This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please help remove Spyware Guard 2008

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Seeking assistance removing Spyware Guard 2008 from my wife's computer (my old laptop). Can't seem to install any of the programs recommended to remove the offending "software" (Malwarebytes AntiMalware, SuperAntiSpyware etc…), visit any of the support websites or manage to remove the program manually. I originally attempted to post my logfile using HJT 1.99.1 and was redirected to reinstall HijackThis 2.00.2 message and repost. It appears that Spyware Guard 2008 is not allowing me to install HJT 2.00.2 on the infected laptop so I have attached the HijackThis v1.99.1 logfile as an attachment rather than in the body of the message. If this will not work can someone please suggest an option that will work. I'm a newbie. Please note: I did have Symantec AntiVirus installed on this laptop at one point when I used this laptop on my company's network a year couple of years ago (after being screened and confirmed clean) but do not currently use use Symantec. No issue deinstalling it and installing another AV and antispyware app. This is the perfect opportunity to install on the other 5 home computers before a serious issue hits home! I also was not able to save an uninstall list with Hijackthis. Every time I attempted to save the uninstall list HijackThis shut down without saving. Thanks in advance for any assistance you can provide to this neophyte. Regards, Jim
[external image: Posted Image]

DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results in the Malware Forum.


Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Thanks for your response.

I followed your instructions and cleared "Hide file extensions for known file types." And cleared "Hide protected operating system files." under the "Hidden files" folder, clicked apply, and then clicked OK. I then downloaded ATF Cleaner and ran per your instructions and downloaded Malwarebytes’ Anti-Malware and attempted to install the program but nothing happens when I double click and attempt to install the program. I renamed the download to imangry.exe and was able to install it. I also downloaded the mwaw-rules.exe file, renamed it and was able to install. I tried to run MWAM multiple times and was not able to actually run it, it just hung. I then rebooted in safe mode and was not able to run MWAM, it just hung with the hourglass. So, to date, I have been unable to run MWAM on this laptop.

I renamed HJTv2.0.2 install file and was finally able to install it, ran it and saved a new logfile. I have not been able to save an uninstall list with HJT 2.0.2 or earlier versions when I hit the “Save List” button HJT appears to save something then HJT shuts down. Maybe I’m looking in the wrong place for the file? I’ve navigated around to everywhere I can think of and then searched the entire computer scanning files changed today and can’t find a file that could be the uninstall list. If I’m missing the point I could use a good dope slap.

My computer’s behavior is as follows:

When I boot the laptop it is taking significantly longer at startup (approx 10 – 12 minutes) the first application that loads appears to be Spyware Guard 2008, the computer freezes at this point or crawls through startup until I close both of the Spyware Guard splash screens and then the laptop appears to continue through the boot process. The laptop runs slower than I remember it running and every few minutes the Spyware Guard 2008 splash screens pop up and I close them. When I attempt to uninstall the Spyware Guard application it disappears from my list of applications and several minutes later it pops back up again, when I attempt to manually remove it from my list of processes it begins to run several minutes later. The application is not allowing me to visit the support websites (such as this one) and does not allow me to install many of the applications to properly scan and remove Spyware Guard 2008. I get the redirects to garbage sites when googling for fixes to Spyware Guard 2008 and then clicking on the link.

I’ve rebooted in safe mode and attempted to run through your instructions but I have the same results. My laptop is running a little slower but I can surf the web. I’m just restricted from visiting certain websites and installing any applications that could potentially remove the offending application. The laptop does slow down considerably when Spyware Guard 2008 is about to pop up.

I have several clean computers available to me so I can download any of the suggested applications to a clean machine and transfer them via stick or other methods but if I cannot run them after installing it’s an issue. Let me know what additional infomation you might need, I realize this is only half of the information requested. Are there any other ways that I can get MWAM running to actually scan the machine?

Thanks.

Here’s my logfile:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:58:14 PM, on 1/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\orclobi\MyDesktop\MyDesktopService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\orclobi\MyDesktop\MyDesktopQOS.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\EzButton\CPLBTS88.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\winscenter.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Spyware Guard 2008\spywareguard.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\sorry.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [CPLBTS88] C:\PROGRA~1\EzButton\CPLBTS88.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [spywareguard] C:\Program Files\Spyware Guard 2008\spywareguard.exe
O4 - HKLM\..\Run: [0412e483] rundll32.exe "C:\WINDOWS\system32\sniwctbo.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [SfKg6wIP] C:\Documents and Settings\Jim Doherty\Application Data\Microsoft\Windows\nagcyxp.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: Digimax Viewer 2.1.lnk = ?
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139720255630
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139720215712
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL pumpvq.dll
O21 - SSODL: ieModule - {B1914F88-CB3E-422C-85BA-FF77D4A3931B} - C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
O21 - SSODL: InternetConnection - {51B82DF7-6F84-458A-8587-1E76CCF5A0E8} - C:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\wiefwuhjes.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MyDesktopService (MyDesktopWindows) - Oracle Corporation - C:\WINDOWS\orclobi\MyDesktop\MyDesktopService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: QOS MyDesktop (QOSMyDesktop) - Oracle - C:\WINDOWS\orclobi\MyDesktop\MyDesktopQOS.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 8068 bytes
I can see a few bad guys in there.

I think this will do the trick.

Please do not delete anything unless instructed to.

NOTE: worksnow is actually Combofix renamed so user is able download and run Combofix

Download worksnow from HERE:


* IMPORTANT !!! Save worksnow to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on worksnow & follow the prompts.

    Note: worksnow will run without the Recovery Console installed.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, combofix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Thanks for all your help. I assume that I have a little more to do before I am out of the woods since I do not have the recovery console installed. I'm kind of amazed at the number of files that were deleted since this laptop is hardly ever used.

While I ran through the ComboFix process I initially received an error message stating that I was not connected to the internet, I confirmed that I had an internet connection, clicked OK then ComboFix attempted to download the necessary files, aborted part way through with a message stating that it could not download the necessary files and prompted me to continue. I clicked OK and then ComboFix scanned for infected files.

Received RootKit !! message with a prompt to reboot and instructions to write down the name of each file. I captured them down and clicked OK. Apparently I did not need to use the information to correct anything manually and I'm not sure if we’ll need them but here they are.

C:\\WINDOWS\system32\drivers\TDSSmhxt.sys
C:\\WINDOWS\system32\TDSSofxh.dll
C:\\WINDOWS\system32\TDSSosvd.dat
C:\\WINDOWS\system32\TDSSbrsr.dll
C:\\WINDOWS\system32\TDSSriqp.dll
C:\\WINDOWS\system32\TDSScfum.dll
C:\\WINDOWS\system32\TDSSlxwp.dll
C:\\WINDOWS\system32\TDSSnmxq.log
C:\\WINDOWS\system32\TDSSsihl.dll
C:\\WINDOWS\system32\TDSSrhym.log
C:\\WINDOWS\system32\TDSStkdv.log

ComboFix rebooted and continued to scan, prompted me to install the “Windows Recovery Console” which I accepted, received Internal Error! failed to enumerate download path error, aborting, shall continue to scan for malware, allowed ComboFix to reboot the laptop and prepared the log report.

Current state of the laptop is that it is running significantly faster, internet access appears faster and more responsive. I rebooted and it took less than 2 minutes versus the 20 minutes it took last time. I will need to install an antivirus/antispyware application and am looking for recommendations as I have several other computers I would like to bring up to speed. I hate to think what might be lurking on my children’s and wife's desktop computers since they have a tendency to click on everything.

I’d prefer to remove Symantec AntiVirus on this machine and replace it with an AV program that I will keep up to date since the Symantec is not properly licensed anymore and a couple of years out of date. Thanks again for your help to date. Here are the requested logs.

ComboFix Log:

ComboFix 09-01-05.05 - Jim Doherty 2009-01-09 21:35:37.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.307 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\worksnow.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Outdated)

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\moduleie.dll
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\Microsoft\Protect\svhost.exe
c:\documents and settings\All Users\Application Data\svhost.exe
c:\documents and settings\Jim Doherty\Application Data\gadcom
c:\documents and settings\Jim Doherty\Application Data\GetModule
c:\documents and settings\Jim Doherty\Application Data\GetModule\dicik.gz
c:\documents and settings\Jim Doherty\Application Data\GetModule\kwdik.gz
c:\documents and settings\Jim Doherty\Application Data\GetModule\ofadik.gz
c:\documents and settings\Jim Doherty\Application Data\SpeedRunner
c:\documents and settings\Jim Doherty\Application Data\SpeedRunner\config.cfg
c:\documents and settings\Jim Doherty\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\GetModule
c:\program files\Mjcore
c:\program files\Mjcore\Mjcore.dll
c:\program files\Spyware Guard 2008
c:\program files\Spyware Guard 2008\conf.cfg
c:\program files\Spyware Guard 2008\mbase.vdb
c:\program files\Spyware Guard 2008\quarantine.vdb
c:\program files\Spyware Guard 2008\queue.vdb
c:\program files\Spyware Guard 2008\spywareguard.exe
c:\program files\Spyware Guard 2008\uninstall.exe
c:\program files\Spyware Guard 2008\vbase.vdb
c:\windows\IE4 Error Log.txt
c:\windows\reged.exe
c:\windows\sorry.exe
c:\windows\spoolsystem.exe
c:\windows\sys.com
c:\windows\syscert.exe
c:\windows\sysexplorer.exe
c:\windows\system32\.log
c:\windows\system32\awtsTLEX.dll
c:\windows\system32\bbnbfich.dll
c:\windows\system32\bivuzy.dll
c:\windows\system32\drivers\TDSSmhxt.sys
c:\windows\system32\fuwaplqe.dll
c:\windows\system32\gjixgjoc.dll
c:\windows\system32\hffibbww.dll
c:\windows\system32\lxsrtvkv.dll
c:\windows\system32\mcrh.tmp
c:\windows\system32\nnnlmMcb.dll
c:\windows\system32\ojaxdd.dll
c:\windows\system32\pumpvq.dll
c:\windows\system32\sniwctbo.dll
c:\windows\system32\tblika.dll
c:\windows\system32\TDSSbrsr.dll
c:\windows\system32\TDSScfum.dll
c:\windows\system32\TDSSlxwp.dll
c:\windows\system32\TDSSnmxq.log
c:\windows\system32\TDSSofxh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsihl.dll
c:\windows\system32\TDSStkdv.log
c:\windows\system32\uofoxr.dll
c:\windows\system32\winscenter.exe
c:\windows\system32\XELTstwa.ini
c:\windows\system32\XELTstwa.ini2
c:\windows\system32\xpbuetgd.dll
c:\windows\system32\xtnxtahn.dll
c:\windows\system32\ynkgsyxd.dll
c:\windows\vmreg.dll
c:\windows\wiaserviv.log

—– BITS: Possible infected sites —–

hxxp://childhe.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_TDSSSERV.SYS
——-\Legacy_TDSSSERV.SYS


((((((((((((((((((((((((( Files Created from 2008-12-10 to 2009-01-10 )))))))))))))))))))))))))))))))
.

2009-01-09 17:05 . 2009-01-04 18:38 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-09 17:04 . 2009-01-09 17:04 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-09 17:04 . 2009-01-04 18:38 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-09 16:54 . 2009-01-09 16:54 d——– c:\program files\Trend Micro
2009-01-07 23:57 . 2009-01-07 23:57 1,320,830 –ahs—- c:\windows\system32\obtcwins.ini
2009-01-06 22:32 . 2009-01-06 22:33 1,320,830 –ahs—- c:\windows\system32\cojgxijg.ini
2009-01-06 21:33 . 2002-11-25 20:24 d——– c:\documents and settings\Administrator\WINDOWS
2009-01-06 21:33 . 2002-11-25 20:32 d——– c:\documents and settings\Administrator\Application Data\Symantec
2009-01-06 21:33 . 2002-11-25 20:28 d——– c:\documents and settings\Administrator\Application Data\InterTrust
2009-01-06 21:33 . 2002-11-25 20:40 d——– c:\documents and settings\Administrator\Application Data\Drag'n Drop CD
2009-01-06 21:33 . 2009-01-06 21:33 d——– c:\documents and settings\Administrator
2009-01-06 21:22 . 2009-01-06 21:22 0 –a—— c:\windows\TPTray.INI
2009-01-05 20:53 . 2009-01-05 20:53 d–h—– c:\windows\PIF
2009-01-05 20:43 . 2009-01-05 20:43 1,307,392 –ahs—- c:\windows\system32\dgteubpx.ini
2009-01-05 07:49 . 2009-01-09 18:05 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-04 20:15 . 2009-01-04 20:15 176,640 –a—— c:\windows\system32\mjkjkfpg.exe
2009-01-04 20:09 . 2009-01-05 20:38 1,307,392 –ahs—- c:\windows\system32\mbkpgtst.ini
2009-01-04 01:01 . 2009-01-04 01:20 d——– c:\windows\SxsCaPendDel
2009-01-04 00:04 . 2009-01-04 00:09 d——– c:\documents and settings\All Users\Application Data\SITEguard
2009-01-04 00:02 . 2009-01-04 00:02 d——– c:\program files\Common Files\iS3
2009-01-04 00:02 . 2009-01-04 01:00 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
2009-01-03 22:00 . 2009-01-03 22:00 d——– c:\program files\Alwil Software
2009-01-03 18:25 . 2009-01-03 18:53 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2009-01-03 17:53 . 2009-01-04 00:09 d——– c:\documents and settings\Jim Doherty\Application Data\Twain
2009-01-03 17:44 . 2009-01-03 17:45 1,307,356 –ahs—- c:\windows\system32\vkvtrsxl.ini
2009-01-03 17:37 . 2009-01-03 17:37 72,192 –a—— c:\windows\system32\pmnkKdEv.dll
2008-12-22 22:19 . 2008-12-22 22:18 410,984 –a—— c:\windows\system32\deploytk.dll
2008-12-22 22:19 . 2008-12-22 22:18 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-12-22 21:03 . 2008-12-22 21:05 d——– c:\program files\iTunes
2008-12-22 21:03 . 2008-12-22 21:05 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-22 21:02 . 2008-12-22 21:02 d——– c:\program files\Bonjour
2008-12-22 21:00 . 2008-12-22 21:01 d——– c:\program files\QuickTime
2008-12-22 20:19 . 2008-12-22 20:19 54,156 –ah—– c:\windows\QTFont.qfn
2008-12-22 20:19 . 2008-12-22 20:19 1,409 –a—— c:\windows\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 04:29 ——— d—–w c:\program files\Symantec AntiVirus
2009-01-04 04:16 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-04 04:12 ——— d—–w c:\program files\Symantec
2009-01-04 04:11 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-12-23 03:18 ——— d—–w c:\program files\Java
2008-12-23 02:04 ——— d—–w c:\program files\iPod
2008-12-03 02:46 ——— d—–w c:\program files\NCH Swift Sound
2008-12-03 02:46 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\NCH Swift Sound
2008-11-23 04:18 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\gtk-2.0
2008-11-22 23:43 ——— d—–w c:\program files\Google
2008-11-16 18:17 ——— d—–w c:\program files\Kodak
2008-11-16 18:17 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\Kodak
2008-11-16 15:59 ——— d—–w c:\program files\Apple Software Update
2008-11-16 16:06 122,880 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-01-04 03:01 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2009-01-04 03:01 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-04 03:01 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2009-01-04 03:02 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-04 03:02 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\MSMSGS.EXE" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2002-03-29 122880]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2002-10-28 167936]
"CPLBTS88"="c:\progra~1\EzButton\CPLBTS88.EXE" [2002-11-08 204800]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2002-11-08 434176]
"CeEPOWER"="c:\program files\TOSHIBA\Power Management\CePMTray.exe" [2002-11-14 86016]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2002-10-17 45056]
"ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [2002-08-20 40960]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2001-11-14 147456]
"StrgSync.exe"="c:\program files\StorageSync\StrgSync.exe" [2004-07-19 3018752]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-11-16 29744]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2002-11-25 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-22 136600]
"nwiz"="nwiz.exe" [2002-11-12 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-02-14 82026]
DataViz Inc Messenger.lnk - c:\program files\Common Files\DataViz\DvzIncMsgr.exe [2006-02-06 28672]
Digimax Viewer 2.1.lnk - c:\program files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe [2006-02-12 634880]
HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-06-09 471040]
Instant Wireless Configuration Utility.lnk - c:\program files\Linksys\WPC11 Config Utility\WPC11Cfg.exe [2006-02-05 180224]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
2004-11-01 14:50 8704 c:\windows\system32\PCANotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JPEG"= JPEGCODE.DLL
"VIDC.MJPG"= JPEGCODE.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R3 WBSD;Winbond Secure Digital Storage Device Driver;c:\windows\system32\drivers\wbsd.sys [2002-11-25 25728]
R3 WPC11;Instant Wireless Network PC Card V3.0 Driver;c:\windows\system32\drivers\LSWLNDS.sys [2006-02-05 54083]
R4 DPortIO;Dritek Port I/O Driver;c:\windows\system32\drivers\DPORTIO.SYS [2001-04-12 3674]
R4 MyDesktopWindows;MyDesktopService;c:\windows\orclobi\MyDesktop\MyDesktopService.exe [2007-10-19 964096]
R4 QOSMyDesktop;QOS MyDesktop;c:\windows\orclobi\MyDesktop\MyDesktopQOS.exe [2006-04-21 450560]
R4 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2005-04-17 124608]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-03-25 29744]
S4 mrtRate;mrtRate; [x]
Unknown4 dsload;dsload; [x]
.
Contents of the 'Scheduled Tasks' folder

2008-12-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-01-10 c:\windows\Tasks\pyadjiih.job
- c:\windows\system32\rundll32.exe [2004-08-04 02:56]
.
- - - - ORPHANS REMOVED - - - -

BHO-{069ade22-8ef4-41ac-8760-fc26b2c1348a} - c:\windows\system32\pumpvq.dll
BHO-{1CE751A8-F846-49EF-BA10-16E3190AB40C} - c:\windows\system32\awtsTLEX.dll
BHO-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\nnnlmMcb.dll
Toolbar-SITEguard - (no file)
HKLM-Run-spywareguard - c:\program files\Spyware Guard 2008\spywareguard.exe
ShellExecuteHooks-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\nnnlmMcb.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/?myHome
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: *.turbotax.com

O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\Jim Doherty\Application Data\Mozilla\Firefox\Profiles\ojn9q6ds.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.oracle.com/
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-09 21:47:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2982558324-977338740-2252588409-1005\Software\Microsoft\SystemCertificates\AddressBook*NULL*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
———————— Other Running Processes ————————
.
c:\program files\Apoint2K\ApntEx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-09 21:51:38 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-10 02:51:35

Pre-Run: 6,252,277,760 bytes free
Post-Run: 6,164,881,408 bytes free

261 — E O F — 2008-12-23 13:10:53

New HijackThis Logfile:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:56:53 PM, on 1/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\PROGRA~1\EzButton\CPLBTS88.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\StorageSync\StrgSync.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\orclobi\MyDesktop\MyDesktopService.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\orclobi\MyDesktop\MyDesktopQOS.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [CPLBTS88] C:\PROGRA~1\EzButton\CPLBTS88.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: Digimax Viewer 2.1.lnk = ?
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139720255630
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139720215712
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MyDesktopService (MyDesktopWindows) - Oracle Corporation - C:\WINDOWS\orclobi\MyDesktop\MyDesktopService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: QOS MyDesktop (QOSMyDesktop) - Oracle - C:\WINDOWS\orclobi\MyDesktop\MyDesktopQOS.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 8056 bytes
We'll work on the removal of Symantec after you're pc is cleaned.

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

http://forums.whatthetech.com/Please_help_remove_Spyware_Guard_2008_t98759.html

File::
c:\windows\Tasks\pyadjiih.job

Collect::
c:\windows\system32\obtcwins.ini
c:\windows\system32\cojgxijg.ini
c:\windows\system32\dgteubpx.ini
c:\windows\system32\mjkjkfpg.exe
c:\windows\system32\mbkpgtst.ini
c:\windows\system32\vkvtrsxl.ini
c:\windows\system32\pmnkKdEv.dll

Folder::
c:\program files\Bonjour

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Thanks for all of your help.

I copied provided code, saved as .txt file, dragged to ComboFix, received prompt regarding not having console, ComboFix doesn't seem to recognize or identify my active internet connection but when I launched IE the connection was recognized and the download started from the Microsoft site , downloaded 4 MB update, accepted user agreement, successfully installed the recovery console, began scanning for infected files, deleted some files, completed multiple stages, Windows shut down and rebooted laptop, prepared log report and HijackThis Logfile.

The computer appears to be running fairly normally, though my internet connection seems to be a little slow (could easily be my ISP). It boots within a minute or two and I’m not receiving any spash or nag screens from the Spyware Guard application or any other unknown apps. There are Windows updates to install, but I haven’t installed since I’m not sure if it will impact what you are directing me to do. Thanks again.

Here’s the new ComboFix Log:

ComboFix 09-01-05.05 - Jim Doherty 2009-01-10 11:33:15.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.253 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\worksnow.exe
Command switches used :: c:\documents and settings\Jim Doherty\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Outdated)
* Created a new restore point

FILE ::
c:\windows\Tasks\pyadjiih.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Bonjour
c:\program files\Bonjour\About Bonjour.rtf
c:\program files\Bonjour\mdnsNSP.dll
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\cojgxijg.ini
c:\windows\system32\dgteubpx.ini
c:\windows\system32\mbkpgtst.ini
c:\windows\system32\mjkjkfpg.exe
c:\windows\system32\obtcwins.ini
c:\windows\system32\pmnkKdEv.dll
c:\windows\system32\vkvtrsxl.ini
c:\windows\Tasks\pyadjiih.job
c:\windows\Temp\tmp3.tmp

.
((((((((((((((((((((((((( Files Created from 2008-12-10 to 2009-01-10 )))))))))))))))))))))))))))))))
.

2009-01-09 17:05 . 2009-01-04 18:38 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-09 17:04 . 2009-01-09 17:04 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-09 17:04 . 2009-01-04 18:38 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-09 16:54 . 2009-01-09 16:54 d——– c:\program files\Trend Micro
2009-01-06 21:33 . 2002-11-25 20:24 d——– c:\documents and settings\Administrator\WINDOWS
2009-01-06 21:33 . 2002-11-25 20:32 d——– c:\documents and settings\Administrator\Application Data\Symantec
2009-01-06 21:33 . 2002-11-25 20:28 d——– c:\documents and settings\Administrator\Application Data\InterTrust
2009-01-06 21:33 . 2002-11-25 20:40 d——– c:\documents and settings\Administrator\Application Data\Drag'n Drop CD
2009-01-06 21:33 . 2009-01-06 21:33 d——– c:\documents and settings\Administrator
2009-01-06 21:22 . 2009-01-06 21:22 0 –a—— c:\windows\TPTray.INI
2009-01-05 20:53 . 2009-01-05 20:53 d–h—– c:\windows\PIF
2009-01-05 07:49 . 2009-01-09 18:05 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-04 01:01 . 2009-01-04 01:20 d——– c:\windows\SxsCaPendDel
2009-01-04 00:04 . 2009-01-04 00:09 d——– c:\documents and settings\All Users\Application Data\SITEguard
2009-01-04 00:02 . 2009-01-04 00:02 d——– c:\program files\Common Files\iS3
2009-01-04 00:02 . 2009-01-04 01:00 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
2009-01-03 22:00 . 2009-01-03 22:00 d——– c:\program files\Alwil Software
2009-01-03 18:25 . 2009-01-03 18:53 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2009-01-03 17:53 . 2009-01-04 00:09 d——– c:\documents and settings\Jim Doherty\Application Data\Twain
2008-12-22 22:19 . 2008-12-22 22:18 410,984 –a—— c:\windows\system32\deploytk.dll
2008-12-22 22:19 . 2008-12-22 22:18 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-12-22 21:03 . 2008-12-22 21:05 d——– c:\program files\iTunes
2008-12-22 21:03 . 2008-12-22 21:05 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-22 21:00 . 2008-12-22 21:01 d——– c:\program files\QuickTime
2008-12-22 20:19 . 2008-12-22 20:19 54,156 –ah—– c:\windows\QTFont.qfn
2008-12-22 20:19 . 2008-12-22 20:19 1,409 –a—— c:\windows\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 04:29 ——— d—–w c:\program files\Symantec AntiVirus
2009-01-04 04:16 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-04 04:12 ——— d—–w c:\program files\Symantec
2009-01-04 04:11 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-12-23 03:18 ——— d—–w c:\program files\Java
2008-12-23 02:04 ——— d—–w c:\program files\iPod
2008-12-03 02:46 ——— d—–w c:\program files\NCH Swift Sound
2008-12-03 02:46 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\NCH Swift Sound
2008-11-23 04:18 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\gtk-2.0
2008-11-22 23:43 ——— d—–w c:\program files\Google
2008-11-16 18:17 ——— d—–w c:\program files\Kodak
2008-11-16 18:17 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\Kodak
2008-11-16 15:59 ——— d—–w c:\program files\Apple Software Update
2008-11-16 16:06 122,880 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-01-04 03:01 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2009-01-04 03:01 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-04 03:01 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2009-01-04 03:02 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-04 03:02 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\MSMSGS.EXE" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2002-03-29 122880]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2002-10-28 167936]
"CPLBTS88"="c:\progra~1\EzButton\CPLBTS88.EXE" [2002-11-08 204800]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2002-11-08 434176]
"CeEPOWER"="c:\program files\TOSHIBA\Power Management\CePMTray.exe" [2002-11-14 86016]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2002-10-17 45056]
"ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [2002-08-20 40960]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2001-11-14 147456]
"StrgSync.exe"="c:\program files\StorageSync\StrgSync.exe" [2004-07-19 3018752]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-22 136600]
"nwiz"="nwiz.exe" [2002-11-12 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-02-14 82026]
Digimax Viewer 2.1.lnk - c:\program files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe [2006-02-12 634880]
Instant Wireless Configuration Utility.lnk - c:\program files\Linksys\WPC11 Config Utility\WPC11Cfg.exe [2006-02-05 180224]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
2004-11-01 14:50 8704 c:\windows\system32\PCANotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JPEG"= JPEGCODE.DLL
"VIDC.MJPG"= JPEGCODE.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DataViz Inc Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DataViz Inc Messenger.lnk
backup=c:\windows\pss\DataViz Inc Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2005-04-08 18:52 48752 c:\program files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
–a—— 2008-11-16 11:06 29744 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2002-11-25 20:36 26112 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R3 WBSD;Winbond Secure Digital Storage Device Driver;c:\windows\system32\drivers\wbsd.sys [2002-11-25 25728]
R3 WPC11;Instant Wireless Network PC Card V3.0 Driver;c:\windows\system32\drivers\LSWLNDS.sys [2006-02-05 54083]
R4 DPortIO;Dritek Port I/O Driver;c:\windows\system32\drivers\DPORTIO.SYS [2001-04-12 3674]
R4 MyDesktopWindows;MyDesktopService;c:\windows\orclobi\MyDesktop\MyDesktopService.exe [2007-10-19 964096]
R4 QOSMyDesktop;QOS MyDesktop;c:\windows\orclobi\MyDesktop\MyDesktopQOS.exe [2006-04-21 450560]
R4 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2005-04-17 124608]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-03-25 29744]
S4 mrtRate;mrtRate; [x]
Unknown4 dsload;dsload; [x]

— Other Services/Drivers In Memory —

*NewlyCreated* - PCANDIS5
.
Contents of the 'Scheduled Tasks' folder

2008-12-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/?myHome
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: *.turbotax.com

O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\Jim Doherty\Application Data\Mozilla\Firefox\Profiles\ojn9q6ds.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.oracle.com/
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-10 11:37:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2982558324-977338740-2252588409-1005\Software\Microsoft\SystemCertificates\AddressBook*NULL*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Apoint2K\ApntEx.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-01-10 11:41:14 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-10 16:41:11
ComboFix2.txt 2009-01-10 02:51:40

Pre-Run: 6,104,969,216 bytes free
Post-Run: 6,112,608,256 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

203 — E O F — 2008-12-23 13:10:53

Here’s the new HijackThis Logfile:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:55:39 AM, on 1/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\PROGRA~1\EzButton\CPLBTS88.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\StorageSync\StrgSync.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\orclobi\MyDesktop\MyDesktopService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\orclobi\MyDesktop\MyDesktopQOS.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [CPLBTS88] C:\PROGRA~1\EzButton\CPLBTS88.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Digimax Viewer 2.1.lnk = ?
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139720255630
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139720215712
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MyDesktopService (MyDesktopWindows) - Oracle Corporation - C:\WINDOWS\orclobi\MyDesktop\MyDesktopService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: QOS MyDesktop (QOSMyDesktop) - Oracle - C:\WINDOWS\orclobi\MyDesktop\MyDesktopQOS.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 7488 bytes

Here's my HJT Uninstall List:

Acoustica Effects Pack
Acoustica Mixcraft
Adobe Acrobat 5.0
Adobe Flash Player 9 ActiveX
ALPS Touch Pad Driver
America Online
AnswerWorks 4.0 Runtime - English
Apple Mobile Device Support
Apple Software Update
ArcSoft PhotoImpression 4
Avance AC'97 Audio
Bonjour
BUM
Digimax A7
Digimax Viewer 2.1
Documents To Go
Drag'n Drop CD
Easy Button
Express Rip
exPressit S.E. 2.2
Google Desktop
Google Earth
Hijackthis 1.99.1
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
HyperSnap-DX 5.62.05
InterVideo WinDVD 4
iPod for Windows 2006-01-10
iPod Updater 2004-11-15
iTunes
Java™ 6 Update 11
KODAK Gallery Upload Software
LimeWire 4.18.8
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Baseline Security Analyzer 1.2.1
Microsoft Office 2000 Disc 2
Microsoft Office 2000 Premium
MP3 CD Converter Professional 5.01
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Network Device Switch 3
NVIDIA Windows 2000/XP Display Drivers
Oracle Connector For Outlook
Oracle Connector for Outlook
Oracle JInitiator 1.3.1.18
Oracle JInitiator [removed]
Oracle Web Conferencing Console
palmOne
PcAnyWhere 11.5 HostLAN
Picasa 3
Prism
Quicken 2003 New User Edition
QuickTime
RealPlayer Basic
Realtek Fast Ethernet Adapter Driver
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB960714)
SMSC IrCC Driver V5.1.2462.0 (WinXP)
SoundTap
StorageSync Backup Software
Symantec AntiVirus
Toshiba Access
TOSHIBA Console
TOSHIBA Hotkey Utility
TOSHIBA Power Management Utility
TOSHIBA Software Modem
Toshiba Software Upgrades
Toshiba Tbiosdrv Driver
Toshiba WinXP Registration
TouchPad On/Off Utility
TurboTax Deluxe Deduction Maximizer 2006
TurboTax ItsDeductible 2006
TurboTax Premier 2007
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
Viewpoint Media Player (Remove Only)
WavePad Uninstall
WexTech AnswerWorks
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinZip
WinZip 10
WinZip Command Line Support Add-On 2.0
Wireless Network PC Card Configuration Utility
Lets get a free anti-virus first

Grisoft AVG
http://free.avg.com/download-avg-anti-virus-free-edition

or

avast! 4
http://www.avast.com/eng/download-avast-home.html

Or

Avira AntiVir Personal - FREE Antivirus
http://www.free-av.com/en/download/1/downl…_antivirus.html

After the above:

To completely uninstall Symantec AntiVirus?
Problem: The solution to many problems with Symantec AntiVirus is to completely uninstall Symantec AntiVirus, then re-install. You can use these instructions to completely uninstall Symantec AntiVirus.

Solution: In order to completely uninstall Symantec AntiVirus and all related components you need to follow these instructions.
Note: This procedure will remove all Symantec products, not just Symantec AntiVirus.

1.Click on Start | Settings | Control Panel
2.In the control panel double-click on Add / Remove Programs
3.Look through the list of installed programs for any item that says either "Norton" or "Symantec" or "LiveUpdate". (for example "Symantec AntiVirus Corporate Edition" or "Norton AntiVirus 2000")
4.For each "Norton", "Symantec", or "LiveUpdate" item, select the item and click Add / Remove. Follow the instructions, and click Yes or Yes to all when prompted.
When you are done there should be no items in the list that say "Norton", "Symantec", or "LiveUpdate".
5.Click OK to close the Add / Remove Programs window.
6.Reboot your computer if it hasn't already automatically rebooted.
7.Delete the c:\Program Files\Symantec AntiVirus (or c:\Program Files\Norton) folder.
8.Delete the c:\Program Files\Symantec folder.
9.Delete the c:\Program Files\Common Files\Symantec Shared folder.
OK, here goes. I appreciate your patience.

I downloaded avast! and installed it and then attempted to follow the uninstall instructions. I did not have a “Norton”, “Symantec” or “Liveupdate” in my applications list (I thought I had attempted to remove Symantec when I left my former employer since I wasn’t entitled to use it). I then deleted the c:\\Program Files\Symantec and c:\\Program Files\Symantec AntiVirus and attempted to delete C:\\Program Files\Common Files\Symantec Shared but was left with a number of files in use that I couldn’t track down, I rebooted and manually removed the files. I was not able to remove one file named c:\\Program Files\Common\Symantec Shared\SSC\vpshell2.dll because it was in use somewhere and I couldn’t stop the process so I did the following. Renamed it to a .txt file, rebooted and then deleted the Symantec Shared folder. Hopefully this does not lead to an issue in attempting to delete Symantec. I do notice that every time I right click on “Start” to go to windows explorer I receive a very quick “Preparing to install” dialogue box that goes right away.

Upon reboot. I still receive a Symantec AntiVirus is turned off alert from Windows Security Alerts so I navigated around and manually deleted the remaining Symantec folders. I’ve installed avast! and completed a scan. It was taking quite a while so I started the scan, left to run some errands for a few hours and avast! paused waiting for input on what to do with the infected files it identified. I then selected “delete all” and finished some chores. I rebooted, ran HiJackThis and saved the Logfile and Uninstall file log and noticed that Symantec still appears in the uninstall log file. I imagine a service is still present but some of the files are missing. I didn’t mention this but I do also wish to remove PC AnyWhere as well.

From a speed perspective the laptop appears to be running OK

You didn’t mention it but I ran another HiJackThis Logfile and it is below.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:52:26 PM, on 1/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\orclobi\MyDesktop\MyDesktopService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\orclobi\MyDesktop\MyDesktopQOS.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\PROGRA~1\EzButton\CPLBTS88.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [CPLBTS88] C:\PROGRA~1\EzButton\CPLBTS88.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Digimax Viewer 2.1.lnk = ?
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139720255630
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139720215712
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Unknown owner - C:\Program Files\Symantec\pcAnywhere\awhost32.exe (file missing)
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Unknown owner - C:\Program Files\Symantec AntiVirus\DefWatch.exe (file missing)
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MyDesktopService (MyDesktopWindows) - Oracle Corporation - C:\WINDOWS\orclobi\MyDesktop\MyDesktopService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: QOS MyDesktop (QOSMyDesktop) - Oracle - C:\WINDOWS\orclobi\MyDesktop\MyDesktopQOS.exe
O23 - Service: SAVRoam (SavRoam) - Unknown owner - C:\Program Files\Symantec AntiVirus\SavRoam.exe (file missing)
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (file missing)
O23 - Service: Symantec AntiVirus - Unknown owner - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (file missing)

–
End of file - 8029 bytes

Here is the most recent Uninstall Log File

Acoustica Effects Pack
Acoustica Mixcraft
Adobe Acrobat 5.0
Adobe Flash Player 9 ActiveX
ALPS Touch Pad Driver
America Online
AnswerWorks 4.0 Runtime - English
Apple Mobile Device Support
Apple Software Update
ArcSoft PhotoImpression 4
Avance AC'97 Audio
avast! Antivirus
Bonjour
BUM
Digimax A7
Digimax Viewer 2.1
Documents To Go
Drag'n Drop CD
Easy Button
Express Rip
exPressit S.E. 2.2
Google Desktop
Google Earth
Hijackthis 1.99.1
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
HyperSnap-DX 5.62.05
InterVideo WinDVD 4
iPod for Windows 2006-01-10
iPod Updater 2004-11-15
iTunes
Java™ 6 Update 11
KODAK Gallery Upload Software
LimeWire 4.18.8
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Baseline Security Analyzer 1.2.1
Microsoft Office 2000 Disc 2
Microsoft Office 2000 Premium
MP3 CD Converter Professional 5.01
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Network Device Switch 3
NVIDIA Windows 2000/XP Display Drivers
Oracle Connector For Outlook
Oracle Connector for Outlook
Oracle JInitiator 1.3.1.18
Oracle JInitiator [removed]
Oracle Web Conferencing Console
palmOne
PcAnyWhere 11.5 HostLAN
Picasa 3
Prism
Quicken 2003 New User Edition
QuickTime
RealPlayer Basic
Realtek Fast Ethernet Adapter Driver
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB960714)
SMSC IrCC Driver V5.1.2462.0 (WinXP)
SoundTap
StorageSync Backup Software
Symantec AntiVirus
Toshiba Access
TOSHIBA Console
TOSHIBA Hotkey Utility
TOSHIBA Power Management Utility
TOSHIBA Software Modem
Toshiba Software Upgrades
Toshiba Tbiosdrv Driver
Toshiba WinXP Registration
TouchPad On/Off Utility
TurboTax Deluxe Deduction Maximizer 2006
TurboTax ItsDeductible 2006
TurboTax Premier 2007
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
Viewpoint Media Player (Remove Only)
WavePad Uninstall
WexTech AnswerWorks
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinZip
WinZip 10
WinZip Command Line Support Add-On 2.0
Wireless Network PC Card Configuration Utility
  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Thanks for the quick response. I've included the ComboFix log. The computer seems to be running OK with the exception of when I right click on the "start" button I receive a windows preparing to install dialogue box that goes away. No other quirky behavior, popups of indication of anything evil going on. I suppose you would be a better judge that I.

Thanks.
Jim



ComboFix 09-01-05.05 - Jim Doherty 2009-01-11 21:10:22.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.275 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\worksnow.exe
AV: avast! antivirus 4.8.1296 [VPS 081219-0] *On-access scanning disabled* (Outdated)
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Outdated)
.

((((((((((((((((((((((((( Files Created from 2008-12-12 to 2009-01-12 )))))))))))))))))))))))))))))))
.

2009-01-09 17:05 . 2009-01-04 18:38 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-09 17:04 . 2009-01-09 17:04 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-09 17:04 . 2009-01-04 18:38 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-09 16:54 . 2009-01-09 16:54 d——– c:\program files\Trend Micro
2009-01-06 21:33 . 2002-11-25 20:24 d——– c:\documents and settings\Administrator\WINDOWS
2009-01-06 21:33 . 2002-11-25 20:28 d——– c:\documents and settings\Administrator\Application Data\InterTrust
2009-01-06 21:33 . 2002-11-25 20:40 d——– c:\documents and settings\Administrator\Application Data\Drag'n Drop CD
2009-01-06 21:33 . 2009-01-06 21:33 d——– c:\documents and settings\Administrator
2009-01-06 21:22 . 2009-01-06 21:22 0 –a—— c:\windows\TPTray.INI
2009-01-05 20:53 . 2009-01-05 20:53 d–h—– c:\windows\PIF
2009-01-05 07:49 . 2009-01-09 18:05 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-04 01:01 . 2009-01-04 01:20 d——– c:\windows\SxsCaPendDel
2009-01-04 00:04 . 2009-01-04 00:09 d——– c:\documents and settings\All Users\Application Data\SITEguard
2009-01-04 00:02 . 2009-01-04 00:02 d——– c:\program files\Common Files\iS3
2009-01-04 00:02 . 2009-01-04 01:00 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
2009-01-03 22:00 . 2009-01-03 22:00 d——– c:\program files\Alwil Software
2009-01-03 18:25 . 2009-01-03 18:53 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2009-01-03 17:53 . 2009-01-04 00:09 d——– c:\documents and settings\Jim Doherty\Application Data\Twain
2008-12-22 22:19 . 2008-12-22 22:18 410,984 –a—— c:\windows\system32\deploytk.dll
2008-12-22 22:19 . 2008-12-22 22:18 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-12-22 21:03 . 2008-12-22 21:05 d——– c:\program files\iTunes
2008-12-22 21:03 . 2008-12-22 21:05 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-22 21:00 . 2008-12-22 21:01 d——– c:\program files\QuickTime
2008-12-22 20:19 . 2008-12-22 20:19 54,156 –ah—– c:\windows\QTFont.qfn
2008-12-22 20:19 . 2008-12-22 20:19 1,409 –a—— c:\windows\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 04:16 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-23 03:18 ——— d—–w c:\program files\Java
2008-12-23 02:04 ——— d—–w c:\program files\iPod
2008-12-03 02:46 ——— d—–w c:\program files\NCH Swift Sound
2008-12-03 02:46 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\NCH Swift Sound
2008-11-23 04:18 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\gtk-2.0
2008-11-22 23:43 ——— d—–w c:\program files\Google
2008-11-17 20:04 2,306,113 —-a-w c:\windows\system32\GPhotos.scr
2008-11-16 18:17 ——— d—–w c:\program files\Kodak
2008-11-16 18:17 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\Kodak
2008-11-16 15:59 ——— d—–w c:\program files\Apple Software Update
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-16 10:37 659,456 —-a-w c:\windows\system32\wininet.dll
2008-11-16 16:06 122,880 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-01-04 03:01 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2009-01-04 03:01 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-04 03:01 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2009-01-04 03:02 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-04 03:02 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((( snapshot@2009-01-09_21.50.43.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-26 17:21:30 1,236,208 —-a-w c:\windows\system32\aswBoot.exe
+ 2008-11-26 17:15:10 97,480 —-a-w c:\windows\system32\AvastSS.scr
+ 2008-11-26 17:15:35 26,944 —-a-w c:\windows\system32\drivers\aavmker4.sys
+ 2008-11-26 17:17:25 20,560 —-a-w c:\windows\system32\drivers\aswFsBlk.sys
+ 2008-11-26 17:18:25 93,296 —-a-w c:\windows\system32\drivers\aswmon.sys
+ 2008-11-26 17:18:18 94,032 —-a-w c:\windows\system32\drivers\aswmon2.sys
+ 2008-11-26 17:16:29 23,152 —-a-w c:\windows\system32\drivers\aswRdr.sys
+ 2008-11-26 17:17:36 111,184 —-a-w c:\windows\system32\drivers\aswSP.sys
+ 2008-11-26 17:16:38 50,864 —-a-w c:\windows\system32\drivers\aswTdi.sys
+ 2009-01-12 00:24:41 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_4ac.dat
+ 2009-01-12 00:24:29 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_7e0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\MSMSGS.EXE" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2002-03-29 122880]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2002-10-28 167936]
"CPLBTS88"="c:\progra~1\EzButton\CPLBTS88.EXE" [2002-11-08 204800]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2002-11-08 434176]
"CeEPOWER"="c:\program files\TOSHIBA\Power Management\CePMTray.exe" [2002-11-14 86016]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2002-10-17 45056]
"ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [2002-08-20 40960]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2001-11-14 147456]
"StrgSync.exe"="c:\program files\StorageSync\StrgSync.exe" [2004-07-19 3018752]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-22 136600]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"nwiz"="nwiz.exe" [2002-11-12 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-02-14 82026]
Digimax Viewer 2.1.lnk - c:\program files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe [2006-02-12 634880]
Instant Wireless Configuration Utility.lnk - c:\program files\Linksys\WPC11 Config Utility\WPC11Cfg.exe [2006-02-05 180224]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
2004-11-01 14:50 8704 c:\windows\system32\PCANotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JPEG"= JPEGCODE.DLL
"VIDC.MJPG"= JPEGCODE.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DataViz Inc Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DataViz Inc Messenger.lnk
backup=c:\windows\pss\DataViz Inc Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
–a—— 2008-11-16 11:06 29744 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2002-11-25 20:36 26112 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-01-11 111184]
R3 WBSD;Winbond Secure Digital Storage Device Driver;c:\windows\system32\drivers\wbsd.sys [2002-11-25 25728]
R3 WPC11;Instant Wireless Network PC Card V3.0 Driver;c:\windows\system32\drivers\LSWLNDS.sys [2006-02-05 54083]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-01-11 20560]
R4 DPortIO;Dritek Port I/O Driver;c:\windows\system32\drivers\DPORTIO.SYS [2001-04-12 3674]
R4 MyDesktopWindows;MyDesktopService;c:\windows\orclobi\MyDesktop\MyDesktopService.exe [2007-10-19 964096]
R4 QOSMyDesktop;QOS MyDesktop;c:\windows\orclobi\MyDesktop\MyDesktopQOS.exe [2006-04-21 450560]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-03-25 29744]
S4 mrtRate;mrtRate; [x]
S4 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" –> c:\program files\Symantec AntiVirus\SavRoam.exe [?]
Unknown4 dsload;dsload; [x]

— Other Services/Drivers In Memory —

*NewlyCreated* - PCANDIS5
.
Contents of the 'Scheduled Tasks' folder

2008-12-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/?myHome
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: *.turbotax.com

O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\Jim Doherty\Application Data\Mozilla\Firefox\Profiles\ojn9q6ds.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.oracle.com/
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-11 21:13:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2982558324-977338740-2252588409-1005\Software\Microsoft\SystemCertificates\AddressBook*NULL*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2009-01-11 21:14:34
ComboFix-quarantined-files.txt 2009-01-12 02:14:27
ComboFix2.txt 2009-01-10 16:41:17
ComboFix3.txt 2009-01-10 02:51:40

Pre-Run: 6,029,942,784 bytes free
Post-Run: 6,051,237,888 bytes free

190 — E O F — 2008-12-23 13:10:53

I receive a windows preparing to install dialogue box that goes away

I don't know what that is.


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\program files\Symantec AntiVirus\SavRoam.exe

Folder::
c:\program files\Symantec AntiVirus

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
I copied the provided text to a CFScript.txt file and ran ComboFix and have included the ComboFix log file. The only issue I notice now is that my Instant Wireless Configuration Utility shows that the laptop is not connected to the internet (shows red) yet I am. The Windows Installer dialogue box pops once for approx 3 seconds, if I right click again on the start button it launched for a fraction of a second, a third or more times right clicking on the start button and the Windows Installer dialogue box does not appear. Symantec AV seems to be uninstalled but I cannot uninstall PCAnyWhere.

Here's the ComboFix log. Did you need any of the HJT logs? Should I start avast! back up?


ComboFix 09-01-05.05 - Jim Doherty 2009-01-11 21:36:14.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.249 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\worksnow.exe
Command switches used :: c:\documents and settings\Jim Doherty\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1296 [VPS 081219-0] *On-access scanning disabled* (Outdated)
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Outdated)
* Created a new restore point

FILE ::
c:\program files\Symantec AntiVirus\SavRoam.exe
.

((((((((((((((((((((((((( Files Created from 2008-12-12 to 2009-01-12 )))))))))))))))))))))))))))))))
.

2009-01-09 17:05 . 2009-01-04 18:38 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-09 17:04 . 2009-01-09 17:04 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-09 17:04 . 2009-01-04 18:38 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-09 16:54 . 2009-01-09 16:54 d——– c:\program files\Trend Micro
2009-01-06 21:33 . 2002-11-25 20:24 d——– c:\documents and settings\Administrator\WINDOWS
2009-01-06 21:33 . 2002-11-25 20:28 d——– c:\documents and settings\Administrator\Application Data\InterTrust
2009-01-06 21:33 . 2002-11-25 20:40 d——– c:\documents and settings\Administrator\Application Data\Drag'n Drop CD
2009-01-06 21:33 . 2009-01-06 21:33 d——– c:\documents and settings\Administrator
2009-01-06 21:22 . 2009-01-06 21:22 0 –a—— c:\windows\TPTray.INI
2009-01-05 20:53 . 2009-01-05 20:53 d–h—– c:\windows\PIF
2009-01-05 07:49 . 2009-01-09 18:05 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-04 01:01 . 2009-01-04 01:20 d——– c:\windows\SxsCaPendDel
2009-01-04 00:04 . 2009-01-04 00:09 d——– c:\documents and settings\All Users\Application Data\SITEguard
2009-01-04 00:02 . 2009-01-04 00:02 d——– c:\program files\Common Files\iS3
2009-01-04 00:02 . 2009-01-04 01:00 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
2009-01-03 22:00 . 2009-01-03 22:00 d——– c:\program files\Alwil Software
2009-01-03 18:25 . 2009-01-03 18:53 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2009-01-03 17:53 . 2009-01-04 00:09 d——– c:\documents and settings\Jim Doherty\Application Data\Twain
2008-12-22 22:19 . 2008-12-22 22:18 410,984 –a—— c:\windows\system32\deploytk.dll
2008-12-22 22:19 . 2008-12-22 22:18 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-12-22 21:03 . 2008-12-22 21:05 d——– c:\program files\iTunes
2008-12-22 21:03 . 2008-12-22 21:05 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-22 21:00 . 2008-12-22 21:01 d——– c:\program files\QuickTime
2008-12-22 20:19 . 2008-12-22 20:19 54,156 –ah—– c:\windows\QTFont.qfn
2008-12-22 20:19 . 2008-12-22 20:19 1,409 –a—— c:\windows\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 04:16 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-23 03:18 ——— d—–w c:\program files\Java
2008-12-23 02:04 ——— d—–w c:\program files\iPod
2008-12-03 02:46 ——— d—–w c:\program files\NCH Swift Sound
2008-12-03 02:46 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\NCH Swift Sound
2008-11-23 04:18 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\gtk-2.0
2008-11-22 23:43 ——— d—–w c:\program files\Google
2008-11-17 20:04 2,306,113 —-a-w c:\windows\system32\GPhotos.scr
2008-11-16 18:17 ——— d—–w c:\program files\Kodak
2008-11-16 18:17 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\Kodak
2008-11-16 15:59 ——— d—–w c:\program files\Apple Software Update
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-16 10:37 659,456 —-a-w c:\windows\system32\wininet.dll
2008-11-16 16:06 122,880 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-01-04 03:01 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2009-01-04 03:01 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-04 03:01 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2009-01-04 03:02 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-04 03:02 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((( snapshot@2009-01-09_21.50.43.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-26 17:21:30 1,236,208 —-a-w c:\windows\system32\aswBoot.exe
+ 2008-11-26 17:15:10 97,480 —-a-w c:\windows\system32\AvastSS.scr
+ 2008-11-26 17:15:35 26,944 —-a-w c:\windows\system32\drivers\aavmker4.sys
+ 2008-11-26 17:17:25 20,560 —-a-w c:\windows\system32\drivers\aswFsBlk.sys
+ 2008-11-26 17:18:25 93,296 —-a-w c:\windows\system32\drivers\aswmon.sys
+ 2008-11-26 17:18:18 94,032 —-a-w c:\windows\system32\drivers\aswmon2.sys
+ 2008-11-26 17:16:29 23,152 —-a-w c:\windows\system32\drivers\aswRdr.sys
+ 2008-11-26 17:17:36 111,184 —-a-w c:\windows\system32\drivers\aswSP.sys
+ 2008-11-26 17:16:38 50,864 —-a-w c:\windows\system32\drivers\aswTdi.sys
+ 2009-01-12 00:24:41 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_4ac.dat
+ 2009-01-12 00:24:29 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_7e0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\MSMSGS.EXE" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2002-03-29 122880]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2002-10-28 167936]
"CPLBTS88"="c:\progra~1\EzButton\CPLBTS88.EXE" [2002-11-08 204800]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2002-11-08 434176]
"CeEPOWER"="c:\program files\TOSHIBA\Power Management\CePMTray.exe" [2002-11-14 86016]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2002-10-17 45056]
"ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [2002-08-20 40960]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2001-11-14 147456]
"StrgSync.exe"="c:\program files\StorageSync\StrgSync.exe" [2004-07-19 3018752]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-22 136600]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"nwiz"="nwiz.exe" [2002-11-12 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-02-14 82026]
Digimax Viewer 2.1.lnk - c:\program files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe [2006-02-12 634880]
Instant Wireless Configuration Utility.lnk - c:\program files\Linksys\WPC11 Config Utility\WPC11Cfg.exe [2006-02-05 180224]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
2004-11-01 14:50 8704 c:\windows\system32\PCANotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JPEG"= JPEGCODE.DLL
"VIDC.MJPG"= JPEGCODE.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DataViz Inc Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DataViz Inc Messenger.lnk
backup=c:\windows\pss\DataViz Inc Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
–a—— 2008-11-16 11:06 29744 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2002-11-25 20:36 26112 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-01-11 111184]
R3 WBSD;Winbond Secure Digital Storage Device Driver;c:\windows\system32\drivers\wbsd.sys [2002-11-25 25728]
R3 WPC11;Instant Wireless Network PC Card V3.0 Driver;c:\windows\system32\drivers\LSWLNDS.sys [2006-02-05 54083]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-01-11 20560]
R4 DPortIO;Dritek Port I/O Driver;c:\windows\system32\drivers\DPORTIO.SYS [2001-04-12 3674]
R4 MyDesktopWindows;MyDesktopService;c:\windows\orclobi\MyDesktop\MyDesktopService.exe [2007-10-19 964096]
R4 QOSMyDesktop;QOS MyDesktop;c:\windows\orclobi\MyDesktop\MyDesktopQOS.exe [2006-04-21 450560]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-03-25 29744]
S4 mrtRate;mrtRate; [x]
S4 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" –> c:\program files\Symantec AntiVirus\SavRoam.exe [?]
Unknown4 dsload;dsload; [x]

— Other Services/Drivers In Memory —

*NewlyCreated* - PCANDIS5
.
Contents of the 'Scheduled Tasks' folder

2008-12-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/?myHome
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: *.turbotax.com

O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\Jim Doherty\Application Data\Mozilla\Firefox\Profiles\ojn9q6ds.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.oracle.com/
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-11 21:37:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2982558324-977338740-2252588409-1005\Software\Microsoft\SystemCertificates\AddressBook*NULL*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2009-01-11 21:39:20
ComboFix-quarantined-files.txt 2009-01-12 02:39:13
ComboFix2.txt 2009-01-12 02:14:35
ComboFix3.txt 2009-01-10 16:41:17
ComboFix4.txt 2009-01-10 02:51:40

Pre-Run: 6,030,008,320 bytes free
Post-Run: 6,030,675,968 bytes free

193 — E O F — 2008-12-23 13:10:53
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\PCANotify.dll

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Completed. Attached are the ComboFix and HJT logfiles. Thanks for your quick responses.

ComboFix 09-01-05.05 - Jim Doherty 2009-01-11 22:02:50.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.219 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\worksnow.exe
Command switches used :: c:\documents and settings\Jim Doherty\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1296 [VPS 081219-0] *On-access scanning disabled* (Outdated)
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Outdated)
* Created a new restore point

FILE ::
c:\windows\system32\PCANotify.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\PCANotify.dll

.
((((((((((((((((((((((((( Files Created from 2008-12-12 to 2009-01-12 )))))))))))))))))))))))))))))))
.

2009-01-09 17:05 . 2009-01-04 18:38 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-09 17:04 . 2009-01-09 17:04 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-09 17:04 . 2009-01-04 18:38 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-09 16:54 . 2009-01-09 16:54 d——– c:\program files\Trend Micro
2009-01-06 21:33 . 2002-11-25 20:24 d——– c:\documents and settings\Administrator\WINDOWS
2009-01-06 21:33 . 2002-11-25 20:28 d——– c:\documents and settings\Administrator\Application Data\InterTrust
2009-01-06 21:33 . 2002-11-25 20:40 d——– c:\documents and settings\Administrator\Application Data\Drag'n Drop CD
2009-01-06 21:33 . 2009-01-06 21:33 d——– c:\documents and settings\Administrator
2009-01-06 21:22 . 2009-01-06 21:22 0 –a—— c:\windows\TPTray.INI
2009-01-05 20:53 . 2009-01-05 20:53 d–h—– c:\windows\PIF
2009-01-05 07:49 . 2009-01-09 18:05 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-04 01:01 . 2009-01-04 01:20 d——– c:\windows\SxsCaPendDel
2009-01-04 00:04 . 2009-01-04 00:09 d——– c:\documents and settings\All Users\Application Data\SITEguard
2009-01-04 00:02 . 2009-01-04 00:02 d——– c:\program files\Common Files\iS3
2009-01-04 00:02 . 2009-01-04 01:00 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
2009-01-03 22:00 . 2009-01-03 22:00 d——– c:\program files\Alwil Software
2009-01-03 18:25 . 2009-01-03 18:53 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2009-01-03 17:53 . 2009-01-04 00:09 d——– c:\documents and settings\Jim Doherty\Application Data\Twain
2008-12-22 22:19 . 2008-12-22 22:18 410,984 –a—— c:\windows\system32\deploytk.dll
2008-12-22 22:19 . 2008-12-22 22:18 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-12-22 21:03 . 2008-12-22 21:05 d——– c:\program files\iTunes
2008-12-22 21:03 . 2008-12-22 21:05 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-22 21:00 . 2008-12-22 21:01 d——– c:\program files\QuickTime
2008-12-22 20:19 . 2008-12-22 20:19 54,156 –ah—– c:\windows\QTFont.qfn
2008-12-22 20:19 . 2008-12-22 20:19 1,409 –a—— c:\windows\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 04:16 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-23 03:18 ——— d—–w c:\program files\Java
2008-12-23 02:04 ——— d—–w c:\program files\iPod
2008-12-03 02:46 ——— d—–w c:\program files\NCH Swift Sound
2008-12-03 02:46 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\NCH Swift Sound
2008-11-23 04:18 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\gtk-2.0
2008-11-22 23:43 ——— d—–w c:\program files\Google
2008-11-16 18:17 ——— d—–w c:\program files\Kodak
2008-11-16 18:17 ——— d—–w c:\documents and settings\Jim Doherty\Application Data\Kodak
2008-11-16 15:59 ——— d—–w c:\program files\Apple Software Update
2008-11-16 16:06 122,880 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-01-04 03:01 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2009-01-04 03:01 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-04 03:01 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2009-01-04 03:02 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-04 03:02 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((( snapshot@2009-01-09_21.50.43.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-26 17:21:30 1,236,208 —-a-w c:\windows\system32\aswBoot.exe
+ 2008-11-26 17:15:10 97,480 —-a-w c:\windows\system32\AvastSS.scr
+ 2008-11-26 17:15:35 26,944 —-a-w c:\windows\system32\drivers\aavmker4.sys
+ 2008-11-26 17:17:25 20,560 —-a-w c:\windows\system32\drivers\aswFsBlk.sys
+ 2008-11-26 17:18:25 93,296 —-a-w c:\windows\system32\drivers\aswmon.sys
+ 2008-11-26 17:18:18 94,032 —-a-w c:\windows\system32\drivers\aswmon2.sys
+ 2008-11-26 17:16:29 23,152 —-a-w c:\windows\system32\drivers\aswRdr.sys
+ 2008-11-26 17:17:36 111,184 —-a-w c:\windows\system32\drivers\aswSP.sys
+ 2008-11-26 17:16:38 50,864 —-a-w c:\windows\system32\drivers\aswTdi.sys
+ 2009-01-12 03:06:18 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_6b8.dat
+ 2009-01-12 03:06:06 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_768.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\MSMSGS.EXE" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2002-03-29 122880]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2002-10-28 167936]
"CPLBTS88"="c:\progra~1\EzButton\CPLBTS88.EXE" [2002-11-08 204800]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2002-11-08 434176]
"CeEPOWER"="c:\program files\TOSHIBA\Power Management\CePMTray.exe" [2002-11-14 86016]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2002-10-17 45056]
"ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [2002-08-20 40960]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2001-11-14 147456]
"StrgSync.exe"="c:\program files\StorageSync\StrgSync.exe" [2004-07-19 3018752]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-22 136600]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"nwiz"="nwiz.exe" [2002-11-12 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-02-14 82026]
Digimax Viewer 2.1.lnk - c:\program files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe [2006-02-12 634880]
Instant Wireless Configuration Utility.lnk - c:\program files\Linksys\WPC11 Config Utility\WPC11Cfg.exe [2006-02-05 180224]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JPEG"= JPEGCODE.DLL
"VIDC.MJPG"= JPEGCODE.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DataViz Inc Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DataViz Inc Messenger.lnk
backup=c:\windows\pss\DataViz Inc Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
–a—— 2008-11-16 11:06 29744 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2002-11-25 20:36 26112 c:\program files\Real\RealPlayer\realplay.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-01-11 111184]
R3 WBSD;Winbond Secure Digital Storage Device Driver;c:\windows\system32\drivers\wbsd.sys [2002-11-25 25728]
R3 WPC11;Instant Wireless Network PC Card V3.0 Driver;c:\windows\system32\drivers\LSWLNDS.sys [2006-02-05 54083]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-01-11 20560]
R4 DPortIO;Dritek Port I/O Driver;c:\windows\system32\drivers\DPORTIO.SYS [2001-04-12 3674]
R4 MyDesktopWindows;MyDesktopService;c:\windows\orclobi\MyDesktop\MyDesktopService.exe [2007-10-19 964096]
R4 QOSMyDesktop;QOS MyDesktop;c:\windows\orclobi\MyDesktop\MyDesktopQOS.exe [2006-04-21 450560]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-03-25 29744]
S4 mrtRate;mrtRate; [x]
S4 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" –> c:\program files\Symantec AntiVirus\SavRoam.exe [?]
Unknown4 dsload;dsload; [x]
.
Contents of the 'Scheduled Tasks' folder

2008-12-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/?myHome
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: *.turbotax.com

O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\Jim Doherty\Application Data\Mozilla\Firefox\Profiles\ojn9q6ds.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.oracle.com/
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-11 22:06:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-2982558324-977338740-2252588409-1005\Software\Microsoft\SystemCertificates\AddressBook*NULL*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Apoint2K\ApntEx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-01-11 22:10:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-12 03:10:21
ComboFix2.txt 2009-01-12 02:39:22
ComboFix3.txt 2009-01-12 02:14:35
ComboFix4.txt 2009-01-10 16:41:17
ComboFix5.txt 2009-01-12 03:02:01

Pre-Run: 6,011,031,552 bytes free
Post-Run: 6,014,394,368 bytes free

194 — E O F — 2008-12-23 13:10:53


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:14:52 PM, on 1/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\orclobi\MyDesktop\MyDesktopService.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\PROGRA~1\EzButton\CPLBTS88.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\WINDOWS\orclobi\MyDesktop\MyDesktopQOS.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\StorageSync\StrgSync.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [CPLBTS88] C:\PROGRA~1\EzButton\CPLBTS88.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Digimax Viewer 2.1.lnk = ?
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139720255630
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139720215712
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Unknown owner - C:\Program Files\Symantec\pcAnywhere\awhost32.exe (file missing)
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Unknown owner - C:\Program Files\Symantec AntiVirus\DefWatch.exe (file missing)
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MyDesktopService (MyDesktopWindows) - Oracle Corporation - C:\WINDOWS\orclobi\MyDesktop\MyDesktopService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: QOS MyDesktop (QOSMyDesktop) - Oracle - C:\WINDOWS\orclobi\MyDesktop\MyDesktopQOS.exe
O23 - Service: SAVRoam (SavRoam) - Unknown owner - C:\Program Files\Symantec AntiVirus\SavRoam.exe (file missing)
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (file missing)
O23 - Service: Symantec AntiVirus - Unknown owner - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (file missing)

–
End of file - 8087 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI