This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] My Computer Is Running Slow And The Pop Ups Won't

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I have a problem that I hope you can help me solve. I googled my problem and found only one site that pertained to the aweful situation that I have. I know that there are many more it was the way I worded it. Nontheless, I am here begging for help. So I will just tell you my delima. My computer is running very slow. I can barely log on. I initially thought that I had problems with add-ons but the problems keep coming. I keep getting a message telling me an exception occured and will give me the path of "c:\WINDOWS\system32\gzmrotate.dll Dll Verify. " I also am now getting a message saying error loading with the path "c:\WINDOWS\system\32\opapvwmlm.dll" I went in and cleaned out alot of stuff I didn't need. I also installed PC tools Registry Mechanic. Before I ran that I ran Ad-Ware SE, I did a full scan with Trend all to no avail. Then I ran PC Reg. Mech. I still have the same problem. I have since downloaded HiJack This and now I am here hoping you can fix my pop ups, the winantivirus that keeps trying to open a new browser but Trend won't allow it thank goodness along with others. I am afraid that I am going to not have a cpu if this persists and It's not a year old yet. Please Please help. If you need more detail just let me know. I don't kwow exactly what to do so I am not going to do anything with the HJT until advised. Thanks BAJF
Hi! Welcome to the WTT forums.
I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Click here to download HJTsetup.exe
  • Save HJTsetup.exe to your desktop.
  • Double click on the HJTsetup.exe icon on your desktop.
  • By default it will install to C:\Program Files\Hijack This.
  • Continue to click Next in the setup dialogue boxes until you get to the Select Additional Tasks dialogue.
  • Put a check by Create a desktop icon then click Next again.
  • Continue to follow the rest of the prompts from there.
  • At the final dialogue box click Finish and it will launch Hijack This.
  • Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
  • Click Save to save the log file and then the log will open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply
Here are the results from HJT-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:20:08 PM, on 9/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\xyhqlesa.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TDispVol.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\DLACTRLW.exe
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\DLACTRLW.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\etgsjjbs.dll",forkonce
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O15 - Trusted Zone: *.stumbleupon.com
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/XSL/mb_us//h…ALStreaming.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/12ba6da8074d69…ip/RdxIE601.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://aolsvc.aol.com/onlinegames/trydiner…h2.1.0.0.67.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://scc-wlan01.ccccd.edu/sre/Downloads/ICSScanner.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…tg.1.0.0.33.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab
O16 - DPF: {D410AFBD-4E26-4D5F-840F-0412D6F6BB8D} (CPlayFirstSandScriptControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…pt.1.0.0.21.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://aolsvc.aol.com/onlinegames/dinerdas…sh.1.0.0.93.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\xyhqlesa.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 12784 bytes
Hi

Could you post the uninstall list too.

Download and Run ComboFix
  • Download this file from below:

    Here
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
Here are my resutls

ComboFix 07-09-14.1 - "You Know….Okay" 2007-09-13 14:33:52.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.198 [GMT -5:00]
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2007
C:\Program Files\Common Files\winantivirus pro 2007
C:\WINDOWS\cookies.ini
C:\WINDOWS\retadpu880.exe
C:\WINDOWS\system32\awvts.dll
C:\WINDOWS\system32\awvvv.dll
C:\WINDOWS\system32\cbxvvtq.dll
C:\WINDOWS\system32\efccday.dll
C:\WINDOWS\system32\efccyab.dll
C:\WINDOWS\system32\etgsjjbs.dll
C:\WINDOWS\system32\fcccdcc.dll
C:\WINDOWS\system32\iifcday.dll
C:\WINDOWS\system32\jkhfc.dll
C:\WINDOWS\system32\jkkjh.dll
C:\WINDOWS\system32\jkklm.dll
C:\WINDOWS\system32\mlmwvpao.ini
C:\WINDOWS\system32\nsq15D.dll
C:\WINDOWS\system32\oapvwmlm.dll
C:\WINDOWS\system32\pmkhi.dll
C:\WINDOWS\system32\rqstv.bak1
C:\WINDOWS\system32\rqstv.bak2
C:\WINDOWS\system32\rqstv.ini
C:\WINDOWS\system32\rqstv.ini2
C:\WINDOWS\system32\sbjjsgte.ini
C:\WINDOWS\system32\ssqrs.dll
C:\WINDOWS\system32\ssttq.dll
C:\WINDOWS\system32\ufacskea.dll
C:\WINDOWS\system32\UpMedia
C:\WINDOWS\system32\vapuiglj.dll
C:\WINDOWS\system32\vtsqq.dll
C:\WINDOWS\system32\vtsqr.dll
C:\WINDOWS\system32\vtstq.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_DOMAINSERVICE
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-08-14 to 2007-09-14 )))))))))))))))))))))))))))))))
.

2007-09-13 14:30 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-13 08:32 d——– C:\DOCUME~1\YOUKNO~1.OKA\APPLIC~1\Talkback
2007-09-12 19:59 8,290 –a—— C:\WINDOWS\system32\sstqn.dll
2007-09-12 17:15 8,290 –a—— C:\WINDOWS\system32\mljgg.dll
2007-09-11 23:47 d——– C:\DOCUME~1\YOUKNO~1.OKA\APPLIC~1\Real
2007-09-11 23:44 d——– C:\DOCUME~1\YOUKNO~1.OKA\APPLIC~1\StumbleUpon
2007-09-11 23:42 d——– C:\DOCUME~1\YOUKNO~1.OKA\APPLIC~1\Google
2007-09-11 23:03 d——– C:\DOCUME~1\YOUKNO~1.OKA\APPLIC~1\Intel
2007-09-11 23:03 d——– C:\DOCUME~1\YOUKNO~1.OKA\APPLIC~1\AOL
2007-09-11 23:02 d——– C:\DOCUME~1\YOUKNO~1.OKA\WINDOWS
2007-09-11 23:02 d——– C:\DOCUME~1\YOUKNO~1.OKA\APPLIC~1\You've Got Pictures Screensaver
2007-09-11 23:02 d——– C:\DOCUME~1\YOUKNO~1.OKA\APPLIC~1\toshiba
2007-09-11 07:58 d——– C:\DOCUME~1\me\APPLIC~1\Google
2007-09-11 07:56 d——– C:\DOCUME~1\me\APPLIC~1\Real
2007-09-11 07:45 d——– C:\DOCUME~1\me\WINDOWS
2007-09-11 07:45 d——– C:\DOCUME~1\me\APPLIC~1\You've Got Pictures Screensaver
2007-09-11 07:45 d——– C:\DOCUME~1\me\APPLIC~1\toshiba
2007-09-11 07:45 d——– C:\DOCUME~1\me\APPLIC~1\Intel
2007-09-11 07:45 d——– C:\DOCUME~1\me\APPLIC~1\AOL
2007-09-10 18:55 75,328 –a—— C:\WINDOWS\system32\xyhqlesa.exe
2007-09-10 07:16 d——– C:\Program Files\BFG
2007-09-10 02:51 8,286 –a—— C:\WINDOWS\system32\mlljh.dll
2007-09-09 23:09 d——– C:\Program Files\Common Files\Download Manager
2007-09-09 11:34 8,286 –a—— C:\WINDOWS\system32\vtutr.dll
2007-09-08 18:37 d——– C:\Program Files\Pizza Frenzy
2007-09-08 16:40 44 –a—— C:\WINDOWS\popcinfo.dat
2007-09-08 16:28 720,896 –a—— C:\WINDOWS\iun6002ev.exe
2007-09-08 16:28 d——– C:\Program Files\Bejeweled 2 Deluxe
2007-09-08 12:11 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
2007-09-08 12:10 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
2007-09-08 12:05 434,252 –a—— C:\WINDOWS\system32\Msvcrtd.dll
2007-09-06 21:48 d——– C:\Program Files\Zone.com Deluxe Games
2007-09-06 12:35 d——– C:\Program Files\Diner Dash 2
2007-09-05 01:52 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
2007-09-04 16:46 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
2007-09-03 18:20 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap
2007-09-03 01:11 20,992 –a—— C:\WINDOWS\jestertb.dll
2007-09-02 22:48 52,309 –a—— C:\WINDOWS\system32\drivers\mam4410u.sys
2007-09-02 22:48 49,867 –a—— C:\WINDOWS\system32\drivers\mardp2k.sys
2007-09-02 22:48 49,484 –a—— C:\WINDOWS\system32\drivers\MARDPNP.SYS
2007-09-02 22:48 36,586 –a—— C:\WINDOWS\system32\drivers\mavcomm.sys
2007-09-02 22:48 25,302 –a—— C:\WINDOWS\system32\drivers\MaVctrl.sys
2007-09-02 22:48 25,044 –a—— C:\WINDOWS\system32\drivers\mam4410m.sys
2007-09-02 22:48 24,784 –a—— C:\WINDOWS\system32\drivers\mam4410c.sys
2007-09-02 22:48 11,986 –a—— C:\WINDOWS\system32\drivers\MaVc2K.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-13 13:17 ——— d——– C:\Program Files\Trend Micro
2007-09-13 08:50 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
2007-09-12 20:10 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
2007-09-10 20:57 ——— d——– C:\Program Files\LimeWire
2007-09-10 20:42 ——— d——– C:\Program Files\RGB
2007-09-07 07:09 ——— d——– C:\Program Files\Apple Software Update
2007-09-03 22:38 240 –a—— C:\WINDOWS\system32\drivers\vsconfig.xml
2007-08-30 19:03 ——— d——– C:\Program Files\BitComet
2007-08-20 08:40 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-08-12 11:10 ——— d——– C:\Program Files\Real
2007-08-12 11:10 ——— d——– C:\Program Files\Common Files\xing shared
2007-08-12 11:09 ——— d——– C:\Program Files\Common Files\Real
2007-08-11 11:05 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-11 11:05 ——— d——– C:\Program Files\Atari
2007-08-10 20:33 ——— d——– C:\DOCUME~1\jfnbsnzb\APPLIC~1\StumbleUpon
2007-08-08 17:24 ——— d——– C:\DOCUME~1\jfnbsnzb\APPLIC~1\Talkback
2007-08-07 19:39 ——— d——– C:\DOCUME~1\jfnbsnzb\APPLIC~1\Google
2007-08-03 14:49 ——— d——– C:\DOCUME~1\Guest\APPLIC~1\StumbleUpon
2007-08-03 14:49 ——— d——– C:\DOCUME~1\Guest\APPLIC~1\MusicNet
2007-08-03 14:48 ——— d——– C:\Program Files\Windows Media Connect 2
2007-08-03 14:48 ——— d——– C:\Program Files\UseNeXT
2007-08-03 14:48 ——— d——– C:\Program Files\StumbleUpon
2007-08-03 14:48 ——— d——– C:\Program Files\QuickTime
2007-08-03 14:48 ——— d——– C:\Program Files\MSBuild
2007-08-03 14:48 ——— d——– C:\Program Files\Microsoft Works
2007-08-03 14:48 ——— d——– C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2007-08-03 14:47 ——— d——– C:\Program Files\MagicISO
2007-08-03 14:47 ——— d——– C:\Program Files\ltmoh
2007-08-03 14:47 ——— d——– C:\Program Files\iTunes
2007-08-03 14:47 ——— d——– C:\Program Files\iPod
2007-08-03 14:47 ——— d——– C:\Program Files\Google
2007-08-03 14:47 ——— d——– C:\Program Files\GemMaster
2007-08-03 14:47 ——— d——– C:\Program Files\ESPNMotion
2007-08-03 14:47 ——— d——– C:\Program Files\EnglishOtto
2007-08-03 14:47 ——— d——– C:\Program Files\DivX
2007-08-03 14:47 ——— d——– C:\Program Files\DIGStream
2007-08-03 14:47 ——— d——– C:\Program Files\DesktopDialer
2007-08-03 14:47 ——— d——– C:\Program Files\DAEMON Tools
2007-08-03 14:47 ——— d——– C:\Program Files\Common Files\AOL
2007-08-03 14:47 ——— d——– C:\Program Files\BitLord
2007-08-03 14:47 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent
2007-08-03 14:47 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
2007-08-02 21:38 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-07-21 10:43 ——— d——– C:\Program Files\Activision Value
2007-07-18 00:00 ——— d——– C:\Program Files\MarkAny
2007-07-17 23:59 ——— d——– C:\Program Files\Samsung
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TFncKy"="TFncKy.exe" []
"TDispVol"="TDispVol.exe" [2005-03-11 18:03 C:\WINDOWS\system32\TDispVol.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 03:32]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-28 00:55]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-28 00:52]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-28 00:55]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 16:56]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 17:02]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-12-16 03:34]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2004-08-18 06:37]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 09:29 C:\WINDOWS\agrsmmsg.exe]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 15:25]
"TPSMain"="TPSMain.exe" [2005-06-01 00:00 C:\WINDOWS\system32\TPSMain.exe]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" []
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-26 19:13]
"dla"="C:\WINDOWS\system32\dla\DLACTRLW.exe" [2005-10-06 08:20]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 20:37]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 15:37]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 14:41]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 15:49]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-09 18:49 C:\WINDOWS\RTHDCPL.exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2007-01-23 01:26]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SMSTray"="C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-02-23 16:32]
"MAAgent"="C:\Program Files\MarkAny\ContentSafer\MAAgent.exe" [2007-01-30 20:36]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-10 09:18]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-08-12 11:08]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
"RegistryMechanic"="" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 03:32]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-12 23:02]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-06-12 23:02:22]

C:\DOCUME~1\jfnbsnzb\STARTM~1\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 16:51 192512]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\\WINDOWS\\system32\\vtsqr

R0 KR10N;KR10N;C:\WINDOWS\system32\drivers\KR10N.sys
R2 tmxpflt;tmxpflt;C:\WINDOWS\system32\DRIVERS\tmxpflt.sys
S3 IO_Memory;IO_Memory;\??\c:\sysprep\Drivers\ioport.sys
S3 mam4410u;mam4410u;C:\WINDOWS\system32\Drivers\mam4410u.sys
S3 SVRPEDRV;SVRPEDRV;\??\C:\SYSPREP\PEDrv.sys
S3 TcUsb;TC USB Kernel Driver;C:\WINDOWS\system32\Drivers\tcusb.sys
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys

.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-14 14:59:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-14 15:03:03 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-14 15:03
.
— E O F —

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:07:13 PM, on 9/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TDispVol.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\DLACTRLW.exe
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\DLACTRLW.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O15 - Trusted Zone: *.stumbleupon.com
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/XSL/mb_us//h…ALStreaming.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/12ba6da8074d69…ip/RdxIE601.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://aolsvc.aol.com/onlinegames/trydiner…h2.1.0.0.67.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://scc-wlan01.ccccd.edu/sre/Downloads/ICSScanner.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…tg.1.0.0.33.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab
O16 - DPF: {D410AFBD-4E26-4D5F-840F-0412D6F6BB8D} (CPlayFirstSandScriptControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…pt.1.0.0.21.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://aolsvc.aol.com/onlinegames/dinerdas…sh.1.0.0.93.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 13731 bytes
Hi

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\WINDOWS\system32\sstqn.dll
C:\WINDOWS\system32\mljgg.dll
C:\WINDOWS\system32\xyhqlesa.exe
C:\WINDOWS\system32\mlljh.dll
C:\WINDOWS\system32\vtutr.dll
C:\WINDOWS\iun6002ev.exe
C:\\WINDOWS\\system32\\vtsqr


Folder::
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent

Registry::
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Sorry it's taking too long.
Kids…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:36:10 PM, on 9/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TDispVol.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\DLACTRLW.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\DLACTRLW.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O15 - Trusted Zone: *.stumbleupon.com
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/XSL/mb_us//h…ALStreaming.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/12ba6da8074d69…ip/RdxIE601.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://aolsvc.aol.com/onlinegames/trydiner…h2.1.0.0.67.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://scc-wlan01.ccccd.edu/sre/Downloads/ICSScanner.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…tg.1.0.0.33.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab
O16 - DPF: {D410AFBD-4E26-4D5F-840F-0412D6F6BB8D} (CPlayFirstSandScriptControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…pt.1.0.0.21.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://aolsvc.aol.com/onlinegames/dinerdas…sh.1.0.0.93.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 13718 bytes
ComboFix 07-09-14.1 - "You Know….Okay" 2007-09-14 18:25:04.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.203 [GMT -5:00] * Created a new restore point FILE:: C:\WINDOWS\system32\sstqn.dll C:\WINDOWS\system32\mljgg.dll C:\WINDOWS\system32\xyhqlesa.exe C:\WINDOWS\system32\mlljh.dll C:\WINDOWS\system32\vtutr.dll C:\WINDOWS\iun6002ev.exe C:\\WINDOWS\\system32\\vtsqr . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{158986B3-5AF5-7E54-5C71-E9D79DAEB2B5} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{169FEB0E-600F-9C43-37B2-0FB72234D00C} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{1CD9B343-072A-F93B-3CD9-51CA9444F3F2} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{2657F853-E796-6832-CD57-6884A41D376A} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{2DC394C9-5D40-EC1B-C479-6EDCADD20C65} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{2F065397-60A7-5EC3-ABD8-5201822C834D} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{3362F7AA-97CE-1963-2358-63DB7A28718D} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{3716A58B-91B4-BBC4-A744-B430C49B83A2} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{379E62E2-599B-C9C2-A0A9-31DFB6016D37} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{47C51931-69AE-3CF2-CF76-C4AA5D5D43CC} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{4C02913D-DFD8-D691-F255-9B14A3FA309F} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{4EFF5316-3B06-F3BB-B38D-2381DFF4C6BE} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{55247932-D5AF-6F09-06E2-05AC983A61BC} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{5DA0463F-EC2E-6F18-7A5E-C321FA530F61} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{71F7D28A-4EBF-DB40-A037-08CC4F17028A} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{8932C1F7-9B3B-6814-DD3B-92E644999265} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{994D0FDF-5F38-B097-673D-8F551C378F76} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{A1C47D0A-11AF-EDFD-8BBE-730558972100} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{A8AC8183-267F-1784-F1CF-4723A31A7126} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{BA6C55A5-C4C5-E1F5-B0CC-96E7BFC60822} C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia\data\{FABA08BA-EF73-E882-BC5F-1A0755BD1B7C} C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\GameData\gtd2.dat C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\GameData\support.dat C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\LicenseStores\WT58D8AB2-0002-4963-8BEF-C53407A55AB8.wtlic C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\LicenseStores\WT7548446-974e-4089-a0d2-e43ae418512b.wtlic C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\LicenseStores\WT\13E38CFC-81C8-11D9-8BDE-F66BAD1E3F3A.wtlic C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\LicenseStores\WT\4B39DF83-1063-4fcc-B1B4-0E116120D387.wtlic C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\LicenseStores\WT\5F7E059C-CAEF-43ad-9378-DD87D8B6B154.wtlic C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\LicenseStores\WT\6DEEEEDF-6404-4f02-AE07-4F4CB1A3D5F6.wtlic C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\LicenseStores\WT\6E19C296-7722-4e20-A653-2CEA4DCBF293.wtlic C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\LicenseStores\WT\81CB1406-81C8-11D9-8BDE-F66BAD1E3F3A.wtlic C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\LicenseStores\WT\D1FBFB02-8F56-11D9-8BDE-F66BAD1E3F3A.wtlic C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\LicenseStores\WT\F3B5F74E-D848-11D9-8BDE-F66BAD1E3F3A.wtlic C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\LicenseStores\WT\WT.sto C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\moregames.ico C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\oem-eula.dat C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\penguins\Cache\Resources\Levels\ScreenShots\list.txt C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\penguins\Cache\Resources\Levels\ScreenShots\Zone1_BounceBack.lvl.bmp C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\penguins\Cache\Resources\Levels\ScreenShots\Zone1_BounceBack.lvlsmall.bmp C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\penguins\Cache\Resources\Levels\ScreenShots\Zone1_LookoutBelow.lvl.bmp C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\penguins\Cache\Resources\Levels\ScreenShots\Zone1_LookoutBelow.lvlsmall.bmp C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\penguins\Cache\Resources\Levels\ScreenShots\Zone1_OverTheHill.lvl.bmp C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\penguins\Cache\Resources\Levels\ScreenShots\Zone1_OverTheHill.lvlsmall.bmp C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\penguins\Cache\Resources\Levels\ScreenShots\Zone1_TheBigBang.lvl.bmp C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\penguins\Cache\Resources\Levels\ScreenShots\Zone1_TheBigBang.lvlsmall.bmp C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\penguins\Cache\updates\updatelist.txt C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\penguins\Persistent\config.dat C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\penguins\Persistent\resources\profiles\profile0.dat C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Installers\installers.txt C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Installers\SetupGamesClient.exe C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Installers\SetupGamesClient.exe_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block1.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block1.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block10.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block10.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block11.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block11.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block12.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block12.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block13.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block13.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block14.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block14.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block15.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block15.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block16.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block16.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block17.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block17.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block18.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block18.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block19.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block19.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block2.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block2.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block20.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block20.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block21.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block21.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block22.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block22.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block23.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block23.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block24.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block24.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block25.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block25.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block26.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block26.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block27.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block27.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block28.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block28.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block29.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block29.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block3.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block3.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block4.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block4.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block5.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block5.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block6.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block6.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block7.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block7.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block8.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block8.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block9.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\block9.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\chrome.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\chrome.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\htdocs-img.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\htdocs-img.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\htdocs.tgz C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\htdocs.tgz_filedata C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game Console\Downloads\Updates\ProductManifest.xml C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent\TOSHIBA Game
I tried to do the online scan but when I said yes to Active X it starts me over and then I say yes to the Active X and it just keeps starting me over. I don't know what to do. My browser won't even open to a full page. I keep trying to maximize it but it won't. I am not happy with this stupid computer.
That's not your computer, it's Kaspersky. I thought that problem had been sorted now. Try this scanner instead. If you have a problem with this one, click out of it then try again, it usually works.
  • Please go HERE to run PandaActiveScan…

  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)

  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to your desktop.
Post the report in your next reply.
Incident Status Location Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\ComboFix\NirCmd.cfexe Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\ComboFix\nircmd.exe Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@go[1].txt Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.systemdoctor.com/] Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[stats1.reliablestats.com/] Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.atdmt.com/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.advertising.com/] Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.go.com/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.advertising.com/] Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.overture.com/] Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.fastclick.net/] Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.zedo.com/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.2o7.net/] Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.zedo.com/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.2o7.net/] Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.zedo.com/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.2o7.net/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.247realmedia.com/] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[ad.yieldmanager.com/] Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.casalemedia.com/] Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.trafficmp.com/] Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.tribalfusion.com/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.realmedia.com/] Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.adrevolver.com/] Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.tradedoubler.com/] Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.mediaplex.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.serving-sys.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.bs.serving-sys.com/] Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.searchportal.information.com/] Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.revenue.net/] Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.statse.webtrendslive.com/] Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[statse.webtrendslive.com/] Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.ads.pointroll.com/] Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.ehg-dig.hitbox.com/] Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.statcounter.com/] Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.questionmarket.com/] Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.burstnet.com/] Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.xiti.com/] Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.yadro.ru/] Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.weborama.fr/] Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.targetnet.com/] Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.statse.webtrendslive.com/S125318] Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.valueclick.com/] Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.server.iad.liveperson.net/] Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.server.iad.liveperson.net/hc/34292599] Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.server.iad.liveperson.net/hc/LPneimanmarcus] Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.target.com/] Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.toplist.cz/] Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.qksrv.net/] Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.phg.hitbox.com/] Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.perf.overture.com/] Spyware:Cookie/Mysearch Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.mysearch.com/] Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.linksynergy.com/] Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.landing.domainsponsor.com/] Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.linksynergy.com/] Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.maxserving.com/] Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Cassandra\Application Data\Mozilla\Firefox\Profiles\yogjwaa8.default\cookies.txt[.i.screensavers.com/] Spyware:Cookie/217.73.66.16 Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@217.73.66[2].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][2].txt Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][2].txt Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][1].txt Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][2].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@advertising[2].txt Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][1].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@atdmt[2].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed]-sys[2].txt Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@ccbill[1].txt Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@cdfreaks[2].txt Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][1].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@doubleclick[1].txt Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@enhance[2].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@fastclick[1].txt Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][2].txt Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@gostats[2].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][2].txt Spyware:Cookie/Servlet Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@livehelper[1].txt Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@mediaplex[1].txt Spyware:Cookie/Mysearch Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@mysearch[2].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@questionmarket[2].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@realmedia[2].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@serving-sys[1].txt Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@statcounter[2].txt Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@target[1].txt Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@toplist[1].txt Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@tradedoubler[1].txt Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@trafficmp[1].txt Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@winantivirus[1].txt Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@winantivirus[2].txt Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][2].txt Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][1].txt Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][1].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][2].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][1].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Cassandra\Cookies\[removed][1].txt Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@xiti[1].txt Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@yadro[1].txt Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Cassandra\Cookies\cassandra@zedo[1].txt Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Cassandra\Desktop\ComboFix.exe[nircmd.exe] Virus:Trj/Downloader.QDR Disinfected C:\Documents and Settings\Cassandra\Local Settings\Temp\Setup(1).exe Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\LB5VNVYY\jaun_20070726[1] Virus:Generic Trojan Disinfected C:\Documents and Settings\Cassandra\Shared\Popcap & Gamehouse 31 games + cracks\Popcap & Gamehouse\Dynomite 2.01\eatdy201ck.exe Potentially unwanted tool:Application/PRScheduler Not disinfected C:\Documents and Settings\Cassandra\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe Spyware:Cookie/Gaytrafficbroker Not disinfected C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\ydeadc2u.default\cookies.txt[gaytrafficbroker.com/] Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\ydeadc2u.default\cookies.txt[.cs.sexcounter.com/] Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\ydeadc2u.default\cookies.txt[counter7.sextracker.com/] Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\ydeadc2u.default\cookies.txt[.sextracker.com/] Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\ydeadc2u.default\cookies.txt[.cs.sexcounter.com/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Guest\Cookies\[removed][2].txt Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\jfnbsnzb\Cookies\jfnbsnzb@atwola[1].txt Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\jfnbsnzb\Cookies\jfnbsnzb@azjmp[1].txt Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\jfnbsnzb\Cookies\jfnbsnzb@burstnet[2].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\jfnbsnzb\Cookies\[removed][2].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\jfnbsnzb\Cookies\jfnbsnzb@fastclick[2].txt Spyware:Cookie/Go Not disinfected C:\Documents and Settings\jfnbsnzb\Cookies\jfnbsnzb@go[1].txt Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\jfnbsnzb\Cookies\[removed][2].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you [removed] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@247realmedia[2].txt Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@2o7[1].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\[removed][1].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\[removed][3].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\[removed][5].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\[removed][7].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\[removed][8].txt Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@adrevolver[1].txt Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\[removed][1].txt Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\[removed][2].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@advertising[1].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@atdmt[2].txt Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@bluestreak[2].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\[removed]-sys[1].txt Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@casalemedia[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@com[1].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@doubleclick[1].txt Spyware:Cookie/Go Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@go[2].txt Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@mediaplex[1].txt Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\[removed][1].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@questionmarket[2].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@realmedia[2].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@serving-sys[2].txt Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\[removed][2].txt Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@trafficmp[2].txt Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@tribalfusion[1].txt Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\[removed][1].txt Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\[removed][1].txt Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@zedo[2].txt Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\You Know….Okay\Cookies\you_know….okay@zedo[3].txt Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\You Know….Okay\Desktop\ComboFix.exe[nircmd.exe] Spyware:Cookie/Winantivirus Not disinfected C:\qoobox\Quarantine\C\WINDOWS\retadpu880.exe.vir Spyware:Spyware/Virtumonde Not disinfected C:\qoobox\Quarantine\C\WINDOWS\system32\cbxvvtq.dll.vir Spyware:Spyware/Virtumonde Not disinfected C:\qoobox\Quarantine\C\WINDOWS\system32\efccday.dll.vir Spyware:Spyware/Virtumonde Not disinfected C:\qoobox\Quarantine\C\WINDOWS\system32\efccyab.dll.vir Spyware:Spyware/Virtumonde Not disinfected C:\qoobox\Quarantine\C\WINDOWS\system32\fcccdcc.dll.vir Spyware:Spyware/Virtumonde Not disinfected C:\qoobox\Quarantine\C\WINDOWS\system32\ufacskea.dll.vir Virus:Trj/Downloader.OZB Disinfected C:\qoobox\Quarantine\C\WINDOWS\system32\xyhqlesa.exe.vir Spyware:Spyware/Virtumonde Not disinfected C:\qoobox\Quarantine\catchme2007-09-14_145924.93.zip[iifcday.dll] Spyware:Spyware/Virtumonde Not disinfected C:\qoobox\Quarantine\catchme2007-09-14_145924.93.zip[vapuiglj.dll] Virus:Trj/Downloader.MDW Disinfected C:\WINDOWS\Downloaded Program Files\popcaploader.dll Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\NirCmd.exe
Hi

Delete the Combofix icon from your Desktop.

Navigate to and delete the following folders (if they are present):

Folders:
C:\Qoobox
C:\Combofix

Download ATF (Atribune Temp File) Cleaner by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it.

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.

*Note* If you do not have Firefox or Opera, those options will be greyed out.

Delete the older versions of Java and download the newest.
Please follow these steps to remove older version Java components.
  • Close any programmes you may have running, ESPECIALLY your web browser
  • Click Start > Control Panel.
  • Click Add/Remove Programs.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove all versions of Java.
  • Reboot your computer once all Java components are removed.
Then download the latest version of Java Runtime Environment (JRE) (4th one down the list), which is JRE6u2, and click Yes at the page warning, then accept the Licence Agreement before downloading the Offline file.


Then post a new HijackThis log, please.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:31:33 PM, on 9/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TDispVol.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\DLACTRLW.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\DLACTRLW.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O15 - Trusted Zone: *.stumbleupon.com
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/XSL/mb_us//h…ALStreaming.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/12ba6da8074d69…ip/RdxIE601.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://aolsvc.aol.com/onlinegames/trydiner…h2.1.0.0.67.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://scc-wlan01.ccccd.edu/sre/Downloads/ICSScanner.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…tg.1.0.0.33.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab
O16 - DPF: {D410AFBD-4E26-4D5F-840F-0412D6F6BB8D} (CPlayFirstSandScriptControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…pt.1.0.0.21.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://aolsvc.aol.com/onlinegames/dinerdas…sh.1.0.0.93.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 13630 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI