This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Need this for University Assignments(Redirecting & Freezi

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

You would not have had that option as the log is showing no infections detected.

I understand Kaspersky online scan is down for a bit, so please run this alternative scan:

Go here to run an online scanner from ESET

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
This is what was on the eset log file when I went and opened it. ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK esets_scanner_update returned -1 esets_gle=53251
Hi, that doesn't appear to have run or saved properly, would you mind trying it again, I want to make certain your system is clean. Also, please post a fresh DDS and attach.txt and advise how your computer is running now and if there are any outstanding issues.
I've just ran the new DDS and Attach files. DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 15:01:44.45 on Thu 12/10/2009 Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_15 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1014.143 [GMT -8:00] SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\agrsmsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\TOSHIBA\IVP\ISM\pinger.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Windows\system32\svchost.exe -k imgsvc c:\TOSHIBA\IVP\swupdate\swupdtmr.exe C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Windows\system32\Dwm.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Toshiba\Power Saver\TPwrMain.exe C:\Program Files\Toshiba\SmoothView\SmoothView.exe C:\Program Files\Toshiba\FlashCards\TCrdMain.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPStart.exe C:\Program Files\Toshiba\ConfigFree\NDSTray.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Windows\WindowsMobile\wmdSync.exe C:\Windows\System32\wpcumi.exe C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Windows\ZSSnp211.exe C:\Windows\Domino.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Program Files\Registry Mechanic\RMTray.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Synaptics\SynTP\SynToshiba.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Internet Explorer\ieuser.exe c:\program files\aol email toolbar\AolMailTbServer.exe C:\Program Files\MSN\Toolbar\3.0.1125.0\msntask.exe C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe C:\Program Files\Java\jre6\bin\jucheck.exe C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe C:\Users\grandkids\Desktop\dds.pif C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2319576 uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s uURLSearchHooks: P2P Max Toolbar: {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - c:\program files\p2p_max\tbP2P_.dll uURLSearchHooks: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll mURLSearchHooks: AOLMAILTBSearch Class: {98572e47-b5fe-43de-9aea-492a1d3064cd} - c:\program files\aol email toolbar\aolmailtb.dll mURLSearchHooks: P2P Max Toolbar: {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - c:\program files\p2p_max\tbP2P_.dll mURLSearchHooks: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: P2P Max Toolbar: {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - c:\program files\p2p_max\tbP2P_.dll BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: AOL Email Toolbar Loader: {fbea8524-8c72-4208-9d12-7fb73e9926eb} - c:\program files\aol email toolbar\aolmailtb.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll TB: AOL Email Toolbar: {a3704fa3-dbf6-46b5-b95e-0677dfd39577} - c:\program files\aol email toolbar\aolmailtb.dll TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll TB: P2P Max Toolbar: {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - c:\program files\p2p_max\tbP2P_.dll TB: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [RegistryMechanic] c:\program files\registry mechanic\RMTray.exe /S uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [TPwrMain] "c:\program files\toshiba\power saver\TPwrMain.EXE" mRun: [SmoothView] "c:\program files\toshiba\smoothview\SmoothView.exe" mRun: [00TCrdMain] "c:\program files\toshiba\flashcards\TCrdMain.exe" mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe mRun: [NDSTray.exe] NDSTray.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [BlackBerryAutoUpdate] "c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe" /background mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Skytel] Skytel.exe mRun: [ZSSnp211] c:\windows\ZSSnp211.exe mRun: [Domino] c:\windows\Domino.exe mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\users\grandk~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\deskto~1.lnk - c:\program files\research in motion\blackberry\DesktopMgr.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: &Search IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL LSP: c:\windows\system32\wpclsp.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~1\GoogleDesktopNetwork3.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\grandk~1\appdata\roaming\mozilla\firefox\profiles\wyuqji36.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1814311&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - P2P Max Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1814311&SearchSource=13 FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1814311&SearchSource=2&q= FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll FF - component: c:\users\grandkids\appdata\roaming\mozilla\firefox\profiles\wyuqji36.default\extensions\{72ae8426-3b8d-4ead-b191-8d0ad1c62158}\components\FFExternalAlert.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\users\grandkids\appdata\local\yahoo!\browserplus\2.4.17\plugins\npybrowserplus_2.4.17.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2007-11-12 7168] S3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [2009-7-19 480128] S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\drivers\ZS211.sys [2009-7-19 1537280] =============== Created Last 30 ================ 2009-12-20 14:49:02 13116 —-a-w- c:\windows\system32\z69troj5be.cpl 2009-12-10 05:52:45 0 d—–w- c:\program files\ESET 2009-12-09 16:19:54 377344 —-a-w- c:\windows\system32\winhttp.dll 2009-12-09 16:19:43 834048 —-a-w- c:\windows\system32\wininet.dll 2009-12-09 16:19:35 78336 —-a-w- c:\windows\system32\ieencode.dll 2009-12-09 16:19:10 411648 —-a-w- c:\windows\system32\drivers\http.sys 2009-12-09 16:19:10 30720 —-a-w- c:\windows\system32\httpapi.dll 2009-12-09 16:19:09 24064 —-a-w- c:\windows\system32\nshhttp.dll 2009-12-09 16:18:18 243712 —-a-w- c:\windows\system32\rastls.dll 2009-12-09 03:06:17 0 d-sh–w- C:\$RECYCLE.BIN 2009-12-07 09:40:39 141577983 —-a-w- c:\windows\MEMORY.DMP 2009-12-07 09:35:23 98816 —-a-w- c:\windows\sed.exe 2009-12-07 09:35:23 77312 —-a-w- c:\windows\MBR.exe 2009-12-07 09:35:23 260096 —-a-w- c:\windows\PEV.exe 2009-12-07 09:35:23 161792 —-a-w- c:\windows\SWREG.exe 2009-12-06 16:26:25 2560 —-a-w- c:\windows\_MSRSTRT.EXE 2009-12-04 05:17:45 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf 2009-11-30 22:52:01 2048 —-a-w- c:\windows\system32\tzres.dll 2009-11-30 03:23:50 1401856 —-a-w- c:\windows\system32\msxml6.dll 2009-11-30 03:23:45 1248768 —-a-w- c:\windows\system32\msxml3.dll 2009-11-30 03:20:25 714240 —-a-w- c:\windows\system32\timedate.cpl 2009-11-22 23:48:34 0 d—–w- c:\programdata\Blizzard 2009-11-22 20:21:20 0 d—–w- c:\program files\ToggleEN 2009-11-17 10:18:06 0 d—–w- c:\program files\Windows Portable Devices 2009-11-17 10:17:41 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf 2009-11-17 10:11:21 92672 —-a-w- c:\windows\system32\UIAnimation.dll 2009-11-17 10:11:20 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll 2009-11-17 10:11:19 3023360 —-a-w- c:\windows\system32\UIRibbon.dll 2009-11-17 10:09:36 81920 —-a-w- c:\windows\system32\wpdbusenum.dll 2009-11-17 10:07:44 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll 2009-11-17 10:07:44 4096 —-a-w- c:\windows\system32\oleaccrc.dll 2009-11-17 10:07:44 234496 —-a-w- c:\windows\system32\oleacc.dll 2009-11-13 03:17:22 2036736 —-a-w- c:\windows\system32\win32k.sys 2009-11-13 03:16:43 355328 —-a-w- c:\windows\system32\WSDApi.dll ==================== Find3M ==================== 2009-11-22 21:10:47 38 —-a-w- c:\users\grandkids\jagex_runescape_preferences.dat 2009-11-22 20:55:23 63 —-a-w- c:\users\grandkids\jagex_runescape_preferences2.dat 2009-11-17 10:17:55 665600 —-a-w- c:\windows\inf\drvindex.dat 2009-11-17 10:17:55 51200 —-a-w- c:\windows\inf\infpub.dat 2009-11-17 10:17:54 86016 —-a-w- c:\windows\inf\infstor.dat 2009-11-17 10:17:54 143360 —-a-w- c:\windows\inf\infstrng.dat 2009-11-06 03:43:56 56 —ha-w- c:\programdata\ezsidmv.dat 2009-11-03 04:42:06 195456 ——w- c:\windows\system32\MpSigStub.exe 2009-10-27 16:47:29 37665 —-a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont 2009-10-01 01:02:17 2537472 —-a-w- c:\windows\system32\wpdshext.dll 2009-10-01 01:02:05 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe 2009-10-01 01:02:04 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll 2009-10-01 01:02:02 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll 2009-10-01 01:02:00 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll 2009-10-01 01:01:59 546816 —-a-w- c:\windows\system32\wpd_ci.dll 2009-10-01 01:01:59 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll 2009-10-01 01:01:56 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll 2009-10-01 01:01:56 350208 —-a-w- c:\windows\system32\WPDSp.dll 2009-10-01 01:01:56 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll 2009-10-01 01:01:56 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll 2009-10-01 01:01:50 226816 —-a-w- c:\windows\system32\WpdMtp.dll 2009-10-01 01:01:49 61952 —-a-w- c:\windows\system32\WpdMtpUS.dll 2009-10-01 01:01:49 33280 —-a-w- c:\windows\system32\WpdConns.dll 2009-09-25 02:10:10 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll 2009-09-25 02:07:08 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll 2009-09-25 02:04:32 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll 2009-09-25 01:49:22 1554432 —-a-w- c:\windows\system32\xpsservices.dll 2009-09-25 01:48:08 351232 —-a-w- c:\windows\system32\XpsPrint.dll 2009-09-25 01:38:29 847360 —-a-w- c:\windows\system32\OpcServices.dll 2009-09-25 01:36:13 280064 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2009-09-25 01:35:31 135680 —-a-w- c:\windows\system32\XpsRasterService.dll 2009-09-25 01:33:25 195584 —-a-w- c:\windows\system32\dxdiagn.dll 2009-09-25 01:33:15 829440 —-a-w- c:\windows\system32\d3d10warp.dll 2009-09-25 01:33:01 369664 —-a-w- c:\windows\system32\WMPhoto.dll 2009-09-25 01:32:59 252928 —-a-w- c:\windows\system32\dxdiag.exe 2009-09-25 01:31:53 519680 —-a-w- c:\windows\system32\d3d11.dll 2009-09-25 01:31:26 486912 —-a-w- c:\windows\system32\d3d10level9.dll 2009-09-25 01:31:21 161280 —-a-w- c:\windows\system32\d3d10_1.dll 2009-09-25 01:31:19 218112 —-a-w- c:\windows\system32\d3d10_1core.dll 2009-09-25 01:31:16 1030144 —-a-w- c:\windows\system32\d3d10.dll 2009-09-25 01:31:15 828928 —-a-w- c:\windows\system32\d2d1.dll 2009-09-25 01:30:23 481792 —-a-w- c:\windows\system32\dxgi.dll 2009-09-25 01:30:23 190464 —-a-w- c:\windows\system32\d3d10core.dll 2009-09-25 01:27:04 793088 —-a-w- c:\windows\system32\FntCache.dll 2009-09-25 01:27:04 37888 —-a-w- c:\windows\system32\cdd.dll 2009-09-25 01:27:04 1064448 —-a-w- c:\windows\system32\DWrite.dll 2009-09-24 22:54:55 258048 —-a-w- c:\windows\system32\winspool.drv 2009-09-24 22:54:53 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe 2009-09-24 22:54:52 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll 2009-04-14 03:50:51 174 –sha-w- c:\program files\desktop.ini 2006-11-02 12:39:34 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:39:34 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 12:39:34 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:39:34 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-02-07 07:00:15 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat 2009-02-07 07:00:15 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat 2009-02-07 07:00:15 32768 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat 2008-11-10 23:14:38 4 –sh–r- c:\windows\system32\drivers\taishop.sys ============= FINISH: 15:05:29.29 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-12-01.01) Microsoft® Windows Vista™ Home Basic Boot Device: \Device\HarddiskVolume2 Install Date: 11/10/2008 3:21:21 PM System Uptime: 12/10/2009 4:06:35 AM (11 hours ago) Motherboard: Intel Corporation | | SANTA ROSA CRB Processor: Intel® Celeron® CPU 540 @ 1.86GHz | U2E1 | 1862/mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 73 GiB total, 40.867 GiB free. D: is CDROM (CDFS) ==== Disabled Device Manager Items ============= ==== Installed Programs ====================== Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.1.4 Adobe Shockwave Player 11.5 AOL Email Toolbar Apple Mobile Device Support Apple Software Update Atheros Driver Installation Program Big Fish Games Client BlackBerry Desktop Software 4.7 Bluetooth Stack for Windows by Toshiba Bonjour CD/DVD Drive Acoustic Silencer Compatibility Pack for the 2007 Office system Download Updater (AOL LLC) DVD MovieFactory for TOSHIBA ESET Online Scanner v3 Google Desktop Google Toolbar for Internet Explorer HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) InstallMgr Intel® Graphics Media Accelerator Driver iPod Copy Expert 3.1.2 iTunes Java™ 6 Update 15 Java™ 6 Update 2 Java™ 6 Update 7 Malwarebytes' Anti-Malware Marvell Miniport Driver Microsoft .NET Framework 3.5 SP1 Microsoft Default Manager Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Search Enhancement Pack Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Works Microsoft XML Parser Mozilla Firefox (3.0.15) MSN Toolbar MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Napster Napster Burn Engine Octoshape add-in for Adobe Flash Player OpenOffice.org Installer 1.0 P2P_Max Toolbar Picasa 2 QuickBooks Financial Center QuickTime Realtek High Definition Audio Driver Registry Mechanic 8.0 Roxio Media Manager Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB973704) Security Update for CAPICOM (KB931906) Security Update for Microsoft Office Excel 2007 (KB973593) Security Update for Microsoft Office Outlook 2007 (KB972363) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office Publisher 2007 (KB969693) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Windows Media Encoder (KB954156) Skype web features Skype™ 4.1 Spelling Dictionaries Support For Adobe Reader 8 Synaptics Pointing Device Driver Texas Instruments PCIxx21/x515/xx12 drivers. TIPCI ToggleEN Toolbar TOSHIBA Assist TOSHIBA ConfigFree TOSHIBA Disc Creator TOSHIBA DVD PLAYER TOSHIBA Extended Tiles for Windows Mobility Center TOSHIBA Games TOSHIBA Hardware Setup Toshiba Registration TOSHIBA SD Memory Utilities TOSHIBA Software Modem TOSHIBA Software Upgrades TOSHIBA Speech System Applications TOSHIBA Speech System SR Engine(U.S.) Version1.0 TOSHIBA Speech System TTS Engine(U.S.) Version1.0 TOSHIBA Value Added Package Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office InfoPath 2007 (KB976416) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 (KB974561) Update for Microsoft Office Word 2007 Help (KB963665) Update for Outlook 2007 Junk Email Filter (kb976884) Windows Media Encoder 9 Series Yahoo! BrowserPlus Yahoo! Messenger Yahoo! Toolbar ZSMC USB PC Camera (ZS0211) ==== End Of File =========================== I am about to re-do the Eset Scan. When I sign on to certain sites the laptop is still loading slowly. The laptop is still getting a message that says the computer is infected and asking me to download an antivirus program. It redirects to this message after I'm already on a site that I've been looking at for a short time.
Hi,

Before you do the online scan, please run these scans:

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

NEXT


Please download exeHelper to your desktop.
  • Double-click on exeHelper.com to run the fix.
  • A black window should pop up, press any key to close once the fix is completed.
  • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
I had ran the report before you sent me this notice. I ran it immediately after I left you the DDS/Attach logs. I still got the same info when I went to the link you requested I go to in order to get the log to post for you to read. ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK esets_scanner_update returned -1 esets_gle=53251 This was the only threat that it found upon running. Target Threat C:\Program Files\My Faster PC\MyFasterPC.exe probably a variant of Win32/Genetik trojan I will go run the other things you are requesting me to run now.
Here is the Gooredfix log. GooredFix by jpshortstuff (06.12.09.1) Log created at 17:11 on 10/12/2009 (grandkids) Firefox version 3.0.15 (en-US) ========== GooredScan ========== ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [17:22 11/11/2008] {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [19:26 11/11/2008] {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [13:28 30/07/2009] {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [15:02 27/10/2009] C:\Users\grandkids\Application Data\Mozilla\Firefox\Profiles\wyuqji36.default\extensions\ {20a82645-c095-46ed-80e3-08825760534b} [06:04 10/09/2009] {635abd67-4fe9-1b23-4f01-e679fa7484c1} [03:39 14/12/2008] {72ae8426-3b8d-4ead-b191-8d0ad1c62158} [17:40 11/10/2009] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [15:29 15/07/2009] -=E.O.F=-
Here is the exeHelper log. exeHelper by Raktor Build 20091204 Run at 17:15:09 on 12/10/09 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished–
Can you go to the 'tools' menu in FireFox > Add-Ons and tell me what add-ons you have installed. Can you advise if you are still getting the fake antivirus alerts? what site are you visiting when this happens, or is it random sites (please mung the link)
Hi, I just signed onto Firefox! I didn't download this but I'm guessing my nephew did. I see these (3) three things: 1. Microsoft .NET Framework Assistant 1.1 2. P2P Max Toolbar [removed] 3. Yahoo! Toolbar 1.6.2.20080910 Yes, I'm still being redirected to a supposed site that is telling me that my computer has infected. I don't think it's so much as a specific site. I think it's when I have too many open at one time. But mostly I notice it redirecting me on www.tagged.com.
Hi,

Let me see another GMER scan.

I will send you the instructions again.

Please check the boxes exactly as shown in the image:


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi, Catbyte! I'm sorry about this taken forever. I've just got the laptop to run the gmer test. I've posted it here. I'm about to re-run the DDS and the Attach log. I this laptop is still freezing up pretty bad. I sometime have to open two or three windows up for my school's website. Today it wouldn't let me. I was able to open one of them. I also had another site open in reference to Arizona Legal. I tried to open the school site in two more windows but it kept telling me that internet explorer can't be displayed. When I started to run the gmer test, I tried to go uncheck the things you told me to however, the scan was taking place as soon as it came up. I was able to uncheck the first three but "Show All" was already unchecked. I then hit scan even though the scan seem to be already taking place without me hitting the scan button.

Attachments:

Hi,

Please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    c:\windows\system32\z69troj5be.cpl

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


NEXT

Visit ADOBEand download the latest version of Acrobat Reader (version 9.2)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT

Go to start > Control Panel > Add/Remove programs
a list of installed programs will populate
Locate the below noted entries and select REMOVE:

Java™ 6 Update 2
Java™ 6 Update 7



NEXT

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI