jteirstein
New member
When the symptoms of something wrong first occurred, I was getting pop-ups from Microsoft Security Essentials (clearly bogus). After a restart, I am prompted by a fake antivirus program called ThinkPoint to do a "scan" before it will even let me access Windows. This seems to be related to a process called "hotfix.exe".
Here is the DDS log and Spybot results for items that couldn't be removed:
DDS (Ver_10-10-21.02) - NTFS_AMD64
Run by Jason at 14:44:22.16 on Sat 10/23/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3895.2178 [GMT -4:00]
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\SysWOW64\svchost.exe -k Akamai
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\Users\Jason\AppData\Roaming\hotfix.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwssvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\ccSvcHst.exe
C:\windows\system32\ThpSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\ccSvcHst.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\explorer.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TECO\Teco.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\windows\system32\wuauclt.exe
C:\Windows\System32\ThpSrv.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\windows\SysWOW64\rundll32.exe
C:\windows\SysWOW64\rundll32.exe
C:\Program Files\TOSHIBA\FlashCards\Hotkey\TcrdKBB.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\windows\system32\igfxext.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\Users\Jason\Desktop\dds.scr
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/ig?brand=TSNA&bmod=TSNA
uDefault_Page_URL = hxxp://www.google.com/ig?brand=TSNA&bmod=TSNA
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=C:\windows\system32\userinit.exe
uWinlogon: Shell=C:\Users\Jason\AppData\Roaming\hotfix.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\IPSBHO.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\coIEPlg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
uRun: [AdobeBridge]
uRun: [nxecaomwsr.exe] "C:\Users\Jason\AppData\Local\Temp\nxecaomwsr.exe"
uRun: [uPc+nerZkfgozaGuo] rundll32.exe C:\Users\Jason\AppData\Local\Temp\hswqq.dll, SystemServer
uRun: [uPc+nerZkfgmOaGuo] rundll32.exe C:\Users\Jason\AppData\Local\Temp\b09mb.dll, SystemServer
uRun: [dpapnet] rundll32 "C:\Users\Jason\AppData\Local\Temp\compcaui.dll",CreateProcessNotify
uRun: [LveehfngoCuUdn\AppData\Local\Temp\bs44k7gqrp3sx4i.exe] C:\Users\Jason\AppData\Local\Temp\bs44k7gqrp3sx4i.exe
uRun: [uPc+nerZkfgqcQJsiv] rundll32.exe C:\Users\Jason\AppData\Local\Temp\rhmk3y8.dll, SystemServer
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRunOnce: [SpybotDeletingB210] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL"
uRunOnce: [SpybotDeletingD2906] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL"
uRunOnce: [SpybotDeletingB5853] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE"
uRunOnce: [SpybotDeletingD1382] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE"
uRunOnce: [SpybotDeletingB5039] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE"
uRunOnce: [SpybotDeletingD1608] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE"
uRunOnce: [SpybotDeletingB8756] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE_old"
uRunOnce: [SpybotDeletingD2641] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE_old"
uRunOnce: [SpybotDeletingB8895] command.com /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe"
uRunOnce: [SpybotDeletingD4362] cmd.exe /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe"
uRunOnce: [SpybotDeletingB8555] command.com /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\m3SrchMn.exe"
uRunOnce: [SpybotDeletingD1750] cmd.exe /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\m3SrchMn.exe"
uRunOnce: [SpybotDeletingB9298] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOESTB.DLL"
uRunOnce: [SpybotDeletingD6215] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOESTB.DLL"
uRunOnce: [SpybotDeletingB9073] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL"
uRunOnce: [SpybotDeletingD1172] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL"
uRunOnce: [SpybotDeletingB3485] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3HIGHIN.EXE"
uRunOnce: [SpybotDeletingD2103] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3HIGHIN.EXE"
uRunOnce: [SpybotDeletingB7704] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IMPIPE.EXE"
uRunOnce: [SpybotDeletingD6755] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IMPIPE.EXE"
uRunOnce: [SpybotDeletingB4915] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MEDINT.EXE"
uRunOnce: [SpybotDeletingD6708] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MEDINT.EXE"
uRunOnce: [SpybotDeletingB9435] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKPLAY.EXE"
uRunOnce: [SpybotDeletingD3001] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKPLAY.EXE"
uRunOnce: [SpybotDeletingB2804] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SLSRCH.EXE"
uRunOnce: [SpybotDeletingD1781] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SLSRCH.EXE"
uRunOnce: [SpybotDeletingB3452] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Avatar\COMMON.F3S"
uRunOnce: [SpybotDeletingD6224] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Avatar\COMMON.F3S"
uRunOnce: [SpybotDeletingB4917] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHECKERS.F3S"
uRunOnce: [SpybotDeletingD5274] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHECKERS.F3S"
uRunOnce: [SpybotDeletingB3248] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHESS.F3S"
uRunOnce: [SpybotDeletingD125] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHESS.F3S"
uRunOnce: [SpybotDeletingB416] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\REVERSI.F3S"
uRunOnce: [SpybotDeletingD5369] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\REVERSI.F3S"
uRunOnce: [SpybotDeletingB1881] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Message\COMMON.F3S"
uRunOnce: [SpybotDeletingD8074] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Message\COMMON.F3S"
uRunOnce: [SpybotDeletingB993] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\COMMON.F3S"
uRunOnce: [SpybotDeletingD3354] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\COMMON.F3S"
uRunOnce: [SpybotDeletingB3173] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\DOG.F3S"
uRunOnce: [SpybotDeletingD7069] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\DOG.F3S"
uRunOnce: [SpybotDeletingB494] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\FISH.F3S"
uRunOnce: [SpybotDeletingD6488] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\FISH.F3S"
uRunOnce: [SpybotDeletingB26] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\KUNGFU.F3S"
uRunOnce: [SpybotDeletingD4713] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\KUNGFU.F3S"
uRunOnce: [SpybotDeletingB6880] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\LIFEGARD.F3S"
uRunOnce: [SpybotDeletingD6739] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\LIFEGARD.F3S"
uRunOnce: [SpybotDeletingB5433] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAID.F3S"
uRunOnce: [SpybotDeletingD5887] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAID.F3S"
uRunOnce: [SpybotDeletingB88] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAILBOX.F3S"
uRunOnce: [SpybotDeletingD9539] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAILBOX.F3S"
uRunOnce: [SpybotDeletingB8097] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\OPERA.F3S"
uRunOnce: [SpybotDeletingD672] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\OPERA.F3S"
uRunOnce: [SpybotDeletingB5332] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\ROBOT.F3S"
uRunOnce: [SpybotDeletingD1488] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\ROBOT.F3S"
uRunOnce: [SpybotDeletingB1457] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SEDUCT.F3S"
uRunOnce: [SpybotDeletingD4582] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SEDUCT.F3S"
uRunOnce: [SpybotDeletingB9682] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SURFER.F3S"
uRunOnce: [SpybotDeletingD2397] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SURFER.F3S"
uRunOnce: [SpybotDeletingB1794] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Overlay\COMMON.F3S"
uRunOnce: [SpybotDeletingD4518] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Overlay\COMMON.F3S"
uRunOnce: [SpybotDeletingB2320] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
uRunOnce: [SpybotDeletingD8260] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
uRunOnce: [SpybotDeletingB1605] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Settings\s_pid.dat"
uRunOnce: [SpybotDeletingD8322] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Settings\s_pid.dat"
uRunOnce: [SpybotDeletingB2558] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\CM.ICO"
uRunOnce: [SpybotDeletingD8969] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\CM.ICO"
uRunOnce: [SpybotDeletingB3065] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\MFC.ICO"
uRunOnce: [SpybotDeletingD827] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\MFC.ICO"
uRunOnce: [SpybotDeletingB6315] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\PSS.ICO"
uRunOnce: [SpybotDeletingD1959] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\PSS.ICO"
uRunOnce: [SpybotDeletingB7701] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\SMILEY.ICO"
uRunOnce: [SpybotDeletingD7128] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\SMILEY.ICO"
uRunOnce: [SpybotDeletingB8280] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\WB.ICO"
uRunOnce: [SpybotDeletingD6022] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\WB.ICO"
uRunOnce: [SpybotDeletingB8461] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\ZWINKY.ICO"
uRunOnce: [SpybotDeletingD8913] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\ZWINKY.ICO"
uRunOnce: [SpybotDeletingB2722] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HKSTUB.DLL"
uRunOnce: [SpybotDeletingD5465] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HKSTUB.DLL"
uRunOnce: [SpybotDeletingB1968] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REGHK.DLL"
uRunOnce: [SpybotDeletingD8490] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REGHK.DLL"
uRunOnce: [SpybotDeletingB6325] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3AUXSTB.DLL"
uRunOnce: [SpybotDeletingD2481] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3AUXSTB.DLL"
uRunOnce: [SpybotDeletingB816] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3DLGHK.DLL"
uRunOnce: [SpybotDeletingD7486] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3DLGHK.DLL"
uRunOnce: [SpybotDeletingB7200] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IDLE.DLL"
uRunOnce: [SpybotDeletingD6472] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IDLE.DLL"
uRunOnce: [SpybotDeletingB7017] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MSG.DLL"
uRunOnce: [SpybotDeletingD89] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MSG.DLL"
uRunOnce: [SpybotDeletingB4551] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3OUTLCN.DLL"
uRunOnce: [SpybotDeletingD2870] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3OUTLCN.DLL"
uRunOnce: [SpybotDeletingB1527] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKIN.DLL"
uRunOnce: [SpybotDeletingD677] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKIN.DLL"
uRunOnce: [SpybotDeletingB2811] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSMLBTN.DLL"
uRunOnce: [SpybotDeletingD1178] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSMLBTN.DLL"
uRunOnce: [SpybotDeletingB3888] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEPLG.DLL"
uRunOnce: [SpybotDeletingD3628] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEPLG.DLL"
uRunOnce: [SpybotDeletingB3765] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL"
uRunOnce: [SpybotDeletingD6166] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL"
uRunOnce: [SpybotDeletingB1800] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSUABTN.DLL"
uRunOnce: [SpybotDeletingD5834] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSUABTN.DLL"
uRunOnce: [SpybotDeletingB2897] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL"
uRunOnce: [SpybotDeletingD361] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL"
uRunOnce: [SpybotDeletingB3782] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3CJPEG.DLL"
uRunOnce: [SpybotDeletingD9029] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3CJPEG.DLL"
uRunOnce: [SpybotDeletingB8673] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HISTSW.DLL"
uRunOnce: [SpybotDeletingD8749] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HISTSW.DLL"
uRunOnce: [SpybotDeletingB3777] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTMLMU.DLL"
uRunOnce: [SpybotDeletingD9901] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTMLMU.DLL"
uRunOnce: [SpybotDeletingB2016] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTTPCT.DLL"
uRunOnce: [SpybotDeletingD2370] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTTPCT.DLL"
uRunOnce: [SpybotDeletingB5447] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL"
uRunOnce: [SpybotDeletingD4934] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL"
uRunOnce: [SpybotDeletingB7293] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3POPSWT.DLL"
uRunOnce: [SpybotDeletingD6044] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3POPSWT.DLL"
uRunOnce: [SpybotDeletingB9011] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3PSSAVR.SCR"
uRunOnce: [SpybotDeletingD7218] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3PSSAVR.SCR"
uRunOnce: [SpybotDeletingB2744] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REPROX.DLL"
uRunOnce: [SpybotDeletingD8926] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REPROX.DLL"
uRunOnce: [SpybotDeletingB5918] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3RESTUB.DLL"
uRunOnce: [SpybotDeletingD8158] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3RESTUB.DLL"
uRunOnce: [SpybotDeletingB7886] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCHMON.EXE"
uRunOnce: [SpybotDeletingD9090] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCHMON.EXE"
uRunOnce: [SpybotDeletingB7096] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCRCTR.DLL"
uRunOnce: [SpybotDeletingD3404] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCRCTR.DLL"
mRun: [TUSBSleepChargeSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
mRun: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
mRun: [<NO NAME>]
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [uPc+nerZkfgqcQJsiv] rundll32.exe C:\Users\Jason\AppData\Local\Temp\rhmk3y8.dll, SystemServer
mRun: [uPc+nerZkfgmOaGuo] rundll32.exe C:\Users\Jason\AppData\Local\Temp\b09mb.dll, SystemServer
mRun: [uPc+nerZkfgozaGuo] rundll32.exe C:\Users\Jason\AppData\Local\Temp\hswqq.dll, SystemServer
mRunOnce: [SpybotDeletingA805] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL"
mRunOnce: [SpybotDeletingC1769] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL"
mRunOnce: [SpybotDeletingA7845] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE"
mRunOnce: [SpybotDeletingC3553] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE"
mRunOnce: [SpybotDeletingA3047] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE"
mRunOnce: [SpybotDeletingC8980] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE"
mRunOnce: [SpybotDeletingA6275] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE_old"
mRunOnce: [SpybotDeletingC5231] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE_old"
mRunOnce: [SpybotDeletingA5749] command.com /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe"
mRunOnce: [SpybotDeletingC2091] cmd.exe /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe"
mRunOnce: [SpybotDeletingA4653] command.com /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\m3SrchMn.exe"
mRunOnce: [SpybotDeletingC4358] cmd.exe /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\m3SrchMn.exe"
mRunOnce: [SpybotDeletingA4471] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOESTB.DLL"
mRunOnce: [SpybotDeletingC9216] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOESTB.DLL"
mRunOnce: [SpybotDeletingA3593] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL"
mRunOnce: [SpybotDeletingC5737] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL"
mRunOnce: [SpybotDeletingA9186] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3HIGHIN.EXE"
mRunOnce: [SpybotDeletingC5090] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3HIGHIN.EXE"
mRunOnce: [SpybotDeletingA9035] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IMPIPE.EXE"
mRunOnce: [SpybotDeletingC9745] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IMPIPE.EXE"
mRunOnce: [SpybotDeletingA7010] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MEDINT.EXE"
mRunOnce: [SpybotDeletingC2513] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MEDINT.EXE"
mRunOnce: [SpybotDeletingA7923] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKPLAY.EXE"
mRunOnce: [SpybotDeletingC9423] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKPLAY.EXE"
mRunOnce: [SpybotDeletingA6621] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SLSRCH.EXE"
mRunOnce: [SpybotDeletingC201] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SLSRCH.EXE"
mRunOnce: [SpybotDeletingA4367] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Avatar\COMMON.F3S"
mRunOnce: [SpybotDeletingC6692] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Avatar\COMMON.F3S"
mRunOnce: [SpybotDeletingA299] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHECKERS.F3S"
mRunOnce: [SpybotDeletingC8851] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHECKERS.F3S"
mRunOnce: [SpybotDeletingA6605] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHESS.F3S"
mRunOnce: [SpybotDeletingC5942] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHESS.F3S"
mRunOnce: [SpybotDeletingA2857] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\REVERSI.F3S"
mRunOnce: [SpybotDeletingC9706] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\REVERSI.F3S"
mRunOnce: [SpybotDeletingA8055] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Message\COMMON.F3S"
mRunOnce: [SpybotDeletingC9389] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Message\COMMON.F3S"
mRunOnce: [SpybotDeletingA4028] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\COMMON.F3S"
mRunOnce: [SpybotDeletingC5692] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\COMMON.F3S"
mRunOnce: [SpybotDeletingA2683] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\DOG.F3S"
mRunOnce: [SpybotDeletingC6884] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\DOG.F3S"
mRunOnce: [SpybotDeletingA6024] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\FISH.F3S"
mRunOnce: [SpybotDeletingC1279] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\FISH.F3S"
mRunOnce: [SpybotDeletingA7047] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\KUNGFU.F3S"
mRunOnce: [SpybotDeletingC2627] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\KUNGFU.F3S"
mRunOnce: [SpybotDeletingA1414] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\LIFEGARD.F3S"
mRunOnce: [SpybotDeletingC2968] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\LIFEGARD.F3S"
mRunOnce: [SpybotDeletingA1019] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAID.F3S"
mRunOnce: [SpybotDeletingC968] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAID.F3S"
mRunOnce: [SpybotDeletingA9536] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAILBOX.F3S"
mRunOnce: [SpybotDeletingC4686] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAILBOX.F3S"
mRunOnce: [SpybotDeletingA5887] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\OPERA.F3S"
mRunOnce: [SpybotDeletingC8542] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\OPERA.F3S"
mRunOnce: [SpybotDeletingA7523] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\ROBOT.F3S"
mRunOnce: [SpybotDeletingC1970] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\ROBOT.F3S"
mRunOnce: [SpybotDeletingA6880] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SEDUCT.F3S"
mRunOnce: [SpybotDeletingC7159] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SEDUCT.F3S"
mRunOnce: [SpybotDeletingA1488] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SURFER.F3S"
mRunOnce: [SpybotDeletingC7578] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SURFER.F3S"
mRunOnce: [SpybotDeletingA9484] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Overlay\COMMON.F3S"
mRunOnce: [SpybotDeletingC2143] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Overlay\COMMON.F3S"
mRunOnce: [SpybotDeletingA8660] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
mRunOnce: [SpybotDeletingC1884] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
mRunOnce: [SpybotDeletingA6165] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Settings\s_pid.dat"
mRunOnce: [SpybotDeletingC3447] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Settings\s_pid.dat"
mRunOnce: [SpybotDeletingA6168] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\CM.ICO"
mRunOnce: [SpybotDeletingC5057] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\CM.ICO"
mRunOnce: [SpybotDeletingA8014] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\MFC.ICO"
mRunOnce: [SpybotDeletingC4333] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\MFC.ICO"
mRunOnce: [SpybotDeletingA1992] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\PSS.ICO"
mRunOnce: [SpybotDeletingC9844] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\PSS.ICO"
mRunOnce: [SpybotDeletingA7866] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\SMILEY.ICO"
mRunOnce: [SpybotDeletingC7667] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\SMILEY.ICO"
mRunOnce: [SpybotDeletingA966] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\WB.ICO"
mRunOnce: [SpybotDeletingC8992] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\WB.ICO"
mRunOnce: [SpybotDeletingA3821] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\ZWINKY.ICO"
mRunOnce: [SpybotDeletingC127] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\ZWINKY.ICO"
mRunOnce: [SpybotDeletingA395] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HKSTUB.DLL"
mRunOnce: [SpybotDeletingC6085] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HKSTUB.DLL"
mRunOnce: [SpybotDeletingA7091] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REGHK.DLL"
mRunOnce: [SpybotDeletingC223] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REGHK.DLL"
mRunOnce: [SpybotDeletingA7432] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3AUXSTB.DLL"
mRunOnce: [SpybotDeletingC95] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3AUXSTB.DLL"
mRunOnce: [SpybotDeletingA4642] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3DLGHK.DLL"
mRunOnce: [SpybotDeletingC4299] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3DLGHK.DLL"
mRunOnce: [SpybotDeletingA7512] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IDLE.DLL"
mRunOnce: [SpybotDeletingC2402] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IDLE.DLL"
mRunOnce: [SpybotDeletingA4422] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MSG.DLL"
mRunOnce: [SpybotDeletingC1475] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MSG.DLL"
mRunOnce: [SpybotDeletingA2582] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3OUTLCN.DLL"
mRunOnce: [SpybotDeletingC2672] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3OUTLCN.DLL"
mRunOnce: [SpybotDeletingA3732] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKIN.DLL"
mRunOnce: [SpybotDeletingC8652] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKIN.DLL"
mRunOnce: [SpybotDeletingA3915] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSMLBTN.DLL"
mRunOnce: [SpybotDeletingC9243] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSMLBTN.DLL"
mRunOnce: [SpybotDeletingA5976] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEPLG.DLL"
mRunOnce: [SpybotDeletingC3455] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEPLG.DLL"
mRunOnce: [SpybotDeletingA1026] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL"
mRunOnce: [SpybotDeletingC420] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL"
mRunOnce: [SpybotDeletingA1954] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSUABTN.DLL"
mRunOnce: [SpybotDeletingC6515] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSUABTN.DLL"
mRunOnce: [SpybotDeletingA2905] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL"
mRunOnce: [SpybotDeletingC1706] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL"
mRunOnce: [SpybotDeletingA9131] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3CJPEG.DLL"
mRunOnce: [SpybotDeletingC5659] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3CJPEG.DLL"
mRunOnce: [SpybotDeletingA3326] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HISTSW.DLL"
mRunOnce: [SpybotDeletingC1967] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HISTSW.DLL"
mRunOnce: [SpybotDeletingA6742] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTMLMU.DLL"
mRunOnce: [SpybotDeletingC9933] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTMLMU.DLL"
mRunOnce: [SpybotDeletingA6757] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTTPCT.DLL"
mRunOnce: [SpybotDeletingC7501] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTTPCT.DLL"
mRunOnce: [SpybotDeletingA9511] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL"
mRunOnce: [SpybotDeletingC47] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL"
mRunOnce: [SpybotDeletingA8858] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3POPSWT.DLL"
mRunOnce: [SpybotDeletingC1789] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3POPSWT.DLL"
mRunOnce: [SpybotDeletingA4086] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3PSSAVR.SCR"
mRunOnce: [SpybotDeletingC555] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3PSSAVR.SCR"
mRunOnce: [SpybotDeletingA7996] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REPROX.DLL"
mRunOnce: [SpybotDeletingC918] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REPROX.DLL"
mRunOnce: [SpybotDeletingA4804] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3RESTUB.DLL"
mRunOnce: [SpybotDeletingC503] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3RESTUB.DLL"
mRunOnce: [SpybotDeletingA3320] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCHMON.EXE"
mRunOnce: [SpybotDeletingC6437] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCHMON.EXE"
mRunOnce: [SpybotDeletingA2829] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCRCTR.DLL"
mRunOnce: [SpybotDeletingC4036] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCRCTR.DLL"
mRunOnce: [SpybotSnD] "C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
StartupFolder: C:\Users\Jason\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg64.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
TB-X64: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
mRun-x64: [(Default)]
mRun-x64: [IgfxTray] C:\windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\windows\system32\igfxpers.exe
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun-x64: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun-x64: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun-x64: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun-x64: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun-x64: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
mRun-x64: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
mRun-x64: [ThpSrv] C:\windows\system32\thpsrv /logon
mRun-x64: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
mRun-x64: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
mRun-x64: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - C:\Users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\ipde21gu.default\
FF - component: C:\Users\Jason\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\components\gvtlf.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
============= SERVICES / DRIVERS ===============
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-1-25 55280]
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1108000.005\symds64.sys [2010-10-22 433200]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1108000.005\symefa64.sys [2010-10-22 221232]
R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\Windows\System32\drivers\thpdrv.sys [2009-6-29 34880]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\Windows\System32\drivers\Thpevm.sys [2009-6-29 14784]
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\Windows\System32\drivers\tos_sps64.sys [2010-1-25 482384]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20101001.001\BHDrvx64.sys [2010-10-2 954928]
R1 ccHP;Symantec Hash Provider;C:\Windows\System32\drivers\NISx64\1108000.005\cchpx64.sys [2010-10-22 615040]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20101021.003\IDSviA64.sys [2010-10-19 476720]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1108000.005\ironx64.sys [2010-10-22 150064]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;C:\Windows\System32\drivers\NISx64\1108000.005\symtdiv.sys [2010-10-22 451120]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 Akamai;Akamai NetSession Interface;C:\windows\System32\svchost.exe -k Akamai [2009-7-13 27136]
R2 cfWiMAXService;ConfigFree WiMAX Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2009-10-28 252784]
R2 ConfigFree Service;ConfigFree Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-3-10 46448]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-1-25 13336]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\ccsvchst.exe [2010-10-22 126392]
R2 rimspci;rimspci;C:\Windows\System32\drivers\rimspe64.sys [2010-1-25 60416]
R2 risdpcie;risdpcie;C:\Windows\System32\drivers\risdpe64.sys [2010-1-25 81408]
R2 rixdpcie;rixdpcie;C:\Windows\System32\drivers\rixdpe64.sys [2010-1-25 55808]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-10-22 1153368]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\TOSHIBA\TECO\TecoService.exe [2009-9-28 251760]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\Windows\System32\drivers\TVALZFL.sys [2009-6-19 14472]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-1-25 2314240]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-10-21 132656]
R3 FwLnk;FwLnk Driver;C:\Windows\System32\drivers\FwLnk.sys [2010-1-25 9216]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-1-25 56344]
R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2009-10-26 151936]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2009-10-30 244736]
R3 PGEffect;Pangu effect driver;C:\Windows\System32\drivers\PGEffect.sys [2010-1-25 35008]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-1-25 236544]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;C:\Windows\System32\drivers\rtl8192se.sys [2010-1-25 946688]
R3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-1-25 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-11-5 137560]
R3 TPCHSrv;TPCH Service;C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2009-11-10 824688]
RUnknown MyWebSearchService;MyWebSearchService; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-3-7 135664]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-3-7 1038088]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-4-19 50688]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-3-9 1255736]
=============== Created Last 30 ================
2010-10-23 03:21:16 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2010-10-23 03:21:16 -------- d-----w- C:\PROGRA~3\Spybot - Search & Destroy
2010-10-23 02:29:03 505392 ----a-w- C:\windows\System32\drivers\NISx64\1108000.005\srtsp64.sys
2010-10-23 02:29:03 451120 ----a-w- C:\windows\System32\drivers\NISx64\1108000.005\symtdiv.sys
2010-10-23 02:29:03 433200 ----a-r- C:\windows\System32\drivers\NISx64\1108000.005\symds64.sys
2010-10-23 02:29:03 32304 ----a-w- C:\windows\System32\drivers\NISx64\1108000.005\srtspx64.sys
2010-10-23 02:29:03 221232 ----a-w- C:\windows\System32\drivers\NISx64\1108000.005\symefa64.sys
2010-10-23 02:29:03 150064 ----a-w- C:\windows\System32\drivers\NISx64\1108000.005\ironx64.sys
2010-10-23 02:29:02 615040 ----a-w- C:\windows\System32\drivers\NISx64\1108000.005\cchpx64.sys
2010-10-23 02:28:35 -------- d-----w- C:\windows\System32\drivers\NISx64\1108000.005
2010-10-22 06:03:18 -------- d-----w- C:\Users\Jason\AppData\Local\CrashDumps
2010-10-22 02:47:47 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2010-10-22 02:46:18 173104 ----a-w- C:\windows\System32\drivers\SYMEVENT64x86.SYS
2010-10-22 02:46:08 -------- d-----w- C:\Program Files\Symantec
2010-10-22 02:46:08 -------- d-----w- C:\Program Files\Common Files\Symantec Shared
2010-10-22 02:35:10 177 ----a-w- C:\Users\Jason\AppData\Roaming\2834.bat
2010-10-22 02:35:07 178 ----a-w- C:\Users\Jason\AppData\Roaming\15569.bat
2010-10-22 02:34:58 514560 ----a-w- C:\Users\Jason\AppData\Roaming\hotfix.exe
2010-10-22 02:34:58 177 ----a-w- C:\Users\Jason\AppData\Roaming\6543.bat
2010-10-22 02:34:41 -------- d-----w- C:\Users\Jason\AppData\Roaming\D9F29B036FD9D3D379685D2C553E39E0
2010-10-22 00:49:18 -------- d-----w- C:\Program Files (x86)\MyWebSearch
2010-10-20 04:26:56 8006480 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{FA48E0E3-F410-41A9-8FF8-778C6240D3CB}\mpengine.dll
2010-10-13 03:01:10 148992 ----a-w- C:\windows\System32\t2embed.dll
2010-10-13 03:01:10 109056 ----a-w- C:\windows\SysWow64\t2embed.dll
2010-10-13 03:01:09 4582912 ----a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe
2010-10-13 03:01:09 2085376 ----a-w- C:\windows\System32\ole32.dll
2010-10-13 03:01:08 4247040 ----a-w- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
2010-10-13 03:01:08 1413632 ----a-w- C:\windows\SysWow64\ole32.dll
2010-10-13 03:01:07 483840 ----a-w- C:\windows\System32\StructuredQuery.dll
2010-10-13 03:01:07 363520 ----a-w- C:\windows\SysWow64\StructuredQuery.dll
2010-10-13 03:01:07 224256 ----a-w- C:\windows\SysWow64\schannel.dll
2010-10-13 03:01:06 633856 ----a-w- C:\windows\System32\comctl32.dll
2010-10-13 03:01:06 530432 ----a-w- C:\windows\SysWow64\comctl32.dll
2010-10-13 03:01:06 340992 ----a-w- C:\windows\System32\schannel.dll
2010-10-08 07:01:17 243712 ----a-w- C:\windows\System32\drivers\ks.sys
2010-10-08 07:01:17 184832 ----a-w- C:\windows\System32\drivers\usbvideo.sys
2010-10-08 03:54:44 -------- d-----w- C:\Users\Jason\AppData\Local\Electronic Arts
2010-10-08 00:06:28 -------- d-----w- C:\Users\Jason\AppData\Local\ElevatedDiagnostics
2010-10-07 01:06:39 2048 ----a-w- C:\windows\SysWow64\tzres.dll
2010-10-07 01:06:39 2048 ----a-w- C:\windows\System32\tzres.dll
2010-10-07 01:06:10 13312 ----a-w- C:\Program Files\Internet Explorer\iecompat.dll
2010-10-07 01:06:10 13312 ----a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll
2010-09-25 05:13:05 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2010-09-25 05:13:04 -------- d-----w- C:\Program Files (x86)\Steam
==================== Find3M ====================
2010-09-08 15:17:46 94208 ----a-w- C:\windows\SysWow64\QuickTimeVR.qtx
2010-09-08 15:17:46 69632 ----a-w- C:\windows\SysWow64\QuickTime.qts
2010-09-08 05:36:17 1192960 ----a-w- C:\windows\System32\wininet.dll
2010-09-08 05:34:34 57856 ----a-w- C:\windows\System32\licmgr10.dll
2010-09-08 04:30:04 978432 ----a-w- C:\windows\SysWow64\wininet.dll
2010-09-08 04:28:15 44544 ----a-w- C:\windows\SysWow64\licmgr10.dll
2010-09-08 04:16:38 482816 ----a-w- C:\windows\System32\html.iec
2010-09-08 03:35:30 1638912 ----a-w- C:\windows\System32\mshtml.tlb
2010-09-08 03:22:31 386048 ----a-w- C:\windows\SysWow64\html.iec
2010-09-08 02:48:16 1638912 ----a-w- C:\windows\SysWow64\mshtml.tlb
2010-09-01 05:12:09 12625920 ----a-w- C:\windows\System32\wmploc.DLL
2010-09-01 04:23:49 12625408 ----a-w- C:\windows\SysWow64\wmploc.DLL
2010-09-01 02:58:34 3123712 ----a-w- C:\windows\System32\win32k.sys
2010-08-31 04:32:30 954752 ----a-w- C:\windows\SysWow64\mfc40.dll
2010-08-31 04:32:30 954288 ----a-w- C:\windows\SysWow64\mfc40u.dll
2010-08-27 06:14:02 236032 ----a-w- C:\windows\System32\srvsvc.dll
2010-08-27 05:46:48 9728 ----a-w- C:\windows\SysWow64\sscore.dll
2010-08-27 03:38:04 463360 ----a-w- C:\windows\System32\drivers\srv.sys
2010-08-27 03:37:48 402944 ----a-w- C:\windows\System32\drivers\srv2.sys
2010-08-27 03:37:26 161792 ----a-w- C:\windows\System32\drivers\srvnet.sys
2010-08-21 06:38:47 1024512 ----a-w- C:\windows\System32\wmpmde.dll
2010-08-21 06:29:47 558592 ----a-w- C:\windows\System32\spoolsv.exe
2010-08-21 05:36:33 738816 ----a-w- C:\windows\SysWow64\wmpmde.dll
2010-07-29 06:30:34 82944 ----a-w- C:\windows\SysWow64\iccvid.dll
============= FINISH: 14:45:04.95 ===============
FunWebProducts: [SBI $51F213BA] Program directory (Directory, fixing failed)
C:\Program Files (x86)\MyWebSearch\bar\
FunWebProducts: [SBI $9975C0B8] Program directory (Directory, fixing failed)
C:\Program Files (x86)\MyWebSearch\bar\1.bin\
MyWay.MyWebSearch: [SBI $676B23CE] Program directory (Directory, fixing failed)
C:\Program Files (x86)\MYWEBSEARCH\
MyWay.MyWebSearch: [SBI $E4947DDB] Library (File, fixed)
C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE_old
Properties.size=28762
Properties.md5=48D50D679D28E5C4BF5A67664CC56B41
Properties.filedate=1287708559
Properties.filedatetext=2010-10-21 20:49:18
MyWay.MyWebSearch: [SBI $F06432E0] Program directory (Directory, fixing failed)
C:\Program Files (x86)\MyWebSearch\bar\1.bin
MyWay.MyWebSearch: [SBI $78882F84] Program directory (Directory, fixing failed)
C:\Program Files (x86)\MyWebSearch\bar
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2010-10-22 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2010-06-29 Includes\Adware.sbi (*)
2010-10-12 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-09-22 Includes\Dialer.sbi (*)
2010-10-12 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2010-10-12 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-08-02 Includes\Keyloggers.sbi (*)
2010-10-12 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2010-09-13 Includes\Malware.sbi (*)
2010-10-19 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-10-12 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-10-12 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-06-29 Includes\Spyware.sbi (*)
2010-10-12 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-08-04 Includes\Trojans.sbi (*)
2010-10-12 Includes\TrojansC-02.sbi (*)
2010-10-12 Includes\TrojansC-03.sbi (*)
2010-10-12 Includes\TrojansC-04.sbi (*)
2010-10-20 Includes\TrojansC-05.sbi (*)
2010-10-12 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
Thanks in advance for you help!
Here is the DDS log and Spybot results for items that couldn't be removed:
DDS (Ver_10-10-21.02) - NTFS_AMD64
Run by Jason at 14:44:22.16 on Sat 10/23/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3895.2178 [GMT -4:00]
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\SysWOW64\svchost.exe -k Akamai
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\Users\Jason\AppData\Roaming\hotfix.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwssvc.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\ccSvcHst.exe
C:\windows\system32\ThpSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\ccSvcHst.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\explorer.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TECO\Teco.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\windows\system32\wuauclt.exe
C:\Windows\System32\ThpSrv.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\windows\SysWOW64\rundll32.exe
C:\windows\SysWOW64\rundll32.exe
C:\Program Files\TOSHIBA\FlashCards\Hotkey\TcrdKBB.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\windows\system32\igfxext.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\Users\Jason\Desktop\dds.scr
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/ig?brand=TSNA&bmod=TSNA
uDefault_Page_URL = hxxp://www.google.com/ig?brand=TSNA&bmod=TSNA
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=C:\windows\system32\userinit.exe
uWinlogon: Shell=C:\Users\Jason\AppData\Roaming\hotfix.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\IPSBHO.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\coIEPlg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
uRun: [AdobeBridge]
uRun: [nxecaomwsr.exe] "C:\Users\Jason\AppData\Local\Temp\nxecaomwsr.exe"
uRun: [uPc+nerZkfgozaGuo] rundll32.exe C:\Users\Jason\AppData\Local\Temp\hswqq.dll, SystemServer
uRun: [uPc+nerZkfgmOaGuo] rundll32.exe C:\Users\Jason\AppData\Local\Temp\b09mb.dll, SystemServer
uRun: [dpapnet] rundll32 "C:\Users\Jason\AppData\Local\Temp\compcaui.dll",CreateProcessNotify
uRun: [LveehfngoCuUdn\AppData\Local\Temp\bs44k7gqrp3sx4i.exe] C:\Users\Jason\AppData\Local\Temp\bs44k7gqrp3sx4i.exe
uRun: [uPc+nerZkfgqcQJsiv] rundll32.exe C:\Users\Jason\AppData\Local\Temp\rhmk3y8.dll, SystemServer
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRunOnce: [SpybotDeletingB210] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL"
uRunOnce: [SpybotDeletingD2906] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL"
uRunOnce: [SpybotDeletingB5853] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE"
uRunOnce: [SpybotDeletingD1382] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE"
uRunOnce: [SpybotDeletingB5039] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE"
uRunOnce: [SpybotDeletingD1608] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE"
uRunOnce: [SpybotDeletingB8756] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE_old"
uRunOnce: [SpybotDeletingD2641] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE_old"
uRunOnce: [SpybotDeletingB8895] command.com /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe"
uRunOnce: [SpybotDeletingD4362] cmd.exe /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe"
uRunOnce: [SpybotDeletingB8555] command.com /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\m3SrchMn.exe"
uRunOnce: [SpybotDeletingD1750] cmd.exe /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\m3SrchMn.exe"
uRunOnce: [SpybotDeletingB9298] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOESTB.DLL"
uRunOnce: [SpybotDeletingD6215] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOESTB.DLL"
uRunOnce: [SpybotDeletingB9073] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL"
uRunOnce: [SpybotDeletingD1172] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL"
uRunOnce: [SpybotDeletingB3485] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3HIGHIN.EXE"
uRunOnce: [SpybotDeletingD2103] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3HIGHIN.EXE"
uRunOnce: [SpybotDeletingB7704] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IMPIPE.EXE"
uRunOnce: [SpybotDeletingD6755] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IMPIPE.EXE"
uRunOnce: [SpybotDeletingB4915] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MEDINT.EXE"
uRunOnce: [SpybotDeletingD6708] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MEDINT.EXE"
uRunOnce: [SpybotDeletingB9435] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKPLAY.EXE"
uRunOnce: [SpybotDeletingD3001] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKPLAY.EXE"
uRunOnce: [SpybotDeletingB2804] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SLSRCH.EXE"
uRunOnce: [SpybotDeletingD1781] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SLSRCH.EXE"
uRunOnce: [SpybotDeletingB3452] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Avatar\COMMON.F3S"
uRunOnce: [SpybotDeletingD6224] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Avatar\COMMON.F3S"
uRunOnce: [SpybotDeletingB4917] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHECKERS.F3S"
uRunOnce: [SpybotDeletingD5274] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHECKERS.F3S"
uRunOnce: [SpybotDeletingB3248] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHESS.F3S"
uRunOnce: [SpybotDeletingD125] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHESS.F3S"
uRunOnce: [SpybotDeletingB416] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\REVERSI.F3S"
uRunOnce: [SpybotDeletingD5369] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\REVERSI.F3S"
uRunOnce: [SpybotDeletingB1881] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Message\COMMON.F3S"
uRunOnce: [SpybotDeletingD8074] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Message\COMMON.F3S"
uRunOnce: [SpybotDeletingB993] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\COMMON.F3S"
uRunOnce: [SpybotDeletingD3354] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\COMMON.F3S"
uRunOnce: [SpybotDeletingB3173] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\DOG.F3S"
uRunOnce: [SpybotDeletingD7069] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\DOG.F3S"
uRunOnce: [SpybotDeletingB494] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\FISH.F3S"
uRunOnce: [SpybotDeletingD6488] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\FISH.F3S"
uRunOnce: [SpybotDeletingB26] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\KUNGFU.F3S"
uRunOnce: [SpybotDeletingD4713] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\KUNGFU.F3S"
uRunOnce: [SpybotDeletingB6880] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\LIFEGARD.F3S"
uRunOnce: [SpybotDeletingD6739] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\LIFEGARD.F3S"
uRunOnce: [SpybotDeletingB5433] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAID.F3S"
uRunOnce: [SpybotDeletingD5887] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAID.F3S"
uRunOnce: [SpybotDeletingB88] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAILBOX.F3S"
uRunOnce: [SpybotDeletingD9539] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAILBOX.F3S"
uRunOnce: [SpybotDeletingB8097] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\OPERA.F3S"
uRunOnce: [SpybotDeletingD672] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\OPERA.F3S"
uRunOnce: [SpybotDeletingB5332] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\ROBOT.F3S"
uRunOnce: [SpybotDeletingD1488] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\ROBOT.F3S"
uRunOnce: [SpybotDeletingB1457] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SEDUCT.F3S"
uRunOnce: [SpybotDeletingD4582] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SEDUCT.F3S"
uRunOnce: [SpybotDeletingB9682] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SURFER.F3S"
uRunOnce: [SpybotDeletingD2397] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SURFER.F3S"
uRunOnce: [SpybotDeletingB1794] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Overlay\COMMON.F3S"
uRunOnce: [SpybotDeletingD4518] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Overlay\COMMON.F3S"
uRunOnce: [SpybotDeletingB2320] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
uRunOnce: [SpybotDeletingD8260] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
uRunOnce: [SpybotDeletingB1605] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Settings\s_pid.dat"
uRunOnce: [SpybotDeletingD8322] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Settings\s_pid.dat"
uRunOnce: [SpybotDeletingB2558] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\CM.ICO"
uRunOnce: [SpybotDeletingD8969] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\CM.ICO"
uRunOnce: [SpybotDeletingB3065] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\MFC.ICO"
uRunOnce: [SpybotDeletingD827] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\MFC.ICO"
uRunOnce: [SpybotDeletingB6315] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\PSS.ICO"
uRunOnce: [SpybotDeletingD1959] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\PSS.ICO"
uRunOnce: [SpybotDeletingB7701] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\SMILEY.ICO"
uRunOnce: [SpybotDeletingD7128] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\SMILEY.ICO"
uRunOnce: [SpybotDeletingB8280] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\WB.ICO"
uRunOnce: [SpybotDeletingD6022] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\WB.ICO"
uRunOnce: [SpybotDeletingB8461] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\ZWINKY.ICO"
uRunOnce: [SpybotDeletingD8913] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\ZWINKY.ICO"
uRunOnce: [SpybotDeletingB2722] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HKSTUB.DLL"
uRunOnce: [SpybotDeletingD5465] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HKSTUB.DLL"
uRunOnce: [SpybotDeletingB1968] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REGHK.DLL"
uRunOnce: [SpybotDeletingD8490] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REGHK.DLL"
uRunOnce: [SpybotDeletingB6325] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3AUXSTB.DLL"
uRunOnce: [SpybotDeletingD2481] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3AUXSTB.DLL"
uRunOnce: [SpybotDeletingB816] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3DLGHK.DLL"
uRunOnce: [SpybotDeletingD7486] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3DLGHK.DLL"
uRunOnce: [SpybotDeletingB7200] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IDLE.DLL"
uRunOnce: [SpybotDeletingD6472] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IDLE.DLL"
uRunOnce: [SpybotDeletingB7017] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MSG.DLL"
uRunOnce: [SpybotDeletingD89] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MSG.DLL"
uRunOnce: [SpybotDeletingB4551] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3OUTLCN.DLL"
uRunOnce: [SpybotDeletingD2870] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3OUTLCN.DLL"
uRunOnce: [SpybotDeletingB1527] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKIN.DLL"
uRunOnce: [SpybotDeletingD677] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKIN.DLL"
uRunOnce: [SpybotDeletingB2811] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSMLBTN.DLL"
uRunOnce: [SpybotDeletingD1178] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSMLBTN.DLL"
uRunOnce: [SpybotDeletingB3888] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEPLG.DLL"
uRunOnce: [SpybotDeletingD3628] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEPLG.DLL"
uRunOnce: [SpybotDeletingB3765] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL"
uRunOnce: [SpybotDeletingD6166] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL"
uRunOnce: [SpybotDeletingB1800] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSUABTN.DLL"
uRunOnce: [SpybotDeletingD5834] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSUABTN.DLL"
uRunOnce: [SpybotDeletingB2897] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL"
uRunOnce: [SpybotDeletingD361] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL"
uRunOnce: [SpybotDeletingB3782] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3CJPEG.DLL"
uRunOnce: [SpybotDeletingD9029] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3CJPEG.DLL"
uRunOnce: [SpybotDeletingB8673] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HISTSW.DLL"
uRunOnce: [SpybotDeletingD8749] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HISTSW.DLL"
uRunOnce: [SpybotDeletingB3777] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTMLMU.DLL"
uRunOnce: [SpybotDeletingD9901] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTMLMU.DLL"
uRunOnce: [SpybotDeletingB2016] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTTPCT.DLL"
uRunOnce: [SpybotDeletingD2370] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTTPCT.DLL"
uRunOnce: [SpybotDeletingB5447] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL"
uRunOnce: [SpybotDeletingD4934] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL"
uRunOnce: [SpybotDeletingB7293] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3POPSWT.DLL"
uRunOnce: [SpybotDeletingD6044] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3POPSWT.DLL"
uRunOnce: [SpybotDeletingB9011] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3PSSAVR.SCR"
uRunOnce: [SpybotDeletingD7218] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3PSSAVR.SCR"
uRunOnce: [SpybotDeletingB2744] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REPROX.DLL"
uRunOnce: [SpybotDeletingD8926] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REPROX.DLL"
uRunOnce: [SpybotDeletingB5918] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3RESTUB.DLL"
uRunOnce: [SpybotDeletingD8158] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3RESTUB.DLL"
uRunOnce: [SpybotDeletingB7886] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCHMON.EXE"
uRunOnce: [SpybotDeletingD9090] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCHMON.EXE"
uRunOnce: [SpybotDeletingB7096] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCRCTR.DLL"
uRunOnce: [SpybotDeletingD3404] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCRCTR.DLL"
mRun: [TUSBSleepChargeSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
mRun: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
mRun: [<NO NAME>]
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [uPc+nerZkfgqcQJsiv] rundll32.exe C:\Users\Jason\AppData\Local\Temp\rhmk3y8.dll, SystemServer
mRun: [uPc+nerZkfgmOaGuo] rundll32.exe C:\Users\Jason\AppData\Local\Temp\b09mb.dll, SystemServer
mRun: [uPc+nerZkfgozaGuo] rundll32.exe C:\Users\Jason\AppData\Local\Temp\hswqq.dll, SystemServer
mRunOnce: [SpybotDeletingA805] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL"
mRunOnce: [SpybotDeletingC1769] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3PLUGIN.DLL"
mRunOnce: [SpybotDeletingA7845] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE"
mRunOnce: [SpybotDeletingC3553] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE"
mRunOnce: [SpybotDeletingA3047] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE"
mRunOnce: [SpybotDeletingC8980] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE"
mRunOnce: [SpybotDeletingA6275] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE_old"
mRunOnce: [SpybotDeletingC5231] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE_old"
mRunOnce: [SpybotDeletingA5749] command.com /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe"
mRunOnce: [SpybotDeletingC2091] cmd.exe /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe"
mRunOnce: [SpybotDeletingA4653] command.com /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\m3SrchMn.exe"
mRunOnce: [SpybotDeletingC4358] cmd.exe /c del "C:\PROGRA~2\MYWEBS~1\bar\1.bin\m3SrchMn.exe"
mRunOnce: [SpybotDeletingA4471] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOESTB.DLL"
mRunOnce: [SpybotDeletingC9216] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOESTB.DLL"
mRunOnce: [SpybotDeletingA3593] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL"
mRunOnce: [SpybotDeletingC5737] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL"
mRunOnce: [SpybotDeletingA9186] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3HIGHIN.EXE"
mRunOnce: [SpybotDeletingC5090] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3HIGHIN.EXE"
mRunOnce: [SpybotDeletingA9035] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IMPIPE.EXE"
mRunOnce: [SpybotDeletingC9745] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IMPIPE.EXE"
mRunOnce: [SpybotDeletingA7010] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MEDINT.EXE"
mRunOnce: [SpybotDeletingC2513] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MEDINT.EXE"
mRunOnce: [SpybotDeletingA7923] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKPLAY.EXE"
mRunOnce: [SpybotDeletingC9423] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKPLAY.EXE"
mRunOnce: [SpybotDeletingA6621] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SLSRCH.EXE"
mRunOnce: [SpybotDeletingC201] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SLSRCH.EXE"
mRunOnce: [SpybotDeletingA4367] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Avatar\COMMON.F3S"
mRunOnce: [SpybotDeletingC6692] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Avatar\COMMON.F3S"
mRunOnce: [SpybotDeletingA299] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHECKERS.F3S"
mRunOnce: [SpybotDeletingC8851] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHECKERS.F3S"
mRunOnce: [SpybotDeletingA6605] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHESS.F3S"
mRunOnce: [SpybotDeletingC5942] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\CHESS.F3S"
mRunOnce: [SpybotDeletingA2857] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\REVERSI.F3S"
mRunOnce: [SpybotDeletingC9706] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Game\REVERSI.F3S"
mRunOnce: [SpybotDeletingA8055] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Message\COMMON.F3S"
mRunOnce: [SpybotDeletingC9389] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Message\COMMON.F3S"
mRunOnce: [SpybotDeletingA4028] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\COMMON.F3S"
mRunOnce: [SpybotDeletingC5692] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\COMMON.F3S"
mRunOnce: [SpybotDeletingA2683] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\DOG.F3S"
mRunOnce: [SpybotDeletingC6884] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\DOG.F3S"
mRunOnce: [SpybotDeletingA6024] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\FISH.F3S"
mRunOnce: [SpybotDeletingC1279] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\FISH.F3S"
mRunOnce: [SpybotDeletingA7047] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\KUNGFU.F3S"
mRunOnce: [SpybotDeletingC2627] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\KUNGFU.F3S"
mRunOnce: [SpybotDeletingA1414] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\LIFEGARD.F3S"
mRunOnce: [SpybotDeletingC2968] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\LIFEGARD.F3S"
mRunOnce: [SpybotDeletingA1019] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAID.F3S"
mRunOnce: [SpybotDeletingC968] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAID.F3S"
mRunOnce: [SpybotDeletingA9536] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAILBOX.F3S"
mRunOnce: [SpybotDeletingC4686] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\MAILBOX.F3S"
mRunOnce: [SpybotDeletingA5887] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\OPERA.F3S"
mRunOnce: [SpybotDeletingC8542] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\OPERA.F3S"
mRunOnce: [SpybotDeletingA7523] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\ROBOT.F3S"
mRunOnce: [SpybotDeletingC1970] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\ROBOT.F3S"
mRunOnce: [SpybotDeletingA6880] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SEDUCT.F3S"
mRunOnce: [SpybotDeletingC7159] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SEDUCT.F3S"
mRunOnce: [SpybotDeletingA1488] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SURFER.F3S"
mRunOnce: [SpybotDeletingC7578] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Notifier\SURFER.F3S"
mRunOnce: [SpybotDeletingA9484] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Overlay\COMMON.F3S"
mRunOnce: [SpybotDeletingC2143] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Overlay\COMMON.F3S"
mRunOnce: [SpybotDeletingA8660] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
mRunOnce: [SpybotDeletingC1884] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3WALLPP.DAT"
mRunOnce: [SpybotDeletingA6165] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\Settings\s_pid.dat"
mRunOnce: [SpybotDeletingC3447] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\Settings\s_pid.dat"
mRunOnce: [SpybotDeletingA6168] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\CM.ICO"
mRunOnce: [SpybotDeletingC5057] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\CM.ICO"
mRunOnce: [SpybotDeletingA8014] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\MFC.ICO"
mRunOnce: [SpybotDeletingC4333] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\MFC.ICO"
mRunOnce: [SpybotDeletingA1992] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\PSS.ICO"
mRunOnce: [SpybotDeletingC9844] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\PSS.ICO"
mRunOnce: [SpybotDeletingA7866] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\SMILEY.ICO"
mRunOnce: [SpybotDeletingC7667] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\SMILEY.ICO"
mRunOnce: [SpybotDeletingA966] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\WB.ICO"
mRunOnce: [SpybotDeletingC8992] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\WB.ICO"
mRunOnce: [SpybotDeletingA3821] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\ZWINKY.ICO"
mRunOnce: [SpybotDeletingC127] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\icons\ZWINKY.ICO"
mRunOnce: [SpybotDeletingA395] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HKSTUB.DLL"
mRunOnce: [SpybotDeletingC6085] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HKSTUB.DLL"
mRunOnce: [SpybotDeletingA7091] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REGHK.DLL"
mRunOnce: [SpybotDeletingC223] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REGHK.DLL"
mRunOnce: [SpybotDeletingA7432] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3AUXSTB.DLL"
mRunOnce: [SpybotDeletingC95] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3AUXSTB.DLL"
mRunOnce: [SpybotDeletingA4642] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3DLGHK.DLL"
mRunOnce: [SpybotDeletingC4299] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3DLGHK.DLL"
mRunOnce: [SpybotDeletingA7512] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IDLE.DLL"
mRunOnce: [SpybotDeletingC2402] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3IDLE.DLL"
mRunOnce: [SpybotDeletingA4422] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MSG.DLL"
mRunOnce: [SpybotDeletingC1475] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MSG.DLL"
mRunOnce: [SpybotDeletingA2582] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3OUTLCN.DLL"
mRunOnce: [SpybotDeletingC2672] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3OUTLCN.DLL"
mRunOnce: [SpybotDeletingA3732] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKIN.DLL"
mRunOnce: [SpybotDeletingC8652] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SKIN.DLL"
mRunOnce: [SpybotDeletingA3915] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSMLBTN.DLL"
mRunOnce: [SpybotDeletingC9243] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSMLBTN.DLL"
mRunOnce: [SpybotDeletingA5976] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEPLG.DLL"
mRunOnce: [SpybotDeletingC3455] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEPLG.DLL"
mRunOnce: [SpybotDeletingA1026] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL"
mRunOnce: [SpybotDeletingC420] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL"
mRunOnce: [SpybotDeletingA1954] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSUABTN.DLL"
mRunOnce: [SpybotDeletingC6515] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSUABTN.DLL"
mRunOnce: [SpybotDeletingA2905] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL"
mRunOnce: [SpybotDeletingC1706] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL"
mRunOnce: [SpybotDeletingA9131] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3CJPEG.DLL"
mRunOnce: [SpybotDeletingC5659] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3CJPEG.DLL"
mRunOnce: [SpybotDeletingA3326] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HISTSW.DLL"
mRunOnce: [SpybotDeletingC1967] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HISTSW.DLL"
mRunOnce: [SpybotDeletingA6742] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTMLMU.DLL"
mRunOnce: [SpybotDeletingC9933] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTMLMU.DLL"
mRunOnce: [SpybotDeletingA6757] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTTPCT.DLL"
mRunOnce: [SpybotDeletingC7501] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3HTTPCT.DLL"
mRunOnce: [SpybotDeletingA9511] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL"
mRunOnce: [SpybotDeletingC47] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL"
mRunOnce: [SpybotDeletingA8858] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3POPSWT.DLL"
mRunOnce: [SpybotDeletingC1789] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3POPSWT.DLL"
mRunOnce: [SpybotDeletingA4086] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3PSSAVR.SCR"
mRunOnce: [SpybotDeletingC555] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3PSSAVR.SCR"
mRunOnce: [SpybotDeletingA7996] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REPROX.DLL"
mRunOnce: [SpybotDeletingC918] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3REPROX.DLL"
mRunOnce: [SpybotDeletingA4804] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3RESTUB.DLL"
mRunOnce: [SpybotDeletingC503] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3RESTUB.DLL"
mRunOnce: [SpybotDeletingA3320] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCHMON.EXE"
mRunOnce: [SpybotDeletingC6437] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCHMON.EXE"
mRunOnce: [SpybotDeletingA2829] command.com /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCRCTR.DLL"
mRunOnce: [SpybotDeletingC4036] cmd.exe /c del "C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3SCRCTR.DLL"
mRunOnce: [SpybotSnD] "C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
StartupFolder: C:\Users\Jason\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg64.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
TB-X64: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
mRun-x64: [(Default)]
mRun-x64: [IgfxTray] C:\windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\windows\system32\igfxpers.exe
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun-x64: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun-x64: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun-x64: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun-x64: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun-x64: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
mRun-x64: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
mRun-x64: [ThpSrv] C:\windows\system32\thpsrv /logon
mRun-x64: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
mRun-x64: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
mRun-x64: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
mRun-x64: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - C:\Users\Jason\AppData\Roaming\Mozilla\Firefox\Profiles\ipde21gu.default\
FF - component: C:\Users\Jason\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\components\gvtlf.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
============= SERVICES / DRIVERS ===============
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-1-25 55280]
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\NISx64\1108000.005\symds64.sys [2010-10-22 433200]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\NISx64\1108000.005\symefa64.sys [2010-10-22 221232]
R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\Windows\System32\drivers\thpdrv.sys [2009-6-29 34880]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\Windows\System32\drivers\Thpevm.sys [2009-6-29 14784]
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\Windows\System32\drivers\tos_sps64.sys [2010-1-25 482384]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20101001.001\BHDrvx64.sys [2010-10-2 954928]
R1 ccHP;Symantec Hash Provider;C:\Windows\System32\drivers\NISx64\1108000.005\cchpx64.sys [2010-10-22 615040]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20101021.003\IDSviA64.sys [2010-10-19 476720]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\NISx64\1108000.005\ironx64.sys [2010-10-22 150064]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;C:\Windows\System32\drivers\NISx64\1108000.005\symtdiv.sys [2010-10-22 451120]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 Akamai;Akamai NetSession Interface;C:\windows\System32\svchost.exe -k Akamai [2009-7-13 27136]
R2 cfWiMAXService;ConfigFree WiMAX Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2009-10-28 252784]
R2 ConfigFree Service;ConfigFree Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-3-10 46448]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-1-25 13336]
R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\17.8.0.5\ccsvchst.exe [2010-10-22 126392]
R2 rimspci;rimspci;C:\Windows\System32\drivers\rimspe64.sys [2010-1-25 60416]
R2 risdpcie;risdpcie;C:\Windows\System32\drivers\risdpe64.sys [2010-1-25 81408]
R2 rixdpcie;rixdpcie;C:\Windows\System32\drivers\rixdpe64.sys [2010-1-25 55808]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2010-10-22 1153368]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\TOSHIBA\TECO\TecoService.exe [2009-9-28 251760]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\Windows\System32\drivers\TVALZFL.sys [2009-6-19 14472]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-1-25 2314240]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-10-21 132656]
R3 FwLnk;FwLnk Driver;C:\Windows\System32\drivers\FwLnk.sys [2010-1-25 9216]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-1-25 56344]
R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2009-10-26 151936]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2009-10-30 244736]
R3 PGEffect;Pangu effect driver;C:\Windows\System32\drivers\PGEffect.sys [2010-1-25 35008]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-1-25 236544]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;C:\Windows\System32\drivers\rtl8192se.sys [2010-1-25 946688]
R3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-1-25 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-11-5 137560]
R3 TPCHSrv;TPCH Service;C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2009-11-10 824688]
RUnknown MyWebSearchService;MyWebSearchService; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-3-7 135664]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-3-7 1038088]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-4-19 50688]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-3-9 1255736]
=============== Created Last 30 ================
2010-10-23 03:21:16 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2010-10-23 03:21:16 -------- d-----w- C:\PROGRA~3\Spybot - Search & Destroy
2010-10-23 02:29:03 505392 ----a-w- C:\windows\System32\drivers\NISx64\1108000.005\srtsp64.sys
2010-10-23 02:29:03 451120 ----a-w- C:\windows\System32\drivers\NISx64\1108000.005\symtdiv.sys
2010-10-23 02:29:03 433200 ----a-r- C:\windows\System32\drivers\NISx64\1108000.005\symds64.sys
2010-10-23 02:29:03 32304 ----a-w- C:\windows\System32\drivers\NISx64\1108000.005\srtspx64.sys
2010-10-23 02:29:03 221232 ----a-w- C:\windows\System32\drivers\NISx64\1108000.005\symefa64.sys
2010-10-23 02:29:03 150064 ----a-w- C:\windows\System32\drivers\NISx64\1108000.005\ironx64.sys
2010-10-23 02:29:02 615040 ----a-w- C:\windows\System32\drivers\NISx64\1108000.005\cchpx64.sys
2010-10-23 02:28:35 -------- d-----w- C:\windows\System32\drivers\NISx64\1108000.005
2010-10-22 06:03:18 -------- d-----w- C:\Users\Jason\AppData\Local\CrashDumps
2010-10-22 02:47:47 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2010-10-22 02:46:18 173104 ----a-w- C:\windows\System32\drivers\SYMEVENT64x86.SYS
2010-10-22 02:46:08 -------- d-----w- C:\Program Files\Symantec
2010-10-22 02:46:08 -------- d-----w- C:\Program Files\Common Files\Symantec Shared
2010-10-22 02:35:10 177 ----a-w- C:\Users\Jason\AppData\Roaming\2834.bat
2010-10-22 02:35:07 178 ----a-w- C:\Users\Jason\AppData\Roaming\15569.bat
2010-10-22 02:34:58 514560 ----a-w- C:\Users\Jason\AppData\Roaming\hotfix.exe
2010-10-22 02:34:58 177 ----a-w- C:\Users\Jason\AppData\Roaming\6543.bat
2010-10-22 02:34:41 -------- d-----w- C:\Users\Jason\AppData\Roaming\D9F29B036FD9D3D379685D2C553E39E0
2010-10-22 00:49:18 -------- d-----w- C:\Program Files (x86)\MyWebSearch
2010-10-20 04:26:56 8006480 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{FA48E0E3-F410-41A9-8FF8-778C6240D3CB}\mpengine.dll
2010-10-13 03:01:10 148992 ----a-w- C:\windows\System32\t2embed.dll
2010-10-13 03:01:10 109056 ----a-w- C:\windows\SysWow64\t2embed.dll
2010-10-13 03:01:09 4582912 ----a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe
2010-10-13 03:01:09 2085376 ----a-w- C:\windows\System32\ole32.dll
2010-10-13 03:01:08 4247040 ----a-w- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
2010-10-13 03:01:08 1413632 ----a-w- C:\windows\SysWow64\ole32.dll
2010-10-13 03:01:07 483840 ----a-w- C:\windows\System32\StructuredQuery.dll
2010-10-13 03:01:07 363520 ----a-w- C:\windows\SysWow64\StructuredQuery.dll
2010-10-13 03:01:07 224256 ----a-w- C:\windows\SysWow64\schannel.dll
2010-10-13 03:01:06 633856 ----a-w- C:\windows\System32\comctl32.dll
2010-10-13 03:01:06 530432 ----a-w- C:\windows\SysWow64\comctl32.dll
2010-10-13 03:01:06 340992 ----a-w- C:\windows\System32\schannel.dll
2010-10-08 07:01:17 243712 ----a-w- C:\windows\System32\drivers\ks.sys
2010-10-08 07:01:17 184832 ----a-w- C:\windows\System32\drivers\usbvideo.sys
2010-10-08 03:54:44 -------- d-----w- C:\Users\Jason\AppData\Local\Electronic Arts
2010-10-08 00:06:28 -------- d-----w- C:\Users\Jason\AppData\Local\ElevatedDiagnostics
2010-10-07 01:06:39 2048 ----a-w- C:\windows\SysWow64\tzres.dll
2010-10-07 01:06:39 2048 ----a-w- C:\windows\System32\tzres.dll
2010-10-07 01:06:10 13312 ----a-w- C:\Program Files\Internet Explorer\iecompat.dll
2010-10-07 01:06:10 13312 ----a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll
2010-09-25 05:13:05 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2010-09-25 05:13:04 -------- d-----w- C:\Program Files (x86)\Steam
==================== Find3M ====================
2010-09-08 15:17:46 94208 ----a-w- C:\windows\SysWow64\QuickTimeVR.qtx
2010-09-08 15:17:46 69632 ----a-w- C:\windows\SysWow64\QuickTime.qts
2010-09-08 05:36:17 1192960 ----a-w- C:\windows\System32\wininet.dll
2010-09-08 05:34:34 57856 ----a-w- C:\windows\System32\licmgr10.dll
2010-09-08 04:30:04 978432 ----a-w- C:\windows\SysWow64\wininet.dll
2010-09-08 04:28:15 44544 ----a-w- C:\windows\SysWow64\licmgr10.dll
2010-09-08 04:16:38 482816 ----a-w- C:\windows\System32\html.iec
2010-09-08 03:35:30 1638912 ----a-w- C:\windows\System32\mshtml.tlb
2010-09-08 03:22:31 386048 ----a-w- C:\windows\SysWow64\html.iec
2010-09-08 02:48:16 1638912 ----a-w- C:\windows\SysWow64\mshtml.tlb
2010-09-01 05:12:09 12625920 ----a-w- C:\windows\System32\wmploc.DLL
2010-09-01 04:23:49 12625408 ----a-w- C:\windows\SysWow64\wmploc.DLL
2010-09-01 02:58:34 3123712 ----a-w- C:\windows\System32\win32k.sys
2010-08-31 04:32:30 954752 ----a-w- C:\windows\SysWow64\mfc40.dll
2010-08-31 04:32:30 954288 ----a-w- C:\windows\SysWow64\mfc40u.dll
2010-08-27 06:14:02 236032 ----a-w- C:\windows\System32\srvsvc.dll
2010-08-27 05:46:48 9728 ----a-w- C:\windows\SysWow64\sscore.dll
2010-08-27 03:38:04 463360 ----a-w- C:\windows\System32\drivers\srv.sys
2010-08-27 03:37:48 402944 ----a-w- C:\windows\System32\drivers\srv2.sys
2010-08-27 03:37:26 161792 ----a-w- C:\windows\System32\drivers\srvnet.sys
2010-08-21 06:38:47 1024512 ----a-w- C:\windows\System32\wmpmde.dll
2010-08-21 06:29:47 558592 ----a-w- C:\windows\System32\spoolsv.exe
2010-08-21 05:36:33 738816 ----a-w- C:\windows\SysWow64\wmpmde.dll
2010-07-29 06:30:34 82944 ----a-w- C:\windows\SysWow64\iccvid.dll
============= FINISH: 14:45:04.95 ===============
FunWebProducts: [SBI $51F213BA] Program directory (Directory, fixing failed)
C:\Program Files (x86)\MyWebSearch\bar\
FunWebProducts: [SBI $9975C0B8] Program directory (Directory, fixing failed)
C:\Program Files (x86)\MyWebSearch\bar\1.bin\
MyWay.MyWebSearch: [SBI $676B23CE] Program directory (Directory, fixing failed)
C:\Program Files (x86)\MYWEBSEARCH\
MyWay.MyWebSearch: [SBI $E4947DDB] Library (File, fixed)
C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSVC.EXE_old
Properties.size=28762
Properties.md5=48D50D679D28E5C4BF5A67664CC56B41
Properties.filedate=1287708559
Properties.filedatetext=2010-10-21 20:49:18
MyWay.MyWebSearch: [SBI $F06432E0] Program directory (Directory, fixing failed)
C:\Program Files (x86)\MyWebSearch\bar\1.bin
MyWay.MyWebSearch: [SBI $78882F84] Program directory (Directory, fixing failed)
C:\Program Files (x86)\MyWebSearch\bar
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2010-10-22 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2010-06-29 Includes\Adware.sbi (*)
2010-10-12 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-09-22 Includes\Dialer.sbi (*)
2010-10-12 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2010-10-12 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-08-02 Includes\Keyloggers.sbi (*)
2010-10-12 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2010-09-13 Includes\Malware.sbi (*)
2010-10-19 Includes\MalwareC.sbi (*)
2010-05-18 Includes\PUPS.sbi (*)
2010-10-12 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-10-12 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-06-29 Includes\Spyware.sbi (*)
2010-10-12 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-08-04 Includes\Trojans.sbi (*)
2010-10-12 Includes\TrojansC-02.sbi (*)
2010-10-12 Includes\TrojansC-03.sbi (*)
2010-10-12 Includes\TrojansC-04.sbi (*)
2010-10-20 Includes\TrojansC-05.sbi (*)
2010-10-12 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
Thanks in advance for you help!
