PDA

View Full Version : host errors, HJT errors



sem825
2010-02-28, 20:48
Due to 4 days of inactivity (I was sick) my original post was closed. My original post is here:

http://forums.spybot.info/showthread.php?t=55511

I know the instructions said NOT to post logs that were requested, but please let me know if you'd like me to post the ComboFix log that Blade81 requested.

I just reran the DDS log, as HJT was not working on my computer. Here are the DDS logs as of today:

DDS log:

DDS (Ver_09-09-29.01) - NTFSx86
Run by Owner at 14:44:03.14 on Sun 02/28/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1395 [GMT -5:00]

SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

============== Running Processes ===============

C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\atieclxx.exe
C:\windows\system32\taskhost.exe
C:\Program Files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe
C:\windows\Explorer.EXE
C:\windows\system32\Dwm.exe
C:\windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Users\Owner\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\TOSHIBA\TECO\TEco.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\Users\Owner\Desktop\dds.com
C:\windows\system32\conhost.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton security suite\engine\3.8.0.41\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton security suite\engine\3.8.0.41\IPSBHO.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton security suite\engine\3.8.0.41\coIEPlg.dll
uRun: [MyTOSHIBA] "c:\program files\toshiba\my toshiba\MyToshiba.exe" /AUTO
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [googletalk] c:\users\owner\appdata\roaming\google\google talk\googletalk.exe /autostart
uRun: [Security Antivirus] "c:\cd65301\SAcd65.exe" /s /d
uRun: [Google Update] "c:\users\owner\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [<NO NAME>]
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
mRun: [NortonOnlineBackupReminder] "c:\program files\toshiba\toshiba online backup\activation\TobuActivation.exe" UNATTENDED
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton security suite\engine\3.8.0.41\CoIEPlg.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\xmmpllk7.default\
FF - prefs.js: browser.search.selectedEngine - search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll
FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\owner\appdata\local\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0308000.029\SymEFA.sys [2010-2-10 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0308000.029\BHDrvx86.sys [2010-2-10 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0308000.029\cchpx86.sys [2010-2-10 482432]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100224.002\IDSvix86.sys [2010-2-25 343088]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-14 176128]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2009-8-10 185712]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
R2 N360;Norton Security Suite;c:\program files\norton security suite\engine\3.8.0.41\ccSvcHst.exe [2010-2-10 117640]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-2-11 1153368]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-8-11 185712]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-19 12920]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-2-10 102448]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2009-12-14 7680]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-12-14 187392]
R3 RTL8187Se;Realtek RTL8187SE Wireless LAN PCIE Network Adapter;c:\windows\system32\drivers\RTL8187Se.sys [2009-12-14 372736]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\n360\0308000.029\symndisv.sys [2010-2-10 48688]
R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2009-12-14 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-8-3 111960]
R3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-8-6 685424]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]

=============== Created Last 30 ================

2010-02-24 09:00 641,536 a------- c:\windows\system32\CPFilters.dll
2010-02-24 09:00 465,408 a------- c:\windows\system32\psisdecd.dll
2010-02-24 09:00 417,792 a------- c:\windows\system32\msdri.dll
2010-02-24 09:00 204,288 a------- c:\windows\system32\MSNP.ax
2010-02-24 09:00 2,048 a------- c:\windows\system32\tzres.dll
2010-02-15 00:07 <DIR> --d----- c:\program files\TrendMicro
2010-02-11 17:16 <DIR> --d----- c:\programdata\Lavasoft
2010-02-11 15:28 <DIR> --d----- c:\programdata\Spybot - Search & Destroy
2010-02-11 15:28 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2010-02-11 15:28 <DIR> --d----- c:\progra~2\Spybot - Search & Destroy
2010-02-11 12:03 <DIR> --d--r-- c:\program files\Norton Support
2010-02-10 15:36 <DIR> --d----- c:\programdata\Sun
2010-02-10 15:35 411,368 a------- c:\windows\system32\deploytk.dll
2010-02-10 14:01 <DIR> --d----- c:\programdata\RegCure
2010-02-10 14:01 <DIR> --d----- c:\progra~2\RegCure
2010-02-10 07:46 107,368 a----r-- c:\windows\system32\GEARAspi.dll
2010-02-10 07:46 26,600 a----r-- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-02-10 07:46 25,648 a----r-- c:\windows\system32\drivers\SymIMV.sys
2010-02-10 07:46 124,976 a------- c:\windows\system32\drivers\SYMEVENT.SYS
2010-02-10 07:46 7,456 a------- c:\windows\system32\drivers\SYMEVENT.CAT
2010-02-10 07:46 806 a------- c:\windows\system32\drivers\SYMEVENT.INF
2010-02-10 07:45 <DIR> --d----- c:\program files\Symantec
2010-02-10 07:45 <DIR> --d----- c:\program files\common files\Symantec Shared
2010-02-10 07:44 <DIR> --d----- c:\windows\system32\drivers\N360
2010-02-10 07:44 <DIR> --d----- c:\program files\Norton Security Suite
2010-02-10 07:42 <DIR> --d----- c:\programdata\PCSettings
2010-02-10 07:42 <DIR> --d----- c:\progra~2\PCSettings
2010-02-10 07:29 118 a------- c:\windows\system32\MRT.INI
2010-02-09 12:45 <DIR> --d----- c:\programdata\3fa8f
2010-02-09 12:45 <DIR> --d----- c:\progra~2\3fa8f
2010-02-09 12:45 <DIR> --dsh--- c:\users\owner\appdata\roaming\Security Antivirus
2010-02-09 12:45 <DIR> --dsh--- c:\programdata\SABRV
2010-02-09 12:45 <DIR> --dsh--- c:\progra~2\SABRV
2010-02-09 12:45 <DIR> --dsh--- C:\cd65301
2010-02-09 01:32 <DIR> --d----- c:\programdata\McAfee

==================== Find3M ====================

2010-02-24 09:16 181,632 -------- c:\windows\system32\MpSigStub.exe
2010-01-18 18:29 365,568 a------- c:\windows\system32\secproc_isv.dll
2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp.dll
2010-01-18 18:29 369,152 a------- c:\windows\system32\secproc.dll
2010-01-18 18:28 324,608 a------- c:\windows\system32\RMActivate_isv.exe
2010-01-18 18:28 277,504 a------- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 18:28 320,512 a------- c:\windows\system32\RMActivate.exe
2010-01-18 18:28 280,064 a------- c:\windows\system32\RMActivate_ssp.exe
2010-01-07 22:18 221,184 a------- c:\windows\system32\drivers\mrxsmb10.sys
2010-01-07 22:17 123,392 a------- c:\windows\system32\drivers\mrxsmb.sys
2010-01-01 18:51 0 a---h--- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2009-12-19 04:02 977,920 a------- c:\windows\system32\wininet.dll
2009-12-19 04:02 12,288 a------- c:\windows\system32\tsbyuv.dll
2009-12-19 04:02 1,328,640 a------- c:\windows\system32\quartz.dll
2009-12-19 04:02 22,016 a------- c:\windows\system32\msyuv.dll
2009-12-19 04:02 31,744 a------- c:\windows\system32\msvidc32.dll
2009-12-19 04:02 13,312 a------- c:\windows\system32\msrle32.dll
2009-12-19 04:02 84,480 a------- c:\windows\system32\mciavi32.dll
2009-12-19 04:02 50,176 a------- c:\windows\system32\iyuv_32.dll
2009-12-19 04:02 91,648 a------- c:\windows\system32\avifil32.dll
2009-12-08 06:40 3,955,288 a------- c:\windows\system32\ntkrnlpa.exe
2009-12-08 06:40 3,899,464 a------- c:\windows\system32\ntoskrnl.exe
2009-12-08 06:32 292,864 a------- c:\windows\system32\apphelp.dll
2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfi.dat
2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfh.dat
2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfd.dat
2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfc.dat
2009-07-13 23:41 174 a--sh--- c:\program files\desktop.ini
2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfi.dat
2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfh.dat
2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfd.dat
2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 16:26 9,633,792 a--shr-- c:\windows\fonts\StaticCache.dat
2009-07-13 20:14 396,800 a--sh--- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 14:44:39.23 ===============


Attach log:




UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-09-29.01)

Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 12/30/2009 2:38:36 PM
System Uptime: 2/28/2010 1:50:58 PM (1 hours ago)

Motherboard: TOSHIBA | | Portable PC
Processor: AMD Athlon(tm) II Dual-Core M300 | Socket S1G3 | 2000/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 289 GiB total, 257.91 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 12/30/2009 2:38:56 PM - TOSHIBA Default System Restore Point
RP3: 12/30/2009 2:39:25 PM - Installed Toshiba Quality Application
RP4: 12/30/2009 3:02:21 PM - Windows Update
RP5: 12/31/2009 6:20:36 PM - Installed iTunes
RP7: 1/3/2010 7:44:01 PM - Configured Microsoft Office Home and Student 2007
RP9: 1/3/2010 7:48:43 PM - Configured Microsoft Office Home and Student 2007
RP10: 1/13/2010 11:34:02 PM - Windows Update
RP11: 1/14/2010 9:30:30 AM - Windows Modules Installer
RP12: 1/14/2010 9:36:30 AM - Windows Update
RP13: 1/16/2010 10:28:00 AM - Windows Update
RP14: 1/22/2010 9:09:27 AM - Windows Update
RP15: 1/27/2010 10:08:21 AM - Windows Update
RP16: 1/30/2010 4:51:05 PM - Windows Update
RP17: 2/1/2010 7:36:48 PM - Windows Update
RP18: 2/5/2010 9:25:54 AM - Windows Update
RP19: 2/8/2010 10:37:00 PM - Windows Update
RP20: 2/10/2010 7:27:22 AM - Windows Update
RP22: 2/10/2010 8:00:10 AM - Windows Defender Checkpoint
RP23: 2/10/2010 3:33:57 PM - Installed Java(TM) 6 Update 18
RP24: 2/11/2010 9:20:08 PM - Windows Update
RP25: 2/15/2010 12:05:52 AM - Installed HiJackThis
RP26: 2/15/2010 2:10:38 PM - Windows Update
RP27: 2/18/2010 9:31:53 PM - Windows Update
RP28: 2/18/2010 9:40:51 PM - Windows Update
RP29: 2/19/2010 9:06:39 AM - Windows Update
RP30: 2/22/2010 7:37:07 PM - Windows Update
RP31: 2/25/2010 11:23:01 PM - Windows Update
RP32: 2/25/2010 11:25:12 PM - Windows Update

==== Installed Programs ======================

Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.1
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Install Manager
Bonjour
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Compatibility Pack for the 2007 Office system
ERUNT 1.1j
Google Chrome
Google Talk (remove only)
Google Toolbar for Internet Explorer
HiJackThis
iTunes
Java Auto Updater
Java(TM) 6 Update 18
Junk Mail filter update
Label@Once 1.0
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (3.6)
MSVCRT
MyToshiba
NetZero Launcher
Norton Internet Security
Norton Security Suite
PlayReady PC Runtime x86
Quickbooks Financial Center
QuickTime
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek USB 2.0 Card Reader
Realtek WLAN Driver
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Skype Launcher
Spybot - Search & Destroy
Synaptics Pointing Device Driver
Toshiba Application and Driver Installer
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Disc Creator
TOSHIBA DVD PLAYER
TOSHIBA eco Utility
TOSHIBA Extended Tiles for Windows Mobility Center
TOSHIBA Hardware Setup
TOSHIBA HDD/SSD Alert
Toshiba Online Backup
TOSHIBA PC Health Monitor
Toshiba Quality Application
TOSHIBA Recovery Media Creator
TOSHIBA Service Station
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
ToshibaRegistration
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WildTangent Games
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer

==== Event Viewer Messages From Past Week ========

2/28/2010 2:36:54 PM, Error: Schannel [36888] - The following fatal alert was generated: 48. The internal error state is 552.
2/28/2010 2:36:54 PM, Error: Schannel [36882] - The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The SSL connection request has failed. The attached data contains the server certificate.
2/28/2010 2:20:06 PM, Error: atikmdag [43029] - Display is not active
2/26/2010 10:35:03 PM, Error: atikmdag [52236] - CPLIB :: General - Invalid Parameter
2/25/2010 11:27:42 PM, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {F81CD990-910B-4BBF-9CB3-6A77F3D697B3}. The error: "2" Happened while starting this command: C:\Program Files\Windows Live\Messenger\msnmsgr.exe -Embedding
2/24/2010 10:50:52 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Owner-PC\Owner SID (S-1-5-21-3957342637-2223780103-148138915-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.

==== End Of File ========================

I appreciate any help/advice you can offer. Thank you!!

Blade81
2010-03-04, 11:37
Hi,

Please post ComboFix log if you have it handy :)

Post also a fresh dds log.

sem825
2010-03-06, 01:44
Will do. I will work on this and post on Sunday. Thank you so much!

Blade81
2010-03-06, 12:32
Ok. Shall wait for your reply :)

sem825
2010-03-08, 16:29
Ack! I didn't realize ComboFix would take well over 12 hours to work through my computer...I hope it's finished by the time I return home tonight. I apologize for the delay!

Blade81
2010-03-08, 17:16
Hi,

If ComboFix hasn't finished see if there's PEV process running in task manager and kill the process if found. If even that doesn't make ComboFix to finish reboot and see if the log gets generated.

sem825
2010-03-09, 01:13
Hello,

ComboFix was still running when I got home, 24 hours after I had started it. My Windows desktop disappeared, so my only option was to shut down and restart. When I did that, no log appeared. I will try running ComboFix again and see what happens this time.

How long should I wait this time? And what is the next step if no log appears?

Thanks, Blade81!

sem825
2010-03-09, 01:28
In addition, in case it helps, here are DDS logs I ran 5 minutes ago:

DDS log:

DDS (Ver_09-09-29.01) - NTFSx86
Run by Owner at 19:25:28.79 on Mon 03/08/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1814 [GMT -5:00]

SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

============== Running Processes ===============

C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\atieclxx.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\windows\system32\sppsvc.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\TECO\TEco.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Owner\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\Users\Owner\Desktop\dds.com
C:\windows\system32\conhost.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [MyTOSHIBA] "c:\program files\toshiba\my toshiba\MyToshiba.exe" /AUTO
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [googletalk] c:\users\owner\appdata\roaming\google\google talk\googletalk.exe /autostart
uRun: [Security Antivirus] "c:\cd65301\SAcd65.exe" /s /d
uRun: [Google Update] "c:\users\owner\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [<NO NAME>]
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
mRun: [NortonOnlineBackupReminder] "c:\program files\toshiba\toshiba online backup\activation\TobuActivation.exe" UNATTENDED
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-14 176128]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2009-8-10 185712]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-2-11 1153368]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-8-11 185712]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-19 12920]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2009-12-14 7680]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-12-14 187392]
R3 RTL8187Se;Realtek RTL8187SE Wireless LAN PCIE Network Adapter;c:\windows\system32\drivers\RTL8187Se.sys [2009-12-14 372736]
R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2009-12-14 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-8-3 111960]
R3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-8-6 685424]
S2 PEVSystemStart;PEVSystemStart;c:\combofix\PEV.cfxxe [2010-3-7 261632]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]

=============== Created Last 30 ================

2010-03-08 19:10 <DIR> --dsh--- C:\$RECYCLE.BIN
2010-03-07 21:32 261,632 a------- c:\windows\PEV.exe
2010-03-07 21:32 161,792 a------- c:\windows\SWREG.exe
2010-03-07 21:32 98,816 a------- c:\windows\sed.exe
2010-03-07 21:32 77,312 a------- c:\windows\MBR.exe
2010-03-07 21:32 <DIR> --ds---- C:\ComboFix
2010-02-24 09:00 641,536 a------- c:\windows\system32\CPFilters.dll
2010-02-24 09:00 465,408 a------- c:\windows\system32\psisdecd.dll
2010-02-24 09:00 417,792 a------- c:\windows\system32\msdri.dll
2010-02-24 09:00 204,288 a------- c:\windows\system32\MSNP.ax
2010-02-24 09:00 2,048 a------- c:\windows\system32\tzres.dll
2010-02-15 00:07 <DIR> --d----- c:\program files\TrendMicro
2010-02-11 17:16 <DIR> --d----- c:\programdata\Lavasoft
2010-02-11 15:28 <DIR> --d----- c:\programdata\Spybot - Search & Destroy
2010-02-11 15:28 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2010-02-11 15:28 <DIR> --d----- c:\progra~2\Spybot - Search & Destroy
2010-02-11 12:03 <DIR> --d--r-- c:\program files\Norton Support
2010-02-10 15:36 <DIR> --d----- c:\programdata\Sun
2010-02-10 15:35 411,368 a------- c:\windows\system32\deploytk.dll
2010-02-10 14:01 <DIR> --d----- c:\programdata\RegCure
2010-02-10 14:01 <DIR> --d----- c:\progra~2\RegCure
2010-02-10 07:46 107,368 a----r-- c:\windows\system32\GEARAspi.dll
2010-02-10 07:46 26,600 a----r-- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-02-10 07:45 <DIR> --d----- c:\program files\Symantec
2010-02-10 07:44 <DIR> --d----- c:\windows\system32\drivers\N360
2010-02-10 07:42 <DIR> --d----- c:\programdata\PCSettings
2010-02-10 07:42 <DIR> --d----- c:\progra~2\PCSettings
2010-02-10 07:29 118 a------- c:\windows\system32\MRT.INI
2010-02-09 12:45 <DIR> --d----- c:\programdata\3fa8f
2010-02-09 12:45 <DIR> --d----- c:\progra~2\3fa8f
2010-02-09 12:45 <DIR> --dsh--- c:\programdata\SABRV
2010-02-09 12:45 <DIR> --dsh--- c:\progra~2\SABRV
2010-02-09 12:45 <DIR> --dsh--- C:\cd65301
2010-02-09 01:32 <DIR> --d----- c:\programdata\McAfee

==================== Find3M ====================

2010-02-24 09:16 181,632 -------- c:\windows\system32\MpSigStub.exe
2010-01-18 18:29 365,568 a------- c:\windows\system32\secproc_isv.dll
2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp.dll
2010-01-18 18:29 369,152 a------- c:\windows\system32\secproc.dll
2010-01-18 18:28 324,608 a------- c:\windows\system32\RMActivate_isv.exe
2010-01-18 18:28 277,504 a------- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 18:28 320,512 a------- c:\windows\system32\RMActivate.exe
2010-01-18 18:28 280,064 a------- c:\windows\system32\RMActivate_ssp.exe
2010-01-07 22:18 221,184 a------- c:\windows\system32\drivers\mrxsmb10.sys
2010-01-07 22:17 123,392 a------- c:\windows\system32\drivers\mrxsmb.sys
2009-12-19 04:02 977,920 a------- c:\windows\system32\wininet.dll
2009-12-19 04:02 12,288 a------- c:\windows\system32\tsbyuv.dll
2009-12-19 04:02 1,328,640 a------- c:\windows\system32\quartz.dll
2009-12-19 04:02 22,016 a------- c:\windows\system32\msyuv.dll
2009-12-19 04:02 31,744 a------- c:\windows\system32\msvidc32.dll
2009-12-19 04:02 13,312 a------- c:\windows\system32\msrle32.dll
2009-12-19 04:02 84,480 a------- c:\windows\system32\mciavi32.dll
2009-12-19 04:02 50,176 a------- c:\windows\system32\iyuv_32.dll
2009-12-19 04:02 91,648 a------- c:\windows\system32\avifil32.dll
2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfi.dat
2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfh.dat
2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfd.dat
2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfc.dat
2009-07-13 23:41 174 a--sh--- c:\program files\desktop.ini
2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfi.dat
2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfh.dat
2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfd.dat
2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 16:26 9,633,792 a--shr-- c:\windows\fonts\StaticCache.dat
2009-07-13 20:14 396,800 a--sh--- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 19:26:17.08 ===============

Attach log:

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-09-29.01)

Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 12/30/2009 2:38:36 PM
System Uptime: 3/8/2010 7:18:10 PM (0 hours ago)

Motherboard: TOSHIBA | | Portable PC
Processor: AMD Athlon(tm) II Dual-Core M300 | Socket S1G3 | 2000/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 289 GiB total, 258.371 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP7: 1/3/2010 7:44:01 PM - Configured Microsoft Office Home and Student 2007
RP9: 1/3/2010 7:48:43 PM - Configured Microsoft Office Home and Student 2007
RP10: 1/13/2010 11:34:02 PM - Windows Update
RP11: 1/14/2010 9:30:30 AM - Windows Modules Installer
RP12: 1/14/2010 9:36:30 AM - Windows Update
RP13: 1/16/2010 10:28:00 AM - Windows Update
RP14: 1/22/2010 9:09:27 AM - Windows Update
RP15: 1/27/2010 10:08:21 AM - Windows Update
RP16: 1/30/2010 4:51:05 PM - Windows Update
RP17: 2/1/2010 7:36:48 PM - Windows Update
RP18: 2/5/2010 9:25:54 AM - Windows Update
RP19: 2/8/2010 10:37:00 PM - Windows Update
RP20: 2/10/2010 7:27:22 AM - Windows Update
RP22: 2/10/2010 8:00:10 AM - Windows Defender Checkpoint
RP23: 2/10/2010 3:33:57 PM - Installed Java(TM) 6 Update 18
RP24: 2/11/2010 9:20:08 PM - Windows Update
RP25: 2/15/2010 12:05:52 AM - Installed HiJackThis
RP26: 2/15/2010 2:10:38 PM - Windows Update
RP27: 2/18/2010 9:31:53 PM - Windows Update
RP28: 2/18/2010 9:40:51 PM - Windows Update
RP29: 2/19/2010 9:06:39 AM - Windows Update
RP30: 2/22/2010 7:37:07 PM - Windows Update
RP31: 2/25/2010 11:23:01 PM - Windows Update
RP32: 2/25/2010 11:25:12 PM - Windows Update
RP33: 3/1/2010 8:30:09 PM - Windows Update
RP34: 3/4/2010 10:23:16 PM - Windows Update
RP35: 3/8/2010 7:13:50 PM - Windows Update

==== Installed Programs ======================

Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.1
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Install Manager
Bonjour
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Compatibility Pack for the 2007 Office system
ERUNT 1.1j
Google Chrome
Google Talk (remove only)
Google Toolbar for Internet Explorer
HiJackThis
iTunes
Java Auto Updater
Java(TM) 6 Update 18
Junk Mail filter update
Label@Once 1.0
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (3.6)
MSVCRT
MyToshiba
NetZero Launcher
PlayReady PC Runtime x86
Quickbooks Financial Center
QuickTime
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek USB 2.0 Card Reader
Realtek WLAN Driver
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Skype Launcher
Spybot - Search & Destroy
Synaptics Pointing Device Driver
Toshiba Application and Driver Installer
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Disc Creator
TOSHIBA DVD PLAYER
TOSHIBA eco Utility
TOSHIBA Extended Tiles for Windows Mobility Center
TOSHIBA Hardware Setup
TOSHIBA HDD/SSD Alert
Toshiba Online Backup
TOSHIBA PC Health Monitor
Toshiba Quality Application
TOSHIBA Recovery Media Creator
TOSHIBA Service Station
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
ToshibaRegistration
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WildTangent Games
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer

==== Event Viewer Messages From Past Week ========

3/8/2010 7:25:21 PM, Error: Schannel [36888] - The following fatal alert was generated: 48. The internal error state is 552.
3/8/2010 7:25:21 PM, Error: Schannel [36882] - The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The SSL connection request has failed. The attached data contains the server certificate.
3/8/2010 7:18:29 PM, Error: atikmdag [52236] - CPLIB :: General - Invalid Parameter
3/8/2010 7:18:29 PM, Error: atikmdag [43029] - Display is not active
3/7/2010 9:32:38 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
3/7/2010 9:21:25 PM, Error: Service Control Manager [7031] - The Norton Security Suite service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
3/6/2010 6:52:16 PM, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {F81CD990-910B-4BBF-9CB3-6A77F3D697B3}. The error: "2" Happened while starting this command: C:\Program Files\Windows Live\Messenger\msnmsgr.exe -Embedding

==== End Of File ===========================

sem825
2010-03-09, 15:40
Hello again,

I ran ComboFix again this morning and this time it worked!

Here is the log:

ComboFix 10-03-07.02 - Owner 03/09/2010 9:30.3.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1968 [GMT -5:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
.

((((((((((((((((((((((((( Files Created from 2010-02-09 to 2010-03-09 )))))))))))))))))))))))))))))))
.

2010-03-09 14:34 . 2010-03-09 14:34 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-03-09 14:34 . 2010-03-09 14:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-09 14:34 . 2010-03-09 14:34 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2010-02-24 14:00 . 2009-12-13 09:30 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-02-24 14:00 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-02-24 14:00 . 2009-12-13 09:29 417792 ----a-w- c:\windows\system32\msdri.dll
2010-02-24 14:00 . 2010-02-02 07:45 2048 ----a-w- c:\windows\system32\tzres.dll
2010-02-19 02:35 . 2010-02-19 02:35 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-02-15 05:07 . 2010-02-15 05:07 388096 ----a-r- c:\users\Owner\AppData\Roaming\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-02-15 05:07 . 2010-02-15 05:07 -------- d-----w- c:\program files\TrendMicro
2010-02-15 05:00 . 2010-02-15 05:00 -------- d-----w- c:\program files\ERUNT
2010-02-11 22:16 . 2010-02-13 05:35 -------- d-----w- c:\programdata\Lavasoft
2010-02-11 20:28 . 2010-02-15 04:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-11 20:28 . 2010-02-11 22:17 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-02-11 19:52 . 2010-02-11 19:52 103050 ----a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{2D3A6BBC-41F4-1F50-18CC-9A77DAEA1AB8}-uninst.exe
2010-02-11 17:03 . 2010-02-11 17:03 -------- d-----r- c:\program files\Norton Support
2010-02-11 15:52 . 2010-02-11 15:52 -------- d-----w- c:\users\Owner\AppData\Local\Deployment
2010-02-11 15:52 . 2010-02-11 15:52 -------- d-----w- c:\users\Owner\AppData\Local\Apps
2010-02-10 20:36 . 2010-02-10 20:36 -------- d-----w- c:\program files\Common Files\Java
2010-02-10 20:35 . 2009-12-17 22:14 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-10 19:01 . 2010-02-11 19:52 -------- d-----w- c:\programdata\RegCure
2010-02-10 12:54 . 2010-02-10 19:51 -------- d-----w- c:\users\Owner\AppData\Local\Diagnostics
2010-02-10 12:46 . 2010-02-10 12:45 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-02-10 12:46 . 2010-02-10 12:45 107368 ----a-r- c:\windows\system32\GEARAspi.dll
2010-02-10 12:45 . 2010-03-08 02:23 -------- d-----w- c:\program files\Symantec
2010-02-10 12:44 . 2010-02-10 19:55 -------- d-----w- c:\windows\system32\drivers\N360
2010-02-10 12:42 . 2010-02-10 12:42 -------- d-----w- c:\programdata\PCSettings
2010-02-10 12:34 . 2010-02-10 12:34 79 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
2010-02-10 12:34 . 2010-02-10 12:34 72 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
2010-02-10 12:34 . 2010-02-10 12:34 71 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
2010-02-10 12:34 . 2010-02-10 12:34 69 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\delfile.drv
2010-02-10 12:34 . 2010-02-10 12:34 59 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\kernel32.dll
2010-02-10 12:34 . 2010-02-10 12:34 5 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\snl2w.dll
2010-02-10 12:34 . 2010-02-10 12:34 47 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\std.dll
2010-02-10 12:34 . 2010-02-10 12:34 28 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\delfile.dll
2010-02-10 12:34 . 2010-02-10 12:34 24 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\dudl.exe
2010-02-10 12:34 . 2010-02-10 12:34 19 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\pal.sys
2010-02-10 12:34 . 2010-02-10 12:34 13 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\PE.exe
2010-02-09 17:55 . 2010-02-10 12:34 12 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\eb.sys
2010-02-09 17:48 . 2010-02-09 17:51 38434288 ----a-w- c:\programdata\Toshiba\TSS\Plugins\SwUpdates\Packages\4d92cef8-7ed7-402d-aa91-6eda708f6bb8\171515_14.32.13.TC00143300K.exe
2010-02-09 17:46 . 2010-02-10 12:34 23 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
2010-02-09 17:46 . 2010-02-10 12:34 2 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\CLSV.exe
2010-02-09 17:46 . 2010-02-09 17:46 41 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
2010-02-09 17:46 . 2010-02-10 12:34 61 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
2010-02-09 17:46 . 2010-02-10 12:34 3 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\hymt.sys
2010-02-09 17:46 . 2010-02-09 17:46 35 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\fix.dll
2010-02-09 17:46 . 2010-02-09 17:46 3 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\sld.drv
2010-02-09 17:46 . 2010-02-09 17:46 43 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\hymt.exe
2010-02-09 17:46 . 2010-02-09 17:46 24 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\cb.exe
2010-02-09 17:45 . 2010-02-09 17:45 51 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.sys
2010-02-09 17:45 . 2010-02-09 17:45 11 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\energy.sys
2010-02-09 17:45 . 2010-02-09 17:46 34 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll
2010-02-09 17:45 . 2010-02-10 12:34 6 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv
2010-02-09 17:45 . 2010-02-15 04:15 -------- d-----w- c:\programdata\3fa8f
2010-02-09 17:45 . 2010-02-09 17:45 -------- d-sh--w- c:\programdata\SABRV
2010-02-09 17:45 . 2010-02-10 12:49 -------- d-----w- C:\cd65301
2010-02-09 06:32 . 2010-02-09 06:32 -------- d-----w- c:\programdata\McAfee

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-24 14:16 . 2009-12-30 20:03 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-20 18:34 . 2009-09-02 05:46 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-19 02:40 . 2009-12-14 23:17 -------- d-----w- c:\programdata\Microsoft Help
2010-02-19 02:39 . 2009-12-14 23:08 -------- d-----w- c:\program files\Microsoft Works
2010-02-10 20:35 . 2009-09-02 05:29 -------- d-----w- c:\program files\Java
2010-02-10 12:44 . 2009-12-14 23:49 -------- d-----w- c:\programdata\Norton
2010-02-10 12:42 . 2009-12-14 23:49 -------- d-----w- c:\programdata\NortonInstaller
2010-01-24 18:26 . 2010-01-02 03:35 1670624 ----a-w- c:\programdata\WildTangent\TOSHIBA Game Console\Downloads\en-us\Installers\SetupGamesClient.exe
2010-01-23 03:07 . 2009-09-02 05:47 -------- d-----w- c:\programdata\Partner
2010-01-18 23:29 . 2010-02-10 03:54 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 23:29 . 2010-02-10 03:54 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-18 23:29 . 2010-02-10 03:54 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-18 23:29 . 2010-02-10 03:54 369152 ----a-w- c:\windows\system32\secproc.dll
2010-01-18 23:28 . 2010-02-10 03:54 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-18 23:28 . 2010-02-10 03:54 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 23:28 . 2010-02-10 03:54 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-18 23:28 . 2010-02-10 03:54 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-08 03:18 . 2010-02-10 03:54 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-01-08 03:17 . 2010-02-10 03:54 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-01-03 07:42 . 2010-01-03 07:42 79367 ----a-w- c:\users\Owner\AppData\Roaming\Google\Google Talk\uninstall.exe
2009-12-30 20:01 . 2009-12-30 20:01 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbBA5B.tmp.exe
2009-12-30 19:41 . 2009-12-30 19:41 79136 ----a-w- c:\users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-30 19:39 . 2009-12-30 19:39 13 --sh--r- c:\windows\system32\drivers\fbd.sys
2009-12-19 09:02 . 2010-01-22 03:55 977920 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 09:02 . 2010-02-10 03:54 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-19 09:02 . 2010-02-10 03:54 1328640 ----a-w- c:\windows\system32\quartz.dll
2009-12-19 09:02 . 2010-02-10 03:54 22016 ----a-w- c:\windows\system32\msyuv.dll
2009-12-19 09:02 . 2010-02-10 03:54 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-19 09:02 . 2010-02-10 03:54 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-19 09:02 . 2010-02-10 03:54 84480 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-19 09:02 . 2010-02-10 03:54 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-19 09:02 . 2010-02-10 03:54 91648 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MyTOSHIBA"="c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe" [2009-08-06 264048]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-02 39408]
"googletalk"="c:\users\Owner\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Google Update"="c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-02-11 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-30 98304]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-29 7625248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-21 1545512]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-08-21 476512]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-07-28 460088]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2009-08-05 738616]
"ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-08-17 1294136]
"TosWaitSrv"="c:\program files\TOSHIBA\TPHM\TosWaitSrv.exe" [2009-08-07 611672]
"Teco"="c:\program files\TOSHIBA\TECO\Teco.exe" [2009-08-12 1324384]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 611672]
"NortonOnlineBackupReminder"="c:\program files\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" [2009-07-16 529256]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)

R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-30 176128]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [2009-08-11 185712]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-08-12 185712]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [2009-06-20 12920]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2009-07-07 7680]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-31 187392]
S3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-04 111960]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-07 685424]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}]
2009-08-06 16:15 264048 ----a-w- c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe
.
Contents of the 'Scheduled Tasks' folder

2010-03-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3957342637-2223780103-148138915-1000Core.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-11 15:52]

2010-03-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3957342637-2223780103-148138915-1000UA.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-11 15:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\xmmpllk7.default\
FF - prefs.js: browser.startup.homepage - www.google.com

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-03-09 09:35:52
ComboFix-quarantined-files.txt 2010-03-09 14:35
ComboFix2.txt 2010-03-09 14:25

Pre-Run: 277,067,923,456 bytes free
Post-Run: 277,016,489,984 bytes free

- - End Of File - - C5465729298489B4BB5817C001802368

Blade81
2010-03-09, 15:42
Hi,

ComboFix run shouldn't take hours this time. If it gets stuck again try to run in safe mode.

Blade81
2010-03-09, 15:56
Seems that I posted without seeing your response first :)


Open notepad and copy/paste the text in the quotebox below into it:



http://forums.spybot.info/showthread.php?t=55859
Collect::
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\delfile.drv
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\kernel32.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\snl2w.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\std.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\delfile.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\dudl.exe
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\pal.sys
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\PE.exe
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\eb.sys
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\CLSV.exe
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\hymt.sys
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\fix.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\sld.drv
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\hymt.exe
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\cb.exe
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.sys
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\energy.sys
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv
Folder::
c:\programdata\3fa8f
c:\programdata\SABRV
C:\cd65301



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Uninstall old Adobe Reader versions and get the latest one (9.3 + update 9.3.1) here (http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows) or get Foxit Reader here (http://www.foxitsoftware.com/pdf/reader_2/down_reader.htm). Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here (http://pdfreaders.org/).


Check here (http://www.adobe.com/software/flash/about/) to see if your Flash is up-to-date (do it separately with each of your browsers). If not, uninstall vulnerable versions by following instructions here (http://kb2.adobe.com/cps/141/tn_14157.html). Fresh version can be obtained here (http://get.adobe.com/flashplayer/).



Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) as instructed in the screenshot here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif).


Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.

sem825
2010-03-09, 17:56
Hi,

Sorry if you missed it, but I did run it again, and it worked. I posted the ComboFix log above (along with a new DDS log). Please let me know if you need any other information from me.

Thanks!

sem825
2010-03-09, 17:57
No problem :)

Will do!

Thanks for all of your help!

sem825
2010-03-10, 05:40
Hi Blade81,

I am posting 4 logs from scans I ran tonight: ComboFix, Kaspersky Online Scanner, and 2 dds logs.

COMBOFIX:

ComboFix 10-03-09.04 - Owner 03/09/2010 20:55:45.4.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1993 [GMT -5:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\cd65301
c:\cd65301\BackUp\McAfee Security Scan Plus.lnk
c:\cd65301\mozcrt19.dll
c:\cd65301\SAV.ico
c:\cd65301\SAVSys\vd952342.bd
c:\cd65301\sqlite3.dll
c:\programdata\3fa8f
c:\programdata\3fa8f\SAV.ico
c:\programdata\SABRV
c:\programdata\SABRV\SAKZV.cfg
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\cb.exe
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\CLSV.exe
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\delfile.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\delfile.drv
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\dudl.exe
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\eb.sys
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\energy.sys
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\fix.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\hymt.exe
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\hymt.sys
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\kernel32.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\pal.sys
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\PE.exe
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.sys
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\sld.drv
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\snl2w.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\std.dll
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys

.
((((((((((((((((((((((((( Files Created from 2010-02-10 to 2010-03-10 )))))))))))))))))))))))))))))))
.

2010-03-10 01:59 . 2010-03-10 02:00 -------- d-----w- c:\users\Owner\AppData\Local\temp
2010-03-10 01:59 . 2010-03-10 01:59 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-03-10 01:59 . 2010-03-10 01:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-10 01:59 . 2010-03-10 01:59 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2010-03-10 01:54 . 2010-03-10 01:54 -------- d-----w- C:\32788R22FWJFW
2010-02-24 14:00 . 2009-12-13 09:30 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-02-24 14:00 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-02-24 14:00 . 2009-12-13 09:29 417792 ----a-w- c:\windows\system32\msdri.dll
2010-02-24 14:00 . 2010-02-02 07:45 2048 ----a-w- c:\windows\system32\tzres.dll
2010-02-19 02:35 . 2010-02-19 02:35 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-02-15 05:07 . 2010-02-15 05:07 388096 ----a-r- c:\users\Owner\AppData\Roaming\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-02-15 05:07 . 2010-02-15 05:07 -------- d-----w- c:\program files\TrendMicro
2010-02-15 05:00 . 2010-02-15 05:00 -------- d-----w- c:\program files\ERUNT
2010-02-11 22:16 . 2010-02-13 05:35 -------- d-----w- c:\programdata\Lavasoft
2010-02-11 20:28 . 2010-02-15 04:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-11 20:28 . 2010-02-11 22:17 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-02-11 19:52 . 2010-02-11 19:52 103050 ----a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{2D3A6BBC-41F4-1F50-18CC-9A77DAEA1AB8}-uninst.exe
2010-02-11 17:03 . 2010-02-11 17:03 -------- d-----r- c:\program files\Norton Support
2010-02-11 15:52 . 2010-02-11 15:52 -------- d-----w- c:\users\Owner\AppData\Local\Deployment
2010-02-11 15:52 . 2010-02-11 15:52 -------- d-----w- c:\users\Owner\AppData\Local\Apps
2010-02-10 20:36 . 2010-02-10 20:36 -------- d-----w- c:\program files\Common Files\Java
2010-02-10 20:35 . 2009-12-17 22:14 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-10 19:01 . 2010-02-11 19:52 -------- d-----w- c:\programdata\RegCure
2010-02-10 12:54 . 2010-02-10 19:51 -------- d-----w- c:\users\Owner\AppData\Local\Diagnostics
2010-02-10 12:46 . 2010-02-10 12:45 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-02-10 12:46 . 2010-02-10 12:45 107368 ----a-r- c:\windows\system32\GEARAspi.dll
2010-02-10 12:45 . 2010-03-08 02:23 -------- d-----w- c:\program files\Symantec
2010-02-10 12:44 . 2010-02-10 19:55 -------- d-----w- c:\windows\system32\drivers\N360
2010-02-10 12:42 . 2010-02-10 12:42 -------- d-----w- c:\programdata\PCSettings
2010-02-09 17:48 . 2010-02-09 17:51 38434288 ----a-w- c:\programdata\Toshiba\TSS\Plugins\SwUpdates\Packages\4d92cef8-7ed7-402d-aa91-6eda708f6bb8\171515_14.32.13.TC00143300K.exe
2010-02-09 06:32 . 2010-02-09 06:32 -------- d-----w- c:\programdata\McAfee

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-24 14:16 . 2009-12-30 20:03 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-20 18:34 . 2009-09-02 05:46 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-19 02:40 . 2009-12-14 23:17 -------- d-----w- c:\programdata\Microsoft Help
2010-02-19 02:39 . 2009-12-14 23:08 -------- d-----w- c:\program files\Microsoft Works
2010-02-10 20:35 . 2009-09-02 05:29 -------- d-----w- c:\program files\Java
2010-02-10 12:44 . 2009-12-14 23:49 -------- d-----w- c:\programdata\Norton
2010-02-10 12:42 . 2009-12-14 23:49 -------- d-----w- c:\programdata\NortonInstaller
2010-01-24 18:26 . 2010-01-02 03:35 1670624 ----a-w- c:\programdata\WildTangent\TOSHIBA Game Console\Downloads\en-us\Installers\SetupGamesClient.exe
2010-01-23 03:07 . 2009-09-02 05:47 -------- d-----w- c:\programdata\Partner
2010-01-18 23:29 . 2010-02-10 03:54 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 23:29 . 2010-02-10 03:54 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-18 23:29 . 2010-02-10 03:54 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-18 23:29 . 2010-02-10 03:54 369152 ----a-w- c:\windows\system32\secproc.dll
2010-01-18 23:28 . 2010-02-10 03:54 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-18 23:28 . 2010-02-10 03:54 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 23:28 . 2010-02-10 03:54 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-18 23:28 . 2010-02-10 03:54 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-08 03:18 . 2010-02-10 03:54 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-01-08 03:17 . 2010-02-10 03:54 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-01-03 07:42 . 2010-01-03 07:42 79367 ----a-w- c:\users\Owner\AppData\Roaming\Google\Google Talk\uninstall.exe
2009-12-30 20:01 . 2009-12-30 20:01 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbBA5B.tmp.exe
2009-12-30 19:41 . 2009-12-30 19:41 79136 ----a-w- c:\users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-30 19:39 . 2009-12-30 19:39 13 --sh--r- c:\windows\system32\drivers\fbd.sys
2009-12-19 09:02 . 2010-01-22 03:55 977920 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 09:02 . 2010-02-10 03:54 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-19 09:02 . 2010-02-10 03:54 1328640 ----a-w- c:\windows\system32\quartz.dll
2009-12-19 09:02 . 2010-02-10 03:54 22016 ----a-w- c:\windows\system32\msyuv.dll
2009-12-19 09:02 . 2010-02-10 03:54 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-19 09:02 . 2010-02-10 03:54 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-19 09:02 . 2010-02-10 03:54 84480 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-19 09:02 . 2010-02-10 03:54 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-19 09:02 . 2010-02-10 03:54 91648 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((( SnapShot@2010-03-09_14.23.58 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 04:55 . 2010-03-10 01:49 50800 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-12-30 22:36 . 2010-03-09 00:20 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-30 22:36 . 2010-03-10 01:49 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-12-30 22:36 . 2010-03-09 00:20 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-12-30 22:36 . 2010-03-10 01:49 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:41 . 2010-03-09 00:20 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:41 . 2010-03-10 01:49 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-12-30 19:40 . 2010-03-09 14:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-30 19:40 . 2010-03-10 01:53 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-30 19:40 . 2010-03-10 01:53 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-30 19:40 . 2010-03-09 14:14 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-30 19:40 . 2010-03-09 14:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-30 19:40 . 2010-03-10 01:53 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-30 19:40 . 2010-03-10 01:49 7562 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3957342637-2223780103-148138915-1000_UserData.bin
- 2010-03-08 02:25 . 2010-03-09 00:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-03-10 01:47 . 2010-03-10 01:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-03-08 02:25 . 2010-03-09 00:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-03-10 01:47 . 2010-03-10 01:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MyTOSHIBA"="c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe" [2009-08-06 264048]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-02 39408]
"googletalk"="c:\users\Owner\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Google Update"="c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-02-11 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-30 98304]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-29 7625248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-21 1545512]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-08-21 476512]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-07-28 460088]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2009-08-05 738616]
"ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-08-17 1294136]
"TosWaitSrv"="c:\program files\TOSHIBA\TPHM\TosWaitSrv.exe" [2009-08-07 611672]
"Teco"="c:\program files\TOSHIBA\TECO\Teco.exe" [2009-08-12 1324384]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 611672]
"NortonOnlineBackupReminder"="c:\program files\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" [2009-07-16 529256]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)

R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-30 176128]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [2009-08-11 185712]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-08-12 185712]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [2009-06-20 12920]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2009-07-07 7680]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-31 187392]
S3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-04 111960]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-07 685424]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}]
2009-08-06 16:15 264048 ----a-w- c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe
.
Contents of the 'Scheduled Tasks' folder

2010-03-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3957342637-2223780103-148138915-1000Core.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-11 15:52]

2010-03-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3957342637-2223780103-148138915-1000UA.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-11 15:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\xmmpllk7.default\
FF - prefs.js: browser.startup.homepage - www.google.com

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-03-09 21:01:22
ComboFix-quarantined-files.txt 2010-03-10 02:01
ComboFix2.txt 2010-03-09 14:35
ComboFix3.txt 2010-03-09 14:25

Pre-Run: 277,043,724,288 bytes free
Post-Run: 277,000,564,736 bytes free

- - End Of File - - 6F34DF47C285B9FB7F912A41C1B98050

KASPERSKY ONLINE SCANNER:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, March 9, 2010
Operating system: Microsoft Home Edition (build 7600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, March 09, 2010 23:07:57
Records in database: 3751592
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Objects scanned: 85262
Threats found: 0
Infected objects found: 0
Suspicious objects found: 0
Scan duration: 01:15:24

No threats found. Scanned area is clean.

Selected area has been scanned.

DDS LOG:


DDS (Ver_09-09-29.01) - NTFSx86
Run by Owner at 23:34:50.18 on Tue 03/09/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1282 [GMT -5:00]

SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

============== Running Processes ===============

C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\atieclxx.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\TECO\TEco.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Owner\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\windows\system32\conhost.exe
C:\Users\Owner\AppData\Local\temp\jkos-Owner\binaries\ScanningProcess.exe
C:\Users\Owner\AppData\Local\temp\jkos-Owner\binaries\ScanningProcess.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\windows\system32\taskhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\Users\Owner\Desktop\dds.com
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [MyTOSHIBA] "c:\program files\toshiba\my toshiba\MyToshiba.exe" /AUTO
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [googletalk] c:\users\owner\appdata\roaming\google\google talk\googletalk.exe /autostart
uRun: [Google Update] "c:\users\owner\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
mRun: [NortonOnlineBackupReminder] "c:\program files\toshiba\toshiba online backup\activation\TobuActivation.exe" UNATTENDED
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\xmmpllk7.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\owner\appdata\local\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-14 176128]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2009-8-10 185712]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-2-11 1153368]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-8-11 185712]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-19 12920]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2009-12-14 7680]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-12-14 187392]
R3 RTL8187Se;Realtek RTL8187SE Wireless LAN PCIE Network Adapter;c:\windows\system32\drivers\RTL8187Se.sys [2009-12-14 372736]
R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2009-12-14 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-8-3 111960]
R3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-8-6 685424]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 getPlusHelper;getPlus(R) Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2009-7-13 20992]

=============== Created Last 30 ================

2010-03-09 21:25 <DIR> --d----- c:\programdata\NOS
2010-03-09 21:09 <DIR> --d----- c:\program files\Windows Installer Clean Up
2010-03-09 21:09 <DIR> --d----- c:\program files\MSECACHE
2010-03-09 21:01 <DIR> --dsh--- C:\$RECYCLE.BIN
2010-03-07 21:32 261,632 a------- c:\windows\PEV.exe
2010-03-07 21:32 161,792 a------- c:\windows\SWREG.exe
2010-03-07 21:32 98,816 a------- c:\windows\sed.exe
2010-03-07 21:32 77,312 a------- c:\windows\MBR.exe
2010-02-24 09:00 641,536 a------- c:\windows\system32\CPFilters.dll
2010-02-24 09:00 465,408 a------- c:\windows\system32\psisdecd.dll
2010-02-24 09:00 417,792 a------- c:\windows\system32\msdri.dll
2010-02-24 09:00 204,288 a------- c:\windows\system32\MSNP.ax
2010-02-24 09:00 2,048 a------- c:\windows\system32\tzres.dll
2010-02-15 00:07 <DIR> --d----- c:\program files\TrendMicro
2010-02-11 17:16 <DIR> --d----- c:\programdata\Lavasoft
2010-02-11 15:28 <DIR> --d----- c:\programdata\Spybot - Search & Destroy
2010-02-11 15:28 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2010-02-11 15:28 <DIR> --d----- c:\progra~2\Spybot - Search & Destroy
2010-02-11 12:03 <DIR> --d--r-- c:\program files\Norton Support
2010-02-10 15:36 <DIR> --d----- c:\programdata\Sun
2010-02-10 15:35 411,368 a------- c:\windows\system32\deploytk.dll
2010-02-10 14:01 <DIR> --d----- c:\programdata\RegCure
2010-02-10 14:01 <DIR> --d----- c:\progra~2\RegCure
2010-02-10 07:46 107,368 a----r-- c:\windows\system32\GEARAspi.dll
2010-02-10 07:46 26,600 a----r-- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-02-10 07:45 <DIR> --d----- c:\program files\Symantec
2010-02-10 07:44 <DIR> --d----- c:\windows\system32\drivers\N360
2010-02-10 07:42 <DIR> --d----- c:\programdata\PCSettings
2010-02-10 07:42 <DIR> --d----- c:\progra~2\PCSettings
2010-02-10 07:29 118 a------- c:\windows\system32\MRT.INI
2010-02-09 01:32 <DIR> --d----- c:\programdata\McAfee

==================== Find3M ====================

2010-02-24 09:16 181,632 -------- c:\windows\system32\MpSigStub.exe
2010-01-18 18:29 365,568 a------- c:\windows\system32\secproc_isv.dll
2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp.dll
2010-01-18 18:29 369,152 a------- c:\windows\system32\secproc.dll
2010-01-18 18:28 324,608 a------- c:\windows\system32\RMActivate_isv.exe
2010-01-18 18:28 277,504 a------- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 18:28 320,512 a------- c:\windows\system32\RMActivate.exe
2010-01-18 18:28 280,064 a------- c:\windows\system32\RMActivate_ssp.exe
2009-12-19 04:02 977,920 a------- c:\windows\system32\wininet.dll
2009-12-19 04:02 12,288 a------- c:\windows\system32\tsbyuv.dll
2009-12-19 04:02 1,328,640 a------- c:\windows\system32\quartz.dll
2009-12-19 04:02 22,016 a------- c:\windows\system32\msyuv.dll
2009-12-19 04:02 31,744 a------- c:\windows\system32\msvidc32.dll
2009-12-19 04:02 13,312 a------- c:\windows\system32\msrle32.dll
2009-12-19 04:02 84,480 a------- c:\windows\system32\mciavi32.dll
2009-12-19 04:02 50,176 a------- c:\windows\system32\iyuv_32.dll
2009-12-19 04:02 91,648 a------- c:\windows\system32\avifil32.dll
2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfi.dat
2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfh.dat
2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfd.dat
2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfc.dat
2009-07-13 23:41 174 a--sh--- c:\program files\desktop.ini
2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfi.dat
2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfh.dat
2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfd.dat
2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 16:26 9,633,792 a--shr-- c:\windows\fonts\StaticCache.dat
2009-07-13 20:14 396,800 a--sh--- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 23:35:14.36 ===============

ATTACH LOG


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-09-29.01)

Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 12/30/2009 2:38:36 PM
System Uptime: 3/9/2010 9:11:44 PM (2 hours ago)

Motherboard: TOSHIBA | | Portable PC
Processor: AMD Athlon(tm) II Dual-Core M300 | Socket S1G3 | 2000/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 289 GiB total, 257.513 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP9: 1/3/2010 7:48:43 PM - Configured Microsoft Office Home and Student 2007
RP10: 1/13/2010 11:34:02 PM - Windows Update
RP11: 1/14/2010 9:30:30 AM - Windows Modules Installer
RP12: 1/14/2010 9:36:30 AM - Windows Update
RP13: 1/16/2010 10:28:00 AM - Windows Update
RP14: 1/22/2010 9:09:27 AM - Windows Update
RP15: 1/27/2010 10:08:21 AM - Windows Update
RP16: 1/30/2010 4:51:05 PM - Windows Update
RP17: 2/1/2010 7:36:48 PM - Windows Update
RP18: 2/5/2010 9:25:54 AM - Windows Update
RP19: 2/8/2010 10:37:00 PM - Windows Update
RP20: 2/10/2010 7:27:22 AM - Windows Update
RP22: 2/10/2010 8:00:10 AM - Windows Defender Checkpoint
RP23: 2/10/2010 3:33:57 PM - Installed Java(TM) 6 Update 18
RP24: 2/11/2010 9:20:08 PM - Windows Update
RP25: 2/15/2010 12:05:52 AM - Installed HiJackThis
RP26: 2/15/2010 2:10:38 PM - Windows Update
RP27: 2/18/2010 9:31:53 PM - Windows Update
RP28: 2/18/2010 9:40:51 PM - Windows Update
RP29: 2/19/2010 9:06:39 AM - Windows Update
RP30: 2/22/2010 7:37:07 PM - Windows Update
RP31: 2/25/2010 11:23:01 PM - Windows Update
RP32: 2/25/2010 11:25:12 PM - Windows Update
RP33: 3/1/2010 8:30:09 PM - Windows Update
RP34: 3/4/2010 10:23:16 PM - Windows Update
RP35: 3/8/2010 7:13:50 PM - Windows Update
RP36: 3/9/2010 9:09:23 PM - Installed Windows Installer Clean Up

==== Installed Programs ======================

Adobe Download Manager
Adobe Flash Player 10 ActiveX
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Install Manager
Bonjour
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Compatibility Pack for the 2007 Office system
ERUNT 1.1j
Google Chrome
Google Talk (remove only)
Google Toolbar for Internet Explorer
HiJackThis
iTunes
Java Auto Updater
Java(TM) 6 Update 18
Junk Mail filter update
Label@Once 1.0
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (3.6)
MSVCRT
MyToshiba
NetZero Launcher
PlayReady PC Runtime x86
Quickbooks Financial Center
QuickTime
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek USB 2.0 Card Reader
Realtek WLAN Driver
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Skype Launcher
Spybot - Search & Destroy
Synaptics Pointing Device Driver
Toshiba Application and Driver Installer
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Disc Creator
TOSHIBA DVD PLAYER
TOSHIBA eco Utility
TOSHIBA Extended Tiles for Windows Mobility Center
TOSHIBA Hardware Setup
TOSHIBA HDD/SSD Alert
Toshiba Online Backup
TOSHIBA PC Health Monitor
Toshiba Quality Application
TOSHIBA Recovery Media Creator
TOSHIBA Service Station
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
ToshibaRegistration
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WildTangent Games
Windows Installer Clean Up
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer

==== Event Viewer Messages From Past Week ========

3/9/2010 9:12:00 PM, Error: atikmdag [52236] - CPLIB :: General - Invalid Parameter
3/9/2010 9:12:00 PM, Error: atikmdag [43029] - Display is not active
3/9/2010 8:59:59 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
3/9/2010 11:35:17 PM, Error: Schannel [36888] - The following fatal alert was generated: 48. The internal error state is 552.
3/9/2010 11:35:17 PM, Error: Schannel [36882] - The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The SSL connection request has failed. The attached data contains the server certificate.
3/9/2010 10:46:11 PM, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {F81CD990-910B-4BBF-9CB3-6A77F3D697B3}. The error: "2" Happened while starting this command: C:\Program Files\Windows Live\Messenger\msnmsgr.exe -Embedding
3/7/2010 9:21:25 PM, Error: Service Control Manager [7031] - The Norton Security Suite service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

==== End Of File ===========================

Thank you again for all of your help!! I really appreciate it!!

Blade81
2010-03-10, 15:12
Thanks for the logs :). Any (earlier) issues left?

sem825
2010-03-11, 05:15
Hi,

I still seem to be having problems in Internet Explorer and Firefox. If I do a search on Google, and click one of the links in the results, I'll usually get a message that says, "The document has moved, redirecting..." and it will take me to a different site, some sort of ad or something...

I ran dds again and here are the logs:

DDS:


DDS (Ver_09-09-29.01) - NTFSx86
Run by Owner at 23:12:09.57 on Wed 03/10/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1462 [GMT -5:00]

SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

============== Running Processes ===============

C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\atieclxx.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\TECO\TEco.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Owner\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\windows\system32\wuauclt.exe
C:\windows\system32\taskhost.exe
C:\windows\servicing\TrustedInstaller.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\Users\Owner\Desktop\dds.com
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [MyTOSHIBA] "c:\program files\toshiba\my toshiba\MyToshiba.exe" /AUTO
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [googletalk] c:\users\owner\appdata\roaming\google\google talk\googletalk.exe /autostart
uRun: [Google Update] "c:\users\owner\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
mRun: [NortonOnlineBackupReminder] "c:\program files\toshiba\toshiba online backup\activation\TobuActivation.exe" UNATTENDED
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\xmmpllk7.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\owner\appdata\local\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-14 176128]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2009-8-10 185712]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-2-11 1153368]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-8-11 185712]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-19 12920]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2009-12-14 7680]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-12-14 187392]
R3 RTL8187Se;Realtek RTL8187SE Wireless LAN PCIE Network Adapter;c:\windows\system32\drivers\RTL8187Se.sys [2009-12-14 372736]
R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2009-12-14 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-8-3 111960]
R3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-8-6 685424]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 getPlusHelper;getPlus(R) Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2009-7-13 20992]

=============== Created Last 30 ================

2010-03-09 21:25 <DIR> --d----- c:\programdata\NOS
2010-03-09 21:09 <DIR> --d----- c:\program files\Windows Installer Clean Up
2010-03-09 21:09 <DIR> --d----- c:\program files\MSECACHE
2010-03-09 21:01 <DIR> --dsh--- C:\$RECYCLE.BIN
2010-03-07 21:32 261,632 a------- c:\windows\PEV.exe
2010-03-07 21:32 161,792 a------- c:\windows\SWREG.exe
2010-03-07 21:32 98,816 a------- c:\windows\sed.exe
2010-03-07 21:32 77,312 a------- c:\windows\MBR.exe
2010-02-24 09:00 641,536 a------- c:\windows\system32\CPFilters.dll
2010-02-24 09:00 465,408 a------- c:\windows\system32\psisdecd.dll
2010-02-24 09:00 417,792 a------- c:\windows\system32\msdri.dll
2010-02-24 09:00 204,288 a------- c:\windows\system32\MSNP.ax
2010-02-24 09:00 2,048 a------- c:\windows\system32\tzres.dll
2010-02-15 00:07 <DIR> --d----- c:\program files\TrendMicro
2010-02-11 17:16 <DIR> --d----- c:\programdata\Lavasoft
2010-02-11 15:28 <DIR> --d----- c:\programdata\Spybot - Search & Destroy
2010-02-11 15:28 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2010-02-11 15:28 <DIR> --d----- c:\progra~2\Spybot - Search & Destroy
2010-02-11 12:03 <DIR> --d--r-- c:\program files\Norton Support
2010-02-10 15:36 <DIR> --d----- c:\programdata\Sun
2010-02-10 15:35 411,368 a------- c:\windows\system32\deploytk.dll
2010-02-10 14:01 <DIR> --d----- c:\programdata\RegCure
2010-02-10 14:01 <DIR> --d----- c:\progra~2\RegCure
2010-02-10 07:46 107,368 a----r-- c:\windows\system32\GEARAspi.dll
2010-02-10 07:46 26,600 a----r-- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-02-10 07:45 <DIR> --d----- c:\program files\Symantec
2010-02-10 07:44 <DIR> --d----- c:\windows\system32\drivers\N360
2010-02-10 07:42 <DIR> --d----- c:\programdata\PCSettings
2010-02-10 07:42 <DIR> --d----- c:\progra~2\PCSettings
2010-02-10 07:29 118 a------- c:\windows\system32\MRT.INI
2010-02-09 01:32 <DIR> --d----- c:\programdata\McAfee

==================== Find3M ====================

2010-02-24 09:16 181,632 -------- c:\windows\system32\MpSigStub.exe
2010-01-18 18:29 365,568 a------- c:\windows\system32\secproc_isv.dll
2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp.dll
2010-01-18 18:29 369,152 a------- c:\windows\system32\secproc.dll
2010-01-18 18:28 324,608 a------- c:\windows\system32\RMActivate_isv.exe
2010-01-18 18:28 277,504 a------- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 18:28 320,512 a------- c:\windows\system32\RMActivate.exe
2010-01-18 18:28 280,064 a------- c:\windows\system32\RMActivate_ssp.exe
2009-12-19 04:02 977,920 a------- c:\windows\system32\wininet.dll
2009-12-19 04:02 12,288 a------- c:\windows\system32\tsbyuv.dll
2009-12-19 04:02 1,328,640 a------- c:\windows\system32\quartz.dll
2009-12-19 04:02 22,016 a------- c:\windows\system32\msyuv.dll
2009-12-19 04:02 31,744 a------- c:\windows\system32\msvidc32.dll
2009-12-19 04:02 13,312 a------- c:\windows\system32\msrle32.dll
2009-12-19 04:02 84,480 a------- c:\windows\system32\mciavi32.dll
2009-12-19 04:02 50,176 a------- c:\windows\system32\iyuv_32.dll
2009-12-19 04:02 91,648 a------- c:\windows\system32\avifil32.dll
2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfi.dat
2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfh.dat
2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfd.dat
2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfc.dat
2009-07-13 23:41 174 a--sh--- c:\program files\desktop.ini
2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfi.dat
2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfh.dat
2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfd.dat
2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 16:26 9,633,792 a--shr-- c:\windows\fonts\StaticCache.dat
2009-07-13 20:14 396,800 a--sh--- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 23:12:32.66 ===============


Attach Log:



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-09-29.01)

Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 12/30/2009 2:38:36 PM
System Uptime: 3/10/2010 8:09:28 PM (3 hours ago)

Motherboard: TOSHIBA | | Portable PC
Processor: AMD Athlon(tm) II Dual-Core M300 | Socket S1G3 | 2000/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 289 GiB total, 257.45 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP9: 1/3/2010 7:48:43 PM - Configured Microsoft Office Home and Student 2007
RP10: 1/13/2010 11:34:02 PM - Windows Update
RP11: 1/14/2010 9:30:30 AM - Windows Modules Installer
RP12: 1/14/2010 9:36:30 AM - Windows Update
RP13: 1/16/2010 10:28:00 AM - Windows Update
RP14: 1/22/2010 9:09:27 AM - Windows Update
RP15: 1/27/2010 10:08:21 AM - Windows Update
RP16: 1/30/2010 4:51:05 PM - Windows Update
RP17: 2/1/2010 7:36:48 PM - Windows Update
RP18: 2/5/2010 9:25:54 AM - Windows Update
RP19: 2/8/2010 10:37:00 PM - Windows Update
RP20: 2/10/2010 7:27:22 AM - Windows Update
RP22: 2/10/2010 8:00:10 AM - Windows Defender Checkpoint
RP23: 2/10/2010 3:33:57 PM - Installed Java(TM) 6 Update 18
RP24: 2/11/2010 9:20:08 PM - Windows Update
RP25: 2/15/2010 12:05:52 AM - Installed HiJackThis
RP26: 2/15/2010 2:10:38 PM - Windows Update
RP27: 2/18/2010 9:31:53 PM - Windows Update
RP28: 2/18/2010 9:40:51 PM - Windows Update
RP29: 2/19/2010 9:06:39 AM - Windows Update
RP30: 2/22/2010 7:37:07 PM - Windows Update
RP31: 2/25/2010 11:23:01 PM - Windows Update
RP32: 2/25/2010 11:25:12 PM - Windows Update
RP33: 3/1/2010 8:30:09 PM - Windows Update
RP34: 3/4/2010 10:23:16 PM - Windows Update
RP35: 3/8/2010 7:13:50 PM - Windows Update
RP36: 3/9/2010 9:09:23 PM - Installed Windows Installer Clean Up

==== Installed Programs ======================

Adobe Download Manager
Adobe Flash Player 10 ActiveX
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Install Manager
Bonjour
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Compatibility Pack for the 2007 Office system
ERUNT 1.1j
Google Chrome
Google Talk (remove only)
Google Toolbar for Internet Explorer
HiJackThis
iTunes
Java Auto Updater
Java(TM) 6 Update 18
Junk Mail filter update
Label@Once 1.0
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (3.6)
MSVCRT
MyToshiba
NetZero Launcher
PlayReady PC Runtime x86
Quickbooks Financial Center
QuickTime
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek USB 2.0 Card Reader
Realtek WLAN Driver
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Skype Launcher
Spybot - Search & Destroy
Synaptics Pointing Device Driver
Toshiba Application and Driver Installer
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Disc Creator
TOSHIBA DVD PLAYER
TOSHIBA eco Utility
TOSHIBA Extended Tiles for Windows Mobility Center
TOSHIBA Hardware Setup
TOSHIBA HDD/SSD Alert
Toshiba Online Backup
TOSHIBA PC Health Monitor
Toshiba Quality Application
TOSHIBA Recovery Media Creator
TOSHIBA Service Station
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
ToshibaRegistration
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WildTangent Games
Windows Installer Clean Up
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer

==== Event Viewer Messages From Past Week ========

3/9/2010 9:12:00 PM, Error: atikmdag [52236] - CPLIB :: General - Invalid Parameter
3/9/2010 8:59:59 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
3/9/2010 10:46:11 PM, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {F81CD990-910B-4BBF-9CB3-6A77F3D697B3}. The error: "2" Happened while starting this command: C:\Program Files\Windows Live\Messenger\msnmsgr.exe -Embedding
3/7/2010 9:21:25 PM, Error: Service Control Manager [7031] - The Norton Security Suite service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
3/10/2010 11:07:44 PM, Error: Schannel [36888] - The following fatal alert was generated: 48. The internal error state is 552.
3/10/2010 11:07:44 PM, Error: Schannel [36882] - The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The SSL connection request has failed. The attached data contains the server certificate.
3/10/2010 11:00:34 PM, Error: atikmdag [43029] - Display is not active

==== End Of File ===========================

Please let me know if there's any other information I can give you. Thanks again for all of your help. I soooo appreciate it!

sem825
2010-03-11, 05:34
Also, the little icons on the tabs within Internet Explorer are incorrect. For example, if I visit urbandictionary.com, a little "u" shows up on the tab. If I then go to GMail.com, the "u" stays when it should be a red and white envelope (the GMail icon) instead. Is this malware-related?

Firefox does not seem to have this problem. Only IE.

Again, please let me know if there's any other info I can provide.

Thanks, and sorry this is taking so long!

Blade81
2010-03-11, 16:35
Hi,

Let's see..

Open notepad and copy/paste the text in the quotebox below into it:



DDS::
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
Reboot::



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows, disable protection software and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log. Is redirecting still there?

sem825
2010-03-12, 04:22
Hello,

That seemed to stop the redirecting (hooray!), but I'm still seeing weird stuff with the tab icons, particularly with Google it seems. If I move from Google to a new site, and return to Google, the "g" icon is replaced by the icon of whatever site I just visited...

I'm posting both the ComboFix log and a new dds log:

ComboFix 10-03-11.02 - Owner 03/11/2010 21:55:39.5.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1568 [GMT -5:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
.

((((((((((((((((((((((((( Files Created from 2010-02-12 to 2010-03-12 )))))))))))))))))))))))))))))))
.

2010-03-12 02:59 . 2010-03-12 02:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-12 02:54 . 2010-03-12 02:54 -------- d-----w- C:\32788R22FWJFW
2010-03-12 02:51 . 2010-03-12 02:51 -------- d-----w- c:\users\Owner\AppData\Local\Apple
2010-03-10 02:09 . 2010-03-10 02:09 3584 ----a-r- c:\users\Owner\AppData\Roaming\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-03-10 02:09 . 2010-03-10 02:09 -------- d-----w- c:\program files\Windows Installer Clean Up
2010-03-10 02:09 . 2010-03-10 02:09 -------- d-----w- c:\program files\MSECACHE
2010-03-10 02:01 . 2010-03-12 03:01 -------- d-----w- c:\users\Owner\AppData\Local\temp
2010-02-24 14:00 . 2009-12-13 09:30 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-02-24 14:00 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-02-24 14:00 . 2009-12-13 09:29 417792 ----a-w- c:\windows\system32\msdri.dll
2010-02-24 14:00 . 2010-02-02 07:45 2048 ----a-w- c:\windows\system32\tzres.dll
2010-02-19 02:35 . 2010-02-19 02:35 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-02-15 05:07 . 2010-02-15 05:07 388096 ----a-r- c:\users\Owner\AppData\Roaming\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-02-15 05:07 . 2010-02-15 05:07 -------- d-----w- c:\program files\TrendMicro
2010-02-15 05:00 . 2010-02-15 05:00 -------- d-----w- c:\program files\ERUNT
2010-02-11 22:16 . 2010-02-13 05:35 -------- d-----w- c:\programdata\Lavasoft
2010-02-11 20:28 . 2010-02-15 04:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-11 20:28 . 2010-02-11 22:17 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-02-11 19:52 . 2010-02-11 19:52 103050 ----a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{2D3A6BBC-41F4-1F50-18CC-9A77DAEA1AB8}-uninst.exe
2010-02-11 17:03 . 2010-02-11 17:03 -------- d-----r- c:\program files\Norton Support
2010-02-11 15:52 . 2010-02-11 15:52 -------- d-----w- c:\users\Owner\AppData\Local\Deployment
2010-02-11 15:52 . 2010-02-11 15:52 -------- d-----w- c:\users\Owner\AppData\Local\Apps
2010-02-10 20:36 . 2010-02-10 20:36 -------- d-----w- c:\program files\Common Files\Java
2010-02-10 20:35 . 2009-12-17 22:14 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-10 19:01 . 2010-02-11 19:52 -------- d-----w- c:\programdata\RegCure
2010-02-10 12:54 . 2010-02-10 19:51 -------- d-----w- c:\users\Owner\AppData\Local\Diagnostics
2010-02-10 12:46 . 2010-02-10 12:45 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-02-10 12:46 . 2010-02-10 12:45 107368 ----a-r- c:\windows\system32\GEARAspi.dll
2010-02-10 12:45 . 2010-03-08 02:23 -------- d-----w- c:\program files\Symantec
2010-02-10 12:44 . 2010-02-10 19:55 -------- d-----w- c:\windows\system32\drivers\N360
2010-02-10 12:42 . 2010-02-10 12:42 -------- d-----w- c:\programdata\PCSettings

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-12 02:54 . 2009-12-14 23:17 -------- d-----w- c:\programdata\Microsoft Help
2010-02-24 14:16 . 2009-12-30 20:03 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-20 18:34 . 2009-09-02 05:46 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-19 02:39 . 2009-12-14 23:08 -------- d-----w- c:\program files\Microsoft Works
2010-02-10 20:35 . 2009-09-02 05:29 -------- d-----w- c:\program files\Java
2010-02-10 12:44 . 2009-12-14 23:49 -------- d-----w- c:\programdata\Norton
2010-02-10 12:42 . 2009-12-14 23:49 -------- d-----w- c:\programdata\NortonInstaller
2010-02-09 17:51 . 2010-02-09 17:48 38434288 ----a-w- c:\programdata\Toshiba\TSS\Plugins\SwUpdates\Packages\4d92cef8-7ed7-402d-aa91-6eda708f6bb8\171515_14.32.13.TC00143300K.exe
2010-02-09 06:32 . 2010-02-09 06:32 -------- d-----w- c:\programdata\McAfee
2010-01-24 18:26 . 2010-01-02 03:35 1670624 ----a-w- c:\programdata\WildTangent\TOSHIBA Game Console\Downloads\en-us\Installers\SetupGamesClient.exe
2010-01-23 03:07 . 2009-09-02 05:47 -------- d-----w- c:\programdata\Partner
2010-01-18 23:29 . 2010-02-10 03:54 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 23:29 . 2010-02-10 03:54 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-18 23:29 . 2010-02-10 03:54 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-18 23:29 . 2010-02-10 03:54 369152 ----a-w- c:\windows\system32\secproc.dll
2010-01-18 23:28 . 2010-02-10 03:54 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-18 23:28 . 2010-02-10 03:54 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 23:28 . 2010-02-10 03:54 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-18 23:28 . 2010-02-10 03:54 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-08 03:18 . 2010-02-10 03:54 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-01-08 03:17 . 2010-02-10 03:54 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-01-03 07:42 . 2010-01-03 07:42 79367 ----a-w- c:\users\Owner\AppData\Roaming\Google\Google Talk\uninstall.exe
2009-12-30 20:01 . 2009-12-30 20:01 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbBA5B.tmp.exe
2009-12-30 19:41 . 2009-12-30 19:41 79136 ----a-w- c:\users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-30 19:39 . 2009-12-30 19:39 13 --sh--r- c:\windows\system32\drivers\fbd.sys
2009-12-19 09:02 . 2010-01-22 03:55 977920 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 09:02 . 2010-02-10 03:54 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-19 09:02 . 2010-02-10 03:54 1328640 ----a-w- c:\windows\system32\quartz.dll
2009-12-19 09:02 . 2010-02-10 03:54 22016 ----a-w- c:\windows\system32\msyuv.dll
2009-12-19 09:02 . 2010-02-10 03:54 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-19 09:02 . 2010-02-10 03:54 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-19 09:02 . 2010-02-10 03:54 84480 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-19 09:02 . 2010-02-10 03:54 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-19 09:02 . 2010-02-10 03:54 91648 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((( SnapShot@2010-03-09_14.23.58 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-02 05:29 . 2010-03-10 02:14 33660 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:55 . 2010-03-12 03:03 51360 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-03-10 02:29 . 2010-03-10 02:29 84507 c:\windows\System32\Macromed\Flash\uninstall_activeX.exe
- 2009-12-30 22:36 . 2010-03-09 00:20 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-30 22:36 . 2010-03-12 02:54 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-30 22:36 . 2010-03-12 02:54 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-30 22:36 . 2010-03-09 00:20 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:41 . 2010-03-12 02:54 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:41 . 2010-03-09 00:20 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-30 19:40 . 2010-03-12 02:54 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-12-30 19:40 . 2010-03-09 14:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-12-30 19:40 . 2010-03-09 14:14 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-12-30 19:40 . 2010-03-12 02:54 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-12-30 19:40 . 2010-03-12 02:54 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-12-30 19:40 . 2010-03-09 14:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-12-14 23:19 . 2010-02-19 02:40 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-12-14 23:19 . 2010-03-12 02:54 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2009-12-14 23:19 . 2010-02-19 02:40 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-12-14 23:19 . 2010-03-12 02:54 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-12-14 23:19 . 2010-02-19 02:40 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-12-14 23:19 . 2010-03-12 02:54 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2010-03-12 02:52 . 2010-03-12 02:52 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2010-02-19 14:07 . 2010-02-19 14:07 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2009-07-13 23:26 . 2009-07-14 01:03 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.1.7600.20655_none_0ca29ea86ca54783\AcRes.dll
+ 2009-07-13 23:26 . 2009-07-14 01:03 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.1.7600.16539_none_0c32a2dd5373d533\AcRes.dll
+ 2009-12-30 19:40 . 2010-03-12 03:03 8130 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3957342637-2223780103-148138915-1000_UserData.bin
+ 2010-03-10 02:12 . 2010-03-12 03:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-03-08 02:25 . 2010-03-09 00:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-03-08 02:25 . 2010-03-09 00:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-03-10 02:12 . 2010-03-12 03:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-13 23:26 . 2009-07-14 01:14 211968 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.20655_none_0ca69fd06ca1acdf\AcXtrnal.dll
+ 2009-07-13 23:27 . 2009-07-14 01:14 559616 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.20655_none_0ca69fd06ca1acdf\AcLayers.dll
+ 2009-07-13 23:26 . 2009-07-14 01:14 211968 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.16539_none_0c36a40553703a8f\AcXtrnal.dll
+ 2009-07-13 23:27 . 2009-07-14 01:14 559616 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.16539_none_0c36a40553703a8f\AcLayers.dll
+ 2009-12-31 05:19 . 2010-03-12 02:51 244558 c:\windows\System32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2010-01-27 00:58 . 2010-01-27 00:58 256280 c:\windows\System32\Macromed\Flash\FlashUtil10e.exe
+ 2006-09-06 23:09 . 2006-09-06 23:09 472064 c:\windows\Installer\14590b.msi
- 2009-12-14 23:19 . 2010-02-19 02:40 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-12-14 23:19 . 2010-03-12 02:54 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-12-14 23:19 . 2010-03-12 02:54 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2009-12-14 23:19 . 2010-02-19 02:40 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-12-14 23:19 . 2010-03-12 02:54 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2009-12-14 23:19 . 2010-02-19 02:40 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2009-12-14 23:19 . 2010-02-19 02:40 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-12-14 23:19 . 2010-03-12 02:54 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2009-07-14 02:03 . 2010-03-08 01:57 6815744 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:03 . 2010-03-12 02:59 6815744 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2009-07-14 04:34 . 2010-02-27 03:38 3798234 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:34 . 2010-03-12 03:03 3798234 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2010-02-04 22:24 . 2010-02-04 22:24 9122304 c:\windows\Installer\a71a273.msp
+ 2010-02-21 06:00 . 2010-02-21 06:00 8480768 c:\windows\Installer\a71a253.msp
+ 2009-12-14 23:19 . 2010-03-12 02:54 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-12-14 23:19 . 2010-02-19 02:40 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2010-03-12 02:54 . 2010-03-12 02:54 6606848 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
+ 2009-07-14 07:18 . 2010-03-11 04:02 15087590 c:\windows\winsxs\ManifestCache\e4e8be02b8fae2a7_blobs.bin
+ 2009-12-30 19:46 . 2010-03-02 05:30 31648712 c:\windows\System32\MRT.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MyTOSHIBA"="c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe" [2009-08-06 264048]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-02 39408]
"googletalk"="c:\users\Owner\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Google Update"="c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-02-11 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-30 98304]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-29 7625248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-21 1545512]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-08-21 476512]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-07-28 460088]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2009-08-05 738616]
"ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-08-17 1294136]
"TosWaitSrv"="c:\program files\TOSHIBA\TPHM\TosWaitSrv.exe" [2009-08-07 611672]
"Teco"="c:\program files\TOSHIBA\TECO\Teco.exe" [2009-08-12 1324384]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 611672]
"NortonOnlineBackupReminder"="c:\program files\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" [2009-07-16 529256]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)

R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-30 176128]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [2009-08-11 185712]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-08-12 185712]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [2009-06-20 12920]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2009-07-07 7680]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-31 187392]
S3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-04 111960]
S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-07 685424]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}]
2009-08-06 16:15 264048 ----a-w- c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe
.
Contents of the 'Scheduled Tasks' folder

2010-03-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3957342637-2223780103-148138915-1000Core.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-11 15:52]

2010-03-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3957342637-2223780103-148138915-1000UA.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-11 15:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\xmmpllk7.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Owner\AppData\Local\Google\Update\1.2.183.17\npGoogleOneClick8.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\windows\system32\sppsvc.exe
c:\program files\TOSHIBA\ConfigFree\CFSwMgr.exe
c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
c:\program files\TOSHIBA\TPHM\TPCHWMsg.exe
c:\windows\system32\vssvc.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2010-03-11 22:04:49 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-12 03:04
ComboFix2.txt 2010-03-10 02:01
ComboFix3.txt 2010-03-09 14:35
ComboFix4.txt 2010-03-09 14:25

Pre-Run: 277,018,537,984 bytes free
Post-Run: 277,211,181,056 bytes free

- - End Of File - - 5B99DA6CEF56933B444AD01F3C1BA5E7

------------------------------------------------------------------------
DDS log:


DDS (Ver_09-09-29.01) - NTFSx86
Run by Owner at 22:21:09.97 on Thu 03/11/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1842 [GMT -5:00]

SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

============== Running Processes ===============

C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\atieclxx.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\windows\system32\Dwm.exe
C:\windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\TECO\TEco.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Owner\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\windows\Explorer.exe
C:\windows\system32\wuauclt.exe
C:\windows\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\Users\Owner\Desktop\dds.com
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [MyTOSHIBA] "c:\program files\toshiba\my toshiba\MyToshiba.exe" /AUTO
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [googletalk] c:\users\owner\appdata\roaming\google\google talk\googletalk.exe /autostart
uRun: [Google Update] "c:\users\owner\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
mRun: [NortonOnlineBackupReminder] "c:\program files\toshiba\toshiba online backup\activation\TobuActivation.exe" UNATTENDED
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\xmmpllk7.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\owner\appdata\local\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-14 176128]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2009-8-10 185712]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-2-11 1153368]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-8-11 185712]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-19 12920]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2009-12-14 7680]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-12-14 187392]
R3 RTL8187Se;Realtek RTL8187SE Wireless LAN PCIE Network Adapter;c:\windows\system32\drivers\RTL8187Se.sys [2009-12-14 372736]
R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2009-12-14 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-8-3 111960]
R3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-8-6 685424]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]

=============== Created Last 30 ================

2010-03-11 22:01 <DIR> --d----- C:\$RECYCLE.BIN
2010-03-09 21:09 <DIR> --d----- c:\program files\Windows Installer Clean Up
2010-03-09 21:09 <DIR> --d----- c:\program files\MSECACHE
2010-03-07 21:32 261,632 a------- c:\windows\PEV.exe
2010-03-07 21:32 161,792 a------- c:\windows\SWREG.exe
2010-03-07 21:32 98,816 a------- c:\windows\sed.exe
2010-03-07 21:32 77,312 a------- c:\windows\MBR.exe
2010-02-24 09:00 641,536 a------- c:\windows\system32\CPFilters.dll
2010-02-24 09:00 465,408 a------- c:\windows\system32\psisdecd.dll
2010-02-24 09:00 417,792 a------- c:\windows\system32\msdri.dll
2010-02-24 09:00 204,288 a------- c:\windows\system32\MSNP.ax
2010-02-24 09:00 2,048 a------- c:\windows\system32\tzres.dll
2010-02-15 00:07 <DIR> --d----- c:\program files\TrendMicro
2010-02-11 17:16 <DIR> --d----- c:\programdata\Lavasoft
2010-02-11 15:28 <DIR> --d----- c:\programdata\Spybot - Search & Destroy
2010-02-11 15:28 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2010-02-11 15:28 <DIR> --d----- c:\progra~2\Spybot - Search & Destroy
2010-02-11 12:03 <DIR> --d--r-- c:\program files\Norton Support
2010-02-10 15:36 <DIR> --d----- c:\programdata\Sun
2010-02-10 15:35 411,368 a------- c:\windows\system32\deploytk.dll
2010-02-10 14:01 <DIR> --d----- c:\programdata\RegCure
2010-02-10 14:01 <DIR> --d----- c:\progra~2\RegCure
2010-02-10 07:46 107,368 a----r-- c:\windows\system32\GEARAspi.dll
2010-02-10 07:46 26,600 a----r-- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-02-10 07:45 <DIR> --d----- c:\program files\Symantec
2010-02-10 07:44 <DIR> --d----- c:\windows\system32\drivers\N360
2010-02-10 07:42 <DIR> --d----- c:\programdata\PCSettings
2010-02-10 07:42 <DIR> --d----- c:\progra~2\PCSettings
2010-02-10 07:29 118 a------- c:\windows\system32\MRT.INI

==================== Find3M ====================

2010-02-24 09:16 181,632 -------- c:\windows\system32\MpSigStub.exe
2010-01-18 18:29 365,568 a------- c:\windows\system32\secproc_isv.dll
2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp.dll
2010-01-18 18:29 369,152 a------- c:\windows\system32\secproc.dll
2010-01-18 18:28 324,608 a------- c:\windows\system32\RMActivate_isv.exe
2010-01-18 18:28 277,504 a------- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 18:28 320,512 a------- c:\windows\system32\RMActivate.exe
2010-01-18 18:28 280,064 a------- c:\windows\system32\RMActivate_ssp.exe
2009-12-19 04:02 977,920 a------- c:\windows\system32\wininet.dll
2009-12-19 04:02 12,288 a------- c:\windows\system32\tsbyuv.dll
2009-12-19 04:02 1,328,640 a------- c:\windows\system32\quartz.dll
2009-12-19 04:02 22,016 a------- c:\windows\system32\msyuv.dll
2009-12-19 04:02 31,744 a------- c:\windows\system32\msvidc32.dll
2009-12-19 04:02 13,312 a------- c:\windows\system32\msrle32.dll
2009-12-19 04:02 84,480 a------- c:\windows\system32\mciavi32.dll
2009-12-19 04:02 50,176 a------- c:\windows\system32\iyuv_32.dll
2009-12-19 04:02 91,648 a------- c:\windows\system32\avifil32.dll
2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfi.dat
2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfh.dat
2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfd.dat
2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfc.dat
2009-07-13 23:41 174 a--sh--- c:\program files\desktop.ini
2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfi.dat
2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfh.dat
2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfd.dat
2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 16:26 9,633,792 a--shr-- c:\windows\fonts\StaticCache.dat
2009-07-13 20:14 396,800 a--sh--- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 22:21:34.95 ===============

Attach Log:

:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-09-29.01)

Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 12/30/2009 2:38:36 PM
System Uptime: 3/11/2010 10:00:19 PM (0 hours ago)

Motherboard: TOSHIBA | | Portable PC
Processor: AMD Athlon(tm) II Dual-Core M300 | Socket S1G3 | 2000/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 289 GiB total, 258.243 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP13: 1/16/2010 10:28:00 AM - Windows Update
RP14: 1/22/2010 9:09:27 AM - Windows Update
RP15: 1/27/2010 10:08:21 AM - Windows Update
RP16: 1/30/2010 4:51:05 PM - Windows Update
RP17: 2/1/2010 7:36:48 PM - Windows Update
RP18: 2/5/2010 9:25:54 AM - Windows Update
RP19: 2/8/2010 10:37:00 PM - Windows Update
RP20: 2/10/2010 7:27:22 AM - Windows Update
RP22: 2/10/2010 8:00:10 AM - Windows Defender Checkpoint
RP23: 2/10/2010 3:33:57 PM - Installed Java(TM) 6 Update 18
RP24: 2/11/2010 9:20:08 PM - Windows Update
RP25: 2/15/2010 12:05:52 AM - Installed HiJackThis
RP26: 2/15/2010 2:10:38 PM - Windows Update
RP27: 2/18/2010 9:31:53 PM - Windows Update
RP28: 2/18/2010 9:40:51 PM - Windows Update
RP29: 2/19/2010 9:06:39 AM - Windows Update
RP30: 2/22/2010 7:37:07 PM - Windows Update
RP31: 2/25/2010 11:23:01 PM - Windows Update
RP32: 2/25/2010 11:25:12 PM - Windows Update
RP33: 3/1/2010 8:30:09 PM - Windows Update
RP34: 3/4/2010 10:23:16 PM - Windows Update
RP35: 3/8/2010 7:13:50 PM - Windows Update
RP36: 3/9/2010 9:09:23 PM - Installed Windows Installer Clean Up
RP37: 3/11/2010 9:51:48 PM - Windows Update
RP38: 3/11/2010 10:04:02 PM - Windows Update

==== Installed Programs ======================

Adobe Flash Player 10 ActiveX
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Install Manager
Bonjour
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Compatibility Pack for the 2007 Office system
ERUNT 1.1j
Google Chrome
Google Talk (remove only)
Google Toolbar for Internet Explorer
HiJackThis
iTunes
Java Auto Updater
Java(TM) 6 Update 18
Junk Mail filter update
Label@Once 1.0
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (3.6)
MSVCRT
MyToshiba
NetZero Launcher
PlayReady PC Runtime x86
Quickbooks Financial Center
QuickTime
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Realtek USB 2.0 Card Reader
Realtek WLAN Driver
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB978380)
Security Update for Microsoft Office Excel 2007 (KB978382)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Skype Launcher
Spybot - Search & Destroy
Synaptics Pointing Device Driver
Toshiba Application and Driver Installer
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Disc Creator
TOSHIBA DVD PLAYER
TOSHIBA eco Utility
TOSHIBA Extended Tiles for Windows Mobility Center
TOSHIBA Hardware Setup
TOSHIBA HDD/SSD Alert
Toshiba Online Backup
TOSHIBA PC Health Monitor
Toshiba Quality Application
TOSHIBA Recovery Media Creator
TOSHIBA Service Station
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
ToshibaRegistration
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WildTangent Games
Windows Installer Clean Up
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer

==== Event Viewer Messages From Past Week ========

3/9/2010 10:46:11 PM, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {F81CD990-910B-4BBF-9CB3-6A77F3D697B3}. The error: "2" Happened while starting this command: C:\Program Files\Windows Live\Messenger\msnmsgr.exe -Embedding
3/7/2010 9:21:25 PM, Error: Service Control Manager [7031] - The Norton Security Suite service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
3/11/2010 9:55:16 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
3/11/2010 9:54:15 PM, Error: Schannel [36888] - The following fatal alert was generated: 48. The internal error state is 552.
3/11/2010 9:54:15 PM, Error: Schannel [36882] - The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The SSL connection request has failed. The attached data contains the server certificate.
3/11/2010 10:00:34 PM, Error: atikmdag [52236] - CPLIB :: General - Invalid Parameter
3/11/2010 10:00:34 PM, Error: atikmdag [43029] - Display is not active

==== End Of File ===========================


Thank you, thank you, thank you, thank you!!!!

Blade81
2010-03-12, 14:54
Hi,

If you run IE with addons disabled (instructions below) does it still behave like that? Could you provide a screenshot of situation?


Click start ->All Programs ->Accessories ->System Tools ->Internet Explorer (No Add-ons)

sem825
2010-03-13, 06:27
I think that fixed it!! Does that mean everything's fixed now?!

What am I missing without the add-ons on IE? Anything important?

I just need to enable Norton again and I'm good to go? Is there an Anti-Virus program that you recommend more than the others? Is there anything additional I should do to prevent this from happening again?

I truly cannot thank you enough, Blade81. You have been extremely helpful! You are amazing. I'll definitely be giving an additional donation to Spybot now.

Thank you, thank you, thank you!! :)

Blade81
2010-03-13, 10:11
Hi,

That tells one of your addons is the causer. In order to be able to run Internet Explorer normally you have to debug out the trouble addon. In Internet Explorer, click tools->manage addons and disable those one by one to find out what is the trouble maker :)

sem825
2010-03-13, 17:48
Wonderful! Thank you so much!! You are wonderful!

Blade81
2010-03-13, 19:06
You're welcome :)

Let's see the final steps.


THESE STEPS ARE VERY IMPORTANT

Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

A To disable the System Restore feature:

1. Click on the Start button.
2. Hover over the Computer option, right click on it and then click Properties.
3. On the left hand side, click Advanced Settings.
4. If asked to permit the action, click on Allow.
5. Click on the System Protection tab.
6. Uncheck any checkboxes listed for your hard drives.
7. Press OK.


B. Reboot.

C Turn ON System Restore.
Follow the steps like you did when disabling system restore but on step 6. check any checkboxes listed for your hard drives.



Now lets uninstall ComboFix:

Click START then RUN
Now copy-paste Combofix /uninstall in the runbox and click OK



Please download OTC (http://oldtimer.geekstogo.com/OTC.exe) and save it to desktop.

Double-click OTC.exe.
Click the CleanUp! button.
Select Yes when the
Begin cleanup Process?
prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.


UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet.

Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.


hosts file:
Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate webpages. We can customize a hosts file so that it blocks certain webpages. However, it can slow down certain computers. This is why using a hosts file is optional!!
Download it here (http://www.mvps.org/winhelp2002/hosts.htm). Make sure you read the instructions on how to install the hosts file. There is a good tutorial here (http://www.bleepingcomputer.com/forums/tutorial51.html)
If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button (at the lower left hand corner of your screen) Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then double-click it. On the dropdown box, change the setting from automatic to manual. Click ok
Run Secunia vulnerability check here (http://secunia.com/vulnerability_scanning/online/) and fix its findings.



Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs and operating system are up to date.

Once again, please post and tell me how things are going with your system... problems etc.

Have a great day,
Blade :cool:

sem825
2010-03-14, 06:22
Hello,

I opened the "System Protection" tab, but I don't see any checkboxes. I see a heading that says "Protection Settings" and then under that, it lists:

TI103426W0D (C:) (System) (It says Protection On)
System (It says Protection Off)

If I click on either, nothing happens.

Did I misunderstand the instructions?
Thanks!

Blade81
2010-03-14, 12:28
Hi,

No, you didn't misunderstand, I explained it a bit wrong.

Make TI103426W0D selected and click "Configure..." in that window select "Turn off system protection" and then click ok. Reboot the system and then re-enable system protection by selecting "Restore system settings and previous versions of files" option and then click ok.

sem825
2010-03-15, 03:06
Hi Blade,

Thanks! I followed all of your steps. I reset system restore, I uninstalled ComboFix, I downloaded and ran OTC, I updated IE, I downloaded hosts file, and I ran Secunia.

All seems to be good, but I just have a few questions:

1) Should I be making Firefox more secure somehow as well (like I did with the security settings in IE)?
2) On the bottom of my IE window, it says "Internet | Protected Mode: Off" - is that okay?
3) When I ran Secunia, it shows 1 insecure version: Adobe Reader 9. It says, "The detected version installed on your system is 9.3.0.148, however, the latest patched version released by the vendor, fixing one or more vulnerabilities, is 9.3.1.203." When I go to the Adobe download site, however, I can't find anything newer than the version I already have. Is this something I should be worried about?

Okay, so now that I've done this, I just need to reinstall Norton and I am good to go?

Thanks for all of your help!

Blade81
2010-03-15, 09:49
Hi,


1) Should I be making Firefox more secure somehow as well (like I did with the security settings in IE)?
recommended Firefox addons

Adblock Plus (http://adblockplus.org/en/installation), WOT (http://www.mywot.com/en/download/ff) and NoScript (https://addons.mozilla.org/firefox/addon/722)


2) On the bottom of my IE window, it says "Internet | Protected Mode: Off" - is that okay?
Do you have UAC disabled? Protected mode is off if you have UAC disabled or start IE by right clicking its icon and select 'run as administrator'.


3) When I ran Secunia, it shows 1 insecure version: Adobe Reader 9. It says, "The detected version installed on your system is 9.3.0.148, however, the latest patched version released by the vendor, fixing one or more vulnerabilities, is 9.3.1.203." When I go to the Adobe download site, however, I can't find anything newer than the version I already have. Is this something I should be worried about?
It's here (http://www.adobe.com/support/downloads/detail.jsp?ftpID=4640).

sem825
2010-03-15, 23:53
Okay, sorry about that. Thank you! I think I updated everything.

Is there anything else left to do?

Blade81
2010-03-16, 10:28
No, that was all :)

sem825
2010-03-16, 14:09
Thanks again for your help, Blade! You have been such a big help. I cannot thank you enough!

Blade81
2010-03-16, 16:25
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help. :)

Note:If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.