Help - Search - Members - Calendar
Full Version:  W32/Mazebat, W3M2Mazebat.B, Win32.Trojan.Spy, Adware Pro doesn't delete the files, Can't get rid of Virus Options
Lavasoft Support Forums > HELP! My computer is infected! What should I do? > Help with Stubborn Infections - HijackThis Logs go here
malmn
Post #1


Newbie


Group: Members
Posts: 1
Joined: Today, 02:08 AM
Member No.: 74,238



Hello everybody,

I have Adware Pro and the program discovers the following viruses, W32/Mazebat, W3M2Mazebat.B, Win32.Trojan.Spy, and more, but isn't getting rid of them and others keep coming back.

I have done various scans but Adaware is not taking the proper action. I can't change the recommended action, and it keeps allowing them to stay on the computer.

Adware also deletes the tazebama.dll and hook files, foundin documents nd settings, but they also keep coming back!!!

Why is this happening? How do I get rid of this virus? I am both worried and frustrated.

Thank you,

Mark
Blade81
Hi,

You need to provide some logs first.


Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt
  • Save both reports to your desktop. Post them back to your topic.

  • Download GMER here by clicking download exe -button and then saving it your desktop:
    • Double-click .exe that you downloaded
    • Click rootkit-tab and then scan.
    • Don't check
      Show All
      box while scanning in progress!
    • When scanning is ready, click Copy.
    • This copies log to clipboard
    • Post log in your reply.
    malmn
    Moi!

    I tried to follow your instructions as best as I could but I ran into problems when running gmer.exe (i did change the name of it). I always get a screen blue (the screen of death) when it runs and scans...what should I do now? Anyhow, here are the first two parts, as asked for.

    Kiitos!

    Mark


    DDS (Ver_09-10-26.01) - NTFSx86
    Run by Mark Lemoine at 6:03:24.42 on 04/11/2009
    Internet Explorer: 8.0.6001.18702
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.311 [GMT 7:00]

    AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\acs.exe
    svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
    C:\Program Files\IDrive\IDriveE Service.exe
    C:\Program Files\IDrive\IDriveWebM.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\svchost.exe -k HPZ12
    C:\WINDOWS\System32\svchost.exe -k HPZ12
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\system32\ThpSrv.exe
    C:\WINDOWS\system32\TODDSrv.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe
    C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    C:\WINDOWS\system32\TDispVol.exe
    C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
    C:\WINDOWS\system32\TPSMain.exe
    C:\WINDOWS\system32\thpsrv.exe
    C:\Program Files\Atheros\ACU.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    C:\WINDOWS\system32\TPSBattM.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\WINDOWS\system32\ZoomingHook.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
    C:\WINDOWS\system32\svchost.exe -k HPService
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Safari\Safari.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Documents and Settings\Mark Lemoine\Desktop\dds.scr
    C:\Documents and Settings\tazebama.dl_

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://tsn.ca/
    uWindow Title = Mark Lemoine's Mobile Machine
    uInternet Connection Wizard,ShellNext = hxxp://www.toshiba.ca/welcome
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
    uRun: [IDriveE Startup] "c:\program files\idrive\IDrvieEStartup.exe" Hide
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [DDWMon] c:\program files\toshiba\toshiba direct disc writer\\ddwmon.exe
    mRun: [HWSetup] c:\program files\toshiba\toshiba applet\HWSetup.exe hwSetUP
    mRun: [CeEKEY] c:\program files\toshiba\e-key\CeEKey.exe
    mRun: [TDispVol] TDispVol.exe
    mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe
    mRun: [TAccessibility] c:\program files\toshiba\accessibility\TAccessibility.exe Instant
    mRun: [TPNF] c:\program files\toshiba\touchpad\TPTray.exe
    mRun: [TUSBSleepChargeSrv] %ProgramFiles%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
    mRun: [TPSMain] TPSMain.exe
    mRun: [ThpSrv] c:\windows\system32\thpsrv /logon
    mRun: [ACU] "c:\program files\atheros\ACU.exe" -nogui
    mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
    mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
    mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
    mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
    mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
    mRun: [ZoomingHook] ZoomingHook.exe
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [SVPWUTIL] c:\program files\toshiba\windows utilities\SVPWUTIL.exe SVPwUTIL
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
    mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\toshiba\bluetooth toshiba stack\TosBtMng.exe
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
    IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
    DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab
    DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://upload.travellerspoint.com/ImageUploader5.cab
    DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1256950174828
    DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: igfxcui - igfxdev.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll

    ============= SERVICES / DRIVERS ===============

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-10-28 64288]
    R0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\drivers\thpdrv.sys [2008-8-21 28536]
    R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\drivers\Thpevm.sys [2007-9-4 6528]
    R1 ISODisk;ISODisk;c:\windows\system32\drivers\ISODisk.sys [2009-7-9 9600]
    R2 IDriveE Service;IDriveE Service;c:\program files\idrive\IDriveE Service.exe [2009-10-28 143360]
    R2 IDriveWebM;IDrive WebManager;c:\program files\idrive\IDriveWebM.exe [2009-10-28 118784]
    R2 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\drivers\tdudf.sys [2007-3-27 105856]
    R2 trudf;TOSHIBA DVD-RAM UDF File System Driver;c:\windows\system32\drivers\trudf.sys [2007-2-20 134016]
    R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [2009-6-29 58208]
    S2 gupdate;Google Update Service (gupdate);"c:\program files\google\update\googleupdate.exe" /svc --> c:\program files\google\update\GoogleUpdate.exe [?]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-9-24 1179232]
    S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-3-26 1684736]
    S3 cecnuvc;Chicony USB 2.0 Camera VD;c:\windows\system32\drivers\cec_uvc.sys --> c:\windows\system32\drivers\cec_uvc.sys [?]
    S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\rtsustor.sys --> c:\windows\system32\drivers\RtsUStor.sys [?]
    S3 RtsUIR;Realtek IR Driver;c:\windows\system32\drivers\rts516xir.sys --> c:\windows\system32\drivers\Rts516xIR.sys [?]
    S3 tap0901;TAP-Win32 Adapter V9;c:\windows\system32\drivers\tap0901.sys [2008-11-20 25216]

    =============== Created Last 30 ================

    2009-11-03 14:38:49 155671 --sh--r- C:\zPharaoh.exe
    2009-11-03 14:38:49 126 --sh--r- C:\autorun.inf
    2009-10-30 10:33:30 0 d-----w- c:\docume~1\markle~1\applic~1\tazebama
    2009-10-29 00:37:06 0 d-----w- c:\windows\pss
    2009-10-28 15:03:46 0 d-----w- c:\program files\IDrive
    2009-10-28 09:56:57 15880 ----a-w- c:\windows\system32\lsdelete.exe
    2009-10-27 23:33:16 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2009-10-27 23:33:09 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2009-10-27 23:27:47 0 dc-h--w- c:\docume~1\alluse~1\applic~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
    2009-10-27 23:26:38 0 d-----w- c:\program files\Lavasoft
    2009-10-27 07:34:58 195440 ------w- c:\windows\system32\MpSigStub.exe
    2009-10-08 09:51:36 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2009-10-08 00:18:14 65036 ---ha-w- c:\windows\system32\mlfcache.dat
    2009-10-07 14:31:57 0 d-----w- c:\program files\iPod
    2009-10-07 14:31:52 0 d-----w- c:\program files\iTunes

    ==================== Find3M ====================

    2009-10-31 10:42:56 545647 ----a-w- c:\windows\system32\cmd.exe
    2009-10-31 10:42:56 372079 ----a-w- c:\windows\system32\osk.exe
    2009-10-31 10:42:56 299887 ----a-w- c:\windows\system32\mobsync.exe
    2009-10-31 10:42:56 229231 ----a-w- c:\windows\system32\magnify.exe
    2009-10-31 10:42:56 210287 ----a-w- c:\windows\system32\narrator.exe
    2009-10-31 10:42:55 695151 ----a-w- c:\windows\system32\spider.exe
    2009-10-31 10:42:55 283503 ----a-w- c:\windows\system32\mshearts.exe
    2009-10-31 10:42:55 276335 ----a-w- c:\windows\system32\winmine.exe
    2009-10-31 10:42:55 213359 ----a-w- c:\windows\system32\sol.exe
    2009-10-31 10:42:55 211823 ----a-w- c:\windows\system32\freecell.exe
    2009-10-31 10:37:54 834415 ----a-w- c:\windows\system32\mstsc.exe
    2009-10-31 10:37:54 499567 ----a-w- c:\windows\system32\mspaint.exe
    2009-10-31 10:37:54 295279 ----a-w- c:\windows\system32\sndvol32.exe
    2009-10-31 10:37:54 288111 ----a-w- c:\windows\system32\sndrec32.exe
    2009-10-31 10:37:54 236911 ----a-w- c:\windows\system32\charmap.exe
    2009-10-31 10:37:54 189295 ----a-w- c:\windows\system32\odbcad32.exe
    2009-10-27 09:48:54 1220608 ----a-w- c:\windows\system32\IDriveEService.dll
    2009-10-09 10:30:46 229376 ----a-w- c:\windows\system32\IDrLocale.dll
    2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
    2009-08-29 08:08:21 916480 ----a-w- c:\windows\system32\wininet.dll
    2009-08-28 10:42:52 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
    2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll
    2009-08-17 16:33:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
    2009-08-06 12:23:46 274288 ----a-w- c:\windows\system32\mucltui.dll
    2009-08-06 12:23:26 215904 ----a-w- c:\windows\system32\muweb.dll
    2009-08-06 04:06:48 59904 ----a-w- c:\windows\system32\zlib1.dll
    2009-08-06 04:02:40 286720 ----a-w- c:\windows\system32\libcurl.dll
    2009-08-06 04:02:32 196608 ----a-w- c:\windows\system32\ssleay32.dll
    2009-08-06 04:02:32 1028096 ----a-w- c:\windows\system32\libeay32.dll
    2009-08-06 04:02:22 143360 ----a-w- c:\windows\system32\libexpatw.dll

    ============= FINISH: 6:04:05.93 ===============

    Click to view attachment
    Blade81
    Hello Mark smile.gif

    DNA

    Above listed ones are P2P file sharing programs. P2P downloads are nowadays one of those things that most likely bring infection into the system. My recommendation is to uninstall these (and other if present) P2P file sharing programs.

    I believe we can continue even without GMER log in this case.


    Please visit this webpage for download links, and instructions for running ComboFix tool:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    Please ensure you read this guide carefully and install the Recovery Console first.

    The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    Once installed, you should see a blue screen prompt that says:

    The Recovery Console was successfully installed.

    Please continue as follows:
    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
      Remember to re-enable them afterwards.

    2. Click Yes to allow ComboFix to continue scanning for malware.

    When the tool is finished, it will produce a report for you.

    Please include the following reports for further review, and so we may continue cleansing the system:

    C:\ComboFix.txt
    New dds log.


    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
    malmn
    Hello again Blade81,

    Well, I did what you told me to do, did every step for ComboFix, including disabling Windows Defender and AdAware. I just ran my virus scanner again (AdAware Pro) and it's still finding many issues and it's blocking certain programs from running like Internet Explorer, Word, Notepad, etc. So I here I have posted the original log that popped up when ComboFix terminated and I have also attached the ComboFix.txt file to this post. Hopefully this can be solved once and for all. I'm still worried.

    Kiitos once again!


    ComboFix 09-11-03.03 - Mark Lemoine 04/11/2009 17:19.1.2 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.348 [GMT 7:00]
    Running from: c:\documents and settings\Mark Lemoine\Desktop\ComboFix.exe
    AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
    .
    The following files were disabled during the run:
    c:\documents and settings\tazebama.dll


    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\autorun.inf
    c:\docume~1\MARKLE~1\LOCALS~1\Temp\install_flash_player.exe
    c:\documents and settings\Mark Lemoine\Application Data\tazebama
    c:\documents and settings\Mark Lemoine\Application Data\tazebama\tazebama.log
    c:\documents and settings\Mark Lemoine\Application Data\tazebama\zPharaoh.dat
    c:\documents and settings\Thanh\Application Data\tazebama
    c:\documents and settings\Thanh\Application Data\tazebama\tazebama.log
    c:\documents and settings\Thanh\Application Data\tazebama\zPharaoh.dat
    C:\zPharaoh.exe
    D:\autorun.inf
    d:\recycler\RECYCLER .exe
    d:\recycler\S-1-5-21-1758645133-1304650760-2999503539-1006\NokiaN73Tools.exe
    d:\recycler\S-1-5-21-1758645133-1304650760-2999503539-1006\S-1-5-21-1758645133-1304650760-2999503539-1006 .exe
    d:\recycler\S-1-5-21-1758645133-1304650760-2999503539-1007\S-1-5-21-1758645133-1304650760-2999503539-1007 .exe
    d:\recycler\WinrRarSerialInstall.exe
    D:\zPharaoh.exe
    C:\autorun.inf . . . . failed to delete

    ----- File Replicators -----

    c:\program files\Apoint2K\hidfind.exe
    c:\program files\Atheros\wsimdbub.exe
    c:\program files\HP\Digital Imaging\help\player\fscommand\C7200_insert_memcard.exe
    c:\program files\HP\Digital Imaging\help\player\fscommand\C7200_load_adf.exe
    c:\program files\HP\Digital Imaging\help\player\fscommand\C7200_load_letter.exe
    c:\program files\HP\Digital Imaging\help\player\fscommand\C7200_load_original.exe
    c:\program files\HP\Digital Imaging\help\player\fscommand\C7200_load_small.exe
    c:\program files\HP\Digital Imaging\help\player\fscommand\C7200_paperjam.exe
    c:\program files\HP\Digital Imaging\help\player\fscommand\C7200_print_4x6.exe
    c:\program files\HP\Digital Imaging\help\player\fscommand\C7200_printcart.exe
    c:\program files\HP\Digital Imaging\help\player\fscommand\C7200_reprint_4x6.exe
    c:\program files\HP\Digital Imaging\help\player\fscommand\C7200_transfer_memcard.exe
    c:\program files\HP\Digital Imaging\help\player\fscommand\C7200_transfer_scan.exe
    c:\program files\TOSHIBA\ConfigFree\CFDialUp.exe
    c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe .. failed to delete
    c:\program files\TOSHIBA\ConfigFree\glaunch.exe
    c:\support\TOOLS\SETUP.EXE
    c:\tosapins\ALPS-Pointing-Device-Driver\hidfind.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\CZE\glaunch.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\DAN\glaunch.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\DUT\glaunch.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\ENG\glaunch.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\FRE\glaunch.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\GER\glaunch.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\ITA\glaunch.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\NDSFiles\CFDialUp.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\NOR\glaunch.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\POL\glaunch.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\POR\glaunch.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\Service\CFSvcs.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\SPA\glaunch.exe
    c:\tosapins\TOSHIBA-ConfigFree\Package\SWE\glaunch.exe
    c:\windows\Installer\{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}\ARPPRODUCTICON.exe
    c:\windows\Installer\{5279374D-87FE-4879-9385-F17278EBB9D3}\ARPPRODUCTICON.exe
    c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe
    c:\windows\Microsoft.NET\Framework\v1.1.4322\jsc.exe
    c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe
    c:\windows\system32\cliconfg.exe
    c:\windows\system32\DRVSTORE\apfiltr_89745551590950D878232A8FA69D5B42FEC4707E\hidfind.exe
    c:\windows\system32\IDriveEXceedCryReg.exe
    .
    Infected copy of c:\windows\pchealth\helpctr\binaries\helpctr.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\helpctr.exe

    Infected copy of c:\windows\pchealth\helpctr\binaries\msconfig.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\msconfig.exe

    Infected copy of c:\windows\system32\charmap.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\charmap.exe

    Infected copy of c:\windows\system32\cmd.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\cmd.exe

    Infected copy of c:\windows\system32\freecell.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\freecell.exe

    Infected copy of c:\windows\system32\magnify.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\magnify.exe

    Infected copy of c:\windows\system32\mobsync.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\mobsync.exe

    Infected copy of c:\windows\system32\mshearts.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\mshearts.exe

    Infected copy of c:\windows\system32\mspaint.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\mspaint.exe

    c:\windows\system32\mstsc.exe . . . is infected!!

    Infected copy of c:\windows\system32\narrator.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\narrator.exe

    Infected copy of c:\windows\system32\odbcad32.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\odbcad32.exe

    Infected copy of c:\windows\system32\osk.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\osk.exe

    Infected copy of c:\windows\system32\sndrec32.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\sndrec32.exe

    Infected copy of c:\windows\system32\sndvol32.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\sndvol32.exe

    Infected copy of c:\windows\system32\sol.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\sol.exe

    Infected copy of c:\windows\system32\spider.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\spider.exe

    Infected copy of c:\windows\system32\winmine.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\winmine.exe

    Infected copy of c:\windows\system32\Restore\rstrui.exe was found and disinfected
    Restored copy from - c:\windows\system32\dllcache\rstrui.exe

    .
    ((((((((((((((((((((((((( Files Created from 2009-10-04 to 2009-11-04 )))))))))))))))))))))))))))))))
    .

    2009-11-04 10:47 . 2009-11-04 10:48 155641 --sh--r- C:\zPharaoh.exe
    2009-11-04 10:35 . 2009-11-04 10:48 -------- d-----w- c:\documents and settings\Mark Lemoine\Application Data\tazebama
    2009-11-04 10:19 . 2009-11-04 10:19 -------- d-----w- c:\documents and settings\SYSTEM
    2009-11-04 08:16 . 2009-11-04 08:16 -------- d-----w- c:\documents and settings\Thanh\Local Settings\Application Data\Apple
    2009-11-03 14:38 . 2009-11-04 10:47 32768 ----a-w- c:\documents and settings\tazebama.dll
    2009-11-03 14:38 . 2009-11-03 23:52 32768 ----a-w- c:\documents and settings\tazebama.dll.vir
    2009-10-28 15:03 . 2009-10-09 10:30 229376 ----a-w- c:\windows\system32\IDrLocale.dll
    2009-10-28 15:03 . 2004-09-28 04:13 526184 ----a-w- c:\windows\system32\XceedCry.dll
    2009-10-28 15:03 . 2009-10-27 09:48 1220608 ----a-w- c:\windows\system32\IDriveEService.dll
    2009-10-28 15:03 . 2009-03-10 09:41 95 ----a-w- c:\windows\system32\RegisterIDriveEDll.bat
    2009-10-28 15:03 . 2004-11-01 05:26 135168 ----a-w- c:\windows\system32\LogMail.dll
    2009-10-28 15:03 . 2009-10-31 23:26 -------- d-----w- c:\program files\IDrive
    2009-10-28 09:56 . 2009-10-27 23:33 15880 ----a-w- c:\windows\system32\lsdelete.exe
    2009-10-27 23:33 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2009-10-27 23:33 . 2009-10-27 23:33 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2009-10-27 23:27 . 2009-10-27 23:27 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
    2009-10-27 23:26 . 2009-10-27 23:26 -------- d-----w- c:\program files\Lavasoft
    2009-10-27 23:26 . 2009-10-27 23:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2009-10-27 07:34 . 2009-10-01 02:29 195440 ------w- c:\windows\system32\MpSigStub.exe
    2009-10-27 07:33 . 2009-10-27 07:33 -------- d-----w- c:\program files\Windows Defender
    2009-10-08 09:51 . 2009-10-08 11:49 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2009-10-08 00:18 . 2009-10-08 00:18 65036 ---ha-w- c:\windows\system32\mlfcache.dat
    2009-10-07 14:31 . 2009-10-07 14:31 -------- d-----w- c:\program files\iPod
    2009-10-07 14:31 . 2009-10-07 14:33 -------- d-----w- c:\program files\iTunes
    2009-10-07 14:12 . 2009-10-07 14:12 -------- d-----w- c:\program files\Safari

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-11-04 10:34 . 2009-06-29 11:15 -------- d-----w- c:\program files\Apoint2K
    2009-11-04 10:34 . 2009-06-29 11:13 -------- d-----w- c:\program files\Atheros
    2009-11-02 22:29 . 2009-06-28 21:06 -------- d-----w- c:\documents and settings\Mark Lemoine\Application Data\Skype
    2009-11-02 22:03 . 2009-06-28 21:08 -------- d-----w- c:\documents and settings\Mark Lemoine\Application Data\skypePM
    2009-11-02 07:30 . 2009-09-13 23:06 -------- d-----w- c:\documents and settings\Thanh\Application Data\Skype
    2009-10-31 10:37 . 2009-03-25 17:13 834415 ----a-w- c:\windows\system32\mstsc.exe
    2009-10-31 02:31 . 2009-06-29 11:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2009-10-30 03:49 . 2009-03-25 18:19 -------- d-----w- c:\program files\Windows Desktop Search
    2009-10-23 04:56 . 2009-08-09 03:41 -------- d-----w- c:\documents and settings\Thanh\Application Data\Apple Computer
    2009-10-23 03:21 . 2009-09-13 23:06 -------- d-----w- c:\documents and settings\Thanh\Application Data\skypePM
    2009-10-11 02:51 . 2009-10-01 23:20 -------- d-----w- c:\documents and settings\Mark Lemoine\Application Data\NeuLion
    2009-10-10 15:41 . 2009-06-29 06:10 275472 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    2009-10-10 06:20 . 2009-08-17 13:36 -------- d-----w- c:\program files\Windows Media Connect 2
    2009-10-10 06:20 . 2009-06-29 11:21 -------- d-----w- c:\program files\Microsoft Works
    2009-10-10 06:20 . 2009-06-29 05:31 -------- d-----w- c:\program files\Star Alliance Timetable
    2009-10-10 06:20 . 2009-06-29 14:38 -------- d-----w- c:\program files\DivX
    2009-10-08 00:17 . 2009-06-28 20:57 -------- d-----w- c:\documents and settings\Mark Lemoine\Application Data\Apple Computer
    2009-10-07 14:31 . 2009-06-28 20:54 -------- d-----w- c:\program files\Common Files\Apple
    2009-10-05 04:31 . 2009-08-09 03:47 78104 ----a-w- c:\documents and settings\Thanh\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-10-01 13:23 . 2009-06-29 20:09 -------- d-----w- c:\program files\Google
    2009-09-15 06:28 . 2009-09-14 12:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
    2009-09-14 11:58 . 2009-09-14 11:57 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    2009-09-14 11:54 . 2009-06-28 20:56 -------- d-----w- c:\program files\QuickTime
    2009-09-14 00:21 . 2009-09-14 00:21 -------- d-----w- c:\documents and settings\All Users\Application Data\TVU Networks
    2009-09-11 22:43 . 2009-06-28 20:41 78104 ----a-w- c:\documents and settings\Mark Lemoine\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-09-11 14:18 . 2009-03-25 05:28 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-04 21:03 . 2009-03-25 05:28 58880 ----a-w- c:\windows\system32\msasn1.dll
    2009-08-29 08:08 . 2009-03-25 05:28 916480 ----a-w- c:\windows\system32\wininet.dll
    2009-08-28 10:42 . 2009-06-28 20:55 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
    2009-08-28 10:42 . 2009-06-28 20:55 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
    2009-08-26 08:00 . 2009-03-25 05:28 247326 ----a-w- c:\windows\system32\strmdll.dll
    2009-08-17 16:33 . 2009-08-17 16:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
    2009-08-06 12:24 . 2009-03-25 17:14 327896 ----a-w- c:\windows\system32\wucltui.dll
    2009-08-06 12:24 . 2009-03-25 17:14 209632 ----a-w- c:\windows\system32\wuweb.dll
    2009-08-06 12:24 . 2009-03-25 17:14 35552 ----a-w- c:\windows\system32\wups.dll
    2009-08-06 12:24 . 2008-10-16 18:09 44768 ----a-w- c:\windows\system32\wups2.dll
    2009-08-06 12:24 . 2009-03-25 17:14 53472 ----a-w- c:\windows\system32\wuauclt.exe
    2009-08-06 12:24 . 2009-03-25 05:28 96480 ----a-w- c:\windows\system32\cdm.dll
    2009-08-06 12:23 . 2009-03-25 17:14 575704 ----a-w- c:\windows\system32\wuapi.dll
    2009-08-06 12:23 . 2009-06-30 00:59 274288 ----a-w- c:\windows\system32\mucltui.dll
    2009-08-06 12:23 . 2009-03-25 17:14 1929952 ----a-w- c:\windows\system32\wuaueng.dll
    2009-08-06 12:23 . 2008-10-16 18:07 215904 ----a-w- c:\windows\system32\muweb.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IDriveE Startup"="c:\program files\IDrive\IDrvieEStartup.exe" [2009-09-21 173520]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ThpSrv"="c:\windows\system32\thpsrv" [X]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-16 141848]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-16 166424]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-16 137752]
    "DDWMon"="c:\program files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe" [2007-04-14 311296]
    "HWSetup"="c:\program files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 28672]
    "CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2009-03-18 827392]
    "SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2009-10-31 316271]
    "TAccessibility"="c:\program files\TOSHIBA\Accessibility\TAccessibility.exe" [2009-10-25 267119]
    "TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2009-04-03 73728]
    "TUSBSleepChargeSrv"="c:\program files\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe" [2009-03-16 252288]
    "ACU"="c:\program files\Atheros\ACU.exe" [2009-03-06 479320]
    "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-12-15 184320]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-04 186904]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
    "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
    "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
    "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2009-10-31 1023111]
    "SVPWUTIL"="c:\program files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2009-03-19 90112]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-04 417792]
    "ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2008-12-19 83336]
    "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
    "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-03-12 17531392]
    "TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2009-04-02 210232]
    "TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2009-03-17 283960]
    "ZoomingHook"="ZoomingHook.exe" - c:\windows\system32\ZoomingHook.exe [2005-06-06 24576]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2009-3-20 2689207]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Documents and Settings\\Thanh\\Local Settings\\Application Data\\Skype\\Phone\\Skype.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\TOSHIBA\\ConfigFree\\CFXFER.exe"=
    "c:\\WINDOWS\\system32\\dpvsetup.exe"=
    "c:\\WINDOWS\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\Program Files\\Safari\\Safari.exe"=

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [28/10/2009 6:33 AM 64288]
    R0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\drivers\thpdrv.sys [21/08/2008 9:35 PM 28536]
    R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\drivers\Thpevm.sys [04/09/2007 9:14 PM 6528]
    R1 ISODisk;ISODisk;c:\windows\system32\drivers\ISODisk.sys [09/07/2009 8:58 PM 9600]
    R2 IDriveE Service;IDriveE Service;c:\program files\IDrive\IDriveE Service.exe [28/10/2009 10:03 PM 143360]
    R2 IDriveWebM;IDrive WebManager;c:\program files\IDrive\IDriveWebM.exe [28/10/2009 10:03 PM 118784]
    R2 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\drivers\tdudf.sys [27/03/2007 2:22 AM 105856]
    R2 trudf;TOSHIBA DVD-RAM UDF File System Driver;c:\windows\system32\drivers\trudf.sys [20/02/2007 2:15 AM 134016]
    S2 gupdate;Google Update Service (gupdate);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
    S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 7:19 PM 13592]
    S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [26/03/2009 3:33 AM 1684736]
    S3 cecnuvc;Chicony USB 2.0 Camera VD;c:\windows\system32\Drivers\cec_uvc.sys --> c:\windows\system32\Drivers\cec_uvc.sys [?]
    S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24/09/2009 6:17 PM 1179232]
    S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys --> c:\windows\system32\Drivers\RtsUStor.sys [?]
    S3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]

    --- Other Services/Drivers In Memory ---

    *Deregistered* - mbr

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    HPService REG_MULTI_SZ HPSLPSVC
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    Contents of the 'Scheduled Tasks' folder

    2009-11-04 c:\windows\Tasks\Ad-Aware Scan (Safe Mode).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 23:32]

    2009-11-04 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 23:32]

    2009-11-04 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 23:32]

    2009-11-04 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 23:32]

    2009-11-04 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 23:32]

    2009-11-04 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://tsn.ca/
    uInternet Connection Wizard,ShellNext = hxxp://www.toshiba.ca/welcome
    uInternet Settings,ProxyOverride = *.local
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-BitTorrent DNA - c:\program files\DNA\btdna.exe
    HKLM-Run-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
    AddRemove-com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 - c:\program files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-11-04 17:48
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(2420)
    c:\windows\system32\WININET.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
    c:\windows\system32\TDispVol.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\hnetcfg.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    c:\windows\system32\TPwrCfg.DLL
    c:\windows\system32\TPwrReg.dll
    c:\windows\system32\TPSTrace.DLL
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\acs.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\ThpSrv.exe
    c:\windows\system32\TODDSrv.exe
    c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
    c:\windows\system32\SearchIndexer.exe
    c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\system32\igfxsrvc.exe
    c:\program files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe
    c:\windows\system32\thpsrv.exe
    c:\windows\system32\TPSBattM.exe
    c:\program files\Apoint2K\Apntex.exe
    c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
    c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
    c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
    c:\windows\system32\SearchProtocolHost.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\windows\system32\SearchFilterHost.exe
    .
    **************************************************************************
    .
    Completion time: 2009-11-04 17:54 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-11-04 10:54

    Pre-Run: 1,584,922,624 bytes free
    Post-Run: 3,341,414,400 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

    Blade81
    Hi,

    Bad news, unfortunately. This is description of the infection you're having there in your system. As you can see it makes big damage to files. My recommendation in file infector cases is to reformat.
    This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
    Invision Power Board © 2001-2009 Invision Power Services, Inc.