Additional Logs
Here are the logs for the MBR Check and Combofix...thanks again for your help! Let me know what I should do next.
MBR Check
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Business Edition
Windows Information: Service Pack 1 (build 6001), 32-bit
Base Board Manufacturer: TOSHIBA
BIOS Manufacturer: TOSHIBA
System Manufacturer: TOSHIBA
System Product Name: ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ
Logical Drives Mask: 0x0000000c
Kernel Drivers (total 157):
0x8283E000 \SystemRoot\system32\ntoskrnl.exe
0x8280B000 \SystemRoot\system32\hal.dll
0x83009000 \SystemRoot\system32\kdcom.dll
0x83011000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x83071000 \SystemRoot\system32\PSHED.dll
0x83082000 \SystemRoot\system32\BOOTVID.dll
0x8308A000 \SystemRoot\system32\CLFS.SYS
0x830CB000 \SystemRoot\system32\CI.dll
0x831AB000 \SystemRoot\system32\drivers\Wdf01000.sys
0x83227000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x83234000 \SystemRoot\system32\drivers\acpi.sys
0x8327A000 \SystemRoot\system32\drivers\WMILIB.SYS
0x83283000 \SystemRoot\system32\drivers\msisadrv.sys
0x8328B000 \SystemRoot\system32\drivers\pci.sys
0x832B2000 \SystemRoot\System32\drivers\partmgr.sys
0x832C1000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x832C4000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x832CE000 \SystemRoot\system32\drivers\volmgr.sys
0x832DD000 \SystemRoot\System32\drivers\volmgrx.sys
0x83327000 \SystemRoot\system32\drivers\intelide.sys
0x8332E000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x8333C000 \SystemRoot\System32\drivers\mountmgr.sys
0x8334C000 \SystemRoot\system32\drivers\atapi.sys
0x83354000 \SystemRoot\system32\drivers\ataport.SYS
0x83372000 \SystemRoot\system32\drivers\fltmgr.sys
0x833A4000 \SystemRoot\system32\drivers\fileinfo.sys
0x833B4000 \SystemRoot\System32\Drivers\PxHelp20.sys
0x8840F000 \SystemRoot\System32\Drivers\ksecdd.sys
0x88480000 \SystemRoot\system32\drivers\ndis.sys
0x8858B000 \SystemRoot\system32\drivers\msrpc.sys
0x885B6000 \SystemRoot\system32\drivers\NETIO.SYS
0x885F0000 \SystemRoot\System32\drivers\tcpip.sys
0x886DA000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x88807000 \SystemRoot\System32\Drivers\Ntfs.sys
0x88916000 \SystemRoot\system32\drivers\volsnap.sys
0x8894F000 \SystemRoot\system32\DRIVERS\TVALZ_O.SYS
0x88954000 \SystemRoot\system32\DRIVERS\tos_sps32.sys
0x8899F000 \SystemRoot\system32\DRIVERS\Thpevm.SYS
0x889A1000 \SystemRoot\system32\DRIVERS\thpdrv.sys
0x889AB000 \SystemRoot\System32\Drivers\spldr.sys
0x889B3000 \SystemRoot\System32\Drivers\mup.sys
0x889C2000 \SystemRoot\System32\drivers\ecache.sys
0x889E9000 \SystemRoot\system32\drivers\disk.sys
0x889FA000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x88A1B000 \SystemRoot\system32\drivers\crcdisk.sys
0x88A44000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x88A4F000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x88A58000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8CC05000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x8D1EB000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8D28A000 \SystemRoot\System32\drivers\watchdog.sys
0x8D297000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8D2A9000 \SystemRoot\system32\DRIVERS\Rtlh86.sys
0x8D400000 \SystemRoot\system32\DRIVERS\NETw4v32.sys
0x8D627000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8D632000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8D670000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8D67F000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x8D68F000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x8D69D000 \SystemRoot\system32\DRIVERS\sdbus.sys
0x8D6B7000 \SystemRoot\system32\DRIVERS\rimmptsk.sys
0x8D6C6000 \SystemRoot\system32\DRIVERS\rimsptsk.sys
0x8D6DA000 \SystemRoot\system32\DRIVERS\rixdptsk.sys
0x8D72B000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8D73E000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8D749000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8D774000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8D776000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8D781000 \SystemRoot\system32\DRIVERS\tdcmdpst.sys
0x8D785000 \SystemRoot\system32\drivers\Afc.sys
0x8D78E000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8D7A7000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0x8D7AD000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8D7B1000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8D7BA000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8D2C0000 \SystemRoot\system32\DRIVERS\storport.sys
0x8D7E8000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8D301000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8D7F3000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8D318000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8D33B000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8D34A000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8D35E000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8D373000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0x88A67000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8D7FE000 \SystemRoot\system32\DRIVERS\swenum.sys
0x88A77000 \SystemRoot\system32\DRIVERS\ks.sys
0x88AA1000 \SystemRoot\system32\DRIVERS\QIOMem.sys
0x88AAA000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x88AB4000 \SystemRoot\system32\DRIVERS\umbus.sys
0x88AC1000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x88AF5000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x8DC01000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x8DDB2000 \SystemRoot\system32\drivers\portcls.sys
0x8DDDF000 \SystemRoot\system32\drivers\drmk.sys
0x8DE04000 \SystemRoot\system32\DRIVERS\AGRSM.sys
0x8DEFF000 \SystemRoot\system32\drivers\modem.sys
0x8DF0C000 \SystemRoot\system32\DRIVERS\MpFilter.sys
0x8DF33000 \SystemRoot\System32\Drivers\Cdr4_xp.SYS
0x8DF34000 \SystemRoot\System32\Drivers\Cdralw2k.SYS
0x8DF35000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8DF3E000 \SystemRoot\System32\Drivers\Null.SYS
0x8DF45000 \SystemRoot\System32\Drivers\Beep.SYS
0x8DF4C000 \SystemRoot\System32\drivers\vga.sys
0x8DF58000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8DF79000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8DF81000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8DF89000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8DF94000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8DFA2000 \SystemRoot\System32\Drivers\tcusb.sys
0x8DFAA000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8DFB3000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8DFC9000 \SystemRoot\system32\DRIVERS\smb.sys
0x88B06000 \SystemRoot\system32\drivers\afd.sys
0x88B4E000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8DFDD000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x88B80000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8DFF4000 \SystemRoot\System32\Drivers\UVCFTR_S.SYS
0x88B96000 \SystemRoot\system32\DRIVERS\netbios.sys
0x88BA4000 \SystemRoot\System32\Drivers\usbvideo.sys
0x88BC5000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x886F5000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x88BD8000 \SystemRoot\system32\drivers\nsiproxy.sys
0x88731000 \SystemRoot\system32\drivers\csc.sys
0x88BE2000 \SystemRoot\System32\Drivers\dfsc.sys
0x88A24000 \SystemRoot\System32\Drivers\crashdmp.sys
0x88A31000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x88A3C000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x81470000 \SystemRoot\System32\win32k.sys
0x8878B000 \SystemRoot\System32\drivers\Dxapi.sys
0x88795000 \SystemRoot\system32\DRIVERS\monitor.sys
0x81690000 \SystemRoot\System32\TSDDD.dll
0x816B0000 \SystemRoot\System32\cdd.dll
0x887A4000 \SystemRoot\system32\drivers\luafv.sys
0x887C7000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x833BD000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x887D7000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x887E1000 \SystemRoot\system32\DRIVERS\rspndr.sys
0xAE004000 \SystemRoot\system32\drivers\spsys.sys
0xAE0B3000 \SystemRoot\system32\drivers\HTTP.sys
0xAE120000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xAE13D000 \SystemRoot\system32\DRIVERS\bowser.sys
0xAE156000 \SystemRoot\System32\drivers\mpsdrv.sys
0xAE16B000 \SystemRoot\system32\drivers\mrxdav.sys
0xAE18B000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xAE1AA000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xAE1E3000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xAE1FB000 \SystemRoot\System32\DRIVERS\srv2.sys
0xAE223000 \SystemRoot\System32\DRIVERS\srv.sys
0xAE289000 \SystemRoot\system32\drivers\peauth.sys
0xAE367000 \SystemRoot\System32\Drivers\secdrv.SYS
0xAE371000 \SystemRoot\System32\drivers\tcpipreg.sys
0xAE37D000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xAE393000 \SystemRoot\system32\DRIVERS\MpNWMon.sys
0xAE39D000 \SystemRoot\system32\DRIVERS\NisDrvWFP.sys
0xAE3A9000 \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{35EFA37D-BD7D-4A56-A4AF-2F43D27C11D8}\MpKsl9ae90f9c.sys
0x774C0000 \Windows\System32\ntdll.dll
Processes (total 71):
0 System Idle Process
4 System
504 C:\Windows\System32\smss.exe
636 csrss.exe
680 csrss.exe
688 C:\Windows\System32\wininit.exe
736 C:\Windows\System32\winlogon.exe
768 C:\Windows\System32\services.exe
780 C:\Windows\System32\lsass.exe
788 C:\Windows\System32\lsm.exe
932 C:\Windows\System32\svchost.exe
976 C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
1024 C:\Windows\System32\svchost.exe
1060 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
1204 C:\Windows\System32\svchost.exe
1236 C:\Windows\System32\svchost.exe
1256 C:\Windows\System32\svchost.exe
1360 C:\Windows\System32\audiodg.exe
1380 C:\Windows\System32\svchost.exe
1400 C:\Windows\System32\SLsvc.exe
1496 C:\Windows\System32\svchost.exe
1620 C:\Windows\System32\svchost.exe
1820 C:\Program Files\Protector Suite QL\upeksvr.exe
1916 C:\Windows\System32\wlanext.exe
328 C:\Windows\System32\spoolsv.exe
356 C:\Windows\System32\svchost.exe
1808 C:\Windows\System32\taskeng.exe
496 C:\Windows\System32\agrsmsvc.exe
1568 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1956 C:\Windows\System32\taskeng.exe
2104 C:\Windows\System32\dwm.exe
2136 C:\Windows\explorer.exe
2300 C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
2332 C:\Program Files\Bonjour\mDNSResponder.exe
2364 C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
2480 C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
2652 C:\Program Files\iTunes\iTunesHelper.exe
2688 C:\Program Files\Microsoft Security Client\msseces.exe
2704 C:\Windows\System32\svchost.exe
2728 C:\Windows\System32\svchost.exe
2780 C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
2836 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
2920 C:\Toshiba\IVP\ISM\pinger.exe
2932 C:\Windows\System32\svchost.exe
2944 C:\Windows\System32\svchost.exe
2956 C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
3032 C:\Program Files\SafeConnect\scManager.sys
3240 C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
3284 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
3304 C:\Windows\System32\svchost.exe
3316 C:\Toshiba\IVP\swupdate\swupdtmr.exe
3380 C:\Windows\System32\ThpSrv.exe
3432 C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
3448 C:\Windows\System32\TODDSrv.exe
3472 C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
3532 C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
3560 C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
3584 C:\Program Files\Viewpoint\Common\ViewpointService.exe
3604 C:\Windows\System32\WebUpdateSvc4.exe
3744 C:\Windows\System32\svchost.exe
3764 C:\Windows\System32\SearchIndexer.exe
3972 C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
1212 C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
2180 C:\Program Files\iPod\bin\iPodService.exe
3636 C:\Program Files\Mozilla Firefox\firefox.exe
4668 C:\Windows\System32\SearchProtocolHost.exe
5572 WmiPrvSE.exe
5744 C:\Windows\System32\wuauclt.exe
5900 C:\Windows\servicing\TrustedInstaller.exe
6096 C:\Windows\explorer.exe
1880 C:\Users\Tiffany\Downloads\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`5dd00000 (NTFS)
PhysicalDrive0 Model Number: TOSHIBAMK1237GSX, Rev: DL130M
Size Device Name MBR Status
--------------------------------------------
111 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: BBAD517F7EAC529451E4B9586C847AE190574F61
Done!
Combo Fix
ComboFix 11-02-08.02 - Tiffany 02/08/2011 21:31:49.1.2 - x86
Microsoft® Windows Vista™ Business 6.0.6001.1.1252.1.1033.18.2037.1147 [GMT -5:00]
Running from: c:\users\Tiffany\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Tiffany\AppData\Local\{1C1E0EDB-A408-4B52-A8B3-75065321C272}
c:\users\Tiffany\AppData\Local\{1C1E0EDB-A408-4B52-A8B3-75065321C272}\chrome.manifest
c:\users\Tiffany\AppData\Local\{1C1E0EDB-A408-4B52-A8B3-75065321C272}\chrome\content\_cfg.js
c:\users\Tiffany\AppData\Local\{1C1E0EDB-A408-4B52-A8B3-75065321C272}\chrome\content\overlay.xul
c:\users\Tiffany\AppData\Local\{1C1E0EDB-A408-4B52-A8B3-75065321C272}\install.rdf
.
((((((((((((((((((((((((( Files Created from 2011-01-09 to 2011-02-09 )))))))))))))))))))))))))))))))
.
2011-02-09 02:46 . 2011-02-09 02:53 -------- d-----w- c:\users\Tiffany\AppData\Local\temp
2011-02-09 02:46 . 2011-02-09 02:46 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-08 14:28 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2011-02-08 13:10 . 2011-01-20 15:39 5890896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{35EFA37D-BD7D-4A56-A4AF-2F43D27C11D8}\mpengine.dll
2011-02-07 23:46 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2011-02-07 23:40 . 2010-11-02 04:26 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2011-02-07 23:40 . 2010-11-02 05:57 109056 ----a-w- c:\windows\system32\iesysprep.dll
2011-02-07 23:40 . 2010-11-02 05:57 743424 ----a-w- c:\program files\Internet Explorer\iedvtool.dll
2011-02-07 23:40 . 2010-11-02 05:57 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-02-07 23:40 . 2011-02-07 23:40 -------- d-----w- c:\programdata\Norton
2011-02-07 23:40 . 2010-11-02 06:03 638232 ----a-w- c:\program files\Internet Explorer\iexplore.exe
2011-02-07 23:40 . 2011-02-08 02:36 -------- d-----w- c:\users\Tiffany\AppData\Local\NPE
2011-02-07 23:35 . 2009-03-08 11:35 144384 ----a-w- c:\program files\Internet Explorer\ExtExport.exe
2011-02-07 23:35 . 2009-03-08 11:35 521216 ----a-w- c:\program files\Internet Explorer\jsdbgui.dll
2011-02-07 23:35 . 2009-03-08 11:34 115712 ----a-w- c:\program files\Internet Explorer\ielowutil.exe
2011-02-07 23:35 . 2009-03-08 11:33 256000 ----a-w- c:\program files\Internet Explorer\ieinstal.exe
2011-02-07 23:03 . 2011-02-07 23:03 -------- dc----w- c:\programdata\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
2011-01-27 12:25 . 2011-01-20 15:39 5890896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-01-26 03:29 . 2010-11-30 15:43 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{14C3B98F-6AA1-4851-B7EB-51AF016B0B4F}\gapaengine.dll
2011-01-26 03:28 . 2011-01-13 09:41 5890896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{60BEC95C-5755-4A1F-A6D4-C7900BBDAA63}\mpengine.dll
2011-01-26 03:11 . 2011-01-26 03:12 -------- d-----w- c:\program files\Microsoft Security Client
2011-01-26 01:34 . 2011-02-09 01:56 -------- d-----w- c:\programdata\Alwil Software
2011-01-26 01:34 . 2011-01-26 01:34 -------- d-----w- c:\program files\Alwil Software
2011-01-26 01:17 . 2011-02-08 12:56 -------- d-----w- c:\program files\Windows Live Safety Center
2011-01-25 13:06 . 2011-01-25 13:06 -------- d-----w- c:\users\Tiffany\AppData\Roaming\Malwarebytes
2011-01-25 13:06 . 2011-01-25 13:06 -------- d-----w- c:\programdata\Malwarebytes
2011-01-25 13:06 . 2010-12-20 23:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-25 13:06 . 2011-01-25 13:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-25 13:06 . 2010-12-20 23:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-12 03:05 . 2010-12-28 14:57 409600 ----a-w- c:\windows\system32\odbc32.dll
2011-01-12 03:05 . 2010-12-28 14:56 708608 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2011-01-12 03:05 . 2010-12-28 14:56 57344 ----a-w- c:\program files\Common Files\System\msadc\msadcs.dll
2011-01-12 03:05 . 2010-12-28 14:56 253952 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
2011-01-12 03:05 . 2010-12-28 14:56 241664 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2011-01-12 03:05 . 2010-12-28 14:56 180224 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
2011-01-12 03:05 . 2010-12-14 15:49 1169408 ----a-w- c:\windows\system32\sdclt.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-10 23:29 . 2010-12-10 23:29 64864 ----a-w- c:\windows\system32\sqlctr90.dll
2010-12-10 23:29 . 2010-12-10 23:29 2248032 ----a-w- c:\windows\system32\sqlncli.dll
2010-12-05 03:32 . 2010-12-05 03:16 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-12-05 03:09 . 2010-10-26 18:38 0 ----a-w- c:\users\Tiffany\AppData\Local\Pjamarusaneyul.bin
2010-11-29 22:38 . 2010-11-29 22:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 22:38 . 2010-11-29 22:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2006-12-04 00:03 2854912 ----a-w- c:\program files\Protector Suite QL\farchns.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2006-12-04 00:03 2854912 ----a-w- c:\program files\Protector Suite QL\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2007-04-20 430080]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-26 39408]
"Google Update"="c:\users\Tiffany\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-12-26 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
"HideFastUserSwitching"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"UseDefaultTile"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2006-12-03 23:50 90112 ----a-w- c:\windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SafeConnect.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SafeConnect.lnk
backup=c:\windows\pss\SafeConnect.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Tiffany^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Tiffany\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ThpSrv]
c:\windows\system32\thpsrv [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-12 02:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
2009-05-19 05:23 49968 ----a-w- c:\program files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2009-08-13 19:51 177440 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Assistant Software]
2007-04-10 23:40 413696 ----a-w- c:\program files\Camera Assistant Software for Toshiba\traybar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2007-05-17 02:14 1862144 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-12-26 23:15 133104 ----atw- c:\users\Tiffany\AppData\Local\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2007-04-04 22:26 154392 ----a-w- c:\windows\System32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-12-11 01:52 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2007-04-04 22:26 138008 ----a-w- c:\windows\System32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 22:16 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-02-04 21:57 4363504 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2007-04-04 22:26 133912 ----a-w- c:\windows\System32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSQLLauncher]
2006-12-03 23:29 49168 ----a-w- c:\program files\Protector Suite QL\launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2007-05-19 00:11 4472832 ----a-w- c:\windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
2007-05-25 23:56 1826816 ----a-w- c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 15:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-12-26 23:06 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2006-10-27 20:50 815104 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
R1 MpKsl0297f395;MpKsl0297f395;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{35EFA37D-BD7D-4A56-A4AF-2F43D27C11D8}\MpKsl0297f395.sys [x]
R1 MpKsl394cf97b;MpKsl394cf97b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6C439268-F526-44CF-A45F-65F15EB48829}\MpKsl394cf97b.sys [x]
R1 MpKsl9ae90f9c;MpKsl9ae90f9c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{35EFA37D-BD7D-4A56-A4AF-2F43D27C11D8}\MpKsl9ae90f9c.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
R2 SSIRuntimeService;SSIRuntimeService;c:\program files\Software Secure, Inc\SSIRuntimeService\SSIRuntimeService.exe [x]
R3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2010-12-05 16968]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [2007-04-27 21504]
S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [2007-02-08 6528]
S2 SCManager;SafeConnect Manager;c:\program files\SafeConnect\scManager.sys servicestart [x]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S2 WebUpdate4;Web Update Wizard Service V4;c:\windows\system32\WebUpdateSvc4.exe [2007-05-18 229856]
S3 QIOMem;Generic IO & Memory Access;c:\windows\system32\DRIVERS\QIOMem.sys [2007-04-09 8192]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 13:22]
2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 13:22]
2011-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-940564989-2044836176-4183550111-1003Core.job
- c:\users\Tiffany\AppData\Local\Google\Update\GoogleUpdate.exe [2008-12-26 23:15]
2011-02-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-940564989-2044836176-4183550111-1003UA.job
- c:\users\Tiffany\AppData\Local\Google\Update\GoogleUpdate.exe [2008-12-26 23:15]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.toshibadirect.com/dpdstart
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
Trusted Zone: brownrudnick.com\citrix
DPF: {15E31F81-702C-48F8-97B1-75AE9155B5E3} - hxxp://remote.lw.com/TSWebCtl.CAB
DPF: {26B2A5DA-BFD6-422F-A89A-28A54C74B12B} - hxxp://www.costcophotocenter.com/upload/activex/v3_0_0_4/PhotoCenter_ActiveX_Control.cab
FF - ProfilePath - c:\users\Tiffany\AppData\Roaming\Mozilla\Firefox\Profiles\penvdabz.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-00TCrdMain - %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-HSON - %ProgramFiles%\TOSHIBA\TBS\HSON.exe
MSConfigStartUp-NDSTray - NDSTray.exe
MSConfigStartUp-SmoothView - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
MSConfigStartUp-TPwrMain - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
MSConfigStartUp-vptray - c:\progra~1\SYMANT~1\VPTray.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-02-08 21:53
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i?????%:t> ?????X?8?X?p?X???X???
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(3580)
c:\program files\Protector Suite QL\farchns.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Protector Suite QL\upeksvr.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\toshiba\IVP\ISM\pinger.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\SafeConnect\scManager.sys
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\windows\system32\ThpSrv.exe
c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Toshiba\Power Saver\TosCoSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
.
**************************************************************************
.
Completion time: 2011-02-08 22:07:24 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-09 03:07
Pre-Run: 13,736,697,856 bytes free
Post-Run: 13,701,287,936 bytes free
- - End Of File - - DB5EF96C367338422A0930744CAFD6D6