I have scanned my computer using about 5 programs all 5 programs says my computer is ok. I have used Hitman Pro, Comodo Anti-virus, AVG full version, regrun reanimator, and Malware bytes.
When i first got the virus it would shutoff my computer completley, but after a few tries i was able to start up my computer. My computer will shutoff if i scan my computer in safe mode with avg. If i scan it in normal mode my computer will not shut off, but the virus wont be found. Once the virus shuts off my computer it takes multiple attempts to start my computer up again.
When I installed comodo Anti-virus it gave me the option to block rpcnetp.exe from starting up an svchost execution.(maybe this stopped the virus? but once it was scanned nothing was found)
I will attach my processes+ startup programs along with the log from the malware bytes scan.
Any help would be much appreciated. I have been trying to get rid of this virus for weeks and have finally caved in.
Startup Programs:
Yes HKCU:Run ctfmon.exe C:\WINDOWS\system32\ctfmon.exe
Yes HKCU:Run ehTray.exe C:\Windows\ehome\ehTray.exe
Yes HKCU:Run WMPNSCFG C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
No HKCU:Run 1160881140 C:\Program Files (x86)\Toshiba Registration\Registration.exe /r “C:\Program Files (x86)\Toshiba Registration\Registration.rpd”
No HKCU:Run dsclogff C:\Users\owner\AppData\Local\Temp\dxdkdcecc\ncdarwxusbs.exe
Yes HKLM:Run Adobe Reader Speed Launcher “C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe”
Yes HKLM:Run QuickTime Task “C:\Program Files (x86)\QuickTime\QTTask.exe” -atboottime
Yes HKLM:Run iTunesHelper “C:\Program Files (x86)\iTunes\iTunesHelper.exe”
Yes HKLM:Run AVG_TRAY C:\Program Files (x86)\AVG\AVG10\avgtray.exe
Yes HKLM:Run Windows Defender %ProgramFiles%\Windows Defender\MSASCui.exe -hide
Yes HKLM:Run COMODO Internet Security “C:\Program Files\COMODO\COMODO Internet Security\cfp.exe” -h
No HKLM:Run 00TCrdMain %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
No HKLM:Run a-squared “C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2guard.exe” /d=60
No HKLM:Run Apoint C:\Program Files\Apoint2K\Apoint.exe
No HKLM:Run BlackBerryAutoUpdate C:\Program Files (x86)\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
No HKLM:Run Camera Assistant Software “C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe” /start
No HKLM:Run cfFncEnabler.exe cfFncEnabler.exe
No HKLM:Run CLMLServer “C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe”
No HKLM:Run COMODO C:\Program Files\COMODO\COMODO livePCsupport\CLPSLA.exe
No HKLM:Run CPA C:\Program Files\COMODO\COMODO livePCsupport\Cpa.exe
No HKLM:Run DivXUpdate “C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe” /CHECKNOW
No HKLM:Run HSON %ProgramFiles%\TOSHIBA\TBS\HSON.exe
No HKLM:Run HWSetup “C:\Program Files\TOSHIBA\Utilities\HWSetup.exe” hwSetUP
No HKLM:Run ITSecMng %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
No HKLM:Run jswtrayutil “C:\Program Files (x86)\Jumpstart\jswtrayutil.exe”
No HKLM:Run KeNotify “C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe”
No HKLM:Run MSSE “c:\Program Files\Microsoft Security Essentials\msseces.exe” -hide -runkey
No HKLM:Run NDSTray.exe NDSTray.exe
No HKLM:Run PCMAgent “C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe”
No HKLM:Run RavTRAY “C:\Program Files (x86)\Rising\RAV\RSTRAY.EXE” -system
No HKLM:Run RtHDVCpl C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
No HKLM:Run Skytel Skytel.exe
No HKLM:Run SmoothView %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
No HKLM:Run SunJavaUpdateSched “C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe”
No HKLM:Run SVPWUTIL “C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe” SVPwUTIL
No HKLM:Run ToshibaServiceStation C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TSS.exe /hide
No HKLM:Run TPwrMain %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
Yes HKLM:RunOnce Malwarebytes’ Anti-Malware “C:\Program Files (x86)\Malwarebytes’ Anti-Malware\mbamgui.exe” /install /silent
Yes Startup User Stardock ObjectDock.lnk C:\Program Files (x86)\Stardock\ObjectDock\ObjectDock.exe
Malwarebytes’:
Malwarebytes’ Anti-Malware 1.51.0.1200
Database version: 6897
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18999
6/19/2011 9:15:26 PM
mbam-log-2011-06-19 (21-15-26).txt
Scan type: Quick scan
Objects scanned: 166388
Time elapsed: 27 minute(s), 3 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Using RegRun There were was one suspicious files:
RES://C:\PROGRA~2\MICROS~1\OFFICE12\EXCEL.EXE/3000 ( I deleted this file)
[attachment deleted by admin]