This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Need this for University Assignments(Redirecting & Freezi

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi! I have a Windows edition laptop. It has Windows Vista Home Basic Service Pack 2. Processor: Intel Celeron 540@ 1.86GHz 1.86GHz Memory RAM 1 GB System Type: 32 - bit Operating System. I am using this laptop to do my college on homework on and I need this checked out immediately as I have assignments due tonight, Sunday, and Monday night. Please help me as soon as possible as this laptop keeps saying it's non-responsive(freezing) and redirecting. I will appreciate all your help. Thanks, Wash09
Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi, Catbyte! This is my 3rd attempt to post the info you requested. As I copy and paste the GMER report the system kept freezing so I will send the DDS and the Attach text first. Then I will try to just attach the GMER report. I hope I did this correct. I also made the donation as well. Thanks for you quick response, Wash09 DDS report: DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 21:15:14.63 on Sat 12/05/2009 Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_15 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1014.214 [GMT -8:00] SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\agrsmsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\TOSHIBA\IVP\ISM\pinger.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Windows\system32\svchost.exe -k imgsvc c:\TOSHIBA\IVP\swupdate\swupdtmr.exe C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\Explorer.EXE C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Toshiba\Power Saver\TPwrMain.exe C:\Program Files\Toshiba\SmoothView\SmoothView.exe C:\Program Files\Toshiba\FlashCards\TCrdMain.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPStart.exe C:\Program Files\Toshiba\ConfigFree\NDSTray.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Windows\WindowsMobile\wmdSync.exe C:\Windows\System32\wpcumi.exe C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Windows\ZSSnp211.exe C:\Windows\Domino.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Program Files\Registry Mechanic\RMTray.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Synaptics\SynTP\SynToshiba.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe C:\Program Files\Java\jre6\bin\jucheck.exe C:\PROGRA~1\MICROS~3\Office12\MSTORDB.EXE C:\Program Files\Internet Explorer\ieuser.exe c:\program files\aol email toolbar\AolMailTbServer.exe C:\Program Files\MSN\Toolbar\3.0.1125.0\msntask.exe C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe C:\Windows\system32\taskeng.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\grandkids\Desktop\dds.pif C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uSearch Page = ${URL_SEARCHPAGE} uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2319576 mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart mSearch Page = ${URL_SEARCHPAGE} uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s uURLSearchHooks: P2P Max Toolbar: {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - c:\program files\p2p_max\tbP2P_.dll uURLSearchHooks: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll uURLSearchHooks: Free TV Bar Toolbar: {a0729639-d831-46c9-811b-9b0aa79fb45a} - c:\program files\free_tv_bar\tbFre0.dll mURLSearchHooks: AOLMAILTBSearch Class: {98572e47-b5fe-43de-9aea-492a1d3064cd} - c:\program files\aol email toolbar\aolmailtb.dll mURLSearchHooks: P2P Max Toolbar: {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - c:\program files\p2p_max\tbP2P_.dll mURLSearchHooks: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll mURLSearchHooks: Free TV Bar Toolbar: {a0729639-d831-46c9-811b-9b0aa79fb45a} - c:\program files\free_tv_bar\tbFre0.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: P2P Max Toolbar: {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - c:\program files\p2p_max\tbP2P_.dll BHO: Free TV Bar Toolbar: {a0729639-d831-46c9-811b-9b0aa79fb45a} - c:\program files\free_tv_bar\tbFre0.dll BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: AOL Email Toolbar Loader: {fbea8524-8c72-4208-9d12-7fb73e9926eb} - c:\program files\aol email toolbar\aolmailtb.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll TB: AOL Email Toolbar: {a3704fa3-dbf6-46b5-b95e-0677dfd39577} - c:\program files\aol email toolbar\aolmailtb.dll TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll TB: P2P Max Toolbar: {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - c:\program files\p2p_max\tbP2P_.dll TB: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll TB: Free TV Bar Toolbar: {a0729639-d831-46c9-811b-9b0aa79fb45a} - c:\program files\free_tv_bar\tbFre0.dll TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File uRun: [1145860967] "c:\program files\toshiba" registration\registration.exe /r "c:\program files\toshiba registration\Registration.rpd" uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [RegistryMechanic] c:\program files\registry mechanic\RMTray.exe /S uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [TPwrMain] "c:\program files\toshiba\power saver\TPwrMain.EXE" mRun: [SmoothView] "c:\program files\toshiba\smoothview\SmoothView.exe" mRun: [00TCrdMain] "c:\program files\toshiba\flashcards\TCrdMain.exe" mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe mRun: [NDSTray.exe] NDSTray.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [BlackBerryAutoUpdate] "c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe" /background mRun: [] mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Skytel] Skytel.exe mRun: [ZSSnp211] c:\windows\ZSSnp211.exe mRun: [Domino] c:\windows\Domino.exe mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\users\grandk~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\deskto~1.lnk - c:\program files\research in motion\blackberry\DesktopMgr.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: &Search IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL LSP: c:\windows\system32\wpclsp.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\grandk~1\appdata\roaming\mozilla\firefox\profiles\wyuqji36.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1814311&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - P2P Max Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1814311&SearchSource=13 FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1814311&SearchSource=2&q= FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll FF - component: c:\users\grandkids\appdata\roaming\mozilla\firefox\profiles\wyuqji36.default\extensions\{72ae8426-3b8d-4ead-b191-8d0ad1c62158}\components\FFExternalAlert.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\users\grandkids\appdata\local\yahoo!\browserplus\2.4.17\plugins\npybrowserplus_2.4.17.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2007-11-12 7168] S2 MyWebSearchService;My Web Search Service;c:\progra~1\mywebs~1\bar\1.bin\mwssvc.exe –> c:\progra~1\mywebs~1\bar\1.bin\mwssvc.exe [?] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-2-22 21504] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-11-12 29744] S3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [2009-7-19 480128] S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\drivers\ZS211.sys [2009-7-19 1537280] =============== Created Last 30 ================ 2009-12-23 13:10:13 5340 —-a-w- c:\windows\system32\4574vizu976a.dll 2009-12-23 11:23:29 13839 —-a-w- c:\windows\system32\589orm35z.ocx 2009-12-21 06:08:08 11399 —-a-w- c:\windows\system32\5bz3sparse9551.dll 2009-12-20 22:45:52 16009 —-a-w- c:\windows\system32\64z1wor5196.cpl 2009-12-20 21:21:51 8093 —-a-w- c:\windows\system32\2639hz5ktool49d.cpl 2009-12-20 14:49:02 13116 —-a-w- c:\windows\system32\z69troj5be.cpl 2009-12-17 16:50:51 11140 —-a-w- c:\windows\system32\50696not-a-viruz9e8.cpl 2009-12-17 09:46:07 9237 —-a-w- c:\windows\system32\36dz9ac5door356.dll 2009-12-13 05:40:49 12635 —-a-w- c:\windows\system32\5e65spzware9021.exe 2009-12-12 17:30:34 17125 —-a-w- c:\windows\system32\z7266vi59s5d3.dll 2009-12-12 06:16:32 16689 —-a-w- c:\windows\system32\19592spam5zt6c6.exe 2009-12-11 23:07:44 7364 —-a-w- c:\windows\system32\14058troj5f9z.cpl 2009-12-06 17:47:41 14689 —-a-w- c:\windows\system32\695cthreat15z7.bin 2009-12-04 10:32:18 8279 —-a-w- c:\windows\system32\59adthreat918z85.ocx 2009-12-04 05:17:45 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf 2009-12-03 14:51:41 0 d—–w- c:\program files\Free_TV_Bar 2009-12-02 21:52:01 13886 —-a-w- c:\windows\system32\54e7addw9re3257z.dll 2009-12-01 15:01:41 7908 —-a-w- c:\windows\system32\1725v59zs5d6.dll 2009-11-30 22:52:01 2048 —-a-w- c:\windows\system32\tzres.dll 2009-11-30 03:23:50 1401856 —-a-w- c:\windows\system32\msxml6.dll 2009-11-30 03:23:45 1248768 —-a-w- c:\windows\system32\msxml3.dll 2009-11-30 03:20:25 714240 —-a-w- c:\windows\system32\timedate.cpl 2009-11-23 15:34:08 13656 —-a-w- c:\windows\system32\14z56w9rm73.bin 2009-11-22 23:48:34 0 d—–w- c:\programdata\Blizzard 2009-11-22 20:21:20 0 d—–w- c:\program files\ToggleEN 2009-11-22 12:08:13 16015 —-a-w- c:\windows\system32\9dz6stea5185.ocx 2009-11-21 14:35:08 6793 —-a-w- c:\windows\system32\1f62th9eaz10598.bin 2009-11-20 20:57:03 10249 —-a-w- c:\windows\system32\192z9not-a-v5rus35e.exe 2009-11-17 10:18:06 0 d—–w- c:\program files\Windows Portable Devices 2009-11-17 10:17:41 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf 2009-11-17 10:11:21 92672 —-a-w- c:\windows\system32\UIAnimation.dll 2009-11-17 10:11:20 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll 2009-11-17 10:11:19 3023360 —-a-w- c:\windows\system32\UIRibbon.dll 2009-11-17 10:09:36 81920 —-a-w- c:\windows\system32\wpdbusenum.dll 2009-11-17 10:07:44 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll 2009-11-17 10:07:44 4096 —-a-w- c:\windows\system32\oleaccrc.dll 2009-11-17 10:07:44 234496 —-a-w- c:\windows\system32\oleacc.dll 2009-11-17 08:58:29 4969 —-a-w- c:\windows\system32\25z2spambot9c.exe 2009-11-14 21:50:57 17727 —-a-w- c:\windows\system32\170thre9tz4654.exe 2009-11-13 03:17:22 2036736 —-a-w- c:\windows\system32\win32k.sys 2009-11-13 03:16:43 355328 —-a-w- c:\windows\system32\WSDApi.dll 2009-11-09 06:38:30 6032 —-a-w- c:\windows\system32\7e80down59azer2709.dll ==================== Find3M ==================== 2009-11-22 21:10:47 38 —-a-w- c:\users\grandkids\jagex_runescape_preferences.dat 2009-11-22 20:55:23 63 —-a-w- c:\users\grandkids\jagex_runescape_preferences2.dat 2009-11-17 10:17:55 665600 —-a-w- c:\windows\inf\drvindex.dat 2009-11-17 10:17:55 51200 —-a-w- c:\windows\inf\infpub.dat 2009-11-17 10:17:54 86016 —-a-w- c:\windows\inf\infstor.dat 2009-11-17 10:17:54 143360 —-a-w- c:\windows\inf\infstrng.dat 2009-11-06 03:43:56 56 —ha-w- c:\programdata\ezsidmv.dat 2009-11-03 04:42:06 195456 ——w- c:\windows\system32\MpSigStub.exe 2009-11-02 20:18:08 3215 —-a-w- c:\windows\system32\591zvir32345.exe 2009-10-27 16:47:29 37665 —-a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont 2009-10-26 19:54:40 7085 —-a-w- c:\windows\system32\20139wzr53e1.exe 2009-10-23 14:39:19 13224 —-a-w- c:\windows\system32\294165acktooz784.bin 2009-10-23 10:33:33 17747 —-a-w- c:\windows\system32\402z59reat25071.bin 2009-10-23 00:58:47 5633 —-a-w- c:\windows\system32\57z7dow59oader1362.dll 2009-10-22 16:30:45 7404 —-a-w- c:\windows\system32\3zfathr5at2929.dll 2009-10-06 17:05:25 7758 —-a-w- c:\windows\system32\4ff2d9wnloader5z3.exe 2009-10-02 12:11:59 4527 —-a-w- c:\windows\system32\17679worm54z5.bin 2009-10-01 01:02:17 2537472 —-a-w- c:\windows\system32\wpdshext.dll 2009-10-01 01:02:05 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe 2009-10-01 01:02:04 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll 2009-10-01 01:02:02 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll 2009-10-01 01:02:00 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll 2009-10-01 01:01:59 546816 —-a-w- c:\windows\system32\wpd_ci.dll 2009-10-01 01:01:59 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll 2009-10-01 01:01:56 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll 2009-10-01 01:01:56 350208 —-a-w- c:\windows\system32\WPDSp.dll 2009-10-01 01:01:56 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll 2009-10-01 01:01:56 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll 2009-10-01 01:01:50 226816 —-a-w- c:\windows\system32\WpdMtp.dll 2009-10-01 01:01:49 61952 —-a-w- c:\windows\system32\WpdMtpUS.dll 2009-10-01 01:01:49 33280 —-a-w- c:\windows\system32\WpdConns.dll 2009-09-28 01:43:43 4964 —-a-w- c:\windows\system32\50399py35z.dll 2009-09-27 22:46:30 12042 —-a-w- c:\windows\system32\1dzdsparse5149.dll 2009-09-25 02:10:10 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll 2009-09-25 02:07:08 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll 2009-09-25 02:04:32 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll 2009-09-25 01:49:22 1554432 —-a-w- c:\windows\system32\xpsservices.dll 2009-09-25 01:48:08 351232 —-a-w- c:\windows\system32\XpsPrint.dll 2009-09-25 01:38:29 847360 —-a-w- c:\windows\system32\OpcServices.dll 2009-09-25 01:36:13 280064 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2009-09-25 01:35:31 135680 —-a-w- c:\windows\system32\XpsRasterService.dll 2009-09-25 01:33:25 195584 —-a-w- c:\windows\system32\dxdiagn.dll 2009-09-25 01:33:15 829440 —-a-w- c:\windows\system32\d3d10warp.dll 2009-09-25 01:33:01 369664 —-a-w- c:\windows\system32\WMPhoto.dll 2009-09-25 01:32:59 252928 —-a-w- c:\windows\system32\dxdiag.exe 2009-09-25 01:31:53 519680 —-a-w- c:\windows\system32\d3d11.dll 2009-09-25 01:31:26 486912 —-a-w- c:\windows\system32\d3d10level9.dll 2009-09-25 01:31:21 161280 —-a-w- c:\windows\system32\d3d10_1.dll 2009-09-25 01:31:19 218112 —-a-w- c:\windows\system32\d3d10_1core.dll 2009-09-25 01:31:16 1030144 —-a-w- c:\windows\system32\d3d10.dll 2009-09-25 01:31:15 828928 —-a-w- c:\windows\system32\d2d1.dll 2009-09-25 01:30:23 481792 —-a-w- c:\windows\system32\dxgi.dll 2009-09-25 01:30:23 190464 —-a-w- c:\windows\system32\d3d10core.dll 2009-09-25 01:27:04 793088 —-a-w- c:\windows\system32\FntCache.dll 2009-09-25 01:27:04 37888 —-a-w- c:\windows\system32\cdd.dll 2009-09-25 01:27:04 1064448 —-a-w- c:\windows\system32\DWrite.dll 2009-09-24 22:54:55 258048 —-a-w- c:\windows\system32\winspool.drv 2009-09-24 22:54:53 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe 2009-09-24 22:54:52 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll 2009-09-21 23:21:16 14484 —-a-w- c:\windows\system32\1730ha59tool1dz.bin 2009-09-20 04:52:12 17821 —-a-w- c:\windows\system32\22985hazktoolbb.dll 2009-09-18 04:21:50 7965 —-a-w- c:\windows\system32\9523thief259z.dll 2009-09-16 23:55:58 2968 —-a-w- c:\windows\system32\z573worm93d.bin 2009-09-10 16:48:01 218624 —-a-w- c:\windows\system32\msv1_0.dll 2009-09-10 14:59:26 8147456 —-a-w- c:\windows\system32\wmploc.DLL 2009-09-10 14:58:28 310784 —-a-w- c:\windows\system32\unregmp2.exe 2009-04-14 03:50:51 174 –sha-w- c:\program files\desktop.ini 2006-11-02 12:39:34 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:39:34 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 12:39:34 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:39:34 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-02-07 07:00:15 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat 2009-02-07 07:00:15 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat 2009-02-07 07:00:15 32768 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat 2008-11-10 23:14:38 4 –sh–r- c:\windows\system32\drivers\taishop.sys ============= FINISH: 21:17:50.32 =============== Attach text: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-12-01.01) Microsoft® Windows Vista™ Home Basic Boot Device: \Device\HarddiskVolume2 Install Date: 11/10/2008 3:21:21 PM System Uptime: 12/4/2009 6:36:19 PM (27 hours ago) Motherboard: Intel Corporation | | SANTA ROSA CRB Processor: Intel® Celeron® CPU 540 @ 1.86GHz | U2E1 | 1862/mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 73 GiB total, 30.105 GiB free. D: is CDROM (CDFS) ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP453: 12/1/2009 4:15:37 PM - Scheduled Checkpoint RP454: 12/2/2009 8:43:06 AM - Scheduled Checkpoint RP455: 12/3/2009 7:35:08 AM - Scheduled Checkpoint RP456: 12/3/2009 9:22:33 PM - Windows Update RP457: 12/5/2009 12:00:09 AM - Scheduled Checkpoint ==== Installed Programs ====================== Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.1.4 Adobe Shockwave Player 11.5 AOL Email Toolbar Apple Mobile Device Support Apple Software Update Atheros Driver Installation Program Big Fish Games Client BlackBerry Desktop Software 4.7 Bluetooth Stack for Windows by Toshiba Bonjour CD/DVD Drive Acoustic Silencer Compatibility Pack for the 2007 Office system Custom Cookbook Download Updater (AOL LLC) DVD MovieFactory for TOSHIBA Free_TV_Bar Toolbar Google Desktop Google Toolbar for Internet Explorer HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) InstallMgr Intel® Graphics Media Accelerator Driver iPod Copy Expert 3.1.2 iTunes Java™ 6 Update 15 Java™ 6 Update 2 Java™ 6 Update 7 LimeWire 5.3.6 Malwarebytes' Anti-Malware Marvell Miniport Driver Microsoft .NET Framework 3.5 SP1 Microsoft Default Manager Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Search Enhancement Pack Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Works Microsoft XML Parser Mozilla Firefox (3.0.15) MSN Toolbar MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Napster Napster Burn Engine Octoshape add-in for Adobe Flash Player OpenOffice.org Installer 1.0 P2P_Max Toolbar Picasa 2 QuickBooks Financial Center QuickTime Realtek High Definition Audio Driver Registry Mechanic 8.0 Roxio Media Manager Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB973704) Security Update for CAPICOM (KB931906) Security Update for Microsoft Office Excel 2007 (KB973593) Security Update for Microsoft Office Outlook 2007 (KB972363) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office Publisher 2007 (KB969693) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Windows Media Encoder (KB954156) Skype web features Skype™ 4.1 Spelling Dictionaries Support For Adobe Reader 8 Synaptics Pointing Device Driver Texas Instruments PCIxx21/x515/xx12 drivers. TIPCI ToggleEN Toolbar TOSHIBA Assist TOSHIBA ConfigFree TOSHIBA Disc Creator TOSHIBA DVD PLAYER TOSHIBA Extended Tiles for Windows Mobility Center TOSHIBA Games TOSHIBA Hardware Setup Toshiba Registration TOSHIBA SD Memory Utilities TOSHIBA Software Modem TOSHIBA Software Upgrades TOSHIBA Speech System Applications TOSHIBA Speech System SR Engine(U.S.) Version1.0 TOSHIBA Speech System TTS Engine(U.S.) Version1.0 TOSHIBA Value Added Package Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 (KB974561) Update for Microsoft Office Word 2007 Help (KB963665) Update for Outlook 2007 Junk Email Filter (kb975960) Windows Media Encoder 9 Series World of Warcraft Trial Yahoo! BrowserPlus Yahoo! Messenger Yahoo! Toolbar ZSMC USB PC Camera (ZS0211) ==== Event Viewer Messages From Past Week ======== 12/3/2009 7:15:58 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service. 12/3/2009 6:43:59 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Roxio Hard Drive Watcher 9 service to connect. 12/3/2009 6:43:59 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 12/3/2009 6:43:59 PM, Error: Service Control Manager [7000] - The My Web Search Service service failed to start due to the following error: The system cannot find the path specified. 12/3/2009 6:42:32 PM, Error: EventLog [6008] - The previous system shutdown at 6:41:20 PM on 12/3/2009 was unexpected. 12/2/2009 8:00:28 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AudioEndpointBuilder service. 12/2/2009 7:52:40 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WPDBusEnum service. 12/2/2009 7:52:10 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SysMain service. 12/2/2009 7:51:40 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the EMDMgmt service. 12/2/2009 7:51:09 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service. 12/2/2009 7:03:40 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {A47979D2-C419-11D9-A5B4-001185AD2B89} to the user grandkids-PC\grandkids SID (S-1-5-21-2805069600-1852196859-333169573-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. 12/2/2009 2:23:42 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the UxSms service. 12/2/2009 2:23:12 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TabletInputService service. 12/1/2009 3:26:42 PM, Error: EventLog [6008] - The previous system shutdown at 3:25:09 PM on 12/1/2009 was unexpected. 11/30/2009 2:35:32 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service. ==== End Of File ===========================
Ok, I keep trying to upload this file. I can't get this report to copy and paste nor attached. I keep getting, "I didn't choose a file to upload." What should I do now. I have it save on my desktop. I was also wondering would the computer let me know when this report was finish? I kind of assume it was done as I waited for a few minutes and nothing happened. So I hit the save button after checking to see that the scroll bar was all the way at the bottom. So, I'm just wondering if I waited long enough to get a completed report.
try sending it to a zip file and attach it. In the mean time, do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
I am still trying to run Combofix. For some reason the laptop shuts down on it on and tells me it did it unexpectedly. I then wait to see it the report is going to generate and it doesn't. So please be patient with me. I will try again after i get off of work. wash09
Try running ComboFix in safe mode if it will not run in normal mode. Tap F8 on bootup till a menu appears…arrow up to safemode with networking > enter
Hi, Catbyte! Here is the combofix file. ComboFix 09-12-08.03 - grandkids 12/08/2009 18:52:12.1.1 - x86 MINIMAL Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1014.614 [GMT -8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-2805069600-1852196859-333169573-500 c:\program files\sFX c:\windows\100z8tr9jb75.dll c:\windows\10209spambot5z7.bin c:\windows\102z65orm59a.bin c:\windows\1030zack9o5l238.ocx c:\windows\104559acktoolzbd.bin c:\windows\104zw9rm7b5.ocx c:\windows\10570wozm391.bin c:\windows\10915virus9fz5.exe c:\windows\10z049pambot2575.ocx c:\windows\11519hackto9z50c.bin c:\windows\1153z9py10.cpl c:\windows\1155zddwar9284.exe c:\windows\1156th9efz50.cpl c:\windows\1205bac5doz91087.ocx c:\windows\1235vzr2901.bin c:\windows\12720hac9to5lz12.exe c:\windows\1275s9eal2z37.exe c:\windows\1285sparze24619.dll c:\windows\12875s5ambzt5be9.ocx c:\windows\12890spambot295z.dll c:\windows\12z31vi9us65a5.dll c:\windows\1349vzr538.ocx c:\windows\13958hazk9oold9.bin c:\windows\13e6sp9rse3095z.cpl c:\windows\1407virz59.dll c:\windows\14277sz5mb9t614.cpl c:\windows\1434zvi9us4f5.ocx c:\windows\144azhreat913755.bin c:\windows\15068v9rzs2f5.ocx c:\windows\15254woz5519.dll c:\windows\15359noz-a-v9rus7a3.ocx c:\windows\1546viz9157.dll c:\windows\157dbackdzor2905.dll c:\windows\15801w5rm90z.bin c:\windows\15828zpy19b.bin c:\windows\15928tr5j5zd.bin c:\windows\15995troz765.dll c:\windows\159z9virus7d7.exe c:\windows\15b5parze8689.ocx c:\windows\1639not-a9vi5us57ez.cpl c:\windows\16570not-a-vzru9597.ocx c:\windows\16579troj49fz.cpl c:\windows\169199ot-a-vir5z5ca.bin c:\windows\1710no9-azvirus51e.cpl c:\windows\171zworm4359.cpl c:\windows\17593not-a-viz9s640.bin c:\windows\17f9sparse2z95.dll c:\windows\18004wo9m53z.ocx c:\windows\181959zambot504.ocx c:\windows\1840z5ot-a-vi9us7d2.bin c:\windows\1858zhacktool1f9.bin c:\windows\1893downzoad5r840.exe c:\windows\19057virus3dz.dll c:\windows\19085s9ambot3z9.dll c:\windows\19195vzru57249.ocx c:\windows\19393t5oj96z.exe c:\windows\19839zo5m29d.ocx c:\windows\19885noz-a-5ir9s41d.dll c:\windows\19z09h5cktool13d.exe c:\windows\19z36w5rm5c1.bin c:\windows\1b5fs9y5are13z9.dll c:\windows\1c3stz9l5457.ocx c:\windows\1e89ad5wzre1109.cpl c:\windows\1z786spy69b5.cpl c:\windows\20325spambotz9.exe c:\windows\2102add5arz2955.bin c:\windows\21120not-a-vir9s1z85.cpl c:\windows\21454sza5bo9465.bin c:\windows\2221ha9ktooz61c5.bin c:\windows\22317not-a-vir5sz19.bin c:\windows\22342nz9-a-vi5us251.exe c:\windows\233z35p976c.exe c:\windows\23555trz91e5.ocx c:\windows\23927hacktoz51da.cpl c:\windows\23979spyz95.bin c:\windows\23edspzware925.ocx c:\windows\23f0d59nlzader2513.cpl c:\windows\24019zpy505.cpl c:\windows\24207worm9z5.ocx c:\windows\24599virus5z.ocx c:\windows\245bstzal31119.ocx c:\windows\24z03tr9j6595.exe c:\windows\25024notza-virus9f5.dll c:\windows\2506thiez29505.ocx c:\windows\250zvi91832.cpl c:\windows\25229troz1bf5.dll c:\windows\25265tz9j6ac.exe c:\windows\2548virz1289.cpl c:\windows\254asparze2944.ocx c:\windows\254z35py13f9.ocx c:\windows\25529izus5aa.cpl c:\windows\25559ackzoor239.bin c:\windows\2555stzal2975.cpl c:\windows\255baddware1z449.dll c:\windows\25995worz5199.ocx c:\windows\25a0vzr19885.bin c:\windows\25z49py555.ocx c:\windows\262edow9lzader3055.bin c:\windows\26545not-9zv5rus393.dll c:\windows\26812zot-a-vi95s27b.cpl c:\windows\2693zhief1856.exe c:\windows\26zad9wnloade51294.bin c:\windows\270d9ir2725z.ocx c:\windows\2742w5z97fb.cpl c:\windows\27558vir9sz5.exe c:\windows\2794viruz5b2.bin c:\windows\27besparse19z65.ocx c:\windows\27z4sp5rse1992.ocx c:\windows\28140z9ambot1535.cpl c:\windows\2819ownloader158z.cpl c:\windows\28237s9z250.cpl c:\windows\28795hackzool671.exe c:\windows\28798szy55d.bin c:\windows\28d5sparse1940z.bin c:\windows\2928nzt-a5virus425.exe c:\windows\293ds5ywarz1996.dll c:\windows\29555ownloazer1222.ocx c:\windows\29679pam5ot2z7.dll c:\windows\29793tzoj5a85.dll c:\windows\29943s5amboz9b.bin c:\windows\2b45a9dw5rz896.cpl c:\windows\2ba2ba5kd9or4z3.cpl c:\windows\2bc8dow9loadzr5855.exe c:\windows\2bcfbackdo9r2z58.dll c:\windows\2cbbackzoo923585.ocx c:\windows\2d5zdo5nloader1992.dll c:\windows\2z051worm391.bin c:\windows\2z19backdo9r1135.dll c:\windows\2z1hacktoo951d5.ocx c:\windows\2z52vir2594.bin c:\windows\2z597troj491.bin c:\windows\2z7439a5ktool548.bin c:\windows\2z8a59ief2958.ocx c:\windows\30229sp9mzot15c.ocx c:\windows\30399tro5z8c.exe c:\windows\309249z5558.cpl c:\windows\30z25spa5bot4979.dll c:\windows\31060s596fbz.dll c:\windows\31069zack9ool85.exe c:\windows\3140559rmz13.bin c:\windows\319z25acktoo921a.dll c:\windows\3209859zm3.bin c:\windows\32335sza59ot645.cpl c:\windows\323539pam5ot54z.cpl c:\windows\3254thr9az14617.bin c:\windows\32579spazbo59da.cpl c:\windows\3265hacztoo5907.cpl c:\windows\33b6dzwnlo9der22655.ocx c:\windows\3508szam9ot382.dll c:\windows\3553adzware439.cpl c:\windows\35619wo9m12z.exe c:\windows\3578th9ef33z.bin c:\windows\35949vzrus515.bin c:\windows\35z1spambot598.ocx c:\windows\3804thzea953529.dll c:\windows\39219tro5za0.dll c:\windows\393zth9eat3885.ocx c:\windows\39517hzcktool36.cpl c:\windows\39815z97d7.cpl c:\windows\39z6h5cktool93.bin c:\windows\3b05ste9l30z5.bin c:\windows\3dcazdware5199.bin c:\windows\3ez9thief1865.ocx c:\windows\3f925hreat10z54.bin c:\windows\3fb1spar5z1996.ocx c:\windows\3fd0doznl9ade52963.bin c:\windows\3ze5bac9door3012.ocx c:\windows\4003zhr9at20059.dll c:\windows\4015thre9t28588z.dll c:\windows\4067w9rm5aaz.ocx c:\windows\40ed9pywar5z072.dll c:\windows\4149ir15z0.cpl c:\windows\4298t5oj5cz.bin c:\windows\429thiez5265.exe c:\windows\4499sp5wzre2016.dll c:\windows\4525steal139z.ocx c:\windows\4590bazk5oor2942.cpl c:\windows\4599threat21z199.cpl c:\windows\45z5addwa9e210.ocx c:\windows\472zorm2495.bin c:\windows\47739zief2758.bin c:\windows\49055zr2419.bin c:\windows\4915viz359.ocx c:\windows\49509zd5are1534.exe c:\windows\49b4t5r9at12z04.exe c:\windows\49bzdownloade5112.dll c:\windows\49d85zr1693.bin c:\windows\49z2ha95toole8.bin c:\windows\4c6spyw9re5z55.exe c:\windows\4c8bzownl95der2316.bin c:\windows\4dacdzwnloade5629.dll c:\windows\4e11back59zr2111.cpl c:\windows\4f059ir49z.bin c:\windows\4fz295eal416.exe c:\windows\5003hacktoolz93.cpl c:\windows\502fa9dwarz116.cpl c:\windows\502fv5r249z.ocx c:\windows\511zs9arse1200.ocx c:\windows\51f9backz9or1796.dll c:\windows\520stea9897z.dll c:\windows\5283spambzt9a9.ocx c:\windows\52886hackzoolf59.bin c:\windows\529z2spam9ot663.dll c:\windows\53262hacztool3f9.bin c:\windows\5370zr9j5cb.bin c:\windows\5407virz9739.exe c:\windows\5537thzef9394.dll c:\windows\5552zir9s4f8.dll c:\windows\55539parse27z4.exe c:\windows\5553worm95dz.bin c:\windows\5559viruz579.dll c:\windows\556h9cktozl75.dll c:\windows\5577stezl31549.bin c:\windows\5592spywzre214.ocx c:\windows\55e75hzea99022.dll c:\windows\5606zack5oor249.bin c:\windows\560fst9al1z48.cpl c:\windows\56z7ha9ktool262.exe c:\windows\57544z9ambot228.ocx c:\windows\5756s9ambot50cz.cpl c:\windows\5766tzo9754.cpl c:\windows\5789zir1337.dll c:\windows\57z5t5oj985.exe c:\windows\58705pambot916z.exe c:\windows\5894noz5a-virus5d19.exe c:\windows\5896zspy22e.cpl c:\windows\5898wor95z.cpl c:\windows\58c29hrea523z58.cpl c:\windows\58e8do9nloadzr567.ocx c:\windows\59206zroj20d.cpl c:\windows\592s5eaz715.exe c:\windows\5967downlo9derz550.cpl c:\windows\596fzparse11585.ocx c:\windows\597z8spy149.ocx c:\windows\59d2stez52332.ocx c:\windows\59f9steal1815z.exe c:\windows\59z7troj995.bin c:\windows\5ae9bac5dooz1417.bin c:\windows\5b55vz59894.ocx c:\windows\5c349teal1030z.exe c:\windows\5c79vzr1543.bin c:\windows\5cc95tezl3029.cpl c:\windows\5cf4dow59oazer1334.dll c:\windows\5dce9hiez853.dll c:\windows\5f58addw5rz15819.exe c:\windows\5z24th5eat7698.dll c:\windows\5z25spyw9re2916.dll c:\windows\5z5699orm470.exe c:\windows\5z7fvir2539.exe c:\windows\5z97bac5door3194.exe c:\windows\6055spambzt4f9.dll c:\windows\6250thie97z0.exe c:\windows\6430b5c9dozr1068.bin c:\windows\64d0backdozr596.dll c:\windows\6528backz9or1567.cpl c:\windows\6561downloz9er1979.exe c:\windows\6566v9z1767.exe c:\windows\6592sparze3143.exe c:\windows\659fspar5e25z5.exe c:\windows\65z1thief9055.ocx c:\windows\661b5hr9at15754z.bin c:\windows\67549ot-a-zirus2f1.ocx c:\windows\6805vir2709z.bin c:\windows\6a18vzr5059.bin c:\windows\6a59thief9279z.ocx c:\windows\6ae6spz5are1559.bin c:\windows\6b3bbackz9or5039.cpl c:\windows\6b60tz5ea92469.exe c:\windows\6f19doznload5r3001.cpl c:\windows\6f33stealz599.cpl c:\windows\6f36d5wnl9aderz40.exe c:\windows\6f74stezl28895.cpl c:\windows\6ff1s95zse1175.dll c:\windows\6z19vir5640.ocx c:\windows\7195spazse1042.ocx c:\windows\71e2stea93255z.cpl c:\windows\7293vizus325.cpl c:\windows\7363w9r54z7.ocx c:\windows\7404ztea56139.cpl c:\windows\7455nzt-9-5irus7bb.bin c:\windows\749z5hreat29439.cpl c:\windows\74c2d9wnlo5der1z01.ocx c:\windows\74zback9oo52867.exe c:\windows\7546spyz91.ocx c:\windows\7568adzware259.exe c:\windows\75a69ownlo5dez808.dll c:\windows\75z0spyware9566.cpl c:\windows\763zback9o5r968.ocx c:\windows\77259ackdoor464z.ocx c:\windows\77d5thre9t1145z.ocx c:\windows\77dcszywar515459.exe c:\windows\781d5zea9544.exe c:\windows\7915spa5se1z9.ocx c:\windows\7971thzef5712.ocx c:\windows\798zs5y51e.dll c:\windows\7994hac5tozl2a8.ocx c:\windows\7a53stzal5509.ocx c:\windows\7a70downloade59z1.ocx c:\windows\7b96sp9r5e7z5.bin c:\windows\7ccthr9zt16857.ocx c:\windows\7d6f5hie92671z.ocx c:\windows\7da0s5arse1z79.dll c:\windows\7e15t9iefz179.exe c:\windows\7ec2bac9zoor3635.cpl c:\windows\7ecfthie5z129.ocx c:\windows\7f09v5z3251.bin c:\windows\7z92hackt9ol588.ocx c:\windows\7ze25hi9f3219.cpl c:\windows\850zworm1905.cpl c:\windows\85z9iruse.cpl c:\windows\8693sp5mboz3fa.dll c:\windows\9045hackt59l4z7.exe c:\windows\90505spz40.exe c:\windows\907ethr5zt9252.bin c:\windows\9099noz-a-vi5us709.cpl c:\windows\90a7spy5are1236z.ocx c:\windows\91541h5ckzool183.exe c:\windows\915esparsz1913.cpl c:\windows\91766z5oj245.dll c:\windows\9234zv5rus51e.bin c:\windows\9265no9-a-zi5us5e2.dll c:\windows\93829s5y1bz.dll c:\windows\93950spa5bot3zd.dll c:\windows\9396vzr95599.bin c:\windows\9406z9y75d.cpl c:\windows\9522tz5j209.dll c:\windows\957a5iz457.bin c:\windows\95z0steal3029.exe c:\windows\95zthreat50099.dll c:\windows\96z87worm651.ocx c:\windows\99954hacktoolz9c.dll c:\windows\9a52addware221z.cpl c:\windows\9ae0downloa5erz341.ocx c:\windows\9czste59145.bin c:\windows\9e53vir8z.cpl c:\windows\9f3b5ckdoor2z88.bin c:\windows\9f5ethiefz52.dll c:\windows\9z6cthief456.bin c:\windows\a95spy5are54z.dll c:\windows\b199hreat52z6.cpl c:\windows\prxid93ps.dat c:\windows\system32\10145zot-a-virus2595.ocx c:\windows\system32\10385t9oj269z.dll c:\windows\system32\104425izus1d9.bin c:\windows\system32\105289a5kzool31e.ocx c:\windows\system32\10833v5ru96z4.ocx c:\windows\system32\11906nz5-a-virus646.exe c:\windows\system32\11944tzoj195.bin c:\windows\system32\1197spywarz2657.ocx c:\windows\system32\12439noz-a-5irus2d2.cpl c:\windows\system32\12888hz5ktool2b9.bin c:\windows\system32\135259arse680z.bin c:\windows\system32\13656h9czt5ol2cd.bin c:\windows\system32\137z9hacktoo5298.exe c:\windows\system32\13929spazbo95df5.ocx c:\windows\system32\13easzar5e9625.bin c:\windows\system32\13z26spambot55d9.dll c:\windows\system32\14058troj5f9z.cpl c:\windows\system32\1455t9rezt12959.exe c:\windows\system32\14z56w9rm73.bin c:\windows\system32\1525ha9ktoolz01.ocx c:\windows\system32\1555z9orm1a4.bin c:\windows\system32\155fvir30z9.bin c:\windows\system32\15934szy5379.dll c:\windows\system32\15981spamboz305.exe c:\windows\system32\163169ack5ool6cz.cpl c:\windows\system32\1642zs9557a.cpl c:\windows\system32\16902wzrm15.cpl c:\windows\system32\16961wo5mzb.exe c:\windows\system32\1698zpyw5re919.cpl c:\windows\system32\16bczi52489.dll c:\windows\system32\16bedzw9lo5der3002.ocx c:\windows\system32\16z959roj17c5.ocx c:\windows\system32\170thre9tz4654.exe c:\windows\system32\17116hac5zool934.cpl c:\windows\system32\1725v59zs5d6.dll c:\windows\system32\1730ha59tool1dz.bin c:\windows\system32\17350nzt-a-v9rus2ca.dll c:\windows\system32\17621notza-virus7395.bin c:\windows\system32\17679worm54z5.bin c:\windows\system32\1795zorm795.exe c:\windows\system32\18157spamb9t3za5.exe c:\windows\system32\18195not-5-vir9z41f.ocx c:\windows\system32\1835spyw9re3z51.bin c:\windows\system32\184925o9-a-virus55z.dll c:\windows\system32\1858zspambo93bb.ocx c:\windows\system32\18695teal1z86.dll c:\windows\system32\18796haczt5ol222.ocx c:\windows\system32\188305o9-a-zirus5fe.exe c:\windows\system32\19186zp9m5ot2f6.bin c:\windows\system32\1924not-5-virus7cz.bin c:\windows\system32\192z9not-a-v5rus35e.exe c:\windows\system32\1951downloazer784.cpl c:\windows\system32\1955spambzt6dd9.ocx c:\windows\system32\19591not-a-viruszf2.exe c:\windows\system32\19592spam5zt6c6.exe c:\windows\system32\195z7spa5bot26e.ocx c:\windows\system32\19a2v5r9z81.ocx c:\windows\system32\19e2z5ief2155.cpl c:\windows\system32\19z25worm49b.exe c:\windows\system32\1c47steaz99075.bin c:\windows\system32\1c929ownload5rz741.cpl c:\windows\system32\1cd2szyware29655.ocx c:\windows\system32\1cz0ste5l997.dll c:\windows\system32\1dzdsparse5149.dll c:\windows\system32\1ee5download9r194z.exe c:\windows\system32\1f01ba9kdo5rz407.ocx c:\windows\system32\1f62th9eaz10598.bin c:\windows\system32\1f9f5d9wzre1871.ocx c:\windows\system32\1febthi9f559z.cpl c:\windows\system32\1ff5thief95z7.dll c:\windows\system32\1z42sp9105.cpl c:\windows\system32\1z774t5oj90.cpl c:\windows\system32\20139wzr53e1.exe c:\windows\system32\20150no9-a-virus63ez.dll c:\windows\system32\2040backd9orz775.cpl c:\windows\system32\20507spy950z.dll c:\windows\system32\205as9arze89.exe c:\windows\system32\2060no9-a-vi5zs743.bin c:\windows\system32\20z5t9ief85.bin c:\windows\system32\21082hackt9ol559z.dll c:\windows\system32\21265spamzot2f59.ocx c:\windows\system32\215zir5972.cpl c:\windows\system32\21z78tr9j5e5.ocx c:\windows\system32\222309ot-a-vizus4f5.dll c:\windows\system32\2295vir30z75.ocx c:\windows\system32\22985hazktoolbb.dll c:\windows\system32\22a4v9z3255.bin c:\windows\system32\23366s5y9z3.exe c:\windows\system32\2376dow9lozd5r418.dll c:\windows\system32\23895spa9bzt27.exe c:\windows\system32\2393zi5320.exe c:\windows\system32\2398sp5mbzt74b9.dll c:\windows\system32\24318ha5kto9lz0.dll c:\windows\system32\24621zot-a-5ir9s69d.cpl c:\windows\system32\25294trzj50f.ocx c:\windows\system32\25369not-z-virus659.dll c:\windows\system32\25491tz9j53f.exe c:\windows\system32\25537zo9mdb.dll c:\windows\system32\2589vzr1645.ocx c:\windows\system32\259e9parse55z4.cpl c:\windows\system32\25z2spambot9c.exe c:\windows\system32\26027t9oj65z.ocx c:\windows\system32\2639hz5ktool49d.cpl c:\windows\system32\26491s9azb5t763.cpl c:\windows\system32\26f2b5ckdoo9z32.cpl c:\windows\system32\2735zackdoor3159.ocx c:\windows\system32\2740z9a5ktool1c.cpl c:\windows\system32\27z54wor5309.dll c:\windows\system32\2828z5ambot49f.bin c:\windows\system32\28622hackt9oz58.dll c:\windows\system32\2909z5ir9s451.bin c:\windows\system32\291vir35z3.bin c:\windows\system32\293cthr9at1654z.bin c:\windows\system32\294165acktooz784.bin c:\windows\system32\2946z5pambot31f.ocx c:\windows\system32\29542not-a-vizus7c5.exe c:\windows\system32\2989zhief2535.cpl c:\windows\system32\2b9bvir2z555.dll c:\windows\system32\2ba6addwa59z227.cpl c:\windows\system32\2be9thzef957.cpl c:\windows\system32\2bzeback9o5r2398.dll c:\windows\system32\2da5thi9z1268.exe c:\windows\system32\2e5bbackdoor429z.exe c:\windows\system32\2eaav5977z.ocx c:\windows\system32\2fa1tzreat19953.exe c:\windows\system32\2z006w9rm45d.dll c:\windows\system32\2z457spambot5ef9.exe c:\windows\system32\2z769sp9mbot2b5.dll c:\windows\system32\2zacthr9at16542.cpl c:\windows\system32\30z59virus74.bin c:\windows\system32\3101tr9j2zb5.dll c:\windows\system32\315astea59z07.ocx c:\windows\system32\31z7thr9at21675.ocx c:\windows\system32\32796vzrus52e5.ocx c:\windows\system32\329adown5oad9z919.ocx c:\windows\system32\3317spazse5995.cpl c:\windows\system32\3435d9wnloader2z75.exe c:\windows\system32\3517no9-a5virzs5.exe c:\windows\system32\35433spy9bz.ocx c:\windows\system32\358bs5ez91640.dll c:\windows\system32\3598zhreat59850.ocx c:\windows\system32\36dz9ac5door356.dll c:\windows\system32\3859dzwnloader5599.exe c:\windows\system32\3915backdoor278z.ocx c:\windows\system32\39165py6z9.cpl c:\windows\system32\39356virus3z7.cpl c:\windows\system32\395b9irz61.dll c:\windows\system32\3982tzoj5759.dll c:\windows\system32\39a3th5eat31z04.ocx c:\windows\system32\3a55thief9z60.bin c:\windows\system32\3d6259ealz839.cpl c:\windows\system32\3e94thzef59.exe c:\windows\system32\3z33st5a92776.cpl c:\windows\system32\3z760s9y78b5.bin c:\windows\system32\3zc0d5wnload9r835.cpl c:\windows\system32\3zd5spa5se9571.ocx c:\windows\system32\3zfathr5at2929.dll c:\windows\system32\402z59reat25071.bin c:\windows\system32\4125dzwn9oader534.dll c:\windows\system32\415959ckdoor2277z.bin c:\windows\system32\416znot9a-v5rus5e8.ocx c:\windows\system32\4279n5t9a-virzs485.cpl c:\windows\system32\429zackdoor5072.exe c:\windows\system32\4308n5t-a-9iruszdf.dll c:\windows\system32\439zs9ambot15e.dll c:\windows\system32\44109or5z54.ocx c:\windows\system32\445a5pyware894z.ocx c:\windows\system32\4555thi9f1z4.dll c:\windows\system32\4574vizu976a.dll c:\windows\system32\4789szywa5e1245.ocx c:\windows\system32\48155iru92cez.ocx c:\windows\system32\4a8da5dw9rz1457.ocx c:\windows\system32\4bz8spar9e7125.bin c:\windows\system32\4c2c5parsz1937.bin c:\windows\system32\4c6zs9eal853.dll c:\windows\system32\4dczv9535.bin c:\windows\system32\4fa7stea579z.dll c:\windows\system32\4ff2d9wnloader5z3.exe c:\windows\system32\50399py35z.dll c:\windows\system32\5058spar9e44z.dll c:\windows\system32\50696not-a-viruz9e8.cpl c:\windows\system32\50848ha9ktozl681.exe c:\windows\system32\50b5sp9rze2256.exe c:\windows\system32\5271zparse13795.ocx c:\windows\system32\52cbsteaz591.bin c:\windows\system32\5302zparse9254.exe c:\windows\system32\5353zroj4339.ocx c:\windows\system32\5367zd5wa9e1592.bin c:\windows\system32\53979troz5be.bin c:\windows\system32\53efdownlza5er9931.cpl c:\windows\system32\5402w9zm66c.exe c:\windows\system32\54e7addw9re3257z.dll c:\windows\system32\55cespy9zr52394.ocx c:\windows\system32\55easpar9520z9.cpl c:\windows\system32\55z6add9are35.cpl c:\windows\system32\56109not-a-vi9us1zf.ocx c:\windows\system32\562bdownz9ader3103.ocx c:\windows\system32\5649downlozde9757.cpl c:\windows\system32\5710spy4zc9.ocx c:\windows\system32\5741s9z492.exe c:\windows\system32\577wo5m391z.cpl c:\windows\system32\579d5parse1112z.ocx c:\windows\system32\57z7dow59oader1362.dll c:\windows\system32\5867t5i9f226z.ocx c:\windows\system32\589cd5wnloadzr513.ocx c:\windows\system32\589orm35z.ocx c:\windows\system32\58d4spa9ze2691.bin c:\windows\system32\58d7sp95arez091.ocx c:\windows\system32\591zvir32345.exe c:\windows\system32\592asteal2z45.bin c:\windows\system32\593espyw5re27z5.cpl c:\windows\system32\5949stealz736.ocx c:\windows\system32\5961zhief2824.exe c:\windows\system32\5971spazbot45b.ocx c:\windows\system32\59a5zir9672.exe c:\windows\system32\59adthreat918z85.ocx c:\windows\system32\59cdvir312z.cpl c:\windows\system32\59z5downloa9er2806.bin c:\windows\system32\5az8sp9ware806.ocx c:\windows\system32\5b5ado9nloader1z44.cpl c:\windows\system32\5b699hrezt7375.cpl c:\windows\system32\5b99iz2599.dll c:\windows\system32\5bd5baczdoor9483.dll c:\windows\system32\5bz3sparse9551.dll c:\windows\system32\5c9fst5zl2399.ocx c:\windows\system32\5cdathze91180.ocx c:\windows\system32\5d1azackdoor2392.bin c:\windows\system32\5d59backdooz2828.bin c:\windows\system32\5d69zhief32465.ocx c:\windows\system32\5d9dthiefz921.cpl c:\windows\system32\5e5tz59f1459.exe c:\windows\system32\5e65spzware9021.exe c:\windows\system32\5f319irz585.ocx c:\windows\system32\5fd9sparsz2564.cpl c:\windows\system32\5ff35ownlozder1798.dll c:\windows\system32\5z098hacktool4849.dll c:\windows\system32\5z39ba9kdoo5963.ocx c:\windows\system32\5z696wo9m616.cpl c:\windows\system32\5z74spywar53269.ocx c:\windows\system32\5z97spamb9t1cb.bin c:\windows\system32\5zf9steal582.dll c:\windows\system32\613zad95are1957.ocx c:\windows\system32\61fcste5lz928.bin c:\windows\system32\62b75ackdo9r31z4.cpl c:\windows\system32\64fddo9z5oader3233.ocx c:\windows\system32\64z1wor5196.cpl c:\windows\system32\6509spamzot6c19.dll c:\windows\system32\6889download5rz94.dll c:\windows\system32\695cthreat15z7.bin c:\windows\system32\699stealz055.cpl c:\windows\system32\69e6thizf595.ocx c:\windows\system32\69z5addware920.bin c:\windows\system32\6bbb9ckdozr1854.cpl c:\windows\system32\6da9sz9wa5e714.dll c:\windows\system32\6e95thief67z.ocx c:\windows\system32\6z9avi5992.exe c:\windows\system32\712e9ackdoor3058z.dll c:\windows\system32\72z7stea9575.ocx c:\windows\system32\7390tzoj795.bin c:\windows\system32\73fftzie95670.dll c:\windows\system32\749zt5ief2344.bin c:\windows\system32\749zw9rm235.dll c:\windows\system32\7528hazktool6a9.cpl c:\windows\system32\75309ackdozr2951.bin c:\windows\system32\755evirz958.cpl c:\windows\system32\7570vir275z9.dll c:\windows\system32\7580notza-virus309.bin c:\windows\system32\758395oz3af.ocx c:\windows\system32\758895reat5z09.dll c:\windows\system32\75a5thief30z9.bin c:\windows\system32\75bzspar9536.bin c:\windows\system32\77z2vir2495.cpl c:\windows\system32\79a0d9wnloadz51494.bin c:\windows\system32\7a0daddware29z59.exe c:\windows\system32\7a4eszar9e22535.bin c:\windows\system32\7b2ba9kd5oz502.bin c:\windows\system32\7e80down59azer2709.dll c:\windows\system32\7f01b9ck5oor7z6.bin c:\windows\system32\7z24downloader28985.ocx c:\windows\system32\7z34d95nloader297.ocx c:\windows\system32\7z3fa5dwar91552.dll c:\windows\system32\7z74download952227.ocx c:\windows\system32\865zt9al2545.dll c:\windows\system32\878zno5-a-virus659.dll c:\windows\system32\901735orz5e5.ocx c:\windows\system32\909fzddware159.dll c:\windows\system32\90f5z5dware752.exe c:\windows\system32\913cthief2z51.bin c:\windows\system32\92665vzrus15.ocx c:\windows\system32\93495pywarez330.dll c:\windows\system32\9436tr9jz325.dll c:\windows\system32\94865teal2389z.ocx c:\windows\system32\9507troz2d6.exe c:\windows\system32\951sp5417z.exe c:\windows\system32\9523thief259z.dll c:\windows\system32\9525trzj193.exe c:\windows\system32\952zvi9us358.exe c:\windows\system32\95511wo5mz6c.ocx c:\windows\system32\957505izus51c.dll c:\windows\system32\9582zddware2476.dll c:\windows\system32\9590zd5ware848.cpl c:\windows\system32\9592trzj16f.bin c:\windows\system32\959szy725.ocx c:\windows\system32\95c8tzief1582.ocx c:\windows\system32\95z07spy43a.cpl c:\windows\system32\9835zroj590.cpl c:\windows\system32\992z5p93a1.cpl c:\windows\system32\9a0zp5rse1925.bin c:\windows\system32\9b99stea51z6.dll c:\windows\system32\9bb6spywar51z90.exe c:\windows\system32\9c5doznloade53125.ocx c:\windows\system32\9cb9ze5l713.exe c:\windows\system32\9dz6stea5185.ocx c:\windows\system32\9e57thiez1586.dll c:\windows\system32\9e7edownlozder1151.cpl c:\windows\system32\b3695r1145z.cpl c:\windows\system32\cb7dow9lo5zer2012.bin c:\windows\system32\d4fdownl59dzr2648.exe c:\windows\system32\dfet9reat1599z.ocx c:\windows\system32\e3cdz9nl5ader2570.cpl c:\windows\system32\ff5thrz9t29326.ocx c:\windows\system32\z0dback59or255.bin c:\windows\system32\z0f7add5are32089.ocx c:\windows\system32\z1449tr5j3e9.cpl c:\windows\system32\z149t5reat8782.exe c:\windows\system32\z1535spy91b.dll c:\windows\system32\z18f9i51946.cpl c:\windows\system32\z2976not-a-v5rus158.dll c:\windows\system32\z2abste593215.dll c:\windows\system32\z368t9oj1a85.ocx c:\windows\system32\z439backdoor295.dll c:\windows\system32\z4599hief1819.ocx c:\windows\system32\z5197spy605.dll c:\windows\system32\z573worm93d.bin c:\windows\system32\z5890vir9s652.cpl c:\windows\system32\z5addwa591510.ocx c:\windows\system32\z5b2a9dwar51931.bin c:\windows\system32\z5c9v5r1397.ocx c:\windows\system32\z6f2addware19475.ocx c:\windows\system32\z71v9r28595.dll c:\windows\system32\z7266vi59s5d3.dll c:\windows\system32\z837vir99095.dll c:\windows\system32\z884thi5f23499.ocx c:\windows\system32\z95addwa9e729.cpl c:\windows\system32\z985vir2384.dll c:\windows\th823567.dat c:\windows\z1499spambot255.exe c:\windows\z1971spambot1995.ocx c:\windows\z22685roj359.dll c:\windows\z3004troj9e55.dll c:\windows\z3635worm791.ocx c:\windows\z3a4vi5779.exe c:\windows\z3b6thr5a929274.bin c:\windows\z40ead5w9re83.ocx c:\windows\z5edthief27309.cpl c:\windows\z6265pamb9t7c9.ocx c:\windows\z6904spy2515.bin c:\windows\z74515irus292.exe c:\windows\z791addwa951171.exe c:\windows\z8280not-a-vi5us9c7.bin c:\windows\z8ded9wnlo5der1877.dll c:\windows\z9b0vir18305.ocx c:\windows\zb5bthreat20059.bin c:\windows\ze83thief9057.cpl c:\windows\zeb2ste59892.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Legacy_SFXDRV ——-\Service_MyWebSearchService ((((((((((((((((((((((((( Files Created from 2009-11-09 to 2009-12-09 ))))))))))))))))))))))))))))))) . 2009-12-09 03:02 . 2009-12-09 03:06 ——– d—–w- c:\users\grandkids\AppData\Local\temp 2009-12-09 03:02 . 2009-12-09 03:02 ——– d—–w- c:\users\Default\AppData\Local\temp 2009-12-06 16:26 . 2009-12-06 16:26 2560 —-a-w- c:\windows\_MSRSTRT.EXE 2009-11-30 22:52 . 2009-10-29 09:17 2048 —-a-w- c:\windows\system32\tzres.dll 2009-11-30 03:23 . 2009-08-11 16:44 1401856 —-a-w- c:\windows\system32\msxml6.dll 2009-11-30 03:23 . 2009-08-11 16:44 1248768 —-a-w- c:\windows\system32\msxml3.dll 2009-11-25 03:38 . 2009-11-25 03:38 ——– d—–w- c:\users\4grandkids\AppData\Roaming\WildTangent 2009-11-24 21:52 . 2009-11-24 22:00 ——– d—–w- c:\users\4grandkids\AppData\Local\Microsoft Games 2009-11-23 00:13 . 2009-11-23 00:13 ——– d—–w- c:\users\grandkids\AppData\Local\Blizzard Entertainment 2009-11-22 23:48 . 2009-11-22 23:48 ——– d—–w- c:\programdata\Blizzard 2009-11-22 23:45 . 2009-12-06 16:33 ——– d—–w- c:\users\Public\Games 2009-11-22 20:21 . 2009-11-22 20:21 ——– d—–w- c:\program files\ToggleEN 2009-11-20 22:53 . 2009-11-20 22:54 ——– d—–w- c:\users\4grandkids\AppData\Local\Adobe 2009-11-17 10:18 . 2009-11-17 10:18 ——– d—–w- c:\program files\Windows Portable Devices 2009-11-17 10:11 . 2009-09-10 02:00 92672 —-a-w- c:\windows\system32\UIAnimation.dll 2009-11-17 10:11 . 2009-09-10 02:00 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll 2009-11-17 10:11 . 2009-09-10 02:01 3023360 —-a-w- c:\windows\system32\UIRibbon.dll 2009-11-17 10:09 . 2009-10-01 01:02 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe 2009-11-17 10:07 . 2009-10-08 21:08 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll 2009-11-17 10:07 . 2009-10-08 21:08 234496 —-a-w- c:\windows\system32\oleacc.dll 2009-11-17 10:07 . 2009-10-08 21:07 4096 —-a-w- c:\windows\system32\oleaccrc.dll 2009-11-13 03:17 . 2009-08-14 13:27 2036736 —-a-w- c:\windows\system32\win32k.sys 2009-11-13 03:16 . 2009-08-10 12:35 355328 —-a-w- c:\windows\system32\WSDApi.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-06 16:32 . 2009-08-08 06:52 ——– d—–w- c:\program files\LimeWire 2009-12-04 05:57 . 2009-11-06 03:38 ——– d—–w- c:\users\grandkids\AppData\Roaming\Skype 2009-12-04 05:57 . 2009-08-08 06:34 ——– d—–w- c:\users\grandkids\AppData\Roaming\Apple Computer 2009-12-04 05:53 . 2009-11-02 21:53 ——– d—–w- c:\users\4grandkids\AppData\Roaming\LimeWire 2009-12-04 05:18 . 2009-11-02 21:58 ——– d—–w- c:\users\4grandkids\AppData\Roaming\Apple Computer 2009-12-04 05:17 . 2009-12-04 05:17 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf 2009-12-04 05:17 . 2009-08-08 04:55 ——– d—–w- c:\programdata\Apple 2009-11-25 03:39 . 2007-11-12 18:48 ——– d—–w- c:\programdata\WildTangent 2009-11-23 05:33 . 2009-08-08 06:53 ——– d—–w- c:\users\grandkids\AppData\Roaming\LimeWire 2009-11-22 21:10 . 2009-05-07 03:07 38 —-a-w- c:\users\grandkids\jagex_runescape_preferences.dat 2009-11-22 20:55 . 2009-09-03 23:03 63 —-a-w- c:\users\grandkids\jagex_runescape_preferences2.dat 2009-11-19 16:04 . 2009-11-06 03:43 ——– d—–w- c:\users\grandkids\AppData\Roaming\skypePM 2009-11-17 10:17 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat 2009-11-17 10:17 . 2009-11-17 10:17 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf 2009-11-13 15:04 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail 2009-11-13 11:09 . 2008-11-10 23:29 ——– d—–w- c:\programdata\Microsoft Help 2009-11-06 03:50 . 2009-11-06 03:50 ——– d—–w- c:\users\grandkids\AppData\Roaming\Gogii 2009-11-06 03:43 . 2009-11-06 03:43 56 —ha-w- c:\programdata\ezsidmv.dat 2009-11-06 03:37 . 2009-11-06 03:36 ——– d—–r- c:\program files\Skype 2009-11-06 03:36 . 2009-11-06 03:36 ——– d—–w- c:\program files\Common Files\Skype 2009-11-06 03:36 . 2009-11-06 03:36 ——– d—–w- c:\programdata\Skype 2009-11-06 02:44 . 2009-02-28 21:53 ——– d—–w- c:\program files\bfgclient 2009-11-03 04:42 . 2009-10-02 20:34 195456 ——w- c:\windows\system32\MpSigStub.exe 2009-11-02 23:36 . 2009-11-02 21:57 63 —-a-w- c:\users\4grandkids\jagex_runescape_preferences2.dat 2009-11-02 23:01 . 2009-11-02 21:56 38 —-a-w- c:\users\4grandkids\jagex_runescape_preferences.dat 2009-10-28 15:31 . 2009-06-29 12:36 129848 —-a-w- c:\users\4grandkids\AppData\Local\GDIPFONTCACHEV1.DAT 2009-10-28 12:01 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Sidebar 2009-10-28 12:01 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Calendar 2009-10-28 12:01 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Collaboration 2009-10-28 12:01 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Photo Gallery 2009-10-28 12:01 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Defender 2009-10-27 15:02 . 2007-11-12 19:25 ——– d—–w- c:\program files\Java 2009-10-11 17:41 . 2009-10-11 17:40 ——– d—–w- c:\program files\P2P_Max 2009-10-11 17:41 . 2009-10-11 17:41 ——– d—–w- c:\program files\Conduit 2009-10-01 01:02 . 2009-11-17 10:09 2537472 —-a-w- c:\windows\system32\wpdshext.dll 2009-10-01 01:02 . 2009-11-17 10:09 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll 2009-10-01 01:02 . 2009-11-17 10:09 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll 2009-10-01 01:02 . 2009-11-17 10:09 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll 2009-10-01 01:01 . 2009-11-17 10:09 546816 —-a-w- c:\windows\system32\wpd_ci.dll 2009-10-01 01:01 . 2009-11-17 10:09 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll 2009-10-01 01:01 . 2009-11-17 10:09 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll 2009-10-01 01:01 . 2009-11-17 10:09 350208 —-a-w- c:\windows\system32\WPDSp.dll 2009-10-01 01:01 . 2009-11-17 10:09 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll 2009-10-01 01:01 . 2009-11-17 10:09 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll 2009-10-01 01:01 . 2009-11-17 10:09 81920 —-a-w- c:\windows\system32\wpdbusenum.dll 2009-10-01 01:01 . 2009-11-17 10:09 40448 —-a-w- c:\windows\system32\drivers\WpdUsb.sys 2009-10-01 01:01 . 2009-11-17 10:09 226816 —-a-w- c:\windows\system32\WpdMtp.dll 2009-10-01 01:01 . 2009-11-17 10:09 61952 —-a-w- c:\windows\system32\WpdMtpUS.dll 2009-10-01 01:01 . 2009-11-17 10:09 33280 —-a-w- c:\windows\system32\WpdConns.dll 2009-09-25 02:10 . 2009-11-17 10:10 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll 2009-09-25 02:07 . 2009-11-17 10:10 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll 2009-09-25 02:04 . 2009-11-17 10:10 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll 2009-09-25 01:49 . 2009-11-17 10:10 1554432 —-a-w- c:\windows\system32\xpsservices.dll 2009-09-25 01:48 . 2009-11-17 10:10 351232 —-a-w- c:\windows\system32\XpsPrint.dll 2009-09-25 01:38 . 2009-11-17 10:10 847360 —-a-w- c:\windows\system32\OpcServices.dll 2009-09-25 01:36 . 2009-11-17 10:10 280064 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2009-09-25 01:35 . 2009-11-17 10:10 135680 —-a-w- c:\windows\system32\XpsRasterService.dll 2009-09-25 01:33 . 2009-11-17 10:10 195584 —-a-w- c:\windows\system32\dxdiagn.dll 2009-09-25 01:33 . 2009-11-17 10:10 829440 —-a-w- c:\windows\system32\d3d10warp.dll 2009-09-25 01:33 . 2009-11-17 10:10 369664 —-a-w- c:\windows\system32\WMPhoto.dll 2009-09-25 01:32 . 2009-11-17 10:10 252928 —-a-w- c:\windows\system32\dxdiag.exe 2009-09-25 01:31 . 2009-11-17 10:10 519680 —-a-w- c:\windows\system32\d3d11.dll 2009-09-25 01:31 . 2009-11-17 10:10 486912 —-a-w- c:\windows\system32\d3d10level9.dll 2009-09-25 01:31 . 2009-11-17 10:10 161280 —-a-w- c:\windows\system32\d3d10_1.dll 2009-09-25 01:31 . 2009-11-17 10:10 218112 —-a-w- c:\windows\system32\d3d10_1core.dll 2009-09-25 01:31 . 2009-11-17 10:10 1030144 —-a-w- c:\windows\system32\d3d10.dll 2009-09-25 01:31 . 2009-11-17 10:10 828928 —-a-w- c:\windows\system32\d2d1.dll 2009-09-25 01:30 . 2009-11-17 10:10 190464 —-a-w- c:\windows\system32\d3d10core.dll 2009-09-25 01:30 . 2009-11-17 10:10 481792 —-a-w- c:\windows\system32\dxgi.dll 2009-09-25 01:27 . 2009-11-17 10:10 634880 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys 2009-09-25 01:27 . 2009-11-17 10:10 37888 —-a-w- c:\windows\system32\cdd.dll 2009-09-25 01:27 . 2009-11-17 10:10 793088 —-a-w- c:\windows\system32\FntCache.dll 2009-09-25 01:27 . 2009-11-17 10:10 1064448 —-a-w- c:\windows\system32\DWrite.dll 2009-09-24 22:54 . 2009-11-17 10:10 258048 —-a-w- c:\windows\system32\winspool.drv 2009-09-24 22:54 . 2009-11-17 10:10 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe 2009-09-24 22:54 . 2009-11-17 10:10 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll 2009-09-14 09:29 . 2009-10-13 20:36 144896 —-a-w- c:\windows\system32\drivers\srv2.sys 2009-09-13 00:40 . 2009-09-13 00:40 14616744 —-a-w- c:\programdata\WildTangent\TOSHIBA Game Console\Downloads\Installers\SetupGamesClient.exe 2009-09-10 16:48 . 2009-10-13 20:37 218624 —-a-w- c:\windows\system32\msv1_0.dll 2009-09-10 14:59 . 2009-10-29 12:15 8147456 —-a-w- c:\windows\system32\wmploc.DLL 2009-09-10 14:58 . 2009-10-29 12:15 310784 —-a-w- c:\windows\system32\unregmp2.exe 2008-11-18 01:00 . 2008-11-18 01:00 122880 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll 2008-11-10 23:14 . 2008-11-10 23:14 4 –sh–r- c:\windows\System32\drivers\taishop.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{72ae8426-3b8d-4ead-b191-8d0ad1c62158}"= "c:\program files\P2P_Max\tbP2P_.dll" [2009-07-15 2224152] "{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTogg.dll" [2009-07-02 2215960] [HKEY_CLASSES_ROOT\clsid\{72ae8426-3b8d-4ead-b191-8d0ad1c62158}] [HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}] 2009-07-02 18:18 2215960 —-a-w- c:\program files\ToggleEN\tbTogg.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{72ae8426-3b8d-4ead-b191-8d0ad1c62158}] 2009-07-15 17:09 2224152 —-a-w- c:\program files\P2P_Max\tbP2P_.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{72ae8426-3b8d-4ead-b191-8d0ad1c62158}"= "c:\program files\P2P_Max\tbP2P_.dll" [2009-07-15 2224152] "{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTogg.dll" [2009-07-02 2215960] [HKEY_CLASSES_ROOT\clsid\{72ae8426-3b8d-4ead-b191-8d0ad1c62158}] [HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{72AE8426-3B8D-4EAD-B191-8D0AD1C62158}"= "c:\program files\P2P_Max\tbP2P_.dll" [2009-07-15 2224152] "{038CB5C7-48EA-4AF9-94E0-A1646542E62B}"= "c:\program files\ToggleEN\tbTogg.dll" [2009-07-02 2215960] [HKEY_CLASSES_ROOT\clsid\{72ae8426-3b8d-4ead-b191-8d0ad1c62158}] [HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480] "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-19 4363504] "RegistryMechanic"="c:\program files\Registry Mechanic\RMTray.exe" [2008-07-03 812952] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-20 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-20 154136] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-20 129560] "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192] "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080] "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-23 538744] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "RtHDVCpl"="RtHDVCpl.exe" [2007-04-25 4444160] "SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-15 102400] "NDSTray.exe"="NDSTray.exe" [BU] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-11-18 29744] "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552] "WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-11-04 615696] "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-09-19 236016] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "Skytel"="Skytel.exe" [2007-04-13 1822720] "ZSSnp211"="c:\windows\ZSSnp211.exe" [2008-12-30 57344] "Domino"="c:\windows\Domino.exe" [2008-12-30 49152] "Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280] c:\users\grandkids\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2008-11-4 1545488] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 "VistaSp2"=hex(B):cc,1c,47,b5,c7,57,ca,01 R2 CWMonitor;Symantec Crimeware Protection Driver;c:\program files\Common Files\Symantec Shared\coShared\CW\1.5\CO_Mon.sys [x] R3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe [2008-01-19 21504] R3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-11-18 29744] R3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [2008-12-30 480128] R3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\Drivers\ZS211.sys [2008-12-30 1537280] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . ——- Supplementary Scan ——- . uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid;=CT2319576 uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: &Search; LSP: c:\windows\system32\wpclsp.dll FF - ProfilePath - c:\users\grandkids\AppData\Roaming\Mozilla\Firefox\Profiles\wyuqji36.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1814311&SearchSource;=3&q;={searchTerms} FF - prefs.js: browser.search.selectedEngine - P2P Max Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1814311&SearchSource;=13 FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1814311&SearchSource;=2&q;= FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll FF - component: c:\users\grandkids\AppData\Roaming\Mozilla\Firefox\Profiles\wyuqji36.default\extensions\{72ae8426-3b8d-4ead-b191-8d0ad1c62158}\components\FFExternalAlert.dll FF - plugin: c:\users\grandkids\AppData\Local\Yahoo!\BrowserPlus\2.4.17\Plugins\npybrowserplus_2.4.17.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . - - - - ORPHANS REMOVED - - - - WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file) ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ———————— Other Running Processes ———————— . c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe c:\windows\system32\agrsmsvc.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe c:\toshiba\IVP\ISM\pinger.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\toshiba\IVP\swupdate\swupdtmr.exe c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe c:\windows\system32\TODDSrv.exe c:\program files\Toshiba\Power Saver\TosCoSrv.exe c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe c:\windows\System32\wsqmcons.exe c:\windows\system32\schtasks.exe . ************************************************************************** . Completion time: 2009-12-08 19:14:13 - machine was rebooted ComboFix-quarantined-files.txt 2009-12-09 03:13 Pre-Run: 33,386,962,944 bytes free Post-Run: 44,956,860,416 bytes free - - End Of File - - A0C82C6A6372B4E3EC974F59DFB8020D
Hi, Catbyte! I'm not sure if I sent you the correct gmer file but it was on my desktop and it looked like the zipped file you were referring to. Otherwise, if this is not the right file. I still have the log on my desktop. How do I change it to a zipped file? Wash09

Attachments:

Hi,

Please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    C:\Windows\System32\drivers\taishop.sys

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
Here is the VirScan.

VirSCAN.org Scanned Report :
Scanned time : 2009/12/08 21:51:37 (PST)
Scanner results: Scanners did not find malware!
File Name : taishop.sys
File Size : 4 byte
File Type : ASCII text, with no line terminators
MD5 : efb3485a5b234353bfa64b591918f451
SHA1 : 283048a147a49a75824178123138bed2b0950135
Online report : http://virscan.org/report/692bfc31c8f9a14d…8f6e0ae4f8.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091209053146 2009-12-09 12.38 -
AhnLab V3 2009.12.09.01 2009.12.09 2009-12-09 1.23 -
AntiVir 8.2.1.102 7.10.1.201 2009-12-08 0.54 -
Antiy 2.0.18 20091204.3347676 2009-12-04 0.12 -
Arcavir 2009 200912081456 2009-12-08 0.02 -
Authentium 5.1.1 200912082317 2009-12-08 1.22 -
AVAST! 4.7.4 091208-1 2009-12-08 0.00 -
AVG 8.5.288 270.14.99/2553 2009-12-09 0.31 -
BitDefender 7.81008.4705189 7.29363 2009-12-09 4.01 -
CA (VET) 35.1.0 7164 2009-12-07 12.86 -
ClamAV 0.95.2 10135 2009-12-09 0.00 -
Comodo 3.13 3187 2009-12-09 1.05 -
CP Secure 1.3.0.5 2009.12.04 2009-12-04 0.00 -
Dr.Web 4.44.0.9170 2009.12.09 2009-12-09 7.48 -
F-Prot 4.4.4.56 20091208 2009-12-08 1.21 -
F-Secure 7.02.73807 2009.12.09.03 2009-12-09 0.05 -
Fortinet 11.140- 11.140 2009-12-08 0.14 -
GData 19.9220/19.612 20091209 2009-12-09 6.18 -
ViRobot 20091208 2009.12.08 2009-12-08 0.78 -
Ikarus T3.1.01.74 2009.12.09.74703 2009-12-09 4.20 -
JiangMin 13.0.900 2009.12.02 2009-12-02 4.87 -
Kaspersky 5.5.10 2009.12.09 2009-12-09 0.02 -
KingSoft 2009.2.5.15 2009.12.9.7 2009-12-09 0.53 -
McAfee 5.3.00 5826 2009-12-08 3.31 -
Microsoft 1.5302 2009.12.09 2009-12-09 6.90 -
Norman 6.01.09 6.01.00 2009-12-08 4.00 -
Panda 9.05.01 2009.12.07 2009-12-07 2.32 -
Trend Micro 9.000-1003 6.682.01 2009-12-09 0.02 -
Quick Heal 10.00 2009.12.09 2009-12-09 1.37 -
Rising 20.0 22.25.02.03 2009-12-09 0.26 -
Sophos 3.02.0 4.48 2009-12-09 2.72 -
Sunbelt 3.9.2381.2 5550 2009-12-08 1.86 -
Symantec 1.3.0.24 20091208.002 2009-12-08 0.21 -
nProtect 20091209.01 6537548 2009-12-09 3.97 -
The Hacker 6.5.0.2 v00088 2009-12-07 1.02 -
VBA32 3.12.12.0 20091208.1706 2009-12-08 2.19 -
VirusBuster 4.5.11.10 10.115.4/2011277 2009-12-08 2.37 -
good,

Please post the MBAM log then do the following on line scan:

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:

1. Click Accept, when prompted to download and install the program files and database of malware definitions.


2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan

3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply

Also, please advise how your computer is running now and if there are any outstanding issues.
Ok, here is the MBAM report. Once the report was done, it said it was completed. Then it told me to click on the Main Menu which directed me back to where I could restart the scan. I ran it again, and just clicked ok then the report generated. I copied/pasted it here. I never saw where I would have an option to select "Remove Selected" therefore I just clicked "OK" when the report was done. Malwarebytes' Anti-Malware 1.39 Database version: 2526 Windows 6.0.6002 Service Pack 2 12/9/2009 2:39:04 PM mbam-log-2009-12-09 (14-39-04).txt Scan type: Quick Scan Objects scanned: 98162 Time elapsed: 7 minute(s), 3 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI