Hello,
Last week my Netbook was infected by one of the variants of Win 7 Home Security after visiting a website which I have regularly visited before without being infected. I was not able to browse to webpages and several messages popped up in the taskbar. I followed the instructions on the following website to remove the infection: http://www.bleepingcomputer.com/virus-removal/remove-win-7-internet-security-2011. Afterwards I scanned with Spybot S&D as well as with Malwarebytes' Anti Malware, and both scans came up clean. I was again able to browse to webpages and there were no longer pop-ups.
Today I scanned again with Spybot S&D and it found the following infection: Fraud.InternetSecurity2011. I am still able to browse and there are no pop-ups.
I would greatly appreciate any help in removing this infection. Please find the results of the Spybot S&D scan and DDS.txt log below.
Husky_
--------------------------------------------------------------------------
Fraud.InternetSecurity2011: [SBI $75AFFB3E] Executable (File, nothing done)
C:\Users\Dieter\AppData\Local\dnk.exe
Properties.size=335872
Properties.md5=0BA3FB8171D7F60B2FD1C8187B69F721
Properties.filedate=1301416442
Properties.filedatetext=2011-03-29 17:34:02
Fraud.InternetSecurity2011: [SBI $75AFFB3E] Executable (File, nothing done)
C:\Users\Dieter\AppData\Local\fsx.exe
Properties.size=335872
Properties.md5=0BA3FB8171D7F60B2FD1C8187B69F721
Properties.filedate=1301416426
Properties.filedatetext=2011-03-29 17:33:46
Fraud.InternetSecurity2011: [SBI $75AFFB3E] Executable (File, nothing done)
C:\Users\Dieter\AppData\Local\gre.exe
Properties.size=335872
Properties.md5=0BA3FB8171D7F60B2FD1C8187B69F721
Properties.filedate=1301416443
Properties.filedatetext=2011-03-29 17:34:02
Fraud.InternetSecurity2011: [SBI $75AFFB3E] Executable (File, nothing done)
C:\Users\Dieter\AppData\Local\lud.exe
Properties.size=335872
Properties.md5=0BA3FB8171D7F60B2FD1C8187B69F721
Properties.filedate=1301416428
Properties.filedatetext=2011-03-29 17:33:47
Fraud.InternetSecurity2011: [SBI $75AFFB3E] Executable (File, nothing done)
C:\Users\Dieter\AppData\Local\mvt.exe
Properties.size=335872
Properties.md5=0BA3FB8171D7F60B2FD1C8187B69F721
Properties.filedate=1301416442
Properties.filedatetext=2011-03-29 17:34:02
Fraud.InternetSecurity2011: [SBI $75AFFB3E] Executable (File, nothing done)
C:\Users\Dieter\AppData\Local\psu.exe
Properties.size=335872
Properties.md5=0BA3FB8171D7F60B2FD1C8187B69F721
Properties.filedate=1301416429
Properties.filedatetext=2011-03-29 17:33:48
Fraud.InternetSecurity2011: [SBI $07CC9A4D] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Start
Fraud.InternetSecurity2011: [SBI $61C84F7D] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Start
Fraud.InternetSecurity2011: [SBI $F5EC9C27] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2011-03-29 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2011-03-18 Includes\Adware.sbi (*)
2011-03-22 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-03-08 Includes\DialerC.sbi (*)
2011-02-24 Includes\HeavyDuty.sbi (*)
2011-03-29 Includes\Hijackers.sbi (*)
2011-03-29 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2011-03-08 Includes\KeyloggersC.sbi (*)
2011-04-05 Includes\Malware.sbi (*)
2011-04-05 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2011-03-15 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2011-03-08 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2011-02-24 Includes\Spyware.sbi (*)
2011-03-15 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-12-28 Includes\Trojans.sbi (*)
2011-04-05 Includes\TrojansC-02.sbi (*)
2011-03-29 Includes\TrojansC-03.sbi (*)
2011-03-08 Includes\TrojansC-04.sbi (*)
2011-04-06 Includes\TrojansC-05.sbi (*)
2011-03-08 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
--------------------------------------------------------------------------
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Dieter at 19:06:27.59 on 07/04/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Starter 6.1.7600.0.1252.44.1033.18.1013.312 [GMT 1:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\ThpSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Toshiba TEMPRO\TemproTray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TECO\Teco.exe
C:\Windows\System32\ThpSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskhost.exe
C:\Users\Dieter\Desktop\dds.scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://toshiba.msn.com
uDefault_Page_URL = hxxp://toshiba.msn.com
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [Toshiba TEMPRO] c:\program files\toshiba tempro\TemproTray.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [HWSetup] c:\program files\toshiba\utilities\HWSetup.exe hwSetUP
mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe
mRun: [SVPWUTIL] c:\program files\toshiba\utilities\SVPWUTIL.exe SVPwUTIL
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [TUSBSleepChargeSrv] %ProgramFiles%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
mRun: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
mRun: [ThpSrv] c:\windows\system32\thpsrv /logon
mRun: [ToshibaServiceStation] c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe /hide:60
mRun: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
mRun: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
mRun: [TosVolRegulator] c:\program files\toshiba\tosvolregulator\TosVolRegulator.exe
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [MobileBroadband] c:\program files\vodafone\vodafone mobile broadband\bin\MobileBroadband.exe /silent
dRun: [TOSHIBA Online Product Information] c:\program files\toshiba\toshiba online product information\topi.exe
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporteren naar Microsoft Excel - c:\progra~1\mif5ba~1\office10\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
TCP: {12FB4F37-C77A-4FEC-9919-0A2E572F53BF} = 10.206.65.68 10.206.65.68
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\dieter\appdata\roaming\mozilla\firefox\profiles\pfk4j8za.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content
FF - component: c:\users\dieter\appdata\roaming\mozilla\firefox\profiles\pfk4j8za.default\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Xmarks: foxmarks@kei.com - %profile%\extensions\foxmarks@kei.com
FF - Ext: Full Fullscreen: {bfe3406c-6f31-4789-86d5-efa50e12c9eb} - %profile%\extensions\{bfe3406c-6f31-4789-86d5-efa50e12c9eb}
FF - Ext: Add Bookmark Here ²: abhere2@moztw.org - %profile%\extensions\abhere2@moztw.org
FF - Ext: Tiny Menu: {d33c2f7c-b1e6-4d46-ab0e-be1f6d05c904} - %profile%\extensions\{d33c2f7c-b1e6-4d46-ab0e-be1f6d05c904}
FF - Ext: rein: rein@notiz.jp - %profile%\extensions\rein@notiz.jp
FF - Ext: Speed Dial: {64161300-e22b-11db-8314-0800200c9a66} - %profile%\extensions\{64161300-e22b-11db-8314-0800200c9a66}
FF - Ext: British English Dictionary: en-GB@dictionaries.addons.mozilla.org - %profile%\extensions\en-GB@dictionaries.addons.mozilla.org
FF - Ext: Woordenboek Nederlands: nl-NL@dictionaries.addons.mozilla.org - %profile%\extensions\nl-NL@dictionaries.addons.mozilla.org
FF - Ext: Toolbar Buttons: {03B08592-E5B4-45ff-A0BE-C1D975458688} - %profile%\extensions\{03B08592-E5B4-45ff-A0BE-C1D975458688}
FF - Ext: Download Statusbar: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} - %profile%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
FF - Ext: deskCut: {9125C9CB-BE2B-4389-A0C7-46A4BDD46AEA} - %profile%\extensions\{9125C9CB-BE2B-4389-A0C7-46A4BDD46AEA}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: FoxyTunes: {463F6CA5-EE3C-4be1-B7E6-7FEE11953374} - %profile%\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
FF - Ext: Pimpoflage: pimpoflage@ffpimp.com - %profile%\extensions\pimpoflage@ffpimp.com
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-3-29 64512]
R0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\drivers\thpdrv.sys [2009-6-29 30272]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\drivers\Thpevm.sys [2009-6-29 13120]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-29 371544]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-3-29 301528]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-3-29 19544]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-3-29 53592]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-3-29 42184]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2010-1-28 185712]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2010-4-6 189808]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-19 12920]
R2 VmbService;Vodafone Mobile Broadband Service;c:\program files\vodafone\vodafone mobile broadband\bin\VmbService.exe [2010-8-18 8704]
R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2010-10-24 24064]
R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2010-10-24 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2010-2-5 111960]
R3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2010-3-31 685424]
R3 vodafone_K380x-z_dc_enum;vodafone_K380x-z_dc_enum;c:\windows\system32\drivers\vodafone_K380x-z_dc_enum.sys [2010-5-20 61952]
R3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\drivers\zteusbvoice.sys [2011-3-31 105856]
R3 ZTEusbwwan;ZTE MBN Miniport;c:\windows\system32\drivers\ZTEusbwwan.sys [2011-3-31 194048]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-3-29 1405384]
S3 massfilter;MBB Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2011-3-31 9216]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2010-10-24 189984]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-5-20 277536]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\toshiba tempro\TemproSvc.exe [2010-2-11 124368]
.
=============== Created Last 30 ================
.
2011-04-07 15:28:27 -------- d-----w- c:\users\dieter\appdata\roaming\Disk Cleaner
2011-03-31 20:32:53 -------- d-----w- c:\users\dieter\appdata\roaming\FLEXnet
2011-03-31 20:25:27 -------- d-----w- c:\users\dieter\appdata\roaming\Vodafone
2011-03-31 20:25:07 194048 ----a-w- c:\windows\system32\drivers\ZTEusbwwan.sys
2011-03-31 20:25:06 105856 ----a-w- c:\windows\system32\drivers\zteusbvoice.sys
2011-03-31 20:25:02 105856 ----a-w- c:\windows\system32\drivers\ZTEusbnmea.sys
2011-03-31 20:24:58 105856 ----a-w- c:\windows\system32\drivers\ZTEusbmdm6k.sys
2011-03-31 20:24:56 105856 ----a-w- c:\windows\system32\drivers\ZTEusbser6k.sys
2011-03-31 20:24:55 9216 ----a-w- c:\windows\system32\drivers\massfilter.sys
2011-03-31 20:24:09 -------- d-----w- c:\progra~2\Vodafone
2011-03-31 20:24:00 -------- d-----w- c:\program files\Vodafone
2011-03-31 20:22:56 -------- d-----w- c:\users\dieter\appdata\local\{F3E8BCCE-24B6-4737-920E-0D6073630E2A}
2011-03-29 22:41:39 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-03-29 22:41:39 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-03-29 22:41:39 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-03-29 22:41:38 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-03-29 22:41:38 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-03-29 22:27:36 293376 ----a-w- c:\windows\system32\browserchoice.exe
2011-03-29 22:23:29 316928 ----a-w- c:\windows\system32\spoolsv.exe
2011-03-29 22:23:27 516096 ----a-w- c:\program files\windows mail\wab.exe
2011-03-29 22:23:26 314368 ----a-w- c:\windows\system32\webio.dll
2011-03-29 22:23:11 133720 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2011-03-29 22:23:11 1037312 ----a-w- c:\windows\system32\lsasrv.dll
2011-03-29 22:23:10 954752 ----a-w- c:\windows\system32\mfc40.dll
2011-03-29 22:23:09 954288 ----a-w- c:\windows\system32\mfc40u.dll
2011-03-29 22:23:04 164864 ----a-w- c:\program files\windows media player\wmplayer.exe
2011-03-29 22:23:02 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2011-03-29 22:21:59 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-29 22:19:50 363520 ----a-w- c:\windows\system32\StructuredQuery.dll
2011-03-29 22:19:06 132608 ----a-w- c:\windows\system32\cabview.dll
2011-03-29 22:15:22 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-03-29 22:15:22 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-03-29 22:15:22 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-03-29 22:14:56 101760 ----a-w- c:\windows\system32\consent.exe
2011-03-29 21:45:03 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-03-29 21:45:03 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-03-29 21:44:35 40648 ----a-w- c:\windows\avastSS.scr
2011-03-29 21:44:27 -------- d-----w- c:\program files\AVAST Software
2011-03-29 21:44:27 -------- d-----w- c:\progra~2\AVAST Software
2011-03-29 21:27:46 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-03-29 21:21:19 -------- dc-h--w- c:\progra~2\{E45B1D3E-BC46-46CA-AC1B-16932832F73E}
2011-03-29 21:20:54 -------- d-----w- c:\program files\Lavasoft
2011-03-29 19:20:56 -------- d-----w- c:\users\dieter\appdata\roaming\KeePass
2011-03-29 19:18:37 -------- d-----w- c:\program files\KeePass Password Safe
2011-03-29 18:23:03 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-03-29 18:23:03 -------- d-----w- c:\progra~2\Spybot - Search & Destroy
2011-03-29 17:42:20 -------- d-----w- c:\users\dieter\appdata\roaming\Malwarebytes
2011-03-29 17:42:15 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-29 17:42:14 -------- d-----w- c:\progra~2\Malwarebytes
2011-03-29 17:42:12 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-29 17:42:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-29 16:34:02 335872 --sha-w- c:\users\dieter\appdata\local\mvt.exe
2011-03-29 16:34:02 335872 --sha-w- c:\users\dieter\appdata\local\gre.exe
2011-03-29 16:34:02 335872 --sha-w- c:\users\dieter\appdata\local\dnk.exe
2011-03-29 16:33:48 335872 --sha-w- c:\users\dieter\appdata\local\psu.exe
2011-03-29 16:33:47 335872 --sha-w- c:\users\dieter\appdata\local\lud.exe
2011-03-29 16:33:46 335872 --sha-w- c:\users\dieter\appdata\local\fsx.exe
2011-03-26 10:27:05 -------- d-----w- c:\program files\CleanUp!
2011-03-26 10:26:53 -------- d-----w- c:\program files\Disk Cleaner
2011-03-26 10:26:19 -------- d-----w- c:\program files\CCleaner
2011-03-24 18:53:39 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2011-03-24 18:49:57 83249512 ----a-w- c:\program files\common files\windows live\.cache\wlc18C1.tmp
2011-03-24 18:46:53 14744 ----a-w- c:\users\dieter\appdata\roaming\microsoft\identitycrl\production\ppcrlconfig.dll
2011-03-24 18:46:33 -------- d-----w- c:\users\dieter\Tracing
2011-03-23 17:50:31 -------- d-----w- c:\users\dieter\appdata\local\CutePDF Writer
2011-03-23 08:14:01 -------- d-----w- c:\program files\GPLGS
2011-03-23 08:13:41 87552 ----a-w- c:\windows\system32\cpwmon2k.dll
2011-03-23 08:13:40 -------- d-----w- c:\program files\Acro Software
2011-03-22 18:38:12 12800 ----a-w- c:\program files\mozilla firefox\plugins\npwachk.dll
2011-03-22 07:56:33 -------- d-----w- c:\program files\SyncToy 2.1
2011-03-20 16:06:27 -------- d-----w- c:\users\dieter\appdata\local\Thunderbird
2011-03-20 14:58:21 -------- d-----w- c:\program files\SopCast
2011-03-12 12:28:40 103864 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2011-03-09 06:31:28 232448 ----a-w- c:\windows\system32\mp3fhg.acm
2011-03-09 06:31:27 810496 ----a-w- c:\windows\system32\xvidcore.dll
2011-03-09 06:31:27 237568 ----a-w- c:\windows\system32\yv12vfw.dll
2011-03-09 06:31:27 183808 ----a-w- c:\windows\system32\xvidvfw.dll
2011-03-09 06:31:27 151552 ----a-w- c:\windows\system32\ac3acm.acm
2011-03-09 06:31:26 80896 ----a-w- c:\windows\system32\ff_vfw.dll
2011-03-09 06:31:21 -------- d-----w- c:\program files\K-Lite Codec Pack
2011-03-09 06:28:09 -------- d-----w- c:\progra~2\DivX
.
==================== Find3M ====================
.
.
============= FINISH: 19:12:35.27 ===============
Last week my Netbook was infected by one of the variants of Win 7 Home Security after visiting a website which I have regularly visited before without being infected. I was not able to browse to webpages and several messages popped up in the taskbar. I followed the instructions on the following website to remove the infection: http://www.bleepingcomputer.com/virus-removal/remove-win-7-internet-security-2011. Afterwards I scanned with Spybot S&D as well as with Malwarebytes' Anti Malware, and both scans came up clean. I was again able to browse to webpages and there were no longer pop-ups.
Today I scanned again with Spybot S&D and it found the following infection: Fraud.InternetSecurity2011. I am still able to browse and there are no pop-ups.
I would greatly appreciate any help in removing this infection. Please find the results of the Spybot S&D scan and DDS.txt log below.
Husky_
--------------------------------------------------------------------------
Fraud.InternetSecurity2011: [SBI $75AFFB3E] Executable (File, nothing done)
C:\Users\Dieter\AppData\Local\dnk.exe
Properties.size=335872
Properties.md5=0BA3FB8171D7F60B2FD1C8187B69F721
Properties.filedate=1301416442
Properties.filedatetext=2011-03-29 17:34:02
Fraud.InternetSecurity2011: [SBI $75AFFB3E] Executable (File, nothing done)
C:\Users\Dieter\AppData\Local\fsx.exe
Properties.size=335872
Properties.md5=0BA3FB8171D7F60B2FD1C8187B69F721
Properties.filedate=1301416426
Properties.filedatetext=2011-03-29 17:33:46
Fraud.InternetSecurity2011: [SBI $75AFFB3E] Executable (File, nothing done)
C:\Users\Dieter\AppData\Local\gre.exe
Properties.size=335872
Properties.md5=0BA3FB8171D7F60B2FD1C8187B69F721
Properties.filedate=1301416443
Properties.filedatetext=2011-03-29 17:34:02
Fraud.InternetSecurity2011: [SBI $75AFFB3E] Executable (File, nothing done)
C:\Users\Dieter\AppData\Local\lud.exe
Properties.size=335872
Properties.md5=0BA3FB8171D7F60B2FD1C8187B69F721
Properties.filedate=1301416428
Properties.filedatetext=2011-03-29 17:33:47
Fraud.InternetSecurity2011: [SBI $75AFFB3E] Executable (File, nothing done)
C:\Users\Dieter\AppData\Local\mvt.exe
Properties.size=335872
Properties.md5=0BA3FB8171D7F60B2FD1C8187B69F721
Properties.filedate=1301416442
Properties.filedatetext=2011-03-29 17:34:02
Fraud.InternetSecurity2011: [SBI $75AFFB3E] Executable (File, nothing done)
C:\Users\Dieter\AppData\Local\psu.exe
Properties.size=335872
Properties.md5=0BA3FB8171D7F60B2FD1C8187B69F721
Properties.filedate=1301416429
Properties.filedatetext=2011-03-29 17:33:48
Fraud.InternetSecurity2011: [SBI $07CC9A4D] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Start
Fraud.InternetSecurity2011: [SBI $61C84F7D] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Start
Fraud.InternetSecurity2011: [SBI $F5EC9C27] Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2011-03-29 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2011-03-18 Includes\Adware.sbi (*)
2011-03-22 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-03-08 Includes\DialerC.sbi (*)
2011-02-24 Includes\HeavyDuty.sbi (*)
2011-03-29 Includes\Hijackers.sbi (*)
2011-03-29 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2011-03-08 Includes\KeyloggersC.sbi (*)
2011-04-05 Includes\Malware.sbi (*)
2011-04-05 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2011-03-15 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2011-03-08 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2011-02-24 Includes\Spyware.sbi (*)
2011-03-15 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-12-28 Includes\Trojans.sbi (*)
2011-04-05 Includes\TrojansC-02.sbi (*)
2011-03-29 Includes\TrojansC-03.sbi (*)
2011-03-08 Includes\TrojansC-04.sbi (*)
2011-04-06 Includes\TrojansC-05.sbi (*)
2011-03-08 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
--------------------------------------------------------------------------
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Dieter at 19:06:27.59 on 07/04/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Starter 6.1.7600.0.1252.44.1033.18.1013.312 [GMT 1:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\ThpSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Toshiba TEMPRO\TemproTray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TECO\Teco.exe
C:\Windows\System32\ThpSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskhost.exe
C:\Users\Dieter\Desktop\dds.scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://toshiba.msn.com
uDefault_Page_URL = hxxp://toshiba.msn.com
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [Toshiba TEMPRO] c:\program files\toshiba tempro\TemproTray.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [HWSetup] c:\program files\toshiba\utilities\HWSetup.exe hwSetUP
mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe
mRun: [SVPWUTIL] c:\program files\toshiba\utilities\SVPWUTIL.exe SVPwUTIL
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [TUSBSleepChargeSrv] %ProgramFiles%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
mRun: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
mRun: [ThpSrv] c:\windows\system32\thpsrv /logon
mRun: [ToshibaServiceStation] c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe /hide:60
mRun: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
mRun: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
mRun: [TosVolRegulator] c:\program files\toshiba\tosvolregulator\TosVolRegulator.exe
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [MobileBroadband] c:\program files\vodafone\vodafone mobile broadband\bin\MobileBroadband.exe /silent
dRun: [TOSHIBA Online Product Information] c:\program files\toshiba\toshiba online product information\topi.exe
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporteren naar Microsoft Excel - c:\progra~1\mif5ba~1\office10\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
TCP: {12FB4F37-C77A-4FEC-9919-0A2E572F53BF} = 10.206.65.68 10.206.65.68
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\dieter\appdata\roaming\mozilla\firefox\profiles\pfk4j8za.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content
FF - component: c:\users\dieter\appdata\roaming\mozilla\firefox\profiles\pfk4j8za.default\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Xmarks: foxmarks@kei.com - %profile%\extensions\foxmarks@kei.com
FF - Ext: Full Fullscreen: {bfe3406c-6f31-4789-86d5-efa50e12c9eb} - %profile%\extensions\{bfe3406c-6f31-4789-86d5-efa50e12c9eb}
FF - Ext: Add Bookmark Here ²: abhere2@moztw.org - %profile%\extensions\abhere2@moztw.org
FF - Ext: Tiny Menu: {d33c2f7c-b1e6-4d46-ab0e-be1f6d05c904} - %profile%\extensions\{d33c2f7c-b1e6-4d46-ab0e-be1f6d05c904}
FF - Ext: rein: rein@notiz.jp - %profile%\extensions\rein@notiz.jp
FF - Ext: Speed Dial: {64161300-e22b-11db-8314-0800200c9a66} - %profile%\extensions\{64161300-e22b-11db-8314-0800200c9a66}
FF - Ext: British English Dictionary: en-GB@dictionaries.addons.mozilla.org - %profile%\extensions\en-GB@dictionaries.addons.mozilla.org
FF - Ext: Woordenboek Nederlands: nl-NL@dictionaries.addons.mozilla.org - %profile%\extensions\nl-NL@dictionaries.addons.mozilla.org
FF - Ext: Toolbar Buttons: {03B08592-E5B4-45ff-A0BE-C1D975458688} - %profile%\extensions\{03B08592-E5B4-45ff-A0BE-C1D975458688}
FF - Ext: Download Statusbar: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} - %profile%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
FF - Ext: deskCut: {9125C9CB-BE2B-4389-A0C7-46A4BDD46AEA} - %profile%\extensions\{9125C9CB-BE2B-4389-A0C7-46A4BDD46AEA}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: FoxyTunes: {463F6CA5-EE3C-4be1-B7E6-7FEE11953374} - %profile%\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
FF - Ext: Pimpoflage: pimpoflage@ffpimp.com - %profile%\extensions\pimpoflage@ffpimp.com
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-3-29 64512]
R0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\drivers\thpdrv.sys [2009-6-29 30272]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\drivers\Thpevm.sys [2009-6-29 13120]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-29 371544]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-3-29 301528]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-3-29 19544]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-3-29 53592]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-3-29 42184]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2010-1-28 185712]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2010-4-6 189808]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-19 12920]
R2 VmbService;Vodafone Mobile Broadband Service;c:\program files\vodafone\vodafone mobile broadband\bin\VmbService.exe [2010-8-18 8704]
R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2010-10-24 24064]
R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2010-10-24 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2010-2-5 111960]
R3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2010-3-31 685424]
R3 vodafone_K380x-z_dc_enum;vodafone_K380x-z_dc_enum;c:\windows\system32\drivers\vodafone_K380x-z_dc_enum.sys [2010-5-20 61952]
R3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\drivers\zteusbvoice.sys [2011-3-31 105856]
R3 ZTEusbwwan;ZTE MBN Miniport;c:\windows\system32\drivers\ZTEusbwwan.sys [2011-3-31 194048]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-3-29 1405384]
S3 massfilter;MBB Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2011-3-31 9216]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2010-10-24 189984]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-5-20 277536]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\toshiba tempro\TemproSvc.exe [2010-2-11 124368]
.
=============== Created Last 30 ================
.
2011-04-07 15:28:27 -------- d-----w- c:\users\dieter\appdata\roaming\Disk Cleaner
2011-03-31 20:32:53 -------- d-----w- c:\users\dieter\appdata\roaming\FLEXnet
2011-03-31 20:25:27 -------- d-----w- c:\users\dieter\appdata\roaming\Vodafone
2011-03-31 20:25:07 194048 ----a-w- c:\windows\system32\drivers\ZTEusbwwan.sys
2011-03-31 20:25:06 105856 ----a-w- c:\windows\system32\drivers\zteusbvoice.sys
2011-03-31 20:25:02 105856 ----a-w- c:\windows\system32\drivers\ZTEusbnmea.sys
2011-03-31 20:24:58 105856 ----a-w- c:\windows\system32\drivers\ZTEusbmdm6k.sys
2011-03-31 20:24:56 105856 ----a-w- c:\windows\system32\drivers\ZTEusbser6k.sys
2011-03-31 20:24:55 9216 ----a-w- c:\windows\system32\drivers\massfilter.sys
2011-03-31 20:24:09 -------- d-----w- c:\progra~2\Vodafone
2011-03-31 20:24:00 -------- d-----w- c:\program files\Vodafone
2011-03-31 20:22:56 -------- d-----w- c:\users\dieter\appdata\local\{F3E8BCCE-24B6-4737-920E-0D6073630E2A}
2011-03-29 22:41:39 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-03-29 22:41:39 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-03-29 22:41:39 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-03-29 22:41:38 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-03-29 22:41:38 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-03-29 22:27:36 293376 ----a-w- c:\windows\system32\browserchoice.exe
2011-03-29 22:23:29 316928 ----a-w- c:\windows\system32\spoolsv.exe
2011-03-29 22:23:27 516096 ----a-w- c:\program files\windows mail\wab.exe
2011-03-29 22:23:26 314368 ----a-w- c:\windows\system32\webio.dll
2011-03-29 22:23:11 133720 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2011-03-29 22:23:11 1037312 ----a-w- c:\windows\system32\lsasrv.dll
2011-03-29 22:23:10 954752 ----a-w- c:\windows\system32\mfc40.dll
2011-03-29 22:23:09 954288 ----a-w- c:\windows\system32\mfc40u.dll
2011-03-29 22:23:04 164864 ----a-w- c:\program files\windows media player\wmplayer.exe
2011-03-29 22:23:02 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2011-03-29 22:21:59 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-29 22:19:50 363520 ----a-w- c:\windows\system32\StructuredQuery.dll
2011-03-29 22:19:06 132608 ----a-w- c:\windows\system32\cabview.dll
2011-03-29 22:15:22 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-03-29 22:15:22 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-03-29 22:15:22 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-03-29 22:14:56 101760 ----a-w- c:\windows\system32\consent.exe
2011-03-29 21:45:03 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-03-29 21:45:03 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-03-29 21:44:35 40648 ----a-w- c:\windows\avastSS.scr
2011-03-29 21:44:27 -------- d-----w- c:\program files\AVAST Software
2011-03-29 21:44:27 -------- d-----w- c:\progra~2\AVAST Software
2011-03-29 21:27:46 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-03-29 21:21:19 -------- dc-h--w- c:\progra~2\{E45B1D3E-BC46-46CA-AC1B-16932832F73E}
2011-03-29 21:20:54 -------- d-----w- c:\program files\Lavasoft
2011-03-29 19:20:56 -------- d-----w- c:\users\dieter\appdata\roaming\KeePass
2011-03-29 19:18:37 -------- d-----w- c:\program files\KeePass Password Safe
2011-03-29 18:23:03 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-03-29 18:23:03 -------- d-----w- c:\progra~2\Spybot - Search & Destroy
2011-03-29 17:42:20 -------- d-----w- c:\users\dieter\appdata\roaming\Malwarebytes
2011-03-29 17:42:15 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-29 17:42:14 -------- d-----w- c:\progra~2\Malwarebytes
2011-03-29 17:42:12 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-29 17:42:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-29 16:34:02 335872 --sha-w- c:\users\dieter\appdata\local\mvt.exe
2011-03-29 16:34:02 335872 --sha-w- c:\users\dieter\appdata\local\gre.exe
2011-03-29 16:34:02 335872 --sha-w- c:\users\dieter\appdata\local\dnk.exe
2011-03-29 16:33:48 335872 --sha-w- c:\users\dieter\appdata\local\psu.exe
2011-03-29 16:33:47 335872 --sha-w- c:\users\dieter\appdata\local\lud.exe
2011-03-29 16:33:46 335872 --sha-w- c:\users\dieter\appdata\local\fsx.exe
2011-03-26 10:27:05 -------- d-----w- c:\program files\CleanUp!
2011-03-26 10:26:53 -------- d-----w- c:\program files\Disk Cleaner
2011-03-26 10:26:19 -------- d-----w- c:\program files\CCleaner
2011-03-24 18:53:39 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2011-03-24 18:49:57 83249512 ----a-w- c:\program files\common files\windows live\.cache\wlc18C1.tmp
2011-03-24 18:46:53 14744 ----a-w- c:\users\dieter\appdata\roaming\microsoft\identitycrl\production\ppcrlconfig.dll
2011-03-24 18:46:33 -------- d-----w- c:\users\dieter\Tracing
2011-03-23 17:50:31 -------- d-----w- c:\users\dieter\appdata\local\CutePDF Writer
2011-03-23 08:14:01 -------- d-----w- c:\program files\GPLGS
2011-03-23 08:13:41 87552 ----a-w- c:\windows\system32\cpwmon2k.dll
2011-03-23 08:13:40 -------- d-----w- c:\program files\Acro Software
2011-03-22 18:38:12 12800 ----a-w- c:\program files\mozilla firefox\plugins\npwachk.dll
2011-03-22 07:56:33 -------- d-----w- c:\program files\SyncToy 2.1
2011-03-20 16:06:27 -------- d-----w- c:\users\dieter\appdata\local\Thunderbird
2011-03-20 14:58:21 -------- d-----w- c:\program files\SopCast
2011-03-12 12:28:40 103864 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2011-03-09 06:31:28 232448 ----a-w- c:\windows\system32\mp3fhg.acm
2011-03-09 06:31:27 810496 ----a-w- c:\windows\system32\xvidcore.dll
2011-03-09 06:31:27 237568 ----a-w- c:\windows\system32\yv12vfw.dll
2011-03-09 06:31:27 183808 ----a-w- c:\windows\system32\xvidvfw.dll
2011-03-09 06:31:27 151552 ----a-w- c:\windows\system32\ac3acm.acm
2011-03-09 06:31:26 80896 ----a-w- c:\windows\system32\ff_vfw.dll
2011-03-09 06:31:21 -------- d-----w- c:\program files\K-Lite Codec Pack
2011-03-09 06:28:09 -------- d-----w- c:\progra~2\DivX
.
==================== Find3M ====================
.
.
============= FINISH: 19:12:35.27 ===============