright © 2006 Microsoft Corporation. All rights reserved. C:\Users\Jessica>del C:\Users\Jessica\AppData\Local\Temp\tmp5D5D.tmp /f /q Could Not Find C:\Users\Jessica\AppData\Local\Temp\tmp5D5D.tmp C:\Users\Jessica> When I got into the Javara website. it gave me several options int eh javare section to download. I didn't know which one to download. please advise. I downloaded the new version of Adobe reader I ran the TFC. I downloaded the HD Tune and ran. All sectors were green. As far as other concerns and issues. I am now having the issue that my web browser screen is in larger or zoomed feeling. the word fonts have not changed but it seems as if the images and screen features are larger. I'm confused about malwarebytes and how it seems not to recongnize viruses when there are some. And how much can webroot really do? Do I have my settings wrong? are programs "clashing" with each other. The computer is very slow to start and after booting is very sluggish when opening programs and the web. I have notice I have lost all my desktop icons and shortcuts prior to talking to you. losing some pictures and what nots, but if I look at the capacity of the C: drive, it is unchanged making me think all of it is still available. Let me know and Thanks again for all your help so far.
Hi yksnemeg,

Right now I am looking further into your system to try and find the cause of the slowness in your system. I will see what I can come up with. :)

I'm confused about malwarebytes and how it seems not to recongnize viruses when there are some. And how much can webroot really do?

While they are both good programs, no program can guarantee 100% security.

When I got into the Javara website. it gave me several options int eh javare section to download. I didn't know which one to download. please advise.

How about doing this. Go to Start > Control Panel > Programs and Features and find all Java entries and delete them. Now go here to download Java and then install it.
———-

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-

In your next reply please post the log created by ComboFix. :)
Ok, here is teh latest info requested. Let me know what my next steps are. Thanks.

ComboFix 11-08-26.04 - Jessica 08/26/2011 16:51:22.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1014.339 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {53211D91-0C31-95F2-E3A5-7661FB22889E}
SP: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {E840FC75-2A0B-9A7C-D915-4D1380A5C223}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\xp
c:\programdata\xp\EBLib.dll
c:\programdata\xp\TPwSav.sys
c:\users\Jessica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tool
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\system32\no
c:\windows\system32\no\toscdspd.cpl.mui
c:\windows\system32\SV
c:\windows\system32\SV\toscdspd.cpl.mui
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_RKHIT
——-\Service_RkHit
.
.
((((((((((((((((((((((((( Files Created from 2011-07-26 to 2011-08-26 )))))))))))))))))))))))))))))))
.
.
2011-08-26 21:03 . 2011-08-26 21:10 ——– d—–w- c:\users\Jessica\AppData\Local\temp
2011-08-26 21:03 . 2011-08-26 21:03 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-08-26 16:57 . 2011-08-16 12:48 7152464 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A3235E38-9693-4E20-BA2D-91495ECD4381}\mpengine.dll
2011-08-25 14:37 . 2011-08-25 14:37 ——– d—–w- c:\program files\HD Tune
2011-08-25 14:16 . 2011-08-25 14:16 ——– d—–w- c:\program files\Common Files\Adobe
2011-08-25 14:11 . 2011-08-25 14:11 ——– d—–w- c:\program files\Common Files\Adobe AIR
2011-08-24 10:46 . 2011-08-24 10:46 ——– d—–w- c:\program files\ESET
2011-08-21 20:47 . 2011-02-16 14:02 292864 —-a-w- c:\windows\system32\atmfd.dll
2011-08-21 20:47 . 2011-02-16 16:16 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-08-21 20:47 . 2011-02-22 13:23 69632 —-a-w- c:\windows\system32\drivers\bowser.sys
2011-08-21 20:47 . 2011-04-14 14:59 75264 —-a-w- c:\windows\system32\drivers\dfsc.sys
2011-08-21 20:46 . 2011-01-20 16:37 638336 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-08-21 20:46 . 2011-01-20 16:08 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-08-21 20:46 . 2011-01-20 16:07 37376 —-a-w- c:\windows\system32\cdd.dll
2011-08-21 20:45 . 2011-02-18 14:03 305152 —-a-w- c:\windows\system32\drivers\srv.sys
2011-08-21 20:45 . 2011-07-06 15:31 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-21 20:45 . 2011-04-29 13:24 79872 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-08-21 20:45 . 2011-04-29 13:24 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-08-21 20:45 . 2011-03-02 15:44 86528 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-08-21 20:45 . 2009-05-04 09:59 25088 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-08-21 20:45 . 2011-04-21 13:58 273408 —-a-w- c:\windows\system32\drivers\afd.sys
2011-08-21 20:44 . 2011-04-29 13:25 146432 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-08-21 20:44 . 2011-04-29 13:25 102400 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-08-21 20:44 . 2011-01-20 16:08 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-08-21 20:44 . 2011-01-20 16:08 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-08-21 20:44 . 2011-01-20 14:12 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-08-21 20:44 . 2011-01-20 13:47 683008 —-a-w- c:\windows\system32\d2d1.dll
2011-08-21 20:44 . 2011-02-22 13:33 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-08-21 20:44 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-08-21 20:44 . 2011-01-20 14:11 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-08-21 20:44 . 2011-01-20 16:08 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-08-21 20:44 . 2011-01-20 16:08 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-08-21 20:43 . 2011-03-03 15:40 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2011-08-21 20:43 . 2011-03-03 13:35 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-08-21 20:43 . 2010-12-29 18:28 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-08-21 20:41 . 2011-06-06 10:59 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-21 20:40 . 2011-04-30 06:09 758784 —-a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2011-08-21 20:40 . 2011-07-23 11:04 129536 —-a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-08-21 20:40 . 2011-07-23 10:59 247808 —-a-w- c:\program files\Internet Explorer\ieproxy.dll
2011-08-21 20:40 . 2011-07-23 10:59 197632 —-a-w- c:\program files\Internet Explorer\IEShims.dll
2011-08-21 20:40 . 2011-07-23 10:59 743424 —-a-w- c:\program files\Internet Explorer\iedvtool.dll
2011-08-21 20:40 . 2011-07-23 11:02 638232 —-a-w- c:\program files\Internet Explorer\iexplore.exe
2011-08-21 20:40 . 2011-04-20 15:50 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-08-21 20:25 . 2011-06-17 20:13 905104 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-09 00:29 . 2011-07-11 14:07 24496 —-a-w- c:\windows\system32\drivers\sshrmd.sys
2011-08-09 00:29 . 2011-07-11 14:07 181008 —-a-w- c:\windows\system32\drivers\ssidrv.sys
2011-08-09 00:29 . 2011-07-11 14:07 45584 —-a-w- c:\windows\system32\drivers\ssfmonm.sys
2011-08-09 00:25 . 2011-08-09 00:26 ——– dc-h–w- c:\programdata\{61D227D1-25DF-4A97-9428-6C9A27015CDA}
2011-08-09 00:25 . 2011-08-09 00:25 ——– d—–w- c:\program files\Webroot
2011-08-09 00:24 . 2011-08-26 11:11 ——– d–h–w- c:\programdata\Webroot
2011-08-08 21:17 . 2011-08-08 21:17 ——– d–h–w- c:\users\Jessica\AppData\Local\PackageAware
2011-07-31 15:28 . 2011-07-31 16:07 ——– d—–w- c:\program files\PC Tools Security
2011-07-31 15:28 . 2011-07-31 16:07 ——– d—–w- c:\program files\Common Files\PC Tools
2011-07-31 15:26 . 2011-07-31 16:05 ——– d—–w- c:\programdata\PC Tools
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-26 20:38 . 2010-05-19 00:42 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-07-23 11:04 . 2011-08-21 20:40 916480 —-a-w- c:\windows\system32\wininet.dll
2011-07-23 11:00 . 2011-08-21 20:40 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-07-23 10:59 . 2011-08-21 20:40 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-07-23 10:59 . 2011-08-21 20:40 109056 —-a-w- c:\windows\system32\iesysprep.dll
2011-07-23 10:59 . 2011-08-21 20:40 71680 —-a-w- c:\windows\system32\iesetup.dll
2011-07-23 10:03 . 2011-08-21 20:40 385024 —-a-w- c:\windows\system32\html.iec
2011-07-23 09:27 . 2011-08-21 20:40 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2011-07-23 09:25 . 2011-08-21 20:40 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-07-11 13:25 . 2011-08-23 20:36 2048 —-a-w- c:\windows\system32\tzres.dll
2011-07-06 23:52 . 2010-06-21 20:40 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 23:52 . 2010-06-21 20:40 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-20 08:54 . 2011-08-21 20:30 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-06-20 08:54 . 2011-08-21 20:30 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-06-17 16:03 . 2011-08-21 20:47 375808 —-a-w- c:\windows\system32\winsrv.dll
2011-06-02 13:34 . 2011-08-23 20:26 2043392 —-a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-01-30 430080]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HWSetup"="\HWSetup.exe hwSetUP" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-20 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-20 154136]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-20 129560]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"NDSTray.exe"="NDSTray.exe" [BU]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-23 438272]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"RtHDVCpl"="c:\windows\RtHDVCpl.exe" [2008-01-30 4911104]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-07-06 1047656]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-07-06 1047656]
"WebrootTrayApp"="c:\program files\Webroot\Security\Current\Framework\WRTray.exe" [2011-08-09 1382984]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
2008-01-29 21:38 583048 —-a-w- c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1c9ae605c644117;Google Update Service (gupdate1c9ae605c644117);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [2007-10-30 937984]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960]
S1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwf.sys [2007-09-01 20352]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 ssfmonm;ssfmonm;c:\windows\system32\DRIVERS\ssfmonm.sys [2011-07-11 45584]
S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-04 126976]
S2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\Security\Current\Framework\WRConsumerService.exe [2011-08-09 3381184]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.facebook.com/
TCP: DhcpNameServer = [removed] [removed]
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-jswtrayutil - c:\program files\Jumpstart\jswtrayutil.exe
MSConfigStartUp-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\2.bin\M3PLUGIN.DLL
MSConfigStartUp-RegistryMechanic - c:\program files\Registry Mechanic\RMTray.exe
MSConfigStartUp-RoxWatchTray - c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-26 17:09
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
———————— Other Running Processes ————————
.
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\agrsmsvc.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Toshiba\Power Saver\TosCoSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Webroot\Security\current\plugins\antimalware\AEI.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Toshiba\ConfigFree\CFSwMgr.exe
c:\windows\ehome\mcupdate.EXE
.
**************************************************************************
.
Completion time: 2011-08-26 17:17:05 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-26 21:16
.
Pre-Run: 54,762,909,696 bytes free
Post-Run: 56,860,119,040 bytes free
.
- - End Of File - - 14ECBB9EB464E243D5384D642CAF676A
Hi yksnemeg,

I notice some Norton/Symantec entries on your system. You can completely remove these using the tool found here .
———-

Please go ahead and run DDS once more and post both of the logs created into your next reply.
———-

Once you complete this let me know how your system is running. :)
Ok, After all this was done, I would say the computer seems to be running better. I'm still confused about losing my files but they hard drive is still at the same capacity. Is my files lost or jsut really hidden? I still done have the feeling that the virus is gone. Since all the scan we did and there was no results and we didn't seem to remove anything. Let me know what you think. Thanks . DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 8.0.6001.19120 Run by [removed] at 9:23:52 on 2011-08-28 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1014.184 [GMT -4:00] . AV: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {53211D91-0C31-95F2-E3A5-7661FB22889E} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {E840FC75-2A0B-9A7C-D915-4D1380A5C223} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files\Webroot\Security\Current\Framework\WRConsumerService.exe C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\system32\agrsmsvc.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc c:\Toshiba\IVP\swupdate\swupdtmr.exe C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Program Files\Webroot\Security\current\plugins\antimalware\AEI.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Toshiba\Power Saver\TPwrMain.exe C:\Program Files\Toshiba\SmoothView\SmoothView.exe C:\Program Files\Toshiba\FlashCards\TCrdMain.exe C:\Program Files\Apoint2K\Apoint.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Toshiba\ConfigFree\NDSTray.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\taskeng.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\mobsync.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\system32\igfxsrvc.exe C:\Program Files\Toshiba\Utilities\KeNotify.exe C:\Windows\RtHDVCpl.exe C:\Windows\WindowsMobile\wmdc.exe C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Apoint2K\ApMsgFwd.exe C:\Windows\ehome\ehmsas.exe C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.facebook.com/ BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File uRun: [TOSCDSPD] "c:\program files\toshiba\toscdspd\TOSCDSPD.exe" uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [WMPNSCFG] "c:\program files\windows media player\WMPNSCFG.exe" mRun: [IgfxTray] "c:\windows\system32\igfxtray.exe" mRun: [HotKeysCmds] "c:\windows\system32\hkcmd.exe" mRun: [Persistence] "c:\windows\system32\igfxpers.exe" mRun: [TPwrMain] "c:\program files\toshiba\power saver\TPwrMain.EXE" mRun: [SmoothView] "c:\program files\toshiba\smoothview\SmoothView.exe" mRun: [00TCrdMain] "c:\program files\toshiba\flashcards\TCrdMain.exe" mRun: [Apoint] "c:\program files\apoint2k\Apoint.exe" mRun: [NDSTray.exe] NDSTray.exe mRun: [HWSetup] \HWSetup.exe hwSetUP mRun: [SVPWUTIL] "c:\program files\toshiba\utilities\SVPWUTIL.exe" SVPwUTIL mRun: [KeNotify] "c:\program files\toshiba\utilities\KeNotify.exe" mRun: [RtHDVCpl] "c:\windows\RtHDVCpl.exe" mRun: [Windows Mobile Device Center] "%windir%\WindowsMobile\wmdc.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [WebrootTrayApp] "c:\program files\webroot\security\current\framework\WRTray.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{38345E4D-9E2C-42F5-AC8A-C5DAC44F2AD7} : DhcpNameServer = 192.168.2.1 TCP: Interfaces\{C731D3F7-418F-474D-8D48-3350BBFC41FE} : DhcpNameServer = 192.168.0.1 TCP: Interfaces\{E3C2285E-83FC-426B-9728-1960F917DBC1} : DhcpNameServer = [removed] [removed] Notify: igfxcui - igfxdev.dll . ============= SERVICES / DRIVERS =============== . R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\drivers\jswpslwf.sys [2008-3-20 20352] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952] R2 ssfmonm;ssfmonm;c:\windows\system32\drivers\ssfmonm.sys [2011-8-8 45584] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] S2 gupdate1c9ae605c644117;Google Update Service (gupdate1c9ae605c644117);"c:\program files\google\update\googleupdate.exe" /svc –> c:\program files\google\update\GoogleUpdate.exe [?] S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\jumpstart\jswpsapi.exe [2008-3-20 937984] S4 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2007-12-25 40960] . =============== Created Last 30 ================ . 2011-08-26 21:17:08 ——– d—–w- c:\users\jessica\appdata\local\temp 2011-08-26 21:08:13 ——– d—–w- C:\$RECYCLE.BIN 2011-08-26 20:47:55 98816 —-a-w- c:\windows\sed.exe 2011-08-26 20:47:55 518144 —-a-w- c:\windows\SWREG.exe 2011-08-26 20:47:55 256000 —-a-w- c:\windows\PEV.exe 2011-08-26 20:47:55 208896 —-a-w- c:\windows\MBR.exe 2011-08-26 20:47:38 ——– d—–w- C:\ComboFix 2011-08-26 16:57:44 7152464 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{a3235e38-9693-4e20-ba2d-91495ecd4381}\mpengine.dll 2011-08-25 14:37:14 ——– d—–w- c:\program files\HD Tune 2011-08-24 10:46:31 ——– d—–w- c:\program files\ESET 2011-08-23 20:36:20 2048 —-a-w- c:\windows\system32\tzres.dll 2011-08-23 20:26:56 2043392 —-a-w- c:\windows\system32\win32k.sys 2011-08-22 01:25:29 876032 —-a-w- c:\windows\system32\XpsPrint.dll 2011-08-21 23:49:03 2048 —-a-w- c:\windows\system32\winrsmgr.dll 2011-08-21 23:47:56 246272 —-a-w- c:\windows\system32\WSManHTTPConfig.exe 2011-08-21 23:47:50 1181696 —-a-w- c:\windows\system32\WsmSvc.dll 2011-08-21 20:47:38 292864 —-a-w- c:\windows\system32\atmfd.dll 2011-08-21 20:47:36 34304 —-a-w- c:\windows\system32\atmlib.dll 2011-08-21 20:47:32 375808 —-a-w- c:\windows\system32\winsrv.dll 2011-08-21 20:47:29 69632 —-a-w- c:\windows\system32\drivers\bowser.sys 2011-08-21 20:47:23 75264 —-a-w- c:\windows\system32\drivers\dfsc.sys 2011-08-21 20:47:17 1205080 —-a-w- c:\windows\system32\ntdll.dll 2011-08-21 20:45:58 305152 —-a-w- c:\windows\system32\drivers\srv.sys 2011-08-21 20:45:51 79872 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-08-21 20:45:51 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-08-21 20:45:50 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-08-21 20:45:41 86528 —-a-w- c:\windows\system32\dnsrslvr.dll 2011-08-21 20:45:41 25088 —-a-w- c:\windows\system32\dnscacheugc.exe 2011-08-21 20:45:33 273408 —-a-w- c:\windows\system32\drivers\afd.sys 2011-08-21 20:43:14 28672 —-a-w- c:\windows\system32\Apphlpdm.dll 2011-08-21 20:43:13 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2011-08-21 20:43:01 429056 —-a-w- c:\windows\system32\EncDec.dll 2011-08-21 20:42:57 322560 —-a-w- c:\windows\system32\sbe.dll 2011-08-21 20:42:55 177664 —-a-w- c:\windows\system32\mpg2splt.ax 2011-08-21 20:42:54 153088 —-a-w- c:\windows\system32\sbeio.dll 2011-08-21 20:41:09 739328 —-a-w- c:\windows\system32\inetcomm.dll 2011-08-21 20:41:04 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2011-08-21 20:39:55 2067968 —-a-w- c:\windows\system32\mstscax.dll 2011-08-21 20:39:54 677888 —-a-w- c:\windows\system32\mstsc.exe 2011-08-21 20:30:15 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-08-21 20:30:10 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-08-21 20:25:11 905104 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-08-09 10:48:03 276992 —-a-w- c:\windows\system32\schannel.dll 2011-08-09 00:29:09 45584 —-a-w- c:\windows\system32\drivers\ssfmonm.sys 2011-08-09 00:29:09 24496 —-a-w- c:\windows\system32\drivers\sshrmd.sys 2011-08-09 00:29:09 181008 —-a-w- c:\windows\system32\drivers\ssidrv.sys 2011-08-09 00:25:46 ——– dc-h–w- c:\programdata\{61D227D1-25DF-4A97-9428-6C9A27015CDA} 2011-08-09 00:25:22 ——– d—–w- c:\program files\Webroot 2011-08-09 00:24:02 ——– d–h–w- c:\programdata\Webroot 2011-08-08 21:17:21 ——– d–h–w- c:\users\jessica\appdata\local\PackageAware 2011-07-31 15:28:07 ——– d—–w- c:\program files\PC Tools Security 2011-07-31 15:28:07 ——– d—–w- c:\program files\common files\PC Tools 2011-07-31 15:26:16 ——– d—–w- c:\programdata\PC Tools . ==================== Find3M ==================== . 2011-08-26 20:38:51 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-07-23 11:04:29 916480 —-a-w- c:\windows\system32\wininet.dll 2011-07-23 11:00:05 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-07-23 10:59:52 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2011-07-23 10:59:34 71680 —-a-w- c:\windows\system32\iesetup.dll 2011-07-23 10:59:34 109056 —-a-w- c:\windows\system32\iesysprep.dll 2011-07-23 10:03:47 385024 —-a-w- c:\windows\system32\html.iec 2011-07-23 09:27:04 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2011-07-23 09:25:38 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-07-06 23:52:42 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-07-06 23:52:42 22712 —-a-w- c:\windows\system32\drivers\mbam.sys . ============= FINISH: 9:31:00.49 ===============
Hi yksnemeg,

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.

I would say the computer seems to be running better.

:thumbup:

all the scan we did and there was no results and we didn't seem to remove anything. Let me know what you think. Thanks

It may not have seemed like it but there was malware that we removed using ComboFix. :) Your system may have been more infected but since you were using system restore to an earlier time some of it may not have been showing, but have now worries as we will be removing all of them when we uninstall ComboFix.
———-

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following text into the Run box as shown and click OK.
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]
———-

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Enable Protected Mode in Internet Explorer. This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:
  • Open Internet Explorer
  • Click on Tools > Internet Options
  • Press Security tab
  • Select Internet zone then place check next to Enable Protected Mode if not already done
  • Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
  • Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
3. Use and Update an Anti-Virus Software - I can not overemphasize the need for you to use and update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here.
**Do not install more than one firewall program because they will conflict with each other**

5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

6. Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

7. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

8. WOT , Web of Trust, As 'Googling' is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
  • Green to go
  • Yellow for caution
  • Red to stop
WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

9. Install Spybot - Search and Destroy - Download and install Spybot - Search and Destroy with its TeaTimer option. This will provide real time spyware and hijacker protection on your computer alongside your virus protection. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D and Ad-aware

10. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?


Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI