Page 3 of 7 FirstFirst 1234567 LastLast
Results 21 to 30 of 67

Thread: unable to update Vista or AVG & misdirected when searching

  1. #21
    Join Date
    Aug 2009
    London, UK


    It worked! I'm still unable to connect to the internet, though, so I'll have to investigate that tomorrow.

    Here is the Combofix log:

    ComboFix 09-08-10.06 - Kie 12/08/2009 22:22.1.2 - NTFSx86
    Microsoft~ windows vistam Business 6.0.6000.0.1252.44.1033.18.2046.1376 [GMT 1:00]
    Running from: d:\users\Kie\Desktop\combofix.exe
    AV: F-Secure Anti-Virus 7.30 *on-access scanning disabled* (updated) {E7512ED5-4245-4B4D-AF3A-382D3F313FI5}
    FW: F-secure Internet security 2008 OEM 8.00 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
    SP: AVG Anti-spyware *disabled* (outdated) {48F2E28D-ED66-4646-9C11-B3055BOAF604}
    SP: F-Secure Anti-virus 7.30 *disabled* (updated) {0651C4BO-ID7E-4682-B965-2E9523C483A5}
    SP: windows Defender *enabled* (outdated) {D68DDC3A-831F-4FAE-9E44-DAI32ClACF46}
    * created a new restore point

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

    c:\program files\Antispywareshield
    c:\program files\Antispywareshield\
    c:\programdata\Microsoft\windows\start Menu\programs\Herocodec
    c:\programdata\Microsoft\windows\start Menu\programs\Herocodec\uninstall.lnk
    c:\users\Kie\AppData\Roaming\Microsoft\windows\start Menu\programs\Herocodec c:\windows\Installer\$patchCache$\Managed\6ACA9EFE6506Dc043852EOB02EBC26B2\8.1.0 \html.ini2

    ((((((((((((((((((((((((((((((((((((((( Drivers/services )))))))))))))))))))))))))))))))))))))))))))))))))


    ((((((((((((((((((((((((( Files created from 2009-07-12 to 2009-08-12 )))))))))))))))))))))))))))))))

    2009-08-11 21:52 . 2009-08-03 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-08-11 21:52 . 2009-08-11 21:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-08-11 21:52 . 2009-08-11 21:52 -------- d-----w- c:\programdata\Malwarebytes
    2009-08-11 21:52 . 2009-08-03 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-08-10 14:46 . 2007-06-28 13:36 401720 ----a-w- c:\program files\HijackThis.exe
    2009-08-10 14:37 . 2009-08-10 14:37 -------- d-----w- c:\program files\ERuNT
    2009-08-05 14:27 . 2009-08-05 14:27 -------- d-----w- C:\AVGTemp
    2009-08-05 00:16 . 2009-08-05 00:16 -------- d-----w- c:\users\Kie\AppData\Roaming\AVG8

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    2009-08-12 21:30 . 2007-04-13 20:11 12 ----a-w- c:\windows\bthservsdp.dat
    2009-08-12 15:38 . 2008-11-11 21:39 -------- d-----w- c:\programdata\Google updater
    2009-08-11 15:02 . 2007-11-13 14:39 -------- d-----w- c:\programdata\fssg
    2009-08-11 14:03 . 2008-03-30 15:14 -------- d-----w- c:\programdata\Grisoft
    2009-08-11 12:26 . 2008-07-05 21:06 -------- d-----w- c:\program files\BitLord
    2009-08-10 12:03 . 2008-07-05 21:06 -------- d-----w- c:\program files\TorrentMan
    2009-08-05 14:25 . 2007-12-02 23:04 1356 ----a-w- c:\users\Kie\AppData\Local\d3d9caps.dat
    2009-08-01 11:49 . 2007-04-13 21:53 -------- d-----w- c:\program files\common Files\symantec Shared
    2009-07-02 21:43 . 2007-12-19 01:02 -------- d-----w- c:\users\Kie\AppData\Roaming\dvdcss

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    *Note* empty entries & legit default entries are not shown

    [HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\uR~searchHooks]
    "{24cc1362-11c6-4918-a2cO-bgee5a563185}"= "c:\program files\ArchiBar\tbArcl.dll" [2008-07-06 1569304]


    [HKEY_LOCAL_MACHINE\~\Browser Helper objects\{24cc1362-11c6-4918-a2cO-bgee5a563185}]
    2008-07-06 22:21 1569304 ----a-w- c:\program files\ArchiBar\tbArc1.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {24cc1362-11c6-4918-a2cO-bgee5a563185} "= "c: \program fi1eS\ArchiBar\tbArcl.dll" [2008-07-06 1569304]


    [HKEY_CURRENT_USER\software\Microsoft\Internet Explorer\Toolbar\webbrowser] "{24cC1362-11C6-4918-A2cO-B9EE5A563185}"= "c:\program files\ArchiBar\tbArcl.dll" [2008-07-06 1569304]

    [HKEY_CLASSES_ROOT\clsid\{24cc1362-11c6-4918-a2cO-bgee5a563185}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\windows\currentversion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-11 39408]

    "windows Defender"="c:\program files\windows Defender\MSAScui.exe" [2007-07-04 1006264]
    "HotKeyscmds"="c:\windows\system32\hkcmd.exe" [2007-04-03 154392]
    "persistence"="c:\windows\system32\igfxpers.exe" [2007-04-03 133912]
    "SVPWUTIL"="c: \program fi1es\ TOSHIBA\Uti1itieS\SvPWUTIL. exe" [2006-03-22 438272]
    "topi"="c:\program files\TOSHIBA\Toshiba online Product Information\topi .exe" [2007-04-02 577536]
    "TPwrMain"="c:\program files\TOSHIBA\power saver\TPwrMain.ExE" [2007-03-29 411192]
    "HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
    "smoothview"="c:\program files\Toshiba\smoothview\smoothview.exe" [2007-05-23 509496]
    "OOTcrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
    "desktop SMS"="c:\program files\IDM\oesktop SMS\DesktopSMS.exe" [2007-06-18 1507328J
    "Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2007-02-19 571024]
    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872J
    "IaNvsrv"="c:\program files\Intel\Intel Matrix Storage Manager\OROM\IaNvsrv\IaNvsrv.exe" [2007-03-13 33048]
    "Acronis Scheduler2 service"="c:\pro~ram files\common Files\Acronis\schedule2\schedhlp.exe [2007-08-02 148760]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
    "iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2006-10-30 256576]
    "EEventManager"="c:\program files\EPSON\creativity Suite\Event Manager\EEventManager.exe" [2006-10-12 102400]
    "HP Software update"="c:\program files\HP\HP software update\HPwuschd2.exe" [2007-10-14 49152]
    "hpqsRMon"="c:\program files\HP\Digital Imaging\bin\hpqsRMon.exe" [2007-08-22 80896]
    "Msconfig"="c:\windows\system32\msconfig.exe" [2006-11-02 222208] "RtHDVCpl"="RtHOVcpl.exe" - c:\windows\RtHOVcpl.exe [2007-06-13 4489216]
    "NoSTrax.exe"="NDsTray.exe" [BU] .
    "skytel '="skytel.exe" - c:\windows\skyTel.exe [2007-05-28 1826816]

    c:\users\Kie\AppOata\Roaming\Microsoft\windows\Start Menu\programs\Startup\
    Adobe Gamma.lnk - c:\program files\common Fil~s\Adobe\calibration\Adobe Gamma
    Loader.exe [2005-3-16 113664] .
    Palm Registration.lnk - c:\program files\palm\register.exe [2008-4-23 2494464]

    c:\programdata\Microsoft\windows\start Menu\programs\Startup\
    Dataviz Inc Messenger.lnk - c:\program files\Common Files\Dataviz\ovzIncMsgr.exe [2008-1-3 28672]
    [HKEY_LOCAL~MACHINE\SYSTEM\Currentcontrolset\control\safeBoot\Minimal\winDefend] @="Service"

    Menu^programs^startup^Directrec configuration Tool.lnk]
    path=c:\programdata\Microsoft\windows\start Menu\programs\startup\directrec configuration Tool.lnk
    backup=c:\windows\pss\Directrec configuration Tool.lnk.commonstartup backupExtension=.commonstartup
    [HKLM\~\startupfolder\c:Apr09ramoataAMicrosoftAwindowsAStart MenuAprogramsAStartupAHP Digltal Imaging Monitor.lnk] path=c:\programdata\Microsoft\windows\Start Menu\programs\Startup\HP Digital Imaging Monltor.lnk
    backup=c:\windows\pSS\HP Digital Imaging Monitor.lnk.commonstartup
    backupExtension=.commonStartup .

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\symantecAntivirus]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\symantecFirewall]

    "TCP Query user{B459534A-25B8-4502-A1E9-AA066B2COEC7}c:\\pro!}ram files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bltlord.exe:BitLord "UDP Query user{314B4A72-81E7-4ABF-A411-989B753FDABO}c:\\pro!}ram files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bltlord.exe:BitLord "{6A8COFFE-D351-4FB9-A1B7-5B31DAB73F8F}"= UDP:c:\program files\TOSHlBA\Utilities\TAcSPROP.exe:Accessibility "{3C57c25E-69CD-4976-B76B-477458EDD568}"= TCP:c:\program files\TosHlBA\Utilities\TAcsPROP.exe:Accessibility
    "TCP Query user{573BA530-5E86-4153-9756-AA5E7A80B5C9}d:\\program files\\itunes\\itunes.exe"= Disabled:uDP:d:\program files\itunes\itunes.exe:iTunes
    "UDP Query user{8c996AA2-4C1C-4888-BBE1-E8A3439128EA}d:\\program files\\itunes\\itunes.exe"= Disabled:Tcp:d:\program files\itunes\itunes.exe:iTunes

    [HKLM\-\services\sharedaccess\parameters\firewallpolicy\publicprofile] "EnableFirewall"= 0 (OxO)

    "DFSR-1"= RPort=5722luDP:%SystemRoot%\system32\svchost.exelsvc=DFSR:Allow inbound TCP trafficl

    RO CpllR;Embedded IR Driver;c:\windows\system32\drivers\cpllR.SYS [06/03/2007 15:01 14848]
    RO iaNvStor;lntelCR) Turbo Memory Technology NAND controller;c:\windows\system32\drivers\iaNvStor.sys [13/04/2007 21:52 210432]
    R1 FSES;F-Secure Email scanning Driver;c:\windows\system32\drivers\fses.sys [13/11/2007 15:41 35024]
    R1 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [13/11/2007 15:41 60064]

    [HKEY_LOCAL_MACHlNE\software\microsoft\winG_MULTl_SZ Pml Driver HPz12 Net Driver HPZ12
    hpdevmgmt REG_MULTl_SZ hpqcxs08 hpqddsvc

    Contents of the 'scheduled Tasks' folder

    2009-01-01 c:\windows\Tasks\AppleSoftwareupdate.job
    - c:\program files\Apple Software update\softwareupdate.exe [2006-10-10 17:13]

    2009-08-12 c:\windows\Tasks\Google Software updater.job
    - c:\program files\Google\Common\Google updater\Googleupdaterservice.exe [2008-11-11 21:02]

    2009-08..,12 c:\windows\Tasks\user_Feed_synchronization-{364B15A7-9ABD-47BF-BD4E-c8850BA667FD } .job
    - c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]

    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-HWSetup - \HWSetup.exe

    ------- supplementary Scan -------

    ustart page = hxxp://
    ulnternet settin!}s,proxyoverride = *.local
    IE: E&xport to Mlcrosoft Excel - c:\progra-1\MICROS-1\office12\EXCEL.EXE/3000
    lE: {{C08CAF1D-COA3-40D5-9970-06D067EAC017} -
    LSP: c:\program files\F-Secure Internet security\FSPs\program\FSLSP.DLL
    Trusted Zone:\download.wondowsupdate
    Trusted Zone:\update

    scanning hidden processes scanning hidden autostart entries scanning hidden files ...
    scan completed successfully hidden files:

    --------------------- LOCKED REGISTRY KEYS ---------------------

    @Denied: (A) (users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (5-1-5-20)
    [HKEY_LOCAL_MACHINE\system\controlset001\Control\class\{4D36E96D-E325-11CE-BFC1- 08002BE10318}\0001\Allusersettings]
    @Denied: (A) (users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (5-1-5-20)

    --------------------- DLLS Loaded Under Running Processes ---------------------

    - - - - - - - > 'Explorer.exe'(3568)
    c:\program files\Arcsoft\photoImpression 5\share\pihook.dll

    ------------------------ Other Running Processes -----------------------*

    c:\program files\common Files\Acronis\schedule2\schedu12.exe
    c:\program files\TosHIBA\ConfigFree\CFsvcs.exe
    c:\program files\olympus\DeviceDetector\DM1service.exe
    c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    c:\program files\TOSHIBA\TOSHIBA DVD PLAYER\TNavlSrv.exe
    c:\program files\TOSHIBA\power saver\Toscosrv.exe
    c:\program files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe
    completion time: 2009-08-12 22:40 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-08-12 21:40
    Pre-Run: 40,646,709,248 bytes free
    Post-Run: 46,590,873,600 bytes free

    213 --- E 0 F --- 2009-04-23 21:14

    Here's the new HJT log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 23:30:52, on 12/08/2009
    platform: windows vista (winNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16830)
    Boot mode: Normal

    Running processes:
    c:\program Files\windows defender\MsAscui.exe
    c:\program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    D:\Users\Kie\Desktop\Hi JaCkThis\HijackThi s.exe

    RO - HKCU\software\Microsoft\Internet Explorer\Main,Start page =
    RI - HKLM\software\Microsoft\Internet Explorer\Main,Default_page_uRL
    RI - HKLM\software\Microsoft\Internet Explorer\Main,Default_Search_URL
    RI - HKLM\software\Microsoft\Internet Explorer\Main,search page =
    RO - HKLM\Software\Microsoft\Internet Explorer\Main,start Page =
    RI - HKCU\software\Microsoft\windows\Currentversion\Internet settings,proxyoverride = *.local
    RO - HKCU\software\Microsoft\Internet Explorer\Toolbar,LinksFolderName
    R3 - URLSearchHook: ArchiBar Toolbar - {24ccI362-11c6-49I8-a2cO-bgee5a563185} ¬c:\program Files\ArchiBar\tbArcl.dll
    02 - BHO: txthlpBHO class - {060235DC-6D84-47BD-95D7-A4EF5099A59D} ¬C:\PROGRA~I\TEXTHE~I\READAN~I\TEXTHE~3.DLL
    02 - BHO: ArchiBar TQolbar - {24ccI362-11c6-4918-a2cO-bgee5a563185} - c:\program Files\Archisar\tbArcl.dll
    02 - BHO: IESiteBlocker.NavFilter ¬{3CA2F3I2-6F6E-4B53-A66E-4E65E497C8CO} - c:\program Files\AVG\AVG8\avgssie.dll (file missing)
    02 - BHO: Google Toolbar Helper - {AAS8ED58-01DD-4d9I-8333-CFI0S77473F7} ¬c:\program files\google\googletoolbarl.dll
    02 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} ¬c:\program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
    02 - BHO: EpsonToolBandKicker Class - {E9942IFB-68DD-40FO-B4Ac-a7027CAE2FlA} ¬c:\program Files\EPsON\EPSON web-To-page\EPSON web-To-page.dll
    02 - BHO: HP smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72EI16A856} ¬c:\program Files\HP\Digital Imaging\Smart web printing\hpswp_BHO.dll
    03 - Toolbar: EPSON web-To-page - {EESD279F-081B-4404-994D-C6B60AAEBA6D} ¬c:\program Files\EPSON\EPSON web-To-page\EPsON web-To-page.dll
    03 - Toolbar: ArchiBar Toolbar - {24ccI362-I1c6-49I8-a2cO-bgee5a563185} ¬C:\program Files\ArchiBar\tbArcl.dll
    03 - Toolbar: &Google - {23I8C2BI-4965-11d4-9BI8-009027A5CD4F} - c:\program files\google\googletoolbarl.dl1
    04 - HKLM\ .. \Run: [windows Defender] %programFiles%\windows Defender\MSAscui.exe -hide
    04 - HKLM\ .. \Run: [HotKeyscmds] c:\windows\system32\hkcmd.exe
    04 - HKLM\ .. \Run: [persistence] c:\windows\system32\igfxpers.exe
    04 - HKLM\ .. \Run: [SVPWUTIL] c:\program Files\TosHIBA\Utilities\SvPwuTIL.exe SVPwUTIL
    04 - HKLM\ .. \Run: [topi] c:\program Files\TOSHIBA\Toshiba online Product Information\topi.exe -startup
    04 - HKLM\ .. \Run: [RtHDVCpl] RtHDVcpl.exe
    04 - HKLM\ .. \Run: [TPwrMain] %programFiles%\TOSHIBA\power saver\TPwrMain.ExE
    04 - HKLM\ .. \Run: [HSON] %programFiles%\TOSHIBA\TBS\HSON.exe
    04 - HKLM\ .. \Run: [smoothview] %programFiles%\Toshiba\Smoothview\SmQothview.exe
    04 - HKLM\ .. \Run: [OOTCrdMain] %programFiles%\TOSHIBA\Flashcards\TCrdMain.exe
    04 - HKLM\ .. \Run: [NDSTray.exe] NDSTray.exe
    04 - HKLM\ .. \Run: [Desktop SMS] c:\program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
    04 - HKLM\ .. \Run: [Toshiba Registration] c:\program Files\Toshiba\Registration\ToshibaRegistration.exe
    04 - HKLM\ .. \Run: [IAAnotif] c:\program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    04 - HKLM\ .. \Run: [IaNvSrv] c:\program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvsrv.exe
    04 - HKLM\ .. \Run: [Acronis scheduler2 service] "c:\program Files\common Files\Acronis\Schedule2\schedhlp.exe"
    04 - HKLM\ .. \Run: [QuickTime Task] "e:\program Files\QuickTime\qnask.exe" -atboottime
    04 - HKLM\ .. \Run: [iTunesHelper] "D:\program Files\iTunes\iTunesHelper.exe"
    04 - HKLM\ .. \Run: [EEventManager] C:\Program Files\EPsON\Creativity Suite\Event Manager\EEventManager.exe
    04 - HKLM\ .. \Run: lHP software update] c:\program Files\HP\HP Software update\HPwuschd2.exe
    04 - HKLM\ .. \Run: [hpqsRMon] c:\program Files\HP\Digital Imaging\bin\hpqsRMon.exe
    04 - HKLM\ .. \Run: [skytel] skr,tel.exe
    04 - HKLM\ .. \Run: [Msconfi g] 'e: \wi ndows\system32\msconfi g. exe" jauto
    04 - HKCU\ .. \Run: [swg] c:\program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    04 - startup: Adobe Gamma.lnk = c:\program Files\common Files\Adobe\calibration\Adobe Gamma Loader.exe
    04 - Startup: palm Registration.lnk = c:\program Files\palm\register.exe
    04 - Global startup: Dataviz Inc Messenger.lnk = c:\program Files\common Files\Dataviz\DvzIncMsgr.exe
    08 - Extra context menu item: E&xport to Microsoft Excel ¬res:jjC:\PROGRA~1\MICROS~1\office12\EXcEL.ExEj3000
    09 - Extra button: Research - {92780B25-18CC-41c8-B9BE-3C9C57IA8263} ¬C:\PROGRA-1\MICROS-1\office12\REFIEBAR.DLL
    09 - Extra button: eBay - {C08CAF1D-COA3-40D5-9970-06D067EAC017} ¬ (file missing)
    09 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} ¬c:\program Files\HP\Digital Imaging\Smart web printin~\hpswp_BHO.dll
    010 - Broken Internet access because of LSP provider c:\program files\f-secure internet security\fsps\program\fslsp.dll' missing
    013 - Gopher Prefix:
    018 - protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} ¬c:\program Files\AVG\AVG8\avgpp.dll (file missing)
    023 - Service: Acronis Scheduler2 Service (AcrSch2svc) - Acronis - c:\program Files\common Files\Acronis\schedule2\schedu12.exe
    023 - Service: Adobe LM Service - Adobe Systems - c:\program Files\common Files\Adobe systems shared\Service\Adobelmsvc.exe
    023 - service: Ati External Event utility - ATI Technologies Inc. ¬c:\windows\system32\Ati2evxx.exe
    023 - Service: Autodesk Licensing Service - Autodesk - c:\program Files\common Files\Autodesk shared\service\Adskscsrv.exe
    023 - service: configFree service (CFSVCS) - TOSHIBA CORPORATION - c:\program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    023 - service: DM1Service - OLYMPUS IMAGING CORP. - c:\program Files\01ympus\DeviceDetector\DM1Service.exe
    023 - Service: Google software updater (gusvc) ~ Goo9le - c:\program Files\Google\common\Google updater\GoogleupdaterServlce.exe
    023 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel corporation - c:\program Files\Intel\Intel Matrix storage Manager\IAANTMon.exe 023 - Service: InstallDriver Table Manager (IDriverT) - Macrovlsion corporation - c:\program Files\common Files\Installshield\Driver\ll\Intel 32\IDriverT.exe 023 - service: Installshield Licensing service - Macrovision
    - c:\program Files\Common Files\Installshield shared\service\InstallShield Licensing service.exe
    023 - service: iPod Service - Apple computer, Inc. - c:\program Files\ipod\bin\ipodservice.exe
    023 - service: symantec core LC - Symantec corporation - c:\program Files\common Files\symantec shared\cCPD-Lc\symlcsvc.exe
    023 - Service: TOSHIBA Navi Support service (TNavisrv) - TOSHIBA corporation ¬c:\program Files\TosHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
    023 - Service: TOSHIBA optical Disc Drive Service (TODDSrv) - TOSHIBA corporation - c:\windows\system32\TODDsrv.exe
    023 - Service: TOSHIBA power Saver CTosCoSrv) - TOSHIBA Corporation - c:\program Files\TosHIBA\power saver\Toscosrv.exe
    023 - Service: TOSHIBA Bluetooth service - TOSHIBA CORPORATION - c:\program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
    023 - service: SecuROM User Access Service CV7) (userAccess7) - unknown owner ¬c:\windows\system32\uAservice7.exe
    End of file - 7919 bytes

    I'm really grateful for your continuing help, Phil. Thanks.


  2. #22
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005


    rosieb, thank you for your PM.

    A helper will continue with your topic soon.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  3. #23
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Florida's SpaceCoast


    Hello rosieb,

    My name is Ken and I will be taking over for Phil.

    You should be able to run Malwarebytes now and this cleaner as Combofix removed the Rootkit that was causing all your issues, but there could be more we cant see.

    Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean

    Drag Malwarebytes to the trash and lets start over nice an clean

    Please download Malwarebytes' Anti-Malware from Here or Here

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected .
    • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
    • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
    Post the report and also a new HJT log please
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  4. #24
    Join Date
    Aug 2009
    London, UK


    Thanks for your help, Ken.

    I've used the TFC but I can't connect to the internet on the infected laptop and I can't work out why not - so I can't download MBAM. I could burn it to a CD on a clean laptop but it wouldn't be able to update.

    What should I do?


  5. #25
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Florida's SpaceCoast


    Hello Rosie

    When you download MBAM it will be fairly current so go ahead and burn it to a CD and transfer it to the infected one.

    Are you trying to get online with Internet Explorer? What exactly happens when you open your browser, are you getting a page not found?

    Try this, open IE and go to Tools> Internet Options> Advanced Tab > Reset Internet Explorer Settings > Reset.....let it do its thing..takes about 15 seconds, then ok your way out , close IE then open it again and see if you can get online.

    You may also have to reset your modem Cable/DSL and router if your using one. Just turn off your computer, pull the power cord to both the modem and router....let this set like this for about 3 minutes. Plug the power cord back into both the router and modem, wait until all the lights are on, then start your computer and wait until it fully loads, then try the internet again.
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  6. #26
    Join Date
    Aug 2009
    London, UK


    Hi Ken. The TFC is still going on the infected laptop. That's over an hour so far. Has it hung up, do you think? It seems stuck on the Recycle Bin.
    How long should I let it run?


  7. #27
    Join Date
    Aug 2009
    London, UK


    Hello Ken
    I tried the IE resets you suggested - to no avail. The lap top connects to the LAN but I cannot access any web pages. Could it be something to do with the F-secure firewall? I thought I'd removed all the AV programs prior to installing just a single program but there seem to be remnants remaining, although not showing in Add/Remove programs.

    Anyway, here are the logs you requested (I printed them and scanned them to my clean laptop):

    Malwarebytes' Anti-Malware 1.40
    Database version: 2551
    windows 6.0.6000

    14/08/2009 21:28:56
    mbam-log-2009-08-14 (21-28-56).txt

    Scan type: Full Scan
    (C:\ID:\I) objects scanned: 233755
    Time elapsed: 49 minute(s), 54 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 3
    Files Infected: 7

    Memory processes Infected:
    (NO malicious items detected)

    Memory Modules Infected:
    (NO malicious items detected)

    Registry Keys Infected:
    (NO malicious items detected)

    Registry values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\windows\currentversion\Run\desktop sms (worm.p2P) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (NO malicious items detected)

    Folders Infected:
    c:\Program Files\Malwarecore 7.4 (Rogue.Malwarecore) -> Quarantined and deleted successfully.
    c:\program Files\Malwarecore 7.4\Quarantine (Rogue.Malwarecore) -> Quarantined and deleted successfully.
    c:\users\Kie\AppData\Roaming\Microsoft\windows\start Menu\programs\Malwarecore 7.4 (Rogue.Malwarecore) -> Quarantined and deleted successfully.

    Files Infected:
    c:\programData\malusasu\malusasu.dll (Trojan.vundo) -> Quarantined and deleted successfully.
    C:\ProgramData\yivivaso\yivivaso.dll (Trojan.vundo) -> Quarantined and deleted successfully.
    c:\Qoobox\Quarantine\c\windows\system32\gxvxcqxiaydlsjadmlutkwdkbigbrvjleolnm.dl l.vir (Trojan.Agent) -> Quarantined and deleted successfully.
    c:\users\Kle\AppData\Local\virtualstore\windows\system32\prnet.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
    c:\users\Kie\AppData\Local\virtualstore\windows\system32\rn.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
    c:\program Files\Malwarecore 7.4\Malwarecore 7.4.url (Rogue.Malwarecore) -> Quarantined and deleted successfully.
    c:\program Files\Malwarecore 7.4\mwdb.dat (Rogue.Malwarecore) -> Quarantined and deleted successfully.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:58:14, on 14/08/2009
    Platform: windows Vista (winNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16830)
    Boot mode: Normal

    Running processes: c:\windows\system32\Dwm.exe
    c:\program Files\windows Defender\MSAscui.exe
    c:\program Files\TOSHIBA\Toshiba online product Information\TOPI.exe
    c:\program Files\TosHIBA\power saver\TPwrMain.exe
    C:\program Files\TOSHIBA\smoothview\smoothview.exe
    c:\program Files\TOSHIBA\Flashcards\TcrdMain.exe
    c:\program Files\TosHIBA\ConfigFree\NDSTray.exe
    c:\program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    c:\Program Files\Common Files\Acronis\Schedule2\schedhlp,exe
    c:\program Files\QuickTime\qttask.exe
    D:\program Files\iTunes\iTunesHelper.exe
    c:\program Files\epson\creativity Suite\Event Manager\EEventManager.exe
    C:\program Files\HP\HP Software update\hpwuschd2.exe
    c:\program Files\HP\Digital Imaging\bin\HpqsRmon.exe
    C:\program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\program Files\TOsHIBA\configFree\cFswMgr.exe

    RI - HKCU\software\Microsoft\Internet Explorer\Main,search Page =
    RO - HKCU\software\Microsoft\Internet Explorer\Main,Start Page =
    RI - HKLM\software\Microsoft\Internet Explorer\Main,Default_pag~uRL
    RI - HKLM\software\Microsoft\Internet Explorer\Main,Default_search_uRL
    RI - HKLM\software\Microsoft\Internet Explorer\Main,search Page =
    RO - HKLM\software\Microsoft\Internet Explorer\Main,start page =
    RO - HKLM\software\Microsoft\Internet Explorer\search,searchAssistant =
    RO - HKLM\software\Microsoft\Internet Explorer\search,customize~earch =
    RI - HKCU\software\Microsoft\windows\currentversion\Internet settings,proxyoverride = *.local
    RO - HKCU\software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    02 - BHO: txthlpBHO Class - {060235DC-6D84-47BD-95D7-A4EF5099A59D} *C:\PROGRA-I\TEXTHE-I\READAN-I\TEXTHE-3.DLL
    02 - BHO: ArchiBar Toolbar - {24ccI362-11c6-4918-a2cO-bgee5a563185} - c:\program Files\ArchiBar\tbArcl.dll
    02 - BHO: IESiteBlocker.NavFilter *{3CA2F312-6F6E-4B53-A66E-4E65E497C8CO} - c:\program Files\AVG\AVG8\avgssie.dll (file missing)
    02 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CFI0577473F7} *c:\program files\google\googletoolbarl.dll
    02 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} *C:\program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
    02 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40FO-B4AC-B7027CAE2FlA} *c:\program Files\EPSON\EPSON web-To-Page\EPsoN web-To-page.dll
    02 - BHO: HP Smart BHO class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72EI16A856} *c:\program Files\HP\Digital Imaging\Smart web printing\hpswp_BHO.dll
    03 - Toolbar: EPSON web-To-page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} *c:\program Files\EPSON\EPSON web-To-page\EPSON web-To-page.dll
    03 - Toolbar: ArchiBar Toolbar - {24ccI362-11c6-4918-a2cO-bgee5a563185} *c:\program Files\ArchiBar\tbArcl.dll
    03 - Toolbar: &Google - {2318C2BI-4965-11d4-9BI8-009027A5CD4F} - c:\program files\google\googletoolbarl.dll
    04 - HKLM\ .. \Run: [windows Defender] %programFiles%\windows Defender\MSAscui.exe -hide
    04 - HKLM\ .. \Run: [HotKeyscmds] C:\windows\system32\hkcmd.exe
    04 - HKLM\ .. \Run: [persistence] c:\windows\system32\igfxpers.exe
    04 - HKLM\ .. \Run: [SVPWUTIL] c:\program Files\TOSHIBA\Utilities\svPwuTIL.exe SVPwUTIL
    04 - HKLM\ .. \Run: [topi] c:\program Files\TOSHIBA\Toshiba online Product Information\topi.exe -startup
    04 - HKLM\ .. \Run: [RtHDVCpl] RtHDVcpl.exe
    04 - HKLM\ .. \Run: [TPwrMain] %programFiles%\TOSHIBA\power saver\TPwrMain.EXE
    04 - HKLM\ .. \Run: [HSON] %programFiles%\TOSHIBA\TBS\HSON.exe
    04 - HKLM\ .. \Run: [smoothviewJ %programFiles%\Toshiba\smoothview\smoothview.exe
    04 - HKLM\ .. \Run: [00TcrdMain] %programFiles%\TOSHIBA\Flashcards\TcrdMain.exe
    04 - HKLM\ .. \Run: [NDSTray.exe] NDsTray.exe
    04 - HKLM\ .. \Run: [Toshiba Registration] c:\program Files\Toshiba\Registration\ToshibaRegistration.exe
    04 ~ HKLM\ .. \Run: [IAAnotif] c:\Program Files\Intel\Intel Matrix storage Manager\iaanotif.exe
    04 - HKLM\ .. \Run: [IaNvSrv] C:\program Fi1es\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvsrv.exe
    04 - HKLM\ .. \Run: [Acronis scheduler2 service] "c:\program Files\Common Files\Acronis\schedule2\schedhlp.exe"
    04 - HKLM\ .. \Run: [QuickTime Task] "c:\program Files\QuickTime\qttask.exe" -atboottime
    04 - HKLM\ .. \Run: [iTunesHelper] "D:\program Files\iTunes\iTunesHelper.exe"
    04 - HKLM\ .. \Run: [EEventManager] c:\program Files\EPSON\creativity Suite\Event Manager\EEventManager.exe
    04 - HKLM\ .. \Run: [HP software update] c:\program Files\HP\HP software update\HPWuschd2.exe
    04 - HKLM\ .. \Run: [hpqsRMon] c:\program Files\HP\Digital Imaging\bin\hpqsRMon.exe
    04 - HKLM\ .. \Run: [skytel] skytel.exe
    04 - HKLM\ .. \Runonce: [Malwarebytes' Anti-Malware] c:\program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    04 - HKCU\ .. \Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    04 - startup: Adobe Gamma.lnk = c:\program Files\common Files\Adobe\calibration\Adobe Gamma Loader.exe
    04 - startup: palm Registration.lnk = c:\program Files\palm\register.exe
    04 - Global startup: Dataviz Inc Messenger.lnk = c:\program Files\common Files\Dataviz\DvzlncMsgr.exe
    09 - Extra button: Research - {92780B25-18CC-41C8-B96E-3C9C571A8263} *C:\PROGRA~1\MICROS~1\Offi~e12\REFIEBAR.DLL
    09 - Extra button: eBay - {C08CAF1D-COA3-40D5-9970-06D067EAC017} * (file missing)
    09 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} *c:\program Files\HP\Digital Imaging\smart web printin~\hpswp_BHO.dll
    010 - Broken Internet access because of LSP provider c:\program files\f-secure internet security\fsps\program\fslsp.dll' missing
    013 - Gopher prefix:
    018 - protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} *c:\program Files\AVG\AVG8\avgpp.dll (file missing)
    023 - Service: Acronis scheduler2 Service (Acrsch2Svc) - Acronis - c:\program Files\common Files\Acronis\schedule2\schedu12.exe
    023 - Service: Adobe LM Service - Adobe Systems - c:\program Files\common Files\Adobe Systems shared\service\Adobelmsvc.exe
    023 - service: Ati External Event utility - ATI Technologies Inc. *c:\windows\system32\Ati2evxx.exe
    023 - Service: Autodesk Licensing Service - Autodesk - C:\program Files\common Files\Autodesk shared\service\Adskscsrv.exe
    023 - service: configFree Service (CFSvcs) - TOSHIBA CORPORATION - c:\program Files\TOSHIBA\configFree\CFsvcs.exe
    023 - service: DM1service - OLYMPUS IMAGING CORP. - c:\program Files\01ympus\DeviceDetector\DM1service.exe
    023 - Service: Google software updater (gusvc) - Google - c:\program Files\Google\common\Google updater\GoogleupdaterServlce.exe
    023 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel corporation - c:\program Files\Intel\Intel Matrix storage Manager\IAANTMon.exe 023 - Service: InstallDriver Table Manager (IDriverT) - Macrovlsion corporation - c:\program Files\Cqmmon Files\Installshield\oriver\11\Intel 32\IoriverT.exe
    023 - Service: Installshield Licensing Service - Macrovision - c:\program Files\common Files\Installshield shared\service\InstallShield Licensing Service.exe
    023 - service: ipod service - Apple Computer, Inc. - c:\program Files\iPod\bin\ipodservice.exe
    023 - Service: symantec Core LC - symantec corporation - C:\program Files\Common Files\symantec shared\ccPo-Lc\symlcsvc.exe
    023 - service: TOSHIBA Navi Support service (TNavisrv) - TOSHIBA corporation *C:\program Files\TosHIBA\TOSHIBA OVD PLAYER\TNaviSrv.exe
    023 - service: TOSHIBA optical Disc Drive service (ToDOsrv) - TOSHIBA Corporation - C:\windows\system32\TODDsrv.exe
    023 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA corporation - c:\program Files\TOSHIBA\power Saver\ToscoSrv.exe
    023 - service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
    023 - service: SecUROM User Access Service (V7) (userAccess7) - Unknown owner *c:\windows\system32\UAserv;ce7.exe
    End of file - 8628 bytes

    Thanks for all your help,

  8. #28
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Florida's SpaceCoast


    Hello Rosie,

    Sometimes TFC will hang if it removes a log of garbage, not to worry , it looks like your up and running.

    Not sure if no internet is related to a malicious program, when your all clean that will tell us. Have you tried calling your ISP and telling them you cant get online??

    Lets make sure there is no part of that rootkit left. This to you can transfer by disk

    1. Download RootRepeal from the following location and save it to your desktop.
    2. Extract RootRepeal.exe from the archive.
    3. Open on your desktop.
    4. Click the tab.
    5. Click the button.
    6. Check all seven boxes:
    7. Push Ok
    8. Check the box for your main system drive (Usually C, and press Ok.
    9. Allow RootRepeal to run a scan of your system. This may take some time.
    10. Once the scan completes, push the button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  9. #29
    Join Date
    Aug 2009
    London, UK


    Hello Ken

    When I try to run RootRepeal, I get an error: FOPS - DeviceIoControl Error! Error Code = 0xc0000024 Extended Info (0x000000d8)

    Should I try a different download?


  10. #30
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Florida's SpaceCoast


    Yes, please do, just drag the one you are having problems with to the trash. There are 3 links for zip and 3 for rar, if your using zip, then try all three.

    If that doesn't work than try this one.

    Please download Rooter Rootkit Detector to your Desktop
    • Doubleclick it to start the tool.
    • A Notepad file containing the report will open, also found at %systemdrive% (usually C:\Rooter.txt.
    • Post the report for me to see.
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts