Spyware / Malware / Virus Removal
Can you Please Help?
15 min read
yksnemeg
Topic Starter
I have had a virus for several weeks and I have been through multiple anit-spywares and other programs have been what seems to have tamed the virus, but now it has escalated to higher needs.. It is telling me i have regestry corruption. I ran HJT and tried to post it but your site told me I have an outdated HJT so I downloaded the newer version adn now can't get it to save to a log file so that I can paste it on here for help. Please help. thanks
jeffce
Hi and Welcome!!
My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.
Vista and Windows 7 users:
These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
Having said that….Let's get going!!
- I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
- The fixes are specific to your problem and should only be used for the issues on this machine.
- Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
- It's often worth reading through these instructions and printing them for ease of reference.
- If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
- Please reply to this thread. Do not start a new topic.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.
Vista and Windows 7 users:
These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
Having said that….Let's get going!!
yksnemeg
Hi, thanks for help in adv advance. I have been fighting off a virus for several minths now. I have ran "Malwarebytes Anti-Malware" and I also have "Webroot Anti-Spyware with Anti-virus" I have used HJT in the past and did some good on previous viruses but this one seems to be getting the best of me. I recently am having "system error" "corrupted registry" warnings and it would pop up a "system repair screen" and tell me i have bad sectors and etc. I have int he last 2 days had to restore my computer to an earlier date to be able to reboot. I had to restore last night after i posted and in turn i went back to the HJT version 2.0.2 which i am posting below. after downloading the new version 2.0.4 then I was not able to run it as admin. by right clicking on the icon. i have vista if I forgot to mention. Thanks again.
Logfile of Trend Micro HijackThis
Scan saved at 6:36:25 AM, on 8/23/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19120)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10q_ActiveX.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] "C:\Windows\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\Windows\system32\hkcmd.exe"
O4 - HKLM\..\Run: [Persistence] "C:\Windows\system32\igfxpers.exe"
O4 - HKLM\..\Run: [TPwrMain] "C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE"
O4 - HKLM\..\Run: [SmoothView] "C:\Program Files\Toshiba\SmoothView\SmoothView.exe"
O4 - HKLM\..\Run: [00TCrdMain] "C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [jswtrayutil] "C:\Program Files\Jumpstart\jswtrayutil.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] "C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe" SVPwUTIL
O4 - HKLM\..\Run: [KeNotify] "C:\Program Files\TOSHIBA\Utilities\KeNotify.exe"
O4 - HKLM\..\Run: [RtHDVCpl] "C:\Windows\RtHDVCpl.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Mobile Device Center] "%windir%\WindowsMobile\wmdc.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [WebrootTrayApp] "C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe"
O4 - HKCU\..\Run: [TOSCDSPD] "C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe"
O4 - HKCU\..\Run: [ehTray.exe] "C:\Windows\ehome\ehTray.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Update Service (gupdate1c9ae605c644117) (gupdate1c9ae605c644117) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Jumpstart\jswpsapi.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Security\current\plugins\antimalware\AEI.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\Security\Current\Framework\WRConsumerService.exe
–
End of file - 7874 bytes
Logfile of Trend Micro HijackThis
Scan saved at 6:36:25 AM, on 8/23/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19120)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10q_ActiveX.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] "C:\Windows\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\Windows\system32\hkcmd.exe"
O4 - HKLM\..\Run: [Persistence] "C:\Windows\system32\igfxpers.exe"
O4 - HKLM\..\Run: [TPwrMain] "C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE"
O4 - HKLM\..\Run: [SmoothView] "C:\Program Files\Toshiba\SmoothView\SmoothView.exe"
O4 - HKLM\..\Run: [00TCrdMain] "C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [jswtrayutil] "C:\Program Files\Jumpstart\jswtrayutil.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] "C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe" SVPwUTIL
O4 - HKLM\..\Run: [KeNotify] "C:\Program Files\TOSHIBA\Utilities\KeNotify.exe"
O4 - HKLM\..\Run: [RtHDVCpl] "C:\Windows\RtHDVCpl.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Mobile Device Center] "%windir%\WindowsMobile\wmdc.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [WebrootTrayApp] "C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe"
O4 - HKCU\..\Run: [TOSCDSPD] "C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe"
O4 - HKCU\..\Run: [ehTray.exe] "C:\Windows\ehome\ehTray.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Update Service (gupdate1c9ae605c644117) (gupdate1c9ae605c644117) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Jumpstart\jswpsapi.exe
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Security\current\plugins\antimalware\AEI.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\Security\Current\Framework\WRConsumerService.exe
–
End of file - 7874 bytes
jeffce
Hi yksnemeg,
Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
Do not re-enable these drivers until otherwise instructed.
———-
Please download DDS from either of these links
LINK 1
LINK 2
and save it to your desktop.
Please include the contents of the following in your next reply:
DDS.txt
Attach.txt
———-
Please download aswMBR to your desktop.
[external image: Posted Image]
Click the image to enlarge it
———-
In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe.
Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
- The application window will appear
- Click the Disable button to disable your CD Emulation drivers
- Click Yes to continue
- A 'Finished!' message will appear
- Click OK
- If it needs to, DeFogger may ask to reboot the machine - click OK
Do not re-enable these drivers until otherwise instructed.
———-
Please download DDS from either of these links
LINK 1
LINK 2
and save it to your desktop.
- Disable any script blocking protection
- Double click dds to run the tool.
- When done, two DDS.txt's will open.
- Save both reports to your desktop.
Please include the contents of the following in your next reply:
DDS.txt
Attach.txt
———-
Please download aswMBR to your desktop.
- Double click the aswMBR icon to run it.
Vista and Windows 7 users right click the icon and choose "Run as administrator". - Click the Scan button to start scan.
- When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
[external image: Posted Image]
Click the image to enlarge it
———-
In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe.
yksnemeg
Thank you again for taking your time to help me. I have done as requested and now posted what was asked. Let me know if I did something wrong and i will do it again.
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.19120
Run by [removed] at 16:25:04 on 2011-08-23
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\Webroot\Security\Current\Framework\WRConsumerService.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\agrsmsvc.exe
C:\Windows\System32\mobsync.exe
c:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Webroot\Security\current\plugins\antimalware\AEI.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Webroot\Security\current\plugins\antimalware\SSU.EXE
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10q_ActiveX.exe
C:\Windows\system32\taskeng.exe
C:\Windows\ehome\mcupdate.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\RacAgent.exe
C:\Users\Jessica\Desktop\Defogger.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\vssvc.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\Jessica\Desktop\dds.com
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k swprv
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.facebook.com/
uDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [TOSCDSPD] "c:\program files\toshiba\toscdspd\TOSCDSPD.exe"
uRun: [ehTray.exe] "c:\windows\ehome\ehTray.exe"
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [WMPNSCFG] "c:\program files\windows media player\WMPNSCFG.exe"
mRun: [IgfxTray] "c:\windows\system32\igfxtray.exe"
mRun: [HotKeysCmds] "c:\windows\system32\hkcmd.exe"
mRun: [Persistence] "c:\windows\system32\igfxpers.exe"
mRun: [TPwrMain] "c:\program files\toshiba\power saver\TPwrMain.EXE"
mRun: [SmoothView] "c:\program files\toshiba\smoothview\SmoothView.exe"
mRun: [00TCrdMain] "c:\program files\toshiba\flashcards\TCrdMain.exe"
mRun: [Apoint] "c:\program files\apoint2k\Apoint.exe"
mRun: [jswtrayutil] "c:\program files\jumpstart\jswtrayutil.exe"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [NDSTray.exe] NDSTray.exe
mRun: [HWSetup] \HWSetup.exe hwSetUP
mRun: [SVPWUTIL] "c:\program files\toshiba\utilities\SVPWUTIL.exe" SVPwUTIL
mRun: [KeNotify] "c:\program files\toshiba\utilities\KeNotify.exe"
mRun: [RtHDVCpl] "c:\windows\RtHDVCpl.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Windows Mobile Device Center] "%windir%\WindowsMobile\wmdc.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [WebrootTrayApp] "c:\program files\webroot\security\current\framework\WRTray.exe"
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{38345E4D-9E2C-42F5-AC8A-C5DAC44F2AD7} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{C731D3F7-418F-474D-8D48-3350BBFC41FE} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{E3C2285E-83FC-426B-9728-1960F917DBC1} : DhcpNameServer = [removed] [removed]
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? ConfigFree Service;ConfigFree Service
R? gupdate1c9ae605c644117;Google Update Service (gupdate1c9ae605c644117)
R? jswpsapi;Jumpstart Wifi Protected Setup
R? RkHit;RkHit
R? TpChoice;Touch Pad Detection Filter driver
R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0
S? FontCache;Windows Font Cache Service
S? jswpslwf;JumpStart Wireless Filter Driver
S? ssfmonm;ssfmonm
S? TOSHIBA SMART Log Service;TOSHIBA SMART Log Service
S? WebrootSpySweeperService;Webroot Spy Sweeper Engine
S? WRConsumerService;Webroot Client Service
.
=============== File Associations ===============
.
regfile=regedit.exe "%1" %*
scrfile="%1" %*
.
=============== Created Last 30 ================
.
2011-08-23 20:24:26 7152464 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{f9058879-6eb3-438f-b441-711ae7d18b01}\mpengine.dll
2011-08-22 20:38:28 7152464 ——w- c:\programdata\microsoft\windows defender\definition updates\{8b666cfc-5764-4042-8a7e-e19923495572}\mpengine.dll
2011-08-22 01:25:29 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-08-21 23:49:03 2048 —-a-w- c:\windows\system32\winrsmgr.dll
2011-08-21 23:47:56 246272 —-a-w- c:\windows\system32\WSManHTTPConfig.exe
2011-08-21 23:47:50 1181696 —-a-w- c:\windows\system32\WsmSvc.dll
2011-08-21 20:47:38 292864 —-a-w- c:\windows\system32\atmfd.dll
2011-08-21 20:47:36 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-08-21 20:47:32 375808 —-a-w- c:\windows\system32\winsrv.dll
2011-08-21 20:47:29 69632 —-a-w- c:\windows\system32\drivers\bowser.sys
2011-08-21 20:47:23 75264 —-a-w- c:\windows\system32\drivers\dfsc.sys
2011-08-21 20:47:17 1205080 —-a-w- c:\windows\system32\ntdll.dll
2011-08-21 20:45:58 305152 —-a-w- c:\windows\system32\drivers\srv.sys
2011-08-21 20:45:51 79872 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-08-21 20:45:51 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-21 20:45:50 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-08-21 20:45:41 86528 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-08-21 20:45:41 25088 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-08-21 20:45:33 273408 —-a-w- c:\windows\system32\drivers\afd.sys
2011-08-21 20:43:14 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2011-08-21 20:43:13 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-08-21 20:43:01 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-08-21 20:42:57 322560 —-a-w- c:\windows\system32\sbe.dll
2011-08-21 20:42:55 177664 —-a-w- c:\windows\system32\mpg2splt.ax
2011-08-21 20:42:54 153088 —-a-w- c:\windows\system32\sbeio.dll
2011-08-21 20:41:09 739328 —-a-w- c:\windows\system32\inetcomm.dll
2011-08-21 20:41:04 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2011-08-21 20:39:55 2067968 —-a-w- c:\windows\system32\mstscax.dll
2011-08-21 20:39:54 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-08-21 20:30:15 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-08-21 20:30:10 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-08-21 20:25:11 905104 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-09 10:48:03 276992 —-a-w- c:\windows\system32\schannel.dll
2011-08-09 00:29:09 45584 —-a-w- c:\windows\system32\drivers\ssfmonm.sys
2011-08-09 00:29:09 24496 —-a-w- c:\windows\system32\drivers\sshrmd.sys
2011-08-09 00:29:09 181008 —-a-w- c:\windows\system32\drivers\ssidrv.sys
2011-08-09 00:25:46 ——– dc-h–w- c:\programdata\{61D227D1-25DF-4A97-9428-6C9A27015CDA}
2011-08-09 00:25:22 ——– d—–w- c:\program files\Webroot
2011-08-09 00:24:02 ——– d–h–w- c:\programdata\Webroot
2011-08-08 21:17:21 ——– d–h–w- c:\users\jessica\appdata\local\PackageAware
2011-07-31 15:28:07 ——– d—–w- c:\program files\PC Tools Security
2011-07-31 15:28:07 ——– d—–w- c:\program files\common files\PC Tools
2011-07-31 15:26:16 ——– d—–w- c:\programdata\PC Tools
.
==================== Find3M ====================
.
2011-07-23 11:04:29 916480 —-a-w- c:\windows\system32\wininet.dll
2011-07-23 11:00:05 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-07-23 10:59:52 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-07-23 10:59:34 71680 —-a-w- c:\windows\system32\iesetup.dll
2011-07-23 10:59:34 109056 —-a-w- c:\windows\system32\iesysprep.dll
2011-07-23 10:03:47 385024 —-a-w- c:\windows\system32\html.iec
2011-07-23 09:27:04 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2011-07-23 09:25:38 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-07-06 23:52:42 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 23:52:42 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
.
============= FINISH: 16:37:04.72 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 3/20/2008 3:39:02 AM
System Uptime: 8/23/2011 4:01:28 PM (0 hours ago)
.
Motherboard: TOSHIBA | | ISKAA
Processor: Intel® Pentium® Dual CPU T2370 @ 1.73GHz | U2E1 | 1067/mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 110 GiB total, 51.478 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
2007 Microsoft Office system
Activation Assistant for the 2007 Microsoft Office suites
Adobe Flash Player 10 ActiveX
Adobe Reader 8.1.3
Adobe Shockwave Player 11.5
ALPS Touch Pad Driver
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Atheros Driver Installation Program
Atheros Wi-Fi Protected Setup Library
AutoUpdate
BlackBerry Device Software v4.5.0 for the BlackBerry 8330 smartphone
Bluetooth Stack for Windows by Toshiba
Bonjour
CD/DVD Drive Acoustic Silencer
DivX Player
DivX Pro Trial
DVD MovieFactory for TOSHIBA
GearDrvs
Google Update Helper
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Product Detection
Intel® Graphics Media Accelerator Driver
iPAQ 200 Improvement
Java™ 6 Update 21
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
Lexi-CALC
Lexi-CALC Calculations (Step 2)
Lexi-Comp Analyze (remove only)
Lexi-Comp Interact Reader (remove only)
Lexi-Comp Reader (remove only)
Lexi-CONNECT
LiveUpdate 3.2 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Malwarebytes' Anti-Malware version 1.51.1.1800
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Edition 2003
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft XML Parser
Move Media Player
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 and SOAP Toolkit 3.0
Norton 360
OGA Notifier 2.0.0048.0
QuickTime
Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
Realtek High Definition Audio Driver
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2509488)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft Office 2007 System (KB2541012)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2541007)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Windows Media Encoder (KB2447961)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Encoder (KB979332)
Spelling Dictionaries Support For Adobe Reader 8
Texas Instruments PCIxx21/x515/xx12 drivers.
TIPCI
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Disc Creator
TOSHIBA DVD PLAYER
TOSHIBA Extended Tiles for Windows Mobility Center
TOSHIBA Flash Cards Support Utility
TOSHIBA Games
TOSHIBA Hardware Setup
Toshiba Registration
TOSHIBA SD Memory Utilities
TOSHIBA Software Modem
TOSHIBA Software Upgrades
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
TrueCrypt
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Outlook 2007 (KB2509470)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (KB2586924)
Utility Common Driver
Webroot Software
Windows Live ID Sign-in Assistant
Windows Media Encoder 9 Series
Windows Mobile Device Center
Windows Mobile Device Center Driver Update
.
==== Event Viewer Messages From Past Week ========
.
8/23/2011 4:03:46 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Cdr4_xp
8/23/2011 4:03:45 PM, Error: Service Control Manager [7022] - The Webroot Spy Sweeper Engine service hung on starting.
8/23/2011 4:03:29 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
8/23/2011 4:03:29 PM, Error: Service Control Manager [7000] - The Google Update Service (gupdate1c9ae605c644117) service failed to start due to the following error: The system cannot find the path specified.
8/22/2011 9:17:01 PM, Error: Service Control Manager [7043] - The Windows Update service did not shut down properly after receiving a preshutdown control.
8/22/2011 9:11:47 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x800f0816: Security Update for Windows Vista (KB2555917).
8/21/2011 8:59:36 PM, Error: Microsoft-Windows-Kernel-General [5] - {Registry Hive Recovered} Registry hive (file): '\??\C:\PROGRA~1\Webroot\Security\Current\plugins\ANTIMA~1\wrstemp\SST-30~1.TMP' was corrupted and it has been recovered. Some data might have been lost.
8/21/2011 5:09:43 PM, Error: Microsoft-Windows-Windows Defender [2004] - Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted: Current Error Code: 0x8050a001 Error description: The program can't find definition files that help detect unwanted software. Check for updates to the definition files, and then try again. For information on installing updates, see Help and Support. Signatures loading: Backup Loading signature version: 1.111.35.0 Loading engine version: 1.1.7104.0
8/21/2011 4:28:57 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Windows Defender - KB915597 (Definition 1.111.216.0).
8/21/2011 3:49:37 PM, Error: Service Control Manager [7022] - The KtmRm for Distributed Transaction Coordinator service hung on starting.
8/21/2011 3:46:38 PM, Error: Service Control Manager [7022] - The Background Intelligent Transfer Service service hung on starting.
8/21/2011 3:46:37 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
8/21/2011 2:48:16 PM, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
8/21/2011 2:16:46 PM, Error: Service Control Manager [7038] - The wscsvc service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: A system shutdown is in progress. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
8/21/2011 2:16:46 PM, Error: Service Control Manager [7000] - The Security Center service failed to start due to the following error: The service did not start due to a logon failure.
8/21/2011 2:16:44 PM, Error: Service Control Manager [7043] - The Group Policy Client service did not shut down properly after receiving a preshutdown control.
8/18/2011 9:06:05 PM, Error: EventLog [6008] - The previous system shutdown at 9:03:30 PM on 8/18/2011 was unexpected.
.
==== End Of File ===========================
aswMBR version 0.9.8.978 Copyright© 2011 AVAST Software
Run date: 2011-08-23 16:54:50
—————————–
16:54:50.528 OS Version: Windows 6.0.6002 Service Pack 2
16:54:50.528 Number of processors: 2 586 0xF0D
16:54:50.528 ComputerName: JESSICA-PC UserName: Jessica
16:54:58.484 Initialize success
16:56:19.703 AVAST engine defs: 11082300
16:56:24.898 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4
16:56:24.898 Disk 0 Vendor: TOSHIBA_MK1246GSX LB213M Size: 114473MB BusType: 3
16:56:28.408 Disk 0 MBR read successfully
16:56:28.408 Disk 0 MBR scan
16:56:29.172 Disk 0 Windows VISTA default MBR code
16:56:29.235 Disk 0 scanning sectors +234440704
16:56:29.453 Disk 0 scanning C:\Windows\system32\drivers
16:57:05.380 Service scanning
16:57:08.281 Modules scanning
16:57:18.655 Disk 0 trace - called modules:
16:57:18.671 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll PCIIDEX.SYS msahci.sys dxgkrnl.sys igdkmd32.sys watchdog.sys tcpip.sys NETIO.SYS NDIS.SYS athr.sys
16:57:18.687 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85667808]
16:57:18.687 3 CLASSPNP.SYS[8317f8b3] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-4[0x84f33b98]
16:57:19.981 AVAST engine scan C:\Windows
16:57:29.544 AVAST engine scan C:\Windows\system32
17:02:12.981 AVAST engine scan C:\Windows\system32\drivers
17:02:37.457 AVAST engine scan C:\Users\Jessica
17:03:29.717 Disk 0 MBR has been saved successfully to "C:\Users\Jessica\Desktop\MBR.dat"
17:03:29.733 The log file has been saved successfully to "C:\Users\Jessica\Desktop\aswMBR.txt"
Thanks again.
jeffce
Hi yksnemeg,
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
———-
I notice that you have Malwarebytes on your system already.
Please open this program, perform and Update and then run a Quick Scan.
It will create a log that I will need in your next reply.
———-
ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan
Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.
———-
In your next reply I will need the logs created by SystemLook, Malwarebytes and ESET Online Scanner.
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
- Double-click SystemLook.exe to run it.
- Copy the content of the following codebox into the main textfield:
:dir c:\programdata\{61D227D1-25DF-4A97-9428-6C9A27015CDA} - Click the Look button to start the scan.
- When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
———-
I notice that you have Malwarebytes on your system already.
It will create a log that I will need in your next reply.
———-
ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan
Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.
- Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan - Click the [external image: Posted Image] button.
- For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
- Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
- Double click on the [external image: Posted Image] icon on your desktop.
- Check [external image: Posted Image]
- Click the Start button.
- Accept any security warnings from your browser.
- Check [external image: Posted Image]
- Make sure that the option "Remove found threats" is Unchecked
- Push the Start button.
- ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time. - When the scan completes, push [external image: Posted Image]
- Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply. - Push the Back button.
- Push Finish
———-
In your next reply I will need the logs created by SystemLook, Malwarebytes and ESET Online Scanner.
yksnemeg
Ok, I believe to have done what is asked, let me know if I haven't. I would like to mention that before i had to restore my computer to a previous date, that Malware found 3 trojan viruses but as you can see now there are none found. Let me know what the next steps are and thanks again.
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7551
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19120
8/24/2011 8:52:36 AM
mbam-log-2011-08-24 (08-52-35).txt
Scan type: Quick scan
Objects scanned: 162991
Time elapsed: 8 minute(s), 18 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
From the ESETScan.txt:
C:\Users\Jessica\AppData\Local\Temp\tmp5D5D.tmp a variant of Win32/Kryptik.RYO trojan
SystemLook 30.07.11 by jpshortstuff
Log created at 08:42 on 24/08/2011 by Jessica
Administrator - Elevation successful
========== dir ==========
c:\programdata\{61D227D1-25DF-4A97-9428-6C9A27015CDA} - Parameters: "(none)"
—Files—
instance.dat –a–c- 98 bytes [00:26 09/08/2011] [00:26 09/08/2011]
mia.lib –a–c- 575060 bytes [00:26 09/08/2011] [22:01 21/07/2011]
WRInstall.dat –a–c- 231 bytes [00:26 09/08/2011] [00:26 09/08/2011]
WRInstall.exe –a–c- 3329056 bytes [00:26 09/08/2011] [22:01 21/07/2011]
WRInstall.lan –a–c- 9 bytes [00:26 09/08/2011] [00:26 09/08/2011]
WRInstall.lnk –a–c- 0 bytes [00:26 09/08/2011] [00:26 09/08/2011]
WRInstall.msi –a–c- 412160 bytes [00:26 09/08/2011] [22:01 21/07/2011]
WRInstall.par –a–c- 2787 bytes [00:26 09/08/2011] [00:26 09/08/2011]
WRInstall.res –a–c- 16536190 bytes [00:26 09/08/2011] [22:01 21/07/2011]
{8B287B75-DF8D-40C8-9620-8E4492C38EF1} –a–c- 0 bytes [00:26 09/08/2011] [00:26 09/08/2011]
—Folders—
OFFLINE d—-c- [00:25 09/08/2011]
-= EOF =-
I hope this helps. Thanks
jeffce
Hi yksnemeg,
Things are looking pretty good regarding malware. What remaining issues do you have?
———-
First open an elevated command prompt > Click Start and type cmd in Start Search.
When cmd.exe populates above, right click it and select Run as Administrator to open an elevated command prompt.
Copy and paste the bolded line below into the command prompt and press Enter.
del C:\Users\Jessica\AppData\Local\Temp\tmp5D5D.tmp /f /q
———-
Please download JavaRa to your desktop and unzip it to its own
folder
You have an older version of Adobe Reader. You can download the current version HERE
You may want to consider Foxit Reader instead. It may be a bit lighter on resources.
Visit their support forum
Foxit Forum
In either case you should uninstall Adobe 8 first. Be sure to move any PDF documents to another folder first though.
———-
Download TFC to your desktop
Please download HD Tune (the free version not the trial), run an error scan on your primary harddrive (full not quick) and report back if any blocks aren't green. It tests your hard drive for bad sectors.
Things are looking pretty good regarding malware. What remaining issues do you have?
———-
First open an elevated command prompt > Click Start and type cmd in Start Search.
When cmd.exe populates above, right click it and select Run as Administrator to open an elevated command prompt.
Copy and paste the bolded line below into the command prompt and press Enter.
del C:\Users\Jessica\AppData\Local\Temp\tmp5D5D.tmp /f /q
———-
Please download JavaRa to your desktop and unzip it to its own
folder
- Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
click Remove Older Versions. - Accept any prompts.
- Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
- Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
Java Runtime Environment (JRE) version for your computer.
You have an older version of Adobe Reader. You can download the current version HERE
You may want to consider Foxit Reader instead. It may be a bit lighter on resources.
Visit their support forum
Foxit Forum
In either case you should uninstall Adobe 8 first. Be sure to move any PDF documents to another folder first though.
———-
Download TFC to your desktop
- Close any open windows.
- Double click the TFC icon to run the program
- TFC will close all open programs itself in order to run,
- Click the Start button to begin the process.
- Allow TFC to run uninterrupted.
- The program should not take long to finish it's job
- Once its finished it should automatically reboot your machine,
- if it doesn't, manually reboot to ensure a complete clean
Please download HD Tune (the free version not the trial), run an error scan on your primary harddrive (full not quick) and report back if any blocks aren't green. It tests your hard drive for bad sectors.
yksnemeg
I have done as requested and here is the results.
Microsoft Windows [Version 6.0.6002]
Copyright © 2006 Microsoft Corporation. All rights reserved.
C:\Users\Jessica>del C:\Users\Jessica\AppData\Local\Temp\tmp5D5D.tmp /f /q
Could Not Find C:\Users\Jessica\AppData\Local\Temp\tmp5D5D.tmp
C:\Users\Jessica>
When I got into the Javara website. it gave me several options int eh javare section to download. I didn't know which one to download. please advise.
I downloaded the new version of Adobe reader
I ran the TFC.
I downloaded the HD Tune and ran. All sectors were green.
As far as other concerns and issues. I am now having the issue that my web browser screen is in larger or zoomed feeling. the word fonts have not changed but it seems as if the images and screen features are larger. I'm confused about malwarebytes and how it seems not to recongnize viruses when there are some. And how much can webroot really do? Do I have my settings wrong? are programs "clashing" with each other. The computer is very slow to start and after booting is very sluggish when opening programs and the web. I have notice I have lost all my desktop icons and shortcuts prior to talking to you. losing some pictures and what nots, but if I look at the capacity of the C: drive, it is unchanged making me think all of it is still available. Let me know and Thanks again for all your help so far.
yksnemeg
ok, from exploring around.. found out that my web browser was set t o zoom of 125%.. that one's fixed.. thanks
jeffce
Hi yksnemeg,
Right now I am looking further into your system to try and find the cause of the slowness in your system. I will see what I can come up with.
———-
Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2
**Note: It is important that it is saved directly to your desktop**
——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–
Double click on ComboFix.exe & follow the prompts.
In your next reply please post the log created by ComboFix.
Right now I am looking further into your system to try and find the cause of the slowness in your system. I will see what I can come up with.
While they are both good programs, no program can guarantee 100% security.I'm confused about malwarebytes and how it seems not to recongnize viruses when there are some. And how much can webroot really do?
How about doing this. Go to Start > Control Panel > Programs and Features and find all Java entries and delete them. Now go here to download Java and then install it.When I got into the Javara website. it gave me several options int eh javare section to download. I didn't know which one to download. please advise.
———-
Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2
**Note: It is important that it is saved directly to your desktop**
——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–
Double click on ComboFix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the C:\ComboFix.txt for further review.
In your next reply please post the log created by ComboFix.
yksnemeg
Ok, here is teh latest info requested. Let me know what my next steps are. Thanks.
ComboFix 11-08-26.04 - Jessica 08/26/2011 16:51:22.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1014.339 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {53211D91-0C31-95F2-E3A5-7661FB22889E}
SP: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {E840FC75-2A0B-9A7C-D915-4D1380A5C223}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\xp
c:\programdata\xp\EBLib.dll
c:\programdata\xp\TPwSav.sys
c:\users\Jessica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tool
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\system32\no
c:\windows\system32\no\toscdspd.cpl.mui
c:\windows\system32\SV
c:\windows\system32\SV\toscdspd.cpl.mui
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_RKHIT
——-\Service_RkHit
.
.
((((((((((((((((((((((((( Files Created from 2011-07-26 to 2011-08-26 )))))))))))))))))))))))))))))))
.
.
2011-08-26 21:03 . 2011-08-26 21:10 ——– d—–w- c:\users\Jessica\AppData\Local\temp
2011-08-26 21:03 . 2011-08-26 21:03 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-08-26 16:57 . 2011-08-16 12:48 7152464 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A3235E38-9693-4E20-BA2D-91495ECD4381}\mpengine.dll
2011-08-25 14:37 . 2011-08-25 14:37 ——– d—–w- c:\program files\HD Tune
2011-08-25 14:16 . 2011-08-25 14:16 ——– d—–w- c:\program files\Common Files\Adobe
2011-08-25 14:11 . 2011-08-25 14:11 ——– d—–w- c:\program files\Common Files\Adobe AIR
2011-08-24 10:46 . 2011-08-24 10:46 ——– d—–w- c:\program files\ESET
2011-08-21 20:47 . 2011-02-16 14:02 292864 —-a-w- c:\windows\system32\atmfd.dll
2011-08-21 20:47 . 2011-02-16 16:16 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-08-21 20:47 . 2011-02-22 13:23 69632 —-a-w- c:\windows\system32\drivers\bowser.sys
2011-08-21 20:47 . 2011-04-14 14:59 75264 —-a-w- c:\windows\system32\drivers\dfsc.sys
2011-08-21 20:46 . 2011-01-20 16:37 638336 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-08-21 20:46 . 2011-01-20 16:08 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-08-21 20:46 . 2011-01-20 16:07 37376 —-a-w- c:\windows\system32\cdd.dll
2011-08-21 20:45 . 2011-02-18 14:03 305152 —-a-w- c:\windows\system32\drivers\srv.sys
2011-08-21 20:45 . 2011-07-06 15:31 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-21 20:45 . 2011-04-29 13:24 79872 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-08-21 20:45 . 2011-04-29 13:24 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-08-21 20:45 . 2011-03-02 15:44 86528 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-08-21 20:45 . 2009-05-04 09:59 25088 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-08-21 20:45 . 2011-04-21 13:58 273408 —-a-w- c:\windows\system32\drivers\afd.sys
2011-08-21 20:44 . 2011-04-29 13:25 146432 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-08-21 20:44 . 2011-04-29 13:25 102400 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-08-21 20:44 . 2011-01-20 16:08 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-08-21 20:44 . 2011-01-20 16:08 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-08-21 20:44 . 2011-01-20 14:12 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-08-21 20:44 . 2011-01-20 13:47 683008 —-a-w- c:\windows\system32\d2d1.dll
2011-08-21 20:44 . 2011-02-22 13:33 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-08-21 20:44 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-08-21 20:44 . 2011-01-20 14:11 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-08-21 20:44 . 2011-01-20 16:08 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-08-21 20:44 . 2011-01-20 16:08 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-08-21 20:43 . 2011-03-03 15:40 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2011-08-21 20:43 . 2011-03-03 13:35 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-08-21 20:43 . 2010-12-29 18:28 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-08-21 20:41 . 2011-06-06 10:59 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-21 20:40 . 2011-04-30 06:09 758784 —-a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2011-08-21 20:40 . 2011-07-23 11:04 129536 —-a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-08-21 20:40 . 2011-07-23 10:59 247808 —-a-w- c:\program files\Internet Explorer\ieproxy.dll
2011-08-21 20:40 . 2011-07-23 10:59 197632 —-a-w- c:\program files\Internet Explorer\IEShims.dll
2011-08-21 20:40 . 2011-07-23 10:59 743424 —-a-w- c:\program files\Internet Explorer\iedvtool.dll
2011-08-21 20:40 . 2011-07-23 11:02 638232 —-a-w- c:\program files\Internet Explorer\iexplore.exe
2011-08-21 20:40 . 2011-04-20 15:50 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-08-21 20:25 . 2011-06-17 20:13 905104 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-09 00:29 . 2011-07-11 14:07 24496 —-a-w- c:\windows\system32\drivers\sshrmd.sys
2011-08-09 00:29 . 2011-07-11 14:07 181008 —-a-w- c:\windows\system32\drivers\ssidrv.sys
2011-08-09 00:29 . 2011-07-11 14:07 45584 —-a-w- c:\windows\system32\drivers\ssfmonm.sys
2011-08-09 00:25 . 2011-08-09 00:26 ——– dc-h–w- c:\programdata\{61D227D1-25DF-4A97-9428-6C9A27015CDA}
2011-08-09 00:25 . 2011-08-09 00:25 ——– d—–w- c:\program files\Webroot
2011-08-09 00:24 . 2011-08-26 11:11 ——– d–h–w- c:\programdata\Webroot
2011-08-08 21:17 . 2011-08-08 21:17 ——– d–h–w- c:\users\Jessica\AppData\Local\PackageAware
2011-07-31 15:28 . 2011-07-31 16:07 ——– d—–w- c:\program files\PC Tools Security
2011-07-31 15:28 . 2011-07-31 16:07 ——– d—–w- c:\program files\Common Files\PC Tools
2011-07-31 15:26 . 2011-07-31 16:05 ——– d—–w- c:\programdata\PC Tools
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-26 20:38 . 2010-05-19 00:42 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-07-23 11:04 . 2011-08-21 20:40 916480 —-a-w- c:\windows\system32\wininet.dll
2011-07-23 11:00 . 2011-08-21 20:40 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-07-23 10:59 . 2011-08-21 20:40 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-07-23 10:59 . 2011-08-21 20:40 109056 —-a-w- c:\windows\system32\iesysprep.dll
2011-07-23 10:59 . 2011-08-21 20:40 71680 —-a-w- c:\windows\system32\iesetup.dll
2011-07-23 10:03 . 2011-08-21 20:40 385024 —-a-w- c:\windows\system32\html.iec
2011-07-23 09:27 . 2011-08-21 20:40 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2011-07-23 09:25 . 2011-08-21 20:40 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-07-11 13:25 . 2011-08-23 20:36 2048 —-a-w- c:\windows\system32\tzres.dll
2011-07-06 23:52 . 2010-06-21 20:40 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 23:52 . 2010-06-21 20:40 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-20 08:54 . 2011-08-21 20:30 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-06-20 08:54 . 2011-08-21 20:30 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-06-17 16:03 . 2011-08-21 20:47 375808 —-a-w- c:\windows\system32\winsrv.dll
2011-06-02 13:34 . 2011-08-23 20:26 2043392 —-a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-01-30 430080]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HWSetup"="\HWSetup.exe hwSetUP" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-20 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-20 154136]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-20 129560]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"NDSTray.exe"="NDSTray.exe" [BU]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-23 438272]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"RtHDVCpl"="c:\windows\RtHDVCpl.exe" [2008-01-30 4911104]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-07-06 1047656]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-07-06 1047656]
"WebrootTrayApp"="c:\program files\Webroot\Security\Current\Framework\WRTray.exe" [2011-08-09 1382984]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
2008-01-29 21:38 583048 —-a-w- c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1c9ae605c644117;Google Update Service (gupdate1c9ae605c644117);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [2007-10-30 937984]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960]
S1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwf.sys [2007-09-01 20352]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 ssfmonm;ssfmonm;c:\windows\system32\DRIVERS\ssfmonm.sys [2011-07-11 45584]
S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-04 126976]
S2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\Security\Current\Framework\WRConsumerService.exe [2011-08-09 3381184]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.facebook.com/
TCP: DhcpNameServer = [removed] [removed]
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-jswtrayutil - c:\program files\Jumpstart\jswtrayutil.exe
MSConfigStartUp-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\2.bin\M3PLUGIN.DLL
MSConfigStartUp-RegistryMechanic - c:\program files\Registry Mechanic\RMTray.exe
MSConfigStartUp-RoxWatchTray - c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-26 17:09
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
———————— Other Running Processes ————————
.
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\agrsmsvc.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Toshiba\Power Saver\TosCoSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Webroot\Security\current\plugins\antimalware\AEI.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Toshiba\ConfigFree\CFSwMgr.exe
c:\windows\ehome\mcupdate.EXE
.
**************************************************************************
.
Completion time: 2011-08-26 17:17:05 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-26 21:16
.
Pre-Run: 54,762,909,696 bytes free
Post-Run: 56,860,119,040 bytes free
.
- - End Of File - - 14ECBB9EB464E243D5384D642CAF676A
ComboFix 11-08-26.04 - Jessica 08/26/2011 16:51:22.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1014.339 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {53211D91-0C31-95F2-E3A5-7661FB22889E}
SP: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {E840FC75-2A0B-9A7C-D915-4D1380A5C223}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\xp
c:\programdata\xp\EBLib.dll
c:\programdata\xp\TPwSav.sys
c:\users\Jessica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tool
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\system32\no
c:\windows\system32\no\toscdspd.cpl.mui
c:\windows\system32\SV
c:\windows\system32\SV\toscdspd.cpl.mui
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_RKHIT
——-\Service_RkHit
.
.
((((((((((((((((((((((((( Files Created from 2011-07-26 to 2011-08-26 )))))))))))))))))))))))))))))))
.
.
2011-08-26 21:03 . 2011-08-26 21:10 ——– d—–w- c:\users\Jessica\AppData\Local\temp
2011-08-26 21:03 . 2011-08-26 21:03 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-08-26 16:57 . 2011-08-16 12:48 7152464 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A3235E38-9693-4E20-BA2D-91495ECD4381}\mpengine.dll
2011-08-25 14:37 . 2011-08-25 14:37 ——– d—–w- c:\program files\HD Tune
2011-08-25 14:16 . 2011-08-25 14:16 ——– d—–w- c:\program files\Common Files\Adobe
2011-08-25 14:11 . 2011-08-25 14:11 ——– d—–w- c:\program files\Common Files\Adobe AIR
2011-08-24 10:46 . 2011-08-24 10:46 ——– d—–w- c:\program files\ESET
2011-08-21 20:47 . 2011-02-16 14:02 292864 —-a-w- c:\windows\system32\atmfd.dll
2011-08-21 20:47 . 2011-02-16 16:16 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-08-21 20:47 . 2011-02-22 13:23 69632 —-a-w- c:\windows\system32\drivers\bowser.sys
2011-08-21 20:47 . 2011-04-14 14:59 75264 —-a-w- c:\windows\system32\drivers\dfsc.sys
2011-08-21 20:46 . 2011-01-20 16:37 638336 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-08-21 20:46 . 2011-01-20 16:08 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-08-21 20:46 . 2011-01-20 16:07 37376 —-a-w- c:\windows\system32\cdd.dll
2011-08-21 20:45 . 2011-02-18 14:03 305152 —-a-w- c:\windows\system32\drivers\srv.sys
2011-08-21 20:45 . 2011-07-06 15:31 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-21 20:45 . 2011-04-29 13:24 79872 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-08-21 20:45 . 2011-04-29 13:24 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-08-21 20:45 . 2011-03-02 15:44 86528 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-08-21 20:45 . 2009-05-04 09:59 25088 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-08-21 20:45 . 2011-04-21 13:58 273408 —-a-w- c:\windows\system32\drivers\afd.sys
2011-08-21 20:44 . 2011-04-29 13:25 146432 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-08-21 20:44 . 2011-04-29 13:25 102400 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-08-21 20:44 . 2011-01-20 16:08 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-08-21 20:44 . 2011-01-20 16:08 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-08-21 20:44 . 2011-01-20 14:12 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-08-21 20:44 . 2011-01-20 13:47 683008 —-a-w- c:\windows\system32\d2d1.dll
2011-08-21 20:44 . 2011-02-22 13:33 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-08-21 20:44 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-08-21 20:44 . 2011-01-20 14:11 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-08-21 20:44 . 2011-01-20 16:08 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-08-21 20:44 . 2011-01-20 16:08 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-08-21 20:43 . 2011-03-03 15:40 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2011-08-21 20:43 . 2011-03-03 13:35 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-08-21 20:43 . 2010-12-29 18:28 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-08-21 20:41 . 2011-06-06 10:59 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-21 20:40 . 2011-04-30 06:09 758784 —-a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2011-08-21 20:40 . 2011-07-23 11:04 129536 —-a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-08-21 20:40 . 2011-07-23 10:59 247808 —-a-w- c:\program files\Internet Explorer\ieproxy.dll
2011-08-21 20:40 . 2011-07-23 10:59 197632 —-a-w- c:\program files\Internet Explorer\IEShims.dll
2011-08-21 20:40 . 2011-07-23 10:59 743424 —-a-w- c:\program files\Internet Explorer\iedvtool.dll
2011-08-21 20:40 . 2011-07-23 11:02 638232 —-a-w- c:\program files\Internet Explorer\iexplore.exe
2011-08-21 20:40 . 2011-04-20 15:50 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-08-21 20:25 . 2011-06-17 20:13 905104 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-09 00:29 . 2011-07-11 14:07 24496 —-a-w- c:\windows\system32\drivers\sshrmd.sys
2011-08-09 00:29 . 2011-07-11 14:07 181008 —-a-w- c:\windows\system32\drivers\ssidrv.sys
2011-08-09 00:29 . 2011-07-11 14:07 45584 —-a-w- c:\windows\system32\drivers\ssfmonm.sys
2011-08-09 00:25 . 2011-08-09 00:26 ——– dc-h–w- c:\programdata\{61D227D1-25DF-4A97-9428-6C9A27015CDA}
2011-08-09 00:25 . 2011-08-09 00:25 ——– d—–w- c:\program files\Webroot
2011-08-09 00:24 . 2011-08-26 11:11 ——– d–h–w- c:\programdata\Webroot
2011-08-08 21:17 . 2011-08-08 21:17 ——– d–h–w- c:\users\Jessica\AppData\Local\PackageAware
2011-07-31 15:28 . 2011-07-31 16:07 ——– d—–w- c:\program files\PC Tools Security
2011-07-31 15:28 . 2011-07-31 16:07 ——– d—–w- c:\program files\Common Files\PC Tools
2011-07-31 15:26 . 2011-07-31 16:05 ——– d—–w- c:\programdata\PC Tools
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-26 20:38 . 2010-05-19 00:42 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-07-23 11:04 . 2011-08-21 20:40 916480 —-a-w- c:\windows\system32\wininet.dll
2011-07-23 11:00 . 2011-08-21 20:40 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-07-23 10:59 . 2011-08-21 20:40 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-07-23 10:59 . 2011-08-21 20:40 109056 —-a-w- c:\windows\system32\iesysprep.dll
2011-07-23 10:59 . 2011-08-21 20:40 71680 —-a-w- c:\windows\system32\iesetup.dll
2011-07-23 10:03 . 2011-08-21 20:40 385024 —-a-w- c:\windows\system32\html.iec
2011-07-23 09:27 . 2011-08-21 20:40 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2011-07-23 09:25 . 2011-08-21 20:40 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-07-11 13:25 . 2011-08-23 20:36 2048 —-a-w- c:\windows\system32\tzres.dll
2011-07-06 23:52 . 2010-06-21 20:40 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 23:52 . 2010-06-21 20:40 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-20 08:54 . 2011-08-21 20:30 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-06-20 08:54 . 2011-08-21 20:30 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-06-17 16:03 . 2011-08-21 20:47 375808 —-a-w- c:\windows\system32\winsrv.dll
2011-06-02 13:34 . 2011-08-23 20:26 2043392 —-a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-01-30 430080]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HWSetup"="\HWSetup.exe hwSetUP" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-20 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-20 154136]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-20 129560]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"NDSTray.exe"="NDSTray.exe" [BU]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-23 438272]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"RtHDVCpl"="c:\windows\RtHDVCpl.exe" [2008-01-30 4911104]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-07-06 1047656]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-07-06 1047656]
"WebrootTrayApp"="c:\program files\Webroot\Security\Current\Framework\WRTray.exe" [2011-08-09 1382984]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
2008-01-29 21:38 583048 —-a-w- c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1c9ae605c644117;Google Update Service (gupdate1c9ae605c644117);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [2007-10-30 937984]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960]
S1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwf.sys [2007-09-01 20352]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 ssfmonm;ssfmonm;c:\windows\system32\DRIVERS\ssfmonm.sys [2011-07-11 45584]
S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-04 126976]
S2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\Security\Current\Framework\WRConsumerService.exe [2011-08-09 3381184]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.facebook.com/
TCP: DhcpNameServer = [removed] [removed]
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-jswtrayutil - c:\program files\Jumpstart\jswtrayutil.exe
MSConfigStartUp-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\2.bin\M3PLUGIN.DLL
MSConfigStartUp-RegistryMechanic - c:\program files\Registry Mechanic\RMTray.exe
MSConfigStartUp-RoxWatchTray - c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-26 17:09
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
———————— Other Running Processes ————————
.
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\agrsmsvc.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Toshiba\Power Saver\TosCoSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Webroot\Security\current\plugins\antimalware\AEI.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Toshiba\ConfigFree\CFSwMgr.exe
c:\windows\ehome\mcupdate.EXE
.
**************************************************************************
.
Completion time: 2011-08-26 17:17:05 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-26 21:16
.
Pre-Run: 54,762,909,696 bytes free
Post-Run: 56,860,119,040 bytes free
.
- - End Of File - - 14ECBB9EB464E243D5384D642CAF676A
jeffce
Hi yksnemeg,
I notice some Norton/Symantec entries on your system. You can completely remove these using the tool found here .
———-
Please go ahead and run DDS once more and post both of the logs created into your next reply.
———-
Once you complete this let me know how your system is running.
I notice some Norton/Symantec entries on your system. You can completely remove these using the tool found here .
———-
Please go ahead and run DDS once more and post both of the logs created into your next reply.
———-
Once you complete this let me know how your system is running.
yksnemeg
Ok, After all this was done, I would say the computer seems to be running better. I'm still confused about losing my files but they hard drive is still at the same capacity. Is my files lost or jsut really hidden? I still done have the feeling that the virus is gone. Since all the scan we did and there was no results and we didn't seem to remove anything. Let me know what you think. Thanks
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.19120
Run by [removed] at 9:23:52 on 2011-08-28
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1014.184 [GMT -4:00]
.
AV: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {53211D91-0C31-95F2-E3A5-7661FB22889E}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Webroot AntiVirus with Spy Sweeper *Disabled/Updated* {E840FC75-2A0B-9A7C-D915-4D1380A5C223}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Webroot\Security\Current\Framework\WRConsumerService.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\agrsmsvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
c:\Toshiba\IVP\swupdate\swupdtmr.exe
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Webroot\Security\current\plugins\antimalware\AEI.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Windows\ehome\ehmsas.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.facebook.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [TOSCDSPD] "c:\program files\toshiba\toscdspd\TOSCDSPD.exe"
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [WMPNSCFG] "c:\program files\windows media player\WMPNSCFG.exe"
mRun: [IgfxTray] "c:\windows\system32\igfxtray.exe"
mRun: [HotKeysCmds] "c:\windows\system32\hkcmd.exe"
mRun: [Persistence] "c:\windows\system32\igfxpers.exe"
mRun: [TPwrMain] "c:\program files\toshiba\power saver\TPwrMain.EXE"
mRun: [SmoothView] "c:\program files\toshiba\smoothview\SmoothView.exe"
mRun: [00TCrdMain] "c:\program files\toshiba\flashcards\TCrdMain.exe"
mRun: [Apoint] "c:\program files\apoint2k\Apoint.exe"
mRun: [NDSTray.exe] NDSTray.exe
mRun: [HWSetup] \HWSetup.exe hwSetUP
mRun: [SVPWUTIL] "c:\program files\toshiba\utilities\SVPWUTIL.exe" SVPwUTIL
mRun: [KeNotify] "c:\program files\toshiba\utilities\KeNotify.exe"
mRun: [RtHDVCpl] "c:\windows\RtHDVCpl.exe"
mRun: [Windows Mobile Device Center] "%windir%\WindowsMobile\wmdc.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [WebrootTrayApp] "c:\program files\webroot\security\current\framework\WRTray.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{38345E4D-9E2C-42F5-AC8A-C5DAC44F2AD7} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{C731D3F7-418F-474D-8D48-3350BBFC41FE} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{E3C2285E-83FC-426B-9728-1960F917DBC1} : DhcpNameServer = [removed] [removed]
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\drivers\jswpslwf.sys [2008-3-20 20352]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]
R2 ssfmonm;ssfmonm;c:\windows\system32\drivers\ssfmonm.sys [2011-8-8 45584]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S2 gupdate1c9ae605c644117;Google Update Service (gupdate1c9ae605c644117);"c:\program files\google\update\googleupdate.exe" /svc –> c:\program files\google\update\GoogleUpdate.exe [?]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\jumpstart\jswpsapi.exe [2008-3-20 937984]
S4 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2007-12-25 40960]
.
=============== Created Last 30 ================
.
2011-08-26 21:17:08 ——– d—–w- c:\users\jessica\appdata\local\temp
2011-08-26 21:08:13 ——– d—–w- C:\$RECYCLE.BIN
2011-08-26 20:47:55 98816 —-a-w- c:\windows\sed.exe
2011-08-26 20:47:55 518144 —-a-w- c:\windows\SWREG.exe
2011-08-26 20:47:55 256000 —-a-w- c:\windows\PEV.exe
2011-08-26 20:47:55 208896 —-a-w- c:\windows\MBR.exe
2011-08-26 20:47:38 ——– d—–w- C:\ComboFix
2011-08-26 16:57:44 7152464 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{a3235e38-9693-4e20-ba2d-91495ecd4381}\mpengine.dll
2011-08-25 14:37:14 ——– d—–w- c:\program files\HD Tune
2011-08-24 10:46:31 ——– d—–w- c:\program files\ESET
2011-08-23 20:36:20 2048 —-a-w- c:\windows\system32\tzres.dll
2011-08-23 20:26:56 2043392 —-a-w- c:\windows\system32\win32k.sys
2011-08-22 01:25:29 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-08-21 23:49:03 2048 —-a-w- c:\windows\system32\winrsmgr.dll
2011-08-21 23:47:56 246272 —-a-w- c:\windows\system32\WSManHTTPConfig.exe
2011-08-21 23:47:50 1181696 —-a-w- c:\windows\system32\WsmSvc.dll
2011-08-21 20:47:38 292864 —-a-w- c:\windows\system32\atmfd.dll
2011-08-21 20:47:36 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-08-21 20:47:32 375808 —-a-w- c:\windows\system32\winsrv.dll
2011-08-21 20:47:29 69632 —-a-w- c:\windows\system32\drivers\bowser.sys
2011-08-21 20:47:23 75264 —-a-w- c:\windows\system32\drivers\dfsc.sys
2011-08-21 20:47:17 1205080 —-a-w- c:\windows\system32\ntdll.dll
2011-08-21 20:45:58 305152 —-a-w- c:\windows\system32\drivers\srv.sys
2011-08-21 20:45:51 79872 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-08-21 20:45:51 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-21 20:45:50 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-08-21 20:45:41 86528 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-08-21 20:45:41 25088 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-08-21 20:45:33 273408 —-a-w- c:\windows\system32\drivers\afd.sys
2011-08-21 20:43:14 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2011-08-21 20:43:13 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-08-21 20:43:01 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-08-21 20:42:57 322560 —-a-w- c:\windows\system32\sbe.dll
2011-08-21 20:42:55 177664 —-a-w- c:\windows\system32\mpg2splt.ax
2011-08-21 20:42:54 153088 —-a-w- c:\windows\system32\sbeio.dll
2011-08-21 20:41:09 739328 —-a-w- c:\windows\system32\inetcomm.dll
2011-08-21 20:41:04 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2011-08-21 20:39:55 2067968 —-a-w- c:\windows\system32\mstscax.dll
2011-08-21 20:39:54 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-08-21 20:30:15 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-08-21 20:30:10 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-08-21 20:25:11 905104 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-09 10:48:03 276992 —-a-w- c:\windows\system32\schannel.dll
2011-08-09 00:29:09 45584 —-a-w- c:\windows\system32\drivers\ssfmonm.sys
2011-08-09 00:29:09 24496 —-a-w- c:\windows\system32\drivers\sshrmd.sys
2011-08-09 00:29:09 181008 —-a-w- c:\windows\system32\drivers\ssidrv.sys
2011-08-09 00:25:46 ——– dc-h–w- c:\programdata\{61D227D1-25DF-4A97-9428-6C9A27015CDA}
2011-08-09 00:25:22 ——– d—–w- c:\program files\Webroot
2011-08-09 00:24:02 ——– d–h–w- c:\programdata\Webroot
2011-08-08 21:17:21 ——– d–h–w- c:\users\jessica\appdata\local\PackageAware
2011-07-31 15:28:07 ——– d—–w- c:\program files\PC Tools Security
2011-07-31 15:28:07 ——– d—–w- c:\program files\common files\PC Tools
2011-07-31 15:26:16 ——– d—–w- c:\programdata\PC Tools
.
==================== Find3M ====================
.
2011-08-26 20:38:51 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-07-23 11:04:29 916480 —-a-w- c:\windows\system32\wininet.dll
2011-07-23 11:00:05 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-07-23 10:59:52 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-07-23 10:59:34 71680 —-a-w- c:\windows\system32\iesetup.dll
2011-07-23 10:59:34 109056 —-a-w- c:\windows\system32\iesysprep.dll
2011-07-23 10:03:47 385024 —-a-w- c:\windows\system32\html.iec
2011-07-23 09:27:04 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2011-07-23 09:25:38 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-07-06 23:52:42 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 23:52:42 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
.
============= FINISH: 9:31:00.49 ===============
jeffce
Hi yksnemeg,
IT APPEARS THAT YOUR LOGS ARE NOW CLEAN
SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! 
This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
Your system may have been more infected but since you were using system restore to an earlier time some of it may not have been showing, but have now worries as we will be removing all of them when we uninstall ComboFix.
———-
The following will implement some cleanup procedures as well as reset System Restore points:
Click Start > Run and copy/paste the following text into the Run box as shown and click OK.
(Note: There is a space between the ..X and the /U that needs to be there.)
[external image: Posted Image]
———-
Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.
Here are some tips to reduce the potential for spyware infection in the future:
1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here.
**Do not install more than one firewall program because they will conflict with each other**
5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.
6. Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.
7. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
8. WOT , Web of Trust, As 'Googling' is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
9. Install Spybot - Search and Destroy - Download and install Spybot - Search and Destroy with its TeaTimer option. This will provide real time spyware and hijacker protection on your computer alongside your virus protection. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D and Ad-aware
10. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
IT APPEARS THAT YOUR LOGS ARE NOW CLEAN
This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
I would say the computer seems to be running better.
It may not have seemed like it but there was malware that we removed using ComboFix.all the scan we did and there was no results and we didn't seem to remove anything. Let me know what you think. Thanks
———-
The following will implement some cleanup procedures as well as reset System Restore points:
Click Start > Run and copy/paste the following text into the Run box as shown and click OK.
(Note: There is a space between the ..X and the /U that needs to be there.)
[external image: Posted Image]
———-
Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.
Here are some tips to reduce the potential for spyware infection in the future:
1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
- From within Internet Explorer click on the Tools menu and then click on Options.
- Click once on the Security tab
- Click once on the Internet icon so it becomes highlighted.
- Click once on the Custom Level button.
- Change the Download signed ActiveX controls to Prompt
- Change the Download unsigned ActiveX controls to Disable
- Change the Initialize and script ActiveX controls not marked as safe to Disable
- Change the Installation of desktop items to Prompt
- Change the Launching programs and files in an IFRAME to Prompt
- Change the Navigate sub-frames across different domains to Prompt
- When all these settings have been made, click on the OK button.
- If it prompts you as to whether or not you want to save the settings, press the Yes button.
- Next press the Apply button and then the OK to exit the Internet Properties page.
- Open Internet Explorer
- Click on Tools > Internet Options
- Press Security tab
- Select Internet zone then place check next to Enable Protected Mode if not already done
- Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
- Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here.
**Do not install more than one firewall program because they will conflict with each other**
5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.
6. Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.
7. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
8. WOT , Web of Trust, As 'Googling' is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
- Green to go
- Yellow for caution
- Red to stop
9. Install Spybot - Search and Destroy - Download and install Spybot - Search and Destroy with its TeaTimer option. This will provide real time spyware and hijacker protection on your computer alongside your virus protection. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D and Ad-aware
10. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI