PDA

View Full Version : Win32.FraudLoad.edt - cannot remove



susanb0207
2011-01-18, 00:09
Sorry disregard my earlier post. I have now found the right file and attach the zipped one: I have tried running as admin and scanning at restart but still wont go away....many thanks



DDS (Ver_10-12-12.02) - NTFSx86
Run by susan at 22:04:39.99 on 17/01/2011
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_23
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2938.1130 [GMT 0:00]

AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: IObit Security 360 *Enabled/Updated* {FAE2835A-B90A-9E7A-85DA-82DBDA7C1E3A}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\RtkAudioService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Sony\Network Utility\NSUService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe
C:\Program Files\Sony\VAIO Media plus\SOHDms.exe
C:\Program Files\Sony\VAIO Media plus\SOHDs.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Sony\VAIO Power Management\SPMService.exe
C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Game Booster\GameBox.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\IObit\IObit Security 360\is360tray.exe
C:\Program Files\Sony\Network Utility\LANUtil.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
C:\Program Files\IObit\IObit Security 360\is360.exe
C:\Program Files\Advanced SystemCare 3\AWC.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\susan\Downloads\dds (1).scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.co.uk/
uDefault_Page_URL = hxxp://www.club-vaio.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mDefault_Page_URL = hxxp://www.club-vaio.com
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
uURLSearchHooks: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\4.1\iobitToolbarIE.dll
mWinlogon: Userinit=Userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\4.1\iobitToolbarIE.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\progra~1\google~1\BAE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\4.1\iobitToolbarIE.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [NSUFloatingUI] "c:\program files\sony\network utility\LANUtil.exe"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [FileHippo.com] "c:\program files\filehippo.com\UpdateChecker.exe" /background
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ISBMgr.exe] "c:\program files\sony\isb utility\ISBMgr.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [MarketingTools] c:\program files\sony\marketing tools\MarketingTools.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [Skytel] Skytel.exe
mRun: [IObit Security 360] "c:\program files\iobit\iobit security 360\IS360tray.exe" /autostart
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe"
dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
StartupFolder: c:\users\susan\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt1\AUTOBACK.EXE
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
Notify: VESWinlogon - VESWinlogon.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath -

============= SERVICES / DRIVERS ===============

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2010-7-29 115008]
R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2010-11-18 386560]
R2 eamonm;eamonm;c:\windows\system32\drivers\eamonm.sys [2010-9-3 137144]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2010-11-4 810144]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\drivers\epfwwfpr.sys [2010-7-29 96920]
R2 IS360service;IS360service;c:\program files\iobit\iobit security 360\is360srv.exe [2011-1-6 312152]
R2 NSUService;NSUService;c:\program files\sony\network utility\NSUService.exe [2008-8-14 299008]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-18 11032]
R2 RtkAudioService;Realtek Audio Service;c:\windows\RTKAUDIOSERVICE.EXE [2008-7-9 104992]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-1-5 1153368]
R2 SOHCImp;VAIO Media plus Content Importer;c:\program files\sony\vaio media plus\SOHCImp.exe [2008-8-14 103712]
R2 SOHDms;VAIO Media plus Digital Media Server;c:\program files\sony\vaio media plus\SOHDms.exe [2008-8-14 353568]
R2 SOHDs;VAIO Media plus Device Searcher;c:\program files\sony\vaio media plus\SOHDs.exe [2008-8-14 62752]
R2 VAIO Power Management;VAIO Power Management;c:\program files\sony\vaio power management\SPMService.exe [2008-7-9 411488]
R2 VCFw;VAIO Content Folder Watcher;c:\program files\common files\sony shared\vaio content folder watcher\VCFw.exe [2009-3-5 5189992]
R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\sony\vcm intelligent analyzing manager\VcmIAlzMgr.exe [2011-1-12 480624]
R3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2009-5-28 4233728]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [2008-7-9 9344]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate1ca184452985c40;Google Update Service (gupdate1ca184452985c40);c:\program files\google\update\GoogleUpdate.exe [2009-8-8 133104]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-7 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-8-14 30192]
S3 UPnPService;UPnPService;c:\program files\common files\magix shared\upnpservice\UPnPService.exe [2009-8-4 544768]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\common files\sony shared\vcmxml\VcmXmlIfHelper.exe [2011-1-10 83312]
S3 VUAgent;VUAgent;c:\program files\sony\vaio update 5\VUAgent.exe [2011-1-10 722288]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

=============== Created Last 30 ================

2011-01-17 21:33:22 -------- d-----w- c:\program files\ERUNT1
2011-01-17 13:42:38 -------- d-----w- c:\program files\Application Updater
2011-01-17 13:42:37 -------- d-----w- c:\program files\IObit Toolbar
2011-01-17 13:42:37 -------- d-----w- c:\program files\common files\Spigot
2011-01-14 09:49:06 6273872 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{83b27187-1e5e-4373-8b72-1baaf9b91449}\mpengine.dll
2011-01-12 10:36:43 413696 ----a-w- c:\windows\system32\odbc32.dll
2011-01-12 10:36:42 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2011-01-12 10:36:42 57344 ----a-w- c:\program files\common files\system\msadc\msadcs.dll
2011-01-12 10:36:42 253952 ----a-w- c:\program files\common files\system\ado\msadox.dll
2011-01-12 10:36:42 241664 ----a-w- c:\program files\common files\system\ado\msadomd.dll
2011-01-12 10:36:42 180224 ----a-w- c:\program files\common files\system\msadc\msadco.dll
2011-01-12 10:36:38 1169408 ----a-w- c:\windows\system32\sdclt.exe
2011-01-12 02:20:07 -------- d-----w- c:\users\susan\appdata\local\xheader-data
2011-01-12 02:19:59 202135 ----a-w- c:\windows\XHeader Uninstaller.exe
2011-01-12 02:19:54 -------- d-----w- c:\program files\XHeader
2011-01-12 02:19:54 -------- d-----w- c:\program files\common files\Thraex Software
2011-01-10 23:25:04 -------- d-----w- c:\program files\Cisco
2011-01-10 23:25:02 -------- d-----w- c:\program files\common files\Intel
2011-01-10 23:24:22 -------- d-----w- c:\users\susan\appdata\roaming\Intel
2011-01-08 10:40:13 -------- d-----w- c:\windows\system32\Adobe
2011-01-08 10:07:42 11776 ----a-w- c:\program files\mozilla firefox\plugins\nprjplug.dll
2011-01-08 10:07:35 -------- d-----w- c:\program files\common files\xing shared
2011-01-08 10:07:26 151776 ----a-w- c:\program files\mozilla firefox\plugins\nppl3260.dll
2011-01-08 10:07:22 100352 ----a-w- c:\program files\mozilla firefox\plugins\nprpjplug.dll
2011-01-07 10:08:06 -------- d-----w- c:\windows\en
2011-01-07 10:07:30 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2011-01-06 15:58:28 -------- d-----w- c:\progra~2\IObit
2011-01-06 15:51:46 -------- d-----w- c:\program files\FreeApps
2011-01-06 15:51:21 -------- d-----w- c:\program files\IObit
2011-01-06 15:51:07 -------- d-----w- c:\progra~2\FreeApp
2011-01-06 15:50:58 814496 ----a-w- c:\users\susan\appdata\roaming\microsoft\windows\templates\FreeAppsSetup.exe
2011-01-06 15:50:49 1841456 ----a-w- c:\users\susan\appdata\roaming\microsoft\windows\templates\DefragSetup.exe
2011-01-06 15:50:22 6781400 ----a-w- c:\users\susan\appdata\roaming\microsoft\windows\templates\GameBoosterSetup.exe
2011-01-06 15:48:43 -------- d-----w- c:\users\susan\appdata\roaming\IObit
2011-01-06 15:48:42 -------- d-----w- c:\program files\Advanced SystemCare 3
2011-01-06 15:29:20 -------- d-----w- c:\users\susan\appdata\local\WinZip
2011-01-06 10:30:26 -------- d-----w- c:\program files\CCleaner
2011-01-06 10:29:59 -------- d-----w- c:\program files\FileHippo.com
2011-01-06 09:53:55 -------- d-----w- c:\program files\Windows Portable Devices
2011-01-06 08:48:50 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2011-01-06 08:48:50 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2011-01-06 08:48:50 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-01-06 08:48:35 469256 ----a-w- c:\program files\common files\windows live\.cache\7de2f8421cbad7e0a\InstallManager_WLE_WLE.exe
2011-01-06 08:48:28 15712 ----a-w- c:\program files\common files\windows live\.cache\7d07f9c21cbad7e09\MeshBetaRemover.exe
2011-01-06 08:48:25 94040 ----a-w- c:\program files\common files\windows live\.cache\7aa1d7021cbad7e08\DSETUP.dll
2011-01-06 08:48:25 525656 ----a-w- c:\program files\common files\windows live\.cache\7aa1d7021cbad7e08\DXSETUP.exe
2011-01-06 08:48:25 1691480 ----a-w- c:\program files\common files\windows live\.cache\7aa1d7021cbad7e08\dsetup32.dll
2011-01-06 08:48:23 94040 ----a-w- c:\program files\common files\windows live\.cache\77fb6f221cbad7e07\DSETUP.dll
2011-01-06 08:48:23 525656 ----a-w- c:\program files\common files\windows live\.cache\77fb6f221cbad7e07\DXSETUP.exe
2011-01-06 08:48:23 1691480 ----a-w- c:\program files\common files\windows live\.cache\77fb6f221cbad7e07\dsetup32.dll
2011-01-06 08:47:35 -------- d-----w- c:\users\susan\appdata\local\Windows Live
2011-01-06 08:46:57 754688 ----a-w- c:\windows\system32\webservices.dll
2011-01-06 08:46:31 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2011-01-06 08:46:30 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2011-01-06 08:46:30 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-01-06 08:44:57 134144 ----a-w- c:\program files\windows portable devices\sqmapi.dll
2011-01-06 08:42:56 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2011-01-06 08:42:55 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2011-01-06 08:42:55 234496 ----a-w- c:\windows\system32\oleacc.dll
2011-01-05 22:51:57 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-01-05 22:51:57 -------- d-----w- c:\progra~2\Spybot - Search & Destroy
2011-01-05 22:25:19 231424 ----a-w- c:\windows\system32\msshsq.dll
2011-01-05 21:48:32 -------- d-----w- c:\windows\system32\eu-ES
2011-01-05 21:48:32 -------- d-----w- c:\windows\system32\ca-ES
2011-01-05 21:48:31 -------- d-----w- c:\windows\system32\vi-VN
2011-01-05 21:03:45 -------- d-----w- c:\windows\system32\EventProviders
2011-01-05 21:01:57 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-01-05 21:01:57 472808 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2011-01-05 19:28:48 -------- d-----w- c:\program files\ESET
2011-01-05 19:18:59 834048 ----a-w- c:\windows\system32\wininet.dll
2011-01-05 19:18:59 389632 ----a-w- c:\windows\system32\html.iec
2011-01-05 19:18:58 78336 ----a-w- c:\windows\system32\ieencode.dll
2011-01-05 19:18:57 -------- d-----w- c:\users\susan\appdata\local\Apple
2011-01-05 19:18:31 2048 ----a-w- c:\windows\system32\tzres.dll
2011-01-05 19:18:16 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-01-05 17:04:39 -------- d-----w- c:\users\susan\appdata\local\Sony_Corporation

==================== Find3M ====================

2010-11-04 18:56:07 345600 ----a-w- c:\windows\system32\wmicmiplugin.dll
2010-11-04 18:55:38 352768 ----a-w- c:\windows\system32\taskschd.dll
2010-11-04 18:55:38 270336 ----a-w- c:\windows\system32\taskcomp.dll
2010-11-04 18:55:12 601600 ----a-w- c:\windows\system32\schedsvc.dll
2010-11-04 16:34:06 171520 ----a-w- c:\windows\system32\taskeng.exe
2010-10-28 15:44:56 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-10-28 13:27:47 292352 ----a-w- c:\windows\system32\atmfd.dll

============= FINISH: 22:05:10.76 ===============

Blade81
2011-01-22, 11:13
Hi,

If you don't use Firefox anymore then uninstall it. Version 2.0.0.20 isn't supported anymore.


Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.

Please continue as follows:


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.


Click Yes to allow ComboFix to continue scanning for malware.


When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds log.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

Blade81
2011-01-29, 12:24
Due to inactivity, this thread will now be closed.

Note:If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh DDS log and a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

If it has been less than three days since your last response and you need the thread re-opened, please send me or other MOD a private message (pm). A valid, working link to the closed topic is required.