As for the wireless/hardwire: I’m afraid I’m not the one to decide… As the majority loves the advantages of wireless (quite frankly: me too), that’s probably not going to be changed back into hardwire…
Next things I did/happened:
1) I tried to turn off everything possible in McAfee. I even made printscreens of what I did:
2) I downloaded ComboFix from the Bleepingcomputer-link in Post 5 and saved as commy.exe on my desktop.
3) I clicked Start then copy pasted “"%userprofile%\desktop\commy.exe" /stepdel” into the search box & hit enter. UAC asked for permission, I gave it. I got “DISCLAIMER OF WARRANTY ON SOFTWARE”, I clicked Yes. I got “Backing up registry…”-window, it automatically closed when ready. After that I’m convinced ComboFix just started scanning. (I’m not 100% certain, nevertheless pretty convinced
Microsoft Windows Recovery Console was not mentioned.) ComboFix was going to reboot – do NOT do it yourself, Combofix will – and did so. ComboFix was prepairing Log Report – Do not run any programs until ComboFix has finished. After a while ComboFix-window was closed and Notepad-window presenting ComboFix-log was opened. I’ll copy paste below as “
ComboFix-log".
BUT, I also got an
error-box:
Not having a clue what “CEC_MAIN.exe” would mean, but assuming this would start the Microsoft Windows Recovery Console, I just clicked OK… Nothing happened.
While waiting patiently for something to happen, I did notice the
shortcut Hard Drive Diagnostic made on my desktop and was still there but had changed, was changed again! This time it has been
turned into an Internet Explorer-shortcut. The
background on the other hand - which was set by default when I bought the computer and wasn't changed ever since until I ran MBAM (it turned into a black screen after running MBAM)
seems unmoved by ComboFix: the picture I chose and put it on the desktop background (to replace the black screen) is still there.
As just waiting for something to happen after having clicked OK-button had failed, I decided to prepair another post.
Meanwhile I had some urgent presents which had to come first. Virus-removal had to cease for a while, although I felt insecure about the status of my computer (having disabled every possible protection, having run ComboFix but not knowing what about the error, what about Microsoft Windows Recovery Console…).
As I wanted to go on the internet, I was prompted with a message Internet Explorer was not my standard browser, did I want to alter it into my standard browser? Although I couldn’t remember Internet Explorer not being my standard browser, I just clicked Yes. Ever since having done that, this message doesn’t seem to appear anymore.
More of a concern however, I was presented with a message I was going to
leave save internetconnection. The information you send, could be watched by others. Do you want to continue?
This message
keeps appearing, every time I open Internet Explorer.
When I want to open GMail (thus far I only noticed for GMail, possibly it's for some other things too, I just don't know it yet) an other message appears stating I'm going to display pages through a safe connection. The information you exchange with this website can be viewed by nobody else on the internet.
Thinking that would be it, yesterday at shutdown I noticed McAfee-icon being checked in taskbar: apparently McAfee did a scan anyway although I tried my best to disable completely (1)) and hadn't changed back because I wanted to ask you first.
So far I think that shall be it.
Wat do I do now?
ComboFix-log:
ComboFix 11-01-10.07 - Anneke 11/01/2011 9:33.1.2 - x86
Microsoft
Windows Vista
Home Premium 6.0.6002.2.1252.32.1043.18.3069.1811 [GMT 1:00]
Gestart vanuit: c:\users\Anneke\Desktop\commy.exe
gebruikte Opdracht switches :: /stepdel
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Nieuw herstelpunt werd aangemaakt
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Anneke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hard Drive Diagnostic
c:\windows\system32\drivers\sst3B3E.sys
c:\program files\Internet Explorer\msimg32.dll
c:\users\Anneke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hard Drive Diagnostic\Hard Drive Diagnostic.lnk
c:\users\Anneke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hard Drive Diagnostic\Uninstall Hard Drive Diagnostic.lnk
c:\users\Anneke\Desktop\Hard Drive Diagnostic.lnk
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\system32\arp.exe
c:\windows\system32\f3PSSavr.scr
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_sst3B3E
-------\Service_sst3B3E
(((((((((((((((((((( Bestanden Gemaakt van 2010-12-11 to 2011-01-11 ))))))))))))))))))))))))))))))
.
2011-01-11 08:39 . 2011-01-11 08:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-28 12:48 . 2010-12-28 12:49 -------- d-----w- c:\windows\system32\ca-ES
2010-12-28 12:48 . 2010-12-28 12:49 -------- d-----w- c:\windows\system32\eu-ES
2010-12-28 12:48 . 2010-12-28 12:49 -------- d-----w- c:\windows\system32\vi-VN
2010-12-28 11:32 . 2010-12-28 11:32 -------- d-----w- c:\windows\system32\EventProviders
2010-12-24 13:55 . 2010-12-24 13:55 -------- d-----w- c:\programdata\IsolatedStorage
2010-12-21 11:56 . 2010-12-21 11:56 -------- d-----w- c:\users\Anneke\AppData\Roaming\Malwarebytes
2010-12-21 11:53 . 2010-12-21 11:53 -------- d-----w- c:\programdata\Malwarebytes
2010-12-21 11:53 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 11:53 . 2010-12-21 21:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-21 11:53 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-17 10:39 . 2010-10-12 13:41 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2010-12-17 10:39 . 2010-10-12 13:41 515584 ----a-w- c:\program files\Windows Mail\wab.exe
2010-12-17 10:39 . 2010-10-12 15:53 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2010-12-17 10:39 . 2010-10-18 13:31 2038272 ----a-w- c:\windows\system32\win32k.sys
2010-12-17 10:39 . 2010-11-04 18:55 601600 ----a-w- c:\windows\system32\schedsvc.dll
2010-12-17 10:39 . 2010-11-04 18:55 352768 ----a-w- c:\windows\system32\taskschd.dll
2010-12-17 10:39 . 2010-11-04 18:56 345600 ----a-w- c:\windows\system32\wmicmiplugin.dll
2010-12-17 10:39 . 2010-11-04 16:34 171520 ----a-w- c:\windows\system32\taskeng.exe
2010-12-17 10:39 . 2010-11-04 18:55 270336 ----a-w- c:\windows\system32\taskcomp.dll
2010-12-17 10:39 . 2010-10-18 13:37 81920 ----a-w- c:\windows\system32\consent.exe
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-06 14:58 . 2010-12-06 14:58 82944 ----a-w- c:\windows\system32\drivers\sst195D.sys
2010-12-06 14:58 . 2010-12-06 14:58 0 ----a-w- c:\windows\system32\drivers\sst195D.tmp
2010-12-06 14:57 . 2010-12-06 14:57 0 ----a-w- c:\windows\system32\drivers\sst3B3E.tmp
2010-11-12 17:53 . 2010-05-14 10:20 472808 ----a-w- c:\windows\system32\deployJava1.dll
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-04-24 430080]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-01 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416]
"NDSTray.exe"="NDSTray.exe" [BU]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-08-03 582992]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-09-09 30192]
"Google EULA Launcher"="c:\program files\Google\Google EULA\GoogleEULALauncher.exe" [2008-05-28 20480]
"Toshiba TEMPO"="c:\program files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe" [2008-04-24 103824]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-08 6037504]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2008-04-29 417792]
"HDMICtrlMan"="c:\program files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe" [2008-04-26 716800]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2008-01-11 574864]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-10 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-17 1848648]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-09-10 122368]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
c:\users\Anneke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2008-4-14 2979144]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-2-12 813584]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2010-1-21 2057536]
WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2010-1-21 9136960]
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files\Toshiba\TRDCReminder\TRDCReminder.exe [2008-3-5 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
R2 gupdate;Google Updateservice (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-09-09 30192]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2008-04-16 40960]
S2 TempoMonitoringService;Notebook Performance Tuning Service ;c:\program files\Toshiba TEMPRO\TempoSVC.exe [2008-04-24 99720]
S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-03 126976]
S2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2010-01-21 110592]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]
S3 NETw5v32;Stuurprogramma voor Intel(R) Wireless WiFi Link Adapter onder Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-04-28 3658752]
S3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe [2008-04-24 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Inhoud van de 'Gedeelde Taken' map
2011-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 14:17]
2011-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 14:17]
2008-08-08 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-10-05 11:32]
2009-12-31 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-10-05 11:32]
2011-01-11 c:\windows\Tasks\User_Feed_Synchronization-{CD84C335-872B-4F86-81AE-25F3500FCE74}.job
- c:\windows\system32\msfeedssync.exe [2010-12-17 04:25]
.
.
------- Bijkomende Scan -------
.
uStart Page =
hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA;uDefault_Search_URL =
hxxp://www.google.com/iemStart Page =
hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEAuInternet Settings,ProxyOverride = *.local
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} -
http://www.webtip.ch/cgi-bin/toshiba/tracker_url2.pl?NLIE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} -
http://www.amazon.co.uk/exec/obidos/redirect-home?tag=Toshibaukbholink-21&site=homeDPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} -
hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab.
.
------- Bestandsassociaties -------
.
.scr=DWGTrueViewScriptFile
.
- - - - ORPHANS VERWIJDERD - - - -
HKLM-Run-ITSecMng - %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe
HKLM-Run-cfFncEnabler.exe - cfFncEnabler.exe
HKLM-Run-TPwrMain - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - %ProgramFiles%\TOSHIBA\TBS\HSON.exe
HKLM-Run-SmoothView - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-00TCrdMain - %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
**************************************************************************
scannen van verborgen processen ...
scannen van verborgen autostart items ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i?????????*???P?y?x?y???y???y??
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden:
**************************************************************************
.
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------
- - - - - - - > 'Explorer.exe'(4600)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
------------------------ Andere Aktieve Processen ------------------------
.
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Toshiba\Power Saver\TosCoSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\system32\conime.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\windows\RtHDVCpl.exe
c:\program files\Toshiba\Power Saver\TPwrMain.exe
c:\program files\Toshiba\SmoothView\SmoothView.exe
c:\program files\Toshiba\FlashCards\TCrdMain.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\BTWLANDP.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\mcafee\msc\mcuimgr.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\program files\Synaptics\SynTP\SynTPHelper.exe
.
**************************************************************************
.
Voltooingstijd: 2011-01-11 09:47:18 - machine werd herstart
ComboFix-quarantined-files.txt 2011-01-11 08:47
Pre-Run: 101.037.477.888 bytes beschikbaar
Post-Run: 105.179.316.224 bytes beschikbaar
- - End Of File - - 3F66BE5A4B8E6E2EEC6A787C13068B06