Hi,
You would not have had that option as the log is showing no infections detected.
I understand Kaspersky online scan is down for a bit, so please run this alternative scan:
Go
here to run an online scanner from
ESET
Note: You will need to use Internet explorer for this scan Turn off the real time scanner of any existing antivirus program while performing the online scan Tick the box next to YES, I accept the Terms of Use. Click Start When asked, allow the activeX control to install Click Start Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked. Click on Advanced Settings, ensure the options Scan for potentially unwanted applications , Scan for potentially unsafe applications , and Enable Anti-Stealth Technology are ticked. Click Scan Wait for the scan to finish Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt Copy and paste that log as a reply to this topic and also let me know how things are now.
This is what was on the eset log file when I went and opened it.
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
esets_scanner_update returned -1 esets_gle=53251
Hi, that doesn't appear to have run or saved properly, would you mind trying it again, I want to make certain your system is clean.
Also, please post a fresh DDS and attach.txt and advise how your computer is running now and if there are any outstanding issues.
Ok,
I will re-run the above reports. No problem.
I've just ran the new DDS and Attach files.
DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 15:01:44.45 on Thu 12/10/2009
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_15
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1014.143 [GMT -8:00]
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\ZSSnp211.exe
C:\Windows\Domino.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Registry Mechanic\RMTray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Internet Explorer\ieuser.exe
c:\program files\aol email toolbar\AolMailTbServer.exe
C:\Program Files\MSN\Toolbar\3.0.1125.0\msntask.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Users\grandkids\Desktop\dds.pif
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2319576
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
uURLSearchHooks: P2P Max Toolbar: {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - c:\program files\p2p_max\tbP2P_.dll
uURLSearchHooks: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll
mURLSearchHooks: AOLMAILTBSearch Class: {98572e47-b5fe-43de-9aea-492a1d3064cd} - c:\program files\aol email toolbar\aolmailtb.dll
mURLSearchHooks: P2P Max Toolbar: {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - c:\program files\p2p_max\tbP2P_.dll
mURLSearchHooks: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: P2P Max Toolbar: {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - c:\program files\p2p_max\tbP2P_.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: AOL Email Toolbar Loader: {fbea8524-8c72-4208-9d12-7fb73e9926eb} - c:\program files\aol email toolbar\aolmailtb.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: AOL Email Toolbar: {a3704fa3-dbf6-46b5-b95e-0677dfd39577} - c:\program files\aol email toolbar\aolmailtb.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
TB: P2P Max Toolbar: {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - c:\program files\p2p_max\tbP2P_.dll
TB: ToggleEN Toolbar: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - c:\program files\toggleen\tbTogg.dll
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [RegistryMechanic] c:\program files\registry mechanic\RMTray.exe /S
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [TPwrMain] "c:\program files\toshiba\power saver\TPwrMain.EXE"
mRun: [SmoothView] "c:\program files\toshiba\smoothview\SmoothView.exe"
mRun: [00TCrdMain] "c:\program files\toshiba\flashcards\TCrdMain.exe"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [NDSTray.exe] NDSTray.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [BlackBerryAutoUpdate] "c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe" /background
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Skytel] Skytel.exe
mRun: [ZSSnp211] c:\windows\ZSSnp211.exe
mRun: [Domino] c:\windows\Domino.exe
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\users\grandk~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\deskto~1.lnk - c:\program files\research in motion\blackberry\DesktopMgr.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Search
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
LSP: c:\windows\system32\wpclsp.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~1\GoogleDesktopNetwork3.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\grandk~1\appdata\roaming\mozilla\firefox\profiles\wyuqji36.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1814311&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - P2P Max Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1814311&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1814311&SearchSource=2&q=
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\users\grandkids\appdata\roaming\mozilla\firefox\profiles\wyuqji36.default\extensions\{72ae8426-3b8d-4ead-b191-8d0ad1c62158}\components\FFExternalAlert.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\users\grandkids\appdata\local\yahoo!\browserplus\2.4.17\plugins\npybrowserplus_2.4.17.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2007-11-12 7168]
S3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [2009-7-19 480128]
S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\drivers\ZS211.sys [2009-7-19 1537280]
=============== Created Last 30 ================
2009-12-20 14:49:02 13116 —-a-w- c:\windows\system32\z69troj5be.cpl
2009-12-10 05:52:45 0 d—–w- c:\program files\ESET
2009-12-09 16:19:54 377344 —-a-w- c:\windows\system32\winhttp.dll
2009-12-09 16:19:43 834048 —-a-w- c:\windows\system32\wininet.dll
2009-12-09 16:19:35 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-12-09 16:19:10 411648 —-a-w- c:\windows\system32\drivers\http.sys
2009-12-09 16:19:10 30720 —-a-w- c:\windows\system32\httpapi.dll
2009-12-09 16:19:09 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-12-09 16:18:18 243712 —-a-w- c:\windows\system32\rastls.dll
2009-12-09 03:06:17 0 d-sh–w- C:\$RECYCLE.BIN
2009-12-07 09:40:39 141577983 —-a-w- c:\windows\MEMORY.DMP
2009-12-07 09:35:23 98816 —-a-w- c:\windows\sed.exe
2009-12-07 09:35:23 77312 —-a-w- c:\windows\MBR.exe
2009-12-07 09:35:23 260096 —-a-w- c:\windows\PEV.exe
2009-12-07 09:35:23 161792 —-a-w- c:\windows\SWREG.exe
2009-12-06 16:26:25 2560 —-a-w- c:\windows\_MSRSTRT.EXE
2009-12-04 05:17:45 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-30 22:52:01 2048 —-a-w- c:\windows\system32\tzres.dll
2009-11-30 03:23:50 1401856 —-a-w- c:\windows\system32\msxml6.dll
2009-11-30 03:23:45 1248768 —-a-w- c:\windows\system32\msxml3.dll
2009-11-30 03:20:25 714240 —-a-w- c:\windows\system32\timedate.cpl
2009-11-22 23:48:34 0 d—–w- c:\programdata\Blizzard
2009-11-22 20:21:20 0 d—–w- c:\program files\ToggleEN
2009-11-17 10:18:06 0 d—–w- c:\program files\Windows Portable Devices
2009-11-17 10:17:41 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-17 10:11:21 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2009-11-17 10:11:20 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2009-11-17 10:11:19 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2009-11-17 10:09:36 81920 —-a-w- c:\windows\system32\wpdbusenum.dll
2009-11-17 10:07:44 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-11-17 10:07:44 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-11-17 10:07:44 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-11-13 03:17:22 2036736 —-a-w- c:\windows\system32\win32k.sys
2009-11-13 03:16:43 355328 —-a-w- c:\windows\system32\WSDApi.dll
==================== Find3M ====================
2009-11-22 21:10:47 38 —-a-w- c:\users\grandkids\jagex_runescape_preferences.dat
2009-11-22 20:55:23 63 —-a-w- c:\users\grandkids\jagex_runescape_preferences2.dat
2009-11-17 10:17:55 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-17 10:17:55 51200 —-a-w- c:\windows\inf\infpub.dat
2009-11-17 10:17:54 86016 —-a-w- c:\windows\inf\infstor.dat
2009-11-17 10:17:54 143360 —-a-w- c:\windows\inf\infstrng.dat
2009-11-06 03:43:56 56 —ha-w- c:\programdata\ezsidmv.dat
2009-11-03 04:42:06 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-27 16:47:29 37665 —-a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont
2009-10-01 01:02:17 2537472 —-a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02:05 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02:04 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02:02 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02:00 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01:59 546816 —-a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01:59 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01:56 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01:56 350208 —-a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01:56 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01:56 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01:50 226816 —-a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01:49 61952 —-a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01:49 33280 —-a-w- c:\windows\system32\WpdConns.dll
2009-09-25 02:10:10 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07:08 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04:32 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49:22 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48:08 351232 —-a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38:29 847360 —-a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36:13 280064 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35:31 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33:25 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33:15 829440 —-a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33:01 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32:59 252928 —-a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31:53 519680 —-a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31:26 486912 —-a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31:21 161280 —-a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31:19 218112 —-a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31:16 1030144 —-a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31:15 828928 —-a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30:23 481792 —-a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30:23 190464 —-a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27:04 793088 —-a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27:04 37888 —-a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27:04 1064448 —-a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54:55 258048 —-a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54:53 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54:52 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-04-14 03:50:51 174 –sha-w- c:\program files\desktop.ini
2006-11-02 12:39:34 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:39:34 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:39:34 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:39:34 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-02-07 07:00:15 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat
2009-02-07 07:00:15 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat
2009-02-07 07:00:15 32768 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat
2008-11-10 23:14:38 4 –sh–r- c:\windows\system32\drivers\taishop.sys
============= FINISH: 15:05:29.29 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft® Windows Vista™ Home Basic
Boot Device: \Device\HarddiskVolume2
Install Date: 11/10/2008 3:21:21 PM
System Uptime: 12/10/2009 4:06:35 AM (11 hours ago)
Motherboard: Intel Corporation | | SANTA ROSA CRB
Processor: Intel® Celeron® CPU 540 @ 1.86GHz | U2E1 | 1862/mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 73 GiB total, 40.867 GiB free.
D: is CDROM (CDFS)
==== Disabled Device Manager Items =============
==== Installed Programs ======================
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.4
Adobe Shockwave Player 11.5
AOL Email Toolbar
Apple Mobile Device Support
Apple Software Update
Atheros Driver Installation Program
Big Fish Games Client
BlackBerry Desktop Software 4.7
Bluetooth Stack for Windows by Toshiba
Bonjour
CD/DVD Drive Acoustic Silencer
Compatibility Pack for the 2007 Office system
Download Updater (AOL LLC)
DVD MovieFactory for TOSHIBA
ESET Online Scanner v3
Google Desktop
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
InstallMgr
Intel® Graphics Media Accelerator Driver
iPod Copy Expert 3.1.2
iTunes
Java™ 6 Update 15
Java™ 6 Update 2
Java™ 6 Update 7
Malwarebytes' Anti-Malware
Marvell Miniport Driver
Microsoft .NET Framework 3.5 SP1
Microsoft Default Manager
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Microsoft XML Parser
Mozilla Firefox (3.0.15)
MSN Toolbar
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Napster
Napster Burn Engine
Octoshape add-in for Adobe Flash Player
OpenOffice.org Installer 1.0
P2P_Max Toolbar
Picasa 2
QuickBooks Financial Center
QuickTime
Realtek High Definition Audio Driver
Registry Mechanic 8.0
Roxio Media Manager
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Windows Media Encoder (KB954156)
Skype web features
Skype™ 4.1
Spelling Dictionaries Support For Adobe Reader 8
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515/xx12 drivers.
TIPCI
ToggleEN Toolbar
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Disc Creator
TOSHIBA DVD PLAYER
TOSHIBA Extended Tiles for Windows Mobility Center
TOSHIBA Games
TOSHIBA Hardware Setup
Toshiba Registration
TOSHIBA SD Memory Utilities
TOSHIBA Software Modem
TOSHIBA Software Upgrades
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Value Added Package
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (kb976884)
Windows Media Encoder 9 Series
Yahoo! BrowserPlus
Yahoo! Messenger
Yahoo! Toolbar
ZSMC USB PC Camera (ZS0211)
==== End Of File ===========================
I am about to re-do the Eset Scan. When I sign on to certain sites the laptop is still loading slowly. The laptop is still getting a message that says the computer is infected and asking me to download an antivirus program. It redirects to this message after I'm already on a site that I've been looking at for a short time.
Hi,
Before you do the online scan, please run these scans:
Please download
GooredFix from one of the locations below and
save it to your Desktop
Download Mirror #1
Download Mirror #2
Ensure all Firefox windows are closed. To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista). When prompted to run the scan, click Yes . GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).
NEXT
Please download
exeHelper to your desktop.
Double-click on exeHelper.com to run the fix. A black window should pop up, press any key to close once the fix is completed. Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
I had ran the report before you sent me this notice. I ran it immediately after I left you the DDS/Attach logs. I still got the same info when I went to the link you requested I go to in order to get the log to post for you to read.
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
esets_scanner_update returned -1 esets_gle=53251
This was the only threat that it found upon running.
Target Threat
C:\Program Files\My Faster PC\MyFasterPC.exe probably a variant of Win32/Genetik trojan
I will go run the other things you are requesting me to run now.
Here is the Gooredfix log.
GooredFix by jpshortstuff (06.12.09.1)
Log created at 17:11 on 10/12/2009 (grandkids)
Firefox version 3.0.15 (en-US)
========== GooredScan ==========
========== GooredLog ==========
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [17:22 11/11/2008]
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} [19:26 11/11/2008]
{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [13:28 30/07/2009]
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [15:02 27/10/2009]
C:\Users\grandkids\Application Data\Mozilla\Firefox\Profiles\wyuqji36.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b} [06:04 10/09/2009]
{635abd67-4fe9-1b23-4f01-e679fa7484c1} [03:39 14/12/2008]
{72ae8426-3b8d-4ead-b191-8d0ad1c62158} [17:40 11/10/2009]
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [15:29 15/07/2009]
-=E.O.F=-
Here is the exeHelper log.
exeHelper by Raktor
Build 20091204
Run at 17:15:09 on 12/10/09
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–
Can you go to the 'tools' menu in FireFox > Add-Ons and tell me what add-ons you have installed.
Can you advise if you are still getting the fake antivirus alerts?
what site are you visiting when this happens, or is it random sites (please mung the link)
Hi, I just signed onto Firefox!
I didn't download this but I'm guessing my nephew did. I see these (3) three things:
1. Microsoft .NET Framework Assistant 1.1
2. P2P Max Toolbar [removed]
3. Yahoo! Toolbar 1.6.2.20080910
Yes, I'm still being redirected to a supposed site that is telling me that my computer has infected. I don't think it's so much as a specific site. I think it's when I have too many open at one time. But mostly I notice it redirecting me on www.tagged.com.
Hi,
Let me see another GMER scan.
I will send you the instructions again.
Please check the boxes exactly as shown in the image:
[external image: Posted Image]
Download
GMER Rootkit Scanner from
here or
here .
Extract the contents of the zipped file to desktop. Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent . If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO .
[external image: Posted Image]
Click the image to enlarge it
In the right panel, you will see several boxes that have been checked. Uncheck the following … Sections IAT/EAT Drives/Partition other than Systemdrive (typically C:\) Show All (don't miss this one) Then click the Scan button & wait for it to finish. Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi, Catbyte!
I'm sorry about this taken forever. I've just got the laptop to run the gmer test. I've posted it here. I'm about to re-run the DDS and the Attach log. I this laptop is still freezing up pretty bad. I sometime have to open two or three windows up for my school's website. Today it wouldn't let me. I was able to open one of them. I also had another site open in reference to Arizona Legal. I tried to open the school site in two more windows but it kept telling me that internet explorer can't be displayed. When I started to run the gmer test, I tried to go uncheck the things you told me to however, the scan was taking place as soon as it came up. I was able to uncheck the first three but "Show All" was already unchecked. I then hit scan even though the scan seem to be already taking place without me hitting the scan button.
Here is the new DDS and the Attach log.
Hi,
Please do the following:
NEXT
Visit
ADOBE and download the latest version of Acrobat Reader (version 9.2)
Having the latest updates ensures there are no security vulnerabilities in your system.
NEXT
Go to start > Control Panel > Add/Remove programs
a list of installed programs will populate
Locate the below noted entries and select REMOVE:
Java™ 6 Update 2
Java™ 6 Update 7
NEXT
Download
TFC to your
desktop
Close any open windows. Double click the TFC icon to run the program TFC will close all open programs itself in order to run, Click the Start button to begin the process. Allow TFC to run uninterrupted. The program should not take long to finish it's job Once its finished it should automatically reboot your machine, if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.