i was successful in fixing all the bugs from the Smart HDD virus following your instruction manuals except for the google redirects. I have tried a number of fixes to solve it but none worked.
Note that the GMER scan came up with a nil report, hence no ark file is attached. Pls also note that it only aloowed me to check the boxes for services, registry, files and c:\
Thanks for your help!
Kind regards
Dan
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Chen at 15:56:58 on 2012-04-28
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.3559.1682 [GMT 10:00]
.
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\atieclxx.exe
C:\windows\system32\WLANExt.exe
C:\windows\system32\conhost.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Norton Internet Security\Engine\18.7.1.3\ccSvcHst.exe
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.202\SymcPCCULaunchSvc.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.202\ccSvcHst.exe
C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\windows\system32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\taskhost.exe
C:\Program Files (x86)\Norton Internet Security\Engine\18.7.1.3\ccSvcHst.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.202\ccSvcHst.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\TECO\Teco.exe
C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe
C:\Program Files (x86)\Toshiba\TOSHIBA Sleep Utility\TSleepSrv.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\windows\system32\taskeng.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\windows\system32\wuauclt.exe
C:\windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\windows\SysWOW64\Macromed\Flash\FlashUtil10n_ActiveX.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\windows\SysWOW64\cmd.exe
C:\windows\system32\conhost.exe
C:\windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.news.com.au/
uDefault_Page_URL = hxxp://toshiba.msn.com
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.1.3\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.1.3\IPS\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: ReImage Helper Verifier: {963b125b-8b21-49a2-a3a8-e37092276531} - C:\Program Files (x86)\ReImageCompanion\updatebhoWin32.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: ReImage Browser Helper: {a0e8bc7d-6959-40b6-8e05-204d9768ad6e} - C:\Program Files (x86)\ReImageCompanion\jsloader.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: TOSHIBA Media Controller Plug-in: {f3c88694-effa-4d78-b409-54b7b2535b14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.1.3\coIEPlg.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [adcbcaaefdacdct] "C:\ProgramData\adcbcaaefdacdct.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRun: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
mRun: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
mRun: [NortonOnlineBackup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun: [Browser companion helper] C:\Program Files (x86)\BrowserCompanion\BCHelper.exe /T=3 /CHI=gmdfpnpdmnjaffhcdbobdjpolhpacaem
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to TOSHIBA Bulletin Board - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll/1000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {97F922BD-8563-4184-87EE-8C4ACA438823} - {5D29E593-73A5-400A-B3BD-6B7A1AF05A31} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{BD2C892E-6EC1-4CD6-B39C-F402F96C8BF2} : DhcpNameServer = 192.168.1.254
Handler: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\ReImageCompanion\tdataprotocol.dll
Handler: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\ReImageCompanion\tdataprotocol.dll
Handler: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\ReImageCompanion\tdataprotocol.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.1.3\coIEPlg.dll
BHO-X64: Symantec NCO BHO - No File
BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.1.3\IPS\IPSBHO.DLL
BHO-X64: Symantec Intrusion Prevention - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: ReImage Helper Verifier: {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files (x86)\ReImageCompanion\updatebhoWin32.dll
BHO-X64: Update Timer - No File
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: ReImage Browser Helper: {a0e8bc7d-6959-40b6-8e05-204d9768ad6e} - C:\Program Files (x86)\ReImageCompanion\jsloader.dll
BHO-X64: script helper for ie - No File
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: TOSHIBA Media Controller Plug-in: {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.1.3\coIEPlg.dll
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRun-x64: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
mRun-x64: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
mRun-x64: [NortonOnlineBackup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
mRun-x64: [Browser companion helper] C:\Program Files (x86)\BrowserCompanion\BCHelper.exe /T=3 /CHI=gmdfpnpdmnjaffhcdbobdjpolhpacaem
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
============= SERVICES / DRIVERS ===============
.
R0 SymDS;Symantec Data Store;C:\windows\system32\drivers\NISx64\1207010.003\SYMDS64.SYS --> C:\windows\system32\drivers\NISx64\1207010.003\SYMDS64.SYS [?]
R0 SymEFA;Symantec Extended File Attributes;C:\windows\system32\drivers\NISx64\1207010.003\SYMEFA64.SYS --> C:\windows\system32\drivers\NISx64\1207010.003\SYMEFA64.SYS [?]
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\windows\system32\DRIVERS\tos_sps64.sys --> C:\windows\system32\DRIVERS\tos_sps64.sys [?]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\BASHDefs\20120413.001\BHDrvx64.sys [2012-4-20 1160824]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\Definitions\IPSDefs\20120427.001\IDSviA64.sys [2012-4-28 488568]
R1 SymIRON;Symantec Iron Driver;C:\windows\system32\drivers\NISx64\1207010.003\Ironx64.SYS --> C:\windows\system32\drivers\NISx64\1207010.003\Ironx64.SYS [?]
R1 SymNetS;Symantec Network Security WFP Driver;C:\windows\system32\Drivers\NISx64\1207010.003\SYMNETS.SYS --> C:\windows\system32\Drivers\NISx64\1207010.003\SYMNETS.SYS [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys --> C:\windows\system32\DRIVERS\vwififlt.sys [?]
R2 AMD External Events Utility;AMD External Events Utility;C:\windows\system32\atiesrxx.exe --> C:\windows\system32\atiesrxx.exe [?]
R2 cfWiMAXService;ConfigFree WiMAX Service;C:\Program Files (x86)\Toshiba\ConfigFree\CFIWmxSvcs64.exe [2010-1-29 249200]
R2 ConfigFree Service;ConfigFree Service;C:\Program Files (x86)\Toshiba\ConfigFree\CFSvcs.exe [2009-3-11 46448]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-4-16 654408]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\18.7.1.3\ccsvchst.exe [2012-4-16 130008]
R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe service --> C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe service [?]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.202\SymcPCCULaunchSvc.exe [2012-4-15 103792]
R2 PCCUJobMgr;Common Client Job Manager Service;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.202\ccSvcHst.exe [2012-4-15 126392]
R2 regi;regi;\??\C:\windows\system32\drivers\regi.sys --> C:\windows\system32\drivers\regi.sys [?]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]
R2 SpyHunter 4 Service;SpyHunter 4 Service;C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [2012-1-18 995744]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\Toshiba\TECO\TecoService.exe [2011-4-8 294328]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\windows\system32\DRIVERS\TVALZFL.sys --> C:\windows\system32\DRIVERS\TVALZFL.sys [?]
R3 amdkmdag;amdkmdag;C:\windows\system32\DRIVERS\atikmdag.sys --> C:\windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\windows\system32\DRIVERS\atikmpag.sys --> C:\windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\windows\system32\drivers\AtihdW76.sys --> C:\windows\system32\drivers\AtihdW76.sys [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-4-16 138360]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\windows\system32\DRIVERS\L1C62x64.sys --> C:\windows\system32\DRIVERS\L1C62x64.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\windows\system32\drivers\mbam.sys --> C:\windows\system32\drivers\mbam.sys [?]
R3 PGEffect;Pangu effect driver;C:\windows\system32\DRIVERS\pgeffect.sys --> C:\windows\system32\DRIVERS\pgeffect.sys [?]
R3 QIOMem;Generic IO & Memory Access;C:\windows\system32\DRIVERS\QIOMem.sys --> C:\windows\system32\DRIVERS\QIOMem.sys [?]
R3 Sftfs;Sftfs;C:\windows\system32\DRIVERS\Sftfslh.sys --> C:\windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\windows\system32\DRIVERS\Sftplaylh.sys --> C:\windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\windows\system32\DRIVERS\Sftredirlh.sys --> C:\windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\windows\system32\DRIVERS\Sftvollh.sys --> C:\windows\system32\DRIVERS\Sftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]
R3 TMachInfo;TMachInfo;C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe [2012-4-15 54136]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-12-9 137632]
R3 TPCHSrv;TPCH Service;C:\Program Files\Toshiba\TPHM\TPCHSrv.exe [2011-7-2 828856]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-3-2 183560]
S3 BtFilter;Bluetooth LowerFilter Class Filter Driver;C:\windows\system32\DRIVERS\btfilter.sys --> C:\windows\system32\DRIVERS\btfilter.sys [?]
S3 fssfltr;fssfltr;C:\windows\system32\DRIVERS\fssfltr.sys --> C:\windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-13 206072]
S3 OlmarikFixer;Olmarik fixer kernel-mode driver;\??\C:\windows\system32\drivers\OlmarikFixer.sys --> C:\windows\system32\drivers\OlmarikFixer.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\windows\system32\Drivers\RtsUStor.sys --> C:\windows\system32\Drivers\RtsUStor.sys [?]
S3 RSUSBVSTOR;RTSUVSTOR.Sys Realtek USB Card Reader;C:\windows\system32\Drivers\RTSUVSTOR.sys --> C:\windows\system32\Drivers\RTSUVSTOR.sys [?]
S3 SrvHsfHDA;SrvHsfHDA;C:\windows\system32\DRIVERS\VSTAZL6.SYS --> C:\windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\windows\system32\DRIVERS\VSTDPV6.SYS --> C:\windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys --> C:\windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys --> C:\windows\system32\drivers\TsUsbGD.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe --> C:\windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2012-04-28 05:20:25 -------- d-----w- C:\Users\Chen\AppData\Local\{38B993D1-F079-4512-B3B8-429E1CC2585F}
2012-04-28 05:12:01 -------- d-----w- C:\Users\Chen\AppData\Local\{600EB53C-EC07-4B08-9040-DB9698626CD6}
2012-04-28 01:11:07 -------- d-----w- C:\Users\Chen\AppData\Local\{07B7F389-4CB5-4CC1-B5EC-BD474F82A30A}
2012-04-27 12:37:03 -------- d-----w- C:\Users\Chen\AppData\Local\{46266ABA-E2F5-41FF-B1C0-8C29FC8DCC10}
2012-04-27 12:34:00 -------- d-----w- C:\TDSSKiller_Quarantine
2012-04-27 12:11:03 29000 ----a-w- C:\windows\System32\drivers\OlmarikFixer.sys
2012-04-27 10:46:23 110080 ----a-r- C:\Users\Chen\AppData\Roaming\Microsoft\Installer\{5B210B8A-B66E-4702-B44D-0D6F388D29EB}\IconF7A21AF7.exe
2012-04-27 10:46:23 110080 ----a-r- C:\Users\Chen\AppData\Roaming\Microsoft\Installer\{5B210B8A-B66E-4702-B44D-0D6F388D29EB}\IconD7F16134.exe
2012-04-27 10:46:23 110080 ----a-r- C:\Users\Chen\AppData\Roaming\Microsoft\Installer\{5B210B8A-B66E-4702-B44D-0D6F388D29EB}\Icon1226A4C5.exe
2012-04-27 10:46:23 -------- d-----w- C:\sh4ldr
2012-04-27 10:46:23 -------- d-----w- C:\Program Files\Enigma Software Group
2012-04-27 10:46:01 -------- d-----w- C:\windows\5B210B8AB66E4702B44D0D6F388D29EB.TMP
2012-04-27 10:45:58 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2012-04-27 09:58:34 -------- d-----w- C:\Users\Chen\AppData\Local\{4501426F-4B26-4528-B23E-3905DB84B493}
2012-04-26 10:27:44 -------- d-----w- C:\Users\Chen\AppData\Local\{0A69F058-5760-4E7B-8F67-2924418105F9}
2012-04-26 02:16:57 -------- d-----w- C:\Users\Chen\AppData\Local\Adobe
2012-04-26 00:13:13 -------- d-----w- C:\Users\Chen\AppData\Local\{F4250AD5-78B4-420E-946B-89C7D7999E7A}
2012-04-25 09:39:58 -------- d-----w- C:\Users\Chen\AppData\Local\{1B9CAE99-EB28-47DA-A23E-D7C3A9FD6BF6}
2012-04-25 08:28:36 537432 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\6850a2741cd22bd01\DXSETUP.exe
2012-04-25 08:28:36 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\68d12cc31cd22bd02\MeshBetaRemover.exe
2012-04-25 08:28:35 89944 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\6850a2741cd22bd01\DSETUP.dll
2012-04-25 08:28:35 1801048 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\6850a2741cd22bd01\dsetup32.dll
2012-04-25 08:28:25 -------- d-----w- C:\Users\Chen\AppData\Local\{87285B9E-4FEA-4AF3-8FE0-E21532721338}
2012-04-25 08:27:16 -------- d-----w- C:\Users\Chen\AppData\Local\{46FE0C69-0E00-4924-9699-545AF4F308E1}
2012-04-25 05:03:11 -------- d-----w- C:\Users\Chen\AppData\Local\{532C22E4-ECDD-4261-86F9-E9F2EA1D4AD5}
2012-04-24 22:02:32 -------- d-----w- C:\Users\Chen\AppData\Local\{B99F9843-91FD-4F4F-B805-F6CC2ECE06F6}
2012-04-24 13:03:09 -------- d-----w- C:\Users\Chen\AppData\Local\{80FCC312-E0F7-4707-AEC3-AC1B13D6637D}
2012-04-24 08:07:53 -------- d-----w- C:\Users\Chen\AppData\Local\Tific
2012-04-22 03:50:56 -------- d-----w- C:\Users\Chen\AppData\Local\{7DFC677B-D455-4190-A8D1-9C8403603604}
2012-04-22 01:01:05 -------- d-----w- C:\Users\Chen\AppData\Local\{4A8DFB3C-BE91-4A3F-B3D3-C167BC86A6BA}
2012-04-21 11:21:30 -------- d-----w- C:\Users\Chen\AppData\Local\{B29A6FA3-547A-4E63-A2C5-72013F65EA93}
2012-04-21 06:57:41 -------- d-----w- C:\Users\Chen\AppData\Local\{266369A8-F569-422C-A214-6D6AA66F8C3A}
2012-04-20 22:54:11 -------- d-----w- C:\Users\Chen\AppData\Local\{EB7DDF92-CD73-44F2-A80A-AFE68A9F32BC}
2012-04-20 10:33:38 -------- d-----w- C:\Users\Chen\AppData\Local\{696478B4-4700-40E7-9505-18A3CF5C5F79}
2012-04-19 10:50:38 -------- d-----w- C:\ProgramData\VirtualizedApplications
2012-04-19 09:35:12 -------- d-----w- C:\Users\Chen\AppData\Local\{572EA269-C8B0-4296-95A5-F994AFA2FE80}
2012-04-18 11:38:12 -------- d-----w- C:\Users\Chen\AppData\Roaming\SoftGrid Client
2012-04-18 11:38:12 -------- d-----w- C:\Users\Chen\AppData\Local\SoftGrid Client
2012-04-18 11:37:15 -------- d-----w- C:\Program Files (x86)\Microsoft Application Virtualization Client
2012-04-18 11:36:56 -------- d-----w- C:\Users\Chen\AppData\Roaming\TP
2012-04-18 10:54:50 -------- d-----w- C:\Users\Chen\AppData\Local\{8B2B324A-B2DC-4E3F-BD59-12B436AF71AC}
2012-04-16 22:23:07 -------- d-----w- C:\Users\Chen\AppData\Local\{FE3076B6-63E3-4870-A841-6875BCD5457E}
2012-04-16 11:41:40 -------- d-----w- C:\Users\Chen\AppData\Local\{42A031F3-8E4D-4B09-8677-668204A2EDC4}
2012-04-16 10:53:14 912504 ----a-w- C:\windows\System32\drivers\NISx64\1207010.003\symefa64.sys
2012-04-16 10:53:14 450680 ----a-w- C:\windows\System32\drivers\NISx64\1207010.003\symds64.sys
2012-04-16 10:53:14 386168 ----a-w- C:\windows\System32\drivers\NISx64\1207010.003\symnets.sys
2012-04-16 10:53:13 744568 ----a-w- C:\windows\System32\drivers\NISx64\1207010.003\srtsp64.sys
2012-04-16 10:53:13 40568 ----a-w- C:\windows\System32\drivers\NISx64\1207010.003\srtspx64.sys
2012-04-16 10:53:13 171128 ----a-w- C:\windows\System32\drivers\NISx64\1207010.003\ironx64.sys
2012-04-16 10:53:02 -------- d-----w- C:\windows\System32\drivers\NISx64\1207010.003
2012-04-16 07:30:06 -------- d-----w- C:\Users\Chen\AppData\Local\{DFC6BC12-F817-4D6C-9412-FC7FAE60A6A2}
2012-04-16 07:21:30 -------- d-----w- C:\windows\SysWow64\Wat
2012-04-16 07:21:30 -------- d-----w- C:\windows\System32\Wat
2012-04-16 07:09:59 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2012-04-16 06:21:35 -------- d-----w- C:\Users\Chen\AppData\Roaming\Malwarebytes
2012-04-16 06:21:15 24904 ----a-w- C:\windows\System32\drivers\mbam.sys
2012-04-16 06:21:15 -------- d-----w- C:\ProgramData\Malwarebytes
2012-04-16 06:21:15 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-04-16 05:59:44 -------- d-----w- C:\rei
2012-04-16 05:59:40 -------- d-----w- C:\Program Files\Reimage
2012-04-16 05:59:37 -------- d-----w- C:\Program Files (x86)\ReImageCompanion
2012-04-16 04:20:58 -------- d-----w- C:\Users\Chen\AppData\Local\{55465910-02B7-48BB-ABF9-48DB6E68585F}
2012-04-16 03:45:07 -------- d-----w- C:\Users\Chen\AppData\Roaming\Tific
2012-04-16 03:08:21 -------- d-----w- C:\Users\Chen\AppData\Local\{5B7EC2D2-5929-4B05-B927-997B1C0B8201}
2012-04-16 02:45:11 -------- d-----w- C:\Users\Chen\AppData\Local\{9415C0B6-496F-4612-A864-A730B5C360C6}
2012-04-16 02:28:43 90112 ----a-w- C:\ProgramData\adcbcaaefdacdct.exe
2012-04-16 00:11:40 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2012-04-15 23:00:59 427520 ----a-w- C:\windows\SysWow64\SearchIndexer.exe
2012-04-15 22:59:37 421888 ----a-w- C:\windows\System32\KernelBase.dll
2012-04-15 22:58:52 1731920 ----a-w- C:\windows\System32\ntdll.dll
2012-04-15 22:58:52 1292080 ----a-w- C:\windows\SysWow64\ntdll.dll
2012-04-15 22:57:14 -------- d-----w- C:\Users\Chen\AppData\Local\{F90F0E8A-67EA-4084-B021-424021A68321}
2012-04-15 21:15:02 81408 ----a-w- C:\windows\System32\imagehlp.dll
2012-04-15 21:15:02 5120 ----a-w- C:\windows\SysWow64\wmi.dll
2012-04-15 21:15:02 5120 ----a-w- C:\windows\System32\wmi.dll
2012-04-15 21:15:02 23408 ----a-w- C:\windows\System32\drivers\fs_rec.sys
2012-04-15 21:15:02 220672 ----a-w- C:\windows\System32\wintrust.dll
2012-04-15 21:15:02 172544 ----a-w- C:\windows\SysWow64\wintrust.dll
2012-04-15 21:15:02 159232 ----a-w- C:\windows\SysWow64\imagehlp.dll
2012-04-15 21:13:20 77312 ----a-w- C:\windows\System32\packager.dll
2012-04-15 21:13:20 67072 ----a-w- C:\windows\SysWow64\packager.dll
2012-04-15 21:04:33 -------- d-----w- C:\Users\Chen\AppData\Local\{EAC0DDA8-BAEC-488A-A5AA-BB6320820172}
2012-04-15 14:06:38 -------- d-----w- C:\Users\Chen\AppData\Local\{09C25146-AEC4-4852-B2FD-5554469B53E6}
2012-04-15 12:36:57 -------- d-----w- C:\Users\Chen\AppData\Local\Windows Live
2012-04-15 12:33:20 -------- d-----w- C:\Users\Chen\AppData\Roaming\Windows Live Writer
2012-04-15 12:33:20 -------- d-----w- C:\Users\Chen\AppData\Local\Windows Live Writer
2012-04-15 12:32:20 9216 ----a-w- C:\windows\System32\rdrmemptylst.exe
2012-04-15 12:32:19 77312 ----a-w- C:\windows\System32\rdpwsx.dll
2012-04-15 12:32:19 149504 ----a-w- C:\windows\System32\rdpcorekmts.dll
2012-04-15 12:32:18 826880 ----a-w- C:\windows\SysWow64\rdpcore.dll
2012-04-15 12:32:18 23552 ----a-w- C:\windows\System32\drivers\tdtcp.sys
2012-04-15 12:32:18 210944 ----a-w- C:\windows\System32\drivers\rdpwd.sys
2012-04-15 12:32:18 1031680 ----a-w- C:\windows\System32\rdpcore.dll
2012-04-15 12:28:32 -------- d-----w- C:\Users\Chen\AppData\Local\ATI
2012-04-15 12:28:23 -------- d-----w- C:\Users\Chen\AppData\Local\Toshiba
2012-04-15 12:27:10 -------- d-----w- C:\Users\Chen\AppData\Local\VirtualStore
2012-04-15 11:04:17 -------- d-----w- C:\ProgramData\Symantec
2012-04-15 11:04:17 -------- d-----w- C:\Program Files (x86)\Symantec
2012-04-15 11:03:58 -------- d-----w- C:\windows\System32\drivers\NortonPCCheckupx64\0200030.0CA
2012-04-15 11:03:58 -------- d-----w- C:\windows\System32\drivers\NortonPCCheckupx64
2012-04-15 11:03:58 -------- d-----w- C:\Program Files\Norton PC Checkup
2012-04-15 11:03:58 -------- d-----w- C:\Program Files (x86)\Norton PC Checkup
2012-04-15 11:03:31 174200 ----a-w- C:\windows\System32\drivers\SYMEVENT64x86.SYS
2012-04-15 11:03:31 -------- d-----w- C:\Program Files\Symantec
2012-04-15 11:03:31 -------- d-----w- C:\Program Files\Common Files\Symantec Shared
2012-04-15 11:03:00 -------- d-----w- C:\windows\System32\drivers\NISx64
2012-04-15 11:02:58 -------- d-----w- C:\ProgramData\Norton
2012-04-15 11:02:58 -------- d-----w- C:\Program Files (x86)\Norton Internet Security
2012-04-15 11:01:59 -------- d-----w- C:\ProgramData\NortonInstaller
2012-04-15 11:01:59 -------- d-----w- C:\Program Files (x86)\NortonInstaller
2012-04-15 11:01:45 -------- d-----w- C:\Program Files (x86)\Amazon
2012-04-15 11:01:20 -------- d-----r- C:\Program Files (x86)\Skype
2012-04-15 10:59:04 -------- d-----w- C:\Program Files (x86)\Microsoft
2012-04-15 10:56:45 -------- d-----w- C:\ProgramData\WildTangent
2012-04-15 10:56:45 -------- d-----w- C:\Program Files (x86)\WildTangent Games
2012-04-15 10:56:45 -------- d-----w- C:\Program Files (x86)\TOSHIBA Games
2012-04-15 10:52:19 138656 ----a-w- C:\windows\System32\TODDSrv.exe
2012-04-15 10:51:41 -------- d-----w- C:\Program Files (x86)\TOSHIBA Corporation
2012-04-15 10:47:37 14112 ----a-w- C:\windows\System32\drivers\regi.sys
2012-04-15 10:47:23 -------- d-----w- C:\Program Files (x86)\Common Files\InterVideo
2012-04-15 10:46:45 -------- d-----w- C:\Program Files (x86)\Common Files\Protexis
2012-04-15 10:46:30 -------- d-----w- C:\ProgramData\Corel
2012-04-15 10:46:30 -------- d-----w- C:\Program Files (x86)\Corel
2012-04-15 10:44:16 -------- d-----w- C:\Program Files (x86)\Common Files\Toshiba Shared
2012-04-15 10:44:12 482384 ----a-w- C:\windows\System32\drivers\tos_sps64.sys
2012-04-15 10:44:10 4178264 ----a-w- C:\windows\SysWow64\D3DX9_41.dll
2012-04-15 10:43:49 38096 ----a-w- C:\windows\System32\drivers\PGEffect.sys
2012-04-15 10:38:11 99320 ----a-w- C:\windows\System32\tosWirelessLANIndicatorCP.dll
2012-04-15 10:37:43 -------- d-----w- C:\windows\SysWow64\sda
2012-04-15 10:37:35 307304 ----a-w- C:\windows\System32\drivers\rtsuvstor.sys
2012-04-15 10:37:35 250984 ----a-w- C:\windows\System32\drivers\RtsUStor.sys
2012-04-15 10:37:34 9888360 ----a-w- C:\windows\SysWow64\RtsUStoricon.dll
2012-04-15 10:37:34 422504 ----a-w- C:\windows\System32\RtsUStor.dll
2012-04-15 10:37:34 -------- d-----w- C:\Program Files (x86)\Realtek
2012-04-15 10:36:50 -------- d-----w- C:\windows\SysWow64\Atheros_L1e
2012-04-15 10:35:58 40832 ----a-w- C:\windows\System32\drivers\TosBtCi.dll
2012-04-15 10:35:01 42096 ----a-r- C:\windows\System32\drivers\btfilter.sys
2012-04-15 10:34:20 -------- d-----w- C:\Program Files (x86)\TOH Class Filter
2012-04-15 10:32:28 -------- d-----w- C:\Program Files\Synaptics
2012-04-15 10:31:21 63648 ----a-w- C:\windows\System32\athihvui.dll
2012-04-15 10:31:21 443040 ----a-w- C:\windows\System32\athihvs.dll
2012-04-15 10:31:21 2675712 ----a-w- C:\windows\System32\drivers\athrx.sys
2012-04-15 10:31:21 -------- d-----w- C:\windows\System32\nn-NO
2012-04-15 10:31:21 -------- d-----w- C:\windows\Options
2012-04-15 10:31:21 -------- d-----w- C:\Program Files (x86)\Atheros
2012-04-15 10:30:34 -------- d-----w- C:\ProgramData\Atheros
2012-04-15 10:28:00 -------- d-----w- C:\Program Files\CONEXANT
2012-04-15 10:25:45 116752 ----a-w- C:\windows\System32\drivers\AtihdW76.sys
2012-04-15 10:22:42 -------- d-----w- C:\Program Files (x86)\Toshiba
2012-04-15 10:22:11 24576 ----a-w- C:\windows\SysWow64\TSCI.dll
2012-04-15 10:22:11 24576 ----a-w- C:\windows\SysWow64\THCI.dll
2012-04-15 10:21:18 0 ----a-w- C:\windows\ativpsrm.bin
2012-04-15 10:20:12 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
2012-04-15 10:20:12 -------- d-----w- C:\Program Files (x86)\Common Files\ATI Technologies
2012-04-15 10:16:22 -------- d-----w- C:\TOSHIBA
2012-04-15 10:15:36 -------- d-sh--w- C:\$RECYCLE.BIN
.
==================== Find3M ====================
.
2012-03-06 06:53:37 5559152 ----a-w- C:\windows\System32\ntoskrnl.exe
2012-03-06 05:59:47 3968368 ----a-w- C:\windows\SysWow64\ntkrnlpa.exe
2012-03-06 05:59:41 3913072 ----a-w- C:\windows\SysWow64\ntoskrnl.exe
2012-02-28 06:56:48 2311168 ----a-w- C:\windows\System32\jscript9.dll
2012-02-28 06:49:56 1390080 ----a-w- C:\windows\System32\wininet.dll
2012-02-28 06:48:57 1493504 ----a-w- C:\windows\System32\inetcpl.cpl
2012-02-28 06:42:55 2382848 ----a-w- C:\windows\System32\mshtml.tlb
2012-02-28 01:18:55 1799168 ----a-w- C:\windows\SysWow64\jscript9.dll
2012-02-28 01:11:21 1427456 ----a-w- C:\windows\SysWow64\inetcpl.cpl
2012-02-28 01:11:07 1127424 ----a-w- C:\windows\SysWow64\wininet.dll
2012-02-28 01:03:16 2382848 ----a-w- C:\windows\SysWow64\mshtml.tlb
2012-02-10 06:36:07 1544192 ----a-w- C:\windows\System32\DWrite.dll
2012-02-10 05:38:43 1077248 ----a-w- C:\windows\SysWow64\DWrite.dll
2012-02-03 04:34:34 3145728 ----a-w- C:\windows\System32\win32k.sys
.
============= FINISH: 15:57:56.48 ===============


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top











