Page 1 of 3 123 LastLast
Results 1 to 10 of 24

Thread: pls help...something is really wrong...

  1. #1
    Junior Member
    Join Date
    Oct 2007
    Posts
    12

    Unhappy pls help...something is really wrong...

    hi
    i am new to this forum and i really hope you could help me.

    as i was searching the net, i came across this forum and saw a post about a problem that is similar to mine: problem with a recycler and system volume information.. and a malware detected by kaspersky as virus.win32.autorun.k (netmanage.dll etc)

    i kept on scanning using kaspersky antivirus and it says that all threats are already treated or sometimes no threats were detected etc...but i still have the hidden folders: recycler and system volume information in my drive C. they were not there before...i also now have a ntdetect.com in my drive C. My computer is not slowing down or anything but i am just so worried.. my mom bought herself a new laptop and i am terrified at the thought of infecting her new laptop with the same bug through my emails and attachments..

    i followed an advise in a previous post regarding Combofix.exe and here is the log report... i also had another text file about files being quarantined... and a qoobox folder in my drive C after the scan

    Combofix.txt:
    ComboFix 07-10-04.5 - Anne Therese C. Lim 2007-10-04 10:15:21.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.153 [GMT 8:00]
    Running from: C:\Documents and Settings\Anne Therese C. Lim\Desktop\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\TEMP.\_istmpi.dir

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


    -------\LEGACY_DNSCON
    -------\LEGACY_NETMANAGER
    -------\dnscon
    -------\NetManager


    ((((((((((((((((((((((((( Files Created from 2007-09-04 to 2007-10-04 )))))))))))))))))))))))))))))))
    .

    2007-10-04 09:42 51,200 --a------ C:\WINDOWS\NirCmd.exe
    2007-10-04 07:11 <DIR> d-------- C:\temporary
    2007-10-03 21:26 <DIR> d--h----- C:\WINDOWS\PIF
    2007-10-02 01:24 <DIR> d-------- C:\Program Files\XoftSpySE
    2007-10-01 12:25 <DIR> d-------- C:\Heart_Sounds
    2007-09-30 10:30 <DIR> d-------- C:\Program Files\Rapidshare Unlimited
    2007-09-30 10:12 <DIR> d-------- C:\Program Files\Heart_Sounds
    2007-09-30 00:20 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
    2007-09-29 22:00 <DIR> d-------- C:\Documents and Settings\Anne Therese C. Lim\.housecall6.6
    2007-09-29 19:13 <DIR> d-------- C:\Program Files\Uniblue
    2007-09-29 19:13 <DIR> d-------- C:\Documents and Settings\Anne Therese C. Lim\Application Data\Uniblue
    2007-09-08 05:59 <DIR> d-------- C:\Program Files\Alarm Clock

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-10-04 10:22 --------- d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2007-10-04 10:21 587296 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
    2007-10-04 10:21 10201888 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
    2007-10-04 10:20 56108 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
    2007-10-04 10:20 137660 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
    2007-10-02 04:49 --------- d-------- C:\Program Files\XTerm Medical Dictionary
    2007-09-22 13:47 --------- d-------- C:\Program Files\TextAloud
    2007-09-21 19:54 --------- d-------- C:\Program Files\Common Files\Skyscape
    2007-09-06 15:42 --------- d-------- C:\Program Files\ReadPlease 2003
    2007-09-04 02:12 82061 --a------ C:\WINDOWS\system32\drivers\klick.dat
    2007-09-04 02:12 81549 --a------ C:\WINDOWS\system32\drivers\klin.dat
    2007-08-18 21:47 --------- d-------- C:\Documents and Settings\Anne Therese C. Lim\Application Data\Help
    2007-08-07 01:05 --------- d-------- C:\Documents and Settings\Anne Therese C. Lim\Application Data\InterVideo
    2007-08-06 21:29 --------- d-------- C:\Documents and Settings\Anne Therese C. Lim\Application Data\dvdcss
    2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
    2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
    2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
    2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
    2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
    2007-07-30 19:19 271224 --a------ C:\WINDOWS\system32\mucltui.dll
    2007-07-30 19:19 207736 --a------ C:\WINDOWS\system32\muweb.dll
    2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
    2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
    2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
    2007-07-23 21:26 73216 --a------ C:\WINDOWS\ST6UNST.EXE
    2007-07-06 19:42 466944 --a------ C:\WINDOWS\The Lords Prayer.scr
    2007-07-06 19:42 28672 --a------ C:\WINDOWS\system32\ssconfig.exe
    2007-07-06 19:42 180224 --a------ C:\WINDOWS\UninstallWSST.exe
    2007-07-06 19:31 466944 --a------ C:\WINDOWS\The 23rd Psalm.scr
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-01 13:10]
    "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-11-02 09:03]
    "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-02 08:59]
    "Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-30 16:46]
    "TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2004-11-30 13:06]
    "CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2005-01-22 13:48]
    "NDSTray.exe"="NDSTray.exe" []
    "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-01-14 17:05]
    "PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-08 06:03]
    "ZoomingHook"="ZoomingHook.exe" [2004-07-15 08:07 C:\WINDOWS\system32\ZoomingHook.exe]
    "SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-09-16 07:03]
    "HWSetup"="C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-12-24 10:07]
    "TOSHIBA Accessibility"="C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe" [2004-12-08 13:24]
    "Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2004-11-13 09:57]
    "SVPWUTIL"="C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2005-02-26 07:59]
    "TPSMain"="TPSMain.exe" [2004-12-29 08:02 C:\WINDOWS\system32\TPSMain.exe]
    "TCtryIOHook"="TCtrlIOHook.exe" [2005-02-17 06:43 C:\WINDOWS\system32\TCtrlIOHook.exe]
    "TFncKy"="TFncKy.exe" []
    "LtMoh"="C:\\Program Files\\ltmoh\\Ltmoh.exe" [2004-12-06 22:53]
    "AGRSMMSG"="AGRSMMSG.exe" [2004-12-06 22:53 C:\WINDOWS\agrsmmsg.exe]
    "snpstd3"="C:\WINDOWS\vsnpstd3.exe" [2005-01-14 11:00]
    "SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-05-17 12:02]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
    "YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-29 06:10]
    "AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2007-01-29 23:02]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 16:32]
    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 00:24]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00]
    "YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-29 06:10]
    "Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-27 15:22]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-21 03:23]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Post-itr Software Notes.lnk - C:\Program Files\3M\PSNotes\psn.exe [2003-10-10 14:53:20]
    RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-03-13 11:38:33]

    C:\Documents and Settings\Anne Therese C. Lim\Start Menu\Programs\Startup\
    Skyscape smARTupdate.lnk - C:\Program Files\Common Files\Skyscape\smARTupdate.exe [2005-03-03 04:33:15]
    WordWeb.lnk - C:\Program Files\WordWeb\wweb32.exe [2007-06-11 09:05:36]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Post-itr Software Notes.lnk - C:\Program Files\3M\PSNotes\psn.exe [2003-10-10 14:53:20]
    RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-03-13 11:38:33]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

    R1 SerTVOutCtlr;TOSHIBA Controls Driver -EPIOMngr;C:\WINDOWS\system32\drivers\EPIOMngr.sys
    R1 SrvcEKIOMngr;SrvcEKIOMngr;C:\WINDOWS\system32\Drivers\EKIoMngr.sys
    R1 SrvcSSIOMngr;SrvcSSIOMngr;C:\WINDOWS\system32\Drivers\SSIoMngr.sys
    R1 TPwSav;Common Driver;C:\WINDOWS\system32\Drivers\TPwSav.sys
    S1 StickyMesger;StickyMesger;\??\C:\Program Files\TOSHIBA\Accessibility\StickyMesger.sys


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0aa3a755-1c02-11dc-ab40-000fb086abc4}]
    Auto\command- E:\RECYCLER\S-1-5-21-1078073611-1993962763-839522115-1003\mmc32.EXE
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-1-5-21-1078073611-1993962763-839522115-1003\mmc32.EXE
    Browser\command- E:\RECYCLER\S-1-5-21-1078073611-1993962763-839522115-1003\mmc32.EXE

    .
    Contents of the 'Scheduled Tasks' folder
    "2007-08-15 06:49:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2007-10-01 12:32:16 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
    - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
    "2007-10-01 12:32:11 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
    - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
    "2007-10-01 18:31:05 C:\WINDOWS\Tasks\Uniblue SpyEraser Nag.job"
    - C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
    "2007-10-01 18:21:16 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
    - C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
    "2007-10-04 02:21:26 C:\WINDOWS\Tasks\XoftSpySE 2.job"
    "2007-10-01 19:40:55 C:\WINDOWS\Tasks\XoftSpySE.job"
    .
    **************************************************************************

    catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-10-04 10:22:38
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2007-10-04 10:24:51 - machine was rebooted
    C:\ComboFix-quarantined-files.txt ... 2007-10-04 10:24
    .
    --- E O F ---

    ComboFix-quarantined-files.txt
    Code:
    2007-10-04 10:18      2888    --a------    C:\Qoobox\Quarantine\Registry_backups\services_NetManager.reg.dat
    2007-10-04 10:18      2948    --a------    C:\Qoobox\Quarantine\Registry_backups\services_dnscon.reg.dat
    2007-10-04 10:18      806    --a------    C:\Qoobox\Quarantine\Registry_backups\LEGACY_DNSCON.reg.dat
    2007-10-04 10:18      848    --a------    C:\Qoobox\Quarantine\Registry_backups\LEGACY_NETMANAGER.reg.dat
    
    
    Folder PATH listing for volume S3A2272D001
    Volume serial number is 7E61-43ED
    C:\QOOBOX\QUARANTINE
    \---Registry_backups
            LEGACY_DNSCON.reg.dat
            LEGACY_NETMANAGER.reg.dat
            services_dnscon.reg.dat
            services_NetManager.reg.dat
    the qoobox folder contains a quarrantine folder --> registry backup --> LEGACY_DNSCON.reg.dat
    LEGACY_NETMANAGER.reg.dat
    services_dnscon.reg.dat
    services_NetManager.reg.dat

    pls help... i really dont know what to do....

    is my computer safe? can i start emailing my mom? was combofix successful in treating my laptop. would my laptop be virus free if i deleted the qoobox folder?
    was kaspersky right in saying that the threats were treated?

    thanks in advance!

  2. #2
    Emeritus
    Join Date
    Nov 2005
    Location
    Texas
    Posts
    1,144

    Default

    Download hijackthis here.

    Scan and post the log from it please.
    MS-MVP Windows Security 2006,2007,2008 & 2009
    ASAP member since 2004

  3. #3
    Junior Member
    Join Date
    Oct 2007
    Posts
    12

    Smile here is the hijackthis log

    Logfile of HijackThis v1.99.1
    Scan saved at 7:40:53 PM, on 10/8/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ACS.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\system32\DVDRAMSV.exe
    C:\Program Files\Spyware Doctor\svcntaux.exe
    C:\Program Files\Spyware Doctor\swdsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
    C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    C:\WINDOWS\system32\ZoomingHook.exe
    C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
    C:\Program Files\Toshiba\Tvs\TvsTray.exe
    C:\WINDOWS\system32\TPSMain.exe
    C:\WINDOWS\system32\TCtrlIOHook.exe
    C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
    C:\Program Files\ltmoh\Ltmoh.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\vsnpstd3.exe
    C:\Program Files\Spyware Doctor\SDTrayApp.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\TPSBattM.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\3M\PSNotes\psn.exe
    C:\WINDOWS\system32\RAMASST.exe
    C:\Program Files\Common Files\Skyscape\smARTupdate.exe
    C:\Program Files\WordWeb\wweb32.exe
    C:\PROGRA~1\3M\PSNotes\PSNGive.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/yco.../www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.shoptoshiba.ca/welcome
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\PROGRA~1\TEXTAL~1\TAForIE.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
    O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    O4 - HKLM\..\Run: [ZoomingHook] ZoomingHook.exe
    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
    O4 - HKLM\..\Run: [TOSHIBA Accessibility] C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe
    O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
    O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
    O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
    O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
    O4 - HKLM\..\Run: [LtMoh] C:\\Program Files\\ltmoh\\Ltmoh.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
    O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Startup: Skyscape smARTupdate.lnk = C:\Program Files\Common Files\Skyscape\smARTupdate.exe
    O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
    O4 - Global Startup: Post-itŪ Software Notes.lnk = C:\Program Files\3M\PSNotes\psn.exe
    O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1181088772875
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: LWWLicenseService - WoltersKluwerLWW - C:\Program Files\Common Files\WoltersKluwerLWW Shared\Service\LWWLicenseService.exe
    O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

  4. #4
    Emeritus
    Join Date
    Nov 2005
    Location
    Texas
    Posts
    1,144

    Default

    Things look OK

    Reboot in safe mode, instructions here.
    Some of these files my have hidden atributes.
    Click Here Should you need instructions for Showing hidden files and folders in Windows.
    Once in safe mode, Click start / then my computer / local disk then follow the process tree.
    Or using Windows Explorer, locate the first file right click then select delete.

    Delete the following folder(s) listed in bold.

    C:\Program Files\Uniblue\SpyEraser

    ---------------------------------

    Download and run - ATF Cleaner instructions here.

    ---------------------------------------

    Please go HERE to run Panda's ActiveScan

    * You need to use IE to run this scan
    * Once you are on the Panda site click the Scan your PC button
    * A new window will open...click the Check Now button
    * Enter your Country
    * Enter your State/Province
    * Enter your e-mail address and click send
    * Select either Home User or Company
    * Click the big Scan Now button
    * If it wants to install an ActiveX component allow it
    * It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    * When download is complete, click on My Computer to start the scan
    * When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
    MS-MVP Windows Security 2006,2007,2008 & 2009
    ASAP member since 2004

  5. #5
    Junior Member
    Join Date
    Oct 2007
    Posts
    12

    Question impt question

    hi

    already restarted in safemode and deleted the uniblue>spyeraser folder. I ran the ATF cleaner and restarted again

    however, it restarted again in safemode. so i went to start-run and typed msconfig again and unchecked safeboot

    then when i restarted, a window came out asking me if i wanted to restart using normal setup (system configuration utility)

    do i run the panda scanner also in safe mode? so i have to restart again using safemode?

    super thanks..

  6. #6
    Emeritus
    Join Date
    Nov 2005
    Location
    Texas
    Posts
    1,144

    Default

    do i run the panda scanner also in safe mode?
    No, I don't think that would be necessary.
    MS-MVP Windows Security 2006,2007,2008 & 2009
    ASAP member since 2004

  7. #7
    Junior Member
    Join Date
    Oct 2007
    Posts
    12

    Default what about the system config utilities?

    hi there's this window asking me if i wanted to restart using normal startup something like that..

    when i clicked ok, it asked me to restart

    do i scan first with the panda scanner or restart first?

    thanks again...

  8. #8
    Emeritus
    Join Date
    Nov 2005
    Location
    Texas
    Posts
    1,144

    Default

    Restart you PC before scanning.

    Don't boot in safe mode.
    MS-MVP Windows Security 2006,2007,2008 & 2009
    ASAP member since 2004

  9. #9
    Junior Member
    Join Date
    Oct 2007
    Posts
    12

    Smile currently scanning...

    hi

    i am currently scanning

    by the way, you said in the ATF cleaner instructions:
    Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
    Note: I would not delete the prefetch unless you have cleaned out some spyware from your system.
    You will notice a slow startup after cleaning out you prefetch files.


    so is i didnt delete the prefetch... is that ok?

    ill post the results of the scan once it's done..

    thanks

  10. #10
    Emeritus
    Join Date
    Nov 2005
    Location
    Texas
    Posts
    1,144

    Default

    so is i didnt delete the prefetch... is that ok?
    Yes
    MS-MVP Windows Security 2006,2007,2008 & 2009
    ASAP member since 2004

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •