Page 2 of 4 FirstFirst 1234 LastLast
Results 11 to 20 of 32

Thread: host errors, HJT errors

  1. #11
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Seems that I posted without seeing your response first


    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    http://forums.spybot.info/showthread.php?t=55859
    Collect::
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\delfile.drv
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\kernel32.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\snl2w.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\std.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\delfile.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\dudl.exe
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\pal.sys
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\PE.exe
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\eb.sys
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\CLSV.exe
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\hymt.sys
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\fix.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\sld.drv
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\hymt.exe
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\cb.exe
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.sys
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\energy.sys
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv
    Folder::
    c:\programdata\3fa8f
    c:\programdata\SABRV
    C:\cd65301

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log.


    Uninstall old Adobe Reader versions and get the latest one (9.3 + update 9.3.1) here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here.


    Check here to see if your Flash is up-to-date (do it separately with each of your browsers). If not, uninstall vulnerable versions by following instructions here. Fresh version can be obtained here.



    Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

    Double-click ATF Cleaner.exe to open it

    Under Main choose:
    Windows Temp
    Current User Temp
    All Users Temp
    Cookies
    Temporary Internet Files
    Java Cache

    *The other boxes are optional*
    Then click the Empty Selected button.

    If you use Firefox:
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    If you use Opera:
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    Click Exit on the Main menu to close the program.


    Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here.


    Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  2. #12
    Junior Member
    Join Date
    Feb 2010
    Posts
    26

    Default

    Hi,

    Sorry if you missed it, but I did run it again, and it worked. I posted the ComboFix log above (along with a new DDS log). Please let me know if you need any other information from me.

    Thanks!

  3. #13
    Junior Member
    Join Date
    Feb 2010
    Posts
    26

    Default

    No problem

    Will do!

    Thanks for all of your help!

  4. #14
    Junior Member
    Join Date
    Feb 2010
    Posts
    26

    Default

    Hi Blade81,

    I am posting 4 logs from scans I ran tonight: ComboFix, Kaspersky Online Scanner, and 2 dds logs.

    COMBOFIX:


    ComboFix 10-03-09.04 - Owner 03/09/2010 20:55:45.4.2 - x86
    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1993 [GMT -5:00]
    Running from: c:\users\Owner\Desktop\ComboFix.exe
    Command switches used :: c:\users\Owner\Desktop\CFScript.txt
    SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\cd65301
    c:\cd65301\BackUp\McAfee Security Scan Plus.lnk
    c:\cd65301\mozcrt19.dll
    c:\cd65301\SAV.ico
    c:\cd65301\SAVSys\vd952342.bd
    c:\cd65301\sqlite3.dll
    c:\programdata\3fa8f
    c:\programdata\3fa8f\SAV.ico
    c:\programdata\SABRV
    c:\programdata\SABRV\SAKZV.cfg
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\cb.exe
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\CLSV.exe
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\delfile.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\delfile.drv
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\dudl.exe
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\eb.sys
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\energy.drv
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\energy.sys
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\fix.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\hymt.exe
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\hymt.sys
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\kernel32.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\pal.sys
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\PE.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\PE.exe
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.drv
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.sys
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\sld.drv
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\snl2w.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\std.dll
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\tjd.drv
    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Recent\tjd.sys

    .
    ((((((((((((((((((((((((( Files Created from 2010-02-10 to 2010-03-10 )))))))))))))))))))))))))))))))
    .

    2010-03-10 01:59 . 2010-03-10 02:00 -------- d-----w- c:\users\Owner\AppData\Local\temp
    2010-03-10 01:59 . 2010-03-10 01:59 -------- d-----w- c:\users\Public\AppData\Local\temp
    2010-03-10 01:59 . 2010-03-10 01:59 -------- d-----w- c:\users\Default\AppData\Local\temp
    2010-03-10 01:59 . 2010-03-10 01:59 -------- d-----w- c:\users\Administrator\AppData\Local\temp
    2010-03-10 01:54 . 2010-03-10 01:54 -------- d-----w- C:\32788R22FWJFW
    2010-02-24 14:00 . 2009-12-13 09:30 641536 ----a-w- c:\windows\system32\CPFilters.dll
    2010-02-24 14:00 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
    2010-02-24 14:00 . 2009-12-13 09:29 417792 ----a-w- c:\windows\system32\msdri.dll
    2010-02-24 14:00 . 2010-02-02 07:45 2048 ----a-w- c:\windows\system32\tzres.dll
    2010-02-19 02:35 . 2010-02-19 02:35 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
    2010-02-15 05:07 . 2010-02-15 05:07 388096 ----a-r- c:\users\Owner\AppData\Roaming\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
    2010-02-15 05:07 . 2010-02-15 05:07 -------- d-----w- c:\program files\TrendMicro
    2010-02-15 05:00 . 2010-02-15 05:00 -------- d-----w- c:\program files\ERUNT
    2010-02-11 22:16 . 2010-02-13 05:35 -------- d-----w- c:\programdata\Lavasoft
    2010-02-11 20:28 . 2010-02-15 04:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-02-11 20:28 . 2010-02-11 22:17 -------- d-----w- c:\programdata\Spybot - Search & Destroy
    2010-02-11 19:52 . 2010-02-11 19:52 103050 ----a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{2D3A6BBC-41F4-1F50-18CC-9A77DAEA1AB8}-uninst.exe
    2010-02-11 17:03 . 2010-02-11 17:03 -------- d-----r- c:\program files\Norton Support
    2010-02-11 15:52 . 2010-02-11 15:52 -------- d-----w- c:\users\Owner\AppData\Local\Deployment
    2010-02-11 15:52 . 2010-02-11 15:52 -------- d-----w- c:\users\Owner\AppData\Local\Apps
    2010-02-10 20:36 . 2010-02-10 20:36 -------- d-----w- c:\program files\Common Files\Java
    2010-02-10 20:35 . 2009-12-17 22:14 411368 ----a-w- c:\windows\system32\deploytk.dll
    2010-02-10 19:01 . 2010-02-11 19:52 -------- d-----w- c:\programdata\RegCure
    2010-02-10 12:54 . 2010-02-10 19:51 -------- d-----w- c:\users\Owner\AppData\Local\Diagnostics
    2010-02-10 12:46 . 2010-02-10 12:45 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
    2010-02-10 12:46 . 2010-02-10 12:45 107368 ----a-r- c:\windows\system32\GEARAspi.dll
    2010-02-10 12:45 . 2010-03-08 02:23 -------- d-----w- c:\program files\Symantec
    2010-02-10 12:44 . 2010-02-10 19:55 -------- d-----w- c:\windows\system32\drivers\N360
    2010-02-10 12:42 . 2010-02-10 12:42 -------- d-----w- c:\programdata\PCSettings
    2010-02-09 17:48 . 2010-02-09 17:51 38434288 ----a-w- c:\programdata\Toshiba\TSS\Plugins\SwUpdates\Packages\4d92cef8-7ed7-402d-aa91-6eda708f6bb8\171515_14.32.13.TC00143300K.exe
    2010-02-09 06:32 . 2010-02-09 06:32 -------- d-----w- c:\programdata\McAfee

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-02-24 14:16 . 2009-12-30 20:03 181632 ------w- c:\windows\system32\MpSigStub.exe
    2010-02-20 18:34 . 2009-09-02 05:46 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-02-19 02:40 . 2009-12-14 23:17 -------- d-----w- c:\programdata\Microsoft Help
    2010-02-19 02:39 . 2009-12-14 23:08 -------- d-----w- c:\program files\Microsoft Works
    2010-02-10 20:35 . 2009-09-02 05:29 -------- d-----w- c:\program files\Java
    2010-02-10 12:44 . 2009-12-14 23:49 -------- d-----w- c:\programdata\Norton
    2010-02-10 12:42 . 2009-12-14 23:49 -------- d-----w- c:\programdata\NortonInstaller
    2010-01-24 18:26 . 2010-01-02 03:35 1670624 ----a-w- c:\programdata\WildTangent\TOSHIBA Game Console\Downloads\en-us\Installers\SetupGamesClient.exe
    2010-01-23 03:07 . 2009-09-02 05:47 -------- d-----w- c:\programdata\Partner
    2010-01-18 23:29 . 2010-02-10 03:54 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
    2010-01-18 23:29 . 2010-02-10 03:54 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
    2010-01-18 23:29 . 2010-02-10 03:54 365568 ----a-w- c:\windows\system32\secproc_isv.dll
    2010-01-18 23:29 . 2010-02-10 03:54 369152 ----a-w- c:\windows\system32\secproc.dll
    2010-01-18 23:28 . 2010-02-10 03:54 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
    2010-01-18 23:28 . 2010-02-10 03:54 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
    2010-01-18 23:28 . 2010-02-10 03:54 320512 ----a-w- c:\windows\system32\RMActivate.exe
    2010-01-18 23:28 . 2010-02-10 03:54 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
    2010-01-08 03:18 . 2010-02-10 03:54 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
    2010-01-08 03:17 . 2010-02-10 03:54 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2010-01-03 07:42 . 2010-01-03 07:42 79367 ----a-w- c:\users\Owner\AppData\Roaming\Google\Google Talk\uninstall.exe
    2009-12-30 20:01 . 2009-12-30 20:01 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbBA5B.tmp.exe
    2009-12-30 19:41 . 2009-12-30 19:41 79136 ----a-w- c:\users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
    2009-12-30 19:39 . 2009-12-30 19:39 13 --sh--r- c:\windows\system32\drivers\fbd.sys
    2009-12-19 09:02 . 2010-01-22 03:55 977920 ----a-w- c:\windows\system32\wininet.dll
    2009-12-19 09:02 . 2010-02-10 03:54 12288 ----a-w- c:\windows\system32\tsbyuv.dll
    2009-12-19 09:02 . 2010-02-10 03:54 1328640 ----a-w- c:\windows\system32\quartz.dll
    2009-12-19 09:02 . 2010-02-10 03:54 22016 ----a-w- c:\windows\system32\msyuv.dll
    2009-12-19 09:02 . 2010-02-10 03:54 31744 ----a-w- c:\windows\system32\msvidc32.dll
    2009-12-19 09:02 . 2010-02-10 03:54 13312 ----a-w- c:\windows\system32\msrle32.dll
    2009-12-19 09:02 . 2010-02-10 03:54 84480 ----a-w- c:\windows\system32\mciavi32.dll
    2009-12-19 09:02 . 2010-02-10 03:54 50176 ----a-w- c:\windows\system32\iyuv_32.dll
    2009-12-19 09:02 . 2010-02-10 03:54 91648 ----a-w- c:\windows\system32\avifil32.dll
    2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
    2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
    .

    ((((((((((((((((((((((((((((( SnapShot@2010-03-09_14.23.58 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-07-14 04:55 . 2010-03-10 01:49 50800 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
    - 2009-12-30 22:36 . 2010-03-09 00:20 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-12-30 22:36 . 2010-03-10 01:49 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-12-30 22:36 . 2010-03-09 00:20 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-12-30 22:36 . 2010-03-10 01:49 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-07-14 04:41 . 2010-03-09 00:20 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-07-14 04:41 . 2010-03-10 01:49 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-12-30 19:40 . 2010-03-09 14:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-12-30 19:40 . 2010-03-10 01:53 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-12-30 19:40 . 2010-03-10 01:53 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-12-30 19:40 . 2010-03-09 14:14 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-12-30 19:40 . 2010-03-09 14:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-12-30 19:40 . 2010-03-10 01:53 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-12-30 19:40 . 2010-03-10 01:49 7562 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3957342637-2223780103-148138915-1000_UserData.bin
    - 2010-03-08 02:25 . 2010-03-09 00:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2010-03-10 01:47 . 2010-03-10 01:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2010-03-08 02:25 . 2010-03-09 00:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2010-03-10 01:47 . 2010-03-10 01:47 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MyTOSHIBA"="c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe" [2009-08-06 264048]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-02 39408]
    "googletalk"="c:\users\Owner\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
    "Google Update"="c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-02-11 135664]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-30 98304]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-29 7625248]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-21 1545512]
    "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-08-21 476512]
    "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-07-28 460088]
    "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2009-08-05 738616]
    "ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-08-17 1294136]
    "TosWaitSrv"="c:\program files\TOSHIBA\TPHM\TosWaitSrv.exe" [2009-08-07 611672]
    "Teco"="c:\program files\TOSHIBA\TECO\Teco.exe" [2009-08-12 1324384]
    "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 611672]
    "NortonOnlineBackupReminder"="c:\program files\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" [2009-07-16 529256]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorUser"= 2 (0x2)
    "EnableUIADesktopToggle"= 0 (0x0)

    R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
    R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-30 176128]
    S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [2009-08-11 185712]
    S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448]
    S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
    S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-08-12 185712]
    S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [2009-06-20 12920]
    S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2009-07-07 7680]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-31 187392]
    S3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512]
    S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-04 111960]
    S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-07 685424]


    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}]
    2009-08-06 16:15 264048 ----a-w- c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe
    .
    Contents of the 'Scheduled Tasks' folder

    2010-03-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3957342637-2223780103-148138915-1000Core.job
    - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-11 15:52]

    2010-03-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3957342637-2223780103-148138915-1000UA.job
    - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-11 15:52]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
    FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\xmmpllk7.default\
    FF - prefs.js: browser.startup.homepage - www.google.com

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2010-03-09 21:01:22
    ComboFix-quarantined-files.txt 2010-03-10 02:01
    ComboFix2.txt 2010-03-09 14:35
    ComboFix3.txt 2010-03-09 14:25

    Pre-Run: 277,043,724,288 bytes free
    Post-Run: 277,000,564,736 bytes free

    - - End Of File - - 6F34DF47C285B9FB7F912A41C1B98050

    KASPERSKY ONLINE SCANNER:

    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0: scan report
    Tuesday, March 9, 2010
    Operating system: Microsoft Home Edition (build 7600)
    Kaspersky Online Scanner version: 7.0.26.13
    Last database update: Tuesday, March 09, 2010 23:07:57
    Records in database: 3751592
    --------------------------------------------------------------------------------

    Scan settings:
    scan using the following database: extended
    Scan archives: yes
    Scan e-mail databases: yes

    Scan area - My Computer:
    C:\
    D:\

    Scan statistics:
    Objects scanned: 85262
    Threats found: 0
    Infected objects found: 0
    Suspicious objects found: 0
    Scan duration: 01:15:24

    No threats found. Scanned area is clean.

    Selected area has been scanned.

    DDS LOG:



    DDS (Ver_09-09-29.01) - NTFSx86
    Run by Owner at 23:34:50.18 on Tue 03/09/2010
    Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1282 [GMT -5:00]

    SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

    ============== Running Processes ===============

    C:\windows\system32\wininit.exe
    C:\windows\system32\lsm.exe
    C:\windows\system32\svchost.exe -k DcomLaunch
    C:\windows\system32\svchost.exe -k RPCSS
    C:\windows\system32\atiesrxx.exe
    C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\windows\system32\svchost.exe -k netsvcs
    C:\windows\system32\svchost.exe -k LocalService
    C:\windows\system32\svchost.exe -k NetworkService
    C:\windows\system32\atieclxx.exe
    C:\windows\System32\spoolsv.exe
    C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\windows\system32\svchost.exe -k imgsvc
    C:\Windows\system32\TODDSrv.exe
    C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
    C:\Program Files\TOSHIBA\TECO\TecoService.exe
    C:\windows\system32\SearchIndexer.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\windows\system32\Dwm.exe
    C:\windows\Explorer.EXE
    C:\windows\system32\taskhost.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
    C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
    C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
    C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
    C:\Program Files\TOSHIBA\TECO\TEco.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Users\Owner\AppData\Roaming\Google\Google Talk\googletalk.exe
    C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\windows\system32\taskeng.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
    C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\windows\System32\svchost.exe -k secsvcs
    C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
    C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
    C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
    C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
    C:\windows\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe
    C:\Program Files\Java\jre6\bin\java.exe
    C:\windows\system32\conhost.exe
    C:\Users\Owner\AppData\Local\temp\jkos-Owner\binaries\ScanningProcess.exe
    C:\Users\Owner\AppData\Local\temp\jkos-Owner\binaries\ScanningProcess.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\windows\system32\taskhost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
    C:\windows\system32\SearchProtocolHost.exe
    C:\windows\system32\SearchFilterHost.exe
    C:\windows\system32\DllHost.exe
    C:\windows\system32\DllHost.exe
    C:\Users\Owner\Desktop\dds.com
    C:\windows\system32\conhost.exe
    C:\windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    uRun: [MyTOSHIBA] "c:\program files\toshiba\my toshiba\MyToshiba.exe" /AUTO
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
    uRun: [googletalk] c:\users\owner\appdata\roaming\google\google talk\googletalk.exe /autostart
    uRun: [Google Update] "c:\users\owner\appdata\local\google\update\GoogleUpdate.exe" /c
    mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
    mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
    mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
    mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
    mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
    mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
    mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
    mRun: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
    mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
    mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
    mRun: [NortonOnlineBackupReminder] "c:\program files\toshiba\toshiba online backup\activation\TobuActivation.exe" UNATTENDED
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
    StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\xmmpllk7.default\
    FF - prefs.js: browser.startup.homepage - www.google.com
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\users\owner\appdata\local\google\update\1.2.183.17\npGoogleOneClick8.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

    ============= SERVICES / DRIVERS ===============

    R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
    R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-14 176128]
    R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2009-8-10 185712]
    R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-2-11 1153368]
    R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-8-11 185712]
    R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-19 12920]
    R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2009-12-14 7680]
    R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-12-14 187392]
    R3 RTL8187Se;Realtek RTL8187SE Wireless LAN PCIE Network Adapter;c:\windows\system32\drivers\RTL8187Se.sys [2009-12-14 372736]
    R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2009-12-14 51512]
    R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-8-3 111960]
    R3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-8-6 685424]
    S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
    S3 getPlusHelper;getPlus(R) Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2009-7-13 20992]

    =============== Created Last 30 ================

    2010-03-09 21:25 <DIR> --d----- c:\programdata\NOS
    2010-03-09 21:09 <DIR> --d----- c:\program files\Windows Installer Clean Up
    2010-03-09 21:09 <DIR> --d----- c:\program files\MSECACHE
    2010-03-09 21:01 <DIR> --dsh--- C:\$RECYCLE.BIN
    2010-03-07 21:32 261,632 a------- c:\windows\PEV.exe
    2010-03-07 21:32 161,792 a------- c:\windows\SWREG.exe
    2010-03-07 21:32 98,816 a------- c:\windows\sed.exe
    2010-03-07 21:32 77,312 a------- c:\windows\MBR.exe
    2010-02-24 09:00 641,536 a------- c:\windows\system32\CPFilters.dll
    2010-02-24 09:00 465,408 a------- c:\windows\system32\psisdecd.dll
    2010-02-24 09:00 417,792 a------- c:\windows\system32\msdri.dll
    2010-02-24 09:00 204,288 a------- c:\windows\system32\MSNP.ax
    2010-02-24 09:00 2,048 a------- c:\windows\system32\tzres.dll
    2010-02-15 00:07 <DIR> --d----- c:\program files\TrendMicro
    2010-02-11 17:16 <DIR> --d----- c:\programdata\Lavasoft
    2010-02-11 15:28 <DIR> --d----- c:\programdata\Spybot - Search & Destroy
    2010-02-11 15:28 <DIR> --d----- c:\program files\Spybot - Search & Destroy
    2010-02-11 15:28 <DIR> --d----- c:\progra~2\Spybot - Search & Destroy
    2010-02-11 12:03 <DIR> --d--r-- c:\program files\Norton Support
    2010-02-10 15:36 <DIR> --d----- c:\programdata\Sun
    2010-02-10 15:35 411,368 a------- c:\windows\system32\deploytk.dll
    2010-02-10 14:01 <DIR> --d----- c:\programdata\RegCure
    2010-02-10 14:01 <DIR> --d----- c:\progra~2\RegCure
    2010-02-10 07:46 107,368 a----r-- c:\windows\system32\GEARAspi.dll
    2010-02-10 07:46 26,600 a----r-- c:\windows\system32\drivers\GEARAspiWDM.sys
    2010-02-10 07:45 <DIR> --d----- c:\program files\Symantec
    2010-02-10 07:44 <DIR> --d----- c:\windows\system32\drivers\N360
    2010-02-10 07:42 <DIR> --d----- c:\programdata\PCSettings
    2010-02-10 07:42 <DIR> --d----- c:\progra~2\PCSettings
    2010-02-10 07:29 118 a------- c:\windows\system32\MRT.INI
    2010-02-09 01:32 <DIR> --d----- c:\programdata\McAfee

    ==================== Find3M ====================

    2010-02-24 09:16 181,632 -------- c:\windows\system32\MpSigStub.exe
    2010-01-18 18:29 365,568 a------- c:\windows\system32\secproc_isv.dll
    2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp_isv.dll
    2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp.dll
    2010-01-18 18:29 369,152 a------- c:\windows\system32\secproc.dll
    2010-01-18 18:28 324,608 a------- c:\windows\system32\RMActivate_isv.exe
    2010-01-18 18:28 277,504 a------- c:\windows\system32\RMActivate_ssp_isv.exe
    2010-01-18 18:28 320,512 a------- c:\windows\system32\RMActivate.exe
    2010-01-18 18:28 280,064 a------- c:\windows\system32\RMActivate_ssp.exe
    2009-12-19 04:02 977,920 a------- c:\windows\system32\wininet.dll
    2009-12-19 04:02 12,288 a------- c:\windows\system32\tsbyuv.dll
    2009-12-19 04:02 1,328,640 a------- c:\windows\system32\quartz.dll
    2009-12-19 04:02 22,016 a------- c:\windows\system32\msyuv.dll
    2009-12-19 04:02 31,744 a------- c:\windows\system32\msvidc32.dll
    2009-12-19 04:02 13,312 a------- c:\windows\system32\msrle32.dll
    2009-12-19 04:02 84,480 a------- c:\windows\system32\mciavi32.dll
    2009-12-19 04:02 50,176 a------- c:\windows\system32\iyuv_32.dll
    2009-12-19 04:02 91,648 a------- c:\windows\system32\avifil32.dll
    2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfi.dat
    2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfh.dat
    2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfd.dat
    2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfc.dat
    2009-07-13 23:41 174 a--sh--- c:\program files\desktop.ini
    2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfi.dat
    2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfh.dat
    2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfd.dat
    2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfc.dat
    2009-06-10 16:26 9,633,792 a--shr-- c:\windows\fonts\StaticCache.dat
    2009-07-13 20:14 396,800 a--sh--- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

    ============= FINISH: 23:35:14.36 ===============

    ATTACH LOG


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-09-29.01)

    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 12/30/2009 2:38:36 PM
    System Uptime: 3/9/2010 9:11:44 PM (2 hours ago)

    Motherboard: TOSHIBA | | Portable PC
    Processor: AMD Athlon(tm) II Dual-Core M300 | Socket S1G3 | 2000/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 289 GiB total, 257.513 GiB free.
    D: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP9: 1/3/2010 7:48:43 PM - Configured Microsoft Office Home and Student 2007
    RP10: 1/13/2010 11:34:02 PM - Windows Update
    RP11: 1/14/2010 9:30:30 AM - Windows Modules Installer
    RP12: 1/14/2010 9:36:30 AM - Windows Update
    RP13: 1/16/2010 10:28:00 AM - Windows Update
    RP14: 1/22/2010 9:09:27 AM - Windows Update
    RP15: 1/27/2010 10:08:21 AM - Windows Update
    RP16: 1/30/2010 4:51:05 PM - Windows Update
    RP17: 2/1/2010 7:36:48 PM - Windows Update
    RP18: 2/5/2010 9:25:54 AM - Windows Update
    RP19: 2/8/2010 10:37:00 PM - Windows Update
    RP20: 2/10/2010 7:27:22 AM - Windows Update
    RP22: 2/10/2010 8:00:10 AM - Windows Defender Checkpoint
    RP23: 2/10/2010 3:33:57 PM - Installed Java(TM) 6 Update 18
    RP24: 2/11/2010 9:20:08 PM - Windows Update
    RP25: 2/15/2010 12:05:52 AM - Installed HiJackThis
    RP26: 2/15/2010 2:10:38 PM - Windows Update
    RP27: 2/18/2010 9:31:53 PM - Windows Update
    RP28: 2/18/2010 9:40:51 PM - Windows Update
    RP29: 2/19/2010 9:06:39 AM - Windows Update
    RP30: 2/22/2010 7:37:07 PM - Windows Update
    RP31: 2/25/2010 11:23:01 PM - Windows Update
    RP32: 2/25/2010 11:25:12 PM - Windows Update
    RP33: 3/1/2010 8:30:09 PM - Windows Update
    RP34: 3/4/2010 10:23:16 PM - Windows Update
    RP35: 3/8/2010 7:13:50 PM - Windows Update
    RP36: 3/9/2010 9:09:23 PM - Installed Windows Installer Clean Up

    ==== Installed Programs ======================

    Adobe Download Manager
    Adobe Flash Player 10 ActiveX
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ATI Catalyst Install Manager
    Bonjour
    Catalyst Control Center - Branding
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center Graphics Previews Vista
    Catalyst Control Center InstallProxy
    Catalyst Control Center Localization All
    ccc-core-static
    ccc-utility
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Czech
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Greek
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCC Help Thai
    CCC Help Turkish
    Compatibility Pack for the 2007 Office system
    ERUNT 1.1j
    Google Chrome
    Google Talk (remove only)
    Google Toolbar for Internet Explorer
    HiJackThis
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 18
    Junk Mail filter update
    Label@Once 1.0
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Home and Student 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Suite Activation Assistant
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Works
    Mozilla Firefox (3.6)
    MSVCRT
    MyToshiba
    NetZero Launcher
    PlayReady PC Runtime x86
    Quickbooks Financial Center
    QuickTime
    Realtek Ethernet Controller Driver
    Realtek High Definition Audio Driver
    Realtek USB 2.0 Card Reader
    Realtek WLAN Driver
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB973704)
    Security Update for Microsoft Office Excel 2007 (KB973593)
    Security Update for Microsoft Office PowerPoint 2007 (KB957789)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB969613)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Skype Launcher
    Spybot - Search & Destroy
    Synaptics Pointing Device Driver
    Toshiba Application and Driver Installer
    TOSHIBA Assist
    TOSHIBA ConfigFree
    TOSHIBA Disc Creator
    TOSHIBA DVD PLAYER
    TOSHIBA eco Utility
    TOSHIBA Extended Tiles for Windows Mobility Center
    TOSHIBA Hardware Setup
    TOSHIBA HDD/SSD Alert
    Toshiba Online Backup
    TOSHIBA PC Health Monitor
    Toshiba Quality Application
    TOSHIBA Recovery Media Creator
    TOSHIBA Service Station
    TOSHIBA Speech System Applications
    TOSHIBA Speech System SR Engine(U.S.) Version1.0
    TOSHIBA Speech System TTS Engine(U.S.) Version1.0
    TOSHIBA Supervisor Password
    TOSHIBA Value Added Package
    ToshibaRegistration
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office InfoPath 2007 (KB976416)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 (KB974561)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    WildTangent Games
    Windows Installer Clean Up
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Mail
    Windows Live Messenger
    Windows Live Photo Gallery
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Upload Tool
    Windows Live Writer

    ==== Event Viewer Messages From Past Week ========

    3/9/2010 9:12:00 PM, Error: atikmdag [52236] - CPLIB :: General - Invalid Parameter
    3/9/2010 9:12:00 PM, Error: atikmdag [43029] - Display is not active
    3/9/2010 8:59:59 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
    3/9/2010 11:35:17 PM, Error: Schannel [36888] - The following fatal alert was generated: 48. The internal error state is 552.
    3/9/2010 11:35:17 PM, Error: Schannel [36882] - The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The SSL connection request has failed. The attached data contains the server certificate.
    3/9/2010 10:46:11 PM, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {F81CD990-910B-4BBF-9CB3-6A77F3D697B3}. The error: "2" Happened while starting this command: C:\Program Files\Windows Live\Messenger\msnmsgr.exe -Embedding
    3/7/2010 9:21:25 PM, Error: Service Control Manager [7031] - The Norton Security Suite service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

    ==== End Of File ===========================

    Thank you again for all of your help!! I really appreciate it!!

  5. #15
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Thanks for the logs . Any (earlier) issues left?
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  6. #16
    Junior Member
    Join Date
    Feb 2010
    Posts
    26

    Default

    Hi,

    I still seem to be having problems in Internet Explorer and Firefox. If I do a search on Google, and click one of the links in the results, I'll usually get a message that says, "The document has moved, redirecting..." and it will take me to a different site, some sort of ad or something...

    I ran dds again and here are the logs:

    DDS:



    DDS (Ver_09-09-29.01) - NTFSx86
    Run by Owner at 23:12:09.57 on Wed 03/10/2010
    Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1462 [GMT -5:00]

    SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

    ============== Running Processes ===============

    C:\windows\system32\wininit.exe
    C:\windows\system32\lsm.exe
    C:\windows\system32\svchost.exe -k DcomLaunch
    C:\windows\system32\svchost.exe -k RPCSS
    C:\windows\system32\atiesrxx.exe
    C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\windows\system32\svchost.exe -k netsvcs
    C:\windows\system32\svchost.exe -k LocalService
    C:\windows\system32\svchost.exe -k NetworkService
    C:\windows\system32\atieclxx.exe
    C:\windows\System32\spoolsv.exe
    C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\windows\system32\svchost.exe -k imgsvc
    C:\Windows\system32\TODDSrv.exe
    C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
    C:\Program Files\TOSHIBA\TECO\TecoService.exe
    C:\windows\system32\SearchIndexer.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\windows\system32\Dwm.exe
    C:\windows\Explorer.EXE
    C:\windows\system32\taskhost.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
    C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
    C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
    C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
    C:\Program Files\TOSHIBA\TECO\TEco.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Users\Owner\AppData\Roaming\Google\Google Talk\googletalk.exe
    C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\windows\system32\taskeng.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
    C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\windows\System32\svchost.exe -k secsvcs
    C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
    C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
    C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
    C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
    C:\windows\system32\wuauclt.exe
    C:\windows\system32\taskhost.exe
    C:\windows\servicing\TrustedInstaller.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\windows\system32\DllHost.exe
    C:\windows\system32\DllHost.exe
    C:\Users\Owner\Desktop\dds.com
    C:\windows\system32\conhost.exe
    C:\windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    uRun: [MyTOSHIBA] "c:\program files\toshiba\my toshiba\MyToshiba.exe" /AUTO
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
    uRun: [googletalk] c:\users\owner\appdata\roaming\google\google talk\googletalk.exe /autostart
    uRun: [Google Update] "c:\users\owner\appdata\local\google\update\GoogleUpdate.exe" /c
    mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
    mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
    mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
    mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
    mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
    mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
    mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
    mRun: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
    mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
    mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
    mRun: [NortonOnlineBackupReminder] "c:\program files\toshiba\toshiba online backup\activation\TobuActivation.exe" UNATTENDED
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
    StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\xmmpllk7.default\
    FF - prefs.js: browser.startup.homepage - www.google.com
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\users\owner\appdata\local\google\update\1.2.183.17\npGoogleOneClick8.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

    ============= SERVICES / DRIVERS ===============

    R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
    R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-14 176128]
    R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2009-8-10 185712]
    R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-2-11 1153368]
    R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-8-11 185712]
    R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-19 12920]
    R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2009-12-14 7680]
    R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-12-14 187392]
    R3 RTL8187Se;Realtek RTL8187SE Wireless LAN PCIE Network Adapter;c:\windows\system32\drivers\RTL8187Se.sys [2009-12-14 372736]
    R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2009-12-14 51512]
    R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-8-3 111960]
    R3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-8-6 685424]
    S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
    S3 getPlusHelper;getPlus(R) Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2009-7-13 20992]

    =============== Created Last 30 ================

    2010-03-09 21:25 <DIR> --d----- c:\programdata\NOS
    2010-03-09 21:09 <DIR> --d----- c:\program files\Windows Installer Clean Up
    2010-03-09 21:09 <DIR> --d----- c:\program files\MSECACHE
    2010-03-09 21:01 <DIR> --dsh--- C:\$RECYCLE.BIN
    2010-03-07 21:32 261,632 a------- c:\windows\PEV.exe
    2010-03-07 21:32 161,792 a------- c:\windows\SWREG.exe
    2010-03-07 21:32 98,816 a------- c:\windows\sed.exe
    2010-03-07 21:32 77,312 a------- c:\windows\MBR.exe
    2010-02-24 09:00 641,536 a------- c:\windows\system32\CPFilters.dll
    2010-02-24 09:00 465,408 a------- c:\windows\system32\psisdecd.dll
    2010-02-24 09:00 417,792 a------- c:\windows\system32\msdri.dll
    2010-02-24 09:00 204,288 a------- c:\windows\system32\MSNP.ax
    2010-02-24 09:00 2,048 a------- c:\windows\system32\tzres.dll
    2010-02-15 00:07 <DIR> --d----- c:\program files\TrendMicro
    2010-02-11 17:16 <DIR> --d----- c:\programdata\Lavasoft
    2010-02-11 15:28 <DIR> --d----- c:\programdata\Spybot - Search & Destroy
    2010-02-11 15:28 <DIR> --d----- c:\program files\Spybot - Search & Destroy
    2010-02-11 15:28 <DIR> --d----- c:\progra~2\Spybot - Search & Destroy
    2010-02-11 12:03 <DIR> --d--r-- c:\program files\Norton Support
    2010-02-10 15:36 <DIR> --d----- c:\programdata\Sun
    2010-02-10 15:35 411,368 a------- c:\windows\system32\deploytk.dll
    2010-02-10 14:01 <DIR> --d----- c:\programdata\RegCure
    2010-02-10 14:01 <DIR> --d----- c:\progra~2\RegCure
    2010-02-10 07:46 107,368 a----r-- c:\windows\system32\GEARAspi.dll
    2010-02-10 07:46 26,600 a----r-- c:\windows\system32\drivers\GEARAspiWDM.sys
    2010-02-10 07:45 <DIR> --d----- c:\program files\Symantec
    2010-02-10 07:44 <DIR> --d----- c:\windows\system32\drivers\N360
    2010-02-10 07:42 <DIR> --d----- c:\programdata\PCSettings
    2010-02-10 07:42 <DIR> --d----- c:\progra~2\PCSettings
    2010-02-10 07:29 118 a------- c:\windows\system32\MRT.INI
    2010-02-09 01:32 <DIR> --d----- c:\programdata\McAfee

    ==================== Find3M ====================

    2010-02-24 09:16 181,632 -------- c:\windows\system32\MpSigStub.exe
    2010-01-18 18:29 365,568 a------- c:\windows\system32\secproc_isv.dll
    2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp_isv.dll
    2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp.dll
    2010-01-18 18:29 369,152 a------- c:\windows\system32\secproc.dll
    2010-01-18 18:28 324,608 a------- c:\windows\system32\RMActivate_isv.exe
    2010-01-18 18:28 277,504 a------- c:\windows\system32\RMActivate_ssp_isv.exe
    2010-01-18 18:28 320,512 a------- c:\windows\system32\RMActivate.exe
    2010-01-18 18:28 280,064 a------- c:\windows\system32\RMActivate_ssp.exe
    2009-12-19 04:02 977,920 a------- c:\windows\system32\wininet.dll
    2009-12-19 04:02 12,288 a------- c:\windows\system32\tsbyuv.dll
    2009-12-19 04:02 1,328,640 a------- c:\windows\system32\quartz.dll
    2009-12-19 04:02 22,016 a------- c:\windows\system32\msyuv.dll
    2009-12-19 04:02 31,744 a------- c:\windows\system32\msvidc32.dll
    2009-12-19 04:02 13,312 a------- c:\windows\system32\msrle32.dll
    2009-12-19 04:02 84,480 a------- c:\windows\system32\mciavi32.dll
    2009-12-19 04:02 50,176 a------- c:\windows\system32\iyuv_32.dll
    2009-12-19 04:02 91,648 a------- c:\windows\system32\avifil32.dll
    2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfi.dat
    2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfh.dat
    2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfd.dat
    2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfc.dat
    2009-07-13 23:41 174 a--sh--- c:\program files\desktop.ini
    2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfi.dat
    2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfh.dat
    2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfd.dat
    2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfc.dat
    2009-06-10 16:26 9,633,792 a--shr-- c:\windows\fonts\StaticCache.dat
    2009-07-13 20:14 396,800 a--sh--- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

    ============= FINISH: 23:12:32.66 ===============


    Attach Log:




    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-09-29.01)

    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 12/30/2009 2:38:36 PM
    System Uptime: 3/10/2010 8:09:28 PM (3 hours ago)

    Motherboard: TOSHIBA | | Portable PC
    Processor: AMD Athlon(tm) II Dual-Core M300 | Socket S1G3 | 2000/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 289 GiB total, 257.45 GiB free.
    D: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP9: 1/3/2010 7:48:43 PM - Configured Microsoft Office Home and Student 2007
    RP10: 1/13/2010 11:34:02 PM - Windows Update
    RP11: 1/14/2010 9:30:30 AM - Windows Modules Installer
    RP12: 1/14/2010 9:36:30 AM - Windows Update
    RP13: 1/16/2010 10:28:00 AM - Windows Update
    RP14: 1/22/2010 9:09:27 AM - Windows Update
    RP15: 1/27/2010 10:08:21 AM - Windows Update
    RP16: 1/30/2010 4:51:05 PM - Windows Update
    RP17: 2/1/2010 7:36:48 PM - Windows Update
    RP18: 2/5/2010 9:25:54 AM - Windows Update
    RP19: 2/8/2010 10:37:00 PM - Windows Update
    RP20: 2/10/2010 7:27:22 AM - Windows Update
    RP22: 2/10/2010 8:00:10 AM - Windows Defender Checkpoint
    RP23: 2/10/2010 3:33:57 PM - Installed Java(TM) 6 Update 18
    RP24: 2/11/2010 9:20:08 PM - Windows Update
    RP25: 2/15/2010 12:05:52 AM - Installed HiJackThis
    RP26: 2/15/2010 2:10:38 PM - Windows Update
    RP27: 2/18/2010 9:31:53 PM - Windows Update
    RP28: 2/18/2010 9:40:51 PM - Windows Update
    RP29: 2/19/2010 9:06:39 AM - Windows Update
    RP30: 2/22/2010 7:37:07 PM - Windows Update
    RP31: 2/25/2010 11:23:01 PM - Windows Update
    RP32: 2/25/2010 11:25:12 PM - Windows Update
    RP33: 3/1/2010 8:30:09 PM - Windows Update
    RP34: 3/4/2010 10:23:16 PM - Windows Update
    RP35: 3/8/2010 7:13:50 PM - Windows Update
    RP36: 3/9/2010 9:09:23 PM - Installed Windows Installer Clean Up

    ==== Installed Programs ======================

    Adobe Download Manager
    Adobe Flash Player 10 ActiveX
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ATI Catalyst Install Manager
    Bonjour
    Catalyst Control Center - Branding
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center Graphics Previews Vista
    Catalyst Control Center InstallProxy
    Catalyst Control Center Localization All
    ccc-core-static
    ccc-utility
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Czech
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Greek
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCC Help Thai
    CCC Help Turkish
    Compatibility Pack for the 2007 Office system
    ERUNT 1.1j
    Google Chrome
    Google Talk (remove only)
    Google Toolbar for Internet Explorer
    HiJackThis
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 18
    Junk Mail filter update
    Label@Once 1.0
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Home and Student 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Suite Activation Assistant
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Works
    Mozilla Firefox (3.6)
    MSVCRT
    MyToshiba
    NetZero Launcher
    PlayReady PC Runtime x86
    Quickbooks Financial Center
    QuickTime
    Realtek Ethernet Controller Driver
    Realtek High Definition Audio Driver
    Realtek USB 2.0 Card Reader
    Realtek WLAN Driver
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB973704)
    Security Update for Microsoft Office Excel 2007 (KB973593)
    Security Update for Microsoft Office PowerPoint 2007 (KB957789)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB969613)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Skype Launcher
    Spybot - Search & Destroy
    Synaptics Pointing Device Driver
    Toshiba Application and Driver Installer
    TOSHIBA Assist
    TOSHIBA ConfigFree
    TOSHIBA Disc Creator
    TOSHIBA DVD PLAYER
    TOSHIBA eco Utility
    TOSHIBA Extended Tiles for Windows Mobility Center
    TOSHIBA Hardware Setup
    TOSHIBA HDD/SSD Alert
    Toshiba Online Backup
    TOSHIBA PC Health Monitor
    Toshiba Quality Application
    TOSHIBA Recovery Media Creator
    TOSHIBA Service Station
    TOSHIBA Speech System Applications
    TOSHIBA Speech System SR Engine(U.S.) Version1.0
    TOSHIBA Speech System TTS Engine(U.S.) Version1.0
    TOSHIBA Supervisor Password
    TOSHIBA Value Added Package
    ToshibaRegistration
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office InfoPath 2007 (KB976416)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 (KB974561)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    WildTangent Games
    Windows Installer Clean Up
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Mail
    Windows Live Messenger
    Windows Live Photo Gallery
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Upload Tool
    Windows Live Writer

    ==== Event Viewer Messages From Past Week ========

    3/9/2010 9:12:00 PM, Error: atikmdag [52236] - CPLIB :: General - Invalid Parameter
    3/9/2010 8:59:59 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
    3/9/2010 10:46:11 PM, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {F81CD990-910B-4BBF-9CB3-6A77F3D697B3}. The error: "2" Happened while starting this command: C:\Program Files\Windows Live\Messenger\msnmsgr.exe -Embedding
    3/7/2010 9:21:25 PM, Error: Service Control Manager [7031] - The Norton Security Suite service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    3/10/2010 11:07:44 PM, Error: Schannel [36888] - The following fatal alert was generated: 48. The internal error state is 552.
    3/10/2010 11:07:44 PM, Error: Schannel [36882] - The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The SSL connection request has failed. The attached data contains the server certificate.
    3/10/2010 11:00:34 PM, Error: atikmdag [43029] - Display is not active

    ==== End Of File ===========================

    Please let me know if there's any other information I can give you. Thanks again for all of your help. I soooo appreciate it!

  7. #17
    Junior Member
    Join Date
    Feb 2010
    Posts
    26

    Default

    Also, the little icons on the tabs within Internet Explorer are incorrect. For example, if I visit urbandictionary.com, a little "u" shows up on the tab. If I then go to GMail.com, the "u" stays when it should be a red and white envelope (the GMail icon) instead. Is this malware-related?

    Firefox does not seem to have this problem. Only IE.

    Again, please let me know if there's any other info I can provide.

    Thanks, and sorry this is taking so long!

  8. #18
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Let's see..

    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    DDS::
    mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
    Reboot::

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Close all browser windows, disable protection software and refering to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log. Is redirecting still there?
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  9. #19
    Junior Member
    Join Date
    Feb 2010
    Posts
    26

    Default

    Hello,

    That seemed to stop the redirecting (hooray!), but I'm still seeing weird stuff with the tab icons, particularly with Google it seems. If I move from Google to a new site, and return to Google, the "g" icon is replaced by the icon of whatever site I just visited...

    I'm posting both the ComboFix log and a new dds log:

    ComboFix 10-03-11.02 - Owner 03/11/2010 21:55:39.5.2 - x86
    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1568 [GMT -5:00]
    Running from: c:\users\Owner\Desktop\ComboFix.exe
    Command switches used :: c:\users\Owner\Desktop\CFScript.txt
    SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    .

    ((((((((((((((((((((((((( Files Created from 2010-02-12 to 2010-03-12 )))))))))))))))))))))))))))))))
    .

    2010-03-12 02:59 . 2010-03-12 02:59 -------- d-----w- c:\users\Default\AppData\Local\temp
    2010-03-12 02:54 . 2010-03-12 02:54 -------- d-----w- C:\32788R22FWJFW
    2010-03-12 02:51 . 2010-03-12 02:51 -------- d-----w- c:\users\Owner\AppData\Local\Apple
    2010-03-10 02:09 . 2010-03-10 02:09 3584 ----a-r- c:\users\Owner\AppData\Roaming\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
    2010-03-10 02:09 . 2010-03-10 02:09 -------- d-----w- c:\program files\Windows Installer Clean Up
    2010-03-10 02:09 . 2010-03-10 02:09 -------- d-----w- c:\program files\MSECACHE
    2010-03-10 02:01 . 2010-03-12 03:01 -------- d-----w- c:\users\Owner\AppData\Local\temp
    2010-02-24 14:00 . 2009-12-13 09:30 641536 ----a-w- c:\windows\system32\CPFilters.dll
    2010-02-24 14:00 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
    2010-02-24 14:00 . 2009-12-13 09:29 417792 ----a-w- c:\windows\system32\msdri.dll
    2010-02-24 14:00 . 2010-02-02 07:45 2048 ----a-w- c:\windows\system32\tzres.dll
    2010-02-19 02:35 . 2010-02-19 02:35 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
    2010-02-15 05:07 . 2010-02-15 05:07 388096 ----a-r- c:\users\Owner\AppData\Roaming\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
    2010-02-15 05:07 . 2010-02-15 05:07 -------- d-----w- c:\program files\TrendMicro
    2010-02-15 05:00 . 2010-02-15 05:00 -------- d-----w- c:\program files\ERUNT
    2010-02-11 22:16 . 2010-02-13 05:35 -------- d-----w- c:\programdata\Lavasoft
    2010-02-11 20:28 . 2010-02-15 04:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-02-11 20:28 . 2010-02-11 22:17 -------- d-----w- c:\programdata\Spybot - Search & Destroy
    2010-02-11 19:52 . 2010-02-11 19:52 103050 ----a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{2D3A6BBC-41F4-1F50-18CC-9A77DAEA1AB8}-uninst.exe
    2010-02-11 17:03 . 2010-02-11 17:03 -------- d-----r- c:\program files\Norton Support
    2010-02-11 15:52 . 2010-02-11 15:52 -------- d-----w- c:\users\Owner\AppData\Local\Deployment
    2010-02-11 15:52 . 2010-02-11 15:52 -------- d-----w- c:\users\Owner\AppData\Local\Apps
    2010-02-10 20:36 . 2010-02-10 20:36 -------- d-----w- c:\program files\Common Files\Java
    2010-02-10 20:35 . 2009-12-17 22:14 411368 ----a-w- c:\windows\system32\deploytk.dll
    2010-02-10 19:01 . 2010-02-11 19:52 -------- d-----w- c:\programdata\RegCure
    2010-02-10 12:54 . 2010-02-10 19:51 -------- d-----w- c:\users\Owner\AppData\Local\Diagnostics
    2010-02-10 12:46 . 2010-02-10 12:45 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
    2010-02-10 12:46 . 2010-02-10 12:45 107368 ----a-r- c:\windows\system32\GEARAspi.dll
    2010-02-10 12:45 . 2010-03-08 02:23 -------- d-----w- c:\program files\Symantec
    2010-02-10 12:44 . 2010-02-10 19:55 -------- d-----w- c:\windows\system32\drivers\N360
    2010-02-10 12:42 . 2010-02-10 12:42 -------- d-----w- c:\programdata\PCSettings

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-03-12 02:54 . 2009-12-14 23:17 -------- d-----w- c:\programdata\Microsoft Help
    2010-02-24 14:16 . 2009-12-30 20:03 181632 ------w- c:\windows\system32\MpSigStub.exe
    2010-02-20 18:34 . 2009-09-02 05:46 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-02-19 02:39 . 2009-12-14 23:08 -------- d-----w- c:\program files\Microsoft Works
    2010-02-10 20:35 . 2009-09-02 05:29 -------- d-----w- c:\program files\Java
    2010-02-10 12:44 . 2009-12-14 23:49 -------- d-----w- c:\programdata\Norton
    2010-02-10 12:42 . 2009-12-14 23:49 -------- d-----w- c:\programdata\NortonInstaller
    2010-02-09 17:51 . 2010-02-09 17:48 38434288 ----a-w- c:\programdata\Toshiba\TSS\Plugins\SwUpdates\Packages\4d92cef8-7ed7-402d-aa91-6eda708f6bb8\171515_14.32.13.TC00143300K.exe
    2010-02-09 06:32 . 2010-02-09 06:32 -------- d-----w- c:\programdata\McAfee
    2010-01-24 18:26 . 2010-01-02 03:35 1670624 ----a-w- c:\programdata\WildTangent\TOSHIBA Game Console\Downloads\en-us\Installers\SetupGamesClient.exe
    2010-01-23 03:07 . 2009-09-02 05:47 -------- d-----w- c:\programdata\Partner
    2010-01-18 23:29 . 2010-02-10 03:54 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
    2010-01-18 23:29 . 2010-02-10 03:54 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
    2010-01-18 23:29 . 2010-02-10 03:54 365568 ----a-w- c:\windows\system32\secproc_isv.dll
    2010-01-18 23:29 . 2010-02-10 03:54 369152 ----a-w- c:\windows\system32\secproc.dll
    2010-01-18 23:28 . 2010-02-10 03:54 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
    2010-01-18 23:28 . 2010-02-10 03:54 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
    2010-01-18 23:28 . 2010-02-10 03:54 320512 ----a-w- c:\windows\system32\RMActivate.exe
    2010-01-18 23:28 . 2010-02-10 03:54 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
    2010-01-08 03:18 . 2010-02-10 03:54 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
    2010-01-08 03:17 . 2010-02-10 03:54 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2010-01-03 07:42 . 2010-01-03 07:42 79367 ----a-w- c:\users\Owner\AppData\Roaming\Google\Google Talk\uninstall.exe
    2009-12-30 20:01 . 2009-12-30 20:01 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbBA5B.tmp.exe
    2009-12-30 19:41 . 2009-12-30 19:41 79136 ----a-w- c:\users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
    2009-12-30 19:39 . 2009-12-30 19:39 13 --sh--r- c:\windows\system32\drivers\fbd.sys
    2009-12-19 09:02 . 2010-01-22 03:55 977920 ----a-w- c:\windows\system32\wininet.dll
    2009-12-19 09:02 . 2010-02-10 03:54 12288 ----a-w- c:\windows\system32\tsbyuv.dll
    2009-12-19 09:02 . 2010-02-10 03:54 1328640 ----a-w- c:\windows\system32\quartz.dll
    2009-12-19 09:02 . 2010-02-10 03:54 22016 ----a-w- c:\windows\system32\msyuv.dll
    2009-12-19 09:02 . 2010-02-10 03:54 31744 ----a-w- c:\windows\system32\msvidc32.dll
    2009-12-19 09:02 . 2010-02-10 03:54 13312 ----a-w- c:\windows\system32\msrle32.dll
    2009-12-19 09:02 . 2010-02-10 03:54 84480 ----a-w- c:\windows\system32\mciavi32.dll
    2009-12-19 09:02 . 2010-02-10 03:54 50176 ----a-w- c:\windows\system32\iyuv_32.dll
    2009-12-19 09:02 . 2010-02-10 03:54 91648 ----a-w- c:\windows\system32\avifil32.dll
    2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
    2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
    .

    ((((((((((((((((((((((((((((( SnapShot@2010-03-09_14.23.58 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-09-02 05:29 . 2010-03-10 02:14 33660 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2009-07-14 04:55 . 2010-03-12 03:03 51360 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
    + 2010-03-10 02:29 . 2010-03-10 02:29 84507 c:\windows\System32\Macromed\Flash\uninstall_activeX.exe
    - 2009-12-30 22:36 . 2010-03-09 00:20 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-12-30 22:36 . 2010-03-12 02:54 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-12-30 22:36 . 2010-03-12 02:54 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-12-30 22:36 . 2010-03-09 00:20 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-07-14 04:41 . 2010-03-12 02:54 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-07-14 04:41 . 2010-03-09 00:20 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-12-30 19:40 . 2010-03-12 02:54 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-12-30 19:40 . 2010-03-09 14:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-12-30 19:40 . 2010-03-09 14:14 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-12-30 19:40 . 2010-03-12 02:54 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2009-12-30 19:40 . 2010-03-12 02:54 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-12-30 19:40 . 2010-03-09 14:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-12-14 23:19 . 2010-02-19 02:40 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
    + 2009-12-14 23:19 . 2010-03-12 02:54 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
    - 2009-12-14 23:19 . 2010-02-19 02:40 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
    + 2009-12-14 23:19 . 2010-03-12 02:54 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
    - 2009-12-14 23:19 . 2010-02-19 02:40 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
    + 2009-12-14 23:19 . 2010-03-12 02:54 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
    + 2010-03-12 02:52 . 2010-03-12 02:52 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
    - 2010-02-19 14:07 . 2010-02-19 14:07 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
    + 2009-07-13 23:26 . 2009-07-14 01:03 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.1.7600.20655_none_0ca29ea86ca54783\AcRes.dll
    + 2009-07-13 23:26 . 2009-07-14 01:03 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.1.7600.16539_none_0c32a2dd5373d533\AcRes.dll
    + 2009-12-30 19:40 . 2010-03-12 03:03 8130 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3957342637-2223780103-148138915-1000_UserData.bin
    + 2010-03-10 02:12 . 2010-03-12 03:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2010-03-08 02:25 . 2010-03-09 00:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2010-03-08 02:25 . 2010-03-09 00:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2010-03-10 02:12 . 2010-03-12 03:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2009-07-13 23:26 . 2009-07-14 01:14 211968 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.20655_none_0ca69fd06ca1acdf\AcXtrnal.dll
    + 2009-07-13 23:27 . 2009-07-14 01:14 559616 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.20655_none_0ca69fd06ca1acdf\AcLayers.dll
    + 2009-07-13 23:26 . 2009-07-14 01:14 211968 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.16539_none_0c36a40553703a8f\AcXtrnal.dll
    + 2009-07-13 23:27 . 2009-07-14 01:14 559616 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.16539_none_0c36a40553703a8f\AcLayers.dll
    + 2009-12-31 05:19 . 2010-03-12 02:51 244558 c:\windows\System32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
    + 2010-01-27 00:58 . 2010-01-27 00:58 256280 c:\windows\System32\Macromed\Flash\FlashUtil10e.exe
    + 2006-09-06 23:09 . 2006-09-06 23:09 472064 c:\windows\Installer\14590b.msi
    - 2009-12-14 23:19 . 2010-02-19 02:40 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
    + 2009-12-14 23:19 . 2010-03-12 02:54 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
    + 2009-12-14 23:19 . 2010-03-12 02:54 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
    - 2009-12-14 23:19 . 2010-02-19 02:40 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
    + 2009-12-14 23:19 . 2010-03-12 02:54 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
    - 2009-12-14 23:19 . 2010-02-19 02:40 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
    - 2009-12-14 23:19 . 2010-02-19 02:40 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
    + 2009-12-14 23:19 . 2010-03-12 02:54 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
    - 2009-07-14 02:03 . 2010-03-08 01:57 6815744 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
    + 2009-07-14 02:03 . 2010-03-12 02:59 6815744 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
    - 2009-07-14 04:34 . 2010-02-27 03:38 3798234 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
    + 2009-07-14 04:34 . 2010-03-12 03:03 3798234 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
    + 2010-02-04 22:24 . 2010-02-04 22:24 9122304 c:\windows\Installer\a71a273.msp
    + 2010-02-21 06:00 . 2010-02-21 06:00 8480768 c:\windows\Installer\a71a253.msp
    + 2009-12-14 23:19 . 2010-03-12 02:54 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
    - 2009-12-14 23:19 . 2010-02-19 02:40 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
    + 2010-03-12 02:54 . 2010-03-12 02:54 6606848 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
    + 2009-07-14 07:18 . 2010-03-11 04:02 15087590 c:\windows\winsxs\ManifestCache\e4e8be02b8fae2a7_blobs.bin
    + 2009-12-30 19:46 . 2010-03-02 05:30 31648712 c:\windows\System32\MRT.exe
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MyTOSHIBA"="c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe" [2009-08-06 264048]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-02 39408]
    "googletalk"="c:\users\Owner\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
    "Google Update"="c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-02-11 135664]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-30 98304]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-29 7625248]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-21 1545512]
    "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2009-08-21 476512]
    "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2009-07-28 460088]
    "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2009-08-05 738616]
    "ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-08-17 1294136]
    "TosWaitSrv"="c:\program files\TOSHIBA\TPHM\TosWaitSrv.exe" [2009-08-07 611672]
    "Teco"="c:\program files\TOSHIBA\TECO\Teco.exe" [2009-08-12 1324384]
    "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 611672]
    "NortonOnlineBackupReminder"="c:\program files\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe" [2009-07-16 529256]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

    c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorUser"= 2 (0x2)
    "EnableUIADesktopToggle"= 0 (0x0)

    R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
    R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-07-30 176128]
    S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [2009-08-11 185712]
    S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448]
    S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
    S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-08-12 185712]
    S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [2009-06-20 12920]
    S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2009-07-07 7680]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-31 187392]
    S3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512]
    S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-04 111960]
    S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-07 685424]


    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}]
    2009-08-06 16:15 264048 ----a-w- c:\program files\TOSHIBA\My Toshiba\MyToshiba.exe
    .
    Contents of the 'Scheduled Tasks' folder

    2010-03-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3957342637-2223780103-148138915-1000Core.job
    - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-11 15:52]

    2010-03-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3957342637-2223780103-148138915-1000UA.job
    - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-11 15:52]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
    FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\xmmpllk7.default\
    FF - prefs.js: browser.startup.homepage - www.google.com
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: c:\users\Owner\AppData\Local\Google\Update\1.2.183.17\npGoogleOneClick8.dll

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\atieclxx.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\windows\system32\TODDSrv.exe
    c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
    c:\windows\system32\taskhost.exe
    c:\windows\system32\conhost.exe
    c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    c:\program files\Synaptics\SynTP\SynTPHelper.exe
    c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
    c:\windows\system32\sppsvc.exe
    c:\program files\TOSHIBA\ConfigFree\CFSwMgr.exe
    c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
    c:\program files\TOSHIBA\TPHM\TPCHWMsg.exe
    c:\windows\system32\vssvc.exe
    c:\windows\servicing\TrustedInstaller.exe
    .
    **************************************************************************
    .
    Completion time: 2010-03-11 22:04:49 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-03-12 03:04
    ComboFix2.txt 2010-03-10 02:01
    ComboFix3.txt 2010-03-09 14:35
    ComboFix4.txt 2010-03-09 14:25

    Pre-Run: 277,018,537,984 bytes free
    Post-Run: 277,211,181,056 bytes free

    - - End Of File - - 5B99DA6CEF56933B444AD01F3C1BA5E7

    ------------------------------------------------------------------------
    DDS log:


    DDS (Ver_09-09-29.01) - NTFSx86
    Run by Owner at 22:21:09.97 on Thu 03/11/2010
    Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2812.1842 [GMT -5:00]

    SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

    ============== Running Processes ===============

    C:\windows\system32\wininit.exe
    C:\windows\system32\lsm.exe
    C:\windows\system32\svchost.exe -k DcomLaunch
    C:\windows\system32\svchost.exe -k RPCSS
    C:\windows\system32\atiesrxx.exe
    C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\windows\system32\svchost.exe -k netsvcs
    C:\windows\system32\svchost.exe -k LocalService
    C:\windows\system32\atieclxx.exe
    C:\windows\system32\svchost.exe -k NetworkService
    C:\windows\System32\spoolsv.exe
    C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\windows\system32\svchost.exe -k imgsvc
    C:\Windows\system32\TODDSrv.exe
    C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
    C:\Program Files\TOSHIBA\TECO\TecoService.exe
    C:\windows\system32\SearchIndexer.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\windows\system32\Dwm.exe
    C:\windows\system32\taskhost.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
    C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
    C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
    C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
    C:\Program Files\TOSHIBA\TECO\TEco.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Users\Owner\AppData\Roaming\Google\Google Talk\googletalk.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\windows\system32\taskeng.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\windows\System32\svchost.exe -k secsvcs
    C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
    C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
    C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
    C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
    C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
    C:\windows\Explorer.exe
    C:\windows\system32\wuauclt.exe
    C:\windows\system32\notepad.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\windows\system32\DllHost.exe
    C:\windows\system32\DllHost.exe
    C:\Users\Owner\Desktop\dds.com
    C:\windows\system32\conhost.exe
    C:\windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    uRun: [MyTOSHIBA] "c:\program files\toshiba\my toshiba\MyToshiba.exe" /AUTO
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
    uRun: [googletalk] c:\users\owner\appdata\roaming\google\google talk\googletalk.exe /autostart
    uRun: [Google Update] "c:\users\owner\appdata\local\google\update\GoogleUpdate.exe" /c
    mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
    mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
    mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
    mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
    mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
    mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
    mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
    mRun: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
    mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
    mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
    mRun: [NortonOnlineBackupReminder] "c:\program files\toshiba\toshiba online backup\activation\TobuActivation.exe" UNATTENDED
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\xmmpllk7.default\
    FF - prefs.js: browser.startup.homepage - www.google.com
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\users\owner\appdata\local\google\update\1.2.183.17\npGoogleOneClick8.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

    ============= SERVICES / DRIVERS ===============

    R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
    R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-14 176128]
    R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2009-8-10 185712]
    R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-2-11 1153368]
    R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-8-11 185712]
    R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-19 12920]
    R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2009-12-14 7680]
    R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-12-14 187392]
    R3 RTL8187Se;Realtek RTL8187SE Wireless LAN PCIE Network Adapter;c:\windows\system32\drivers\RTL8187Se.sys [2009-12-14 372736]
    R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2009-12-14 51512]
    R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-8-3 111960]
    R3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-8-6 685424]
    S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]

    =============== Created Last 30 ================

    2010-03-11 22:01 <DIR> --d----- C:\$RECYCLE.BIN
    2010-03-09 21:09 <DIR> --d----- c:\program files\Windows Installer Clean Up
    2010-03-09 21:09 <DIR> --d----- c:\program files\MSECACHE
    2010-03-07 21:32 261,632 a------- c:\windows\PEV.exe
    2010-03-07 21:32 161,792 a------- c:\windows\SWREG.exe
    2010-03-07 21:32 98,816 a------- c:\windows\sed.exe
    2010-03-07 21:32 77,312 a------- c:\windows\MBR.exe
    2010-02-24 09:00 641,536 a------- c:\windows\system32\CPFilters.dll
    2010-02-24 09:00 465,408 a------- c:\windows\system32\psisdecd.dll
    2010-02-24 09:00 417,792 a------- c:\windows\system32\msdri.dll
    2010-02-24 09:00 204,288 a------- c:\windows\system32\MSNP.ax
    2010-02-24 09:00 2,048 a------- c:\windows\system32\tzres.dll
    2010-02-15 00:07 <DIR> --d----- c:\program files\TrendMicro
    2010-02-11 17:16 <DIR> --d----- c:\programdata\Lavasoft
    2010-02-11 15:28 <DIR> --d----- c:\programdata\Spybot - Search & Destroy
    2010-02-11 15:28 <DIR> --d----- c:\program files\Spybot - Search & Destroy
    2010-02-11 15:28 <DIR> --d----- c:\progra~2\Spybot - Search & Destroy
    2010-02-11 12:03 <DIR> --d--r-- c:\program files\Norton Support
    2010-02-10 15:36 <DIR> --d----- c:\programdata\Sun
    2010-02-10 15:35 411,368 a------- c:\windows\system32\deploytk.dll
    2010-02-10 14:01 <DIR> --d----- c:\programdata\RegCure
    2010-02-10 14:01 <DIR> --d----- c:\progra~2\RegCure
    2010-02-10 07:46 107,368 a----r-- c:\windows\system32\GEARAspi.dll
    2010-02-10 07:46 26,600 a----r-- c:\windows\system32\drivers\GEARAspiWDM.sys
    2010-02-10 07:45 <DIR> --d----- c:\program files\Symantec
    2010-02-10 07:44 <DIR> --d----- c:\windows\system32\drivers\N360
    2010-02-10 07:42 <DIR> --d----- c:\programdata\PCSettings
    2010-02-10 07:42 <DIR> --d----- c:\progra~2\PCSettings
    2010-02-10 07:29 118 a------- c:\windows\system32\MRT.INI

    ==================== Find3M ====================

    2010-02-24 09:16 181,632 -------- c:\windows\system32\MpSigStub.exe
    2010-01-18 18:29 365,568 a------- c:\windows\system32\secproc_isv.dll
    2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp_isv.dll
    2010-01-18 18:29 85,504 a------- c:\windows\system32\secproc_ssp.dll
    2010-01-18 18:29 369,152 a------- c:\windows\system32\secproc.dll
    2010-01-18 18:28 324,608 a------- c:\windows\system32\RMActivate_isv.exe
    2010-01-18 18:28 277,504 a------- c:\windows\system32\RMActivate_ssp_isv.exe
    2010-01-18 18:28 320,512 a------- c:\windows\system32\RMActivate.exe
    2010-01-18 18:28 280,064 a------- c:\windows\system32\RMActivate_ssp.exe
    2009-12-19 04:02 977,920 a------- c:\windows\system32\wininet.dll
    2009-12-19 04:02 12,288 a------- c:\windows\system32\tsbyuv.dll
    2009-12-19 04:02 1,328,640 a------- c:\windows\system32\quartz.dll
    2009-12-19 04:02 22,016 a------- c:\windows\system32\msyuv.dll
    2009-12-19 04:02 31,744 a------- c:\windows\system32\msvidc32.dll
    2009-12-19 04:02 13,312 a------- c:\windows\system32\msrle32.dll
    2009-12-19 04:02 84,480 a------- c:\windows\system32\mciavi32.dll
    2009-12-19 04:02 50,176 a------- c:\windows\system32\iyuv_32.dll
    2009-12-19 04:02 91,648 a------- c:\windows\system32\avifil32.dll
    2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfi.dat
    2009-07-13 23:56 291,294 a------- c:\windows\inf\perflib\0409\perfh.dat
    2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfd.dat
    2009-07-13 23:56 31,548 a------- c:\windows\inf\perflib\0409\perfc.dat
    2009-07-13 23:41 174 a--sh--- c:\program files\desktop.ini
    2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfi.dat
    2009-07-13 19:34 291,294 a------- c:\windows\inf\perflib\0000\perfh.dat
    2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfd.dat
    2009-07-13 19:34 31,548 a------- c:\windows\inf\perflib\0000\perfc.dat
    2009-06-10 16:26 9,633,792 a--shr-- c:\windows\fonts\StaticCache.dat
    2009-07-13 20:14 396,800 a--sh--- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

    ============= FINISH: 22:21:34.95 ===============

    Attach Log:

    :
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-09-29.01)

    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 12/30/2009 2:38:36 PM
    System Uptime: 3/11/2010 10:00:19 PM (0 hours ago)

    Motherboard: TOSHIBA | | Portable PC
    Processor: AMD Athlon(tm) II Dual-Core M300 | Socket S1G3 | 2000/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 289 GiB total, 258.243 GiB free.
    D: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP13: 1/16/2010 10:28:00 AM - Windows Update
    RP14: 1/22/2010 9:09:27 AM - Windows Update
    RP15: 1/27/2010 10:08:21 AM - Windows Update
    RP16: 1/30/2010 4:51:05 PM - Windows Update
    RP17: 2/1/2010 7:36:48 PM - Windows Update
    RP18: 2/5/2010 9:25:54 AM - Windows Update
    RP19: 2/8/2010 10:37:00 PM - Windows Update
    RP20: 2/10/2010 7:27:22 AM - Windows Update
    RP22: 2/10/2010 8:00:10 AM - Windows Defender Checkpoint
    RP23: 2/10/2010 3:33:57 PM - Installed Java(TM) 6 Update 18
    RP24: 2/11/2010 9:20:08 PM - Windows Update
    RP25: 2/15/2010 12:05:52 AM - Installed HiJackThis
    RP26: 2/15/2010 2:10:38 PM - Windows Update
    RP27: 2/18/2010 9:31:53 PM - Windows Update
    RP28: 2/18/2010 9:40:51 PM - Windows Update
    RP29: 2/19/2010 9:06:39 AM - Windows Update
    RP30: 2/22/2010 7:37:07 PM - Windows Update
    RP31: 2/25/2010 11:23:01 PM - Windows Update
    RP32: 2/25/2010 11:25:12 PM - Windows Update
    RP33: 3/1/2010 8:30:09 PM - Windows Update
    RP34: 3/4/2010 10:23:16 PM - Windows Update
    RP35: 3/8/2010 7:13:50 PM - Windows Update
    RP36: 3/9/2010 9:09:23 PM - Installed Windows Installer Clean Up
    RP37: 3/11/2010 9:51:48 PM - Windows Update
    RP38: 3/11/2010 10:04:02 PM - Windows Update

    ==== Installed Programs ======================

    Adobe Flash Player 10 ActiveX
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ATI Catalyst Install Manager
    Bonjour
    Catalyst Control Center - Branding
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center Graphics Previews Vista
    Catalyst Control Center InstallProxy
    Catalyst Control Center Localization All
    ccc-core-static
    ccc-utility
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Czech
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Greek
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCC Help Thai
    CCC Help Turkish
    Compatibility Pack for the 2007 Office system
    ERUNT 1.1j
    Google Chrome
    Google Talk (remove only)
    Google Toolbar for Internet Explorer
    HiJackThis
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 18
    Junk Mail filter update
    Label@Once 1.0
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Home and Student 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Suite Activation Assistant
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Works
    Mozilla Firefox (3.6)
    MSVCRT
    MyToshiba
    NetZero Launcher
    PlayReady PC Runtime x86
    Quickbooks Financial Center
    QuickTime
    Realtek Ethernet Controller Driver
    Realtek High Definition Audio Driver
    Realtek USB 2.0 Card Reader
    Realtek WLAN Driver
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB978380)
    Security Update for Microsoft Office Excel 2007 (KB978382)
    Security Update for Microsoft Office PowerPoint 2007 (KB957789)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB969613)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Skype Launcher
    Spybot - Search & Destroy
    Synaptics Pointing Device Driver
    Toshiba Application and Driver Installer
    TOSHIBA Assist
    TOSHIBA ConfigFree
    TOSHIBA Disc Creator
    TOSHIBA DVD PLAYER
    TOSHIBA eco Utility
    TOSHIBA Extended Tiles for Windows Mobility Center
    TOSHIBA Hardware Setup
    TOSHIBA HDD/SSD Alert
    Toshiba Online Backup
    TOSHIBA PC Health Monitor
    Toshiba Quality Application
    TOSHIBA Recovery Media Creator
    TOSHIBA Service Station
    TOSHIBA Speech System Applications
    TOSHIBA Speech System SR Engine(U.S.) Version1.0
    TOSHIBA Speech System TTS Engine(U.S.) Version1.0
    TOSHIBA Supervisor Password
    TOSHIBA Value Added Package
    ToshibaRegistration
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office InfoPath 2007 (KB976416)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 (KB974561)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    WildTangent Games
    Windows Installer Clean Up
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Mail
    Windows Live Messenger
    Windows Live Photo Gallery
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Upload Tool
    Windows Live Writer

    ==== Event Viewer Messages From Past Week ========

    3/9/2010 10:46:11 PM, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {F81CD990-910B-4BBF-9CB3-6A77F3D697B3}. The error: "2" Happened while starting this command: C:\Program Files\Windows Live\Messenger\msnmsgr.exe -Embedding
    3/7/2010 9:21:25 PM, Error: Service Control Manager [7031] - The Norton Security Suite service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
    3/11/2010 9:55:16 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
    3/11/2010 9:54:15 PM, Error: Schannel [36888] - The following fatal alert was generated: 48. The internal error state is 552.
    3/11/2010 9:54:15 PM, Error: Schannel [36882] - The certificate received from the remote server was issued by an untrusted certificate authority. Because of this, none of the data contained in the certificate can be validated. The SSL connection request has failed. The attached data contains the server certificate.
    3/11/2010 10:00:34 PM, Error: atikmdag [52236] - CPLIB :: General - Invalid Parameter
    3/11/2010 10:00:34 PM, Error: atikmdag [43029] - Display is not active

    ==== End Of File ===========================


    Thank you, thank you, thank you, thank you!!!!

  10. #20
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    If you run IE with addons disabled (instructions below) does it still behave like that? Could you provide a screenshot of situation?


    Click start ->All Programs ->Accessories ->System Tools ->Internet Explorer (No Add-ons)
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •