Raymondo
2010-07-09, 20:30
I have just started with Hijack this and have a log I have used many different virus detectors up to today I am not sure if my last attempt has removed them so if someone can check out these logs for me with some advice in reply:bigthumb:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4296
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
10/07/2010 1:21:39 AM
mbam-log-2010-07-10 (01-21-39).txt
Scan type: Quick scan
Objects scanned: 63613
Time elapsed: 4 minute(s), 46 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 11
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 10
Files Infected: 52
Memory Processes Infected:
C:\Program Files\Spyware Cease\SpywareCease.exe (Rogue.SpywareCease) -> Not selected for removal.
Memory Modules Infected:
C:\Program Files\Spyware Cease\md5.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\mtools.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\networkdll.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\opfile.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\QAreaDLL.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RkHitApi.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\sctdll.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\spkdll.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\udefend.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\ussafe.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\zlib1.dll (Rogue.SpywareCease) -> Not selected for removal.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Spyware Cease (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RepairBackup (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RepairBackup\del (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\update (Rogue.SpywareCease) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Cease (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Error Repair Professional (Rogue.ErrorRepairProfessional) -> Not selected for removal.
C:\Program Files\Error Repair Professional\Backups (Rogue.ErrorRepairProfessional) -> Not selected for removal.
C:\Program Files\Error Repair Professional\startbug (Rogue.ErrorRepairProfessional) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner For Vista (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\Program Files\Free Registry Cleaner For Vista (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
Files Infected:
C:\Windows\System32\drivers\RKHit.sys (Rogue.Spywarecease) -> Not selected for removal.
C:\Program Files\Spyware Cease\AutoUpdate.exe (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\bcfile.lst (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\bmgac (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\dxddd (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\fp.fpl (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\hrdb.hrl (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\idamx (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\iflee (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\license.key (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\LSR.lsr (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\md5.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\mtools.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\networkdll.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\opfile.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\QAreaDLL.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\rgp.tmp (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RkHitApi.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\sctdll.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\spkdll.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\SpywareCease.chm (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\SpywareCease.exe (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\SpywareCease.url (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\tmp5 (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\twcfile.lst (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\udefend.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\unins000.dat (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\unins000.exe (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\update1 (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\update2 (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\update3 (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\ussafe.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\vf (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\wcfile.lst (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\xxcum (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\zlib1.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RepairBackup\del.txt (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RepairBackup\removestartup.dat (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RepairBackup\startup.dat (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\update\Update_a.ini (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\update\uplist.up (Rogue.SpywareCease) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Cease\Spyware Cease on the Web.lnk (Rogue.SpywareCease) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Cease\Spyware Cease.lnk (Rogue.SpywareCease) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Cease\Uninstall Spyware Cease.lnk (Rogue.SpywareCease) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner For Vista\Free Registry Cleaner for Vista.lnk (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner For Vista\Uninstall Free Registry Cleaner for Vista.lnk (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\Program Files\Free Registry Cleaner For Vista\backuphkcu.REG (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\Program Files\Free Registry Cleaner For Vista\RegCleanerForVista.exe (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\Program Files\Free Registry Cleaner For Vista\unins000.dat (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\Program Files\Free Registry Cleaner For Vista\unins000.exe (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\Users\hare\AppData\Roaming\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\hare\AppData\Roaming\fvgqad.dat (Malware.Trace) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:28:31 AM, on 10/07/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Program Files\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe
C:\Program Files\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spyware Cease\SpywareCease.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\ctfmon.exe
C:\Downloads\HiJackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\KeePass Password Safe\KeePass.exe
C:\Windows\System32\notepad.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstart
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [PCMAgent] "C:\Program Files\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe"
O4 - HKLM\..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [UVS10 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1670725582-812871076-957031153-1002\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'USER')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk.disabled
O4 - Global Startup: Bluetooth Manager.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://oas.support.microsoft.com/ActiveX/MSDcode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 10333 bytes
==========================
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4296
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
10/07/2010 1:21:39 AM
mbam-log-2010-07-10 (01-21-39).txt
Scan type: Quick scan
Objects scanned: 63613
Time elapsed: 4 minute(s), 46 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 11
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 10
Files Infected: 52
Memory Processes Infected:
C:\Program Files\Spyware Cease\SpywareCease.exe (Rogue.SpywareCease) -> Not selected for removal.
Memory Modules Infected:
C:\Program Files\Spyware Cease\md5.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\mtools.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\networkdll.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\opfile.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\QAreaDLL.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RkHitApi.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\sctdll.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\spkdll.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\udefend.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\ussafe.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\zlib1.dll (Rogue.SpywareCease) -> Not selected for removal.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Spyware Cease (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RepairBackup (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RepairBackup\del (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\update (Rogue.SpywareCease) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Cease (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Error Repair Professional (Rogue.ErrorRepairProfessional) -> Not selected for removal.
C:\Program Files\Error Repair Professional\Backups (Rogue.ErrorRepairProfessional) -> Not selected for removal.
C:\Program Files\Error Repair Professional\startbug (Rogue.ErrorRepairProfessional) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner For Vista (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\Program Files\Free Registry Cleaner For Vista (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
Files Infected:
C:\Windows\System32\drivers\RKHit.sys (Rogue.Spywarecease) -> Not selected for removal.
C:\Program Files\Spyware Cease\AutoUpdate.exe (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\bcfile.lst (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\bmgac (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\dxddd (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\fp.fpl (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\hrdb.hrl (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\idamx (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\iflee (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\license.key (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\LSR.lsr (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\md5.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\mtools.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\networkdll.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\opfile.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\QAreaDLL.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\rgp.tmp (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RkHitApi.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\sctdll.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\spkdll.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\SpywareCease.chm (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\SpywareCease.exe (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\SpywareCease.url (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\tmp5 (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\twcfile.lst (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\udefend.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\unins000.dat (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\unins000.exe (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\update1 (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\update2 (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\update3 (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\ussafe.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\vf (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\wcfile.lst (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\xxcum (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\zlib1.dll (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RepairBackup\del.txt (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RepairBackup\removestartup.dat (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\RepairBackup\startup.dat (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\update\Update_a.ini (Rogue.SpywareCease) -> Not selected for removal.
C:\Program Files\Spyware Cease\update\uplist.up (Rogue.SpywareCease) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Cease\Spyware Cease on the Web.lnk (Rogue.SpywareCease) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Cease\Spyware Cease.lnk (Rogue.SpywareCease) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Cease\Uninstall Spyware Cease.lnk (Rogue.SpywareCease) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner For Vista\Free Registry Cleaner for Vista.lnk (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner For Vista\Uninstall Free Registry Cleaner for Vista.lnk (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\Program Files\Free Registry Cleaner For Vista\backuphkcu.REG (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\Program Files\Free Registry Cleaner For Vista\RegCleanerForVista.exe (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\Program Files\Free Registry Cleaner For Vista\unins000.dat (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\Program Files\Free Registry Cleaner For Vista\unins000.exe (Rogue.FreeRegistryCleanerForVista) -> Not selected for removal.
C:\Users\hare\AppData\Roaming\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\hare\AppData\Roaming\fvgqad.dat (Malware.Trace) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:28:31 AM, on 10/07/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Toshiba\Utilities\KeNotify.exe
C:\Program Files\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe
C:\Program Files\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spyware Cease\SpywareCease.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\ctfmon.exe
C:\Downloads\HiJackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\KeePass Password Safe\KeePass.exe
C:\Windows\System32\notepad.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstart
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [PCMAgent] "C:\Program Files\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe"
O4 - HKLM\..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [UVS10 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1670725582-812871076-957031153-1002\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'USER')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk.disabled
O4 - Global Startup: Bluetooth Manager.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://oas.support.microsoft.com/ActiveX/MSDcode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 10333 bytes
==========================
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)