This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.Gen.2 followed by Tidserv Activity 2

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I recently started getting detection alerts talking about trojan.gen.2 being block a few days ago. The next day I looked in my history and I had 79 attempts by trojan.gen.2 I guess to attack. I get these messages almost every couple of minutes. Then today, I get an alert talking about Tidserv Activity 2 and needed manual removal. I have followed all of the instructions around the web and nothing can detect anything. I ran a complete system scan while in safe mode and it detected 32 threats but shortly after my computer just shuts off. What steps should I take from here?
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

Please download DDS from one of the following links and save it to your desktop.
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

In your next reply please post the logs created by DDS and GMER. :)
I have attached the attachment., gmer, and dds files for your reviewing. Pasted below is the contents of the DDS file. Question about the GMER.exe scan You said to uncheck IAT/EAT, Drives/Partitions other than C: Drive, and Show All. On the one that I did a scan with the only boxes that are able to be adjusted were the Services, Registry, Files, C:\, and ADS. The others are greyed out. . DDS (Ver_2011-06-23.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 Run by [removed] at 16:18:02 on 2011-10-21 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3836.1439 [GMT -4:00] . AV: Norton Security Suite *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton Security Suite *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Security Suite *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe svchost.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\windows\system32\SearchFilterHost.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\windows\SysWOW64\cmd.exe C:\windows\system32\conhost.exe C:\windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA uSearch Bar = Preserve uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA uURLSearchHooks: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn0.dll mURLSearchHooks: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn0.dll mWinlogon: Userinit=userinit.exe BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\IPS\IPSBHO.DLL BHO: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn0.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll TB: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn0.dll EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll uRun: [DS3 Tool] C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe -mini uRun: [Desktop Software] "C:\Program Files (x86)\Common Files\SupportSoft\bin\bcont.exe" /ini "C:\Program Files (x86)\ComcastUI\Desktop Software\uinstaller.ini" /fromrun /starthidden uRun: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 mRun: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" mRun: [ddoctorv2] "C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2 mRun: [] mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe StartupFolder: C:\Users\Cory's\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\PDANET~1.LNK - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll LSP: mswsock.dll Trusted Zone: acura.com Trusted Zone: bcconnect.net Trusted Zone: honda.com Trusted Zone: honda.com\www.in DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {297DE2B6-509A-4B36-93C5-A65276606900} - hxxp://www.in.honda.com/rraaapps/rraasec/codebase/RRAAINAX/RraainAX.CAB DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://akamaicdn.webex.com/client/WBXclient-T27L10NSP25-10481/nbr/ieatgpc1.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{29C43A92-DCC1-4DD3-8519-D08A5773B253} : DhcpNameServer = 192.168.42.129 TCP: Interfaces\{6F03E144-5C89-4AE4-B521-E65C0966017A} : DhcpNameServer = 192.168.2.1 TCP: Interfaces\{6F03E144-5C89-4AE4-B521-E65C0966017A}\2456C6B696E6F5E4F575962756C6563737F5246434234344 : DhcpNameServer = 192.168.2.1 TCP: Interfaces\{6F03E144-5C89-4AE4-B521-E65C0966017A}\2656C6B696E6 : DhcpNameServer = 192.168.2.1 TCP: Interfaces\{6F03E144-5C89-4AE4-B521-E65C0966017A}\2656C6B696E6534376 : DhcpNameServer = 192.168.2.1 [removed] [removed] TCP: Interfaces\{6F03E144-5C89-4AE4-B521-E65C0966017A}\475736B65627 : DhcpNameServer = 192.168.2.1 Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4 BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO-X64: 0x1 - No File BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll BHO-X64: HP Print Enhancer - No File BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll BHO-X64: Symantec NCO BHO - No File BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\IPS\IPSBHO.DLL BHO-X64: Symantec Intrusion Prevention - No File BHO-X64: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn0.dll BHO-X64: Zynga - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll BHO-X64: HP Smart BHO Class - No File TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll TB-X64: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\prxtbZyn0.dll EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun-x64: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 mRun-x64: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" mRun-x64: [ddoctorv2] "C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2 mRun-x64: [(Default)] mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun-x64: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe . ============= SERVICES / DRIVERS =============== . R0 PxHlpa64;PxHlpa64;C:\windows\system32\Drivers\PxHlpa64.sys –> C:\windows\system32\Drivers\PxHlpa64.sys [?] R0 SMR210;Symantec SMR Utility Service 2.1.0;C:\windows\system32\drivers\SMR210.SYS –> C:\windows\system32\drivers\SMR210.SYS [?] R0 SymDS;Symantec Data Store;C:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS –> C:\windows\system32\drivers\N360x64\0501000.01D\SYMDS64.SYS [?] R0 SymEFA;Symantec Extended File Attributes;C:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS –> C:\windows\system32\drivers\N360x64\0501000.01D\SYMEFA64.SYS [?] R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\windows\system32\DRIVERS\tos_sps64.sys –> C:\windows\system32\DRIVERS\tos_sps64.sys [?] R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20111014.001\BHDrvx64.sys [2011-10-14 1155704] R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20111020.030\IDSviA64.sys [2011-10-20 488568] R1 SymIRON;Symantec Iron Driver;C:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS –> C:\windows\system32\drivers\N360x64\0501000.01D\Ironx64.SYS [?] R1 SymNetS;Symantec Network Security WFP Driver;C:\windows\system32\Drivers\N360x64\0501000.01D\SYMNETS.SYS –> C:\windows\system32\Drivers\N360x64\0501000.01D\SYMNETS.SYS [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys –> C:\windows\system32\DRIVERS\vwififlt.sys [?] R2 AMD External Events Utility;AMD External Events Utility;C:\windows\system32\atiesrxx.exe –> C:\windows\system32\atiesrxx.exe [?] R2 cfWiMAXService;ConfigFree WiMAX Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2009-8-10 248688] R2 ConfigFree Gadget Service;ConfigFree Gadget Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2009-7-14 42368] R2 ConfigFree Service;ConfigFree Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-3-10 46448] R2 eBLVD;eBLVD;C:\Program Files (x86)\eBLVD\ebhost.exe [2011-1-26 569912] R2 N360;Norton Security Suite;C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\ccsvchst.exe [2011-10-2 130008] R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\TOSHIBA\TECO\TecoService.exe [2009-8-11 252272] R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\windows\system32\DRIVERS\TVALZFL.sys –> C:\windows\system32\DRIVERS\TVALZFL.sys [?] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-8-12 136824] R3 FwLnk;FwLnk Driver;C:\windows\system32\DRIVERS\FwLnk.sys –> C:\windows\system32\DRIVERS\FwLnk.sys [?] R3 PGEffect;Pangu effect driver;C:\windows\system32\DRIVERS\pgeffect.sys –> C:\windows\system32\DRIVERS\pgeffect.sys [?] R3 pneteth;PdaNet Broadband;C:\windows\system32\DRIVERS\pneteth.sys –> C:\windows\system32\DRIVERS\pneteth.sys [?] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\windows\system32\Drivers\RtsUStor.sys –> C:\windows\system32\Drivers\RtsUStor.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys –> C:\windows\system32\DRIVERS\Rt64win7.sys [?] R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;C:\windows\system32\DRIVERS\rtl8192se.sys –> C:\windows\system32\DRIVERS\rtl8192se.sys [?] R3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-1-17 54136] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-8-3 137560] R3 TPCHSrv;TPCH Service;C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2009-8-4 826224] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 pnetmdm;PdaNet Modem;C:\windows\system32\DRIVERS\pnetmdm64.sys –> C:\windows\system32\DRIVERS\pnetmdm64.sys [?] S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys –> C:\windows\system32\drivers\tsusbflt.sys [?] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\windows\system32\DRIVERS\vwifimp.sys –> C:\windows\system32\DRIVERS\vwifimp.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe –> C:\windows\system32\Wat\WatAdminSvc.exe [?] . =============== Created Last 30 ================ . 2011-10-21 04:02:04 96376 —-a-w- C:\windows\System32\drivers\SMR210.SYS 2011-10-20 18:02:43 16728065 —-a-w- C:\Setup_V14.0.35_TOS_Oct152011.exe 2011-10-20 08:35:52 ——– d—–w- C:\Users\Cory's\AppData\Local\NPE 2011-10-18 10:17:15 ——– d—–we C:\windows\system64 2011-10-14 08:06:10 ——– d—–w- C:\Users\Cory's\AppData\Local\{D57C3781-DE2B-4DDE-B3E0-A0E294C38C55} 2011-10-14 08:05:59 ——– d—–w- C:\Users\Cory's\AppData\Local\{6C50881F-52A9-4320-A52D-A0ABA8200630} 2011-10-14 07:43:02 ——– d—–w- C:\Users\Cory's\AppData\Roaming\Origin 2011-10-14 07:42:39 ——– d—–w- C:\Users\Cory's\AppData\Local\Origin 2011-10-14 07:42:14 ——– d—–w- C:\ProgramData\Origin 2011-10-14 07:42:13 ——– d—–w- C:\Program Files (x86)\Origin Games 2011-10-14 07:41:34 ——– d—–w- C:\Program Files (x86)\Origin 2011-10-13 02:37:49 3138048 —-a-w- C:\windows\System32\win32k.sys 2011-10-13 02:35:32 75776 —-a-w- C:\windows\SysWow64\psisrndr.ax 2011-10-13 02:35:32 613888 —-a-w- C:\windows\System32\psisdecd.dll 2011-10-13 02:35:32 465408 —-a-w- C:\windows\SysWow64\psisdecd.dll 2011-10-13 02:35:31 108032 —-a-w- C:\windows\System32\psisrndr.ax 2011-10-13 02:34:12 571904 —-a-w- C:\windows\SysWow64\oleaut32.dll 2011-10-13 02:34:12 331776 —-a-w- C:\windows\System32\oleacc.dll 2011-10-13 02:34:12 233472 —-a-w- C:\windows\SysWow64\oleacc.dll 2011-10-13 02:34:11 861696 —-a-w- C:\windows\System32\oleaut32.dll 2011-10-12 04:53:23 ——– d—–w- C:\Users\Cory's\AppData\Local\{05E6AE91-0E74-4C0F-AB89-C8FB70CE78D3} 2011-10-12 04:52:59 ——– d—–w- C:\Users\Cory's\AppData\Local\{68AA567A-7506-41C3-9830-8349824833A0} 2011-10-06 03:41:24 ——– d—–w- C:\Users\Cory's\AppData\Roaming\Malwarebytes 2011-10-06 03:41:11 ——– d—–w- C:\ProgramData\Malwarebytes 2011-10-06 03:41:07 25416 —-a-w- C:\windows\System32\drivers\mbam.sys 2011-10-02 21:17:45 912504 —-a-w- C:\windows\System32\drivers\N360x64\0501000.01D\symefa64.sys 2011-10-02 21:17:45 386168 —-a-w- C:\windows\System32\drivers\N360x64\0501000.01D\symnets.sys 2011-10-02 21:17:44 744568 —-a-w- C:\windows\System32\drivers\N360x64\0501000.01D\srtsp64.sys 2011-10-02 21:17:44 450680 —-a-w- C:\windows\System32\drivers\N360x64\0501000.01D\symds64.sys 2011-10-02 21:17:44 40568 —-a-w- C:\windows\System32\drivers\N360x64\0501000.01D\srtspx64.sys 2011-10-02 21:17:44 171128 —-a-r- C:\windows\System32\drivers\N360x64\0501000.01D\ironx64.sys 2011-10-02 21:17:15 ——– d—–w- C:\windows\System32\drivers\N360x64\0501000.01D 2011-10-02 05:10:49 ——– d—–w- C:\ProgramData\Electronic Arts 2011-10-02 05:03:42 ——– d—–w- C:\Program Files (x86)\Microsoft WSE 2011-10-01 17:56:32 34288 —-a-w- C:\windows\System32\drivers\GEARAspiWDM.sys 2011-09-30 14:09:46 9049936 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5AF91242-10D5-4987-97AD-ED6E3BA32DA7}\mpengine.dll 2011-09-27 14:37:57 55307 —-a-w- C:\ProgramData\tmp4B5D.tmp 2011-09-27 08:30:28 404640 —-a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl . ==================== Find3M ==================== . 2011-10-20 18:03:18 43 —-a-w- C:\TOSSetup.bat 2011-10-02 21:17:47 174200 —-a-w- C:\windows\System32\drivers\SYMEVENT64x86.SYS 2011-09-16 11:34:58 16708131 —-a-w- C:\Setup_V14.0.30_TOS_Sep142011.exe 2011-08-18 19:17:45 441805 —-a-w- C:\ProgramData\tmpD7C5.tmp 2011-08-18 17:01:05 97150 —-a-w- C:\ProgramData\tmpBBC5.tmp . ============= FINISH: 16:18:59.98 ===============
Hi cory t,


I have attached the attachment., gmer, and dds files for your reviewing. Pasted below is the contents of the DDS file. Question about the GMER.exe scan You said to uncheck IAT/EAT, Drives/Partitions other than C: Drive, and Show All. On the one that I did a scan with the only boxes that are able to be adjusted were the Services, Registry, Files, C:\, and ADS. The others are greyed out.

Go ahead and run the following for me please:

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
Hi cory t,

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
I disable my norton security suite firewall and antivirus but the program is still detecting that they are still active. Also, I cannot directly save it to my desktop because something to do with the risk of the file. My only option is to run the program and then move it to my desktop from my Downloads folder.
Hi cory t,

I disable my norton security suite firewall and antivirus but the program is still detecting that they are still active.

Go ahead and continue running ComboFix past the warning about the antivirus and firewall.

Also, I cannot directly save it to my desktop

It is fine to run it from your Download folder for now :)
It completed the report and deleted the files and folders and restarted. It said it was preparing logs and then a alert poped up saying c:\ Program Files\TOSHIBA\TPHM17PCHWMsg.exe Illegal operation attempted on a registry key that has been marked for deletion. I left it alone for about an hour and ComboFix still says its preparing logs.
Hi cory t, Go ahead and just reboot your system and that should take care of it. You MAY have to reboot twice but it won't be a problem. Then look in your C:\ drive and find ComboFix.txt and then post that log into your next reply. :)
Also, ComboFix made a program I use for work unable to be opened. I located this, "2011-10-20 18:03:18 . 2011-03-08 15:47:11 43 —-a-w- C:\TOSSetup.batin" in the ComboFix history text doc. This program is safe.

I located this, "2011-10-20 18:03:18 . 2011-03-08 15:47:11 43 —-a-w- C:\TOSSetup.batin" in the ComboFix history text doc. This program is safe.

This was not removed. It is showing where it has been created in the past 3 months.

The ComboFix log looks incomplete. Make sure that you copied all correctly. If that was all there was please re-run ComboFix and post that log into your next reply. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI