nffc86
Topic Starter
Hello, from yesterday I have been getting random IE pop ups (I use Chrome as my browser). My AVG free, ad-aware and Malwarebytes' Anti-Malware have not found anything on my computer. I would appreciate assistance in getting rid of this problem as it's rather annoying!
DDStxt:
DDS (Ver_10-03-17.01) - NTFSX64
Run by [removed] at 23:11:30.11 on 20/04/2010
Internet Explorer: 8.0.6001.18904 BrowserJavaVersion: 1.6.0_16
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.4094.1858 [GMT 1:00]
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files (x86)\AVG\AVG9\avgchsva.exe
C:\Program Files (x86)\AVG\AVG9\avgrsa.exe
C:\Windows\system32\lsm.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrva.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Fruboa.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\AVG\AVG9\avgemc.exe
C:\Program Files (x86)\AVG\AVG9\avgnsa.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Creative\Sound Blaster X-Fi Surround 5.1\Volume Panel\VolPanlu.exe
C:\Program Files (x86)\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Users\Helen\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Spotify\spotify.exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Last.fm\LastFM.exe
C:\Users\Helen\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Helen\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files (x86)\AVG\AVG9\avgui.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Helen\Documents\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
mLocal Page = c:\windows\syswow64\blank.htm
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files (x86)\avg\avg8\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
uRun: [msnmsgr] "c:\program files (x86)\windows live\messenger\msnmsgr.exe" /background
uRun: [WMPNSCFG] c:\program files (x86)\windows media player\WMPNSCFG.exe
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
uRun: [SUPERAntiSpyware] c:\program files (x86)\superantispyware\SUPERAntiSpyware.exe
uRun: [PlayNC Launcher]
uRun: [Google Update] "c:\users\helen\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Skype] "c:\program files (x86)\skype\phone\Skype.exe" /nosplash /minimized
mRun: [JMB36X IDE Setup] c:\windows\raidtool\xInsIDE.exe
mRun: [F5D9050] c:\program files (x86)\belkin\f5d9050\Belkinwcui.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "c:\program files (x86)\java\jre6\bin\jusched.exe"
mRun: [VolPanel] "c:\program files (x86)\creative\sound blaster x-fi surround 5.1\volume panel\VolPanlu.exe" /r
mRun: [Module Loader] "c:\program files (x86)\creative\shared files\module loader\DLLML.exe" -StartUpRun
mRun: [AVG9_TRAY] c:\progra~2\avg\avg9\avgtray.exe
mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files (x86)\itunes\iTunesHelper.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15109/CTPID.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files (x86)\superantispyware\SASWINLO.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files (x86)\superantispyware\SASSEH.DLL
TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [RtHDVCpl] c:\program files\realtek\audio\hda\RAVCpl64.exe
mRun-x64: [Skytel] c:\program files\realtek\audio\hda\Skytel.exe
mRun-x64: [Creative SB Monitoring Utility] RunDll32 sbavmon.dll,SBAVMonitor
AppInit_DLLs-X64: avgrssta.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\helen\appdata\roaming\mozilla\firefox\profiles\oyl2qeas.default\
FF - component: c:\program files (x86)\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\users\helen\appdata\local\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-8-15 68640]
R1 AvgLdx64;AVG Free AVI Loader Driver x64;c:\windows\system32\drivers\avgldx64.sys [2009-6-17 269320]
R1 AvgMfx64;AVG Free On-access Scanner Minifilter Driver x64;c:\windows\system32\drivers\avgmfx64.sys [2009-6-17 35464]
R1 AvgTdiA;AVG Free8 Network Redirector x64;c:\windows\system32\drivers\avgtdia.sys [2009-6-17 317520]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-7-2 203264]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files (x86)\avg\avg9\avgemc.exe [2010-3-14 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files (x86)\avg\avg9\avgwdsvc.exe [2010-3-14 308064]
R2 ES lite Service;ES lite Service for program management.;c:\program files (x86)\gigabyte\easysaver\essvr.exe [2009-6-16 68136]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]
R2 LVPrcS64;Process Monitor;c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe [2008-7-26 187928]
R3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [2009-10-13 976896]
R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\drivers\LVPr2M64.sys [2008-7-26 30232]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\drivers\lvrs64.sys [2009-8-18 790424]
R3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\drivers\LVUSBS64.sys [2009-8-18 50072]
R3 LVUVC64;Logitech QuickCam E3500(UVC);c:\windows\system32\drivers\lvuvc64.sys [2009-8-18 5068056]
R3 netr28ux;Linksys USB Wireless LAN Card Driver for Vista;c:\windows\system32\drivers\netr28ux.sys [2007-12-14 709632]
R3 Razerlow;Razer Pro|Solutions;c:\windows\system32\drivers\DB3G.sys [2005-11-7 21120]
S1 SASDIFSV;SASDIFSV;c:\program files (x86)\superantispyware\sasdifsv.sys [2009-8-5 9968]
S1 SASKUTIL;SASKUTIL;c:\program files (x86)\superantispyware\SASKUTIL.SYS [2009-8-5 74480]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-6-18 89920]
S3 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;c:\program files (x86)\common files\creative labs shared\service\AL1Licensing.exe [2009-10-13 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\common files\creative labs shared\service\CTAELicensing.exe [2009-10-13 79360]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\dragon age\bin_ship\daupdatersvc.service.exe [2010-2-25 25832]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 27648]
S3 netr7364;Belkin Wireless 54G USB Network Adapter Driver for Vista;c:\windows\system32\drivers\netr7364.sys [2009-6-17 575488]
S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-21 19968]
S3 SASENUM;SASENUM;c:\program files (x86)\superantispyware\SASENUM.SYS [2009-8-5 7408]
S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl64.sys [2009-10-16 50176]
S4 IAMTXPE;Driver for Intel® Active Management Technology - KCS;c:\windows\system32\drivers\IAMTXPE.sys [2009-6-17 43008]
S4 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2009-6-17 56320]
============== File Associations ===============
JSEFile=c:\windows\syswow64\WScript.exe "%1" %*
=============== Created Last 30 ================
2010-04-19 21:57:36 0 d—–w- c:\program files (x86)\Trend Micro
2010-04-19 20:29:03 159232 —-a-w- c:\windows\Fruboa.exe
2010-04-14 22:00:04 1427336 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 22:00:03 29696 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 22:00:03 225280 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 22:00:02 273920 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 22:00:02 135680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 22:00:02 106496 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 22:00:00 4697992 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 21:59:57 612864 —-a-w- c:\windows\system32\vbscript.dll
2010-04-14 21:59:57 420352 —-a-w- c:\windows\syswow64\vbscript.dll
2010-04-14 21:59:55 72192 —-a-w- c:\windows\system32\l3codeca.acm
2010-04-14 21:59:55 62464 —-a-w- c:\windows\syswow64\l3codeca.acm
2010-04-14 21:59:55 220672 —-a-w- c:\windows\syswow64\l3codecp.acm
2010-04-14 21:59:55 181760 —-a-w- c:\windows\system32\l3codecp.acm
2010-04-13 18:03:09 98304 —-a-w- c:\windows\syswow64\cabview.dll
2010-04-13 18:03:09 104960 —-a-w- c:\windows\system32\cabview.dll
2010-04-13 18:03:06 218624 —-a-w- c:\windows\system32\wintrust.dll
2010-04-13 18:03:06 172032 —-a-w- c:\windows\syswow64\wintrust.dll
2010-04-08 20:15:37 56 —ha-w- c:\windows\syswow64\ezsidmv.dat
2010-04-08 20:10:55 0 d—–r- c:\program files (x86)\Skype
2010-04-08 20:10:48 0 d—–w- c:\programdata\Skype
2010-04-02 19:16:23 0 d—–w- c:\program files\iPod
2010-04-02 19:16:21 0 d—–w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2010-04-02 19:16:21 0 d—–w- c:\program files\iTunes
2010-04-02 19:10:13 0 d—–w- c:\program files\Bonjour
2010-04-02 19:10:13 0 d—–w- c:\program files (x86)\Bonjour
2010-04-01 07:40:13 294912 —-a-w- c:\windows\system32\browserchoice.exe
==================== Find3M ====================
2010-04-20 17:50:36 23080 —-a-w- c:\windows\gdrv.sys
2010-04-20 17:46:23 317520 —-a-w- c:\windows\system32\drivers\avgtdia.sys
2010-04-12 20:47:54 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-04-02 19:11:38 86016 —-a-w- c:\windows\inf\infpub.dat
2010-04-02 19:11:38 143360 —-a-w- c:\windows\inf\infstor.dat
2010-04-02 19:11:37 239616 —-a-w- c:\windows\inf\infstrng.dat
2010-03-20 10:57:37 15688 —-a-w- c:\windows\system32\lsdelete.exe
2010-03-14 11:55:43 35464 —-a-w- c:\windows\system32\drivers\avgmfx64.sys
2010-03-14 11:55:43 12976 —-a-w- c:\windows\system32\avgrssta.dll
2010-03-14 11:55:18 269320 —-a-w- c:\windows\system32\drivers\avgldx64.sys
2010-02-23 07:03:02 1147904 —-a-w- c:\windows\system32\wininet.dll
2010-02-23 06:57:40 132096 —-a-w- c:\windows\system32\iesysprep.dll
2010-02-23 06:57:39 77312 —-a-w- c:\windows\system32\iesetup.dll
2010-02-23 06:39:13 916480 —-a-w- c:\windows\syswow64\wininet.dll
2010-02-23 06:39:00 1209344 —-a-w- c:\windows\syswow64\urlmon.dll
2010-02-23 06:37:26 206848 —-a-w- c:\windows\syswow64\occache.dll
2010-02-23 06:35:21 611840 —-a-w- c:\windows\syswow64\mstime.dll
2010-02-23 06:34:51 5944832 —-a-w- c:\windows\syswow64\mshtml.dll
2010-02-23 06:34:49 594432 —-a-w- c:\windows\syswow64\msfeeds.dll
2010-02-23 06:34:49 55296 —-a-w- c:\windows\syswow64\msfeedsbs.dll
2010-02-23 06:34:06 25600 —-a-w- c:\windows\syswow64\jsproxy.dll
2010-02-23 06:33:45 71680 —-a-w- c:\windows\syswow64\iesetup.dll
2010-02-23 06:33:45 1985536 —-a-w- c:\windows\syswow64\iertutil.dll
2010-02-23 06:33:45 164352 —-a-w- c:\windows\syswow64\ieui.dll
2010-02-23 06:33:45 109056 —-a-w- c:\windows\syswow64\iesysprep.dll
2010-02-23 06:33:44 55808 —-a-w- c:\windows\syswow64\iernonce.dll
2010-02-23 06:33:44 184320 —-a-w- c:\windows\syswow64\iepeers.dll
2010-02-23 06:33:44 11070976 —-a-w- c:\windows\syswow64\ieframe.dll
2010-02-23 06:33:38 387584 —-a-w- c:\windows\syswow64\iedkcs32.dll
2010-02-23 05:19:22 162816 —-a-w- c:\windows\system32\ieUnatt.exe
2010-02-23 04:55:36 133632 —-a-w- c:\windows\syswow64\ieUnatt.exe
2010-02-23 04:55:24 173056 —-a-w- c:\windows\syswow64\ie4uinit.exe
2010-02-23 04:54:43 13312 —-a-w- c:\windows\syswow64\msfeedssync.exe
2010-02-20 23:15:56 32768 —-a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:14:20 33792 —-a-w- c:\windows\system32\httpapi.dll
2010-02-20 23:06:41 24064 —-a-w- c:\windows\syswow64\nshhttp.dll
2010-02-20 23:05:14 30720 —-a-w- c:\windows\syswow64\httpapi.dll
2010-02-20 21:30:08 620032 —-a-w- c:\windows\system32\drivers\http.sys
2010-02-12 11:01:24 95520 —-a-w- c:\windows\system32\dnssd.dll
2010-02-12 11:01:24 119584 —-a-w- c:\windows\system32\dns-sd.exe
2010-02-12 10:46:14 91424 —-a-w- c:\windows\syswow64\dnssd.dll
2010-02-12 10:46:14 107808 —-a-w- c:\windows\syswow64\dns-sd.exe
2010-01-25 12:10:22 538624 —-a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:10:22 160768 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:10:22 160768 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:10:03 539136 —-a-w- c:\windows\system32\secproc.dll
2010-01-25 12:08:59 460288 —-a-w- c:\windows\system32\msdrm.dll
2010-01-25 12:00:35 471552 —-a-w- c:\windows\syswow64\secproc_isv.dll
2010-01-25 12:00:35 152576 —-a-w- c:\windows\syswow64\secproc_ssp_isv.dll
2010-01-25 12:00:35 152064 —-a-w- c:\windows\syswow64\secproc_ssp.dll
2010-01-25 12:00:22 471552 —-a-w- c:\windows\syswow64\secproc.dll
2010-01-25 11:58:52 332288 —-a-w- c:\windows\syswow64\msdrm.dll
2010-01-25 08:29:35 413696 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:29:31 600576 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:29:31 409600 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-25 08:29:28 599552 —-a-w- c:\windows\system32\RMActivate.exe
2010-01-25 08:21:20 526336 —-a-w- c:\windows\syswow64\RMActivate_isv.exe
2010-01-25 08:21:20 346624 —-a-w- c:\windows\syswow64\RMActivate_ssp_isv.exe
2010-01-25 08:21:18 518144 —-a-w- c:\windows\syswow64\RMActivate.exe
2010-01-25 08:21:18 347136 —-a-w- c:\windows\syswow64\RMActivate_ssp.exe
2010-01-23 09:44:17 2048 —-a-w- c:\windows\system32\tzres.dll
2010-01-23 09:26:13 2048 —-a-w- c:\windows\syswow64\tzres.dll
2009-11-18 13:11:00 665600 —-a-w- c:\windows\inf\drvindex.dat
2008-01-21 03:21:59 174 –sha-w- c:\program files\desktop.ini
2008-01-21 03:21:59 174 –sha-w- c:\program files (x86)\desktop.ini
2006-11-02 15:14:56 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 15:14:56 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 15:14:56 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 15:14:56 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-11-16 19:37:28 245760 –sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-10-23 11:56:04 245760 –sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
============= FINISH: 23:12:35.37 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-20 23:35:26
Windows 6.0.6002 Service Pack 2
Running: 3ybmnd5n.exe
—- Files - GMER 1.0.15 —-
File C:\Users\Helen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EITVVL2W\st[5] 4515 bytes
File C:\Users\Helen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R31V2BUK\01[7].htm 2906 bytes
File C:\Users\Helen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R31V2BUK\iframe3[3].htm 744 bytes
File C:\Users\Helen\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt 0 bytes
—- EOF - GMER 1.0.15 —-
DDStxt:
DDS (Ver_10-03-17.01) - NTFSX64
Run by [removed] at 23:11:30.11 on 20/04/2010
Internet Explorer: 8.0.6001.18904 BrowserJavaVersion: 1.6.0_16
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.4094.1858 [GMT 1:00]
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files (x86)\AVG\AVG9\avgchsva.exe
C:\Program Files (x86)\AVG\AVG9\avgrsa.exe
C:\Windows\system32\lsm.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrva.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Fruboa.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\AVG\AVG9\avgemc.exe
C:\Program Files (x86)\AVG\AVG9\avgnsa.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Creative\Sound Blaster X-Fi Surround 5.1\Volume Panel\VolPanlu.exe
C:\Program Files (x86)\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Users\Helen\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Spotify\spotify.exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Last.fm\LastFM.exe
C:\Users\Helen\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Helen\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files (x86)\AVG\AVG9\avgui.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Helen\Documents\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
mLocal Page = c:\windows\syswow64\blank.htm
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files (x86)\avg\avg8\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
uRun: [msnmsgr] "c:\program files (x86)\windows live\messenger\msnmsgr.exe" /background
uRun: [WMPNSCFG] c:\program files (x86)\windows media player\WMPNSCFG.exe
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
uRun: [SUPERAntiSpyware] c:\program files (x86)\superantispyware\SUPERAntiSpyware.exe
uRun: [PlayNC Launcher]
uRun: [Google Update] "c:\users\helen\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [Skype] "c:\program files (x86)\skype\phone\Skype.exe" /nosplash /minimized
mRun: [JMB36X IDE Setup] c:\windows\raidtool\xInsIDE.exe
mRun: [F5D9050] c:\program files (x86)\belkin\f5d9050\Belkinwcui.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "c:\program files (x86)\java\jre6\bin\jusched.exe"
mRun: [VolPanel] "c:\program files (x86)\creative\sound blaster x-fi surround 5.1\volume panel\VolPanlu.exe" /r
mRun: [Module Loader] "c:\program files (x86)\creative\shared files\module loader\DLLML.exe" -StartUpRun
mRun: [AVG9_TRAY] c:\progra~2\avg\avg9\avgtray.exe
mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files (x86)\itunes\iTunesHelper.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15109/CTPID.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files (x86)\superantispyware\SASWINLO.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files (x86)\superantispyware\SASSEH.DLL
TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [RtHDVCpl] c:\program files\realtek\audio\hda\RAVCpl64.exe
mRun-x64: [Skytel] c:\program files\realtek\audio\hda\Skytel.exe
mRun-x64: [Creative SB Monitoring Utility] RunDll32 sbavmon.dll,SBAVMonitor
AppInit_DLLs-X64: avgrssta.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\helen\appdata\roaming\mozilla\firefox\profiles\oyl2qeas.default\
FF - component: c:\program files (x86)\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\users\helen\appdata\local\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-8-15 68640]
R1 AvgLdx64;AVG Free AVI Loader Driver x64;c:\windows\system32\drivers\avgldx64.sys [2009-6-17 269320]
R1 AvgMfx64;AVG Free On-access Scanner Minifilter Driver x64;c:\windows\system32\drivers\avgmfx64.sys [2009-6-17 35464]
R1 AvgTdiA;AVG Free8 Network Redirector x64;c:\windows\system32\drivers\avgtdia.sys [2009-6-17 317520]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-7-2 203264]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files (x86)\avg\avg9\avgemc.exe [2010-3-14 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files (x86)\avg\avg9\avgwdsvc.exe [2010-3-14 308064]
R2 ES lite Service;ES lite Service for program management.;c:\program files (x86)\gigabyte\easysaver\essvr.exe [2009-6-16 68136]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]
R2 LVPrcS64;Process Monitor;c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe [2008-7-26 187928]
R3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [2009-10-13 976896]
R3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\drivers\LVPr2M64.sys [2008-7-26 30232]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\drivers\lvrs64.sys [2009-8-18 790424]
R3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\drivers\LVUSBS64.sys [2009-8-18 50072]
R3 LVUVC64;Logitech QuickCam E3500(UVC);c:\windows\system32\drivers\lvuvc64.sys [2009-8-18 5068056]
R3 netr28ux;Linksys USB Wireless LAN Card Driver for Vista;c:\windows\system32\drivers\netr28ux.sys [2007-12-14 709632]
R3 Razerlow;Razer Pro|Solutions;c:\windows\system32\drivers\DB3G.sys [2005-11-7 21120]
S1 SASDIFSV;SASDIFSV;c:\program files (x86)\superantispyware\sasdifsv.sys [2009-8-5 9968]
S1 SASKUTIL;SASKUTIL;c:\program files (x86)\superantispyware\SASKUTIL.SYS [2009-8-5 74480]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-6-18 89920]
S3 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;c:\program files (x86)\common files\creative labs shared\service\AL1Licensing.exe [2009-10-13 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\common files\creative labs shared\service\CTAELicensing.exe [2009-10-13 79360]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\dragon age\bin_ship\daupdatersvc.service.exe [2010-2-25 25832]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 27648]
S3 netr7364;Belkin Wireless 54G USB Network Adapter Driver for Vista;c:\windows\system32\drivers\netr7364.sys [2009-6-17 575488]
S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-21 19968]
S3 SASENUM;SASENUM;c:\program files (x86)\superantispyware\SASENUM.SYS [2009-8-5 7408]
S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl64.sys [2009-10-16 50176]
S4 IAMTXPE;Driver for Intel® Active Management Technology - KCS;c:\windows\system32\drivers\IAMTXPE.sys [2009-6-17 43008]
S4 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2009-6-17 56320]
============== File Associations ===============
JSEFile=c:\windows\syswow64\WScript.exe "%1" %*
=============== Created Last 30 ================
2010-04-19 21:57:36 0 d—–w- c:\program files (x86)\Trend Micro
2010-04-19 20:29:03 159232 —-a-w- c:\windows\Fruboa.exe
2010-04-14 22:00:04 1427336 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 22:00:03 29696 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 22:00:03 225280 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 22:00:02 273920 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 22:00:02 135680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 22:00:02 106496 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 22:00:00 4697992 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 21:59:57 612864 —-a-w- c:\windows\system32\vbscript.dll
2010-04-14 21:59:57 420352 —-a-w- c:\windows\syswow64\vbscript.dll
2010-04-14 21:59:55 72192 —-a-w- c:\windows\system32\l3codeca.acm
2010-04-14 21:59:55 62464 —-a-w- c:\windows\syswow64\l3codeca.acm
2010-04-14 21:59:55 220672 —-a-w- c:\windows\syswow64\l3codecp.acm
2010-04-14 21:59:55 181760 —-a-w- c:\windows\system32\l3codecp.acm
2010-04-13 18:03:09 98304 —-a-w- c:\windows\syswow64\cabview.dll
2010-04-13 18:03:09 104960 —-a-w- c:\windows\system32\cabview.dll
2010-04-13 18:03:06 218624 —-a-w- c:\windows\system32\wintrust.dll
2010-04-13 18:03:06 172032 —-a-w- c:\windows\syswow64\wintrust.dll
2010-04-08 20:15:37 56 —ha-w- c:\windows\syswow64\ezsidmv.dat
2010-04-08 20:10:55 0 d—–r- c:\program files (x86)\Skype
2010-04-08 20:10:48 0 d—–w- c:\programdata\Skype
2010-04-02 19:16:23 0 d—–w- c:\program files\iPod
2010-04-02 19:16:21 0 d—–w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2010-04-02 19:16:21 0 d—–w- c:\program files\iTunes
2010-04-02 19:10:13 0 d—–w- c:\program files\Bonjour
2010-04-02 19:10:13 0 d—–w- c:\program files (x86)\Bonjour
2010-04-01 07:40:13 294912 —-a-w- c:\windows\system32\browserchoice.exe
==================== Find3M ====================
2010-04-20 17:50:36 23080 —-a-w- c:\windows\gdrv.sys
2010-04-20 17:46:23 317520 —-a-w- c:\windows\system32\drivers\avgtdia.sys
2010-04-12 20:47:54 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-04-02 19:11:38 86016 —-a-w- c:\windows\inf\infpub.dat
2010-04-02 19:11:38 143360 —-a-w- c:\windows\inf\infstor.dat
2010-04-02 19:11:37 239616 —-a-w- c:\windows\inf\infstrng.dat
2010-03-20 10:57:37 15688 —-a-w- c:\windows\system32\lsdelete.exe
2010-03-14 11:55:43 35464 —-a-w- c:\windows\system32\drivers\avgmfx64.sys
2010-03-14 11:55:43 12976 —-a-w- c:\windows\system32\avgrssta.dll
2010-03-14 11:55:18 269320 —-a-w- c:\windows\system32\drivers\avgldx64.sys
2010-02-23 07:03:02 1147904 —-a-w- c:\windows\system32\wininet.dll
2010-02-23 06:57:40 132096 —-a-w- c:\windows\system32\iesysprep.dll
2010-02-23 06:57:39 77312 —-a-w- c:\windows\system32\iesetup.dll
2010-02-23 06:39:13 916480 —-a-w- c:\windows\syswow64\wininet.dll
2010-02-23 06:39:00 1209344 —-a-w- c:\windows\syswow64\urlmon.dll
2010-02-23 06:37:26 206848 —-a-w- c:\windows\syswow64\occache.dll
2010-02-23 06:35:21 611840 —-a-w- c:\windows\syswow64\mstime.dll
2010-02-23 06:34:51 5944832 —-a-w- c:\windows\syswow64\mshtml.dll
2010-02-23 06:34:49 594432 —-a-w- c:\windows\syswow64\msfeeds.dll
2010-02-23 06:34:49 55296 —-a-w- c:\windows\syswow64\msfeedsbs.dll
2010-02-23 06:34:06 25600 —-a-w- c:\windows\syswow64\jsproxy.dll
2010-02-23 06:33:45 71680 —-a-w- c:\windows\syswow64\iesetup.dll
2010-02-23 06:33:45 1985536 —-a-w- c:\windows\syswow64\iertutil.dll
2010-02-23 06:33:45 164352 —-a-w- c:\windows\syswow64\ieui.dll
2010-02-23 06:33:45 109056 —-a-w- c:\windows\syswow64\iesysprep.dll
2010-02-23 06:33:44 55808 —-a-w- c:\windows\syswow64\iernonce.dll
2010-02-23 06:33:44 184320 —-a-w- c:\windows\syswow64\iepeers.dll
2010-02-23 06:33:44 11070976 —-a-w- c:\windows\syswow64\ieframe.dll
2010-02-23 06:33:38 387584 —-a-w- c:\windows\syswow64\iedkcs32.dll
2010-02-23 05:19:22 162816 —-a-w- c:\windows\system32\ieUnatt.exe
2010-02-23 04:55:36 133632 —-a-w- c:\windows\syswow64\ieUnatt.exe
2010-02-23 04:55:24 173056 —-a-w- c:\windows\syswow64\ie4uinit.exe
2010-02-23 04:54:43 13312 —-a-w- c:\windows\syswow64\msfeedssync.exe
2010-02-20 23:15:56 32768 —-a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:14:20 33792 —-a-w- c:\windows\system32\httpapi.dll
2010-02-20 23:06:41 24064 —-a-w- c:\windows\syswow64\nshhttp.dll
2010-02-20 23:05:14 30720 —-a-w- c:\windows\syswow64\httpapi.dll
2010-02-20 21:30:08 620032 —-a-w- c:\windows\system32\drivers\http.sys
2010-02-12 11:01:24 95520 —-a-w- c:\windows\system32\dnssd.dll
2010-02-12 11:01:24 119584 —-a-w- c:\windows\system32\dns-sd.exe
2010-02-12 10:46:14 91424 —-a-w- c:\windows\syswow64\dnssd.dll
2010-02-12 10:46:14 107808 —-a-w- c:\windows\syswow64\dns-sd.exe
2010-01-25 12:10:22 538624 —-a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:10:22 160768 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:10:22 160768 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:10:03 539136 —-a-w- c:\windows\system32\secproc.dll
2010-01-25 12:08:59 460288 —-a-w- c:\windows\system32\msdrm.dll
2010-01-25 12:00:35 471552 —-a-w- c:\windows\syswow64\secproc_isv.dll
2010-01-25 12:00:35 152576 —-a-w- c:\windows\syswow64\secproc_ssp_isv.dll
2010-01-25 12:00:35 152064 —-a-w- c:\windows\syswow64\secproc_ssp.dll
2010-01-25 12:00:22 471552 —-a-w- c:\windows\syswow64\secproc.dll
2010-01-25 11:58:52 332288 —-a-w- c:\windows\syswow64\msdrm.dll
2010-01-25 08:29:35 413696 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:29:31 600576 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:29:31 409600 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-25 08:29:28 599552 —-a-w- c:\windows\system32\RMActivate.exe
2010-01-25 08:21:20 526336 —-a-w- c:\windows\syswow64\RMActivate_isv.exe
2010-01-25 08:21:20 346624 —-a-w- c:\windows\syswow64\RMActivate_ssp_isv.exe
2010-01-25 08:21:18 518144 —-a-w- c:\windows\syswow64\RMActivate.exe
2010-01-25 08:21:18 347136 —-a-w- c:\windows\syswow64\RMActivate_ssp.exe
2010-01-23 09:44:17 2048 —-a-w- c:\windows\system32\tzres.dll
2010-01-23 09:26:13 2048 —-a-w- c:\windows\syswow64\tzres.dll
2009-11-18 13:11:00 665600 —-a-w- c:\windows\inf\drvindex.dat
2008-01-21 03:21:59 174 –sha-w- c:\program files\desktop.ini
2008-01-21 03:21:59 174 –sha-w- c:\program files (x86)\desktop.ini
2006-11-02 15:14:56 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 15:14:56 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 15:14:56 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 15:14:56 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-11-16 19:37:28 245760 –sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-10-23 11:56:04 245760 –sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
============= FINISH: 23:12:35.37 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-20 23:35:26
Windows 6.0.6002 Service Pack 2
Running: 3ybmnd5n.exe
—- Files - GMER 1.0.15 —-
File C:\Users\Helen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EITVVL2W\st[5] 4515 bytes
File C:\Users\Helen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R31V2BUK\01[7].htm 2906 bytes
File C:\Users\Helen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R31V2BUK\iframe3[3].htm 744 bytes
File C:\Users\Helen\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt 0 bytes
—- EOF - GMER 1.0.15 —-